Business

What Happened With Twitter’s ‘Bug’ And Why It Told Everyone To Change Their Passwords

[Shutterstock - rvlsoft]

Daily Caller News Foundation logo
Eric Lieberman Managing Editor
Font Size:

“Out of an abundance of caution” Twitter advised all users Thursday to change their passwords.

The appeal, though, wasn’t because it was hacked or infiltrated. Rather, it was due to the social media company recently discovering that account information like passwords were left exposed, albeit internally.

The culprit: “a bug.”

Due to an error in Twitter’s computers system, “passwords were written to an internal log before completing the hashing process,” Twitter CTO Parag Agrawal wrote on a company blog post first disclosing the situation. “We found this error ourselves, removed the passwords, and are implementing plans to prevent this bug from happening again.”

Agrawal explained that company procedure is to “mask” passwords through hashing, which will replace the actual password with an obscure set of numbers, letters, and potentially other characters to be stored. The passwords in this instance, however, were never obfuscated through the hashing process.

Twitter is sure to claim that its investigation “shows no indication of breach or misuse by anyone.”

But people may never really be able to tell for sure — at least until someone accesses the several other accounts that sync with Twitter.

“This is a huge deal because Twitter is often used as a single sign-on mechanism into other websites,” George Avetisov, CEO of HYPR, a leader in “decentralized authentication,” told The Daily Caller News Foundation. “A compromised Twitter password may be used to login on completely unrelated websites.”

Despite Twitter’s outward confidence of the bug’s dubious consequences, Aleksandr Yampolskiy, co-founder of SecurityScorecard, a company that monitors and grades the cybersecurity health of any organization, says “we don’t know,” and Twitter’s actions, or lack thereof, are telling of the potential repercussions.

“Having an unencrypted password in the logs certainly increases the chances of that happening,” Yampolskiy said in regards to the chances of individuals’ information being exposed. “Even if an attacker compromised Twitter’s systems — if the passwords are properly protected, he’d have to reverse the hash, which is a very hard and often impossible process. In this case, however, he wouldn’t have to do it.”

There is also the possibility, Yampolskiy conjectured, that “a system administrator working for Twitter can see cleartext passwords and reveal them outside if he was unscrupulous.”

Regardless of whether passwords were compromised, Agrawal outlined and encouraged a number of ways to increase the security of one’s account, including two-factor authentication — a mechanism that multiple tech experts told TheDCNF is superior to most others.

To cybersecurity experts like Avetisov and Yampolskiy that on its own is not enough.

“Twitter should have mandated two-factor authentication by now, but it’s still optional,” said Avetisov. “While this isn’t a silver bullet, it certainly makes hacking a user’s account much more difficult.”

Yampolskiy thinks people will view a plea from the platform to change their passwords as “a big inconvenience.”

“It will be interesting to see users’ reaction to this,” he continued.

A spokeswoman for Twitter told TheDCNF that they are “not forcing a password reset but are presenting the information for people to make an informed decision about their account.”

“We believe this is the right thing to do,” the company representative said. Without a compulsion to do so, people may not exercise the best cybersecurity practices, which is of course a responsibility of users, but one that will also ultimately spill culpability onto Twitter — whether fair or not.

Yampolskiy also agrees with Avetisov, arguing that two-factor authentication should be set up by default, and not merely advocated for.

Agrawal said he and Twitter are sorry that this happened, but also added that they “didn’t have to” share such information and levy a request for people to change their passwords.

He eventually also apologized for the “mistake” of saying they had no obligation of disclosure.

How much Twitter really “puts people who use” their service first isn’t explicit since, according to Yampolskiy’s SecurityScorecard, it lags behind peers in the technology industry at least for the past year.

Still, Avetisov says that social media companies in general “are not particularly well known or praised for their cybersecurity practices.”

“Although internal practices and employee access may be held to a high regard, the user security has not kept up,” he continued. “LinkedIn had one of the worst password breaches of all time and Facebook’s recent privacy woes are not helping the narrative that social media giants value user account security.”

Follow Eric on Twitter

Send tips to eric@dailycallernewsfoundation.org.

All content created by the Daily Caller News Foundation, an independent and nonpartisan newswire service, is available without charge to any legitimate news publisher that can provide a large audience. All republished articles must include our logo, our reporter’s byline and their DCNF affiliation. For any questions about our guidelines or partnering with us, please contact licensing@dailycallernewsfoundation.org.

Tags : twitter
Eric Lieberman

PREMIUM ARTICLE: Subscribe To Keep Reading

Sign up

By subscribing you agree to our Terms of Use

You're signed up!

Sign up

By subscribing you agree to our Terms of Use

You're signed up!
Sign up

By subscribing you agree to our Terms of Use

You're signed up!

Sign up

By subscribing you agree to our Terms of Use

You're signed up!
Sign up

By subscribing you agree to our Terms of Use

You're signed up!

Sign Up

By subscribing you agree to our Terms of Use

You're signed up!
Sign up

By subscribing you agree to our Terms of Use

You're signed up!
Sign up

By subscribing you agree to our Terms of Use

You're signed up!
BENEFITS READERS PASS PATRIOTS FOUNDERS
Daily and Breaking Newsletters
Daily Caller Shows
Ad Free Experience
Exclusive Articles
Custom Newsletters
Editor Daily Rundown
Behind The Scenes Coverage
Award Winning Documentaries
Patriot War Room
Patriot Live Chat
Exclusive Events
Gold Membership Card
Tucker Mug

What does Founders Club include?

Tucker Mug and Membership Card
Founders

Readers,

Instead of sucking up to the political and corporate powers that dominate America, The Daily Caller is fighting for you — our readers. We humbly ask you to consider joining us in this fight.

Now that millions of readers are rejecting the increasingly biased and even corrupt corporate media and joining us daily, there are powerful forces lined up to stop us: the old guard of the news media hopes to marginalize us; the big corporate ad agencies want to deprive us of revenue and put us out of business; senators threaten to have our reporters arrested for asking simple questions; the big tech platforms want to limit our ability to communicate with you; and the political party establishments feel threatened by our independence.

We don't complain -- we can't stand complainers -- but we do call it how we see it. We have a fight on our hands, and it's intense. We need your help to smash through the big tech, big media and big government blockade.

We're the insurgent outsiders for a reason: our deep-dive investigations hold the powerful to account. Our original videos undermine their narratives on a daily basis. Even our insistence on having fun infuriates them -- because we won’t bend the knee to political correctness.

One reason we stand apart is because we are not afraid to say we love America. We love her with every fiber of our being, and we think she's worth saving from today’s craziness.

Help us save her.

A second reason we stand out is the sheer number of honest responsible reporters we have helped train. We have trained so many solid reporters that they now hold prominent positions at publications across the political spectrum. Hear a rare reasonable voice at a place like CNN? There’s a good chance they were trained at Daily Caller. Same goes for the numerous Daily Caller alumni dominating the news coverage at outlets such as Fox News, Newsmax, Daily Wire and many others.

Simply put, America needs solid reporters fighting to tell the truth or we will never have honest elections or a fair system. We are working tirelessly to make that happen and we are making a difference.

Since 2010, The Daily Caller has grown immensely. We're in the halls of Congress. We're in the Oval Office. And we're in up to 20 million homes every single month. That's 20 million Americans like you who are impossible to ignore.

We can overcome the forces lined up against all of us. This is an important mission but we can’t do it unless you — the everyday Americans forgotten by the establishment — have our back.

Please consider becoming a Daily Caller Patriot today, and help us keep doing work that holds politicians, corporations and other leaders accountable. Help us thumb our noses at political correctness. Help us train a new generation of news reporters who will actually tell the truth. And help us remind Americans everywhere that there are millions of us who remain clear-eyed about our country's greatness.

In return for membership, Daily Caller Patriots will be able to read The Daily Caller without any of the ads that we have long used to support our mission. We know the ads drive you crazy. They drive us crazy too. But we need revenue to keep the fight going. If you join us, we will cut out the ads for you and put every Lincoln-headed cent we earn into amplifying our voice, training even more solid reporters, and giving you the ad-free experience and lightning fast website you deserve.

Patriots will also be eligible for Patriots Only content, newsletters, chats and live events with our reporters and editors. It's simple: welcome us into your lives, and we'll welcome you into ours.

We can save America together.

Become a Daily Caller Patriot today.

Signature

Neil Patel