Live data from Hacker News

Twitter warns that private tweets were public for years

bbc.com

71–80 of 196 posts

Re: Twitter warns that private tweets were public for years

#71

This headline/article are pretty misleading. It makes the issue sound like if you had "Protect My Tweets" enabled, your tweets were still public. From reading the original notice [ https://help.twitter.com/en/protected-tweets-android ] it sounds like the setting would just be disabled, which then made your tweets public. But not that Twitter's app would continue to say they were protected. That's a pretty significant…

If you don't check your settings before each tweet, there's not much difference for between your settings being changed and your settings not working correctly.

Private tweets and profiles show a padlock next to the user's name... You don't have to go to any obscure menu to find out whether your tweets are public or not.

Re: Twitter warns that private tweets were public for years

#72
post #9

Just my own opinion, but at this point I think it's prudent to assume that pretty much anything you send out into the digital network world is public. If it's not something you would want the world knowing you said, don't put it out there. Security breaches happen. Bugs happen. Sometimes law enforcement just comes by and says, "Give me everything that user X has ever done." In short, sh!t happens. "Everything I do on…

Eric Schmidt: "If you have something that you don’t want anyone to know, maybe you shouldn’t be doing it in the first place." People have taken this different ways, but personally I think it's sage advice. We've lost our ability to keep secrets. Information wants to be free. We're terrible at digital security. Pretend everything you type into a computer is on the front page of the New York Times.

[deleted]

Re: Twitter warns that private tweets were public for years

#73
post #10
post #9

Just my own opinion, but at this point I think it's prudent to assume that pretty much anything you send out into the digital network world is public. If it's not something you would want the world knowing you said, don't put it out there. Security breaches happen. Bugs happen. Sometimes law enforcement just comes by and says, "Give me everything that user X has ever done." In short, sh!t happens. "Everything I do on…

Totally agree. But where does that leave us with “The Cloud”?

Not just the cloud. Any internet connected system, whether in the cloud or on-premises, is vulnerable to intrusion, data breaches, etc.

The only system that would be somewhat trustworthy would be a totally air-gapped internal system. This used to be the norm, pre-internet. Few businesses really have this today.

Re: Twitter warns that private tweets were public for years

#74
post #14

Earlier quoted context omitted.

With a couple exceptions perhaps, like Signal or iMessage? But I agree; unless the service is part of a very small whitelist, assume it's public.

except even those messages can become public, if one party makes them so, so even "secure" messaging should be considered compromised.

Modern secure messaging systems are typically OTR and have deniability: after the session ends, anybody can forge messages to make it look like they came from you. Sure the messages can become public, but they're no more "proof" than someone saying "X said Y".

Re: Twitter warns that private tweets were public for years

#75
post #9

Just my own opinion, but at this point I think it's prudent to assume that pretty much anything you send out into the digital network world is public. If it's not something you would want the world knowing you said, don't put it out there. Security breaches happen. Bugs happen. Sometimes law enforcement just comes by and says, "Give me everything that user X has ever done." In short, sh!t happens. "Everything I do on…

I'm often surprised how much people share via Slack as if it's an impenetrable fortress: perfect for pasting admin passwords, keys, and incriminating opinions and business secrets... if that floodgate ever opens then it will be a crazy time for us devs!

Just as a heads up on this, slack doesn't even use HTTPS! Your employer can certainly read all private slacks on your work network, even if it's a non-work-slack workspace

Re: Twitter warns that private tweets were public for years

#76

Earlier quoted context omitted.

I'm often surprised how much people share via Slack as if it's an impenetrable fortress: perfect for pasting admin passwords, keys, and incriminating opinions and business secrets... if that floodgate ever opens then it will be a crazy time for us devs!

Just as a heads up on this, slack doesn't even use HTTPS! Your employer can certainly read all private slacks on your work network, even if it's a non-work-slack workspace

Do you have a source for this? That sounds very surprising if true.

Re: Twitter warns that private tweets were public for years

#77
post #9

Just my own opinion, but at this point I think it's prudent to assume that pretty much anything you send out into the digital network world is public. If it's not something you would want the world knowing you said, don't put it out there. Security breaches happen. Bugs happen. Sometimes law enforcement just comes by and says, "Give me everything that user X has ever done." In short, sh!t happens. "Everything I do on…

> That's the thought we should all have in our heads before we send any post, or send any text, or send any email, or send any photo, or etc etc etc. We shouldn't rely on some company, that's using us to make money, to protect our privacy.

So don't, but that doesn't mean that everything can be attributed to you personally - even attributing something to a relatively dissociated username is difficult. At best you'll get an IP and that IP could belong to one or many people.

Anything you idiotically attribute to yourself (including private messages on your accounts) is attributable to you personally - assume all cloud services are fully compromised or extremely willing to misbehave.

Act accordingly. Never provide real information online, use shared IPs, VPNs, Tor in cases where repercussions could be significant. If you want privacy, don't expect it to be provided, take personal responsibility for it.

Re: Twitter warns that private tweets were public for years

#78

Earlier quoted context omitted.

I'm often surprised how much people share via Slack as if it's an impenetrable fortress: perfect for pasting admin passwords, keys, and incriminating opinions and business secrets... if that floodgate ever opens then it will be a crazy time for us devs!

Just as a heads up on this, slack doesn't even use HTTPS! Your employer can certainly read all private slacks on your work network, even if it's a non-work-slack workspace

This is absolutely not true, as a cursory examination of your browser's dev tools will reveal.

Re: Twitter warns that private tweets were public for years

#79
post #9

Just my own opinion, but at this point I think it's prudent to assume that pretty much anything you send out into the digital network world is public. If it's not something you would want the world knowing you said, don't put it out there. Security breaches happen. Bugs happen. Sometimes law enforcement just comes by and says, "Give me everything that user X has ever done." In short, sh!t happens. "Everything I do on…

Eric Schmidt: "If you have something that you don’t want anyone to know, maybe you shouldn’t be doing it in the first place." People have taken this different ways, but personally I think it's sage advice. We've lost our ability to keep secrets. Information wants to be free. We're terrible at digital security. Pretend everything you type into a computer is on the front page of the New York Times.

He's making a powerful argument against... trade secrets? Or are only corporations allowed to zealously guard their secrets, and natural persons just have to assume those corporations will leak their petty ones?

Re: Twitter warns that private tweets were public for years

#80

Earlier quoted context omitted.

Eric Schmidt: "If you have something that you don’t want anyone to know, maybe you shouldn’t be doing it in the first place." People have taken this different ways, but personally I think it's sage advice. We've lost our ability to keep secrets. Information wants to be free. We're terrible at digital security. Pretend everything you type into a computer is on the front page of the New York Times.

> Eric Schmidt: "If you have something that you don’t want anyone to know, maybe you shouldn’t be doing it in the first place." Would he extend this idea to clandestince agencies?

Or Google's trade secrets...
Post reply on HN