>To keep your identity as veiled as possible, we recommend not adding a publicly known phone number or email address to your Twitter account. And yet they actually demanded I give them mine, and have repeatedly, recently demanded a confirmation. Phone numbers are one of the worst 2fas.
An incident impacting 5M accounts and private information on Twitter
301–310 of 479 posts
Re: An incident impacting 5M accounts and private information on Twitter
#302Re: An incident impacting 5M accounts and private information on Twitter
#303> When we learned about this, we immediately investigated and fixed it. At that time, we had no evidence to suggest someone had taken advantage of the vulnerability. > In July 2022, we learned through a press report that someone had potentially leveraged this and was offering to sell the information they had compiled. After reviewing a sample of the available data for sale, we confirmed that a bad actor had taken adv…
Out of curiosity, why is it only 5M and not 500M? You would think the same vulnerability applied to every server, not just one or one cluster, if they are using automated deployments
Re: An incident impacting 5M accounts and private information on Twitter
#304Earlier quoted context omitted.
"We have no evidence that this was exploited" is a standard psychological trick they pull in vulnerability announcements to give an unfounded impression that it hasn't been exploited.
I wonder, if you destroy all the evidence this was exploited, can you still claim you don't have any evidence this was exploited? Asking for opinions from non-lawyers only please
Re: An incident impacting 5M accounts and private information on Twitter
#305I believe this is the vulnerability reported to Twitter which awarded $5000 from its bug bounty program. https://hackerone.com/reports/1439026
$5k seems embarrassingly low so something with such horrendous impact. Potentially allowing for doxing, and because phone numbers are the lynchpin for many 2FA and consumer-facing telco security is generally lax, total user hijacking across multiple platforms. What an absolute disaster.
Re: An incident impacting 5M accounts and private information on Twitter
#306>To keep your identity as veiled as possible, we recommend not adding a publicly known phone number or email address to your Twitter account. And yet they actually demanded I give them mine, and have repeatedly, recently demanded a confirmation. Phone numbers are one of the worst 2fas.
They recently (early this year) onboarded a few million kids with the Minecraft account migration, and a lot of those new accounts will have flagged as "suspicious activity" and demanded a mobile number to verify who they are..
Re: An incident impacting 5M accounts and private information on Twitter
#307>To keep your identity as veiled as possible, we recommend not adding a publicly known phone number or email address to your Twitter account. And yet they actually demanded I give them mine, and have repeatedly, recently demanded a confirmation. Phone numbers are one of the worst 2fas.
Re: An incident impacting 5M accounts and private information on Twitter
#308Earlier quoted context omitted.
I wonder, if you destroy all the evidence this was exploited, can you still claim you don't have any evidence this was exploited? Asking for opinions from non-lawyers only please
haha. I am a lawyer so sorry, but while you might be able to claim that, you are legally and ethically obligated to also divulge the intentional spoiling of hte evidence.
Re: An incident impacting 5M accounts and private information on Twitter
#309It's why I've been relatively ok with everything Apple has been doing here. Someone needs to drag us into the modern age of authentication and it hasn't been any standards body. They can write specs all day but unless they can get players to adopt them then they're worthless. It's Netscape 3.0 all over again.
Re: An incident impacting 5M accounts and private information on Twitter
#310> When we learned about this, we immediately investigated and fixed it. At that time, we had no evidence to suggest someone had taken advantage of the vulnerability. > In July 2022, we learned through a press report that someone had potentially leveraged this and was offering to sell the information they had compiled. After reviewing a sample of the available data for sale, we confirmed that a bad actor had taken adv…
Out of curiosity, why is it only 5M and not 500M? You would think the same vulnerability applied to every server, not just one or one cluster, if they are using automated deployments