Jump to content

Twitter Misused Private Security Info to Help Advertisers


steven36

Recommended Posts

Twitter says it inadvertently used private information, provided by users for the purpose of protecting their accounts, to help companies target them with ads.

 

123902652_157057565437211473.jpg

 

Users provided Twitter with their phone numbers and email addresses in order to enable certain security features, such as two-factor authentication, to prevent their accounts from being hijacked. Twitter, in turn, used that information to help advertisers reach specific audiences, the company said in a statement on Tuesday.

 

“We cannot say with certainty how many people were impacted by this, but in an effort to be transparent, we wanted to make everyone aware. No personal data was ever shared externally with our partners or any other third parties,” the company said.

 

The personal data was used in Twitter’s “Tailored Audiences” advertising system, which allows companies to upload lists of phone numbers and email addresses of people they wish to target with ads. Twitter then matches the lists with its own internal records.

 

Twitter said the error that allowed the security information to be used was fixed as of September 17. It did not say how long the error was ongoing. A company spokesperson said it had nothing further to share regarding the timeline beyond what’s in its statement.

 

“We’re very sorry this happened and are taking steps to make sure we don’t make a mistake like this again,” it said in a statement.

 

Twitter is not the first social media company to use contact information provided by users for security purposes in order to make money. Gizmodo revealed that Facebook was intentionally doing so last year.

 

Source

Link to comment
Share on other sites


  • Replies 1
  • Views 497
  • Created
  • Last Reply

Twitter transgression proves why its flawed 2FA system is such a privacy trap

 

Twitter 2FA is every bit as bad as critics said it was. Site signals a change is coming.

 

123943903_157058012179641407.jpg

 

If ever there was a surefire way to sour users against a two-factor authentication system that was already highly flawed, Twitter has found it. On Tuesday, the social media site said that it used phone numbers and email addresses provided for 2FA protection to tailor ads to users.

 

Twitter requires users to provide a valid phone number to be eligible for 2FA protection. A working cell phone number is mandatory even when users' 2FA protection is based solely on security keys or authenticator apps, which don't rely on phone numbers to work. Deleting a phone number from a user's Twitter settings immediately withdraws an account from Twitter 2FA, as I confirmed just prior to publishing this post.

 

123943953_157058012179641407.png

 

Security and privacy advocates have long grumbled about this requirement, which isn't a condition of using 2FA protection from Google, Github, and other top-ranked sites. On Tuesday, Twitter gave critics a new reason to complain. The site said it may have inadvertently used email addresses and phone numbers provided for 2FA and other security purposes to match users to marketing lists provided by advertisers. Twitter didn't say if the number of users affected by the blunder was in the hundreds or the millions or how long the improper targeting lasted.

 

Company officials wrote:

We cannot say with certainty how many people were impacted by this, but in an effort to be transparent, we wanted to make everyone aware. No personal data was ever shared externally with our partners or any other third parties. As of September 17, we have addressed the issue that allowed this to occur and are no longer using phone numbers or email addresses collected for safety or security purposes for advertising.

Security advocates, including Matt Green—a Johns Hopkins professor specializing in cryptography—wasted no time castigating Twitter for the gaffe.

 

"In all seriousness: whose idea was it to use a valuable advertising identifier as an input to a security system," he wrote on Twitter. "This is like using raw meat to secure your tent against bears."

In all seriousness: whose idea was it to use a valuable advertising identifier as an input to a security system. This is like using raw meat to secure your tent against bears.

— Matthew Green (@matthew_d_green) October 8, 2019

Not all 2FA was created equal

Two-factor authentication has emerged as the single-most effective means for protecting accounts against phishing and so-called credential-stuffing attacks (the latter uses passwords swept up in breaches on one site to guess passwords on unrelated sites). As the name suggests, 2FA requires a factor—for example, a security key or a fingerprint—in addition to a password to successfully log in from a device that has never accessed the account before.

 

Over the past few years, security practitioners have increasingly turned away from 2FA based on SMS text messages. The reasons: (1) attackers can take control of users' phone numbers by impersonating the owners and getting the carrier to swap out the SIM card, and (2) SMS messages can be hijacked through weaknesses in the Signalling System No. 7 routing protocol that cellular carriers use to make their networks interoperable. Attackers have been known to actively exploit these weaknesses more than once.

 

A far more effective means of 2FA relies on physical security keys that connect over USB or NFC interfaces or—less secure but still better than SMS—one-time passwords generated by authenticator apps. Twitter allows either form of 2FA. Both require a user to provide a phone number.

Twitter signals a change is coming

Twitter representatives declined to answer on the record why a phone number is required to use 2FA. A representative on background, however, said that the requirement is based on previous experiences in which users frequently lost access to other 2FA methods and were locked out of accounts with no way to recover. Twitter officials now recognize that tying 2FA to a phone number isn't ideal, and they are looking for ways to decouple the two in the future.

 

Last year, Facebook was outed for using 2FA-provided phone numbers to send notifications that weren't related to security. The social network said the behavior was the result of a bug.

While SMS-based 2FA isn't ideal, it's still better for most people than no 2FA at all—at least when services don't use phone numbers for marketing purposes.

 

Source

 

 

Link to comment
Share on other sites


Archived

This topic is now archived and is closed to further replies.

  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...