6 ms·
This is the text of the message I received (once for each account, all created back around the same time January 2007): Hi, dewitt Twitter believes that y
by dewitt 14y ago
This is the text of the message I received (once for each account, all created back around the same time January 2007):
Hi, dewitt
Twitter believes that your account may have been compromised by a website or service not associated with Twitter. We've reset your password to prevent others from accessing your account.
You'll need to create a new password for your Twitter account. You can select a new password at this link: ***
As always, you can also request a new password from our password-resend page: https://twitter.com/account/resend_password
Please don't reuse your old password and be sure to choose a strong password (such as one with a combination of letters, numbers, and symbols).
In general, be sure to:
Always check that your browser's address bar is on a https://twitter.com website before entering your password. Phishing sites often look just like Twitter, so check the URL before entering your login information!
Avoid using websites or services that promise to get you lots of followers. These sites have been known to send spam updates and damage user accounts.
Review your approved connections on your Applications page at https://twitter.com/settings/applications. If you see any applications that you don't recognize, click the Revoke Access button.
For more information, visit our help page for hacked or compromised accounts.
The Twitter Team
Best of luck to the security and support teams. Days like these are not fun at all.
- dewitt 14y agoAnd for people trying to puzzle out who was impacted, several these accounts (all with random strings for passwords, btw) were barely ever used at all, often not for several years. The only thing they had in common was their early creation date, and hence relatively low user ids. My guess is that the hackers simply scanned user ids starting from 1 and worked their way up.
- guelo 14y agoThat would explain the high incidence among hackers, who are more often early adopters. I've been surprised by how many people I've heard of getting the email, including people in this comment thread and myself, considering only 250,000 emails were sent out of their couple hundred million accounts.
- baconhigh 14y agoany chance it was through an app that you allowed access?
- dewitt 14y agoNo. I suspect their email template was out of sync with this particular incident.
- jandy 14y agoI've been suspecting the same thing. Two of my accounts received the email, both created several years ago, while none of my newer accounts have been compromised.
- timdorr 14y agoAre there big gaps in the early user ids? I'm 4145801 and received this message.
- nevster 14y agoYeah - I'd say there are big gaps. I'm 1577581 and got the email. You can check people's join dates here http://www.whendidyoujointwitter.com/ http://www.whendidyoujointwitter.com/
- lacerus 14y agoThanks! I'm 793689, joined 25 February 2007, and got the e-mail.
- bitbckt 14y agoTwitter employee, here. At one point in time, auto_increment_increment was > 1 on the MySQL master for uid generation. This led to many holes in the uid range.
- newbie12 14y agoYeah I received the email from Twitter, account created in April 2007 and haven't tweeted since 2010.
- brucehoult 14y agoOnly 2950 accounts with IDs from 1 to 6136 still exist, so there's been pretty much a 50% attrition rate at that level.
- fredoliveira 14y agoI'm seeing a ton of people I know on twitter complain - I'm user 5511, and these are people who joined at the very beginning too - so your theory is indeed apparently correct. I got an email myself, and reset my already super complex password.
- jschuur 14y agoUser 5,260 and an active, daily users. Got an email that my account was impacted.
- iomike 14y ago3750 and ditto.
- p4bl0 14y agoI don't know what # user I am (how can I get this information?) but my twitter account was also created in 2007 (on the 8th of April says whendidyoujointwitter.com) and is still active. Also received the email.
- chris24 14y agoThe Twitter API exposes a user's ID. Some Twitter clients (like Tweetbot) show this information. You can use http://mytwitterid.com/ http://mytwitterid.com/ to find yours.
- paulgb 14y agoOr just view source on twitter.com (after logging in) and search for the first instance of "data-user-id"
- fakeer 14y agoThat means https://api.twitter.com/1/users/show.xml?user_id=12 https://api.twitter.com/1/users/show.xml?user_id=12 13 14 were hacked too. And those must have been accounts of interest if not of others' and the gentry.
- Alex3917 14y agoThis is bullshit. I just got this message, and until I signed into HN I had no idea if Twitter was hacked or if there was a problem on my end. Which would be alarming, because all of my passwords are 30+ random characters, and I never reuse passwords across websites. Fuck you, Twitter.
- KMag 14y agodef random_password(n): random_char = '1' # chosen by fair dice, guaranteed random return random_char * n Just kidding. That stinks. I'm guessing your password was quite strong. Any idea how many bits of entropy it was? It sounds like at this point Twitter sent out the email in parallel with trying to figure out how these compromises happen. Since they salt the hashed passwords, they don't know how complex your password was. Of course, you should still change your password. I changed my 80-bit Linkedin password after it was stolen.
- pearkes 14y agoJust a guess here, but maybe to get the emails out to users fast they re-used an existing template that was intended for resets due to 3rd party incidents.
- morganb180 14y agoAgree. I didn't know what was going on. I use 17 random char passwords too and the way the email is written makes it sound like I did something wrong.
- ForFreedom 14y ago
- maukdaddy 14y agoI'll add a datapoint here too. I also had my password reset. Creation date: March 2007 User ID: 2,7xx,xxx
- djhworld 14y agoSurely these sorts of messages are prime candidates for opportunist phishing attacks?