“I’m selling data of 400M Twitter users that was scraped via a vulnerability”
breached.vc
breached.vc
It's not just real email addresses, but this leak (if real) could have also de-anonymized a bunch of people if they were foolish enough to use their real name, or their email address that has this info
Sigh... So many of the massive social media leaks are just people taking advantage of their publicly documented APIs.
I fear more services will stop providing public APIs and maybe even use constantly changing obfuscation like Snapchat and TikTok to make it harder to use their internal APIs.
That sounds interesting. Can you point me to some resources to learn more about this?
https://hot3eed.github.io/snap_part1_obfuscations.html
This one about TikTok was recently on the HN front page:
I have a Twitter account for which I no longer remember the username, and have lost the password. It is, and has been for years, impossible to recover the account, because of a circular dependency in the lost password / account recovery form. I've been tweeting at Twitter Support for years with no avail.
Looks like I can just search this data for my email address and find out what the account name is.
I couldn't remember if Scott Morrison did so, but Google results seem to indicate it[1].
[1] https://www.google.com/search?q=%22%40scottmorrisonpm%22
Meanwhile ScottMorrisonMP has no dip in caches. http://web.archive.org/web/20210801000000*/Twitter.com/Scott...
Perhaps Apple ought to follow Google into the AI-assistant-powered call screening business.
I hardly ever get an unknown important call that doesn’t fall in those categories. This has me not picking up the phone for spam calls, but I hardly ever miss an important call.
There are other things I’ve setup that I don’t want to go into because they can be solved by the spam callers and I’d like to keep it a secret ;)
Edit: wording
But maybe that's not the case?
In France for example, this activity was under scrutiny for decades (2014: https://www.lemonde.fr/vie-quotidienne/article/2014/02/12/de..., 2022: https://www.francetvinfo.fr/internet/telephonie/demarchage-t...), and even if the law is now more restrictive than before : - no week-end call - calls from 10am to 1pm and 2pm to 8pm - you can be included in bloctel, a "do not call me list" it still leave room for this activity.
Almost all these jobs will probably be replaced by AI in a near future, so the main leverage will disappear and ...
But I did stop getting so many spam calls in recent months, so I assume ATT or other phone service providers in the US have enabled some type of anti spam measure.
They only called me once, because I hadn't used the account in a month.
They've only emailed me once since then.
TELUS calls it “Call Control”, and all its subsidiaries offer it. The major phone providers offer it too. It is the only thing I miss from my old TELUS plan.
The real answer is for the phone companies to use a protocol that doesn’t allow easy spoofing of any phone number (I believe one has been proposed but not adopted). Hilariously, I even have a medical provider app called Doximity that abuses this network ‘feature’ to disguise a doctor’s personal cell phone as the phone number of their medical clinic.
I get calls from abroad, the phishing kind. They are easy to block if you do not have business there.
In Canada, sometimes 5 per day.
One trigger here was creating an account in a particular bank. Seems to be breached. Unfortunately Canada is a captive market, we don't have much choice.
I always hit "Block this number" option before deleting.
Phone company (AT&T) labels some in red as Spam; Apple does the same.
I know no news site will ever get clicks from "Competent Government Helps Solve Real Problem", and I know we're not 100% there, but it was genuinely a leap forward and people should talk about it more.
Yes, also from Canada it’s absolutely the worst. I came from the Netherlands, and it’s absolute world of difference. The telcos need to resolve this at a system level and get rid of these call centre software solutions. However, I’m sure Telus/Bell/Rodger are all get lots of money from all these calls so no incentive to stop them.
Can’t help but think that at some point people made the wrong decision along the way.
There are many things they could improve on and I think dealing with spam is probably low on their list.
The effect was that spam calls directly benefited the telcos at the expense of the person called if they answered the call.
I've lived and worked in Canada for many years, the longer I was there the more the outward shine wore off and eventually I just saw it as a loosely collected set of monopolies with the state backing them filtering every dollar from Canadians that they could get their hands on.
But what if Apple gets hacked? They still know your real email, right?
It was funny to have Pizza Hutt and McDonald’s both think they’d called each other. Or two people standing right next to each other.
I nearly got in quite a bit of trouble when someone pranked two high level people in the military, and they decided to have a conversation they probably shouldn’t have had on personal cell phones.
It was fun while it lasted… but I wonder if something like this could work for spam calls. Basically instead of forwarding to voicemail, have it route to some pre recorded messages you make “yeah” “hello” “I didn’t hear that, can you say that again” and loud background noises playing. Then it can send you the recording as your “voicemail”. Could be fun.
1 (347) 514-7296
Edit: thanks, all the reasons listed to give them a phone # dont apply to me so Im safe
(Only reason I attached a number to my main is because I needed API access many years ago, for years before that it never had a number attached to it)
So much so if you pay and use a temporary number from services like OnOff. Twitter cleavely detect this and never sends you a verification code.
You need to use a number that is likely tied into a major phone network, most people will do this, as for the privacy conscious like me I had no way of circumventing the measures Twitter had in place at the time. It was very frustrating.
It was around the time that Elon tweeted out something about telcos sending out spam sms in twitters name.
Meaning you don't have a twitter account or do you use a burner phone?
And yes I do have some burner phone numbers too if I need one but I generally just dont use services that need it.
If they're not burning out yet they will be. You can't gut that much of an organisation in one go and expect it to still function.
I'm not sure what evidence you're looking for, you can take Elon at his own word that he is expecting the remaining employees to shoulder significantly higher burdens than normal. You don't build bedrooms inside of an office when your employees have a healthy work-life balance.
Users can check their own email/phone/etc to verify that the attacker has the data, without the attacker revealing the data.
I'm surprised this doesn't happen more.
That’s not to say ‘most people’ should have their own domain, but renewal is one of the least tricky aspects of domain ownership.
You used to be able to sign up with just an email address then they started forcing phone number verification by lying and saying they caught your account acting like a bot so you needed to verify you’re human using phone number (you got the message even if you did nothing or just followed a few people, total lie)
The part where Twitter was SMS only is like a footnote in its history.
Twitter’s been collecting phone numbers since at least late 2006:
https://web.archive.org/web/20061103054924/http://twitter.co...
At least one name and email address among the non-trivial ones is also correct.
1) I've seen s lot of leaks being ransomed by hackers and hacker groups before and this post seem a bit amateurish (terms, payment, reference to GDPR, name calling Elon etc)
2) That's not how GDPR fines work (the numbers referenced in the post regarding 400m users). The previous fines were given because of the lack of notifying the EU regulators. Not because of the size of the breach. If Twitter is only made aware of this leak now, they can send the reports now and then work on their internal investigation and no fines will be given.
Seller is or was Twitter employee at some point this year.
Multiple users on the thread are the same user (the OP).
This has been planned since the Elon takeover as a plan B in case things got sour...they got sour.
I suppose you mean how much it could be sold for ? The easiest/safest buyers is probably the company itself paid for by their insurance policies. Such policies will likely cover ransoms in the millions.
However with the current Twitter management it probably won't work, Musk may even not be paying the premiums given that he is not paying office rents or more likely be unwilling to negotiate .
For any other deal it is depends a lot on the seller and buyer. You wouldn't want to be drinking polonium after driving hard bargain with the Russians after all.
I'm glad I did
Just need to change my phone number and I'm set.
The sample includes high profile US accounts (who are globally known) and high profile Indian accounts (that are not globally known).
It's pretty easy to google "big India twitter accounts" or "big China twitter accounts" - there is a China newspaper on the list, a France Gov agency, ...
Meanwhile I have multiple Google and twitter accounts validated through one phone number.
[1] https://support.discord.com/hc/en-us/articles/4413460214807-... [2] https://support.discord.com/hc/en-us/articles/360000961212-P...
So yeah, essentially you do need to verify.
Seriously? The people in power probably have many, many phone numbers, and getting a new one is not such a big deal.
Getting a new phone number is a much bigger deal for people not in power, and so are the possible negative outcomes from this (e.g. revealing the hidden identity of stalked or politically prosecuted individuals who are not in positions of power)
You used the word ”anymore”.
Obviously, you are implying that Twitter required a phone number in the past, but because you did not specify the time of the change, we must assume. It could be that phone numbers are not required since an hour ago or a year ago.
Regardless, if it was a requirement, chances are high that a good portion of the 400+M users in this (supposed) data breach were encouraged to share their phone number with Twitter.
Not to dismiss your contribution but if you have to write ”anymore” I don’t see the point of your comment.
This isn't what we are talking about. We are talking about requiring users to "prove they are human" by giving Twitter a phone number and then entering an authentication code that they text to that number.
It doesn't accomplish anything because I can get a new SIM card and a month of "unlimited" talk and text prepaid service for about USD 20(?). I didn't think of it much but looking back it is clearly a data grab.
I suspect twitter did this to pretty much everyone.
This happened to me.
I made an account, not using a phone number.
I then did not use it, for something like a month.
I posted - and the account was suspended, I was emailed, "you have violated our T&C, please provide your phone number to validate your account".
I may be wrong, but to my eye, they were attempting by deception to trick and force users into handing over their phone numbers.
I explained I had no phone number, and I had not posted at all, so it was hard to see how I had violated the T&C, and the account was unfrozen, and has been fine since then.
OP is right, this is a privacy disaster.
The only way I could resolve it was by using a phone number. Meanwhile they've harvested 2-3 of my anon and temp emails.
“Your account is permanently suspended After careful review, we determined your account broke the Twitter Rules. Your account is permanently in read-only mode, which means you can’t Tweet, Retweet, or Like content. You won’t be able to create new accounts. If you think we got this wrong, you can submit an appeal.”
I can’t even follow anyone, but at least I can read tweets.
As I tweeted nothing nor indeed followed anyone all I can assume is that you have to have a real phone number to sign up.
And people on the Twitch subreddit insult you for even questioning this issue, even after they had a data leak. And yes, that's a majority opinion over there.
It's sad.
A: "Hey I had a problem at the con this weekend"
B: "How dare you talk about that, that's DRAMA! Take your DRAMA elsewhere, LLAMA. I'll have you know the guy who runs ConWeekend is my best friend! You're Banned for life! Long live ConWeekend! And here's that Japanese BANNED meme video to play you out! HAHA I SAVED THE FANDOM!"
Given the fannish nature of Twitch and its audience in general, this level of almost religious fanboying and "how dare you question the Gods" mentality is very familiar (my teens and 20s were spent in fandoms - first anime, then comics, then furry).
I've seen this in every single one of them to some extent, but especially furry and Twitch. It's sad, because -- as they, sunlight is the best disinfectant -- and all this does is block the sunlight and discourage people from talking about issues.
The smart move here might be to pay the hacker.
Probably cheaper than Twitter, Saint Vincent and the Grenadines' GDP[0] is about half of SpaceX's revenue.
[0] yes I know that's not the same thing as "net worth", and also countries are not generally for sale, despite things like the Alaska and Louisiana purchases.
If this hack is true Musk buying Twitter shows he is no genius or ever was. He's just another ego maniac Trump type which the majority of the public is tired of
Instead, the proper solution is after verifying legitimacy of the leak to immediately (within 72 hours) notify supervisory authority and users about personal data breach according to Articles 33 and 34 of GDPR.
Edit: works again.
The GDPR does not make impossible demands like "never have a security breach".
For recovery and nonrepudiation purposes, storing a salted hash of the phone number would be the wiser course. If using SMS for notification, services like Twitter should have API callbacks and delegate the problems of multi-platform notifications to a trusted third-party similar to credit card processing.
You can easily brute force the narrow key space if you’re trying to verify if it’s “known”. And if you want to send an actual message you need the full value.
Sounds more like you want to outsource user verification and receive an opaque token for future validation.
Then, wait until someone texts that number in, and salt/hash the caller ID number and compare it to what you’ve got stored. If there’s a match, then you’re authenticated.
Probably lots of issues with this from ux perspective…
Not too secure, as phone numbers are easy to crack (possibly with randomized salt, that even twitter has to “brute force”?), but at least not every entry will be easily readable.
It might not be an issue for some types of usage, but sounds risky if used for account security/recovery/etc.
If the number is not actually validated in a secure (enough) manner, there's no point in using phone numbers at all.
This is something Signal should look into if they're interested in an alternative revenue stream.
I would have assumed any kind of banned interaction with the USA’s baddies list countries (e.g. Iran, Syria, or North Korea) would apply to allowing users to sign up with phone numbers as well.
Though I guess there’s always cross referencing known contacts of expats and dissents.
There’s literally nothing to retaliate about in the Twitter files it’s entirely a nothingburger dressed up for outrage points.
This data is also from 2021 to early 2022 before Twitter files was even a thing.
Even if it’s a nothingburger, putting out bad PR for FBI and CIA has got to make you some powerful enemies.
> Twitter patched this in early 2022 so breach data is 2021 to 2022
Timeline of releasing the breached data can be correlated with another event, but the date that they obtained the loot is irrelevant. They could have simply purchased this from an unknown 3rd party themselves. We simply don't know.
1. The FBI/CIA hacked Twitter and leaked their database in retaliation for the "Twitter files"
2. The FBI/CIA hacked Twitter (or someone else did and they obtained the data) back in early 2022 (for an unknown reason), and are now leaking the data in retaliation for the "Twitter files"
3. FBI/CIA hack Twitter as soon as they can compile enough justification. Use data whenever it is useful, including retaliation.
Based on Snowden leaks, it wouldn’t surprise me if Twitter was hacked very soon after it was created.
The seller could be lying about that, but there is relatively strong circumstantial evidence that suggests they are telling the truth.
It’s moot anyway, since they can always filter their stolen databases by potential methods of exfiltration, so the dump looks like it only used a certain vulnerability.
To be honest the evidence for anything in this discussion is circumstantial and probably spurious at best.
All the skeptic comments in this thread seem to worry about the veracity of the claims, but that’s irrelevant to the question of would FBI/CIA retaliate.
Also, I wouldn't call Twitter's original moderation fair or balanced. There were clearly voices within who thought they were trying to fit policy to decisions they'd already made post-hoc. (Unfortunately if anything it's even worse now.)
There’s no right to post CSAM or revenge porn on the internet, so of course the FBI “drives the removal” of that, it is their job.
I’ve done legal compliance for this elsewhere, I have turned down government requests without being persecuted in return, and I know for a fact Twitter’s previous administration was one of the most aggressive at fighting back here and put a great deal of legal effort into it. Example of a more cooperative response would maybe be Amazon Ring.
There’s also no right for foreign intelligence ops to post on US social media so of course the CIA has opinions on that, it’s their job. Etc.
(Current example of this one: a Chinese group is flooding Twitter search for different Chinese city names with ads for sex workers, to block people searching covid news.)
All these things happen under the rule of law, not random emails. If you don’t like it, change the law. I don’t know why you’d want to do that though.
I agree people might’ve said something other than this, but those people are amateurs and are wrong; talk to the EFF if you actually need advice here.
You clearly have no idea what's in them judging from your comment...
It’s disappointing how the commenting postures surrounding culture war issues curtail curiosity, the spirit of inquiry more generally. A now naive-seeming but widely held assumption about the information revolution was that the instant availability of primary source material would lead to more informed public debate. It’s now apparent to me that knowing how you’re supposed to feel, and what others think, are more important— at the very least more useful— than any naive interest in trying to interpret the messy reality.
Why would the FBI be involved with anything related to revenge porn? Posting revenge porn is not a federal crime.
(Tangentially, it appears that there remain two states in which revenge porn is not a crime. Yuck.)
I don’t think it’s a crime to literally leave it up in the same way distributing CSAM is, but it’s evidence someone is committing a crime, which is a TOS violation most places as most sites don’t want to encourage that. And Twitter’s TOS is what Twitter cares about. Whether reports come in as emails or their annoying inefficient report form is not important.
See: https://twitter.com/mtaibbi/status/1606701436104245248?s=46&... and earlier parts that show that their own influence campaigns had free reign: https://twitter.com/lhfang/status/1605294195975114765?s=46&t...
Some of them aren’t; these are mistakes. law enforcement can report posts the same way anyone else can, and if they report the wrong ones you can ignore them. They don’t have special powers. It’s fine.
(Also, Taibbi moved to Russia in the 90s, assaulted underage women, and publicly wrote about it in his publication the Exile. This is also a kind of bias.)
It makes zero sense to me that this email (https://twitter.com/mtaibbi/status/1606701482308669440?s=46&...) would have anything to do with Hunter Biden's penis. The Twitter employee is clearly talking about feeling unable to not act on a pro-russian tweet even though they hadn't been able to support any action on it using Twitter's own policies.
The point is, the US government partially infiltrated Twitter, and then applied regular external pressure on it to applying badly defined policies against their targets.
If you want Twitter to be upset about that one, you may have to get them to move to some non-aligned country. Maybe there’s some kind of Yandex Twitter? In the meantime, it’s probably against TOS insofar as it’s a spambot, but state media like VOA seem okay.
Also I don't understand why non-US citizens should be allowed to have their speech rights crushed by the US government. Many people of different nationalities live in the US and should be free to speak -- they shouldn't be censored by the US government wearing a glove ("US Tech Organisations") but effectively calling the shots.
I don’t think the EU is capable of making a popular social media site either unfortunately. They don’t have the culture.
Twitter does have blatant Chinese propaganda up, like their wolf warrior diplomats and Chen Weihua, which is another good sign for what they’re allowing elsewhere. Maybe that’s just because Chen is so incompetent it’s funny to let him post…
Isn’t Twitter blocked in China? Do wolf warriors not see any hypocrisy in using it?
Not being hypocritical isn’t even a universal virtue.
He could’ve just had Bari Weiss release everything. (Weiss has, in the meantime, been unfollowed and presumably fired as Elon’s journalist because she tried to mildly criticize him once.)
But this is something in the real world, not a logic puzzle, and unfortunately in the real world you actually do need to consider the context of everything using all available information. I mean, you going “this guy is just coincidentally a sex offender” is not the common man on the street’s response, and most journalists are literally not sex offenders.
I don’t know what Elon is doing. He’s of course extremely compromised by multiple governments, I mean he owns SpaceX and a Chinese Tesla factory, and Saudi Arabia (who’s planted spies at Twitter before) is a major investor now. I also suspect Elon doesn’t know what he’s doing, though.
Him saying “oh I didn’t mean it” only in 2017 when people asked about during a MeToo wave isn’t, I think, particularly convincing.
And, who is doing the retaliating?
FBI or “OGA”
Which we know they did, in spades, in other contexts; but I've seen no evidence in the "Twitter files" to indicate anything illegal was going on in this context. The government briefed Twitter that they expected disinformation campaigns and to be on the lookout for them. The government also flagged a bunch of tweets as "hey, these are sus and might violate your rules, you ought to take a look" like anyone else can do.
Whatever Musk and Taibbi are trying to cook up, they seem to have forgotten who was running the federal government at the time. It wasn't Joe Biden or tHe LiBeRaLs. The whole thing is stupid.
One thing I can’t get my head around is Twitter censoring joke accounts. Do you think it was because they were under so much time pressure that they erred on the side of trusting the Government suggestions?
If a joke account specifies it's a joke account in it's profile information, great. But that content doesn't get displayed when someone shares a tweet made by that account.
Now, think about how many times you may have come across something on the internet that was a joke, but also easy to misread as a serious comment. Such is the nature of a lot of online dialogue.
You've now got a tweet that can easily be (mis)read as truthful, being shared by people on their accounts who could insist to their own followers (who might not do their own due diligence and look at the joke account's profile to see that it's fake) that it's real, and voila, suddenly you've got a joke being used to spread misinformation.
I'm not defending Twitter or taking a side here, nor am I saying that's what happened. But it's a possibility that that's one perspective taken.
If you use twitter as an auth point for other websites you should switch now as a bankruptcy filing might also include a twitter site shut down.
Easy money.
edit: oh god there are two more people doing the "Oh I'll bet! How much?" - I've seen this hundreds of times before. Someone states their honest opinion on here, and a handful of others chime in trying to goad them into staking money on it. When they obviously don't (because why on earth would they?) they get accused of being insincere, not being willing to stake "real" money on it (with perhaps the implication that they're small-fry, and do not have the means to do so unlike the wealthy, high-rolling proposer of the wager), or whatever. It's childish, nobody thinks you're cool and nobody believes you'd actually make a frivolous 10k bet with a pseudonymous person.
Also I didn't goad anybody into doing anything: they offered to bet and I took the bait (and then edited their post to remove the request for betting). Not the other way around.
If you're not willing to bet, then don't create a post on the internet stating that you're willing to bet? simple.
This is not a betting platform and tbh I think dang et al would get in trouble if it turned out HN was facilitating some form of gambling. In reality trying to make someone put money behind their predictions is a way to try to make them back down, look silly/small/cheap and as I said originally, it is childish. Don't do it.
But still, this is a very good reminder about using twitter as login somewhere else!
What odds you taking? I'll take 1:4 odds of bankruptcy in Jan 2023 up to £500 (e.g. I get £125 if it doesnt go bankrupt then and you get £500 if it does).
And now they’ve been saddled with debt whose interest is equal to about their annual revenues before 50% of their largest advertisers stopped advertising.
And they’ve certainly exposed themselves to massive FCC and EU fines.
I think Jan 2023 is way too early, but Twitter has a lot of financial footguns just waiting to go off.