Earlier quoted context omitted.
It doesn't have to be a psychological trick. Sometimes you don't actually have evidence it was exploited - at which point what are you meant to say?
"we have no way of knowing" is a much more informative statement than "we have no evidence", but it belies fallibility on the part of the speaker.
An incident impacting 5M accounts and private information on Twitter
351–360 of 479 posts
Re: An incident impacting 5M accounts and private information on Twitter
#352Anyone else annoyed by the growing use of the word "impact" to speak increasingly passively? People are so afraid to make a claim nowadays, even if it's obviously true. They speak of "impacts" or that something will be "impacted". But they seem to want to avoid saying who or what will be impacted. "I was impacted by today's layoffs." "We expect there to be impacts to website traffic." These meaningless words do nothi…
Re: An incident impacting 5M accounts and private information on Twitter
#353Almost
Re: An incident impacting 5M accounts and private information on Twitter
#354>To keep your identity as veiled as possible, we recommend not adding a publicly known phone number or email address to your Twitter account. And yet they actually demanded I give them mine, and have repeatedly, recently demanded a confirmation. Phone numbers are one of the worst 2fas.
Re: An incident impacting 5M accounts and private information on Twitter
#355Anyone else annoyed by the growing use of the word "impact" to speak increasingly passively? People are so afraid to make a claim nowadays, even if it's obviously true. They speak of "impacts" or that something will be "impacted". But they seem to want to avoid saying who or what will be impacted. "I was impacted by today's layoffs." "We expect there to be impacts to website traffic." These meaningless words do nothi…
Re: An incident impacting 5M accounts and private information on Twitter
#356>To keep your identity as veiled as possible, we recommend not adding a publicly known phone number or email address to your Twitter account. And yet they actually demanded I give them mine, and have repeatedly, recently demanded a confirmation. Phone numbers are one of the worst 2fas.
[deleted]
Re: An incident impacting 5M accounts and private information on Twitter
#357>To keep your identity as veiled as possible, we recommend not adding a publicly known phone number or email address to your Twitter account. And yet they actually demanded I give them mine, and have repeatedly, recently demanded a confirmation. Phone numbers are one of the worst 2fas.
I had to look up whether this was actually official communication, since it sounds like a kafkaesque fever dream, but yes it's real.
Tech CO's have been doing everything in their power to get your number and email, used it for advertising, and deliberately disabled non-regular phone numbers. And now suddenly you're being gaslit that it's your fault for complying with their demands.
The cream of the cake is the vague "if your phone number is publicly known" stuff. Well yeah, every single phone number is publicly known because it's enumerable. Even if it weren't, almost everyone's number is harvested and resold by gray-market data brokers. Sounds like they want to muddy the waters and make it sound like a targeted vulnerability when in reality it is indiscriminate.
Re: An incident impacting 5M accounts and private information on Twitter
#358Earlier quoted context omitted.
Prepaid phone plans in the USA charge you a monthly rate just like subscription plans do. They may also charge you for usage, though that appears to have fallen off compared to the past. Some years ago I looked into prepaid pricing and determined that it was significantly more expensive than a subscription plan at even my almost-never-use-it levels of phone use. (At that time, pricing was based on (1) a reasonable pe…
Wow, the prepaid plans in your country suck. How they work here is: 1. You need to top up by €20 at least once a year to keep your account 2. You may sign up to an offer, which will deduct a portion of a top up each month to activate the offer (e.g top up by > €20, the phone company takes €10 for unlimited texts, or €20 for unlimited data). 3. If you don't top up as required by your offer, you fall back to a state as…
Now pre-paid is often just paying for a month before usage rather than after usage. Even cheaper providers like Mint sign you up for 3 months at once, which can get expensive if all you want it for is just satisfying Twitter.
Re: An incident impacting 5M accounts and private information on Twitter
#359>To keep your identity as veiled as possible, we recommend not adding a publicly known phone number or email address to your Twitter account. And yet they actually demanded I give them mine, and have repeatedly, recently demanded a confirmation. Phone numbers are one of the worst 2fas.
Re: An incident impacting 5M accounts and private information on Twitter
#360Earlier quoted context omitted.
I have 100% seen this happen.
really? what do you mean 'middle management is trained to keep that from getting to the top'? intentional malfeasance? where I work people are trying their best but dealing with complex systems, memories, and methods of communication. because of this, security issues are sometimes missed, sometimes poorly communicated, and sometimes poorly remediated.
Fwiw, I've ended up being "middle management" at a large company, with deep technical background, and I'm trained and incentivized to report, escalate, inform, communicate, share, and otherwise ensure its addressed up the bloody wazoo. I get slapped on the hand for not communicating / informing enough, never for communicating too much. Over 2 decades, I've never seen my executives try to cover something. "Manage the narrative", sure, but that's largely about how they craft a sentence, not about not reporting.
However, I have also witnessed corporate culture in other places (as embedded consultant) where each layer is terrified of layer above, and each layer is heavily punished for reporting "bad news". They were institutionally set up to fail project deployment as risks are not escalated and they proudly plunge forward. They're not sure much top-down knowingly obstructed to hide stuff, as much as electroshock therapied that it's a bad experience. Taking the most cursory log at the most basic logs and saying "whee, no evidence of exploit!!" Would be par for the course :-/