Live data from Hacker News

An incident impacting 5M accounts and private information on Twitter

privacy.twitter.com

211–220 of 479 posts

Re: An incident impacting 5M accounts and private information on Twitter

#211

Earlier quoted context omitted.

I’m six months in and they haven’t asked for a phone number yet. I dread the day when they do. This is where proficiency in the Twilio API comes in handy.

Don't you still have to use an actual phone number when you sign up for Twilio?

If you trust twilio security policy you can defer the weakness of Twitter policy in favor of the strength of twilio.

Re: An incident impacting 5M accounts and private information on Twitter

#212

Earlier quoted context omitted.

You can remove your phone number after creating the account.

And right after you do your account will be locked

I have an account with no email address and no phone number so not sure what you mean.

Re: An incident impacting 5M accounts and private information on Twitter

#213

"we recommend not adding a publicly known phone number or email address to your Twitter account." This is literally impossible. You can't create a Twitter account without a phone number. It sometimes allows you to do so, but then is blocked within 24 hours until you add one. It's insulting that Twitter should lie about that.

> publicly known

Note the PR words they used. Which amounts to, "If you want privacy, it's not our problem. Go create a virtual number somewhere."

Re: An incident impacting 5M accounts and private information on Twitter

#215

Another reminder not to use Twitter. It's not worth it. Mastodon is better.

Could not have picked a worse name for a social network.

who cares, this is the ultimate in bike shedding.

there's never a discussion on HN where someone brings up a product without this asinine comment about its name.

btw Mastodon is great software and it has a great name and branding. It's all subjective.

Re: An incident impacting 5M accounts and private information on Twitter

#216

Earlier quoted context omitted.

It doesn't have to be a psychological trick. Sometimes you don't actually have evidence it was exploited - at which point what are you meant to say?

It would be more honest to say "We aren't able to determine whether it was exploited" which could better brace potentially impacted users for the possibility they might be affected. This is a relatively benign case but the same language is used in other breaches when people should be taking measures like freezing their credit or reviewing financial transactions.

How can anyone make any assertions about unknown unknowns?

It's one thing to say "My car was stolen", and another to declare "I am unable to determine if it's en route to the Taliban."

Re: An incident impacting 5M accounts and private information on Twitter

#217

Earlier quoted context omitted.

"We have no evidence that this was exploited" is a standard psychological trick they pull in vulnerability announcements to give an unfounded impression that it hasn't been exploited.

It doesn't have to be a psychological trick. Sometimes you don't actually have evidence it was exploited - at which point what are you meant to say?

The burden of proof should fall on them to demonstrate that it wasn't exploited.

Otherwise, the reasonable thing to do is to assume that it was exploited, because they have no evidence to show that it wasn't.

The phrase is a psychological trick because it creates the illusion that the burden of proof falls on the other side.

Re: An incident impacting 5M accounts and private information on Twitter

#218

Earlier quoted context omitted.

It doesn't have to be a psychological trick. Sometimes you don't actually have evidence it was exploited - at which point what are you meant to say?

The burden of proof should fall on them to demonstrate that it wasn't exploited. Otherwise, the reasonable thing to do is to assume that it was exploited, because they have no evidence to show that it wasn't. The phrase is a psychological trick because it creates the illusion that the burden of proof falls on the other side.

You can't prove a negative.

Re: An incident impacting 5M accounts and private information on Twitter

#219
post #2

> When we learned about this, we immediately investigated and fixed it. At that time, we had no evidence to suggest someone had taken advantage of the vulnerability. > In July 2022, we learned through a press report that someone had potentially leveraged this and was offering to sell the information they had compiled. After reviewing a sample of the available data for sale, we confirmed that a bad actor had taken adv…

Or they don't monitor that system for that type of access at all and so literally don't know.

Re: An incident impacting 5M accounts and private information on Twitter

#220
post #2

> When we learned about this, we immediately investigated and fixed it. At that time, we had no evidence to suggest someone had taken advantage of the vulnerability. > In July 2022, we learned through a press report that someone had potentially leveraged this and was offering to sell the information they had compiled. After reviewing a sample of the available data for sale, we confirmed that a bad actor had taken adv…

"We have no evidence that this was exploited" is a standard psychological trick they pull in vulnerability announcements to give an unfounded impression that it hasn't been exploited.

Suppose Twitter did all it could to investigate and found no evidence. What would you rather have Twitter say in that case ?
Post reply on HN