Live data from Hacker News

Ask HN: Twitter account stolen by presumed vulnerability

news.ycombinator.com

31–39 of 39 posts

Re: Ask HN: Twitter account stolen by presumed vulnerability

#31
post #30

Earlier quoted context omitted.

I was referring specifically to Twitter -- it's been a while since I checked, but doesn't Twitter require an email address for every account on signup? If you're offering a service that doesn't rely on email, I do see a gray area there for using SMS as a fallback; but most services I use don't fall into that category. I've even seen banks go down this direction -- banks that both require me to have an email to make a…

> I was referring specifically to Twitter -- it's been a while since I checked, but doesn't Twitter require an email address for every account on signup? I see, I misunderstood. it does not require an email address on signup, they’ve been pushing more and more aggressively to force new accounts to have numbers tied to them in fact[1]. https://mobile.twitter.com/i/flow/signup in a private browser tab in fact defaults…

Oof. That's disappointing to hear, but I appreciate the heads up.

My more cynical side agrees with you that the shift is probably mostly explained by data collection and user monitoring. I would like to give Twitter's security team the benefit of the doubt, or say that they're expanding into different markets and it's an accessibility thing, but... I dunno. I'm not sure I actually believe that.

Re: Ask HN: Twitter account stolen by presumed vulnerability

#32

Earlier quoted context omitted.

Yes I did. I will call my mobile provider to see if any changes were recently made. I originally didn't suspect a SIM swap attack as I received a text message from one of my contacts around the time the e-mail address was changed. I was out of town of course and did not have my data on. I saw the Twitter e-mail notification the following day. Checking with my mobile provider will be a safe bet for sure. Thank you for…

I thought about this a bit further. Wouldn't the join date of May 2019 on the account [0] signify that the user may not have actually reset my password/e-mail address but rather created a new account? Ether way, I am still going to contact my mobile provider to be sure. [0] - https://twitter.com/scott

Maybe the attacker simply changed your username after gaining access, paving way for them to register a new account in that name.

Re: Ask HN: Twitter account stolen by presumed vulnerability

#33
post #32

Earlier quoted context omitted.

I thought about this a bit further. Wouldn't the join date of May 2019 on the account [0] signify that the user may not have actually reset my password/e-mail address but rather created a new account? Ether way, I am still going to contact my mobile provider to be sure. [0] - https://twitter.com/scott

Maybe the attacker simply changed your username after gaining access, paving way for them to register a new account in that name.

That's a good thought but I don't think that's the case unfortunately. My e-mail address is not associated with any Twitter account at this time.

Twitter states they cannot find an account with my e-mail address if I try a password reset. As far as I can tell, my previous account has vanished as I mentioned in my OP.

Re: Ask HN: Twitter account stolen by presumed vulnerability

#34
I just wanted to provide an update regarding my mobile carrier. I gave them a call today and there were no recent changes on my account. I'm still thinking this was an exploit or vulnerability on Twitter's end. I will continue to try to reach out to Twitter employees.

Re: Ask HN: Twitter account stolen by presumed vulnerability

#37

It looks like you got your account back? How did that happen?

I'm still working to figure that part out honestly. As you can see, it looks like my account has only been partially restored at this time.

At this time, I still do not have login access to the account and I don't know who "john" is (the public name on the account). I have not been contacted directly by anyone at Twitter support.

If I receive more information I will post it here if I am able to.

Re: Ask HN: Twitter account stolen by presumed vulnerability

#38
post #32

Earlier quoted context omitted.

Maybe the attacker simply changed your username after gaining access, paving way for them to register a new account in that name.

That's a good thought but I don't think that's the case unfortunately. My e-mail address is not associated with any Twitter account at this time. Twitter states they cannot find an account with my e-mail address if I try a password reset. As far as I can tell, my previous account has vanished as I mentioned in my OP.

When they take over your account they do a forced delete and create a new account. That way they "own" the name and it is much harder to get back.

Re: Ask HN: Twitter account stolen by presumed vulnerability

#39
post #32

Earlier quoted context omitted.

Maybe the attacker simply changed your username after gaining access, paving way for them to register a new account in that name.

That's a good thought but I don't think that's the case unfortunately. My e-mail address is not associated with any Twitter account at this time. Twitter states they cannot find an account with my e-mail address if I try a password reset. As far as I can tell, my previous account has vanished as I mentioned in my OP.

After changing the username, couldn't they change the email address too?
Post reply on HN