Live data from Hacker News

An incident impacting 5M accounts and private information on Twitter

privacy.twitter.com

81–90 of 479 posts

Re: An incident impacting 5M accounts and private information on Twitter

#81

Earlier quoted context omitted.

No mention of that fact that 'use another phone number' is quite an expensive thing to do in countries where a phone number has an annual fee of hundreds of dollars. Suddenly 'use twitter securely' has gone from 'free' to 'hundreds of dollars a year'. Perhaps they should announce this as a price change instead?

If you know the right providers it's about $2/month for a non-VOIP, physical SIM to receive SMS for this sort of garbage.

These phone number blocks have usually been utilized by spammers in the past. A lot of them don't work.

Re: An incident impacting 5M accounts and private information on Twitter

#82

Earlier quoted context omitted.

I guess I was thinking more like "limiting the number of attempts" than "limiting the number of attempts over time" -- take time out of the equation (but then NAT causes trouble). But even so, you're right: as the threat landscape approaches the size of the result set, it breaks down no matter what.

That has some problems. If you limit the total number of attempts globally then the feature is effectively disabled, every botnet and script will blow through the attempt budget and real users can't use it. Global limits and IP address limits are not useful, and because we're assuming the user is unauthenticated (using the password reset), we have no other way of distinguishing good traffic.

Captcha comes to mind, but that's a cat-and-mouse game in the age of machine learning (not to mention actual humans working for a bad actor). Cloudflare seems to be on the cutting edge with their newest challenge mechanism, but good vs bad is somewhat distinct from human vs script.

Re: An incident impacting 5M accounts and private information on Twitter

#83

>If you operate a pseudonymous Twitter account, we understand the risks an incident like this can introduce and deeply regret that this happened. To keep your identity as veiled as possible, we recommend not adding a publicly known phone number or email address to your Twitter account. I'm so sick of this kind of victim blaming, you're forced to add a phone number to use twitter.

I have yet to add my phone number to my account. My guess is that it isn't applicable for legacy accounts circa 2008.

Re: An incident impacting 5M accounts and private information on Twitter

#85

>If you operate a pseudonymous Twitter account, we understand the risks an incident like this can introduce and deeply regret that this happened. To keep your identity as veiled as possible, we recommend not adding a publicly known phone number or email address to your Twitter account. I'm so sick of this kind of victim blaming, you're forced to add a phone number to use twitter.

You can remove your phone number after creating the account.

I really doubt it's a hard delete.

Re: An incident impacting 5M accounts and private information on Twitter

#86

Can we have a proper postmortem about this please, with information about the exact process that was required to obtain this information? > We take our responsibility to protect your privacy very seriously and it is unfortunate that this happened. Patently not seriously enough.

It's always hilarious: Whenever any company is caught not taking X seriously, the first thing they do is issue a press release that starts with "Here at COMPANY, we take X very seriously!"

Re: An incident impacting 5M accounts and private information on Twitter

#88

Earlier quoted context omitted.

>countries where a phone number has an annual fee of hundreds of dollars. Is this a thing? I've never heard of it. Where?

It's true in the USA if you stick to the big providers... Ring up t-mobile and say 'I'd like a line with 0 minutes and 0 GB of data, just to receive verification texts for Twitter' and they'll probably quote you $200 a year or so...

Why the arbitrary limitation to the “big providers” - you can get a basic Tello plan with SIM for $5/month prepaid - and they’re a T-mobile MVNO so it’s a T-Mobile number.

Re: An incident impacting 5M accounts and private information on Twitter

#89
I said this before years ago about Signal, Robinhood and Coinbase [0] and right now it's 2022 and SMS 2FA is still being used despite SS7 attacks, SIM swapping, one-click zero-day SMS attacks as found in Pegasus and sophisticated SMS phishing attacks. [1]

Really. One needs to think about logging into any service that requires ONLY Phone number 2FA and this should be a wake up call.

Twitter really should get a massive multi-million dollar fine for this breach.

[0] https://news.ycombinator.com/item?id=29264937

[1] https://news.ycombinator.com/item?id=32385362

Re: An incident impacting 5M accounts and private information on Twitter

#90
post #40

Earlier quoted context omitted.

You need a plan to have a number because it's difficult/impossible to get a number allocated to you as an individual. If we assume "hundreds" means >=$200/year, then the maximum monthly payment we can have for that not to be true is $16/mo. The absolute cheapest phone plans I could find in the US that weren't for alarm systems were $15/mo on mvnos like mint. In practice, I suspect few people are paying less than $25-…

There are no prepaids? Which country do you have in mind?

At some point it just gets ludicrous, though.

Is it reasonable for everybody to go buy "burner" phones to sign up for Twitter?

The truth is, it's stupid for Twitter to require a phone number, and it's especially stupid that they blame the user for using their real number.

Post reply on HN