Can this be an API leak which Chinese MSS used to track Chinese users?
It may well as be if we believe that API wasn't implementing discoverability restrictions from privacy settings, and only hid users on the UI level.
> Basically Twitter got pwned big time, and now denies it because GDPR will ruin them if breach is proven.
Here is what Doubi's online followers figured:
> State security got all phone numbers used for Twitter phone verification up to May 2019 and possibly till July.
> Twitter haphazardly closed the breach in complete secrecy.
> API hole explanation is excluded as people with 100% private accs got police visits.
> People with foreign SIM cards also got into trouble. So the explanation that China compromised Twitter's SMS providers is also excluded, as its improbable that they did it in 4+ countries.
> 2016 breach is also out of question.
> The only explanation is that they got hold on a big piece of their user DB, or, worse, they have an active infiltrator in Twitter, or Twitter voluntarily cooperated.
The story has some problem, Doubi is not an SSR developer, SSR was a high school girl's popular personal fork who mysteriously stopped.
Doubi is a blogger sharing GFW circumvention tips, like easy-to-use installing scripts for VPS, tutorials, reviews and a list of donated free acounts. Before his arrest, his blog had been under attack, domain names blocked.
The phone number thing is very dangerous, twitter bascially won't allow you to use it after a while if you don't provide a valid phone number.
If I was China, I'd go for this. Twitter has thousands of employees, many of which can surely be turned with some pressure. Also many who has family in China that can be used for leverage.
I’d have to imagine this is very common, and they’ve probably got one at all the big tech companies. It’s an underreported threat IMO. Who would say no to doubling their salary in exchange for running the occasional DB query for their home country?
And if a little persuasion was needed, the folder with evidence of assets secrets that would turn their life upside down if revealed. Ideally real secrets, but these days made up ones are probably as effective.
Oh boy, I’d encourage you to work in government for a year or two. I did IT for a government department that eventually wound up being investigated for letting the Taliban use their equipment (all I did was help them troubleshoot run of the mill PC issues FWIW). I personally know someone who had root access to a government land auction DB. Someone asked them to run “off the book” queries in exchange for looking the other way if said DBA wanted to run their own unaudited queries.
At competent companies -- I make no claim about Twitter here, but certainly at Google or at my employer -- it is extremely uncommon to have access to that database. All requests to access are logged and individually permissioned. Asking to access without a good reason, such as attachment to an active customer ticket, etc -- will get a hard no.
But at the same time, there's usually a way round it. For example, break the account in some way so the user opens a ticket, then grab the ticket and dump the whole contents of the account to 'debug'.
At a public company like Twitter, for SOX compliance reasons, it will be very difficult to find someone that has such permissions, and running anything unusual can be easily found by auditing. I'd stop with the conspiracy theories.
In general, most companies want to scope SOX as narrowly as possible. So if you can, only things that your auditors think will affect revenue reporting.
Querying ads performance data? Sure, we'll SOXify it.
Querying user accounts writ large? "Meh, our engineers need to be productive."
There are always weaknesses and internal vulnerabilities in every system.
If it was from the inside more likely a privileged user was compromised. It could also explain why Twitter is being quiet, especially if the investigation is ongoing.
Anyone who isn't stupid. Considering how may big corporations have ties with government agencies, if you try to pull something like that and you get caught you could easily be charged with espionage.
Even people with large IQs can be 'temporarily' stupid. Hence the term "lapse in judgement." Somebody who's intelligent but lets their ego run wild might believe they're too smart to get caught.
It doesn't scale -- the more you do it, the more likely one of them is to squeal or be caught, then MSS would be leaking their priority target list straight to the the FBI. Instead they would carefully target people with access, but not necessarily force them to divulge information / tamper with systems except when they really need it.
Occam's razor supports this one. Which would also bring liability to Twitter for not taking adequate steps to secure their servers.
It's not like they get l337 h4xx0rs to pwn their internal systems; they probably just have login credentials or permissions they shouldn't have, which aren't audited, and they can sneak things out in plain sight.
If China got OPM, they could easily get most of Twitter's DBs. Most likely through Nationals passing vulns back to home state intelligence agency, who can exfil data but not finger the moles.
You answered your own question yourself it that thread it seems:
> API hole explanation is excluded as people with 100% private accs got police visits.
Still, thanks for sharing, that's hell of a story. I don't speak Chinese and have no idea what's ShadowSocksR and why this Doubi guy was so hated by Chinese govt for that. Would appreciate more details.
Can this be an API leak which Chinese MSS used to track Chinese users?
It may well as be if we believe that API wasn't implementing discoverability restrictions from privacy settings, and only hid users on the UI level.
> Basically Twitter got pwned big time, and now denies it because GDPR will ruin them if breach is proven. Here is what Doubi's online followers figured:
> State security got all phone numbers used for Twitter phone verification up to May 2019 and possibly till July.
> Twitter haphazardly closed the breach in complete secrecy.
> API hole explanation is excluded as people with 100% private accs got police visits.
> People with foreign SIM cards also got into trouble. So the explanation that China compromised Twitter's SMS providers is also excluded, as its improbable that they did it in 4+ countries.
> 2016 breach is also out of question.
> The only explanation is that they got hold on a big piece of their user DB, or, worse, they have an active infiltrator in Twitter, or Twitter voluntarily cooperated.