Live data from Hacker News

An incident impacting 5M accounts and private information on Twitter

privacy.twitter.com

221–230 of 479 posts

Re: An incident impacting 5M accounts and private information on Twitter

#221

Earlier quoted context omitted.

"We have no evidence that this was exploited" is a standard psychological trick they pull in vulnerability announcements to give an unfounded impression that it hasn't been exploited.

Suppose Twitter did all it could to investigate and found no evidence. What would you rather have Twitter say in that case ?

"We are unable to determine if the vulnerability was exploited."

How hard they looked is not of any consequence if they can't tell it wasn't exploited.

Re: An incident impacting 5M accounts and private information on Twitter

#222
post #45

Earlier quoted context omitted.

Probably the latter - all companies operating in the EU have had short (ie. 30 days) retention policies on anything user-identifiable (ie. http logs) for a while now. But if they didn't keep sufficient logs, they should have alerted the users back then, not now.

AFAIK there is an exception for security purposes. They could be hashing or "anonymizing" the IPs and keep the data longer.

[deleted]

Re: An incident impacting 5M accounts and private information on Twitter

#223
post #29

Earlier quoted context omitted.

But you can abandon a number after you registered on Twitter. Doesn't help against agencies but against scrappers

My very recent experience contradicts this. I removed my number and was immediately locked out until I added it back.

They mean you can get a different phone number, not remove it from twitter.

Re: An incident impacting 5M accounts and private information on Twitter

#224

Remember that phone numbers are only 10 digits long, so brute forcing all phone numbers is totally doable. Considering that, if you implement any flow that involves checking if a phone number is already in use, then you are effectively leaking to an attacker a list of every phone number that uses your product.

It's interesting to wonder why only 5M accounts were affected by this exploit, especially if it's brute forceable. IIRC this vulnerability was widely known about for at least months before it was fixed, so I can't imagine nobody in the know had access to the resources/botnets necessary to enumerate through every account. Have only 5M accounts linked their phone numbers on Twitter? That's less than 2% of their total a…

5,000,000 seconds is about two months. The attackers simply might not have had enough time to check more numbers than that.

(Assumption: They were checking only one number per second, either to avoid detection or because they were rate-limited.)

Re: An incident impacting 5M accounts and private information on Twitter

#225
post #213

"we recommend not adding a publicly known phone number or email address to your Twitter account." This is literally impossible. You can't create a Twitter account without a phone number. It sometimes allows you to do so, but then is blocked within 24 hours until you add one. It's insulting that Twitter should lie about that.

> publicly known Note the PR words they used. Which amounts to, "If you want privacy, it's not our problem. Go create a virtual number somewhere."

IME, numbers they have classified has VOIP or otherwise not a consumer or business cell service are disallowed. Skype numbers do not work, and I have had a spotty experience with Google Voice numbers as well.

Re: An incident impacting 5M accounts and private information on Twitter

#226
post #2

> When we learned about this, we immediately investigated and fixed it. At that time, we had no evidence to suggest someone had taken advantage of the vulnerability. > In July 2022, we learned through a press report that someone had potentially leveraged this and was offering to sell the information they had compiled. After reviewing a sample of the available data for sale, we confirmed that a bad actor had taken adv…

Probably the latter - all companies operating in the EU have had short (ie. 30 days) retention policies on anything user-identifiable (ie. http logs) for a while now. But if they didn't keep sufficient logs, they should have alerted the users back then, not now.

AFAIK there are exceptions for many purposes, taxes, law enforcement, "critical business functions", etc of the 30 day window. Tax records, which can be quite PII and personal, need to be kept for ~7 years in the US for instance. Anything that needs to go to law enforcement stays around until the court case is over which can be longer.

Re: An incident impacting 5M accounts and private information on Twitter

#228
post #191

Earlier quoted context omitted.

it adds a small cost to creating sockpoppets but it adds much larger value in having personal data for targeted ads like my sibling said, twitter was dishonest to their users how the phone number was to be used if it's just to prevent bot signups, why keep it on file at all?

They no longer use it for ads, so the value now is just fraud and security. > if it's just to prevent bot signups, why keep it on file at all? I mean, you need the actual number for 2FA. I guess maybe you could hash it after some amount of time just for blocking bots? You couldn't just discard it or one number could create unlimited bots.

They might use it in ranking posts presented to you. Or deciding where yours rank.

There’s more to sorting than just ads, security and fraud.

Re: An incident impacting 5M accounts and private information on Twitter

#229
post #2

> When we learned about this, we immediately investigated and fixed it. At that time, we had no evidence to suggest someone had taken advantage of the vulnerability. > In July 2022, we learned through a press report that someone had potentially leveraged this and was offering to sell the information they had compiled. After reviewing a sample of the available data for sale, we confirmed that a bad actor had taken adv…

https://astralcodexten.substack.com/p/the-phrase-no-evidence...

Re: An incident impacting 5M accounts and private information on Twitter

#230

Earlier quoted context omitted.

"We have no evidence that this was exploited" is a standard psychological trick they pull in vulnerability announcements to give an unfounded impression that it hasn't been exploited.

Suppose Twitter did all it could to investigate and found no evidence. What would you rather have Twitter say in that case ?

Saying there is an absence of evidence (of a leak) isn't useful by itself unless they also indicate whether that is evidence of absence (of a leak). I.e., they should indicate whether it is likely that they would have caught it if a leak had occured (e.g., via extensive logging).
Post reply on HN