Slashdot Mirror


Twitter Denies Breach of 32 Million Accounts (twitter.com)

An anonymous reader writes: "We have investigated reports of Twitter usernames/passwords on the dark web, and we're confident that our systems have not been breached," posted the company's security office, Michael Coates. In a blog post, he wrote that Twitter use HTTPS "everywhere" and secures account credentials with bcrypt, while also watching for suspicious account activity based on location, device type, and login history. Responding to recent reports of 32 million compromised accounts, he blamed malware and also recycled passwords, which mean "a breach of passwords associated with website X could result in compromised accounts at unrelated website Y."

"When so many breaches are announced in a short window of time, it may be natural to assume that any mention of 'another breach' is true and valid. Nefarious individuals leverage this environment in order to either bundle old breached data or repackage accounts from a variety of breaches, and then claim they have login information and passwords for website Z."

A security expert gave the same explanation to InformationWeek. And Brian Krebs recently pointed out that a Tweet claiming 73 million compromised Dropbox accounts was actually just recycling credentials from a 2013 breach at Tumblr. A recent breach of Mark Zuckerberg's Twitter account was attributed to a low-security password.

28 comments

  1. ok. by turkeydance · · Score: 1

    it was only 31,999,999.

    1. Re:ok. by sheepleherd · · Score: 1

      it was 32mega accounts, not 32mebi accounts

  2. Of course there was no "breach". by hey! · · Score: 2, Funny

    This is social media we're talking about. Stuff just got inadvertently shared more widely than anticipated.

    --
    Post may contain irony: discontinue use if experiencing mood swings, nausea or elevated blood pressure.
  3. Obligatory by Hognoxious · · Score: 1

    Well they would, wouldn't they?

    Famous unquotes of history: "Sure, I bumped the motherfuckers off." -- Al Capone.

    --
    Confucius say, "Find worm in apple - bad. Find half a worm - worse."
    1. Re:Obligatory by Anonymous Coward · · Score: 0

      In some alternate universe, that's a real quote.

  4. maybe somebody has a bunch of fake info by FudRucker · · Score: 1

    and they are trying to sell collections of usernames with fake passwords just to make a few bucks, they are low life bottom feeders looking for a quick buck

    --
    Politics is Treachery, Religion is Brainwashing
    1. Re: maybe somebody has a bunch of fake info by Anonymous Coward · · Score: 1

      Ugh, do people not even read the summary? Twitter let's you log in with an email address and password combination. If the someone used the same email address and password for, say, LinkedIn and Twitter, it would be easy to try all the LinkedIn credentials on Twitter and see if anything works. What is with this baseless and illogical speculation from people on here, especially when it's contrary to the story? Why is it so hard for people to read the summary now?

    2. Re:maybe somebody has a bunch of fake info by ShanghaiBill · · Score: 1

      and they are trying to sell collections of usernames with fake passwords just to make a few bucks, they are low life bottom feeders

      If they are polluting the underworld with fake info and ripping off even more malicious criminals, then that would be a public service.

    3. Re: maybe somebody has a bunch of fake info by FudRucker · · Score: 1

      i am so sorry, i am a Twitter junkie, and i just stopped reading at 140 characters, Twitter ruined me

      --
      Politics is Treachery, Religion is Brainwashing
  5. They were probably from other breaches by Anonymous Coward · · Score: 0

    People reuse passwords frequently. This was probably data harvested from other breaches and tested against Twitter. I suspect that Twitter is correct that they weren't breached, even though the accounts are likely compromised. These credentials shouldn't be up for sale, though, and we need better cooperation through Interpol to arrest and prosecute these criminals. The problem is that the police in countries like Russia won't do a damn thing and it's a haven for criminals. These are professional criminals who deserve to prosecuted as organized crime is, considering the scale of these operations and breaches. We also need widespread use of password management services, one time use passwords, and two factor authentication.

  6. Oops by Anonymous Coward · · Score: 0

    You'd think the head of a huge global social media company would know better than to secure his own social media accounts with the password "dadada".

    1. Re:Oops by Anonymous Coward · · Score: 0

      You'd think the head of a huge global social media company would know better than to secure his own social media accounts with the password "dadada".

      I'm sure he knows better than to use such a password on anything important.

      I'm also sure he knows better than to post anything important or revealing on Facebook. Or even to use it much at all.

  7. Quite amazing by JustNiz · · Score: 0

    How these retards live in denial amazes me.

    1. Re: Quite amazing by Anonymous Coward · · Score: 0

      Do you have any evidence to back up.your comment? Do you have anything that indicates Twitter was breached? If so, please present that evidence.

      Otherwise, you're just talking out your ass and should be modded as a troll. That seems to be really common around here.

      Twitter isn't denying that these credentials are valid. They're simply denying that were obtained by breaching Twitter's systems. I would suspect they're making this claim partly based on searching their systems for evidence of an intrusion and didn't find any. That wouldn't be living in denial but rather making a claim based on evidence.

    2. Re:Quite amazing by fuzzyf · · Score: 1

      Retards? Really? That is so.... mature of you.

      If someone hacked twitter they would get away with more accounts than just 32m. So password reuse from any other breach in the last 6 months seems like a fairly credible explaination IMHO.

  8. Some accounts have obviously been hacked by Anonymous Coward · · Score: 0

    with troll posts, like this one.

    1. Re:Some accounts have obviously been hacked by NotInHere · · Score: 1

      Trump often says "I like hispanics". It is always followed by "their leaders are smarter than our leaders, they are ripping us off".

      I doubt this is a troll post, unless you consider Trump to be a twitter troll (which is 100% legitimate although I don't agree with it).

  9. My Twitter password is.... by Anonymous Coward · · Score: 0

    twittertwat.

    If you can find the account it belongs to, it's yours.

    1. Re:My Twitter password is.... by Anonymous Coward · · Score: 0

      my password is: google.com

    2. Re:My Twitter password is.... by Anonymous Coward · · Score: 0

      my password is: google.com

      Hi Sundar.

  10. They are probably mostly by bobstreo · · Score: 1

    social media bots to promote whatever someone pays for.

    Briganding accounts to attack people you don't agree with.

    Command and control/status accounts for botnets.

    Dead drops for data

    Fake celebrities.

    Kind of like twitter in general.

  11. twitter is just an elaborate prank by Anonymous Coward · · Score: 0

    to pass the turing test by other means. if you can't raise the quality of the ai lower the bar for passing for human...

  12. vk 100M cleartext passwords by Anonymous Coward · · Score: 0

    Given unusual amount of Russian email accounts linked to twitter accounts, and vk's recent 100M breach with cleartext passwords; this is most likely due to someone trying out vk credentials against twitter and got through. One more reason to use unique passwords across sites.

  13. Twitter Cash by Anonymous Coward · · Score: 0

    So, let's see.

    Each time Twitter is hacked, they spend $1,000,000 dollars (US) to payoff media friendly "security experts" and business info sites like TheStreet (such as Jim Cramer) to say nice things about Twitter, how long does Twitter have before they burn through their cash?

    1 Month?
    1 Week?
    1 Day?

    Ha ha

  14. Happened to me by ArchieBunker · · Score: 1

    I created an account a few years ago but never did anything with it. When I did try and login I was now following hundreds of random Russian and Arabic accounts. I have since closed the account.

    --
    Only the State obtains its revenue by coercion. - Murray Rothbard
    1. Re: Happened to me by Anonymous Coward · · Score: 0

      Why didn't you accept Edith's and meatheads friends request?

  15. You can encrypt connections all you want by Anonymous Coward · · Score: 0

    You can but if there are covert government agents hired into these big companies how will you prevent the untrusted to be trustworthy with your data? This is true across all aspects of data collection. There are reasons there are laws against unreasonable searches. It isn't just because the searches are time consuming. They would be paid literally by your tax dollars to do it.

    It is because they can use your data to render you crippled and fuck you up. So why did you give it up in the first place? baaaaaaad sheeeeeep.

    https://en.wikipedia.org/wiki/Motives_for_spying

  16. Far too many services... by grahamtriggs · · Score: 1

    that require registration for no reason, and don't provide or make use of shared identity services.

    If people didn't have so many accounts all over the place, there wouldn't be the password reuse, or so many attack vectors.