Twitter says bug may have exposed some direct messages to third-party developers
techcrunch.com
techcrunch.com
We have validated that this bug might have occurred when all of the following technical circumstances were true during the relevant time period for this issue:
đźž„ Two or more registered developers had active Account Activity API subscriptions configured for domains that resolved to the same public IP;
đźž„ For active subscriptions, URL paths (after the domain) had to match exactly across those registered developers -- e.g. https://example.com/[webhooks/twitter] and https://anotherexample.com/[webhooks/ twitter ];
đźž„ Those registered developers had activity relevant to their subscriptions occur in the same 6-minute time period (relevant because of a cache-like behavior); and
🞄 Those registered developers’ subscribers’ activities originated from the same backend server from within Twitter’s datacenter
Under those circumstances, if the bug occurred, the issue (transmission of activities to the wrong webhook URL) could have persisted until one of the following conditions were met:
đźž„ For up to two weeks, OR
đźž„ Until no relevant activity occurred for 6 minutes, OR
đźž„ Until the IP address of the developer whose data was being misdelivered changed
I hope this is true. I got the message and only really use twitter DMs for communicating with banks and airlines.
The message itself seems really poorly worded to me - I assumed that one of their APIs didn't check permissions and included all DMs and protected tweets in its output. "one or more" makes me assume "all" and "may" usually means "definitely has" in these kind of messages so it would have been great if they had included details about potential mitigating factors.
https://blog.twitter.com/developer/en_us/topics/tools/2018/d...
I'm not trying to downplay this, but I'm also not sending United Airlines my innermost secrets here...
I'm going out on a limb here and say the average hackernews user is not the average twitter user :)
With these details I think any personal information I included in DMs is less likely to be used maliciously through this bug than e.g. from someone accessing my twitter account directly or through a malicious actor at the Brand Account I intended to share with.
So the bug affected roughly 3.3 million Twitter accounts. And it also affected everyone who may be impacted by the contents of the messages which were not protected, whether you're a Twitter user or not, which could be many millions more.
In this day and age, you shouldn't settle for anything less.
Likely via regulation. Possibly by lawsuit.
"Twitter also said that earlier this year there was a bug where log files where created with user passwords in plaintext. Twitter urges users to change their passwords"
I mean, what type of company with over a billion dollars in VC capital stores passwords in plaintext?
Even if the logfiles are rotated every day you don't know if a developer has seen somebody's password during that window, so all passwords are assumed to be compromised.
> May 3, 2018
> Due to a bug, passwords were written to an internal log before completing
> the hashing process. We found this error ourselves, removed the passwords,
> and are implementing plans to prevent this bug from happening again.
> — https://blog.twitter.com/official/en_us/topics/company/2018/...
user's -> users'
__plural__
Also:
>a “bug” sent user’s private direct messages to third-party developers “who were not authorized to receive them.”
But:
>it’s “highly unlikely” that any communication was sent to the incorrect developers at all
Which one is it?