11 ms·
A Twitter app bug was used to match 17M phone numbers to user accounts
- mherdeg 7y ago> Over a two-month period, Balic said he matched records from users in Israel, Turkey, Iran, Greece, Armenia, France and Germany, he said, but stopped after Twitter blocked the effort on December 20. Sounds like the other thing Balic discovered (not explicitly published here) is the rate limit below which Twitter's anomaly detection will not notice that you are using an interesting API endpoint. > While he did not alert Twitter to the vulnerability, he took many of the phone numbers of high-profile Twitter users — including politicians and officials — to a WhatsApp group in an effort to warn users directly. Uh. I wonder how that went over?
- ec109685 7y agoDoesn’t really have anything to do with the Android app. He was using an api endpoint that anyone could hit. Step #1, turn two factor authentication on Step #2, have your phone number leaked because of a dumb feature.
- deogeo 7y agoI think these days, Twitter will suspend your account immediately after sing-up, for "suspicious activity", and require a phone number to re-enable it.
- Mirioron 7y agoAt this point it has to be on purpose, right? There is no way that Twitter has just overlooked this closing of accounts "for suspicious activity" for years right when the account is created.
- deogeo 7y agoOf course it is. If pressed, they will surely find a justification for it in reducing spam and bots. Less defensible is why they would wait to get a phone number until after you make an account. And of course, try not to compare it with the Chinese rules requiring phone number verification for online accounts...
- kick 7y agoI made one a week or two ago, followed some people, made a few tweets, and wasn't asked for a phone number. I wasn't even asked for a CAPTCHA. I deleted the account a few days later because Twitter is dull and the entire point of what I was trying to do was see if the rumors of immediate account flagging were true. They don't seem to be.
- newnewpdro 7y agoI made one a few months ago and it immediately did the suspicious activity provide phone number b.s. I've not tried again since, and considered twitter 100% off-limits after that experience since it's obviously just an effort to acquire phone numbers coupled to accounts and email addresses under the guise of "security".
- sdoering 7y agothanks. I registered an account lately and wondered why this happened. thanks for clarification.
- throwiay987 7y agowas the account you created with your personal information? because if you create a throwaway it will be flagged immediately, but if you use the image of a friend for example, you can continue for a couple of hours before getting flagged
- kick 7y agoIt had no personal information whatsoever, and the profile picture was of static noise.
- tohnjitor 7y agoIt could depend on which accounts you interact with.
- codedokode 7y ago
- ec109685 7y agoThe dumb feature is letting folks look up their friends by their phone number.
- ribosometronome 7y agoIt sounds like he spent two months extracting data through a flaw that's existed for years and then bragged about it after it got closed to his egregious usage. Is this considered normal or ethical behavior for a security researcher?
- thepangolino 7y agoThey literally ruined it for everyone else for the publicity. Typical of PR obsessed white hat script kiddies.
- sp332 7y agoThere's nothing white-hat about this. He accessed as much private data as possible, and didn't report the vulnerability to Twitter or to affected users.
- MiroF 7y agothis is grey hat at best
- Buge 7y agoWhat was ruined? And who ruined it?
- dredmorbius 7y agoAccess to what had until then been an 0day. Ibrahim Balic "ruined" it, though public bragging (which is not responsible disclosure).
- Buge 7y agoRuining access to a 0day sounds like a good thing to me. I don't want people to have access to 0days. Some people dislike the term "responsible disclosure" and believe it's not a moral imperative: https://hn.algolia.com/?query=author:tptacek%20responsible%20disclosure&sort=byDate&prefix&page=0&dateRange=all&type=comment https://hn.algolia.com/?query=author:tptacek%20responsible%2... Of course what Ibrahim did wasn't full disclosure either, so he shouldn't be fully congratulated. But bragging about it was better than keeping silent about it in this case.
- 1f60c 7y agoI think it was irresponsible to keep collecting more phone numbers, and I think he should've let Twitter handle informing users of this vulnerability. Had he used responsible disclosure, he could have claimed a nice bug bounty (between $280 and $2,940, according to [0]). [0]: https://hackerone.com/twitter
- chance_state 7y agoI'm always curious why these bug bounty programs for billion dollar companies pay so little. Why not make this a 10K, 25K bounty even if it's small potatoes? That amount is nothing to Twitter but might prevent what happened in this case (continued collection of data, public release before Twitter could notify users, etc). I've noticed this trend of painfully cheap bounties at most other tech giants too.
- DataWorker 7y agoSupply of labor. The lump of labor fallacy does not apply to software bugs.
- throwiay987 7y agoits literally the main reason i will never be in favor of this "responsible disclosure" It pays shit and also vilifies users for learning how the system was built
- sp332 7y agoKatie Moussouris has spoken a lot about this. The incentives are pretty complex. https://www.computerweekly.com/news/252450337/Bug-bounties-not-a-silver-bullet-Katie-Moussouris-warns https://www.computerweekly.com/news/252450337/Bug-bounties-n... https://www.zdnet.com/article/relying-on-bug-bounties-not-appropriate-risk-management-katie-moussouris/ https://www.zdnet.com/article/relying-on-bug-bounties-not-ap... https://threatpost.com/newsmaker-interview-katie-moussouris-on-improving-bug-bounty-programs/139488/ https://threatpost.com/newsmaker-interview-katie-moussouris-...
- 7y ago
- baybal2 7y agoVery relevant: https://news.ycombinator.com/item?id=21747424 https://news.ycombinator.com/item?id=21747424 Can this be an API leak which Chinese MSS used to track Chinese users? It may well as be if we believe that API wasn't implementing discoverability restrictions from privacy settings, and only hid users on the UI level. > Basically Twitter got pwned big time, and now denies it because GDPR will ruin them if breach is proven. Here is what Doubi's online followers figured: > State security got all phone numbers used for Twitter phone verification up to May 2019 and possibly till July. > Twitter haphazardly closed the breach in complete secrecy. > API hole explanation is excluded as people with 100% private accs got police visits. > People with foreign SIM cards also got into trouble. So the explanation that China compromised Twitter's SMS providers is also excluded, as its improbable that they did it in 4+ countries. > 2016 breach is also out of question. > The only explanation is that they got hold on a big piece of their user DB, or, worse, they have an active infiltrator in Twitter, or Twitter voluntarily cooperated.
- x0x0 7y agoWhat is SSR? Sorry for the dumb question; all I can find in my moment of curiosity is something about VPNs.
- jorblumesea 7y agoIf China got OPM, they could easily get most of Twitter's DBs. Most likely through Nationals passing vulns back to home state intelligence agency, who can exfil data but not finger the moles.
- 7y ago
- Can_Not 7y agoVery cool, also you can't use MFA authentication on Twitter without giving them your phone number.
- FeatureIncomple 7y agoTwitter now supports OTP 2fa as well.
- tialaramex 7y agoAnd FIDO Security Keys (U2F / WebAuthn) The particularly nice thing about FIDO Security Keys that's relevant here is even a hideously incompetent implementation doesn't hurt you. The Relying Party (in this case Twitter) doesn't end up with any secrets, they get an apparently random "cookie" value to give back to you when they want you to prove you've still got that key, and a elliptic curve public key that doesn't correlate to anything except your login on their site. If they screwed up so badly that the Twitter web site showed a user's U2F parameters to every single visitor looking at their tweets it not only wouldn't unmask any pseudonyms used (as a phone number definitely would) it wouldn't even make it easier to login in as that user. FIDO is the right thing everywhere that a second factor is needed, but even more so when you don't trust the implementers to do a good job.
- woadwarrior01 7y agoTwitter currently, does not allow adding more than one U2F keys to an account. It’s normative to have at least one extra key for backup. Google, Github, even Facebook support adding multiple hardware tokens to an account, but not Twitter. Also, if you try requesting for an API key, they insist that you add a phone number to your account.
- app4soft 7y ago> you can't use MFA authentication on Twitter without giving them your phone number. GitHub also require MFA authentication since this year. Does it mean that any MFA authentication now has same leaks?
- whywhywhywhy 7y ago“ he took many of the phone numbers of high-profile Twitter users — including politicians and officials — to a WhatsApp group in an effort to warn users directly” What on earth does this actually mean? And why does he still have a verified Twitter account or an account at all when he exploited it for 2 months without informing them?
- RicardoLuis0 7y agoI'm pretty sure it means, he made a WhatsApp group, and added/invited those high-profile people to warn them
- cipherzero 7y agoI agree. I read that he harvested 17M numbers for 2 months and have a hard time believing he’s a security researcher...
- A4ET8a8uTh0 7y agoI see stuff like this and I keep wondering whether it is a bug or an undocumented feature.
- 3fe9a03ccd14ca5 7y agoThe worst part about this is that twitter requires you to add a phone number. Why?? That’s very privacy hostile, since a phone number is very personal and identifiable. And it’s like a bait and switch. They don’t require it at sign up, but within a short time they’ll lock your account until you add it.
- xorcist 7y agoAny user database is massively more valuable with verified phone numbers. Even simple chat apps now require personally identifiable information to use.
- tjoff 7y agoWell that depends on what you intend to use it for... Since twitter don't have a legitimate need for it I'd never give them my number. A disposable number, maybe.
- Cyph0n 7y agoIs there a way to get a disposable number that cannot be tied to your identity somehow (in the US, at least)?
- vageli 7y ago> Is there a way to get a disposable number that cannot be tied to your identity somehow (in the US, at least)? I have never had to present id when buying a prepaid phone in the US.
- boring_twenties 7y agoWhat about cameras and facial recognition?
- angry_octet 7y ago
- _jomo 7y agoThis is a "feature", not a bug. Twitter keeps asking for phone numbers all the time and then suggests you also allow others to discover your account via phone number. So this guy merely enumerated a lot of phone numbers and found accounts of users who agreed to have their phone number publicly match their account.
- almost_usual 7y agoThe worst thing about this ‘feature’ argument is how it could be slightly tweaked into a CFAA violation.
- krick 7y agoNobody abused anything. If anyone should be sued for that, it's Twitter, not somebody who used their service exactly the way they invite you to do.
- krick 7y agoYeah. Not long ago I thought I can finally try Twitter, but 20 minutes in (just enough time to follow a couple of people and to start getting familiar with the UI) I found UI to be totally blocked by the demand I submit my phone or else. Naturally, I figured I don't need Twitter that much. So to call a feature nobody asked for which they went a long way to introduce a "bug"... yeah.
- deleted 7y ago[deleted]
- dx87 7y agoSame thing happened to me when I just wanted to sign up to follow some esports organizations. It says a phone number is optional during signup, then a few minutes after I create my account it becomes locked and I get an automated message saying that I'm suspected of being a bot, and the only way to unlock it is by giving them my phone number.
- xorcist 7y agoI recently started to use the "neo-banks" (fintech apps that may or may not be actual banks, mostly for payments). All of them offer an app and APIs and ways to discover which contacts use the same app via their phone number. Immediately following this I received highly targeted phishing sms messages that included links to plausible looking login pages. Perhaps this shouldn't be too surprising, but people will get burned and somebody will have to pay for it.
- ENOTTY 7y agoSo this is a different bug than the one Twitter cryptically e-mailed users about. Cool cool
- Lammy 7y agoThis must be the "Account Security Issue" Twitter e-mailed me about last week. I was wondering when they'd release more details: https://i.imgur.com/yjzMtLB.png https://i.imgur.com/yjzMtLB.png Transcription: "SUBJECT: Twitter Account Security Issue – Update Twitter for Android Hello, We recently fixed an issue that could have compromised your account. Although we don’t have evidence that this was exploited, we can’t completely confirm so we are letting you know. You can learn more about this issue here. Please update to the latest version of Twitter for Android as soon as possible to make sure your account is secure. We’re sorry this happened and will continue working to keep your information secure on Twitter. You can reach out to our Office of Data Protection through this form to request information regarding your account security. Thanks, Twitter" Edit: err, no, this appears to be something different still. Not a good week for Twitter: https://news.ycombinator.com/item?id=21847198 https://news.ycombinator.com/item?id=21847198
- codedokode 7y agoWhen sites collect phone numbers to "find friends", there is always a chance that they will be leaked. And even worse, someone having enough resources will check all existing phone numbers and get a mapping between numbers and accounts. This reminds me of a story posted on Russian site [1], where researchers managed to bypass Instagram's protection and find accounts by phone number. Sadly, I cannot confirm described method because their site requires a Google Account to find Instagram account by phone number. But if it's true it shows that even Facebook and thousands of its engineers cannot protect their users' data. [1] https://translate.google.com/translate?sl=ru&tl=en&u=https%3A%2F%2Fhabr.com%2Fru%2Fcompany%2Fpostuf%2Fblog%2F479094%2F https://translate.google.com/translate?sl=ru&tl=en&u=https%3...
- londons_explore 7y agoWhen you have a typical "find friends" feature, there is no way to secure it. Each friend can lookup a large address book of 1000 users, then very quickly the whole valid phone number space can be searched.
- FrozenVoid 7y agoWhen a website asks for a phone number i treat it as "please provide a DNA sample and birth certificate in triplicate" and close the tab. Its ridiculous to what ends consumers will go and accept as "privacy compromises". Hopefully GDPR will make these practices costly enough.
- skinkestek 7y agoCannot read it. I get lost in some "respect your privacy" nonsense.
- wdb 7y agoDid they report this breach as required by GDPR rules in the EUR? I can't imagine the GDPR rules don't reply to an American company when they are active in the EU? Especially, if they have (do they?) a branch in EU like for ads revenue or royalties to lessen the tax pay in Ireland or The Netherlands like Uber
- rootsudo 7y agoSimilar bug was used maliciously by HK Police for identifying Telegram users. Telegram now has an option for identification by number.