Follow

HackerOne covered the vulnerability back in January.

which allowed anyone to enter a phone number or email address, and then find the associated twitterID

counter.social/@ecksmc/1094025

I have obtained multiple files, one per phone number country code, containing the phone number <-> Twitter account name pairing for entire country’s telephone number space from +XX 0000 to +XX 9999.

Any twitter account which had the Discoverability | Phone option enabled in late 2021 was listed in the dataset.

The option referred to here is a setting which is pretty deeply hidden within Twitter’s settings, and which appears to be on by default. Here’s a direct link.

twitter.com/settings/contacts

security specialist who yesterday tweeted about the issue had their Twitter account suspended the same day. Internationally recognized computer security expert Chad Loder predicted Twitter’s reaction, and was confirmed right within minutes

Ben Lovejoy

- Nov. 25th 2022 6:36 am

security specialist who yesterday tweeted about the issue had their Twitter account suspended the same day. Internationally recognized computer security expert Chad Loder predicted Twitter’s reaction, and was confirmed right within minutes

A massive Twitter data breach last year, exposing more than five million phone numbers and email addresses, was worse than initially reported

9to5mac.com/2022/11/25/massive

@ecksmc
Thanks for posting this thread and the link to the settings. Thankfully, mine had been turned off./deselected.

@ecksmc fun story. I joined burd to learn more from my college instructors and their private research. I did not know about that setting.

I had a "conversation" about AI and its misuses which led to privacy violations in USA. Someone did not agree with me.

Since then my number, because of that particular setting, has been severely compromised. If I wasn't an infosec person, I have no idea what I would have done.

Sign in to participate in the conversation

CounterSocial is the first Social Network Platform to take a zero-tolerance stance to hostile nations, bot accounts and trolls who are weaponizing OUR social media platforms and freedoms to engage in influence operations against us. And we're here to counter it.