Twitter bug may have sent users' DMs to unknown developers


San Francisco, Sep 22 (IANS): A bug in Twitter's platform for third-party app developers exposed some Direct Messages (DMs) from nearly 3 million users to outsiders, the micro-blogging platform has admitted.

The bug ran from May 2017 and within hours of discovering it on September 10, Twitter said it fixed the bug to prevent data from being unintentionally sent to the incorrect developer.

"The bug affected less than 1 per cent of people on Twitter. The bug may have caused some of these interactions to be unintentionally sent to another registered developer," Twitter said in a blog post on Saturday.

"In some cases, this may have included certain DMs or protected tweets, for example a Direct Message with an airline that had authorised an Account Activity API (AAAPI) developer."

The Account Activity API allows registered developers to build tools to better support businesses and their communications with customers on Twitter.

Twitter currently has over 336 million users and one per cent means nearly 3 million of those were affected.

If your business authorised a developer using the AAAPI to access your account, the bug may have impacted your activity data in error.

"We're very sorry this happened. If your account was affected by this bug, we will contact you directly through an in-app notice and on twitter.com," said the company.

In May, the micro-blogging platform asked its 336 million users to change their password across its services after it discovered a bug that stored passwords in plain text in an internal system.

Twitter said it found no sign that hackers accessed the exposed data but advised users that they should enter a new password on all services where their current password has been used.

  

Top Stories


Leave a Comment

Title: Twitter bug may have sent users' DMs to unknown developers



You have 2000 characters left.

Disclaimer:

Please write your correct name and email address. Kindly do not post any personal, abusive, defamatory, infringing, obscene, indecent, discriminatory or unlawful or similar comments. Daijiworld.com will not be responsible for any defamatory message posted under this article.

Please note that sending false messages to insult, defame, intimidate, mislead or deceive people or to intentionally cause public disorder is punishable under law. It is obligatory on Daijiworld to provide the IP address and other details of senders of such comments, to the authority concerned upon request.

Hence, sending offensive comments using daijiworld will be purely at your own risk, and in no way will Daijiworld.com be held responsible.