Live data from Hacker News

An incident impacting 5M accounts and private information on Twitter

privacy.twitter.com

121–130 of 479 posts

Re: An incident impacting 5M accounts and private information on Twitter

#121
post #101

So after forcing users to enter a phone number to continue using twitter, despite twitter having no need to know the users phone number, they then leak the phone numbers and associated accounts. Great. But it gets worse... After being told of the leak in January, rather than disclosing the fact millions of users data had been open for anyone who looked, they quietly fixed it and hoped nobody else had found it. It was…

Requiring a phone number is part of fraud & spam prevention. Maybe you'd make a different tradeoff but that's not "no reason."

> The FTC says Twitter induced people to provide their phone numbers and email addresses by claiming that the company’s purpose was, for example, to “Safeguard your account.

> ...

> But according to the FTC, much more was going on behind the scenes. In fact, in addition to using people’s phone numbers and email addresses for the protective purposes the company claimed, Twitter also used the information to serve people targeted ads – ads that enriched Twitter by the multi-millions.

source: https://www.ftc.gov/business-guidance/blog/2022/05/twitter-p...

So you're right, it wasn't for "no reason", but it also wasn't just for fraud and spam prevention, security, or any of the other lies Twitter told users.

Re: An incident impacting 5M accounts and private information on Twitter

#122

So after forcing users to enter a phone number to continue using twitter, despite twitter having no need to know the users phone number, they then leak the phone numbers and associated accounts. Great. But it gets worse... After being told of the leak in January, rather than disclosing the fact millions of users data had been open for anyone who looked, they quietly fixed it and hoped nobody else had found it. It was…

I know the answer is money in politics, SV culture, etc. But it's near certainty twitter will continue as they do in and 2 weeks everyone will move on.

Maybe they get a small boo-boo in the form of a symbolic fine, mangers scramble for a bit, and then the whole thing happens again and again.

Why is this?

Re: An incident impacting 5M accounts and private information on Twitter

#123
post #2

> When we learned about this, we immediately investigated and fixed it. At that time, we had no evidence to suggest someone had taken advantage of the vulnerability. > In July 2022, we learned through a press report that someone had potentially leveraged this and was offering to sell the information they had compiled. After reviewing a sample of the available data for sale, we confirmed that a bad actor had taken adv…

You seem to believe "we had no evidence to suggest someone had taken advantage of the vulnerability" implies "we looked for any evidence of it", it doesn't, not in that case nor in any similar situation.

Re: An incident impacting 5M accounts and private information on Twitter

#124

Earlier quoted context omitted.

That has some problems. If you limit the total number of attempts globally then the feature is effectively disabled, every botnet and script will blow through the attempt budget and real users can't use it. Global limits and IP address limits are not useful, and because we're assuming the user is unauthenticated (using the password reset), we have no other way of distinguishing good traffic.

Captcha comes to mind, but that's a cat-and-mouse game in the age of machine learning (not to mention actual humans working for a bad actor). Cloudflare seems to be on the cutting edge with their newest challenge mechanism, but good vs bad is somewhat distinct from human vs script.

My wife was in charge of security at MySpace back when MySpace was still a thing and there was one occasion that the MySpace team was manually feeding images to a suspected human acting as a bot. As I recall it became clear to both sides that there were humans on the other end and it ended with a picture of a scantily-clad woman and a response of “very funny.”

Re: An incident impacting 5M accounts and private information on Twitter

#125

Earlier quoted context omitted.

In the USA. They range from 4 (St. Helena) to 13 (Austria), I believe.

It's typically smaller though, not every phone number is allocated and many are in sequential groups. Some are special cased, you don't need to search any number matching `****555***` in north america for example, which cuts down on the search space quite a bit.

"Quite a bit"? Filtering out ***555**** removes only 0.1% of phone numbers ;)

Re: An incident impacting 5M accounts and private information on Twitter

#126

So what you’re saying is that you discovered a vulnerability that leaked the private information of your users, said absolutely nothing for 6 months, then finally came clean, but only because you were forced to because people were selling data on the deep web. Please take your “sorry” and shove it where the sun doesn’t shine. You don’t “take our privacy seriously”. This is utterly ridiculous and unacceptable, and in…

>didn’t bother to do an investigation into whether it leaked data (which clearly is possible, because you’ve done it now)

It sounds like they confirmed the exploit by looking at the hacked data, not by a renewed search of previously available logs.

Re: An incident impacting 5M accounts and private information on Twitter

#127

Earlier quoted context omitted.

That has some problems. If you limit the total number of attempts globally then the feature is effectively disabled, every botnet and script will blow through the attempt budget and real users can't use it. Global limits and IP address limits are not useful, and because we're assuming the user is unauthenticated (using the password reset), we have no other way of distinguishing good traffic.

Captcha comes to mind, but that's a cat-and-mouse game in the age of machine learning (not to mention actual humans working for a bad actor). Cloudflare seems to be on the cutting edge with their newest challenge mechanism, but good vs bad is somewhat distinct from human vs script.

[deleted]

Re: An incident impacting 5M accounts and private information on Twitter

#128

So what you’re saying is that you discovered a vulnerability that leaked the private information of your users, said absolutely nothing for 6 months, then finally came clean, but only because you were forced to because people were selling data on the deep web. Please take your “sorry” and shove it where the sun doesn’t shine. You don’t “take our privacy seriously”. This is utterly ridiculous and unacceptable, and in…

>didn’t bother to do an investigation into whether it leaked data (which clearly is possible, because you’ve done it now) It sounds like they confirmed the exploit by looking at the hacked data, not by a renewed search of previously available logs.

Yeah, I misread that part. Edited my comment.

Re: An incident impacting 5M accounts and private information on Twitter

#129

I believe this is the vulnerability reported to Twitter which awarded $5000 from its bug bounty program. https://hackerone.com/reports/1439026

$5k seems embarrassingly low so something with such horrendous impact. Potentially allowing for doxing, and because phone numbers are the lynchpin for many 2FA and consumer-facing telco security is generally lax, total user hijacking across multiple platforms. What an absolute disaster.
Post reply on HN