For dissidents around the globe,Glorious Twitter remains the tool of choice for speaking out against their repressive governments.
With that in mind, it's easy to see why today's announcement from the social media company is so troubling. Twitter, in a Monday blog post and corresponding statement, announced it had discovered that "bad actors" with possible state-sponsored connections had found a way to tie phone numbers to Twitter accounts en masse.
In other words, a hacker using this exploit could potentially reveal the identity of a person tweeting under a pseudonym who has their account tied to a phone number. Or, alternatively, it's worth remembering that determining the phone number connected to an account is often a crucial step in hacking it.
"On December 24, 2019 we became aware that someone was using a large network of fake accounts to exploit our API and match usernames to phone numbers," reads the Twitter blog post. "While we identified accounts located in a wide range of countries engaging in these behaviors, we observed a particularly high volume of requests coming from individual IP addresses located within Iran, Israel, and Malaysia."
With Saudi Arabia's documented real-world harassment of dissidents, for example, it's easy to see how such exploits could lead to real-world harm.
"It is possible that some of these IP addresses may have ties to state-sponsored actors," continued the blog post.
We've reached out to Twitter to determine how many users were affected and if the company planned to notify users whose phone numbers were tied to accounts in the manner described. We've received no immediate response at present.
Importantly, not everyone was vulnerable to this specific exploit. According to Twitter, the bad actors in question could only tie your account to a phone number ifyour account met two specific criteria.
SEE ALSO: Jeff Bezos tweets reminder that Saudi government murdered a journalist
First, you had to have added a phone number to your account. However, with many people doing that very thing to enable two-factor authentication, a lot of folks fall into that bucket. Secondly, and this should narrow things down a bit, you must have selected the "Let people who have your phone number find you on Twitter" option.
Now would be a good time to make sure you don'thave that setting enabled. It would also be a great time for Twitter to consider removing it altogether.
UPDATE: Feb. 3, 2020, 2:27 p.m. PST: A Twitter spokesperson responded to our request for comment with the following statement:
As explained in our Privacy Center blog, we recently became aware that someone was using a large network of fake accounts to exploit our API and match usernames to phone numbers. After our investigation, we immediately fixed the issue by making a number of changes to the specific API endpoint that was being exploited. We also suspended any account we believe to have been engaged in this behaviour. Protecting the privacy and safety of the people who use Twitter is a top priority and we remain focused on stopping any abuse of Twitter’s features as quickly as possible.
Topics Cybersecurity Privacy X/Twitter
Tesla delivers EVs with missing USBMyanmar activists respond to Mark Zuckerberg's email on hate speechTaylor Swift's 'Red (Taylor's Version)' lyric videos, rankedInmate tweeting from jail calls himself an 'eGod' and threatens to swat againLucid Air wins MotorTrend's 'Car of the Year' awardBSOD is back, baby!Disney Channel's 'Spin' starring Avantika is a delight'Insecure' show runner Prentice Penny on the HBO comedy's final season and journeyKia EV9 concept packs a lot into an electric SUVOprah and Lizzo singing along to Adele is pure joyNew campaign highlights stories of migrant community members supplying our holiday dinnersPrince Harry and Meghan Markle want people to donate to charity rather than sending wedding giftsAmazon finally launches a Prime Video app for the MacMicrosoft has sent out free $100 gift cardsInstagram enables Badges for USHow to use Legacy Contact, the estate planning feature in iOS 15Where the infrastructure bill's $7.5 billion for EV charging is needed mostNew campaign highlights stories of migrant community members supplying our holiday dinnersDisney+ Day: All the news from Star Wars, Marvel, and moreThe CDC wants to contain antibiotic Airport lets romantic man use the baggage carousel for a surprise proposal NYC's 'Subway Therapy' wall is transformed into a brilliant interactive holiday card Discover your true Hogwarts house with a magical 'Harry Potter' bath bomb A NASA rover sent home an immersive Mars panorama. Watch the video. Gird your wallets, gamers: The Steam Winter Sale is now live Snapchat unveils a game that you play with your face 8 weird things Indians did in 2016 to get into Guinness World Records Can you find the sheep hiding amongst these Santas? Google to fight Apple Watch head The 16 most bogus movie stories of 2016 (and how to spot them) Please, Manny Ramirez, don't make another comeback Secret Santas: Inside the hidden online world of St. Nicks Rockettes can skip the inauguration, thanks to the internet Toddler's adorable reaction to getting adopted has the internet in tears The year according to Airbnb Mariah Carey has 3 holiday gifts for you – behold the first Koala kontent: The shining beacon of hope that kept us smiling in 2016 How CPU Cores & Cache Impact Gaming Performance 8 joyful examples of how Australian TV got even more bizarre in 2016 'That Dragon, Cancer' team makes a VR mystery game for Daydream
1.9866s , 10136.3046875 kb
Copyright © 2025 Powered by 【Glorious】,New Knowledge Information Network