Live data from Hacker News

An incident impacting 5M accounts and private information on Twitter

privacy.twitter.com

361–370 of 479 posts

Re: An incident impacting 5M accounts and private information on Twitter

#361

Earlier quoted context omitted.

It doesn't have to be a psychological trick. Sometimes you don't actually have evidence it was exploited - at which point what are you meant to say?

It would be more honest to say "We aren't able to determine whether it was exploited" which could better brace potentially impacted users for the possibility they might be affected. This is a relatively benign case but the same language is used in other breaches when people should be taking measures like freezing their credit or reviewing financial transactions.

How about we don’t use terse language and a short blog post to describe a complex thing and instead talk about what happened, what you did to investigate, WHY you couldn’t determine if it was exploited, and what the heck you intend to do about it? How about some facts and transparency? How about some real honesty?

Re: An incident impacting 5M accounts and private information on Twitter

#363
post #2

> When we learned about this, we immediately investigated and fixed it. At that time, we had no evidence to suggest someone had taken advantage of the vulnerability. > In July 2022, we learned through a press report that someone had potentially leveraged this and was offering to sell the information they had compiled. After reviewing a sample of the available data for sale, we confirmed that a bad actor had taken adv…

Out of curiosity, why is it only 5M and not 500M? You would think the same vulnerability applied to every server, not just one or one cluster, if they are using automated deployments

Doing it slowly over time to not raise an alarm and collect the information, rather than twitter noticing a massive upticks in password resets that don’t go through?

Re: An incident impacting 5M accounts and private information on Twitter

#364
post #259

Earlier quoted context omitted.

I have 100% seen this happen.

really? what do you mean 'middle management is trained to keep that from getting to the top'? intentional malfeasance? where I work people are trying their best but dealing with complex systems, memories, and methods of communication. because of this, security issues are sometimes missed, sometimes poorly communicated, and sometimes poorly remediated.

This certainly happens. If you speak to a corporate lawyer about a potentially sensitive issue, they will encourage you to use the phone, don't put anything in writing, and don't tell anybody especially not higher ups in the company, until you sort things out with them first.

Re: An incident impacting 5M accounts and private information on Twitter

#365
> If you operate a pseudonymous Twitter account, we understand the risks an incident like this can introduce and deeply regret that this happened. To keep your identity as veiled as possible, we recommend not adding a publicly known phone number or email address to your Twitter account.

First time I've heard a company actually say this. It's obvious to people who understand a bit about tech and security, but not obvious to the layperson. Twitter actually deserve a tiny amount of credit for giving practical advice that reduces adversity for users in the event of a breach.

Re: An incident impacting 5M accounts and private information on Twitter

#366
post #365

> If you operate a pseudonymous Twitter account, we understand the risks an incident like this can introduce and deeply regret that this happened. To keep your identity as veiled as possible, we recommend not adding a publicly known phone number or email address to your Twitter account. First time I've heard a company actually say this. It's obvious to people who understand a bit about tech and security, but not obvi…

Except for a long time they shut down accounts without a phone number under the pretense of "suspicious activity". For some reason, these suspicions could be immediately allayed only by providing your phone number.

Being forced to do something and later being advised not to do that thing out of deep concern for my well-being? Yeah, that's the Twitter UX vibe: the most self-regarding, passive-aggressive person you know, in software form.

Re: An incident impacting 5M accounts and private information on Twitter

#367
post #365

> If you operate a pseudonymous Twitter account, we understand the risks an incident like this can introduce and deeply regret that this happened. To keep your identity as veiled as possible, we recommend not adding a publicly known phone number or email address to your Twitter account. First time I've heard a company actually say this. It's obvious to people who understand a bit about tech and security, but not obvi…

No, that's just shifting the blame onto the user. If they are asking for something as sensitive as a mobile number, then they need to protect it properly.

They ask for a mobile number to verify you're a real human, then they say "Ha it's your fault you gave us a sensitive mobile number". 99.9% of users only have one mobile, and have no idea how to get an alternate number, so they just give the number they have.

Re: An incident impacting 5M accounts and private information on Twitter

#368
post #264
post #187

Earlier quoted context omitted.

Discord is also like this and it drives me nuts.

They also refuse voip numbers. I am now at 20 back and forth emails with Discord support explaining I do not own a cell phone. They are seriously suggesting I buy one just to use Discord.

Maybe there needs to be some sort of law that prohibits this sort of thing.

In the meantime, Discord has been added to my "do not recommend" list.

Re: An incident impacting 5M accounts and private information on Twitter

#369
> To keep your identity as veiled as possible, we recommend not adding a publicly known phone number or email address to your Twitter account.

What? How? Twitter doesn’t allow voip numbers or any sms gateway that is not a brick and mortar teleco company that requires full ID verification.

Re: An incident impacting 5M accounts and private information on Twitter

#370
post #2

> When we learned about this, we immediately investigated and fixed it. At that time, we had no evidence to suggest someone had taken advantage of the vulnerability. > In July 2022, we learned through a press report that someone had potentially leveraged this and was offering to sell the information they had compiled. After reviewing a sample of the available data for sale, we confirmed that a bad actor had taken adv…

"We have no evidence that this was exploited" is a standard psychological trick they pull in vulnerability announcements to give an unfounded impression that it hasn't been exploited.

Yes, potentially a euphemism for "we did not check to see if this was exploited, and thereby have no evidence it was exploited."
Post reply on HN