Categories: SecurityWorkspace

Twitter Fixes Privacy Bug That Affected 93,000 Users

Twitter has said it fixed a bug in its systems that affected the privacy of more than 93,000 accounts for several months.

The issue affected protected accounts, whose messages are under normal circumstances only visible to “followers” approved by the user, according to Bob Lord, Twitter’s director of information security. In the case of 93,788 of these accounts, non-approved followers were allowed to receive protected tweets via SMS or push notifications, according to Lord.

Apology

The bug had been in effect since November 2013, Lord said.

While the number of users is small compared with Twitter’s more than 240 million active users per month, Lord said the company was taking the issue seriously.

“This should not have happened,” Lord said in a blog post on Sunday. “We’ve emailed each of these affected users to let them know about this bug and extend our whole-hearted apologies.”

The unapproved follows have been removed, and Twitter said it has “taken steps” to prevent a similar situation from recurring.

The bug was discovered and reported to Twitter by a “white hat” security researcher, according to Lord.

Ongoing security problems

The event follows a false alarm earlier this month, when a system error resulted in Twitter sending thousands of messages to users, telling them, erroneously, that their accounts had been compromised.

A real security breach last year resulted in the passwords and usernames of 250,000 users being stolen, along with emails and other data, while in August a hacker leaked the details of more than 15,000 Twitter accounts, which had apparently been stored by third-party applications.

Twitter accounts have also become a popular target for activist organisations such as the Syrian Electronic Army (SEA), with major organisations such as Microsoft, Thomson Reuters, CNN, and the Guardian, and others seeing their Twitter accounts compromised in recent months.

Such incidents have led Twitter to introduce a number of improvements to its security and authentication systems. In 2012 Twitter enabled the secure HTTPS protocol for its users by default.

In February Twitter posted its first earnings report since it went public last November, showing improving financials but slowing growth in the company’s user base. The company revealed it has 241 million monthly active users, with 48 billion views of Twitter timelines recorded in the last three months.

Are you a security pro? Try our quiz!

Matthew Broersma

Matt Broersma is a long standing tech freelance, who has worked for Ziff-Davis, ZDnet and other leading publications

Recent Posts

Russia Accused Of Cyberattack On Germany’s Ruling Party, Defence Firms

German foreign minister warns Russia will face consequences for “absolutely intolerable” cyberattack on ruling party,…

2 days ago

Alphabet Axes Hundreds Of Staff From ‘Core’ Organisation

Google is reportedly laying off at least 200 staff from its “Core” organisation, including key…

2 days ago

Apple Announces Record Share Buyback, Amid iPhone Sales Decline

Investor appeasement? Apple unveils huge $110 billion share buyback program, as sales of iPhone decline…

2 days ago

Tesla Backs Away From Gigacasting Manufacturing – Report

Tesla retreats from pioneering gigacasting manufacturing process, amid cost cutting and challenges at EV giant

3 days ago

US Urges No AI Control Of Nuclear Weapons

No skynet please. After the US, UK and France pledge human only control of nuclear…

3 days ago