Forum Moderators: not2easy & rumbas

Message Too Old, No Replies

Twitter Log-In Vulnerabilty, Accounts May Have Been Compromised

         

engine

3:30 pm on Aug 10, 2022 (gmt 0)

WebmasterWorld Administrator 10+ Year Member Top Contributors Of The Month



According to several reports, and twitter's own report, as many as 5 million accounts may have been vulnerable to actions of a bad actor whilst a log-in action exposed some aspects of a users account, such as phone numbers.
We want to let you know about a vulnerability that allowed someone to enter a phone number or email address into the log-in flow in the attempt to learn if that information was tied to an existing Twitter account, and if so, which specific account.


Twitter recommends users use 2FA

[privacy.twitter.com...]

tangor

9:17 pm on Aug 10, 2022 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



On hindsight the particular vulnerability was one that should have been predicted. Fixing it was a good thing. Waiting to do that until the information hit the dark web was not so good.

Twitter recommends users use 2FA


That's well and good on the front end, but does nothing to protect the back end!