Live data from Hacker News

An incident impacting 5M accounts and private information on Twitter

privacy.twitter.com

231–240 of 479 posts

Re: An incident impacting 5M accounts and private information on Twitter

#231
post #32

I already fixed it, by not using Twitter.

Truly. It is infuriating dealing with the phone number rigamarole.

Why does X company require me to use a certain phone number/IPv4 address/2FA? It doesn't improve security, it does not protect against sybil attacks. The reason is vendor lock-in and data collection.

It's not worth dealing with this crap to access another time-wasting/brainwashing app.

At the same time, there is no shortage of users here willing to give lip service to these backwards practices.

Re: An incident impacting 5M accounts and private information on Twitter

#232
post #45

Earlier quoted context omitted.

Probably the latter - all companies operating in the EU have had short (ie. 30 days) retention policies on anything user-identifiable (ie. http logs) for a while now. But if they didn't keep sufficient logs, they should have alerted the users back then, not now.

AFAIK there is an exception for security purposes. They could be hashing or "anonymizing" the IPs and keep the data longer.

For security reasons IP addresses needs to be available in plain text. There is no time limit for how long time you can store the data, but you need to be able to motivate why.

Re: An incident impacting 5M accounts and private information on Twitter

#233
Turkish law authorities have abused Twitter's login system in the past several years. If an anonym Twitter account was critisizing Erdoğan they were trying to log in, try to reset the password, choose phone number and then Twitter was showing last two digits of the phone number.

They also have list of known people who were critisizing the Erdoğan publicaly but without any bad words, unable to open a criminal case agains that person.

Then they were matching probable phone numbers (last two digits) from Twitter with these knnown people'phone numbers. If there was a match (last two digits) they opened a criminal case.

And then that person was being visited by police officers in the morning, arrested for several hours, then he had to attend hearings for 3 years, like once evry 4 months. Also he had to hire a lawyer, for 5 minimal salaries.

At the end he probably wins the case if he is not the owner of that Twitter account, and Erdoğan pays around 1x minimal salary to defendant's lawyer.

Re: An incident impacting 5M accounts and private information on Twitter

#234
post #45

Earlier quoted context omitted.

AFAIK there is an exception for security purposes. They could be hashing or "anonymizing" the IPs and keep the data longer.

No that's not valid at all! You must remove any trace of your ability to backwards engineering the IPs. Hashing isn't sufficient since it's so easy to run over the whole IPv4 space. This is one of the trade offs.

You could probably make the argument that you need to store http logs with cleartext IP addresses for more than 30 days for operational security and fraud detection reasons. I would certainly consider 180+ days of cleartext IP addresses quite necessary to be able to react to any security or abuse incidents.

Re: An incident impacting 5M accounts and private information on Twitter

#236

Earlier quoted context omitted.

No, that's a normal statement when there's no evidence something occurred. "I have no evidence he murdered someone" As opposed to "He might have murdered someone, or not, I just don't have any evidence" "It's possible he murdered someone I don't have any evidence though" "I don't have any evidence he murdered someone but that doesn't mean he didn't, I'm just asking questions"

That is not a normal statement if it is your company's fault the question even came up. "We left a giant tub filled with cyanide completely unsupervised in front of our door for months. We have no evidence that it was used to murder someone." Has an entirely different sound to it, no?

More like the tub was filled with water and "we have no evidence it was used to drown someone (but also we didn't check for floating bodies)"

Re: An incident impacting 5M accounts and private information on Twitter

#237

Earlier quoted context omitted.

"We have no evidence that this was exploited" is a standard psychological trick they pull in vulnerability announcements to give an unfounded impression that it hasn't been exploited.

No, that's a normal statement when there's no evidence something occurred. "I have no evidence he murdered someone" As opposed to "He might have murdered someone, or not, I just don't have any evidence" "It's possible he murdered someone I don't have any evidence though" "I don't have any evidence he murdered someone but that doesn't mean he didn't, I'm just asking questions"

It doesn't tell you whether they have actively investigated the incident though. And if they did, how thorough they were.

Re: An incident impacting 5M accounts and private information on Twitter

#238

Earlier quoted context omitted.

"We have no evidence that this was exploited" is a standard psychological trick they pull in vulnerability announcements to give an unfounded impression that it hasn't been exploited.

Suppose Twitter did all it could to investigate and found no evidence. What would you rather have Twitter say in that case ?

Provide some level of detail on how they looked for evidence. "We have no evidence" could mean "we didn't bother looking for evidence", or "we looked extensively for evidence, but didn't find any." In fact, the company has an incentive not to keep logs or collect evidence specifically so they can truthfully claim they don't have any evidence of a breach

Re: An incident impacting 5M accounts and private information on Twitter

#239
post #2

> When we learned about this, we immediately investigated and fixed it. At that time, we had no evidence to suggest someone had taken advantage of the vulnerability. > In July 2022, we learned through a press report that someone had potentially leveraged this and was offering to sell the information they had compiled. After reviewing a sample of the available data for sale, we confirmed that a bad actor had taken adv…

"We have no evidence that this was exploited" is a standard psychological trick they pull in vulnerability announcements to give an unfounded impression that it hasn't been exploited.

Absolutely. That said, it's very very hard sometimes to prove a negative.

Re: An incident impacting 5M accounts and private information on Twitter

#240

I wonder how it affects the Musk’s case of declining to buy Twitter? Surely they concealed from him the fact of this breach?

Yes I wonder about this as well. Say Musk had good reasons to suspect some private information was at risk and Twitter kept denying anything was going on. No matter how minor the actual impact would be in the end, this would not paint Twitter in a favourable light especially in a legal battle where Musk claims Twitter held back vital information.
Post reply on HN