A Twitter app bug was used to match 17M phone numbers to user accounts
techcrunch.com
techcrunch.com
Can this be an API leak which Chinese MSS used to track Chinese users?
It may well as be if we believe that API wasn't implementing discoverability restrictions from privacy settings, and only hid users on the UI level.
> Basically Twitter got pwned big time, and now denies it because GDPR will ruin them if breach is proven. Here is what Doubi's online followers figured:
> State security got all phone numbers used for Twitter phone verification up to May 2019 and possibly till July.
> Twitter haphazardly closed the breach in complete secrecy.
> API hole explanation is excluded as people with 100% private accs got police visits.
> People with foreign SIM cards also got into trouble. So the explanation that China compromised Twitter's SMS providers is also excluded, as its improbable that they did it in 4+ countries.
> 2016 breach is also out of question.
> The only explanation is that they got hold on a big piece of their user DB, or, worse, they have an active infiltrator in Twitter, or Twitter voluntarily cooperated.
Twitter needs a whistleblower/leaker at this point.
If I was China, I'd go for this. Twitter has thousands of employees, many of which can surely be turned with some pressure. Also many who has family in China that can be used for leverage.
Of course, if I'm China, I can try it with enough people to get several assets.
Also, of the offer includes "we won't kill your grandma", uptake might be higher.
Turning someone is rarely an upfront request.
You make friends with them and make small talk about politics to see if there are any sympathies to your cause.
Ask for a small favor and see if they'll do it, then progress slowly. You only ask them to break the law once they're already on your side.
> MICE: Money, Ideology, Compromise, and Ego or Extortion (depending on source)
> RASCLS: Reciprocation, Authority, Scarcity, Commitment and Consistency, Liking, and Social Proof.
In general, most companies want to scope SOX as narrowly as possible. So if you can, only things that your auditors think will affect revenue reporting.
Querying ads performance data? Sure, we'll SOXify it. Querying user accounts writ large? "Meh, our engineers need to be productive."
If it was from the inside more likely a privileged user was compromised. It could also explain why Twitter is being quiet, especially if the investigation is ongoing.
https://www.npr.org/2019/11/07/777352750/how-saudi-arabia-us...
I’ve worked for lots of SOX companies as a third party and had root/sqlplus on most of them. There’s really to relationship between SOX and security.
It's not like they get l337 h4xx0rs to pwn their internal systems; they probably just have login credentials or permissions they shouldn't have, which aren't audited, and they can sneak things out in plain sight.
https://www.npr.org/2019/11/07/777352750/how-saudi-arabia-us...
> API hole explanation is excluded as people with 100% private accs got police visits.
Still, thanks for sharing, that's hell of a story. I don't speak Chinese and have no idea what's ShadowSocksR and why this Doubi guy was so hated by Chinese govt for that. Would appreciate more details.
Doubi was one of main developers of Shadowsocks, a traffic obfuscation tool to jump the Chinese firewall.
As said, the guy openly defied Chinese 3 letter services for years, and even trolled a number of agents whom he managed deanonymise himself.
I don't know about any other allegations but this is wrong. GDPR revenue penalties don't apply to breaches.
Doubi is a blogger sharing GFW circumvention tips, like easy-to-use installing scripts for VPS, tutorials, reviews and a list of donated free acounts. Before his arrest, his blog had been under attack, domain names blocked.
The phone number thing is very dangerous, twitter bascially won't allow you to use it after a while if you don't provide a valid phone number.
Police monitoring: https://twitter.com/tianlan/status/936909920334528513 https://twitter.com/midiexiang6555/status/117813328167558348...
Fried-rice festival, commemorating the day Mao's only son was spotted and bombed in North Korea while out cooking fried-rice. https://twitter.com/tianlan/status/1198841340865331200
Sounds like the other thing Balic discovered (not explicitly published here) is the rate limit below which Twitter's anomaly detection will not notice that you are using an interesting API endpoint.
> While he did not alert Twitter to the vulnerability, he took many of the phone numbers of high-profile Twitter users — including politicians and officials — to a WhatsApp group in an effort to warn users directly.
Uh. I wonder how that went over?
Is this considered normal or ethical behavior for a security researcher?
Ibrahim Balic "ruined" it, though public bragging (which is not responsible disclosure).
Some people dislike the term "responsible disclosure" and believe it's not a moral imperative:
https://hn.algolia.com/?query=author:tptacek%20responsible%2...
Of course what Ibrahim did wasn't full disclosure either, so he shouldn't be fully congratulated. But bragging about it was better than keeping silent about it in this case.
Especially given that things like GDPR and and the CCPA are drawing clear boundaries around private data and how companies can use it, it shouldn't be impossible to make laws that regulate how third parties access and use that data.
I'd also hope that Twitter faces regulatory penalties and perhaps civil liability depending on the harm done.
This is no different than SSH into some machine and try password combinations, or try to login someones email with bruteforce.
Although rate limiting etc is necessary, I think brute forcing someones email account should be illegal.
Hopefully it wasn't just closed to him, but closed to everyone else too.
> Is this considered normal or ethical behavior for a security researcher?
weev did something similar (scraped 100k phone numbers from Apple, then shared them with a journalist) and was convicted and sentenced to 41 months in prison for it.
So this guy merely enumerated a lot of phone numbers and found accounts of users who agreed to have their phone number publicly match their account.
So to call a feature nobody asked for which they went a long way to introduce a "bug"... yeah.
And it’s like a bait and switch. They don’t require it at sign up, but within a short time they’ll lock your account until you add it.
Even simple chat apps now require personally identifiable information to use.
Since twitter don't have a legitimate need for it I'd never give them my number. A disposable number, maybe.
I have never had to present id when buying a prepaid phone in the US.
Also, even if the phone is totally anonymous, you'll be geo-located as soon as you use it. By cell towers at least, and perhaps by WiFi and GPS.
That arguably != "cannot". But you can get close by using Tor via nested VPNs to access Reddit. And by paying with some suitably anonymous cryptocurrency. Maybe well-mixed Bitcoin. Or some Etherium flavor, perhaps exchanged to Bitcoin.
Alternatively, some virtual SMS sites may still work for Twitter. Or there are sites where you can lease actual hosted SIM cards.
Sadly, not all services are good. Many of them block SMS from banks, loan firms and payment systems and I don't want to support them.
that email for the curious:
Hello,
Your account appears to have exhibited automated behavior that violates the Twitter Rules: https://support.twitter.com/articles/18311.
In order to continue safely using Twitter, please follow these steps:
1. Log in to your account on the web or open your Twitter app (iOS or Android). 2. You’ll see a prompt letting you know your account has been locked. Click or tap “Start”. 3. Select your country/region from the drop down menu, and then enter your phone number. 4. Click “Send code” and Twitter will send you a text message with a confirmation code (note that your standard message rates may apply). 5. Enter the code you received in the “Your code” box and click “Submit”. 6. You will see a confirmation message that your account is now unlocked.
Once you confirm your identity, it may take up to a few minutes for your account to be unlocked.
If you’re still experiencing an issue after confirming your identity, please reply to this message and provide us with specific details of the problem you're experiencing. We’ll do our best to help!
Thanks,
Twitter Support
If you reply to this saying you don't have a phone they will re-enable your account but there's no mention of that or "click here to verify account" option.
It has been a year and it still takes me straight to the phone number form any time I click a link for twitter. I can't even log out or do anything else.
So now I must either provide the phone number, use Twitter incognito, or delete the cookies. My guess is that for the casual non-tech user this means they will never use Twitter again until they put in their phone number because it's not possible to back out.
Step #1, turn two factor authentication on
Step #2, have your phone number leaked because of a dumb feature.
And of course, try not to compare it with the Chinese rules requiring phone number verification for online accounts...
I deleted the account a few days later because Twitter is dull and the entire point of what I was trying to do was see if the rumors of immediate account flagging were true. They don't seem to be.
I've not tried again since, and considered twitter 100% off-limits after that experience since it's obviously just an effort to acquire phone numbers coupled to accounts and email addresses under the guise of "security".
Also, Microsoft will require a phone number once you try to log into an Outlook email account from other IP address than you have signed up with. Again, it says the number is necessary to "secure an account from hackers" or something like this.
That's quite a good idea.. They're effectively using your IP as a 2nd factor auth for those people who refuse to use 2 factor. If, like many people, you have a static IP at home, and they whitelist IP's your sessions roam to, you may never need to log in from a new IP.
Immediately following this I received highly targeted phishing sms messages that included links to plausible looking login pages.
Perhaps this shouldn't be too surprising, but people will get burned and somebody will have to pay for it.
[0]: https://hackerone.com/twitterWhy not make this a 10K, 25K bounty even if it's small potatoes?
That amount is nothing to Twitter but might prevent what happened in this case (continued collection of data, public release before Twitter could notify users, etc).
I've noticed this trend of painfully cheap bounties at most other tech giants too.
It pays shit and also vilifies users for learning how the system was built
https://www.computerweekly.com/news/252450337/Bug-bounties-n...
https://www.zdnet.com/article/relying-on-bug-bounties-not-ap...
https://threatpost.com/newsmaker-interview-katie-moussouris-...
Honestly, a lot of the reasons I'm seeing for lowering the payout of bounties seems to revolve around "It's too expensive"
Sadly software is going the way of construction. Things Will only change when tptb get inordinately effected.
This reminds me of a story posted on Russian site [1], where researchers managed to bypass Instagram's protection and find accounts by phone number. Sadly, I cannot confirm described method because their site requires a Google Account to find Instagram account by phone number. But if it's true it shows that even Facebook and thousands of its engineers cannot protect their users' data.
[1] https://translate.google.com/translate?sl=ru&tl=en&u=https%3...
What on earth does this actually mean? And why does he still have a verified Twitter account or an account at all when he exploited it for 2 months without informing them?
Transcription:
"SUBJECT: Twitter Account Security Issue – Update Twitter for Android
Hello,
We recently fixed an issue that could have compromised your account. Although we don’t have evidence that this was exploited, we can’t completely confirm so we are letting you know. You can learn more about this issue here.
Please update to the latest version of Twitter for Android as soon as possible to make sure your account is secure.
We’re sorry this happened and will continue working to keep your information secure on Twitter. You can reach out to our Office of Data Protection through this form to request information regarding your account security.
Thanks, Twitter"
Edit: err, no, this appears to be something different still. Not a good week for Twitter: https://news.ycombinator.com/item?id=21847198
The particularly nice thing about FIDO Security Keys that's relevant here is even a hideously incompetent implementation doesn't hurt you. The Relying Party (in this case Twitter) doesn't end up with any secrets, they get an apparently random "cookie" value to give back to you when they want you to prove you've still got that key, and a elliptic curve public key that doesn't correlate to anything except your login on their site. If they screwed up so badly that the Twitter web site showed a user's U2F parameters to every single visitor looking at their tweets it not only wouldn't unmask any pseudonyms used (as a phone number definitely would) it wouldn't even make it easier to login in as that user. FIDO is the right thing everywhere that a second factor is needed, but even more so when you don't trust the implementers to do a good job.
Also, if you try requesting for an API key, they insist that you add a phone number to your account.
GitHub also require MFA authentication since this year.
Does it mean that any MFA authentication now has same leaks?
Other than my banks, none of the systems I've enabled MFA for required a telephone number.
That includes: Dropbox, GitHub, Slack, Facebook, Nintendo, Google, Login.gov and the Digidentity.eu variant of Gov.uk Verify.
Everywhere it was possible I used my FIDO Security Keys which are phishing proof, impractical to de-anonymise and foolproof because the site has no secrets to leak. Whenever I hear that a site I already used MFA for gained WebAuthn or U2F I go back and switch that site to Security Keys.
Everywhere else I used TOTP (Google Authenticator) which can be phished using a live proxy and the site could leak their copy of your TOTP secret (not the changing code, but the secret that drives it) but other than those two concerns it's pretty safe. At least nobody can work out your real world identity by knowing your TOTP secrets.