Earlier quoted context omitted.
Amen. Google is asking me to add 2FA to an account for work, and there's no way to do so except from phone numbers or Google Authenticator which I'd rather not use. It's the only service that doesn't let me use something like Authy for OTP.
Google will allow you to use (and they prefer, and you should too) a Security Key. I use this wherever I can. I don't Tweet, but if I did it would be secured with Security Keys. I have Facebook only inside a single contain on one machine, secured with Security Keys. And so on for many services. More services should do WebAuthn.
An incident impacting 5M accounts and private information on Twitter
401–410 of 479 posts
Re: An incident impacting 5M accounts and private information on Twitter
#402Remember that phone numbers are only 10 digits long, so brute forcing all phone numbers is totally doable. Considering that, if you implement any flow that involves checking if a phone number is already in use, then you are effectively leaking to an attacker a list of every phone number that uses your product.
Bad login? "Not a valid user/pass combo"
Password recovery? No matter what email or phone provided, simply say "If the email matches our records, we will send a recovery link".
Re: An incident impacting 5M accounts and private information on Twitter
#403> we recommend not adding a publicly known phone number or email address to your Twitter account. > While no passwords were exposed, we encourage everyone who uses Twitter to enable 2-factor authentication I think those things are incompatible, or at least Twitter really gives that impression. Great recommendation /s
The full sentence states: While no passwords were exposed, we encourage everyone who uses Twitter to enable 2-factor authentication using authentication apps or hardware security keys to protect your account from unauthorized logins. So it actually does not imply adding a phone number, which is seemingly what you have tried to imply with the cut-off quote provided.
Re: An incident impacting 5M accounts and private information on Twitter
#404Isn't this the second or third time for Twitter to have this exact same flaw? From 2020: https://www.socialmediatoday.com/news/twitter-uncovers-secur... I might be confused; this is a very old feature of Twitter that does have an opt out. Maybe this new disclosure is the opt out didn't work? https://help.twitter.com/en/safety-and-security/email-and-ph... It's a different problem, but this year Twitter also got a $150…
Re: An incident impacting 5M accounts and private information on Twitter
#405So after forcing users to enter a phone number to continue using twitter, despite twitter having no need to know the users phone number, they then leak the phone numbers and associated accounts. Great. But it gets worse... After being told of the leak in January, rather than disclosing the fact millions of users data had been open for anyone who looked, they quietly fixed it and hoped nobody else had found it. It was…
The whole announcement reeks of "Stop hitting yourself!" What scum. They had lots of chances to fix this, the first one being not collecting phone numbers in the first place. They chose to do that, and then they didn't adequately protect it, and now they're oh so very surprised that someone might be doxing their most vulnerable users. If anyone is harmed by this, Twitter should be held liable.
https://www.theverge.com/2022/5/25/23141968/ftc-doj-twitter-...
Re: An incident impacting 5M accounts and private information on Twitter
#406> we recommend not adding a publicly known phone number or email address to your Twitter account. > While no passwords were exposed, we encourage everyone who uses Twitter to enable 2-factor authentication I think those things are incompatible, or at least Twitter really gives that impression. Great recommendation /s
The full sentence states: While no passwords were exposed, we encourage everyone who uses Twitter to enable 2-factor authentication using authentication apps or hardware security keys to protect your account from unauthorized logins. So it actually does not imply adding a phone number, which is seemingly what you have tried to imply with the cut-off quote provided.
It actually does.
The sentence you quoted contains the link "enable 2-factor authentication", which goes to a page where adding a phone number is the FIRST method described.
"There are three methods to choose from: Text message, Authentication app, or Security key..... If you don’t already have a phone number associated with your account, we’ll prompt you to enter it."
Re: An incident impacting 5M accounts and private information on Twitter
#407Earlier quoted context omitted.
$5k seems embarrassingly low so something with such horrendous impact. Potentially allowing for doxing, and because phone numbers are the lynchpin for many 2FA and consumer-facing telco security is generally lax, total user hijacking across multiple platforms. What an absolute disaster.
I have found many far more serious bugs, even at larger companies, that have paid me under $500. No one feels security researchers time is even worth that of the internal engineers creating the bugs.
Re: An incident impacting 5M accounts and private information on Twitter
#408Earlier quoted context omitted.
Rate limiting is not useful meaningfully. For a service we ran we regularly had botnets with 100k+ IP addresses making one request an hour to endpoints, which absolutely decimated the backend but hit no limits at all that a real user wouldn't also trigger. Even with a couple of requests an hour you could enumerate the entire phone number space in a very short period with that botnet.
Out of curiosity, how does someone possibly get 100k+ IP addresses? I had enough trouble getting 1 public IP address.
And this is service offered by registered Israeli company that get formal agreement from "bots" to route traffic through them. Very shady, but totally legal service that used by a lot of data collection agencies for price tracking on Amazon or getting data from Linkedin, etc.
Re: An incident impacting 5M accounts and private information on Twitter
#409Re: An incident impacting 5M accounts and private information on Twitter
#410Earlier quoted context omitted.
Phone numbers in the US. In other parts of the world, they're longer.
And all US numbers begin with 555, or so I’m lead to believe.
Similarly, any time an American car has a fender-bender, or at least one of its wheels leaves the ground, it explodes in a massive fireball.