Live data from Hacker News

An incident impacting 5M accounts and private information on Twitter

privacy.twitter.com

281–290 of 479 posts

Re: An incident impacting 5M accounts and private information on Twitter

#281

Perhaps Twitter needs to make it easier to create accounts anonymously and stop virtue signaling (i.e suspend accounts created over Tor onion-service) With pseudonymous usage of public services information minimisation to maintain operational-security against private user-data being disclosed by external hackers or rogue insiders is a mantra that needs to be followed religiously.

Virtue signaling? Preventing completely anonymously accounts doesn't seem to fit that colloquial definition of that, I always assumed it meant taking an action simply for social signalling, that has no benefit to you otherwise.

How about the fact Twitter recently launched an official onion-service yet it is claimed by users when attempting to create an account with email over it the account is locked for 'abuse' within short order?

Re: An incident impacting 5M accounts and private information on Twitter

#282

Perhaps Twitter needs to make it easier to create accounts anonymously and stop virtue signaling (i.e suspend accounts created over Tor onion-service) With pseudonymous usage of public services information minimisation to maintain operational-security against private user-data being disclosed by external hackers or rogue insiders is a mantra that needs to be followed religiously.

I’m six months in and they haven’t asked for a phone number yet. I dread the day when they do. This is where proficiency in the Twilio API comes in handy.

Created and accessed over Tor or a clearnet connection?

Re: An incident impacting 5M accounts and private information on Twitter

#283

Earlier quoted context omitted.

Twitter would actively block one time numbers. This seems like a lie. I tried to use onoff numbers with Twitter on multiple occasions but failed to receive anything. They are being very misleading here.

-- not only do they block one time numbers - google voice numbers - etc - they claim you CAN sign up with just an email account - let you - and then 30 minutes later automatically lock your account and tell you the only way to verify it is with a number - I was setting up an account a week ago for a client and I eventually gave up - because I was sick of being lied to by their UI --

Some people claim this is the situation with the new Twitter onion-service. Sad.

Re: An incident impacting 5M accounts and private information on Twitter

#284

>To keep your identity as veiled as possible, we recommend not adding a publicly known phone number or email address to your Twitter account. And yet they actually demanded I give them mine, and have repeatedly, recently demanded a confirmation. Phone numbers are one of the worst 2fas.

Amen. Google is asking me to add 2FA to an account for work, and there's no way to do so except from phone numbers or Google Authenticator which I'd rather not use. It's the only service that doesn't let me use something like Authy for OTP.

Re: An incident impacting 5M accounts and private information on Twitter

#285

Earlier quoted context omitted.

"we have no way of knowing" is a much more informative statement than "we have no evidence", but it belies fallibility on the part of the speaker.

"We have no way of knowing" may not be correct statement. There could always be a way to know that you may have missed. It would be inhuman to claim "we have no way of knowing" in circumstances like this.

Fair enough, perhaps to be more specific they could say "we have not kept sufficiently detailed logs to determine what happened"

Re: An incident impacting 5M accounts and private information on Twitter

#286
I'm disappointed and growing hopeless about the state of software engineering at these companies that this sort of issue is not caught in engineering design documents, during development/debugging, or during code reviews. Any competent engineer should have the sensibility to have seen that the implementation they've designed or programmed leaks private information in some scenarios.

Or, perhaps the UX design team intentionally decided that mentioning the Twitter username associated with the email address would be a "helpful" piece of info to present at this point in the login/signup flow. In this case, too, the design team should have known that privacy far outweighs any potential helpfulness.

Re: An incident impacting 5M accounts and private information on Twitter

#287
post #183

Earlier quoted context omitted.

It's interesting to wonder why only 5M accounts were affected by this exploit, especially if it's brute forceable. IIRC this vulnerability was widely known about for at least months before it was fixed, so I can't imagine nobody in the know had access to the resources/botnets necessary to enumerate through every account. Have only 5M accounts linked their phone numbers on Twitter? That's less than 2% of their total a…

Phone numbers in the US. In other parts of the world, they're longer.

And all US numbers begin with 555, or so I’m lead to believe.

Re: An incident impacting 5M accounts and private information on Twitter

#288

>To keep your identity as veiled as possible, we recommend not adding a publicly known phone number or email address to your Twitter account. And yet they actually demanded I give them mine, and have repeatedly, recently demanded a confirmation. Phone numbers are one of the worst 2fas.

Amen. Google is asking me to add 2FA to an account for work, and there's no way to do so except from phone numbers or Google Authenticator which I'd rather not use. It's the only service that doesn't let me use something like Authy for OTP.

I have the 2FA for my work account in 1Password (if that's reasonable is another discussion) so there should be a way to use something else besides Google Authenticator or phone number.

Re: An incident impacting 5M accounts and private information on Twitter

#289

Earlier quoted context omitted.

Virtue signaling? Preventing completely anonymously accounts doesn't seem to fit that colloquial definition of that, I always assumed it meant taking an action simply for social signalling, that has no benefit to you otherwise.

How about the fact Twitter recently launched an official onion-service yet it is claimed by users when attempting to create an account with email over it the account is locked for 'abuse' within short order?

I certainly understand why you want to use Tor to create a Twitter account, I guess the disconnect is you seem to feel it is fundamentally and obviously wrong to prevent this, but it does seem fairly clear why you'd offer a service to allow logins yet not signups. And in any case, can't speak to why an individual account got banned
Post reply on HN