TWITTER KEEPS PASSWORDS IN PLAINTEXT

TWITTER SR. NETWORK SECURITY ENGINEER ADMITS TO KEEPING PASSWORDS IN PLAINTEXT
youtu.be/jUtr7fNwagg?t=335

Other urls found in this thread:

twitter.com/wikileaks/status/951310420224167936
en.wikipedia.org/wiki/Cryptographic_hash_function
theatlantic.com/politics/archive/2017/11/james-okeefe/546911/
twitter.com/SFWRedditImages

wtf is he getting out of this?

>We have a backup system
wow it's nothing

what?

No they don't. Are you a brainlet?

I had a Twatter but my account was hacked because they allowed UNLIMITED login attempts at one point. The person who took it put up a bunch of ISIS shit on it. Glad I didn't put my name in my handle.

...

A power trip

Most bank accounts don't care about capitals in passwords either. Try it.

Yea they do. Are you a brainlet?

they keep backups, incase the guv'ment requests them or the usual reasons you keep backups

this aint news

>using social networks
>ever

he sounds like a fag

I bet it's the same everywhere, even here.

>believing some bullshit on a YouTube video and not an actual source
pls go

if this is Donaldo's downfall then he had it coming
Twitter is cancer

How does what he says imply that they store passwords in plaintext in any way you fucking brainlet?

Did you watch the fucking video brainlet?

>project veritas
>unearther of the CNN "nothing burger"
>not an actual source
How's living under a rock since Hill lost been for you?

>project veritas

Yeah, that is trash.

t. CNN viewer

Why so, reddit spacer?

>unearther of the CNN "nothing burger"

One guy at CNN said some story was a nothing burger, aka all of CNN is fake news.

How stupid are you?

Yes I did. Where did he say they do anything to indicate that they store passwords in plain text idiot?

>"one guy at CNN"
>>>>>one guy
when you have a show with your name in it (The Messy Truth with Van Jones), you're no longer "one guy"
this wasn't some intern, user
but you know that, don't you?

I don't know I didn't watch the video

He doesn't even know he's being filmed dude.

>veritas using protonmail
Absolutely based

Also wikileaks just twitted this news:

Undercover video appears to show Twitter security engineer saying that Twitter keeps all deleted direct messages and Tweets in case they need to hand them over to the government at a later date.

twitter.com/wikileaks/status/951310420224167936

>Undercover video appears to show Twitter security engineer saying that Twitter keeps all deleted direct messages and Tweets in case they need to hand them over to the government at a later date.
I guarantee you every social media monolith does this. Keeping passwords around in plaintext is the only strange thing imo.

>special snowflake with 666gorillion genders impersonating people
get off my Sup Forums showflake

Exsqueeze me?

THEY DON'T KEEP PASSWORDS AROUND IN PLAIN TEXT YOU FUCKING IDIOT.

>"I can tell you exactly who logged in from where, what username and password"
>"I can tell you... what username and password"
>"I can tell you... password"
That good enough for you?

wasn't me responding to you btw

>news

Literally every site of any consequence on the internet does this. You're fucking retarded if you think otherwise. Fuck, it's probably in the TOS.

When did Sup Forums get stupid?

who.... are you?

last night's storm

Twitter has essentially testified before Congress that they're the most unethical communications corporation on the planet. Why anyone still uses their service, I have no clue.

There's a 99% chance he misspoke. It's probably visible, but with a one way hash. So they know if it's the same password as last time, but they don't know what it is.

I literally use it to see what's going on in the world though infowars, wikileaks and assange
I don't use my real name not tweet anything

yeah but that's not what he said tho

because that's the only people you can trust. you and me both, brother.

>what username and password
Yes the password with the hash of 13451adb3c3 that was created May 15, 2013 YOU FUCKING IDIOT.

we forgot The Donald

if I can see your mom's butt with a hash of fuck u I can still see your mom's butt

>being this mad that you were btfo and outed as an idiot

>this fucking idiot equating giving database access with commiting resources to breaking your own encryption

look lemme spell it out for u
you are telling me I can see x with a hash of y
If this is the case, I can still see x.
Make sense?

It's fucking project veritas.

They probably had like 10 conversations with the guy and made him repeat shit over and over again until he used the words they liked.

If they honestly use plaintext passwords, they are very likely the dumbest fucking tech company on the planet. But you don't get as big as twitter by being the dumbest fuckers on the planet.

Ok. You managed to hack Twitter's database and find someone with a password that has a salted hash of 13451adb3c3. What's the plaintext?

>But you don't get as big as twitter by being the dumbest fuckers on the planet.
Oh, idealism. If only.

no, you misunderstand, according to Twitter's senior network security engineer, I can see the password. Why should I care for the hash when I have the password? I'm sure twitter does use a hash for logins but I have no reason to worry about it because I have the password.
u big dumy

Hey Van Jones. Big fan. I appreciated your crocodile tears live on cam.

Being able to tell what password was used is not the same as seeing what the password is.

A lot of people call Trump the dumbest motherfucker on the planet and he's the only person keeping Twitter in the news

He can see WHAT password was used, not the actual password you brainlet. Can't even understand hashing.

how would you define "I can tell you exactly what username and password" means then
If he told you exactly what your username and password was, what do YOU imagine he would tell you?

Username: 1337hacker1337
Password: The one you created May 15, 2013 with a hash of 13451adb3c3. That uniquely identifies the password you used.

>I can tell you exactly what username and password
Nobody said that.

what

>But you don't get as big as twitter by being the dumbest fuckers on the planet.
Target, Sony, Equifax

en.wikipedia.org/wiki/Cryptographic_hash_function

yes vic I understand how hashing works
but I can see the password, according to the senior network security engineer
So, why should the hash matter to me, a potential hacker?

Of which none of them stored passwords in plain text.

>Watching any video involving James O' Queef

calm down vic nobody remembers you anymore you're gonna be alright

>but I can see the password, according to the senior network security engineer
You can see what password was used. He didn't say you can see the unhashed user input, only sensational clickbait headlines are saying that.

Just everything else. Don't really need the passwords when you can just take everything of value directly from an account.

This. As much as I would love to see Twitter taken down for being that grossly incompetent, that's not what he said and it's incredibly unlikely that they store passwords in plaintext

a.) I can see what password was used, not what password hash.
b.) Which sensational clickbait headlines? I can't find them

Hmm. turns out you can just say any words in any order you want and its an argument all of a sudden. did trump do this?

>if you spot a senior network security engineer accidentally admitting to an insecure practice, you're a FUCKING ALT-RIGHTIST TRUMP SUPPORTING CONFEDERIST!!!

Please stop, you have no idea what you are talking about. Twitter does not keep user passwords in plaintext. Now, whether or not they use a strong cryptographic hash is another question. Wouldn't be surprised if they are using MD5.

A lot of major sites keep hashes of your previously-used passwords in case you try to reuse the same one again, which would be a poor security choice if it were allowed

video material from O'queef is not to be trusted. Ideologically or otherwise. You're an alt-child.

why
what has he fabricated?

Wasted quads

>I can see what password was used, not what password hash.
Again, nobody said you can see the actual plaintext password, but I see that distinction means nothing to you.

>b.) Which sensational clickbait headlines? I can't find them
I was mistaken, every headline focuses on Trump's DMs. I'll rephrase to 'sensational all-caps thread subjects'.

He (the Senior Network Security Engineer) stated that he can tell you "exactly who logged in from where" and "what username and password" they used to do so.
Stop doing this unless you're some twisted liar who agrees with me but thinks that spouting ridiculous arguments against my case will strengthen my case.

>not old enough to remember
>wants me to do research for him
I guess you'll just have to have faith in his ideology that he's being honest :^)

Use your brain. This video itself is clickbait. It's uninteresting bullshit to anyone with even vague knowledge of how social media sites have to operate already knows.

I know the passwords must be hashed because there's no "wait, in plaintext? You can see the password?" immediately following his statement. The entire video would be about Twitter storing passwords in plaintext if it was true. I know O'Keefe is retarded, but that's extreme. It would be the first time in his life that he had a real story on his hands.

It's a good thing they store deleted messages. Look at the guy that went to jail for rape because the girl deleted his messages changing the context.

Explain how you would authenticate users without being able to tell "what username and password" they used if usernames and passwords are the authentication method of your service. Knowing what password was used is not the same as knowing what the password actually is.

>It would be the first time in his life that he had a real story on his hands.
a video o'keefe made led to fucking acorn shutting down dude, at least, according to the atlantic
dunno how much trust you wanna put in them tho

lmao, bro they know this. This is a digital overton window. stop replying. sage all feilds. O 'Queef levels of honesty.

theatlantic.com/politics/archive/2017/11/james-okeefe/546911/
They right, but read more. O Queef is old news, dude fakes everything.

oh fuck its sony PSN all over again. When did people stop learning from the mistakes of others?

dude I'm reading the whole article and I'm not really seeing much actually in the way of delegitimizing O'Keefe
this shit looks like it was written by a middle schooler who just really hated the guy desu

>10 conversations with the guy and made him repeat shit over and over again until he used the words they liked
and he never picked up on it, seems legit

also what does o'keefe's integrity (which you seem to have a hard time actually y'know, calling into question for any legitimate reason) have to do with ANYTHING? The video is the video, and the video is video of what the TWITTER SENIOR NETWORK ENGINEER SAID IN PERSON
tfw left can't argue without ad hominem

>no face of speaker in video
It's fabricated.

>telling lies

>also what does o'keefe's integrity have to do with ANYTHING? The video is the video, and the video is video of what the TWITTER SENIOR NETWORK ENGINEER SAID IN PERSON

wow that rly enlightened me friend u rly blasted my argument away dammmmm
did u know that i'm a liberal democrat tho? just not in favor of the current liberal democratic party
also where's that from

>Liberal
That explains a lot. Don't expect an argument from someone that just came to this thread to make fun of you. Be smarter.

I'm a liberal in some respects (I do think people should be able to use whatever drugs they want) but not in others (I don't think the state should be expected to pay for drug users' medical bills due to them fucking themselves up for being careless retards about the dangerous chemicals they consume, nor do I think the government should not be expected to lock them up when they act out)
party politics are stupid tho in my onion

By using cryptographic hashing. And then you'd have the entry in your history about what hash was used to login, not what password.

except for trump, who da fack still uses twitter??

If your not OP you have some work to do. Stop believing ideological lies from the right. Their inner story is based on a lie. Always has been. This thread is further proof. Move the goal post, purposefully misrepresent data and facts, simplify complex nuance. Overton window online. same shit different day.

If you are op. well... you already know what your doing, but your nonetheless doing it. Good luck with that.

lol what