Interesting how just throwing the 5M figure in the title changed everything for this post: https://u.ale.sh/some-accounts.png
An incident impacting 5M accounts and private information on Twitter
271–280 of 479 posts
Re: An incident impacting 5M accounts and private information on Twitter
#272Earlier quoted context omitted.
Discord is also like this and it drives me nuts.
They also refuse voip numbers. I am now at 20 back and forth emails with Discord support explaining I do not own a cell phone. They are seriously suggesting I buy one just to use Discord.
Re: An incident impacting 5M accounts and private information on Twitter
#273Earlier quoted context omitted.
"We have no evidence that this was exploited" is a standard psychological trick they pull in vulnerability announcements to give an unfounded impression that it hasn't been exploited.
I wonder, if you destroy all the evidence this was exploited, can you still claim you don't have any evidence this was exploited? Asking for opinions from non-lawyers only please
source: I am not a lawyer
Re: An incident impacting 5M accounts and private information on Twitter
#274Re: An incident impacting 5M accounts and private information on Twitter
#275I think you will see more of this class of attack. Lots of companies have various 'forgot my username'/'forgot my password'/'trying to sign up for a new account with a new email address but existing phone number'/'add a friend by email or phone' flows. It's very easy to accidentally leak some info that shouldn't be leaked while implementing such a flow, since you are peering into the users database querying by email/…
Re: An incident impacting 5M accounts and private information on Twitter
#276Earlier quoted context omitted.
I always wonder who "we" refers to in that usage, legally speaking. Does it refer only to a subset of employees / board members who are authorized to speak for the company? Because then even if someone analyzing logs sees something damning, if middle management is trained to stop that knowledge from reaching the top, then those speaking for the company can continue saying "we" didn't know it.
I have 100% seen this happen.
where I work people are trying their best but dealing with complex systems, memories, and methods of communication. because of this, security issues are sometimes missed, sometimes poorly communicated, and sometimes poorly remediated.
Re: An incident impacting 5M accounts and private information on Twitter
#277Earlier quoted context omitted.
It would be more honest to say "We aren't able to determine whether it was exploited" which could better brace potentially impacted users for the possibility they might be affected. This is a relatively benign case but the same language is used in other breaches when people should be taking measures like freezing their credit or reviewing financial transactions.
How can anyone make any assertions about unknown unknowns? It's one thing to say "My car was stolen", and another to declare "I am unable to determine if it's en route to the Taliban."
Re: An incident impacting 5M accounts and private information on Twitter
#278Earlier quoted context omitted.
"We have no evidence that this was exploited" is a standard psychological trick they pull in vulnerability announcements to give an unfounded impression that it hasn't been exploited.
I wonder, if you destroy all the evidence this was exploited, can you still claim you don't have any evidence this was exploited? Asking for opinions from non-lawyers only please
Re: An incident impacting 5M accounts and private information on Twitter
#279Earlier quoted context omitted.
It doesn't have to be a psychological trick. Sometimes you don't actually have evidence it was exploited - at which point what are you meant to say?
I mean in practice what it tends to mean is the logs only had a 3 month ttl so really could be either way. "no evidence" implies there is at least a place there could have been evidence, they looked, and didn't find any, which is a weak but nonzero update towards it having not happened. It would be nice if they clarified exactly what they checked.
Yeah I'd never assume that any of that is true. Sure, there probably are ways twitter could find out if something has been being exploited like evidence in server logs or new batches of accounts showing up for sale on the black market, but I wouldn't trust that they looked for them, or that they looked very hard, or that the person making press statements was told about it either way.
If a company has a financial incentive to not find information it's weird to assume they'd seriously look or be trusted to be honest about what they found.
Re: An incident impacting 5M accounts and private information on Twitter
#280Earlier quoted context omitted.
I have 100% seen this happen.
really? what do you mean 'middle management is trained to keep that from getting to the top'? intentional malfeasance? where I work people are trying their best but dealing with complex systems, memories, and methods of communication. because of this, security issues are sometimes missed, sometimes poorly communicated, and sometimes poorly remediated.
Hiding something often takes years to uncover and by then management has moved on, maybe even to their second company!