Twitter Says That Stolen Data From Them Isn’t From Them

  • January 12, 2023
Infosec

If you have given up on following news about Twitter, I don’t blame you, but there as been a batch of ~400 million user records being sold online and marketed as coming from breaching Twitter’s systems.

Today Twitter is saying that there was “no evidence” of that data coming from Twitter’s systems.

After a comprehensive investigation, our Incident Response and Privacy and Data Protection teams concluded that:

  • 5.4 million user accounts reported in November were found to be the same as those exposed in August 2022.
  • 400 million instances of user data in the second alleged breach could not be correlated with the previously reported incident, nor with any new incident.
  • 200 million dataset could not be correlated with the previously reported incident or any data originating from an exploitation of Twitter systems.
  • Both datasets were the same, though the second one had the duplicated entries removed.
  • None of the datasets analyzed contained passwords or information that could lead to passwords being compromised.

Therefore, based on information and intel analyzed to investigate the issue, there is no evidence that the data being sold online was obtained by exploiting a vulnerability of Twitter systems.

There are two problems with this kind of statement:

  1. “No evidence” doesn’t mean it didn’t happen.
  2. How can anyone reasonably trust Twitter with this evaluation?

Whether you like Elon Musk or not, he’s all over the place, going down rabbit holes of conspiracy theories, and has gutted Twitter of talent, either directly or indirectly, especially in areas such as security. Even the rapidly shrinking group of people who still think Elon is a genius would have to take a deep breath and a LONG pause before believing a report like this because of the repetitional damage he has caused to Twitter and his own brand.

Trust matters a lot with these kinds of reports, and Twitter has none.

Related Posts

LinkedIn is Going Great

🚨🔥AI will obviously solve everything because hype is never ever wrong. Do you want to know a thing that will help you?! I have an AI thing that does stuff like, I don’t know, let’s say sales or marketing…whatever. It’s amazing though and it won’t be replaced in a matter of days by a new model.

Read more

Software Development is Dead, Long Live Developers!

“If you don’t learn to code, in ten years it will be like being illiterate!” That was what someone exclaimed on a panel discussion I was on in 2013. It was a talk about bringing technology and entertainment together held in Beverly Hills and hosted by a coding bootcamp company. Two of the people on the panel were from a different bootcamp company, and then there was me, an actual technologist working in entertainment.

Read more

Apple Intelligence Summaries Are a Mess

Jason Snell over at Six Colors takes Apple to task over the current state of their Apple Intelligence notification summaries. He’s 100% right. They are bad, especially when summarizing news, and that’s unacceptable even with the “beta” tag. Take a look at his included example: A non-apology and the promise of a warning label isn’t enough.

Read more