Earlier quoted context omitted.
Probably the latter - all companies operating in the EU have had short (ie. 30 days) retention policies on anything user-identifiable (ie. http logs) for a while now. But if they didn't keep sufficient logs, they should have alerted the users back then, not now.
AFAIK there is an exception for security purposes. They could be hashing or "anonymizing" the IPs and keep the data longer.
An incident impacting 5M accounts and private information on Twitter
131–140 of 479 posts
Re: An incident impacting 5M accounts and private information on Twitter
#132Earlier quoted context omitted.
Agreed but, in what jurisdiction does Twitter require phone numbers?
A year or so ago, I created an account and followed ten or so people (no tweets at that time). When I went to log in the next day, it wouldn't let me log in until I attached a phone number. As I understand it, that was a relatively common occurrence.
Pretending they're not requiring something when in practice, a giant proportion of their userbase faces it.
Pretending anything changes when you click 'See This Less Often' on some annoying feature.
Constantly undoing a user's preference for 'Latest' over algorithmic 'Home'.
Claiming they don't "soft-ban" but absolutely, verifiably, hiding some users' content from others who have explicitly followed them.
Implying there's some effective "appeal" process for arbitrary & often clearly erroneous moderations decisions – when instead it's just designed for coercing compliance, including the simualted "voluntary" deletion of tweets, under penalty of losing your account indefinitely.
Slurring & hiding replies with no hint of offense as "potentially offensive".
Describing tweets as "unavailable" when (often) all you have to do is click to see it - wasting users time.
Offering "Show additional replies" even when there's nothing more to show – again wasting users' time.
Re: An incident impacting 5M accounts and private information on Twitter
#133> When we learned about this, we immediately investigated and fixed it. At that time, we had no evidence to suggest someone had taken advantage of the vulnerability. > In July 2022, we learned through a press report that someone had potentially leveraged this and was offering to sell the information they had compiled. After reviewing a sample of the available data for sale, we confirmed that a bad actor had taken adv…
"We have no evidence that this was exploited" is a standard psychological trick they pull in vulnerability announcements to give an unfounded impression that it hasn't been exploited.
Re: An incident impacting 5M accounts and private information on Twitter
#134Can we have a proper postmortem about this please, with information about the exact process that was required to obtain this information? > We take our responsibility to protect your privacy very seriously and it is unfortunate that this happened. Patently not seriously enough.
It's always hilarious: Whenever any company is caught not taking X seriously, the first thing they do is issue a press release that starts with "Here at COMPANY, we take X very seriously!"
He settled that issue with an under-the-table payout, but the first thing he did after that was to send out a stern memo to all staff warning them that "we will tolerate ABSOLUTELY NO sexual harassment at this company!"
Re: An incident impacting 5M accounts and private information on Twitter
#135Re: An incident impacting 5M accounts and private information on Twitter
#136What unit is mm? Millimetres?
Re: An incident impacting 5M accounts and private information on Twitter
#137What unit is mm? Millimetres?
Re: An incident impacting 5M accounts and private information on Twitter
#138> When we learned about this, we immediately investigated and fixed it. At that time, we had no evidence to suggest someone had taken advantage of the vulnerability. > In July 2022, we learned through a press report that someone had potentially leveraged this and was offering to sell the information they had compiled. After reviewing a sample of the available data for sale, we confirmed that a bad actor had taken adv…
"We have no evidence that this was exploited" is a standard psychological trick they pull in vulnerability announcements to give an unfounded impression that it hasn't been exploited.
"I have no evidence he murdered someone"
As opposed to
"He might have murdered someone, or not, I just don't have any evidence"
"It's possible he murdered someone I don't have any evidence though"
"I don't have any evidence he murdered someone but that doesn't mean he didn't, I'm just asking questions"
Re: An incident impacting 5M accounts and private information on Twitter
#139I never wanted to give you my phone number, Twitter. You demanded it.
Re: An incident impacting 5M accounts and private information on Twitter
#140Remember that phone numbers are only 10 digits long, so brute forcing all phone numbers is totally doable. Considering that, if you implement any flow that involves checking if a phone number is already in use, then you are effectively leaking to an attacker a list of every phone number that uses your product.