Earlier quoted context omitted.
It doesn't have to be a psychological trick. Sometimes you don't actually have evidence it was exploited - at which point what are you meant to say?
It would be more honest to say "We aren't able to determine whether it was exploited" which could better brace potentially impacted users for the possibility they might be affected. This is a relatively benign case but the same language is used in other breaches when people should be taking measures like freezing their credit or reviewing financial transactions.
An incident impacting 5M accounts and private information on Twitter
361–370 of 479 posts
Re: An incident impacting 5M accounts and private information on Twitter
#362Re: An incident impacting 5M accounts and private information on Twitter
#363> When we learned about this, we immediately investigated and fixed it. At that time, we had no evidence to suggest someone had taken advantage of the vulnerability. > In July 2022, we learned through a press report that someone had potentially leveraged this and was offering to sell the information they had compiled. After reviewing a sample of the available data for sale, we confirmed that a bad actor had taken adv…
Out of curiosity, why is it only 5M and not 500M? You would think the same vulnerability applied to every server, not just one or one cluster, if they are using automated deployments
Re: An incident impacting 5M accounts and private information on Twitter
#364Earlier quoted context omitted.
I have 100% seen this happen.
really? what do you mean 'middle management is trained to keep that from getting to the top'? intentional malfeasance? where I work people are trying their best but dealing with complex systems, memories, and methods of communication. because of this, security issues are sometimes missed, sometimes poorly communicated, and sometimes poorly remediated.
Re: An incident impacting 5M accounts and private information on Twitter
#365First time I've heard a company actually say this. It's obvious to people who understand a bit about tech and security, but not obvious to the layperson. Twitter actually deserve a tiny amount of credit for giving practical advice that reduces adversity for users in the event of a breach.
Re: An incident impacting 5M accounts and private information on Twitter
#366> If you operate a pseudonymous Twitter account, we understand the risks an incident like this can introduce and deeply regret that this happened. To keep your identity as veiled as possible, we recommend not adding a publicly known phone number or email address to your Twitter account. First time I've heard a company actually say this. It's obvious to people who understand a bit about tech and security, but not obvi…
Being forced to do something and later being advised not to do that thing out of deep concern for my well-being? Yeah, that's the Twitter UX vibe: the most self-regarding, passive-aggressive person you know, in software form.
Re: An incident impacting 5M accounts and private information on Twitter
#367> If you operate a pseudonymous Twitter account, we understand the risks an incident like this can introduce and deeply regret that this happened. To keep your identity as veiled as possible, we recommend not adding a publicly known phone number or email address to your Twitter account. First time I've heard a company actually say this. It's obvious to people who understand a bit about tech and security, but not obvi…
They ask for a mobile number to verify you're a real human, then they say "Ha it's your fault you gave us a sensitive mobile number". 99.9% of users only have one mobile, and have no idea how to get an alternate number, so they just give the number they have.
Re: An incident impacting 5M accounts and private information on Twitter
#368Earlier quoted context omitted.
Discord is also like this and it drives me nuts.
They also refuse voip numbers. I am now at 20 back and forth emails with Discord support explaining I do not own a cell phone. They are seriously suggesting I buy one just to use Discord.
In the meantime, Discord has been added to my "do not recommend" list.
Re: An incident impacting 5M accounts and private information on Twitter
#369What? How? Twitter doesn’t allow voip numbers or any sms gateway that is not a brick and mortar teleco company that requires full ID verification.
Re: An incident impacting 5M accounts and private information on Twitter
#370> When we learned about this, we immediately investigated and fixed it. At that time, we had no evidence to suggest someone had taken advantage of the vulnerability. > In July 2022, we learned through a press report that someone had potentially leveraged this and was offering to sell the information they had compiled. After reviewing a sample of the available data for sale, we confirmed that a bad actor had taken adv…
"We have no evidence that this was exploited" is a standard psychological trick they pull in vulnerability announcements to give an unfounded impression that it hasn't been exploited.