An incident impacting 5M accounts and private information on Twitter
privacy.twitter.com
privacy.twitter.com
Considering that, if you implement any flow that involves checking if a phone number is already in use, then you are effectively leaking to an attacker a list of every phone number that uses your product.
They range from 4 (St. Helena) to 13 (Austria), I believe.
Filtering out *5*... would remove 1%. So wouldn't ***555**** remove closer to 0.01%, not 0.1%?
And for anyone who didn't read TFA, this incident goes well beyond leaking what phone numbers use the product, it leaked the usernames associated with each as well.
Or if this functionality needs to return the value, require an authenticated user and impose rate limits based on reputation (which could just be account age)
For instance, Facebook and Twitter used to tell you which profile a phone number belonged to when you put it in the search box (maybe it was this issue). You could restrict that to authenticated users that were 30 days+ old and impose rate limits per day on top of that. A regular user could still look up a few numbers per day but someone enumerating phone numbers would need lots of 1 month old accounts (more effort/cost)
They can then earn money from people who want to rent access to these botnets.
There are also free VPN services who, in their fine print, say that users grant them permission to route other traffic via their connections.
And this is service offered by registered Israeli company that get formal agreement from "bots" to route traffic through them. Very shady, but totally legal service that used by a lot of data collection agencies for price tracking on Amazon or getting data from Linkedin, etc.
Have only 5M accounts linked their phone numbers on Twitter? That's less than 2% of their total accounts (~290M). I don't know what the industry average is for linking phone numbers, but this seems like an exceptionally low ratio.
Similarly, any time an American car has a fender-bender, or at least one of its wheels leaves the ground, it explodes in a massive fireball.
For example in the UK the country code is 44, all mobile phone numbers start with 7, with 9 digits after that.
(Assumption: They were checking only one number per second, either to avoid detection or because they were rate-limited.)
[1] https://www.bleepingcomputer.com/news/security/twitter-revea...
The purposes of phone numbers:
1. Verify you are a not a bot: no need to store anything except TRUE once verified.
2. 2FA - well use something better than SMS, but if you must, store the hash, and make me enter my number for the 2FA each time. Compare with hash and then send SMS.
- Account search during password recovery (lets users search for their account by phone number): https://twitter.com/account/begin_password_reset
- User discoverability and account recommendations (users who upload their address books can find others by phone number, users who share their number can be found by others): https://help.twitter.com/en/using-twitter/account-suggestion...
Hashing numbers has other implications, like support impact (some folks don’t know their own phone number), preventing the ability to offer SMS updates in countries that need it (or to reactivate that feature in national emergencies for countries that SMS support was pulled from), as well as making potential marketing, data mining, satisfying legal requests, and future feature development harder.
So your suggestion is a good one for a privacy-conscious service that doesn’t already depend on (or that is unwilling to relinquish) unhashed numbers, but it probably isn’t in the nature of twitter to seek to protect user data at the expense of existing or future features, even after leaks like this.
Bad login? "Not a valid user/pass combo"
Password recovery? No matter what email or phone provided, simply say "If the email matches our records, we will send a recovery link".
But it gets worse... After being told of the leak in January, rather than disclosing the fact millions of users data had been open for anyone who looked, they quietly fixed it and hoped nobody else had found it.
It was only when the press started to notice they finally disclosed the leak.
That isn't just one bug causing a security leak - it's a chain of bad decisions and bad security culture, and if anything should attract government fines for lax data security, this is it.
What scum. They had lots of chances to fix this, the first one being not collecting phone numbers in the first place. They chose to do that, and then they didn't adequately protect it, and now they're oh so very surprised that someone might be doxing their most vulnerable users.
If anyone is harmed by this, Twitter should be held liable.
https://www.theverge.com/2022/5/25/23141968/ftc-doj-twitter-...
> ...
> But according to the FTC, much more was going on behind the scenes. In fact, in addition to using people’s phone numbers and email addresses for the protective purposes the company claimed, Twitter also used the information to serve people targeted ads – ads that enriched Twitter by the multi-millions.
source: https://www.ftc.gov/business-guidance/blog/2022/05/twitter-p...
So you're right, it wasn't for "no reason", but it also wasn't just for fraud and spam prevention, security, or any of the other lies Twitter told users.
But then again, they wouldn't make much money otherwise.
like my sibling said, twitter was dishonest to their users how the phone number was to be used
if it's just to prevent bot signups, why keep it on file at all?
> if it's just to prevent bot signups, why keep it on file at all?
I mean, you need the actual number for 2FA. I guess maybe you could hash it after some amount of time just for blocking bots? You couldn't just discard it or one number could create unlimited bots.
There’s more to sorting than just ads, security and fraud.
Maybe they get a small boo-boo in the form of a symbolic fine, mangers scramble for a bit, and then the whole thing happens again and again.
Why is this?
This sort of thing will only be fixed when we hold companies accountable for failing to protect customer data through regulation with many rows of sharp teeth.
Because non-twitter users don't give a fuck. And also, twitter users don't give a fuck.
In the meantime, Discord has been added to my "do not recommend" list.
I can't even count how many companies suggested that I should 'just get a phone number' to use their service.
How is twitter notifying users? Has anyone posted screenshots of this notification? I want to know where this notice will appear.
Costs only a few rubles. If you convert it to euros it’s between 1-10 cents, depending on the service and country.
The bottom line is: IDs for sim cards are useless.
PS. I wasn't aware of SS7, reading up on it now.
I might be confused; this is a very old feature of Twitter that does have an opt out. Maybe this new disclosure is the opt out didn't work? https://help.twitter.com/en/safety-and-security/email-and-ph...
It's a different problem, but this year Twitter also got a $150M fine for illegally using the phone numbers they demand from users for marketing purposes. https://www.theverge.com/2022/5/25/23141968/ftc-doj-twitter-...
Lots of companies have various 'forgot my username'/'forgot my password'/'trying to sign up for a new account with a new email address but existing phone number'/'add a friend by email or phone' flows. It's very easy to accidentally leak some info that shouldn't be leaked while implementing such a flow, since you are peering into the users database querying by email/phone/other identifier while the user hasn't properly authenticated yet.
First time I've heard a company actually say this. It's obvious to people who understand a bit about tech and security, but not obvious to the layperson. Twitter actually deserve a tiny amount of credit for giving practical advice that reduces adversity for users in the event of a breach.
Being forced to do something and later being advised not to do that thing out of deep concern for my well-being? Yeah, that's the Twitter UX vibe: the most self-regarding, passive-aggressive person you know, in software form.
They ask for a mobile number to verify you're a real human, then they say "Ha it's your fault you gave us a sensitive mobile number". 99.9% of users only have one mobile, and have no idea how to get an alternate number, so they just give the number they have.
Even so, it's the first time I've seen a company actually imply to the public in plain English that they can't protect private info, rather than maintain a facade of security that doesn't actually exist.
As you point out though, if Twitter requires a phone number to sign up and 99.9% of users use their personal number, then Twitter are basically saying "our security sucks and if you want an account you have no alternative...".
Some interesting corollaries:
- Are there any services that will sign up to twitter on behalf of users? (and would they work or would it be merely shifting trust from Twitter to a potentially less trustworthy party?)
- I wonder if Twitter could consider not requiring personal info at sign up so as to avoid this dark UX
- Is there a 10 minute mail for phone numbers?
I realise though that this is possibly an anti-spam measure (which I'm in favour of), since I've connected through Tor when creating the account. But this procedure stands in stark contrast to the advise given in the article.
With pseudonymous usage of public services information minimisation to maintain operational-security against private user-data being disclosed by external hackers or rogue insiders is a mantra that needs to be followed religiously.
Guess Linux users are bad, or whatever makes them trigger each f*ING time.
They also have list of known people who were critisizing the Erdoğan publicaly but without any bad words, unable to open a criminal case agains that person.
Then they were matching probable phone numbers (last two digits) from Twitter with these knnown people'phone numbers. If there was a match (last two digits) they opened a criminal case.
And then that person was being visited by police officers in the morning, arrested for several hours, then he had to attend hearings for 3 years, like once evry 4 months. Also he had to hire a lawyer, for 5 minimal salaries.
At the end he probably wins the case if he is not the owner of that Twitter account, and Erdoğan pays around 1x minimal salary to defendant's lawyer.
I never wanted to give you my phone number, Twitter. You demanded it.
From the linked notice, fwiw: "We will be directly notifying the account owners we can confirm were affected by this issue."
> This bug resulted from an update to our code in June 2021
Does this mean the problem existed for 7 months and nobody at Twitter noticed until they received a bug report?
A more sophisticated system that could look at the ips in use and compare to previously used ips for the accounts would notice something.
Really. One needs to think about logging into any service that requires ONLY Phone number 2FA and this should be a wake up call.
Twitter really should get a massive multi-million dollar fine for this breach.
> We take our responsibility to protect your privacy very seriously and it is unfortunate that this happened.
Patently not seriously enough.
He settled that issue with an under-the-table payout, but the first thing he did after that was to send out a stern memo to all staff warning them that "we will tolerate ABSOLUTELY NO sexual harassment at this company!"
The companies I've worked for have always ignored any stated values as soon as it costs them money or gets in the way of making money. Which is, you know, always.
> In July 2022, we learned through a press report that someone had potentially leveraged this and was offering to sell the information they had compiled. After reviewing a sample of the available data for sale, we confirmed that a bad actor had taken advantage of the issue before it was addressed.
Yikes. Sounds like they either didn't dig deep enough to see if it was exploited or they don't keep records long enough to be sure.
But if they didn't keep sufficient logs, they should have alerted the users back then, not now.
"In the context of the European GDPR the Article 29 Working Party has stated that while the technique of salting and then hashing data “reduce[s] the likelihood of deriving the input value,” because “calculating the original attribute value hidden behind the result of a salted hash function may still be feasible within reasonable means,” the salted-hashed output should be considered pseudonymized data that remains subject to the GDPR."
Under CCPA, I think that is enough, HOWEVER, business must implement business processes that specifically prohibit reidentification. So again, not useful at all in this case.
The question should be is IP address a PII or not. Under CCPA and GDPR it is, but only if it “identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer or household.”
where I work people are trying their best but dealing with complex systems, memories, and methods of communication. because of this, security issues are sometimes missed, sometimes poorly communicated, and sometimes poorly remediated.
Hiding something often takes years to uncover and by then management has moved on, maybe even to their second company!
Fwiw, I've ended up being "middle management" at a large company, with deep technical background, and I'm trained and incentivized to report, escalate, inform, communicate, share, and otherwise ensure its addressed up the bloody wazoo. I get slapped on the hand for not communicating / informing enough, never for communicating too much. Over 2 decades, I've never seen my executives try to cover something. "Manage the narrative", sure, but that's largely about how they craft a sentence, not about not reporting.
However, I have also witnessed corporate culture in other places (as embedded consultant) where each layer is terrified of layer above, and each layer is heavily punished for reporting "bad news". They were institutionally set up to fail project deployment as risks are not escalated and they proudly plunge forward. They're not sure much top-down knowingly obstructed to hide stuff, as much as electroshock therapied that it's a bad experience. Taking the most cursory log at the most basic logs and saying "whee, no evidence of exploit!!" Would be par for the course :-/
As a non-lawyer, that sure sounds like sketchy advice, even beyond the rest.
Right, but how so? A person or company can get into trouble with things being written down or made known to others. Having a lawyer consider it first is legally prudent and is entirely reasonable and common advice given out to any person (don't speak to police/regulator/other party/internet/newspaper/etc before consulting your lawyer). If you think that's ethically sound advice for a person, then what changes the calculus for a corporation?
> and maybe not the best strategy for the individual if they're being instructed to keep information to themselves instead of passing it up the chain in the company. Is that intended to keep just that employee responsible for whatever mess?
Probably less instructed to keep it to yourself, more encouraged to stick to "official" reporting channels, and then when you do that or come into contact with such issues by other means, more encouragement to use the phone.
And it completely depends on what it is as to the intention I guess. Initially so that the lawyers are able to consider and advise. But sure you aren't paying the lawyer so they are only taking care of your interests so far as that coincides with the company's interests. So if you had a concern that you would be responsible for a legal problem, or are a victim of a criminal or civil legal matter from the company or another person in it, then I would say you should consider discussing that with your own lawyer.
Isn't that taught in..uh..I dunno, middle school science class?
Just because you don't see the rabbit, doesn't mean it doesn't exist.
https://medicine.uq.edu.au/article/2019/04/you-look-do-not-f...
They should be open and forthcoming about their level of confidence, instead of using the least worrying language they can offer while remaining technically correct.
Seems like a fair expectation to have, to me.
Yeah I'd never assume that any of that is true. Sure, there probably are ways twitter could find out if something has been being exploited like evidence in server logs or new batches of accounts showing up for sale on the black market, but I wouldn't trust that they looked for them, or that they looked very hard, or that the person making press statements was told about it either way.
If a company has a financial incentive to not find information it's weird to assume they'd seriously look or be trusted to be honest about what they found.
This is a relatively benign case but the same language is used in other breaches when people should be taking measures like freezing their credit or reviewing financial transactions.
It's one thing to say "My car was stolen", and another to declare "I am unable to determine if it's en route to the Taliban."
The only thing that could happen with the data would be that it is exploited.
The only thing that happens to stolen cars is not going to the taliban.
These are not even similar in nature. They aren't saying "the data was stolen". They also aren't saying "the data was available for exploit we are unable to determine if that occured."
What if they never looked for evidence of unauthorized access? They wouldn't have any!
This is the same as modern science and medicine frequently using this academic phrase, no evidence, when what they mean is that there has been no investigation.
Another thing to mention would be how long in the past you were able to look. E.g. in this case they have found out that the bug was introduced in 2021, were they able to inspect logs covering all of that period or did they only had limited logs/other evidence so it's impossible to know whether anyone used this opportunity or not?
Nothing would have stopped someone from using it. Probably best to assume that they have.
This will be read by optimistically 1% of people, the rest will just catch the summary. This way, you at least get to write the summary.
It could also mean "oh I spent five minutes looking into it and didn't see any evidence"
Otherwise, the reasonable thing to do is to assume that it was exploited, because they have no evidence to show that it wasn't.
The phrase is a psychological trick because it creates the illusion that the burden of proof falls on the other side.
Which is maybe not the worst strategy, but it's going to be pretty exhausting.
I'd suggest that instead we should just expect and enforce a certain amount of openness and honesty from companies when they fuck up in this way, so we can make informed decisions.
In the US and elsewhere, there are already some penalties for covering up a problem, and they should be expanded commensurately with the potential harm.
If there were, call it p, and let q = Π(P), P∈N:P is prime (Eratosthenes showed this is computable)
Then q+1 % 1 modulo every lesser prime, meaning q+1 is prime, and p is thus not the greatest prime.
There you go. We have just proven a negative.
"I have no evidence he murdered someone"
As opposed to
"He might have murdered someone, or not, I just don't have any evidence"
"It's possible he murdered someone I don't have any evidence though"
"I don't have any evidence he murdered someone but that doesn't mean he didn't, I'm just asking questions"
"We left a giant tub filled with cyanide completely unsupervised in front of our door for months. We have no evidence that it was used to murder someone."
Has an entirely different sound to it, no?
"We left a giant tub filled with cyanide completely unsupervised in front of our door for months. We have no evidence that it was used to murder someone."
No one would say that second sentence, if you don't have evidence of something you don't state that because of the set of objects and events that didn't happen is infinite.
"We left a giant tub filled with cyanide completely unsupervised in front of our door for months. We have no evidence that someone accidentally fell into it, an animal died in it, it was used in a bank robbery, someone's cell phone slipped it in............"
"That person owns a gun legally, we have no evidence that he used it to murder someone"
Why not
"
How hard they looked is not of any consequence if they can't tell it wasn't exploited.
source: I am not a lawyer
I could bring up examples across both sides of the isle. It's all a big game.
Absence of evidence IS some evidence of absence if you look thoroughly. It sure isn't anything of the kind if you haven't actually tried to gather the evidence or are aware of giant holes in what you were able to gather.
Security incident response teams do not have the same strange distinction between "real" evidence and the non-published non-peer-reviewed evidence which cannot be relied on or even really mentioned.
EDIT: A few refreshes shows it's slow and occasionally failing in the browser for me...
Until then :middle_finger:
What? How? Twitter doesn’t allow voip numbers or any sms gateway that is not a brick and mortar teleco company that requires full ID verification.
I think that Google recently forced most accounts to give a phone number even if you don't use 2FA (probably for ID purposes). That's one reason why I like this service: https://www.emailnator.com/, instead of using my own gmail address for signups.
Anonimity is going down the toilet really fast in the US...
So they may contact you, or may not. It would be nice if this gets added to something like haveibeenpwned
This sounds misleading or incompetent. If someone was harvesting data, then logs would indicate how many such login attempts were being made per second/minute/hour/day and the activity would spike in certain days, times, geographical areas to suggest this kind of activity is going on.
Even if the attacker was really careful spreading their activity over long periods of time & routing it via multiple geographical areas, the overall activity would show an uptick before & after the bug.
I find it highly unlikely that a company of the size of Twitter could not ascertain from their internal data that a bug like this was exploited or not.
Or, perhaps the UX design team intentionally decided that mentioning the Twitter username associated with the email address would be a "helpful" piece of info to present at this point in the login/signup flow. In this case, too, the design team should have known that privacy far outweighs any potential helpfulness.
It's why I've been relatively ok with everything Apple has been doing here. Someone needs to drag us into the modern age of authentication and it hasn't been any standards body. They can write specs all day but unless they can get players to adopt them then they're worthless. It's Netscape 3.0 all over again.
A chaos actor with malintent executed a social engineering attack and thereby acquired sensitive private data from several million active human accounts with the goal we believe to misclassify humans as bots and thereby thwart the actor's own publicly but impulsively stated goal of acquiring Twitter and becoming custodian of this data. This actor is still at large though we expect to see him in Delaware Chancery Court in September where he will be punished for his impulsive chaos.
I'm so sick of this kind of victim blaming, you're forced to add a phone number to use twitter.
BTW, no Twitter account is "ours". If it was, we could download everything (friends and all) and move it somewhere else. Twitter needs to take ownership of all data on their platform - user accounts included. Trying to separate them into different entities is ridiculous.
It’s unfolding in real-time with Tyler Technologies and we’ll have to see how it plays out. Intelligent institutional investors are poring money into a company that is responsible for leaking millions of intended to be confidential CRIMINAL RECORDS and is trying to blame JudyRecords for finding their mistake.
Again it goes to show we don’t really own anything that turns digital, and no safeguards are guaranteed. The only recourse is legal action, which is, IMHO going to bankrupt Tyler r force numerous spin offs to pay the class action results from the CA State Bar…and potentially hundreds more.[0]
The environment is one of no consequences when hiding behind a corporate banner, for most intents and purposes. Choose who you work for wisely.
[0] www.JudyRecords.com
One would think dishonestly blaming others for the consequences of their own conduct would also affect stakeholder value.
Suddenly 'use twitter securely' has gone from 'free' to 'hundreds of dollars a year'. Perhaps they should announce this as a price change instead?
Is this a thing? I've never heard of it. Where?
It is expensive if you need to keep the plan around, but Twitter doesn't seem to regularly send SMSes to the phone number, so you probably don't need to pay beyond the first month.
Some years ago I looked into prepaid pricing and determined that it was significantly more expensive than a subscription plan at even my almost-never-use-it levels of phone use. (At that time, pricing was based on (1) a reasonable per-use rate, which would have been very cheap; combined with (2) a high flat fee charged on any day you used any feature of the plan, which already nullified any price advantage; and (3) a requirement to add funding to the plan every month, regardless of whether you had an existing balance.)
How they work here is:
1. You need to top up by €20 at least once a year to keep your account
2. You may sign up to an offer, which will deduct a portion of a top up each month to activate the offer (e.g top up by > €20, the phone company takes €10 for unlimited texts, or €20 for unlimited data).
3. If you don't top up as required by your offer, you fall back to a state as if you had no offer
4. If you have no offer there's fixed fees of like 20c/sms and €0.50/min of calls, €2/day for 100mb of data
Now pre-paid is often just paying for a month before usage rather than after usage. Even cheaper providers like Mint sign you up for 3 months at once, which can get expensive if all you want it for is just satisfying Twitter.
Is it reasonable for everybody to go buy "burner" phones to sign up for Twitter?
The truth is, it's stupid for Twitter to require a phone number, and it's especially stupid that they blame the user for using their real number.
Can you not get an activated SIM off the street?
Mostly, like any other country, this happened because they found bad people were using pre activated sim cards for terrorism.
My exiting phone number is now 14 years old, same provider, prepaid. I have been required to submit updated KYC about 4 times in these years.
“We can screw up, if it’s important enough for you to stay anonymous you should get a separate phone number and email”
That is a good tip with every company. If you want better security, have less trust in the services you’re using.
This goes to what victim blaming is. Yes. It would be great if the victim lived in a better world. But sometimes extra caution could help them now without waiting for the entire world to change.
This advice is bullshit.
I had some old accounts that did not require a phone number.
At least until I wanted to enable TOTP 2FA.
At which point the numnuts at Twitter would not just let me "just" enable TOTP, I was forced to provide a phone number (which, to add insult to injury, for at long time they refused to accept because they would only send messages to a limited number of carriers).
And also used a sketchy service provider who was selling personal info about Twitter users to governments: https://9to5mac.com/2022/02/09/twitter-2fa-text-privacy/
Twitter has been habitually careless with user info & user privacy.
This may be Twitter's best anti-bot measure, although state-sponsored troll farms will likely be able to afford all the SIM cards they want and need.
Pretending they're not requiring something when in practice, a giant proportion of their userbase faces it.
Pretending anything changes when you click 'See This Less Often' on some annoying feature.
Constantly undoing a user's preference for 'Latest' over algorithmic 'Home'.
Claiming they don't "soft-ban" but absolutely, verifiably, hiding some users' content from others who have explicitly followed them.
Implying there's some effective "appeal" process for arbitrary & often clearly erroneous moderations decisions – when instead it's just designed for coercing compliance, including the simualted "voluntary" deletion of tweets, under penalty of losing your account indefinitely.
Slurring & hiding replies with no hint of offense as "potentially offensive".
Describing tweets as "unavailable" when (often) all you have to do is click to see it - wasting users time.
Offering "Show additional replies" even when there's nothing more to show – again wasting users' time.
I tried to use onoff numbers with Twitter on multiple occasions but failed to receive anything. They are being very misleading here.
is that true for the desktop web client?
When I created an account, they blocked it 30 seconds later (before I had done literally anything) and would only unblock it upon me adding a phone number. Google suggested that this was common practice by them at the time.
I don't get the definition of "publicly" here. Does it mean something on Internet, or include numbers I tell people in-person? If the former, not so many people put their number online I suppose...
If you operate a pseudonymous account anywhere, you should always assume there's a slight possibility that one day your identity is known.
I think it's not far stretched to think that in the future, malevolent governments will have access to whatever things we may have posted and use it against us.
I suspect the reason was some rapid changes in my IP address in a short period, together with a lot of Twitter tabs open – whose constant background requests often seem to trigger, for me, some sort of Twitter-side connection-slowing. (Their own shoddy, high-weight design makes my normal usage pattern look like a DoS attack to them.)
So your style of usage, moreso than your account age, is likely for being spared their arbitrary phone-number inquisition.
Twitter should not be requiring phone numbers, especially when they don't care enough to protect them.
This is why we should get back to protocols for communication instead of platforms.
They do this to combat spammers, don’t they?
An older external article[1] about the hack mentions 5.4M accounts.
[1]: https://www.cshub.com/attacks/news/54-million-twitter-accoun...
IIRC, this is at least a third email / phone number dataleak bug that they have.
Almost
And they did not give notice to users. GDPR breach.
Oh and a new identity please. Thanks.
But of course : They're sorry.
being able to attach identities to numbers.
as for brut forcing I'm sure they have limited attempts among other measures.
Please take your “sorry” and shove it where the sun doesn’t shine. You don’t “take our privacy seriously”. This is utterly ridiculous and unacceptable, and in a fair world you would be punished heavily for it.
Edit: an earlier version of this comment criticised Twitter for not doing an investigation earlier to uncover the fact that a leak occurred. This accusation was based on me misreading the press report - see one of the child comments for details. I’ve removed that part of the comment.
It sounds like they confirmed the exploit by looking at the hacked data, not by a renewed search of previously available logs.
I think the real fault is in them forcing users to enter this type of data to begin with, because that makes the only options to surrender your data to them or to not use the app at all.
It would be interesting to see if numbers from verified accounts were included in the leak, that would be very telling.
> (...) To keep your identity as veiled as possible, we recommend not adding a publicly known phone number or email address to your Twitter account.
Well, you're the ones constantly temporarily banning my account for not providing a phone number...
Most shadow banning show the posts if visited via the profile but are invisible if viewed as replies to someone else's post or while signed out and using different IP address. Might be worth checking. Not asserting that this is the case with Twitter though.
If only my phone company also had this policy!
I'm thinking out loud for various other options that can be utilized: a private 256 char length key? You can also store it in a (Azure) key vault, so that it's easily accessible to you from other devices as well. I hope social media companies get open to more secure alternates, but security seems to be their after-thought.
> Don't sign up.
FTFY
Dear Twitter, We need a phone number to be able to use Twitter longer than a week otherwise we get blocked for “suspicious activity” (which is entirely bullshit - logging in from the same IP is not suspicious).
So what should we do? Go to AT&T and open a new line? Jokers.
And yet they actually demanded I give them mine, and have repeatedly, recently demanded a confirmation.
Phone numbers are one of the worst 2fas.
(If you want it, mine's another recommendation for Authy.)
Google Auth is just TOTP, yet Authy is not capable of using it somehow? I'm so confused lol. I've used plenty of TOTP apps with Google.
At least I couldn't find other way to enable TOTP i.e. first SMS.
Data right now is typically bought and sold with an expectation that most of it is crap. it's faster to buy and process 5000 dirty items that probably has a few good leads buried within it than to find leads manually / naturally or broadcast random advertising. (I left the industry in 2020 and my NDA expired in 2021)
Data quality is typically assessed at the "Does this data field have a value for this line item" level. That means data vendors are financially incentivized to make shit up about you as much as they can get away with. think about it for a second, these companies are selling themselves as the source of truth. the actual accuracy does not matter, and the better you are then the less data your customers buy. the data goes stale faster than the accuracy of the data becomes relevant
Did you like a post about a fresh baked baguette that had #french as one of the 100 tags associated with it? congrats, you're french now. it's not exactly this ridiculous, but you get my point
there are some verification focused services - like they take a list of emails and check if they are valid email addresses. Some use fine print to say they are only validating whether or not it is of valid email address FORMATTING, and make no claim about whether or not the email will bounce. verifying if the email address actually belongs to the person it claims to is not part of the deal.
it's nearly an impossible task, because you have no actual source of truth to verify it against. So data vendor A and B give you different results for the same search - now what? you have to manually research and see whos "right" or "more recent".
even if it looks like good data, it might be stale. For example, company size, revenue, C level email addresses, etc all change over time.
so if a customer wants cleaner data - you basically charge them to pump the dataset through Mechanical Turks or upwork or something to have people try to verify things manually. Datasets can be large though and this gets expensive, so it tends to be better to just buy the crap data for cheaper and figure it out yourself
I have a conspiracy theory that these verification services are behind a lot of the phone spam today. they are just checking if your phone number is valid, they dont actually care if you answer.
Exactly this. But they can get away with basically anything. Worst case for them is they show you a premium ad you aren’t interested in. Best case is they guess correctly
Three-dot "More" > Settings and Privacy > Privacy and Safety > Content You See > Interests
"These are some of the interests matched to you based on your profile, activity, and the Topics you follow. These are used to personalize your experience across Twitter, including the ads you see. You can adjust your interests if something doesn’t look right. Any changes you make may take a little while to go into effect."
They recently (early this year) onboarded a few million kids with the Minecraft account migration, and a lot of those new accounts will have flagged as "suspicious activity" and demanded a mobile number to verify who they are..
I had to look up whether this was actually official communication, since it sounds like a kafkaesque fever dream, but yes it's real.
Tech CO's have been doing everything in their power to get your number and email, used it for advertising, and deliberately disabled non-regular phone numbers. And now suddenly you're being gaslit that it's your fault for complying with their demands.
The cream of the cake is the vague "if your phone number is publicly known" stuff. Well yeah, every single phone number is publicly known because it's enumerable. Even if it weren't, almost everyone's number is harvested and resold by gray-market data brokers. Sounds like they want to muddy the waters and make it sound like a targeted vulnerability when in reality it is indiscriminate.
> While no passwords were exposed, we encourage everyone who uses Twitter to enable 2-factor authentication
I think those things are incompatible, or at least Twitter really gives that impression. Great recommendation /s
While no passwords were exposed, we encourage everyone who uses Twitter to enable 2-factor authentication using authentication apps or hardware security keys to protect your account from unauthorized logins.
So it actually does not imply adding a phone number, which is seemingly what you have tried to imply with the cut-off quote provided.
It actually does.
The sentence you quoted contains the link "enable 2-factor authentication", which goes to a page where adding a phone number is the FIRST method described.
"There are three methods to choose from: Text message, Authentication app, or Security key..... If you don’t already have a phone number associated with your account, we’ll prompt you to enter it."
People are so afraid to make a claim nowadays, even if it's obviously true. They speak of "impacts" or that something will be "impacted". But they seem to want to avoid saying who or what will be impacted.
"I was impacted by today's layoffs." "We expect there to be impacts to website traffic."
These meaningless words do nothing except to say "something has happened" which puts the reader in the mindset of having to unravel a mystery.
Anytime you write it's your job to make yourself understood. I don't want to have to be Encyclopedia Brown to figure out what you're trying to tell me.
https://books.google.com/ngrams/graph?content=impacting&year...
Edit: A better headline for OP would have been "Private phone numbers + email addresses leaked for 5M Twitter accounts"
there's never a discussion on HN where someone brings up a product without this asinine comment about its name.
btw Mastodon is great software and it has a great name and branding. It's all subjective.
This is literally impossible. You can't create a Twitter account without a phone number. It sometimes allows you to do so, but then is blocked within 24 hours until you add one.
It's insulting that Twitter should lie about that.
Note the PR words they used. Which amounts to, "If you want privacy, it's not our problem. Go create a virtual number somewhere."
They had a breach and actively actively hid it for an extended period of time. Obviously both sides have good lawyers, but it's hard to see how this doesn't hurt Twitter in regards to the legal battle over the Musk deal unwinding
Why does X company require me to use a certain phone number/IPv4 address/2FA? It doesn't improve security, it does not protect against sybil attacks. The reason is vendor lock-in and data collection.
It's not worth dealing with this crap to access another time-wasting/brainwashing app.
At the same time, there is no shortage of users here willing to give lip service to these backwards practices.