news.volyx.in

“I’m selling data of 400M Twitter users that was scraped via a vulnerability” (breached.vc)

510 points by prakhar897 · 1351 days ago · 280 comments on HN

Article summary

A data breach of 400 million Twitter users has been reported, with the seller claiming to have obtained the data via a vulnerability. The breach allegedly includes emails and phone numbers, and some commenters have verified the legitimacy of the sample data provided. The vulnerability was reportedly patched by Twitter in early 2022. The breach data is estimated to be from 2021 to 2022.

Main themes

  • Twitter data breach
  • GDPR fines and regulations
  • API security risks
  • Domain ownership and maintenance
  • Twitter bankruptcy speculation
  • Online security and authentication best practices

What commenters say

  • Paying the criminals to buy the data exclusively is not a viable solution to avoid GDPR fines.
  • The proper solution is to notify the supervisory authority and users about the personal data breach according to GDPR regulations.
  • Some commenters believe that Twitter will file for bankruptcy in January 2023 due to compliance deadlines and potential fines.
  • Others disagree, arguing that the company will take steps to avoid bankruptcy and maximize the value of its assets.
  • The use of public APIs can be a security risk, and some services may stop providing them or use obfuscation techniques to prevent scraping.
  • Having a personal domain email address can be risky if the domain is not properly maintained and renewed.
  • The breach highlights the importance of using secure and unique login credentials, rather than relying on Twitter as an authentication point for other websites.