Live data from Hacker News

An incident impacting 5M accounts and private information on Twitter

privacy.twitter.com

181–190 of 479 posts

Re: An incident impacting 5M accounts and private information on Twitter

#181

Another reminder not to use Twitter. It's not worth it. Mastodon is better.

Could not have picked a worse name for a social network.

Are you talking about Twitter or Mastodon? Many company and product names are awkward before they become mainstream.

Re: An incident impacting 5M accounts and private information on Twitter

#182

So what you’re saying is that you discovered a vulnerability that leaked the private information of your users, said absolutely nothing for 6 months, then finally came clean, but only because you were forced to because people were selling data on the deep web. Please take your “sorry” and shove it where the sun doesn’t shine. You don’t “take our privacy seriously”. This is utterly ridiculous and unacceptable, and in…

[deleted]

Re: An incident impacting 5M accounts and private information on Twitter

#183

Remember that phone numbers are only 10 digits long, so brute forcing all phone numbers is totally doable. Considering that, if you implement any flow that involves checking if a phone number is already in use, then you are effectively leaking to an attacker a list of every phone number that uses your product.

It's interesting to wonder why only 5M accounts were affected by this exploit, especially if it's brute forceable. IIRC this vulnerability was widely known about for at least months before it was fixed, so I can't imagine nobody in the know had access to the resources/botnets necessary to enumerate through every account. Have only 5M accounts linked their phone numbers on Twitter? That's less than 2% of their total a…

Phone numbers in the US. In other parts of the world, they're longer.

Re: An incident impacting 5M accounts and private information on Twitter

#184

Earlier quoted context omitted.

In India, its not expensive at all, but every sim card is available only after you provide a copy of your national id card aka Aadhar Card.

> but every sim card is available only after you provide a copy of your national id card aka Aadhar Card. Can you not get an activated SIM off the street?

No, technically every SIM gets activated only when mobile phone provider gets the user's documents copy & a verification call comes from mobile company's service center to an existing number of yours or family (& you verify your documents details). If you don't have a existing number to reach, they make you to bring documents to official store. There is no pre activated SIM cards.

Mostly, like any other country, this happened because they found bad people were using pre activated sim cards for terrorism.

My exiting phone number is now 14 years old, same provider, prepaid. I have been required to submit updated KYC about 4 times in these years.

Re: An incident impacting 5M accounts and private information on Twitter

#186

Earlier quoted context omitted.

Well, “after investigating by , we were unable to find evidence it was exploited” would be a good start, as it would indicate some effort was put into disproving the hypothesis.

I'm 100% certain they did put in actual effort. If you're so keen on knowing, there's a form at the bottom you can use to ask them.

[deleted]

Re: An incident impacting 5M accounts and private information on Twitter

#187

So after forcing users to enter a phone number to continue using twitter, despite twitter having no need to know the users phone number, they then leak the phone numbers and associated accounts. Great. But it gets worse... After being told of the leak in January, rather than disclosing the fact millions of users data had been open for anyone who looked, they quietly fixed it and hoped nobody else had found it. It was…

Discord is also like this and it drives me nuts.

Re: An incident impacting 5M accounts and private information on Twitter

#188
post #121
post #101

Earlier quoted context omitted.

Requiring a phone number is part of fraud & spam prevention. Maybe you'd make a different tradeoff but that's not "no reason."

> The FTC says Twitter induced people to provide their phone numbers and email addresses by claiming that the company’s purpose was, for example, to “Safeguard your account. > ... > But according to the FTC, much more was going on behind the scenes. In fact, in addition to using people’s phone numbers and email addresses for the protective purposes the company claimed, Twitter also used the information to serve peopl…

Exactly. I don't have an issue with this if I know they're not using it to farm shit off of me.

But then again, they wouldn't make much money otherwise.

Re: An incident impacting 5M accounts and private information on Twitter

#189
post #42

Earlier quoted context omitted.

In India, its not expensive at all, but every sim card is available only after you provide a copy of your national id card aka Aadhar Card.

But as the OP mentioned, you need to maintain a paid plan and activity on the SIM to keep your number from expiring. It’s neither indefinite nor free.

Yes, I meant that even if somebody who wants to keep the identity unattached to twitter (& thus not risk doxxing after twitter data leak), in India its not possible at all even if they have money to afford.

Re: An incident impacting 5M accounts and private information on Twitter

#190

> How to Protect Your Account > (...) To keep your identity as veiled as possible, we recommend not adding a publicly known phone number or email address to your Twitter account. Well, you're the ones constantly temporarily banning my account for not providing a phone number...

> How to Protect Your Account

I'm thinking out loud for various other options that can be utilized: a private 256 char length key? You can also store it in a (Azure) key vault, so that it's easily accessible to you from other devices as well. I hope social media companies get open to more secure alternates, but security seems to be their after-thought.

Post reply on HN