Twitter data breach exposes contact details for 5.4M accounts; on sale for $30k
9to5mac.com
9to5mac.com
That seems like gross negligence to me no matter what the reason for that is, but I play in a much smaller pond and maybe I just don't understand that the cost to do things ethically at scale is always greater than cleanup.
A tweet isn't a binding offer last I checked.
[0]. https://www.eff.org/deeplinks/2019/10/twitter-uninentionally...
I have considered my Twitter DMs to be 'future public information' for a few years now. Same with Facebook. Likelihood of them all being leaked someday seems to be extremely high. I put a lot more trust in Signal, especially disappearing messages.
Strangely, this sort of thinking used to be "common knowledge" / "common sense" back before everyone started self-publishing every detail of their private lives on world-wide public forums like Facebook and Twitter…
Amusing side note; The "Grumpy Old Farts" back in the day where I grew up used to refer to "common sense" as "horse sense", and when asked why, they'd respond "Because every horse has it, even if every person don't!"
So if another company had a previous breach somewhere which linked both the email and the phone number and then a physical address came up...
Then it's game, set and they're fully doxxed and that's that.
If your justification for requiring non-VOIP numbers is "it decreases the number of bots on the service" and the service is overrun with bots, clearly requiring non-VOIP numbers hasn't done much of anything to decrease the number of bots.
Is it a shared number?
iirc they had a guarantee that the number won't be reused for the same service for at least 6 months from order.
Untrue.
Source: my Twitter account uses a Google voice number.
Whatsapp had 55 employees when it was sold, which sounds about right. But 7.5k for just pushing some data around? GTA was developed by 1000 people, and I mean both programatically and content wise it's way more challenging.
So what are those 7500 people working on?
/s
[0] https://twitter.com/ajtourville/status/1547265025345216515
they still send a lot of email to that address, but I haven't been able to login for 10 years, maybe more more? I've made a few half hearted attempts. oh well.
I suppose having a jurassic era account is helpful. It was either compromised years ago, or not even twitter can access the data. :shrug:
E: Disclaimer - I don't care which way the Musk vs Twitter thing goes. I just can see this being the next sticking point
"I know how to make this go away, let's accept his offer, pass him a spliff, and say 'wouldn't it be hilarious to do the deal without due diligence?'"
[unanimous laughter]
In all seriousness, I'm really hoping that Twitter takes Musk down a notch here, and most of the legal maneuvering has filled me with childish glee. Until today, that is. If the twitter board was aware of this, I'm not sure that even signing away diligence would get them off the hook. I'm not a lawyer, so I'm not really sure what to think here
The corporate secretary always as a fiduciary responsibility to record in written form what was discussed at a board meeting.
Human beings on juries (or judges) decide these things. If you promise to sell someone a car and don't disclose that a raccoon is living in the seat cushion, it doesn't really matter what you made them sign, you're at risk of an adverse judgement.
You could threaten to call up a random person's employer and call them a racist unless they paid you. Seems as likely to work as this would be.
You would need someone high profile enough to get the attention of a social media mob to really threaten people.
This version of Blade Runner sucks!
The simplest answer is No. HIBP doesn’t know whether you are in this db, but it also isn’t a true breach.
As far as I'm concerned it's not only user-hostile, but deliberately malicious. Moreover, there's no excuse for services to use phone numbers for 2FA.
this is the reason why all megacorp mobile apps and every other free flashlight/calculator/alarm app require access to your contact list.
Discord allows you to enable phone number verification at a per-admin level basis; and it is done to reduce spam and bots. You can't just pretend the problem doesn't exist.
i’m a privacy junkie, but we can’t just handwave those away and pretend they don’t exist.
Just kidding but this happened to me when I used IRC back in around 1993-1994. For some reason I would respond anyway and would get banned for a time.
This is a solved problem, but these things create friction for the user. And friction is the opposite of what modern tech says you want to provide to your user.
Get them to endlessly scroll, comment thoughtlessly.
In a sense they are used as a kind of "hashcash" to raise the cost of fake accounts.
You can improve privacy by one-way transforming the number in a way your systems can't undo (eg hmac with a key in hsm configured for enc only, with rate limiting), but naively you lose agility and some useful capability (eg ban accounts with numbers from this range).
So store two hashes, one being the whole number, another being the number excluding the last 2 digits. These aren’t difficult problems to solve. The bigger issue is that they’re not revenue generating solutions, but rather the opposite.