A self-proclaimed data enthusiast calling themselves ‘ThinkingOne’ has made a huge database containing 201 million pieces of user data from X freely available. The data is said to have come from two previous leaks and includes email addresses, locations and profile data of users of the social media platform.

    • TacticalCheddar@lemm.ee
      link
      fedilink
      English
      arrow-up
      0
      ·
      edit-2
      2 months ago

      It also includes the people that deleted their Twitter accounts following the acquisition. I’m one of those people and I’m especially annoyed because I only used that blasted app only to register to some giveaways when I was in middle school. I have since discontinued that email account, but still.

    • Rose@slrpnk.net
      link
      fedilink
      English
      arrow-up
      0
      ·
      2 months ago

      If it had happened now, that figure might be accurate. However, this was originally exploited in 2022, so it’s probably pretty bad.

    • gedaliyah@lemmy.world
      link
      fedilink
      English
      arrow-up
      0
      ·
      2 months ago

      Mastodon is much better and resistant to enshittification. Bluesky is not federated or decentralized.

    • pogmommy@lemmy.ml
      link
      fedilink
      English
      arrow-up
      0
      ·
      2 months ago

      Bluesky will be in the same boat given enough time. Mastodon is the only proper stand-in for twitter.

      • Delusion6903@discuss.online
        link
        fedilink
        English
        arrow-up
        0
        ·
        2 months ago

        I’ve been on mastodon for 8 years and it’s ok but it can’t catch the masses. It has been paralyzed from advancing by a vocal minority.

        It shouldn’t take 6 years to get search and quote posts. They also need optional algorithmic feeds.

        • Scrollone@feddit.it
          link
          fedilink
          English
          arrow-up
          0
          ·
          2 months ago

          100% agree. The user experience of Mastodon is unappealing for the masses. Bluesky will enshittify for sure, but it’s the only real replacement for Twitter nowadays.

  • mbirth@lemmy.ml
    link
    fedilink
    English
    arrow-up
    0
    ·
    2 months ago

    This vulnerability made it possible to collect user data simply by knowing someone’s email address or phone number.

    Another example of where it pays off to have separate email addresses/aliases for every website/service you use.

      • adry@piefed.social
        link
        fedilink
        English
        arrow-up
        0
        ·
        edit-2
        2 months ago

        That’s re-victimization. People do people stuff, like using social networks. Furthermore, the database probably goes as far as previous to being bought, enshittified and renamed by Musk. So… you’re not being fair.

        • booly@sh.itjust.works
          link
          fedilink
          English
          arrow-up
          0
          ·
          2 months ago

          The actual data compromise happened sometime before July 2022, months before Elon’s purchase of Twitter happened. Telling people they shouldn’t have registered their real phone numbers to Twitter in 2015 or whatever isn’t really a helpful argument to make today.

        • Mike@lemm.ee
          link
          fedilink
          English
          arrow-up
          0
          ·
          2 months ago

          I’m fairy sure the guy above said “use X” not use social media. X is a particularly shitty platform.

      • suicidaleggroll@lemm.ee
        link
        fedilink
        English
        arrow-up
        0
        ·
        edit-2
        2 months ago

        Yes, and Bitwarden+SimpleLogin. Bitwarden to keep track of login info including the alias that is used for that site. SimpleLogin is where the aliasing is actually handled, they have a decent UI for enabling/disabling or generating reverse aliases (for outgoing emails) when needed.

        It does take a little more effort to manage it, but it’s worth the payoff. I’ve been using this setup for about 9 months now and I finally got my first spam email a week ago. I looked at the address it was sent to, it was an alias I used at a site I ordered something from about 6 months ago. I sent them a message letting them know that either someone at their company is selling customer info to scammers or their database has been leaked, then I shut off the alias. No more spam.

        • brbposting@sh.itjust.works
          link
          fedilink
          English
          arrow-up
          0
          ·
          2 months ago

          I sent them a message letting them know that either someone at their company is selling customer info to scammers or their database has been leaked, then I shut off the alias.

          🫡

      • Ideonek@lemm.ee
        link
        fedilink
        English
        arrow-up
        0
        ·
        2 months ago

        Proton Pass has a feature exactly for that. You can create unlimited number of aliases, and kill ones that bacame compromised.

      • mbirth@lemmy.ml
        link
        fedilink
        English
        arrow-up
        0
        ·
        2 months ago

        My email provider allows for unlimited aliases. So, while I have 600+ email addresses, emails to them all end up in the same mailbox.

        The accounts for all the websites and services (with their specific email address) are in a KeePass database and they all have random passwords, too.

        The only small issue is when you have to contact support of some service. Then, I have to configure the specific email address in my client so they can match that to my account with them. But most email clients allow multiple sender addresses without having to fiddle with the rest of the settings.

      • NikoWantToGoBowling@lemm.ee
        link
        fedilink
        English
        arrow-up
        0
        ·
        2 months ago

        Password manager plus an emailing alias service. Protonpass integrates with SimpleLogin but there’s also ones like Firefox relay and anomaly (all open source)

    • SippyCup@feddit.nl
      link
      fedilink
      English
      arrow-up
      0
      ·
      2 months ago

      Seems like a dedicated person might be able to prove that. Go through the available data and see what % of leaked accounts actually point to a real person, or even a unique person. If it’s mostly bots you’d see that pretty quick

      • GenosseFlosse@feddit.org
        link
        fedilink
        English
        arrow-up
        0
        ·
        2 months ago

        Check how many accounts pushing republican propaganda only post during St. Petersburg business hours… 🙃

  • itisileclerk@lemmy.world
    link
    fedilink
    English
    arrow-up
    0
    ·
    2 months ago

    Or this could be publicity stunt “look how many users we have, many users, beutifull users like never before, nobody knew how many users as there”.

    • Obelix@feddit.org
      link
      fedilink
      English
      arrow-up
      0
      ·
      2 months ago

      Exactly this. We knew that everything would get shaky after he fired all those people and a data leak is the consequence