Live data from Hacker News

An incident impacting 5M accounts and private information on Twitter

privacy.twitter.com

131–140 of 479 posts

Re: An incident impacting 5M accounts and private information on Twitter

#131
post #45

Earlier quoted context omitted.

Probably the latter - all companies operating in the EU have had short (ie. 30 days) retention policies on anything user-identifiable (ie. http logs) for a while now. But if they didn't keep sufficient logs, they should have alerted the users back then, not now.

AFAIK there is an exception for security purposes. They could be hashing or "anonymizing" the IPs and keep the data longer.

No that's not valid at all! You must remove any trace of your ability to backwards engineering the IPs. Hashing isn't sufficient since it's so easy to run over the whole IPv4 space. This is one of the trade offs.

Re: An incident impacting 5M accounts and private information on Twitter

#132
post #50
post #21

Earlier quoted context omitted.

Agreed but, in what jurisdiction does Twitter require phone numbers?

A year or so ago, I created an account and followed ten or so people (no tweets at that time). When I went to log in the next day, it wouldn't let me log in until I attached a phone number. As I understand it, that was a relatively common occurrence.

And, this is just one of many examples of a deep, deep dishonesty at the core of Twitter Inc's operations:

Pretending they're not requiring something when in practice, a giant proportion of their userbase faces it.

Pretending anything changes when you click 'See This Less Often' on some annoying feature.

Constantly undoing a user's preference for 'Latest' over algorithmic 'Home'.

Claiming they don't "soft-ban" but absolutely, verifiably, hiding some users' content from others who have explicitly followed them.

Implying there's some effective "appeal" process for arbitrary & often clearly erroneous moderations decisions – when instead it's just designed for coercing compliance, including the simualted "voluntary" deletion of tweets, under penalty of losing your account indefinitely.

Slurring & hiding replies with no hint of offense as "potentially offensive".

Describing tweets as "unavailable" when (often) all you have to do is click to see it - wasting users time.

Offering "Show additional replies" even when there's nothing more to show – again wasting users' time.

Re: An incident impacting 5M accounts and private information on Twitter

#133
post #2

> When we learned about this, we immediately investigated and fixed it. At that time, we had no evidence to suggest someone had taken advantage of the vulnerability. > In July 2022, we learned through a press report that someone had potentially leveraged this and was offering to sell the information they had compiled. After reviewing a sample of the available data for sale, we confirmed that a bad actor had taken adv…

"We have no evidence that this was exploited" is a standard psychological trick they pull in vulnerability announcements to give an unfounded impression that it hasn't been exploited.

It doesn't have to be a psychological trick. Sometimes you don't actually have evidence it was exploited - at which point what are you meant to say?

Re: An incident impacting 5M accounts and private information on Twitter

#134

Can we have a proper postmortem about this please, with information about the exact process that was required to obtain this information? > We take our responsibility to protect your privacy very seriously and it is unfortunate that this happened. Patently not seriously enough.

It's always hilarious: Whenever any company is caught not taking X seriously, the first thing they do is issue a press release that starts with "Here at COMPANY, we take X very seriously!"

A story an old coworker of mine often told was about the CEO at a previous company he had worked for. This guy was apparently pretty scummy in general, but one time he got threatened with a lawsuit for sexually propositioning his secretary.

He settled that issue with an under-the-table payout, but the first thing he did after that was to send out a stern memo to all staff warning them that "we will tolerate ABSOLUTELY NO sexual harassment at this company!"

Re: An incident impacting 5M accounts and private information on Twitter

#138
post #2

> When we learned about this, we immediately investigated and fixed it. At that time, we had no evidence to suggest someone had taken advantage of the vulnerability. > In July 2022, we learned through a press report that someone had potentially leveraged this and was offering to sell the information they had compiled. After reviewing a sample of the available data for sale, we confirmed that a bad actor had taken adv…

"We have no evidence that this was exploited" is a standard psychological trick they pull in vulnerability announcements to give an unfounded impression that it hasn't been exploited.

No, that's a normal statement when there's no evidence something occurred.

"I have no evidence he murdered someone"

As opposed to

"He might have murdered someone, or not, I just don't have any evidence"

"It's possible he murdered someone I don't have any evidence though"

"I don't have any evidence he murdered someone but that doesn't mean he didn't, I'm just asking questions"

Re: An incident impacting 5M accounts and private information on Twitter

#139
Pretty disgusting they don't have a thing to check if they leaked my personal information, which lets not forget they screamed and stamped their feet to force me to hand over in the first place.

I never wanted to give you my phone number, Twitter. You demanded it.

Re: An incident impacting 5M accounts and private information on Twitter

#140

Remember that phone numbers are only 10 digits long, so brute forcing all phone numbers is totally doable. Considering that, if you implement any flow that involves checking if a phone number is already in use, then you are effectively leaking to an attacker a list of every phone number that uses your product.

CPU throughput =/= endpoint throughput
Post reply on HN