Live data from Hacker News

An incident impacting 5M accounts and private information on Twitter

privacy.twitter.com

271–280 of 479 posts

Re: An incident impacting 5M accounts and private information on Twitter

#271

Interesting how just throwing the 5M figure in the title changed everything for this post: https://u.ale.sh/some-accounts.png

Well yeah. Some accounts could be two. If I see language like that in a headline, I pretty much ignore it. It's like when I see the word "may" in a headline. "New wonder drug may cure cancer." That isn't even news.

Re: An incident impacting 5M accounts and private information on Twitter

#272
post #264
post #187

Earlier quoted context omitted.

Discord is also like this and it drives me nuts.

They also refuse voip numbers. I am now at 20 back and forth emails with Discord support explaining I do not own a cell phone. They are seriously suggesting I buy one just to use Discord.

I've seriously considered buying burner phones like a goddamn drug dealer for bullshit like this.

Re: An incident impacting 5M accounts and private information on Twitter

#273

Earlier quoted context omitted.

"We have no evidence that this was exploited" is a standard psychological trick they pull in vulnerability announcements to give an unfounded impression that it hasn't been exploited.

I wonder, if you destroy all the evidence this was exploited, can you still claim you don't have any evidence this was exploited? Asking for opinions from non-lawyers only please

To be sure, use a clean room implementation: let IT destroy all the evidence, always. Then legal can claim 'we don't have any evidence'.

source: I am not a lawyer

Re: An incident impacting 5M accounts and private information on Twitter

#274

Earlier quoted context omitted.

Could not have picked a worse name for a social network.

Are you talking about Twitter or Mastodon? Many company and product names are awkward before they become mainstream.

Twitter is light hearted. Mastodon sounds like obscure metal band

Re: An incident impacting 5M accounts and private information on Twitter

#275

I think you will see more of this class of attack. Lots of companies have various 'forgot my username'/'forgot my password'/'trying to sign up for a new account with a new email address but existing phone number'/'add a friend by email or phone' flows. It's very easy to accidentally leak some info that shouldn't be leaked while implementing such a flow, since you are peering into the users database querying by email/…

[deleted]

Re: An incident impacting 5M accounts and private information on Twitter

#276
post #259

Earlier quoted context omitted.

I always wonder who "we" refers to in that usage, legally speaking. Does it refer only to a subset of employees / board members who are authorized to speak for the company? Because then even if someone analyzing logs sees something damning, if middle management is trained to stop that knowledge from reaching the top, then those speaking for the company can continue saying "we" didn't know it.

I have 100% seen this happen.

really? what do you mean 'middle management is trained to keep that from getting to the top'? intentional malfeasance?

where I work people are trying their best but dealing with complex systems, memories, and methods of communication. because of this, security issues are sometimes missed, sometimes poorly communicated, and sometimes poorly remediated.

Re: An incident impacting 5M accounts and private information on Twitter

#277

Earlier quoted context omitted.

It would be more honest to say "We aren't able to determine whether it was exploited" which could better brace potentially impacted users for the possibility they might be affected. This is a relatively benign case but the same language is used in other breaches when people should be taking measures like freezing their credit or reviewing financial transactions.

How can anyone make any assertions about unknown unknowns? It's one thing to say "My car was stolen", and another to declare "I am unable to determine if it's en route to the Taliban."

Its not an unknown unknown. If there's a vulnerability and you're a hot target, you know there's a decent chance of getting exploited.

Re: An incident impacting 5M accounts and private information on Twitter

#278

Earlier quoted context omitted.

"We have no evidence that this was exploited" is a standard psychological trick they pull in vulnerability announcements to give an unfounded impression that it hasn't been exploited.

I wonder, if you destroy all the evidence this was exploited, can you still claim you don't have any evidence this was exploited? Asking for opinions from non-lawyers only please

haha. I am a lawyer so sorry, but while you might be able to claim that, you are legally and ethically obligated to also divulge the intentional spoiling of hte evidence.

Re: An incident impacting 5M accounts and private information on Twitter

#279

Earlier quoted context omitted.

It doesn't have to be a psychological trick. Sometimes you don't actually have evidence it was exploited - at which point what are you meant to say?

I mean in practice what it tends to mean is the logs only had a 3 month ttl so really could be either way. "no evidence" implies there is at least a place there could have been evidence, they looked, and didn't find any, which is a weak but nonzero update towards it having not happened. It would be nice if they clarified exactly what they checked.

> "no evidence" implies there is at least a place there could have been evidence, they looked, and didn't find any

Yeah I'd never assume that any of that is true. Sure, there probably are ways twitter could find out if something has been being exploited like evidence in server logs or new batches of accounts showing up for sale on the black market, but I wouldn't trust that they looked for them, or that they looked very hard, or that the person making press statements was told about it either way.

If a company has a financial incentive to not find information it's weird to assume they'd seriously look or be trusted to be honest about what they found.

Re: An incident impacting 5M accounts and private information on Twitter

#280
post #259

Earlier quoted context omitted.

I have 100% seen this happen.

really? what do you mean 'middle management is trained to keep that from getting to the top'? intentional malfeasance? where I work people are trying their best but dealing with complex systems, memories, and methods of communication. because of this, security issues are sometimes missed, sometimes poorly communicated, and sometimes poorly remediated.

Almost all companies operate with an extremely low level of trust and most places are blame, shame, and ultimately game the system all the way down.

Hiding something often takes years to uncover and by then management has moved on, maybe even to their second company!

Post reply on HN