This is a relatively benign case but the same language is used in other breaches when people should be taking measures like freezing their credit or reviewing financial transactions.
It's one thing to say "My car was stolen", and another to declare "I am unable to determine if it's en route to the Taliban."
The only thing that could happen with the data would be that it is exploited.
The only thing that happens to stolen cars is not going to the taliban.
These are not even similar in nature. They aren't saying "the data was stolen". They also aren't saying "the data was available for exploit we are unable to determine if that occured."
What if they never looked for evidence of unauthorized access? They wouldn't have any!
This is the same as modern science and medicine frequently using this academic phrase, no evidence, when what they mean is that there has been no investigation.
Another thing to mention would be how long in the past you were able to look. E.g. in this case they have found out that the bug was introduced in 2021, were they able to inspect logs covering all of that period or did they only had limited logs/other evidence so it's impossible to know whether anyone used this opportunity or not?
Nothing would have stopped someone from using it. Probably best to assume that they have.
This will be read by optimistically 1% of people, the rest will just catch the summary. This way, you at least get to write the summary.
Seems like a fair expectation to have, to me.
Otherwise, the reasonable thing to do is to assume that it was exploited, because they have no evidence to show that it wasn't.
The phrase is a psychological trick because it creates the illusion that the burden of proof falls on the other side.
Which is maybe not the worst strategy, but it's going to be pretty exhausting.
I'd suggest that instead we should just expect and enforce a certain amount of openness and honesty from companies when they fuck up in this way, so we can make informed decisions.
In the US and elsewhere, there are already some penalties for covering up a problem, and they should be expanded commensurately with the potential harm.
If there were, call it p, and let q = Π(P), P∈N:P is prime (Eratosthenes showed this is computable)
Then q+1 % 1 modulo every lesser prime, meaning q+1 is prime, and p is thus not the greatest prime.
There you go. We have just proven a negative.
Yeah I'd never assume that any of that is true. Sure, there probably are ways twitter could find out if something has been being exploited like evidence in server logs or new batches of accounts showing up for sale on the black market, but I wouldn't trust that they looked for them, or that they looked very hard, or that the person making press statements was told about it either way.
If a company has a financial incentive to not find information it's weird to assume they'd seriously look or be trusted to be honest about what they found.
It could also mean "oh I spent five minutes looking into it and didn't see any evidence"