Live data from Hacker News

Twitter for Android Security Vulnerability

privacy.twitter.com

11–20 of 28 posts

Re: Twitter for Android Security Vulnerability

#11
post #10

If only old hardware/phones could get OS security updates by any mechanism. I have a growing drawer of old hardware that is perfectly functional but no longer updateable.

Likely with locked bootloaders as well!

There needs to be a law that states that once a company stops supporting s device they must release the keys to allow users to modify their devices themselves.

Re: Twitter for Android Security Vulnerability

#12
post #4

identified October 2018 fixed August 2020 Good job Twitter https://source.android.com/security/bulletin/2018-10-01

The security patch from Google is from October 2018 it looks like.

So Twitter is to blame for not coding a mitigation for vulnerable devices? Or is it the phone manufacturer's fault for not releasing security patches for their phones?

Re: Twitter for Android Security Vulnerability

#14
post #8

Better yet: don't install the Twitter app, and instead use m.twitter.com, which works perfectly and stays entirely within the browser's sandbox as it should. You can have a separate icon for that as though it were an app, and if you really want to, you can enable push notifications just as you could with an app.

My experience is that the web app does not work perfectly. In fact I get an endless spinner >50% of the time and lord help me if I try to open a comment thread.

No kidding! I rarely look at Twitter, but if I do, in 50% of cases I have to refresh the page to get any content to show. I thought I was the only one.

Re: Twitter for Android Security Vulnerability

#15
They're awfully vague about exactly what the vulnerability was and what could exploit it. I thought the sandboxing between apps would be quite solid and well-tested. Did that break somehow, or did the Twitter app have some kind of insecure API for other apps to interface with the local Twitter app?

Re: Twitter for Android Security Vulnerability

#17
post #8

Better yet: don't install the Twitter app, and instead use m.twitter.com, which works perfectly and stays entirely within the browser's sandbox as it should. You can have a separate icon for that as though it were an app, and if you really want to, you can enable push notifications just as you could with an app.

My experience is that the web app does not work perfectly. In fact I get an endless spinner >50% of the time and lord help me if I try to open a comment thread.

Agreed. I rarely use Twitter anymore, but when I do, I use the mobile site, and it's awful in my experience. My phone is about 1.5 years old, but I don't think a website should struggle to load on a somewhat old phone.

Re: Twitter for Android Security Vulnerability

#18

Better yet: don't install the Twitter app, and instead use m.twitter.com, which works perfectly and stays entirely within the browser's sandbox as it should. You can have a separate icon for that as though it were an app, and if you really want to, you can enable push notifications just as you could with an app.

I'm often getting some form of "you're rate limited", "not allowed to perform this action" etc. until I hard-reload the full page.

Given that others have reported it, and it's been there for a long time, I suspect Twitter at the very least intentionally doesn't put too much resources behind the web site to force people to use the app.

Of course, if a service really wants to push an app onto me, it's clear that the app gives them some real benefits, and its usually the kind that aren't a benefit for me (more tracking, better ways to push ads, more "engagement" notifications, ...). So the harder something wants to push an app, the clearer it is that I never, ever want their app to touch my device.

Re: Twitter for Android Security Vulnerability

#19

Better yet: don't install the Twitter app, and instead use m.twitter.com, which works perfectly and stays entirely within the browser's sandbox as it should. You can have a separate icon for that as though it were an app, and if you really want to, you can enable push notifications just as you could with an app.

I'm often getting some form of "you're rate limited", "not allowed to perform this action" etc. until I hard-reload the full page. Given that others have reported it, and it's been there for a long time, I suspect Twitter at the very least intentionally doesn't put too much resources behind the web site to force people to use the app. Of course, if a service really wants to push an app onto me, it's clear that the ap…

> I'm often getting some form of "you're rate limited", "not allowed to perform this action" etc. until I hard-reload the full page.

I thought I was the only person dealing with this.. It happens for pretty much every tweet that I open in a browser. After a refresh, everything loads fine, but it's quite annoying.

Re: Twitter for Android Security Vulnerability

#20

Better yet: don't install the Twitter app, and instead use m.twitter.com, which works perfectly and stays entirely within the browser's sandbox as it should. You can have a separate icon for that as though it were an app, and if you really want to, you can enable push notifications just as you could with an app.

I'm often getting some form of "you're rate limited", "not allowed to perform this action" etc. until I hard-reload the full page. Given that others have reported it, and it's been there for a long time, I suspect Twitter at the very least intentionally doesn't put too much resources behind the web site to force people to use the app. Of course, if a service really wants to push an app onto me, it's clear that the ap…

I get this every single time a tweet opens in the iOS web view. I have got their app but either they or Apple or someone screwed something up and tweets never open in it.
Post reply on HN