Twitter Okta Leak Exposes Class of "Protected Users"
files.catbox.moe
files.catbox.moe
https://files.catbox.moe/60azcq.png
Update 2: Twitter account sharing the leak suspended as of minutes ago:
https://x.com/TheAntifaTurtle/ https://x.com/TheAntifaTurtle/status/1816199705598255470
I tried submitting this above URL just now because this link is now flagged (probably because of the domain allegedly distributing malware) but I think it got immediately shadow-banned (https://news.ycombinator.com/item?id=41070308).
Why would they used Okta to pass such list of "protected users" to the clients? vx-undeground also mentioned that requesting the endpoint from different locations return different status codes (404 and 403).
> vx-undeground also mentioned that requesting the endpoint from different locations return different status codes (404 and 403).
That in itself, I wouldn't read too much into either way; not particularly uncommon.
Tangentially, I find it especially important to question evidence which so easily confirms my preexisting biases.
I also wonder the same, but also it wouldn't be the first time in our industry that we see a tool or service used in a complete backwards manner.
1. Elon fired everyone that knew what they were doing and this is a product of incompetence. 2. It’s fake.
You'd think a "leak" would reveal several other, as of yet unknown users, right? Not even a few internal test accounts? Some of them are even misspelled.
Occam's razor is that someone doctored a random page and threw in every well-known salacious account and then screenshotted it.
And the list of slurs is so short and incomprehensive almost like someone made it for a screenshot based on whatever came to mind
- The Okta URL that's just a unix timestamp from 12 hours ago.
- There's a missing/wrong cert per the original screenshot (given all other points, likely just a local /etc/hosts override)
- A misspelled list of rightwing accounts
- A very esoteric list of slurs, with some British/Australian stuff specifically
- It's an Okta SSO config.
This is definitely fake.
on top of what others have said, this seems super fishy.
The subdomain cannot resolve as it does not have a valid cert, and okta does not have an API to do this.
Come on fellas, do better.
Regardless, there definitely exists a hidden whitelisting to "protected users" spread their hatred, otherwise accounts like this that explicitly use slurs (https://twitter.com/NsPostingFs) would be banned long ago.
CONNECTED(00000006) depth=2 C = US, O = DigiCert Inc, OU = www.digicert.com, CN = DigiCert Global Root CA verify return:1 depth=1 C = US, O = DigiCert Inc, CN = DigiCert TLS RSA SHA256 2020 CA1 verify return:1 depth=0 C = US, ST = California, L = San Francisco, O = "Okta, Inc.", CN = .okta.com verify return:1 write W BLOCK --- Certificate chain 0 s:/C=US/ST=California/L=San Francisco/O=Okta, Inc./CN=.okta.com i:/C=US/O=DigiCert Inc/CN=DigiCert TLS RSA SHA256 2020 CA1 1 s:/C=US/O=DigiCert Inc/CN=DigiCert TLS RSA SHA256 2020 CA1 i:/C=US/O=DigiCert Inc/OU=www.digicert.com/CN=DigiCert Global Root CA ---
the sub-domain in the image is "protected-users" - which makes no sense, btw.
I did some more digging. there is a SOA record for twitter.biz which says noc.twitter.com is responsible for it.
DATA: a.u09.twtrdns.net. noc.twitter.com. 2023050934 3600 600 604800 60 MNAME: a.u09.twtrdns.net. RNAME: noc.twitter.com. Serial: 2023050934 Refresh: 1 hour Retry: 10 minutes Expire: 7 days TTL: 1 minute
(that's noc @ twitter.com, by the way, the RNAME is an email address where you replace the leftmost dot with an @.)
Be careful with "that subdomain", though -- beeflourishing.okta.com also resolves, they've probably got a wildcard DNS entry and definitely have a wildcard SSL cert there.
None of that is evidence of this thing.
if it is real - keyword here being if - Twitter would have to had created its own parser for this. while not hard, why wouldn't they just... use something like JSON? YAML? TOML? ...XML?
i'm also not sure why would they host a configuration file like this out on the open web, when it's accessed strictly by the backend. why? what's the point...?
somethings fishy here, can someone clue me in on this...?
The Russia ones should be ringing alarm bells. How can TikTok take so much flak (some of this is reasonable, some is not IMH) but Elon is allowed to run a fifth column for Russia in the US?