Live data from Hacker News

An incident impacting 5M accounts and private information on Twitter

privacy.twitter.com

371–380 of 479 posts

Re: An incident impacting 5M accounts and private information on Twitter

#371

Earlier quoted context omitted.

really? what do you mean 'middle management is trained to keep that from getting to the top'? intentional malfeasance? where I work people are trying their best but dealing with complex systems, memories, and methods of communication. because of this, security issues are sometimes missed, sometimes poorly communicated, and sometimes poorly remediated.

This certainly happens. If you speak to a corporate lawyer about a potentially sensitive issue, they will encourage you to use the phone, don't put anything in writing, and don't tell anybody especially not higher ups in the company, until you sort things out with them first.

> don't tell anybody especially not higher ups in the company

As a non-lawyer, that sure sounds like sketchy advice, even beyond the rest.

Re: An incident impacting 5M accounts and private information on Twitter

#372

Earlier quoted context omitted.

Well, “after investigating by , we were unable to find evidence it was exploited” would be a good start, as it would indicate some effort was put into disproving the hypothesis.

I'm 100% certain they did put in actual effort. If you're so keen on knowing, there's a form at the bottom you can use to ask them.

Then they should share a bit about what they researched and how confident they are one way or another.

Seems like a fair expectation to have, to me.

Re: An incident impacting 5M accounts and private information on Twitter

#373
post #365

> If you operate a pseudonymous Twitter account, we understand the risks an incident like this can introduce and deeply regret that this happened. To keep your identity as veiled as possible, we recommend not adding a publicly known phone number or email address to your Twitter account. First time I've heard a company actually say this. It's obvious to people who understand a bit about tech and security, but not obvi…

No. That’s not practical advice. Twitter is gaslighting us. You can’t use Twitter without a phone number. They require it.

Re: An incident impacting 5M accounts and private information on Twitter

#374

Earlier quoted context omitted.

You can't prove a negative.

In which case, the second paragraph applies.

But then you might as well just assume everything is compromised, at all times, even if there's been no announcement. They could just not be telling you.

Which is maybe not the worst strategy, but it's going to be pretty exhausting.

I'd suggest that instead we should just expect and enforce a certain amount of openness and honesty from companies when they fuck up in this way, so we can make informed decisions.

Re: An incident impacting 5M accounts and private information on Twitter

#375

Earlier quoted context omitted.

It would be more honest to say "We aren't able to determine whether it was exploited" which could better brace potentially impacted users for the possibility they might be affected. This is a relatively benign case but the same language is used in other breaches when people should be taking measures like freezing their credit or reviewing financial transactions.

How about we don’t use terse language and a short blog post to describe a complex thing and instead talk about what happened, what you did to investigate, WHY you couldn’t determine if it was exploited, and what the heck you intend to do about it? How about some facts and transparency? How about some real honesty?

> instead talk about what happened, what you did to investigate, WHY you couldn’t determine if it was exploited, and what the heck you intend to do about it?

This will be read by optimistically 1% of people, the rest will just catch the summary. This way, you at least get to write the summary.

Re: An incident impacting 5M accounts and private information on Twitter

#376

Earlier quoted context omitted.

It doesn't have to be a psychological trick. Sometimes you don't actually have evidence it was exploited - at which point what are you meant to say?

It would be more honest to say "We aren't able to determine whether it was exploited" which could better brace potentially impacted users for the possibility they might be affected. This is a relatively benign case but the same language is used in other breaches when people should be taking measures like freezing their credit or reviewing financial transactions.

"At this time, there is no obvious evidence of malicious activity"

Re: An incident impacting 5M accounts and private information on Twitter

#377

Earlier quoted context omitted.

"We have no evidence that this was exploited" is a standard psychological trick they pull in vulnerability announcements to give an unfounded impression that it hasn't been exploited.

I always wonder who "we" refers to in that usage, legally speaking. Does it refer only to a subset of employees / board members who are authorized to speak for the company? Because then even if someone analyzing logs sees something damning, if middle management is trained to stop that knowledge from reaching the top, then those speaking for the company can continue saying "we" didn't know it.

Tech needs regulation like the finance industry in this regard. Regulation that can push responsibility for breaches up the chain. There must be ways to escalate and if something is seen and reported but not acted on, then liability goes upwards. CEO's in Finance and Banking do A LOT of compliance work and it does catch a lot of problems.

Re: An incident impacting 5M accounts and private information on Twitter

#378
post #2

> When we learned about this, we immediately investigated and fixed it. At that time, we had no evidence to suggest someone had taken advantage of the vulnerability. > In July 2022, we learned through a press report that someone had potentially leveraged this and was offering to sell the information they had compiled. After reviewing a sample of the available data for sale, we confirmed that a bad actor had taken adv…

"We have no evidence that this was exploited" is a standard psychological trick they pull in vulnerability announcements to give an unfounded impression that it hasn't been exploited.

It would be a lot more convincing if they said they put a team on to it to investigate extensively and didn't find anything indicating it was exploited.

Absence of evidence IS some evidence of absence if you look thoroughly. It sure isn't anything of the kind if you haven't actually tried to gather the evidence or are aware of giant holes in what you were able to gather.

Re: An incident impacting 5M accounts and private information on Twitter

#379

Is this going to be the thing that gets Elon Musk off the hook for his billion dollar fine for backing out of the deal? They had a breach and actively actively hid it for an extended period of time. Obviously both sides have good lawyers, but it's hard to see how this doesn't hurt Twitter in regards to the legal battle over the Musk deal unwinding

This starts getting toward "everything everywhere is securities fraud". This probably would have come up in tech diligence but he waived that.

Re: An incident impacting 5M accounts and private information on Twitter

#380

Earlier quoted context omitted.

Yes. The proper way to implement this flow is to ask for the information, and then present the exact same result screen regardless of the actions taken. Any additional information or action should be done exclusively through the contact information you have on record.

And making sure constant time on the response. Otherwise the slower response likely corresponds to a real phone number if the backend synchronously did more actions, such as sending a recovery email. The backend would need to be really slow however in order for a strong enough signal for this to be useful.

Still it’s so much better to have the binary information of whether or not an account exists with that information than exactly which account it is.
Post reply on HN