Test if your password has been chnaged by going to incognito mode, logging in again. If you cannot then someone has managed to take over your account. if you can login then a) you were careless with your password or b) twitter has a serious problem (which it is depends on how paranoid we think you are with passwords) but it would at least tell us something Anyway I hope this gets resolved satisfactorily soon :-)
Yes, someone else suggested the same thing: password not changed.
So now I'm really worried, because that means either this machine is compromised which has far larger implications than my Twitter account or there is something really bad going on at Twitter. Ericabiz suggested setting up Google authenticator, I think I can do that using my Yubikey and that will be the next step once the account is working normally again.
With some of the details that have come out, like this: https://news.ycombinator.com/item?id=31240589 maybe it would be a good idea to check your environment for carbon monoxide, or ask someone you trust in real life if you've been displaying erratic behavior. People arguing on a forum about Twitter might be overlooking a health issue you might be experiencing.
I'm confused - was OP's account compromised, or not? It sounds like it was, but he doesn't seem very fussed about how it happened or keeping it from happening again, just annoyed that Twitter's response to it isn't faster. Is it this commonplace for twitter accounts to be taken over? Also, is saying things like "Go die" an insta-ban on twitter? I don't use it but I thought it took more than that.
Also confused. Seems like the actual story here is that OP or Twitter was compromised, not that a Tweet was blocked. At least that's what I'm more curious about.
It may have also been "Web Intent" abuse? https://developer.twitter.com/en/docs/twitter-for-websites/t... Web Intent is a very open API and doesn't require a specific API relationship (you don't need to approve an "app" to do it). It is built to present a confirmation page specific to the given "Web Intent" interaction, but there have been reports over the years of adware/malware bypassing the confirmation page (or p…
Oh that is a very good one, I never ever even thought that something like that was possible, I thought that by just using a browser and a strong password that I was protected against that kind of trick. Thank you. Between the various comments in this thread bit by bit I'm beginning to wonder how safe this setup really is. Qubes OS starts to look better by the minute...
Yeah, I've gone down some paranoia rabbit holes into isolating my Facebook, Google, and Twitter logins into their own Containers with Firefox's Container tabs. It makes for a very interesting web browsing experience that is increasingly distant from the "mainstream" view of the web. (Even beyond the fact that Firefox usage in general is so rare according to current metrics of the Chromium hegemony.) It's amazing the dark patterns that websites get into when a Facebook, Google, or Twitter tracker doesn't work or doesn't return user details. Google specifically seems to punish me with a vast increase in the number of ReCAPTCHA attempts I'm forced to make (and you start to find out how many sites still use ReCAPTCHA as their primary prevention tool).
Twitter blocking an account for a message made by that account seems mundane and uninteresting. The related issue of someone-else allegedly posting on the author's Twitter-account would seem more interesting.
With some of the details that have come out, like this: https://news.ycombinator.com/item?id=31240589 maybe it would be a good idea to check your environment for carbon monoxide, or ask someone you trust in real life if you've been displaying erratic behavior. People arguing on a forum about Twitter might be overlooking a health issue you might be experiencing.
I think I would be aware of that.
You very well might not be. Carbon monoxide, stress, medication, sleepwalking, etc. If it's CO, at least try going outside and getting fresh air and see if things clear up. And at least ask someone for their opinion and get a CO detector. It's well worth a try for your own well-being.
I would not make any assumptions about implementation details to which I have no access.
It is common practice in the industry to never delete data. There are also legal reasons for this.
Having been part of 'the industry' for the last 40 years or so I'm fairly well informed about how things are done and that between 'common practice' and 'actual implementation details' there can be a very, very large difference.
Is it possible for the "appeal" process to be compromised with any arbitrary content so that was what triggered the email? Are you sure the email is really from Twitter and not some kind of phishing?
>* But I have an unbroken record of many years of being able to maintain my accounts without any compromises* If I was paid a quarter every time I heard a similar line during an emergency incidence response, I wouldn't need to be working incidence response anymore. No one gets hacked, until they do. Everyone claims they have the best password, the most secure machine, the most cautious of habits. Then they get hacked…
True. Which is why I would really love to know one way or another how this was done.