{"id":198347,"date":"2020-02-06T06:20:52","date_gmt":"2020-02-06T03:20:52","guid":{"rendered":"http:\/\/ww-vb.mine.nu\/w108\/twitters-default-settings-could-be-exposing-identifying-information\/"},"modified":"2020-02-06T06:20:52","modified_gmt":"2020-02-06T03:20:52","slug":"twitters-default-settings-could-be-exposing-identifying-information","status":"publish","type":"post","link":"https:\/\/hameed.nwar.uk\/sa\/twitters-default-settings-could-be-exposing-identifying-information\/","title":{"rendered":"Twitter&#8217;s default settings could be exposing identifying information"},"content":{"rendered":"<p> [ad_1]<br \/>\n<br \/><img decoding=\"async\" src=\"https:\/\/cdn0.tnwcdn.com\/wp-content\/blogs.dir\/1\/files\/2019\/10\/Twitter-Safety-796x418.jpg\" \/><\/p>\n<div>\n<p>Twitter recently disclosed an \u201cincident\u201d in how the service handles phone numbers. The announcement declared that it had shut down \u201ca large network of fake accounts\u201d responsible for uploading lists of phone numbers and then using Twitter\u2019s own API to match them to individual usernames.<\/p>\n<p>According to the Electronic Frontier Foundation (EFF), this is precisely the type of activity used to create reverse-lookup tools: the types of services that match specific users, or their accounts, with an otherwise random phone number.<\/p>\n<p>Twitter, Facebook, and other social networks all offer the option to upload your contact list into the application to connect with other users. The APIs used to support these types of uploads often contain limitations to keep bad actors from exploiting the tools. But there\u2019s almost always a workaround. In Twitter\u2019s case one of the API limitations in place rejects anyone who tries to upload a list of sequential phone numbers \u2014 a clear indication that it\u2019s not a user uploading their contacts.<\/p>\n<p>But the security researchers who tipped Twitter off to the problem found a comically simple workaround: randomize the uploaded information to avoid sequential strings of numbers. This allowed them to match phone numbers to usernames for more than 17 million Twitter users, including celebrities and public officials.<\/p>\n<p>So far the problem only seems to affect Twitter accounts who have a phone number associated with their account, and have \u201cphone number discoverability\u201d enabled in their settings. If you\u2019re unsure, you can check the EFF\u2019s step-by-step guide to checking your settings here.<\/p>\n<p>According to <a href=\"https:\/\/privacy.twitter.com\/en\/blog\/2020\/an-incident-impacting-your-account-identity\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">Twitter<\/a>, the API exploit is believed to have originated from IP addresses in Iran, Israel, and Malaysia. \u201cIt\u2019s possible that some of these IP addresses may have ties to state-sponsored actors,\u201d a spokesperson wrote.<\/p>\n<p>It\u2019s not the first time Twitter has mangled the handling of users\u2019 phone numbers. In October the company fessed up to allowing advertisers to use phone numbers and email addresses \u2014 that users provided for \u201csafety and security purposes\u201d like two-factor authentication \u2014 to tailor audiences in its ad tracking system, known as Tailored Audiences and Partner Audiences.<\/p>\n<p>A <a href=\"https:\/\/help.twitter.com\/en\/information-and-ads\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">blog post<\/a> announcing the issue said:<\/p>\n<blockquote>\n<p><span>We cannot say with certainty how many people were impacted by this, but in an effort to be transparent, we wanted to make everyone aware. No personal data was ever shared externally with our partners or any other third parties.<\/span><\/p>\n<\/blockquote>\n<p>Twitter claimed the mistake was \u201cunintentional\u201d and \u201cinadvertent.\u201d<\/p>\n<\/p><\/div>\n<p><script async src=\"\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><br \/>\n<br \/>[ad_2]<br \/>\n<br \/><a href=\"https:\/\/thenextweb.com\/security\/2020\/02\/06\/twitters-default-settings-could-be-exposing-identifying-information\/\">Source link <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>[ad_1] Twitter recently disclosed an \u201cincident\u201d in how the service handles phone numbers. The announcement declared that it had shut down \u201ca large network of fake accounts\u201d responsible for uploading lists of phone numbers and then using Twitter\u2019s own API to match them to individual usernames. According to the Electronic Frontier Foundation (EFF), this is &hellip;<\/p>\n","protected":false},"author":1,"featured_media":198348,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2],"tags":[],"class_list":["post-198347","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-tie-world"],"_links":{"self":[{"href":"https:\/\/hameed.nwar.uk\/sa\/wp-json\/wp\/v2\/posts\/198347","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/hameed.nwar.uk\/sa\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/hameed.nwar.uk\/sa\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/hameed.nwar.uk\/sa\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/hameed.nwar.uk\/sa\/wp-json\/wp\/v2\/comments?post=198347"}],"version-history":[{"count":0,"href":"https:\/\/hameed.nwar.uk\/sa\/wp-json\/wp\/v2\/posts\/198347\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/hameed.nwar.uk\/sa\/wp-json\/wp\/v2\/media\/198348"}],"wp:attachment":[{"href":"https:\/\/hameed.nwar.uk\/sa\/wp-json\/wp\/v2\/media?parent=198347"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/hameed.nwar.uk\/sa\/wp-json\/wp\/v2\/categories?post=198347"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/hameed.nwar.uk\/sa\/wp-json\/wp\/v2\/tags?post=198347"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}