12 votes

Twitter's Android app disabled "protect my tweets" when other settings were changed, potentially making private tweets public

3 comments

  1. [3]
    SourceContribute
    Link
    What a long time....I wonder how this affected people and how much damage this has really done.

    Anyone who updated the email address linked to their account between November 2014 and January 2019 could have had messages exposed, it said.

    Twitter said it fixed the flaw on 14 January and would share more information if it became available.

    What a long time....I wonder how this affected people and how much damage this has really done.

    5 votes
    1. [2]
      Deimos
      Link Parent
      I edited the title since I think the BBC headline is pretty misleading (and let me know if you think it needs further editing). A better description of the issue is on the official Twitter page...

      I edited the title since I think the BBC headline is pretty misleading (and let me know if you think it needs further editing). A better description of the issue is on the official Twitter page (which is linked from the article). I think it's especially important to note that it only affected the Android app.

      It sounds like they basically had an error that would change the "protect my tweets" setting back to the default (off) whenever anyone changed various other settings through the app. This is a pretty common error with settings pages, where when the user isn't changing a particular setting at the time, it interprets the absence of a value being sent for that setting as "set to default" instead of "keep the current setting".

      3 votes
      1. SourceContribute
        Link Parent
        Thanks for the title edit! I would hope they'd have regression tests for settings pages; lord knows I've spent many mind-numbing hours writing tests for this kind of thing -_-'

        Thanks for the title edit!

        It sounds like they basically had an error that would change the "protect my tweets" setting back to the default (off) whenever anyone changed various other settings through the app.

        I would hope they'd have regression tests for settings pages; lord knows I've spent many mind-numbing hours writing tests for this kind of thing -_-'

        3 votes