Twitter password recovery bug exposes 10,000 users' personal information

The company has notified those affected and will suspend users who exploited the bug

Twitter has notified 10,000 users that their email addresses and phone numbers may have been exposed due to a bug in the website's password recovery feature.

The incident happened over the course of 24 hours on an unspecified day last week, but the company alerted affected users on Wednesday.

"Any user that we find to have exploited the bug to access another account’s information will be permanently suspended, and we will also be engaging law enforcement as appropriate so they may conduct a thorough investigation and bring charges as warranted," Twitter said in a blog post.

It's not uncommon for website features to be abused to expose users' identifying information, such as email addresses and phone numbers. In 2012, Facebook imposed a limit on phone number searches through its mobile website, because a security hole could have allowed attackers to search through phone numbers sequentially and match them to existing users.

Other leaks of personal information can be hard for users to detect. For example, recent data breaches at online dating websites Adult Friend Finder and Ashley Madison understandably enraged a lot of users whose spouses, partners or friends did not know that they had accounts there.

However, many of those users didn't know that ,even before hackers broke into those websites, anyone could have checked if their email addresses were registered through the sites' password recovery systems.

Users should not count on websites to shield their affiliations with those services, because leaks of registration information are common. From a security perspective, users valuing their privacy should take advantage of tools available to protect their accounts from possible hijacking, for example by enabling two-factor authentication when offered.

Twitter offers a feature called "login verification" that requires users to supply one-time-use codes sent to their phones in addition to their passwords when they authenticate. In addition, Twitter offers the option to require additional information, such as the user's email address or phone number, when initiating password resets. This option can be found on the account's security and privacy settings page. Without it, initiating a password reset requires only the account's username.

Twitter users should also consider using a strong password or passphrase of 10 or more characters, periodically reviewing their accounts' login histories, and checking their account application tabs and revoking access to any applications that are no longer used.

Join the PC World newsletter!

Error: Please check your email address.

Our Back to Business guide highlights the best products for you to boost your productivity at home, on the road, at the office, or in the classroom.

Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.

Lucian Constantin

IDG News Service
Show Comments

Most Popular Reviews

Latest News Articles

Resources

PCW Evaluation Team

Azadeh Williams

HP OfficeJet Pro 8730

A smarter way to print for busy small business owners, combining speedy printing with scanning and copying, making it easier to produce high quality documents and images at a touch of a button.

Andrew Grant

HP OfficeJet Pro 8730

I've had a multifunction printer in the office going on 10 years now. It was a neat bit of kit back in the day -- print, copy, scan, fax -- when printing over WiFi felt a bit like magic. It’s seen better days though and an upgrade’s well overdue. This HP OfficeJet Pro 8730 looks like it ticks all the same boxes: print, copy, scan, and fax. (Really? Does anyone fax anything any more? I guess it's good to know the facility’s there, just in case.) Printing over WiFi is more-or- less standard these days.

Ed Dawson

HP OfficeJet Pro 8730

As a freelance writer who is always on the go, I like my technology to be both efficient and effective so I can do my job well. The HP OfficeJet Pro 8730 Inkjet Printer ticks all the boxes in terms of form factor, performance and user interface.

Michael Hargreaves

Windows 10 for Business / Dell XPS 13

I’d happily recommend this touchscreen laptop and Windows 10 as a great way to get serious work done at a desk or on the road.

Aysha Strobbe

Windows 10 / HP Spectre x360

Ultimately, I think the Windows 10 environment is excellent for me as it caters for so many different uses. The inclusion of the Xbox app is also great for when you need some downtime too!

Mark Escubio

Windows 10 / Lenovo Yoga 910

For me, the Xbox Play Anywhere is a great new feature as it allows you to play your current Xbox games with higher resolutions and better graphics without forking out extra cash for another copy. Although available titles are still scarce, but I’m sure it will grow in time.

Featured Content

Latest Jobs

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?