Live data from Hacker News

An incident impacting 5M accounts and private information on Twitter

privacy.twitter.com

301–310 of 479 posts

Re: An incident impacting 5M accounts and private information on Twitter

#301

>To keep your identity as veiled as possible, we recommend not adding a publicly known phone number or email address to your Twitter account. And yet they actually demanded I give them mine, and have repeatedly, recently demanded a confirmation. Phone numbers are one of the worst 2fas.

I was just able to remove my phone number from my account settings and wandered into a Fred Sanford-level of junk data -- Twitter had me identified as a female (I'm male), had "interests" tied to me for both "Alexandria Ocasio-Cortez" and "Ben Shapiro" (they're most certainly not), and had my languages as "French" and "Indonesian" (I know only English). Bad digital hygiene.

Re: An incident impacting 5M accounts and private information on Twitter

#303
post #2

> When we learned about this, we immediately investigated and fixed it. At that time, we had no evidence to suggest someone had taken advantage of the vulnerability. > In July 2022, we learned through a press report that someone had potentially leveraged this and was offering to sell the information they had compiled. After reviewing a sample of the available data for sale, we confirmed that a bad actor had taken adv…

Out of curiosity, why is it only 5M and not 500M? You would think the same vulnerability applied to every server, not just one or one cluster, if they are using automated deployments

Could be a time intensive exploit. Maybe they didn't have enough time to mine the other 455M.

Re: An incident impacting 5M accounts and private information on Twitter

#304

Earlier quoted context omitted.

"We have no evidence that this was exploited" is a standard psychological trick they pull in vulnerability announcements to give an unfounded impression that it hasn't been exploited.

I wonder, if you destroy all the evidence this was exploited, can you still claim you don't have any evidence this was exploited? Asking for opinions from non-lawyers only please

Don't currently have? Sure. The quote says "At that time, we had no evidence" so I think that would be harder to argue. You could maybe make the case the statement means: At that specific moment we didn't have any evidence because we already destroyed it. But it certainly implies they mean they had not found any before that point in time.

Re: An incident impacting 5M accounts and private information on Twitter

#305

I believe this is the vulnerability reported to Twitter which awarded $5000 from its bug bounty program. https://hackerone.com/reports/1439026

$5k seems embarrassingly low so something with such horrendous impact. Potentially allowing for doxing, and because phone numbers are the lynchpin for many 2FA and consumer-facing telco security is generally lax, total user hijacking across multiple platforms. What an absolute disaster.

Besides impact, $5K also doesn't make sense when compared to employee compensation.

Re: An incident impacting 5M accounts and private information on Twitter

#306

>To keep your identity as veiled as possible, we recommend not adding a publicly known phone number or email address to your Twitter account. And yet they actually demanded I give them mine, and have repeatedly, recently demanded a confirmation. Phone numbers are one of the worst 2fas.

It's gonna be fun when this happens to Microsoft.

They recently (early this year) onboarded a few million kids with the Minecraft account migration, and a lot of those new accounts will have flagged as "suspicious activity" and demanded a mobile number to verify who they are..

Re: An incident impacting 5M accounts and private information on Twitter

#307

>To keep your identity as veiled as possible, we recommend not adding a publicly known phone number or email address to your Twitter account. And yet they actually demanded I give them mine, and have repeatedly, recently demanded a confirmation. Phone numbers are one of the worst 2fas.

Some days I wish I could go without a phone number and have all my communications through an open protocol

Re: An incident impacting 5M accounts and private information on Twitter

#308

Earlier quoted context omitted.

I wonder, if you destroy all the evidence this was exploited, can you still claim you don't have any evidence this was exploited? Asking for opinions from non-lawyers only please

haha. I am a lawyer so sorry, but while you might be able to claim that, you are legally and ethically obligated to also divulge the intentional spoiling of hte evidence.

As if the people giving orders at some of these companies care about ethics... ;)

Re: An incident impacting 5M accounts and private information on Twitter

#309
Tying identity to a phone number is one of those things that solved an immediate need (2FA) but it's riddled with so many issues and concerns that the only reason we're still doing it is because the alternatives are a huge step up in complexity and user frustration.

It's why I've been relatively ok with everything Apple has been doing here. Someone needs to drag us into the modern age of authentication and it hasn't been any standards body. They can write specs all day but unless they can get players to adopt them then they're worthless. It's Netscape 3.0 all over again.

Re: An incident impacting 5M accounts and private information on Twitter

#310
post #2

> When we learned about this, we immediately investigated and fixed it. At that time, we had no evidence to suggest someone had taken advantage of the vulnerability. > In July 2022, we learned through a press report that someone had potentially leveraged this and was offering to sell the information they had compiled. After reviewing a sample of the available data for sale, we confirmed that a bad actor had taken adv…

Out of curiosity, why is it only 5M and not 500M? You would think the same vulnerability applied to every server, not just one or one cluster, if they are using automated deployments

The rest are bot accounts right?
Post reply on HN