How I Discovered a Security Vulnerability in Twitter That Impacted 1.5M Users
bostinnovation.com
bostinnovation.com
Most of the writeup is just a narrative about what he saw and who he talked to afterwards. I'm a little disappointed. I was hoping for more technical detail.
In standard Rails, which the Twitter support ticket site may very well be, this is a one line fix; call User.tickets.find_by_id instead of Ticket.find_by_id.
It would have been more useful if the author included some details and possibly speculation (as you have provided) as to what was going on in Twitter's ticketing setup so that we could all learn from it.
* Was this actually 1.5M users or just tickets? Thats a lot of upset people if so.
"@Charles Your team does a great job. 100-200 tickets per hour. How do you do it?"
"@Wayne My secret is keyboard macros and Text Expander. Some days can be pretty overwhelming though!"
Was this a case of account passwords being sent to Twitter Support by users - 'hey, I can't login, my password is bigclown' - or does Twitter Support have a way to access the user's actual password?
If it's the latter, that's a time bomb waiting to go off.
Took me 8 months to get someone at Skype to acknowledge the issue; to my knowledge it was never escalated. Wouldn't be surprised if it's still there...
Was the vulnerability in Zendesk or in how Twitter had configured the system?
Edited out "not '96 anymore", the word "breathless", and my assessment of his effort to track down security@ as "hinky"; I wasn't happy with the tone of this comment in retrospect either.