Live data from Hacker News

An incident impacting 5M accounts and private information on Twitter

privacy.twitter.com

191–200 of 479 posts

Re: An incident impacting 5M accounts and private information on Twitter

#191
post #101

Earlier quoted context omitted.

Requiring a phone number is part of fraud & spam prevention. Maybe you'd make a different tradeoff but that's not "no reason."

it adds a small cost to creating sockpoppets but it adds much larger value in having personal data for targeted ads like my sibling said, twitter was dishonest to their users how the phone number was to be used if it's just to prevent bot signups, why keep it on file at all?

They no longer use it for ads, so the value now is just fraud and security.

> if it's just to prevent bot signups, why keep it on file at all?

I mean, you need the actual number for 2FA. I guess maybe you could hash it after some amount of time just for blocking bots? You couldn't just discard it or one number could create unlimited bots.

Re: An incident impacting 5M accounts and private information on Twitter

#192
It's one of the many reasons why I don't like to associate my phone number with an account for 2FA and such... Or any other information that they don't need (like name, etc...).

I think that Google recently forced most accounts to give a phone number even if you don't use 2FA (probably for ID purposes). That's one reason why I like this service: https://www.emailnator.com/, instead of using my own gmail address for signups.

Anonimity is going down the toilet really fast in the US...

Re: An incident impacting 5M accounts and private information on Twitter

#193

Earlier quoted context omitted.

It doesn't have to be a psychological trick. Sometimes you don't actually have evidence it was exploited - at which point what are you meant to say?

The phrasing is a bit more specific.. "At that time, we had no evidence.." It could also mean "oh I spent five minutes looking into it and didn't see any evidence"

thats a lawyered up comment

Re: An incident impacting 5M accounts and private information on Twitter

#194
This is why Managers and PMs should not be deciding priority of security betterments. I've never worked at, or heard of, a company that adequately incentivizes or takes posthoc corrective actions for EMs/PMs around long term consequences or brand threats. They're tragedies of the commons of sorts.

Re: An incident impacting 5M accounts and private information on Twitter

#195

Earlier quoted context omitted.

"We have no evidence that this was exploited" is a standard psychological trick they pull in vulnerability announcements to give an unfounded impression that it hasn't been exploited.

No, that's a normal statement when there's no evidence something occurred. "I have no evidence he murdered someone" As opposed to "He might have murdered someone, or not, I just don't have any evidence" "It's possible he murdered someone I don't have any evidence though" "I don't have any evidence he murdered someone but that doesn't mean he didn't, I'm just asking questions"

That is not a normal statement if it is your company's fault the question even came up.

"We left a giant tub filled with cyanide completely unsupervised in front of our door for months. We have no evidence that it was used to murder someone."

Has an entirely different sound to it, no?

Re: An incident impacting 5M accounts and private information on Twitter

#196

So after forcing users to enter a phone number to continue using twitter, despite twitter having no need to know the users phone number, they then leak the phone numbers and associated accounts. Great. But it gets worse... After being told of the leak in January, rather than disclosing the fact millions of users data had been open for anyone who looked, they quietly fixed it and hoped nobody else had found it. It was…

I know the answer is money in politics, SV culture, etc. But it's near certainty twitter will continue as they do in and 2 weeks everyone will move on. Maybe they get a small boo-boo in the form of a symbolic fine, mangers scramble for a bit, and then the whole thing happens again and again. Why is this?

Twitter is vulnerable, most vulnerable of the big social media sites it seems. The Musk deal has fallen through, and it seems like Musk was not the only one to lose confidence in Twitter. It could easily go the way of Myspace. How many users does Myspace have these days? Active users

Re: An incident impacting 5M accounts and private information on Twitter

#197

> How to Protect Your Account > (...) To keep your identity as veiled as possible, we recommend not adding a publicly known phone number or email address to your Twitter account. Well, you're the ones constantly temporarily banning my account for not providing a phone number...

> How to Protect Your Account

> Don't sign up.

FTFY

Re: An incident impacting 5M accounts and private information on Twitter

#198
post #164

Earlier quoted context omitted.

It's interesting to wonder why only 5M accounts were affected by this exploit, especially if it's brute forceable. IIRC this vulnerability was widely known about for at least months before it was fixed, so I can't imagine nobody in the know had access to the resources/botnets necessary to enumerate through every account. Have only 5M accounts linked their phone numbers on Twitter? That's less than 2% of their total a…

Maybe Musk is right, they are all bots.

Maybe Musk is behind this to weasel out of the contract?

Re: An incident impacting 5M accounts and private information on Twitter

#199
post #70

>If you operate a pseudonymous Twitter account, we understand the risks an incident like this can introduce and deeply regret that this happened. To keep your identity as veiled as possible, we recommend not adding a publicly known phone number or email address to your Twitter account. I'm so sick of this kind of victim blaming, you're forced to add a phone number to use twitter.

I mean, originally twitter was an SMS based service. It was made for phones.

Yep, Twitter got my phone number because at the time 40404 was the only mobile interface, and half the point of the service.

Re: An incident impacting 5M accounts and private information on Twitter

#200

> How to Protect Your Account > (...) To keep your identity as veiled as possible, we recommend not adding a publicly known phone number or email address to your Twitter account. Well, you're the ones constantly temporarily banning my account for not providing a phone number...

They said don't add a publicly known phone number to your account, so you have to create a Google Voice account that you'll never use except for account credentials like this. But Twitter will probably ban you for not using a real phone number. Or, you'll reuse that phone number across other accounts until one of them gets hacked and that phone number sold on the dark net, and now it's a public phone number again.

Last time I tried (last year), Twitter did not accept VoIP numbers. I tried Google Voice and Sudo (which are provisioned by Twilio).
Post reply on HN