3 ms·
> In January 2022, we received a report through our bug bounty program > This bug resulted from an update to our code in June 2021 Does this mean the problem
by cecilpl2 4y ago
> In January 2022, we received a report through our bug bounty program
> This bug resulted from an update to our code in June 2021
Does this mean the problem existed for 7 months and nobody at Twitter noticed until they received a bug report?
- ameliaquining 4y agoThat's not unusual for a security bug; it's not like this stopped people from using the app in a way that they'd loudly complain about or that would show up in metrics.
- mcintyre1994 4y agoGiven they didn't think it was exploited they must have pretty poor logging and analytics around that part of their infrastructure. Someone managed to abuse it millions of times and they didn't know about it even after they'd fixed it and knew exactly where to look for abuse.
- Beaver117 4y agoCurious what kind of logs/analytics would you add and watch to catch something like this?
- tpxl 4y agoYou should notice a spike in any request logging metric if someone exploits this.
- deleted 4y ago[deleted]
- robryan 4y agoDepends on the normal usage, if someone was doing this across unique ips and slow enough that the usage change may be say 1% it wouldn't be noticed. A more sophisticated system that could look at the ips in use and compare to previously used ips for the accounts would notice something.
- bpodgursky 4y agoCleaning house before due diligence.