Live data from Hacker News

An incident impacting 5M accounts and private information on Twitter

privacy.twitter.com

391–400 of 479 posts

Re: An incident impacting 5M accounts and private information on Twitter

#391

Earlier quoted context omitted.

No, that's a normal statement when there's no evidence something occurred. "I have no evidence he murdered someone" As opposed to "He might have murdered someone, or not, I just don't have any evidence" "It's possible he murdered someone I don't have any evidence though" "I don't have any evidence he murdered someone but that doesn't mean he didn't, I'm just asking questions"

That is not a normal statement if it is your company's fault the question even came up. "We left a giant tub filled with cyanide completely unsupervised in front of our door for months. We have no evidence that it was used to murder someone." Has an entirely different sound to it, no?

How does it have a different sound?

"We left a giant tub filled with cyanide completely unsupervised in front of our door for months. We have no evidence that it was used to murder someone."

No one would say that second sentence, if you don't have evidence of something you don't state that because of the set of objects and events that didn't happen is infinite.

"We left a giant tub filled with cyanide completely unsupervised in front of our door for months. We have no evidence that someone accidentally fell into it, an animal died in it, it was used in a bank robbery, someone's cell phone slipped it in............"

"That person owns a gun legally, we have no evidence that he used it to murder someone"

Why not

"

Re: An incident impacting 5M accounts and private information on Twitter

#392

Earlier quoted context omitted.

More like the tub was filled with water and "we have no evidence it was used to drown someone (but also we didn't check for floating bodies)"

"We left our gun outside, unsecured, but no one has complained they were shot with it and we didn't detect any fingerprints on it when we finally noticed it wasn't locked up properly"

Now you're claiming they didn't investigate properly which a completely different situation that you also don't have evidence for.

Re: An incident impacting 5M accounts and private information on Twitter

#393
post #183

Earlier quoted context omitted.

It's interesting to wonder why only 5M accounts were affected by this exploit, especially if it's brute forceable. IIRC this vulnerability was widely known about for at least months before it was fixed, so I can't imagine nobody in the know had access to the resources/botnets necessary to enumerate through every account. Have only 5M accounts linked their phone numbers on Twitter? That's less than 2% of their total a…

Phone numbers in the US. In other parts of the world, they're longer.

International phone numbers can be up to 15 digits, but in most places the rules narrow them down further.

For example in the UK the country code is 44, all mobile phone numbers start with 7, with 9 digits after that.

Re: An incident impacting 5M accounts and private information on Twitter

#394
post #2

> When we learned about this, we immediately investigated and fixed it. At that time, we had no evidence to suggest someone had taken advantage of the vulnerability. > In July 2022, we learned through a press report that someone had potentially leveraged this and was offering to sell the information they had compiled. After reviewing a sample of the available data for sale, we confirmed that a bad actor had taken adv…

"We have no evidence that this was exploited" is a standard psychological trick they pull in vulnerability announcements to give an unfounded impression that it hasn't been exploited.

It's not a trick. Incident response (not vulnerability announcement) is all about evidence. If you can't prove it, it didn't happen. They can probably stil take precautionary measures though which the announcement is part of.

Re: An incident impacting 5M accounts and private information on Twitter

#395
post #229
post #2

> When we learned about this, we immediately investigated and fixed it. At that time, we had no evidence to suggest someone had taken advantage of the vulnerability. > In July 2022, we learned through a press report that someone had potentially leveraged this and was offering to sell the information they had compiled. After reviewing a sample of the available data for sale, we confirmed that a bad actor had taken adv…

https://astralcodexten.substack.com/p/the-phrase-no-evidence...

This link is not particularly relevant, as it talks about how the phrase "no evidence" is used within a specific community and that community has little overlap with the community which writes press releases after security incidents.

Security incident response teams do not have the same strange distinction between "real" evidence and the non-published non-peer-reviewed evidence which cannot be relied on or even really mentioned.

Re: An incident impacting 5M accounts and private information on Twitter

#396
post #388

> we recommend not adding a publicly known phone number or email address to your Twitter account. > While no passwords were exposed, we encourage everyone who uses Twitter to enable 2-factor authentication I think those things are incompatible, or at least Twitter really gives that impression. Great recommendation /s

How are those things incompatible?

Re: An incident impacting 5M accounts and private information on Twitter

#397
post #125

Earlier quoted context omitted.

It's typically smaller though, not every phone number is allocated and many are in sequential groups. Some are special cased, you don't need to search any number matching `****555***` in north america for example, which cuts down on the search space quite a bit.

"Quite a bit"? Filtering out ***555**** removes only 0.1% of phone numbers ;)

I didn't do the math here but: Filtering out 5*... would remove 10% of the search space. (dots mean "followed by more stars")

Filtering out *5*... would remove 1%. So wouldn't ***555**** remove closer to 0.01%, not 0.1%?

Re: An incident impacting 5M accounts and private information on Twitter

#398

Earlier quoted context omitted.

The burden of proof should fall on them to demonstrate that it wasn't exploited. Otherwise, the reasonable thing to do is to assume that it was exploited, because they have no evidence to show that it wasn't. The phrase is a psychological trick because it creates the illusion that the burden of proof falls on the other side.

You can't prove a negative.

There is no greatest prime number.

If there were, call it p, and let q = Π(P), P∈N:P is prime (Eratosthenes showed this is computable)

Then q+1 % 1 modulo every lesser prime, meaning q+1 is prime, and p is thus not the greatest prime.

There you go. We have just proven a negative.

Re: An incident impacting 5M accounts and private information on Twitter

#399

Earlier quoted context omitted.

Strange you say that. I’m six months into my pseudonymous account and they haven’t tried to extort my phone number. It’s like they know from my behavior that I don’t want to be doxxed by Twitter Inc. I signed up using a VPN and a weird email address, and used an AD blocker.

Do they shadowban such accounts? Are you aware if your posts and comments are visible to others?

There are many different levels of shadowban apparently. You can be excluded from being able to trend, or gain followers, or to have post visibility at all based on what I've observed. It mainly gets triggered by complaining about Twitter or a favored sponsor... Twitter considers those things censorable, but not upsetting violence and shocking pr0n for some strange reason... ugh.

Re: An incident impacting 5M accounts and private information on Twitter

#400
post #388

> we recommend not adding a publicly known phone number or email address to your Twitter account. > While no passwords were exposed, we encourage everyone who uses Twitter to enable 2-factor authentication I think those things are incompatible, or at least Twitter really gives that impression. Great recommendation /s

The full sentence states:

While no passwords were exposed, we encourage everyone who uses Twitter to enable 2-factor authentication using authentication apps or hardware security keys to protect your account from unauthorized logins.

So it actually does not imply adding a phone number, which is seemingly what you have tried to imply with the cut-off quote provided.

Post reply on HN