22 ms·
"@" on Twitter
- isp 8y agoAt least two usernameless Twitter profiles exist: https://twitter.com/intent/user?user_id=34313404 https://twitter.com/intent/user?user_id=34313404 https://twitter.com/intent/user?user_id=71996998 https://twitter.com/intent/user?user_id=71996998 (credit: https://twitter.com/FakeUnicode/status/989868697660477440 https://twitter.com/FakeUnicode/status/989868697660477440 ) It is possible to retweet-with-quote the tweets, but not to retweet directly or (as far as I can tell) to link to individual tweets directly. EDIT: It is possible to link to individual tweets. Added links. The user says (tweet_id 989794618467409920 - https://twitter.com/i/web/status/989794618467409920 https://twitter.com/i/web/status/989794618467409920 ) that there are "many bugs" using the account in various clients. tweet_id 829989674353573889 ( https://twitter.com/i/web/status/829989674353573889 https://twitter.com/i/web/status/829989674353573889 ) may be my all-time favourite tweet. (A tweet by @, with name @, contents @)
- enthdegree 8y agoHow could such an account have been created?
- oh_sigh 8y agoHard to say without knowing the code, but one common problem is to do something like length checking a username to ensure it is a certain length, and then later stripping out illegal characters.
- deleted 8y ago[deleted]
- jakevn 8y agoPossibly a difference in implementation of unicode between validation and persistence/use. Validates successfully due to one or more "valid" unicode characters -> translated to zero characters due to stripping of invalid unicode character at some point after validation.
- brobinson 8y agoMaybe related to MySQL's 3-byte "utf8" charset which doesn't actually support unicode properly? (you are supposed to use "utf8mb4" nowadays though a lot of material still refers to "utf8")
- joombaga 8y agoFound this out when someone pushed a git commit message with a 4byte emoji and it broke our CI server -_-
- tedmiston 8y agoRegex gone bad?
- wpietri 8y agoI asked somebody who used to work there, and the answer I got was that there are a bunch of accounts from back before validation was as tight as it is now. Which seems reasonable to me. At-replies were not something that Twitter started with, but instead were community-driven with software support added later: https://blog.twitter.com/official/en_us/a/2008/how-replies-work-on-twitter-and-how-they-might.html https://blog.twitter.com/official/en_us/a/2008/how-replies-w... It's a good reminder that it's always easier to relax restrictions than to tighten them. But then again, if Twitter early on were run by the sort of people who were inclined to lock down everything, it might not have evolved enough to be really useful to people. I hazily remember the Friendster guy getting really mad that people were creating accounts for non-human things that they loved, like cities and bars and companies. I think he went on a banning spree. Instead of saying, "Look how much people love my platform! Let me support them in their efforts."
- CommieBobDole 8y agoIf I recall correctly, when Google Plus was new and people were excited about it, a whole bunch of companies flocked to the site to set up accounts for their businesses. But Google hadn't launched the "business account" functionality yet, so they banned them all. I guess Google Plus and Friendster are good examples of how that mindset works out.
- Gigablah 8y agoBecause nobody could conceivably impersonate a business and cause all sorts of legal and PR issues.
- computerfriend 8y agoJust like nobody could impersonate a person?
- Gigablah 8y agoThat's already a given. We are all, in a way, impersonating other (mostly insufferable) persons.
- cyberferret 8y agoMVP mania perhaps? You know, the old chestnut about "You have to get the shoddiest, most ethereal, stuck together with sticky tape and chewing gum version of your app out there to get market validation before you do some serious development work on it" ideology that is always being touted in the startup world... It tends to lead to this sort of technical debt.
- hultner 8y agoTo be honest at least in this case it’s probably worth it. It great to have something delivered so we don’t waste enormous energy on building features no one ends up wanting.
- laumars 8y agoMVP doesn't necessarily mean a product is buggy. It means a product excludes nice-to-have features that doesn't add immediate value. Basic validation is something I've always pushed for even for MVPs as that often goes hand in hand with platform security (another thing I still push for in MVPs)
- notyourwork 8y agoAnother case in the land of per client validation handled differently and mostly incorrectly.
- ChuckMcM 8y agoThat must be Bobby Droptables twitter account :-)
- blackflame7000 8y agohttps://xkcd.com/327/ https://xkcd.com/327/
- dghughes 8y agoThe modern twist to that seems to be little miss Infinity https://www.reddit.com/r/javascript/comments/8f57i1/psa_there_are_over_1000_people_in_the_us_named/ https://www.reddit.com/r/javascript/comments/8f57i1/psa_ther...
- paultopia 8y agoNow I want to change my name to NaN
- make3 8y agoyou probably don't, if the story about the cars with plates on a variations of "NO PLATE" is any indication https://www.snopes.com/fact-check/licensed-to-bill/ https://www.snopes.com/fact-check/licensed-to-bill/
- oneeyedpigeon 8y agoWow. Problem one: applicant writes "no plate" instead of leaving it blank or writing in a crossed line. Problem two: so do the law enforcement officials! The former is a silly mistake; the latter should be a learning opportunity.
- Keloo 8y agoMaybe try car plate sql injection. :D http://1.bp.blogspot.com/-URBVGKEBRss/U0GgQetIwEI/AAAAAAAAC20/b0DEdUTSCwo/s1600/i.img.jpe http://1.bp.blogspot.com/-URBVGKEBRss/U0GgQetIwEI/AAAAAAAAC2...
- 8y ago
- geuis 8y agoHow big is twitter’s engineering department? Their mobile website doesn’t even load the content of the tweet. Yesterday it was throwing an error that the api was rate limited. For their own site! They’ve been systematically destroying their own foundation by alienating the developer community for years and they can’t even get their own product to work reliably.
- donttrack 8y ago... And they literally just have to show you 280 characters. Thank God they are not building flying cars..
- zaxomi 8y agoAnd to show you that 280 characters they need to download about 6 kbyte css, 4 kbyte javascript, 17 kbyte Google analytics, 26 kbyte jquery, 1.5 kbyte favicon, and some images... Total about 100 kbytes.
- oneeyedpigeon 8y agoIt's almost as if "they literally just have to show you 280 characters" is a bit of an oversimplification.
- FridgeSeal 8y agoI think the point they were making was that they do all this extraneous stuff as well: if I’m looking at a single tweet, why on earth does it need to serve that much JS up? Why on earth is it not a simple HTML page with the information on it?
- FridgeSeal 8y agoMobile Twitter is maybe the single most useless website I’ve ever had to use lol. Clicking on a link to a tweet has 1/20 chance of ever actually loading the tweet. All other occurrences are evenly split between loading nothing except the top bar and calling it a day, and throwing an error message. Reloading the directly or using the reload button they provide will usually result in the rate limiting message. I don’t even bother clicking on twitter links anymore. I just hope it worked for someone else and they paste the contents in the comments.
- tedmiston 8y agoSo, it seems like it's not possible to view this person's profile (at least on the web app in Safari)? Also can't retweet them.
- cromwellian 8y agoReminds me on the old Commodore 64 Quantum-Link service (former version of AOL), there was a hack called 'Q-Armor' where you could get a username of all spaces, and no sysops or any chat room managers could kick you, or do anything to your account.
- giarc 8y agoBecause they couldn't determine how many spaces your username was or because of some other bug?
- joebergeron 8y agoPresumably because whitespace is stripped between command arguments, so something like "KICK <USERNAME>" would be useless.
- wolco 8y agoQ-Link was great for its time.
- rasz 8y agopeople griefing in online games (hacks/aimbots) often run with nicks like ||||||||||II||I|||||||||||||II1111|||||||IIIIIIIIII||||||||||||
- donatj 8y agoMy friends AIM account back in the day was essentially this. He basically had to find you.
- sizzle 8y agoI used to use aim chat booters by a blog named 'esoteric code' program was called subterfuge. Familiar with it by any chance? I thought it was brilliant.
- alanh 8y ago(not downvoting you, but your comment makes no sense at all to me)
- deleted 8y ago[deleted]
- ClassyJacket 8y agoSlightly related but very interesting: the 2010 Twitter bug where simply tweeting "Accept [username]" would automatically force them to follow you. My understanding is that for the sake of simpler interfaces such as SMS, which they let hold the whole service back for a long long time, they had a "follow [username]" feature - and if the person had to approve follow requests, it would send one to them. To accept the request, you just sent "accept [username]" and the follow would happen. However, they never actually checked that a request had ever been sent before allowing you to accept it, allowing you to simply force anyone to follow you with a single tweet. Next time you make a seemingly obvious mistake, don't feel too bad. Even Twitter did it. https://techcrunch.com/2010/05/10/does-this-twitter-bug-force-anyone-to-follow-you/ https://techcrunch.com/2010/05/10/does-this-twitter-bug-forc...
- CGamesPlay 8y agoA similarly lulzy but much more sinister-looking bug happened at Facebook, where an index into an array of users was mistakenly treated as a user id, so the message intended for user 4 in the array ended up going to the user with ID 4, aka zuck.
- weberc2 8y agoThat sounds like a pretty PHP-specific bug. Downvoters: most programming languages don’t silently convert strings (i.e., usernames) to array indices. Even Python doesn’t do this. While this particular bug probably wouldn’t be possible in most other languages, I’m only commenting because it’s rare and amusing to see bugs that are so language specific. I’m not making a generic “lol PHP” joke.
- ldjb 8y agoFor a while I had my display name (as opposed to @ handle) on Twitter set to the empty string. It didn't cause major issues as far as I could tell, though it would cause some Twitter clients to display my tweets unusually. I achieved this by entering a greater than symbol (>) in the input field. Twitter presumably tried stripping any HTML tags, which resulted in an empty string. I'm not sure if this still works; they might have fixed that bug. Presumably something similar happened with the accounts that have empty @ handles.
- hk__2 8y ago> I achieved this by entering a greater than symbol (>) in the input field. Twitter presumably tried stripping any HTML tags, which resulted in an empty string. I'm not sure if this still works; they might have fixed that bug. I just tried it and got the following error: > Name can't include 'invalid characters' Note how it doesn’t define "invalid characters".
- warent 8y agoIs product quality degrading on the internet over time? It used to be that once a week or longer I would find some amusing bug. But now it's not uncommon for that I encounter dozens of bugs daily on various popular services that are worth $millions or $billions, which is just obnoxious. Not only that, but usually the services have no way of filing a bug report or getting in touch with support. It seems like internet giants are becoming too big for their britches, and also they're forcing each other into this insane cycle of "ship first, fix later" just to stay competitive. What can we do about this, if anything?
- jcadam 8y agoNothing. It seems the secret to success in software is shipping as fast as possible, and so far the market has proven that users are extremely forgiving of bad quality. And bad security. And hostile privacy practices. Users suck.
- mattigames 8y agoExactly, you could be killing a baby for each HTTP request and they wouldn't care, as long as its useful and don't costs them a dollar.
- rco8786 8y agoYou encounter dozens of bugs daily? That doesn’t really pass the smell test.
- jimktrains2 8y agoAcross multiple services 5hat seems right. So much stuff has broken or buggy UI it's not funny.
- rco8786 8y agoConsider that the bare minimum for dozens is 24...
- thought_alarm 8y agoPerhaps we should go back to Usenet and IRC?
- cottsak 8y agoI love how the routing is all borked and you can't properly interact with that account.
- dghughes 8y agoMichael from Vsauce mentioned this on his Twitter today and mere minutes later @ replied "Hiya!" and I burst out laughing. https://twitter.com/tweetsauce/status/989899710176509952 https://twitter.com/tweetsauce/status/989899710176509952
- acobster 8y agoI thought it was funny and kind of charming that Vsauce is the single account they follow.
- nevi-me 8y agoIt's a lesson for us to learn when building services that people create accounts on. There's another one, https://twitter.com/@home https://twitter.com/@home. It redirects back to Twitter's home page. I discovered this while looking for "@home", which is a homeware store.
- BillinghamJ 8y agoThat will happen for any reserved names where it is used for a page rather than registered by a user. e.g.: http://twitter.com/@search http://twitter.com/@search
- emmelaich 8y agoIn the very early days of Google, searching for $@ or $* or some other shell-sensitive character combos produced strange results. I never did push it to the point of security exploitation.
- blattimwind 8y agoI've seen a similar bug in a web forum where someone wondered why "ke$ha" is rendered as "ke". "ke$DB" was quite interesting.
- tempodox 8y agoSo, did the devs programming the username field forget to sanitize text input, or were they just working without a spec? Neither scenario would be particularly surprising.
- berendk 8y agoThis XKCD[1] to my mind. [1] https://xkcd.com/1963/ https://xkcd.com/1963/
- acobster 8y agoSame.
- frou_dh 8y agoIt seems a bit gross when usernames and normal pages are mashed into the same namespace, e.g. https://twitter.com/search https://twitter.com/search I guess Github does the same: https://github.com/pulls https://github.com/pulls Reddit has the nice /u/... thing, but I suppose that is a bit awkward when saying URLs out loud.
- Operyl 8y agoI usually just say “u slash username” or “r slash subredditname.” Not terribly awkward.
- kiliankoe 8y agoEspecially since it forces you to basically map out your entire site before letting users register accounts. Or you rename users squatting your routes later on, which seems like a terrible idea.
- eddyg 8y agoOr, you take advantage of lists like this[0] and make sure users can’t pick names that would be “problematic”. [0] https://zimbatm.github.io/hostnames-and-usernames-to-reserve/ https://zimbatm.github.io/hostnames-and-usernames-to-reserve...
- kiliankoe 8y agoAh thanks, I was looking for that earlier and couldn't find it :)
- neya 8y agoThis is a real problem. It's also a security issue. One of the reasons why we created this database of huge disallowed usernames: https://github.com/dsignr/disallowed-usernames https://github.com/dsignr/disallowed-usernames
- umanwizard 8y agoAnecdotally, practically anyone who's part of "US internet culture" of my generation (I'm 28) understands what you mean when you say "arr slash worldnews" and how to navigate there.
- sygma 8y agoReminds me of some artists who included a script tag in their book title so that when the book got listed on online shops it would make the page spawn a JavaScript alert()
- Kliment 8y agoHere's a talk by said artists (sorry about the title) that talks about this and their other work https://media.ccc.de/v/34c3-9278-ecstasy_10x_yellow_twitter_120mg_mdma https://media.ccc.de/v/34c3-9278-ecstasy_10x_yellow_twitter_...