Stories
Slash Boxes
Comments

SoylentNews is people

posted by takyon on Monday December 31 2018, @12:07AM   Printer-friendly
from the dial-404-for-flaw dept.

Submitted via IRC for SoyCow1984

Twitter security flaw uses text spoofing to hijack UK accounts

A Twitter security flaw gives hackers a way to post unauthorized tweets via text messaging, and British cybersecurity firm Insinia has proven its existence by hijacking some celebrities' accounts. The company was able to post tweets as other people without having to enter their passwords by spoofing their mobile numbers. It's easy to forget the feature if you have data and a smartphone, but Twitter still allows you to tweet via SMS. You simply have to link your digits to your account and then text what you want to post to a number Twitter designated for your country and carrier.

A Twitter spokesperson explained to The Guardian that the bug "allowed certain accounts with a connected UK phone number to be targeted by SMS spoofing." It's not entirely clear what makes certain accounts susceptible to the bug, but as Gizmodo explains, Insinia was able to send out unauthorized tweets using "longcodes." See, Twitter uses two kinds of numbers for tweeting via SMS: longcodes and shortcodes. The former looks like a typical phone number, while the latter is just three to five digits. It's different for every country and, sometimes, every carrier -- the USA uses a shortcode (40404), for instance, while the UK uses both shortcodes and a longcode (+447624800379).


Original Submission

 
This discussion has been archived. No new comments can be posted.
Display Options Threshold/Breakthrough Mark All as Read Mark All as Unread
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
  • (Score: 4, Funny) by stretch611 on Monday December 31 2018, @01:23PM

    by stretch611 (6199) on Monday December 31 2018, @01:23PM (#780243)

    I have 2 questions...

    1) Does this work at all in the US?

    2) Anyone know Trump's cell phone number?

    --
    Now with 5 covid vaccine shots/boosters altering my DNA :P
    Starting Score:    1  point
    Moderation   +2  
       Funny=2, Total=2
    Extra 'Funny' Modifier   0  
    Karma-Bonus Modifier   +1  

    Total Score:   4