Taking TF's reporting at face value, would twitter be able to sufficiently identify a user? Does Twitter have the address, real names, etc. of its users?
Taking TF's reporting at face value, would twitter be able to sufficiently identify a user? Does Twitter have the address, real names, etc. of its users?
Why would Twitter voluntarily run that sort of query to satisfy a subpoena?
Whether it's difficult and risky for the average user depends on the threat model. "Twitter doesn't directly have my name, address, or phone number sitting in their database next to my account" is easy. Other things are more difficult.
The only thing that falls apart is the IP address identification, which is only a very small signal for identifying an internet user. X/Twitter undoubtedly has more identity information than just an IP address.
That said I don't know how much browser fingerprinting Twitter might be doing and if fingerprints from other services might be possible to crossreference. Much higher risk is probably visiting other sites both with and without the VPN using the same browser without thinking about it and thus leaking your fingerprint or even account cookies that way. Or if you don't run a filter then visiting a site without the VPN that embeds Twitter tracking assets would leak to them directly.
You sue the social media to get the IP at time, then sue ISP with the reference to that suit to get IRL identity from IP + time, then sue the person using that IRL identity. Some parts of this has been simplified because courts having to process 3 lawsuits to move just couple grands for just a "@username I murder you this particular way and time" is ridiculous.
What if the accused used Tor or foreign VPN? I guess the matter goes to local FBI equivalent?
Unless someone spent a lot of effort to avoid it, any person with a IP address probably had something that established a connection at some point to one of those companies and that connection probably contained an identifier of some kind. It might have been a software update check, some user telemetry, a browser tab open to social media, a connection to icloud etc.
Once you get a match you ask that company for a list of every IP address that was ever used by that user/account, and in that list you should get a bunch of connections from an IP that belongs to a regular ISP. Very few people are using a VPN 100% of the time.
People are not always good at infosec for convenience, and Twitter's design for this was incompetent even before Musk's acquisition.