Twitter says it patched a bug that could have shared users’ private messages

FAN Editor

Twitter said Friday it has patched a bug that could have shared users’ private messages with software developers outside of the company.

The issue is estimated to have impacted less than 1 percent of Twitter’s total user base, which includes 335 million monthly active users as of July. The company’s stock price was down 3 percent and hit a day low after the bug’s disclosure.

“We have no evidence to suggest that any data was improperly misused or exploited anywhere,” a company spokeswoman told CNBC, emphasizing that the bug could only occur if a series of complex criteria were met. “There’s virtually no possibility that this happened but we still want to be thorough.”

Twitter said it is continuing to investigate the situation. The company said it has also contacted third-party “developers who may have been impacted,” the company said in a blog post.

Here’s Twitter’s full statement:

We recently discovered a bug in our Account Activity API (AAAPI). This API allows registered developers to build tools to better support businesses and their communications with customers on Twitter. If you interacted with an account or business on Twitter that relied on a developer using the AAAPI to provide their services, the bug may have caused some of these interactions to be unintentionally sent to another registered developer. In some cases this may have included certain Direct Messages or protected Tweets, for example a Direct Message with an airline that had authorized an AAAPI developer. Similarly, if your business authorized a developer using the AAAPI to access your account, the bug may have impacted your activity data in error.

It is important to note that based on our initial analysis, a complex series of technical circumstances had to occur at the same time for this bug to have resulted in account information definitively being shared with the wrong source. More here.

Key updates:

  • The bug ran from May 2017 and within hours of discovering it on September 10, 2018, we shipped a fix to prevent data from being unintentionally sent to the incorrect developer.
  • The bug affected less than 1% of people on Twitter.
  • Any party that may have received unintended information was a developer registered through our developer program, which we have significantly expanded in recent months to prevent abuse and misuse of data.

What’s next?

  • If your account was affected by this bug, we will contact you directly through an in-app notice and on twitter.com.
  • We have contacted our developer partners and are working with them to ensure that they are complying with their obligations to delete information they should not have.
  • Our investigation is ongoing. We will continue to provide updates with any relevant information.

We’re very sorry this happened. We recognize and appreciate the trust you place in us, and are committed to earning that trust every day. For more on our updated API policies and how to monitor the apps you are using on Twitter, see here and here.

This story is developing. Please check back for updates.

Free America Network Articles

Leave a Reply

Next Post

Owner of 3D-printed gun firm arrested in alleged sexual assault of a minor

The owner of a controversial company that makes 3D-printed gun blueprints has reportedly been arrested in Taiwan after being accused in Texas of sexually assaulting a 16-year-old and then paying her $500. The U.S. Marshals Service is aware of suspect Cody Wilson’s arrest, the agency said in a statement Friday. […]