Twitter actually shipped this trivial security issue

แชร์
ฝัง
  • เผยแพร่เมื่อ 21 พ.ย. 2024

ความคิดเห็น • 416

  • @prosfilaes
    @prosfilaes 7 หลายเดือนก่อน +1841

    In 1994, TSR published the Encyclopedia Magicka; unfortunately, at the last moment, an editor had changed mage to wizard. It fixed the use of "mage" in the text, but it also changed all versions of damage to dawizard and image to iwizard. Funny that Twitter actually did this live.

    • @635574
      @635574 7 หลายเดือนก่อน +83

      Lmao and this bugged version got printed? Coul have been 2 other substitution from fixing it as well.

    • @Stratelier
      @Stratelier 7 หลายเดือนก่อน +268

      This is why search-replace functions typically include a "whole word" option.

    • @seanwilson9925
      @seanwilson9925 6 หลายเดือนก่อน +122

      The iWizard pro max

    • @sycration
      @sycration 6 หลายเดือนก่อน +38

      newest apple devices leaked

    • @Pallidum
      @Pallidum 6 หลายเดือนก่อน +113

      A clbuttic mistake.

  • @juusolatva
    @juusolatva 6 หลายเดือนก่อน +2114

    I love that everyone still calls it Twitter

    • @notmyname998
      @notmyname998 6 หลายเดือนก่อน +166

      Why would anyone stop calling it Twitter? Just because one man decided not to call it Twitter that doesn't mean that the name changed, it is the same as if I start calling my car a Ferrari when it's in fact a BMW... No one else will call it Ferrari.
      The same thing with Facebook, it will always be Facebook because this is how people know it

    • @DarkGob
      @DarkGob 6 หลายเดือนก่อน

      @@notmyname998 I mean, if the *owner* starts calling it something else, then yeah that does mean that the name changed.
      The problem is that Elon Musk inexplicably doesn't seem to understand just how valuable a brand can be. You can't buy the name recognition that Twitter has/had, and he just went and tried to flush it down the toilet (or pour it down the sink, perhaps). Ironically, he failed precisely because of how much name recognition Twitter does have -- it has penetrated far too deep into the public psyche for anyone to call the site anything else. The fact that the site URL remained unchanged for so long didn't help either, nor did Elon's antics that made it so most people just refused to acknowledge this dumb vanity project of an "everything app" that he clings to like a security blanket.

    • @vappyreon1176
      @vappyreon1176 6 หลายเดือนก่อน +261

      ​@@notmyname998 it's not even that, it's just that x is a dumb name and Twitter is less dumb

    • @madhausen
      @madhausen 6 หลายเดือนก่อน

      @@notmyname998 I prefer to call it Thefacebook 😎

    • @notmyname998
      @notmyname998 6 หลายเดือนก่อน +4

      Also true

  • @johongo
    @johongo 7 หลายเดือนก่อน +2176

    would have been hilarious if they reversed it by replacing "x" with "twitter"

    • @capsey_
      @capsey_ 6 หลายเดือนก่อน +287

      that would be etwittertremely funny

    • @fractaltinker
      @fractaltinker 6 หลายเดือนก่อน

      @@capsey_ that would be x.twitteryz funny

    • @charliesretrocomputing
      @charliesretrocomputing 6 หลายเดือนก่อน +76

      That would have been so etwitterciting to see!

    • @Exachad
      @Exachad 6 หลายเดือนก่อน

      Immediately registering TwitterVideos domain then.

    • @Cbp846
      @Cbp846 6 หลายเดือนก่อน +122

      setwitter

  • @chernobyl169
    @chernobyl169 7 หลายเดือนก่อน +1259

    I never would have guessed that laying off 75% of the staff, reorganizing the business, handing down functionality edicts, and running the company on shoestrings would result in lack of oversight and technical debt so egregious that it leads to easily exploitable feature creep on a monthly basis
    OH WAIT, YES I DID. MANY TIMES.

    • @derpaboopderp1286
      @derpaboopderp1286 6 หลายเดือนก่อน +3

      Good job man 🎉

    • @cinex20
      @cinex20 6 หลายเดือนก่อน

      lack of foresight*

    • @fangirlmc
      @fangirlmc 6 หลายเดือนก่อน +22

      and yet old Twitter was definitely worse than new Twitter.

    • @UltimaDoombotMK1
      @UltimaDoombotMK1 6 หลายเดือนก่อน +35

      ​@@cinex20Lack of any kind of sight*
      Look at Elon, do you think he's actually smart enough to have hindsight?

    • @floreroafloreril1458
      @floreroafloreril1458 6 หลายเดือนก่อน +48

      ​@@fangirlmcIt wasn't. There were less pedos and extremists. Lol

  • @mariobot128
    @mariobot128 6 หลายเดือนก่อน +470

    The security team got fired because they weren't writing enough lines of code

    • @antonliakhovitch8306
      @antonliakhovitch8306 6 หลายเดือนก่อน +39

      This... actually sounds plausible.

    • @SuperShado101
      @SuperShado101 6 หลายเดือนก่อน

      ​@@antonliakhovitch8306This is what Elon said he did, so yeah

    • @randys2669
      @randys2669 6 หลายเดือนก่อน

      ​@@antonliakhovitch8306Some of Twitter's layoffs were literally decided based on numbers of lines of code. It's not just plausible, it's likely.

    • @ExzaktVid
      @ExzaktVid 6 หลายเดือนก่อน +8

      How to add more lines to your code, easy tutorial below
      If(
      1+1=2
      ) {
      Live}
      Else{
      Die}

    • @hpsmash77
      @hpsmash77 6 หลายเดือนก่อน +12

      ​@@ExzaktVid ==*

  • @christopherstaples6758
    @christopherstaples6758 7 หลายเดือนก่อน +280

    @4:20 , actually you can just pass the user / password to the real website and still log them , the end user is still none the wiser , nothing stoping you from running another website fully within your phising site , with input logging

    • @635574
      @635574 7 หลายเดือนก่อน +56

      This is a few standard deviations above average scammer IQ

    • @jellifygirl
      @jellifygirl 6 หลายเดือนก่อน

      ​@@635574Rather, there's no need to bother. Once you've got their details, you've got their details.

    • @enderkatze6129
      @enderkatze6129 6 หลายเดือนก่อน +3

      Good to know.

    • @EntityVsEntityInteractions
      @EntityVsEntityInteractions 6 หลายเดือนก่อน +11

      To do so effectively and in a convincing way (not displaying a tab within a tab, not taking 10s+ to load, etc) would require a lot more effort & expertise than the average phisher has at their disposal...

    • @biigsmokee
      @biigsmokee 6 หลายเดือนก่อน

      @@EntityVsEntityInteractions wrong, setoolkit is open source and widely available

  • @MawdyDev
    @MawdyDev 6 หลายเดือนก่อน +103

    The Muskrat gave the original Twitter staff a crappy ultimatum and most of them walked out. He's likely been struggling to hire experienced coders, because people with any shred of confidence refuse to work for him.

  • @Sabagegah
    @Sabagegah 7 หลายเดือนก่อน +996

    S E C U R I T Y I S S U E I N B I O

    • @pinguluk1
      @pinguluk1 6 หลายเดือนก่อน +1

      lmao

    • @Frozd
      @Frozd 6 หลายเดือนก่อน +1

      that's fucking hilarious

  • @jaade9485
    @jaade9485 6 หลายเดือนก่อน +69

    a spiteful childish change AND its poorly implemented? nooo that doesnt sound like elon at all

    • @dIancaster
      @dIancaster 5 หลายเดือนก่อน

      Poorly implemented, sure, but I’m not really sure where your getting “spiteful childish” from. A lot of the URLs that the website uses still has Twitter in them. It would be confusing for users if they saw Twitter as well as X. Rebasing all the URLs to go from Twitter to X retroactively is the slower, more expensive option. By displaying it like this, assuming it worked right, you can maintain the aesthetic cohesion while the underlying URLs need not be updated yet.

  • @newold1093
    @newold1093 7 หลายเดือนก่อน +1284

    This is what happens when you have Elon as your code reviewer 😂

    • @tiagorainho5011
      @tiagorainho5011 7 หลายเดือนก่อน +29

      Yeah because its the ceo reviewing the code 🤡

    • @alexstomberg8306
      @alexstomberg8306 7 หลายเดือนก่อน

      @@tiagorainho5011 fr lol

    • @netrunner01
      @netrunner01 7 หลายเดือนก่อน +196

      @@tiagorainho5011 Elon literally made engineers print out code and present it to him when he bought Twitter 😂. He's a known micromanager

    • @jacobstamm
      @jacobstamm 7 หลายเดือนก่อน +120

      @@tiagorainho5011You’re joking, but that is literally what happened.

    • @2BTO
      @2BTO 7 หลายเดือนก่อน

      @@tiagorainho5011delete this comment buddy

  • @Pockeywn
    @Pockeywn 6 หลายเดือนก่อน +205

    why do i feel like elon just went in and coded this himself

    • @Luky.73
      @Luky.73 6 หลายเดือนก่อน +9

      nah you are giving him too much credit, twitter would break if elon programed a single line

    • @Pockeywn
      @Pockeywn 5 หลายเดือนก่อน

      @@Luky.73 that honestly feels like just a bandaid ass weird bit of code that he couldve written.. like it sorta DID almost break stuff

  • @omri9325
    @omri9325 7 หลายเดือนก่อน +246

    Microsoft Azure password change page takes the crown on horrible UI that looks like phishing

    • @sehaless
      @sehaless 6 หลายเดือนก่อน +2

      I don't use azure, what are they doing? Do you have a TL;DR?

    • @inverlock
      @inverlock 6 หลายเดือนก่อน +35

      @@sehalessit’s a dev UI straight out of 2004

    • @sehaless
      @sehaless 6 หลายเดือนก่อน +10

      @@inverlock oof, hey, at least it's fast.. right?

    • @Bpinator
      @Bpinator 6 หลายเดือนก่อน +13

      Lmao it does, it looks so old. Theres a lot of little legacy items still kicking around in Azure/365

    • @chri-k
      @chri-k 6 หลายเดือนก่อน +14

      and Oracle's entire site

  • @neonoir__
    @neonoir__ 6 หลายเดือนก่อน +33

    this is what happens when the company culture is "just do whatever dumb shit elon wants without asking questions if you dont wanna be fired"

  • @DogsRNice
    @DogsRNice 6 หลายเดือนก่อน +69

    Reminds me of a Minecraft server I joined like 11 years ago that had a word filtering plugin to stop swearing
    Except they somehow configured it to change "hello" to "hekko"
    Presumably trying to prevent anyone from saying "hell"

    • @brucewayne1777
      @brucewayne1777 6 หลายเดือนก่อน +28

      That's a known issue called the scunthrope problem.

    • @dylanharding5720
      @dylanharding5720 6 หลายเดือนก่อน

      ​@@brucewayne1777scunthorpe, not scunthrope. And of course, there's a ton of other towns with those types of names - Penistone for example.

    • @addison1024
      @addison1024 6 หลายเดือนก่อน

      @@brucewayne1777also seen frequently with penistone

    • @antonliakhovitch8306
      @antonliakhovitch8306 6 หลายเดือนก่อน

      ​@@brucewayne1777*Scunthorpe

    • @Starwort
      @Starwort 6 หลายเดือนก่อน

      ​@@brucewayne1777it's a clbuttic problem

  • @green8026
    @green8026 7 หลายเดือนก่อน +311

    obviously a bad bug, but completely ridiculous to say "I cannot imagine an experienced software engineer who wouldn't consider security vulnerabilities with URL rewrites". as a software quality professional, I have found COUNTLESS bad bugs from people who have been software engineers for 10+ years. bugs that reveal PHI, XSS bugs, bugs that bring down entire sites, etc

    • @Templarfreak
      @Templarfreak 6 หลายเดือนก่อน +34

      obviously that 10+ years of experience was _not_ in security for them XD

    • @Charlie7753
      @Charlie7753 6 หลายเดือนก่อน +9

      But in this case it wasnˋt a bug.

    • @danielr8257
      @danielr8257 6 หลายเดือนก่อน

      Most of the bugs or vulnerabilities that experienced software engineers add in are not intuitive and mistakes get made because it isn't an issue that is often encountered in regular development and require special consideration. Every software engineer is well aware of the limits of search and replace, it's the reason you always use "refactor" in your IDE instead of "find and replace". It's practically one of the first things you learn as a software engineer, when you try to change a variable name and it ends up changing a bunch of other stuff you didn't want it to as well. Extending that intuition to URL replacements is such a small logical leap. I'm a very inexperienced software developer and even I make sure to be extra careful when having to parse strings because there are always a ridiculous number of edge cases to account for (e.g. word extraction can't just look for spaces since punctuation exists and sometimes punctuation like single quotes are considered parts of words and sometimes aren't).
      It's one thing to leave in a segfault that didn't get caught because it happened to point to allocated memory while testing or even code injection vulnerabilities that weren't accounted for in the test cases and another to not recognize the potential issues with a full search and replace, especially when it apparently wasn't tested on edge cases before deployment (e.g. ensuring "netflitwitter dot twitter" not being replaced with anything since it should only replace second-level domain names and only "twitter" by itself). Even the simplest and smallest set of reasonably made test cases would have caught this bug.
      I might've accepted an experienced software engineer accidentally replacing top level domains with "X" since ".twitter" isn't really a valid domain, but replacing every instance of "twitter" even when it isn't the full domain name is a bit ridiculous, even for an inexperienced developer, let alone an experienced one.

    • @VonVikoGoat
      @VonVikoGoat 6 หลายเดือนก่อน +18

      in fact newer people tend to be more cautious. experience people are often arrogant and refuse to fix their mistakes

    • @idontwantahandlethough
      @idontwantahandlethough 6 หลายเดือนก่อน +19

      @@VonVikoGoat well yeah, but you can only be cautious of dangers you're _aware of._ That's the issue for newer people: you can be as cautious as you want, but if you didn't know that something is a possibility, you can't viably protect against it.

  • @mikapeltokorpi7671
    @mikapeltokorpi7671 6 หลายเดือนก่อน +96

    When you fire 80% of your engineers at once...

  • @AlexRaylight
    @AlexRaylight 6 หลายเดือนก่อน +19

    But the Musk fans were saying that all those tech employees who left weren't important, and that twitter will be fine regardless... 🤔

  • @alicenNorwood
    @alicenNorwood 7 หลายเดือนก่อน +267

    Twitter actually had XSS in the feed 3 years ago

    • @dingus2332
      @dingus2332 7 หลายเดือนก่อน +14

      There are many subdomains of Twitter , where XSS happens

    • @3_smh_3
      @3_smh_3 7 หลายเดือนก่อน

      @@dingus2332 dang!

    • @REAZNx
      @REAZNx 7 หลายเดือนก่อน +7

      You mean Tweetdeck?

    • @al-ft1ng
      @al-ft1ng 7 หลายเดือนก่อน +6

      @@dingus2332 Such as ? Any PoC ? Anything to back your claim lol? Do you have any previously documented PoC ?

    • @dingus2332
      @dingus2332 7 หลายเดือนก่อน

      @@al-ft1ng it's just a known thing ... They launch subdomains ,hunters with tools scan that new vulnerable subdomain and report them immediately

  • @xdevs23
    @xdevs23 6 หลายเดือนก่อน +58

    That's why you should use a password manager with phishing detection where it automatically matches the domain against the URL stored in your passwords and thus only show the ones that match the domain.

    • @Z-of1zx
      @Z-of1zx 6 หลายเดือนก่อน +3

      Examples of password managers with this functionality?

    • @Bob-bs9ok
      @Bob-bs9ok 6 หลายเดือนก่อน

      ​@@Z-of1zxpass, pretty much the standard on unix systems, does this.

    • @sun3k
      @sun3k 6 หลายเดือนก่อน

      bitwarden is a pretty good free one

    • @xdevs23
      @xdevs23 6 หลายเดือนก่อน

      @@Z-of1zx Android Password Store and gopass extension for browsers (uses the pass system)

    • @brucewayne1777
      @brucewayne1777 6 หลายเดือนก่อน

      ​@@Z-of1zx lastpass, 1password, keepass (with the browser extension). Honestly I think all of them have that

  • @EronanTruth
    @EronanTruth 6 หลายเดือนก่อน +41

    Sadly the reason for the "no review" is much more trivial. It's very likely that people didn't want to "review" it than they actively didn't because everyone knew this was a bad idea, but the "person" who made the decision had a lot of power within the company and really, really, really wanted it. Because in general, there is absolutely no reason to implement this change and a waste of man hours.
    So they wanted to get this done, let the person who's making the stupid decision see it crash. And then get back to actual important work.

  • @oxyacetylene_
    @oxyacetylene_ 6 หลายเดือนก่อน +55

    twitter used to have XSS on their desktop client, there was a self-replicating tweet going around for a couple of hours

    • @aaaaaaaaaaaaa-b6w
      @aaaaaaaaaaaaa-b6w 6 หลายเดือนก่อน +4

      Tweetdeck*

    • @halyoalex8942
      @halyoalex8942 6 หลายเดือนก่อน +11

      I remember the Tom Scott video on that one 😂

    • @gunstorm05
      @gunstorm05 6 หลายเดือนก่อน +1

      It was not an issue on an official Twitter product. That was a third-party client.

  • @ladyalicent705
    @ladyalicent705 6 หลายเดือนก่อน +365

    As a wise man once said: “If he can deadname his own daughter, we can deadname his goofy ahhh platform”

    • @joshy541
      @joshy541 6 หลายเดือนก่อน +33

      It ain't his, he just adopted it and tried to rename yet another of his children to something with an X in it

    • @ladyalicent705
      @ladyalicent705 6 หลายเดือนก่อน +60

      @@joshy541 I’m talking about Vivian, not XÆA-12

    • @joshy541
      @joshy541 6 หลายเดือนก่อน +48

      @@ladyalicent705 yeah I got you, I'm just saying he adopted Twitter and tried to force a new name on it. Because Twitter sure as heck didn't want to be renamed

    • @TuhljinTampergauge
      @TuhljinTampergauge 6 หลายเดือนก่อน

      Men can't give birth.

    • @TuhljinTampergauge
      @TuhljinTampergauge 6 หลายเดือนก่อน +9

      TH-cam doesn't want you to know this, but here's a secret knowledge from the before time (literally couldn't post this without this preamble to throw off the bot): Men can't give birth.

  • @PetWanties
    @PetWanties 6 หลายเดือนก่อน +12

    I can imagine that this got into prod because it's considered a front end / visual change and it might have less strict review standards? Still wild that apparently whoever wrote this didn't realize the implications.

  • @coreydevs
    @coreydevs 7 หลายเดือนก่อน +23

    Crazy because my first thought was linkedin is starting to look a lot like facebook

  • @DissociatedWomenIncorporated
    @DissociatedWomenIncorporated 6 หลายเดือนก่อน +21

    Elon Musk, living proof of the meritocracy! 🤣🤣🤣

  • @Mustafa-099
    @Mustafa-099 7 หลายเดือนก่อน +12

    Thanks for providing the link to the original post
    You the best!

  • @CentreMetre
    @CentreMetre 6 หลายเดือนก่อน +6

    Im by far not the best programmer, but i think its fair to take the piss out of twitter for this considering how big of a company they are and how many people there are.

  • @DennouNeko
    @DennouNeko 7 หลายเดือนก่อน +25

    Just like a lot of changes since Elon took over, sounds like a change that was enforced from above. Guess someone is salty that nobody calls it X

  • @mafiawerbung
    @mafiawerbung 7 หลายเดือนก่อน +22

    Remember the self retweeting tweet?

    • @addison1024
      @addison1024 6 หลายเดือนก่อน

      All I know about web security is from Tom Scott, and it seems like I might actually be set for a while

  • @sage5296
    @sage5296 6 หลายเดือนก่อน +6

    "I'm sure they have best practices in place"
    You mean like firing all of the people who know what they're doing cuz they're not needed supposedly?

  • @joeykeilholz925
    @joeykeilholz925 6 หลายเดือนก่อน +4

    It's giving "fired for not enough lines of code"

  • @pastori2672
    @pastori2672 7 หลายเดือนก่อน +22

    scared with the google part i actually used it and btw when are the systems design videos bro

  • @aka5h_ra0
    @aka5h_ra0 7 หลายเดือนก่อน +8

    Petition for neetcode to create web app security videos!

    • @ExecutionMods
      @ExecutionMods 7 หลายเดือนก่อน +5

      ehh like he said hes not a security expert. there's plenty of experts with full fledged courses out there tho

    • @aka5h_ra0
      @aka5h_ra0 7 หลายเดือนก่อน +2

      @@ExecutionMods yes I agree there are plenty of other courses out there, but the way this dude teaches is just 🔥🔥

    • @ExecutionMods
      @ExecutionMods 7 หลายเดือนก่อน +1

      ​@@aka5h_ra0 i agree i like his style of teaching a lot

  • @wlockuz4467
    @wlockuz4467 6 หลายเดือนก่อน +3

    Stop spreading rumours.
    There was a thorough code review done. Everyone printed their code on paper, at least first 2-4 pages were peer reviewed, few LGTM were exchanged, and only then the code was merged in production.

  • @miserablepile
    @miserablepile 7 หลายเดือนก่อน +14

    This is what happens when Musk keeps his teams "lean innovative, and hungry for the next growth phase cycle"

    • @jonathanhoward1499
      @jonathanhoward1499 7 หลายเดือนก่อน +1

      Good. He's right. It's social fucking media

    • @Moocow2003
      @Moocow2003 6 หลายเดือนก่อน

      ​@@jonathanhoward1499security issues aren't a price I'm willing to pay for innovation

    • @joeykeilholz925
      @joeykeilholz925 6 หลายเดือนก่อน

      ​@@jonathanhoward1499in no way is he right. He is a complete moron. Reevaluate everything that lead you to say that

  • @ecchioni
    @ecchioni 7 หลายเดือนก่อน +200

    This is what happens when you fire most engineers and make the remaining sleep in office in order to work 120 hour weeks.

    • @Sammysapphira
      @Sammysapphira 7 หลายเดือนก่อน +7

      Blatantly false and Twitter has run better than ever with the downsized team once all the bloat and hr department were removed. Elons twitter team has shipped more features than Jack has in the past 10 years.

    • @josephp.3341
      @josephp.3341 7 หลายเดือนก่อน +90

      @@Sammysapphira The company is doing terrible compared to how it used to. I mean imagine becoming the new CEO and the most significant thing you have to show for it a new competitor spawned and took a massive amount of your market share - something unthinkable years prior.

    • @tapwater424
      @tapwater424 7 หลายเดือนก่อน +55

      @@Sammysapphira Every post is bots replying with engagement bait not related to the original content.

    • @Peter-tx7qf
      @Peter-tx7qf 7 หลายเดือนก่อน +57

      ​@@Sammysapphira Twitter is literally shit now, only bots on every post and the features are shit and get pulled back every 3 months. It's tragic how he fucked it up soo bad.

    • @TheKennyWorld
      @TheKennyWorld 7 หลายเดือนก่อน

      ​@@tapwater424And you think that is caused by Elon? How? Couldn't be just a coincidence?

  • @yichenchong7728
    @yichenchong7728 7 หลายเดือนก่อน +5

    I don't think the Google page was that big of an issue, as long as you confirm that the sign in page that opened is with a Google domain, because if the app itself isn't made by Google, it only has access to Google's OAuth flows (and any other permissions you share in the screen after the login), and OAuth is pretty secure; you wouldn't lose your Google credentials just because a site got you to OAuth to them (I believe its a PKCE flow to be more specific, but I could be wrong).
    That being said, if you have to type in your password to a Google page, you'd better be sure that sign in page is by Google, even if the app itself isn't.

  • @givowo
    @givowo 6 หลายเดือนก่อน +1

    The XSS vulnerability actually happened years ago. Tom Scott made a video about it, and its called the self retweeting tweet

  • @ZNZbane
    @ZNZbane 5 หลายเดือนก่อน +1

    Haven't seen the vuln yet, but I've actually never heard of a CSRF! That's really interesting, definitely something to watch out for that never got covered in my security classes (or maybe I just missed those days, lol).

    • @ZNZbane
      @ZNZbane 5 หลายเดือนก่อน +1

      ok now that I have, that is PROFOUNDLY embarrassing. That's a mistake that I feel like anybody sandboxing the code could check, are they just shipping anything?!

  • @compenuered2830
    @compenuered2830 7 หลายเดือนก่อน +8

    it's grock becoming devin

  • @natescode
    @natescode 7 หลายเดือนก่อน +51

    Maybe Elon fired all the smart people yoo.

    • @AWriterWandering
      @AWriterWandering 6 หลายเดือนก่อน +33

      The smart people knew better than to stick around

    • @kintustis
      @kintustis 6 หลายเดือนก่อน +10

      smart people can get paid the same without the 100 hour weeks, so they've all left by now.

    • @joeykeilholz925
      @joeykeilholz925 6 หลายเดือนก่อน

      Worst part is he still works there.

  • @matthewrease2376
    @matthewrease2376 6 หลายเดือนก่อน +2

    You should never trust what's displayed anyway. Always check the mouse hover on a link.

  • @neoqueto
    @neoqueto 6 หลายเดือนก่อน +2

    That's such a... "PHP 5.6 newbie WordPress tinymce fork" kind of mistake.

    • @evinroen6401
      @evinroen6401 6 หลายเดือนก่อน

      I have no idea what any of this means

  • @l1nuxguy646
    @l1nuxguy646 6 หลายเดือนก่อน +3

    I bet you Musk said to do it this way and refused to listen to anyone who explained.

  • @StarGarnet03
    @StarGarnet03 6 หลายเดือนก่อน +4

    musk has such an inflated ego and insecurity from people not calling the popular app it's original name that he accidentally created avenues for scams with shitty find/replace code

  • @idontwantahandlethough
    @idontwantahandlethough 6 หลายเดือนก่อน

    LOL this SCREAMS "everyone who knew anything at Twitter has left the building"

  • @plukerpluck
    @plukerpluck 6 หลายเดือนก่อน

    This is no different that allowing custom hyperlinks though. Twitter doesn't support rich test, so that change in functionality does result in a vulnerability, but most other social media sites have allowed rich text for years (including LinkedIn where you're reading that). So individuals should already be used to checking the actual URL on links.
    Effectively, it is a bug, and it is technically a vulnerability, but no more so than the rest of the internet **intentionally** allows.

  • @CZRWK
    @CZRWK 6 หลายเดือนก่อน

    "I'm sure they have best practices in place."
    Hilarious misunderstanding of Elon's Twitter.

  • @ryanreed4698
    @ryanreed4698 6 หลายเดือนก่อน +5

    Why is he still pushing X, just such a stupid name.

    • @mathiasrryba
      @mathiasrryba 6 หลายเดือนก่อน +8

      because he's obsessed with it. He always wanted it and he pushes it into everything, even his own children's names.

  • @chrisakaschulbus4903
    @chrisakaschulbus4903 6 หลายเดือนก่อน

    Getting paranoid because buttons look funny?
    That's everyday for me with my crappy connection...

  • @Bukki13
    @Bukki13 6 หลายเดือนก่อน +3

    setwitter

    • @superwhizz114
      @superwhizz114 6 หลายเดือนก่อน +2

      gay setwitter

  • @MillySilly-1
    @MillySilly-1 6 หลายเดือนก่อน

    another example of companies making useless changes instead of fixing real problems

  • @Boxygirl96
    @Boxygirl96 5 หลายเดือนก่อน

    On a less important note: petition to call the site Twitty if he finds a way to ban the term Twitter correctly

  • @sobari745
    @sobari745 6 หลายเดือนก่อน

    Elon Musk is truly a genius. I didn’t think it was possible to run such a massive company into the ground so fast and efficiently.

  • @UCXEO5L8xnaMJhtUsuNXhlmQ
    @UCXEO5L8xnaMJhtUsuNXhlmQ 6 หลายเดือนก่อน

    Well when your criteria for keeping employees is lines of code written it follows naturally that you're going to keep employees who have to rewrite and correct code

  • @SaurianSavior
    @SaurianSavior 6 หลายเดือนก่อน +1

    I see everyone has gone onto take the piss out of Elon for the many many mistakes he made. The funny thing for me is this is because Elon decided Twitter should be called a letter.
    And now it's breaking people's tweets, because nobody calls the site by the letter. Of course, it's more complicated, like - read the other comments.

  • @rotatopotato5212
    @rotatopotato5212 7 หลายเดือนก่อน +70

    This is why I deleted my Twitter account very soon after Elon took over and fired most of the engineers. Especially after I learned 2FA broke immediately. As an engineer, I can only imagine the amount of details that are getting thrown out the window.

    • @adama7752
      @adama7752 7 หลายเดือนก่อน

      Lol, they've had hack bypassing 2fA years before Elon.
      It was always a mess. You're just unable to moderate your bias here

    • @Leo-sd3jt
      @Leo-sd3jt 7 หลายเดือนก่อน

      @devstuff2576no, they deleted it because they could see that Elon was breaking things. That’s why they reference how 2fa broke on the site

    • @nou4605
      @nou4605 7 หลายเดือนก่อน

      ​@devstuff2576Skill issue

    • @Sammysapphira
      @Sammysapphira 7 หลายเดือนก่อน +7

      He didn't fire the engineers. He fires the slackgineers.

    • @ifeoluwaadeoye6557
      @ifeoluwaadeoye6557 7 หลายเดือนก่อน +43

      @@Sammysapphira really? And now they have a security issue. Looks like the 'slackgineers' doing the work.

  • @thepwrtank18
    @thepwrtank18 6 หลายเดือนก่อน +8

    twittervideos

  • @Seydaschu
    @Seydaschu 6 หลายเดือนก่อน +3

    Let's compromise. Xitter.

    • @RaceBandit
      @RaceBandit 6 หลายเดือนก่อน

      How many of the doxxers, swatters, and SJWs are gone?

  • @Afro__Joe
    @Afro__Joe 7 หลายเดือนก่อน +6

    What happens when you get rid of all your talent to save an extra penny.

  • @TrueTechLead
    @TrueTechLead 7 หลายเดือนก่อน +4

    That is so goofy.

  • @SandraWantsCoke
    @SandraWantsCoke 7 หลายเดือนก่อน +1

    I gave you the 777th like, really enjoy your videos! (never done a leetcode question in my life)

  • @ObaidKnight
    @ObaidKnight 7 หลายเดือนก่อน +2

    How can we learn more about this type of stuff?

    • @jshowao
      @jshowao 7 หลายเดือนก่อน

      owasp is a good site to learn about this stuff.

  • @Alexis-lt3zy
    @Alexis-lt3zy 6 หลายเดือนก่อน

    Twitter has previously had XSS attacks...

  • @perz1val
    @perz1val 6 หลายเดือนก่อน +3

    Doing a text replace and not botheting to only match the real domains is just amateurish. Did an intern do this?

  • @hypermeero4782
    @hypermeero4782 7 หลายเดือนก่อน +17

    what if i told you that I can make the CSRF hack happen in twitter in few seconds?

    • @hypermeero4782
      @hypermeero4782 7 หลายเดือนก่อน +3

      and even better, make some random people follow some other random people.

    • @Yoruplays
      @Yoruplays 7 หลายเดือนก่อน

      @@hypermeero4782 is there no csrf tokens on their requests?

    • @omcar13
      @omcar13 7 หลายเดือนก่อน

      @@hypermeero4782 I'd ask you to do it

    • @beniungur1722
      @beniungur1722 7 หลายเดือนก่อน

      @@hypermeero4782 report it and they'll probably reward you

    • @raulhernandez2010
      @raulhernandez2010 7 หลายเดือนก่อน +8

      can you use it to make my twitter blow up 😊

  • @PetWanties
    @PetWanties 6 หลายเดือนก่อน +1

    For the google webpage / login you showed, it's always good to check the certificate of the website, authority domains will have their own certs that are (usually) easy to recognize.

  • @Aeduo
    @Aeduo 7 หลายเดือนก่อน +1

    The review process having a lot of odd barriers to even getting to the point where someone is looking at it really sounds liek that usual corpo adversarial conditioning approach to things where they just add difficulty to some task they think should have some gravity to it rather than trusting anybody to make a good judgment, and in this case, it was going to be seen by someone doing the reviewing anyway. But in their mind, everyone is just going to be irresponsible and everything is a slippery slope because they have zero trust in their workers to have reasonable judgment. Just seems like usual corpo owner culture issues though.
    Twitter just seems like a bit of a circus though. :p

  • @hattrickster33
    @hattrickster33 6 หลายเดือนก่อน

    Just like the renaming failed since Elon didn't listen to marketing and UX experts, I wouldn't be surprised if this "solution" came down from the top without considering input from SWEs who know what they're doing.

  • @wlockuz4467
    @wlockuz4467 6 หลายเดือนก่อน

    This would've never happened at old Twitter because they never would've changed the name 🤦‍♂️

  • @xanderlastname3281
    @xanderlastname3281 6 หลายเดือนก่อน +1

    A clbuttic clbuttic mistake

  • @disasterarea9341
    @disasterarea9341 7 หลายเดือนก่อน +1

    i liked twitter but i stopped using it once elon took over. yikes

  • @alicenNorwood
    @alicenNorwood 7 หลายเดือนก่อน +23

    What NeetCode is new primeagen?

    • @climber-fd1ww
      @climber-fd1ww 7 หลายเดือนก่อน +55

      Not a chance. I actually learned a few technical concepts with Neetcode. I usually leave a primeagen's video wanting that hour back

    • @UnknownEntity606
      @UnknownEntity606 7 หลายเดือนก่อน

      Neetcode is 10x more beginner friendly

    • @zweitekonto9654
      @zweitekonto9654 7 หลายเดือนก่อน +7

      ​@@climber-fd1wwLMAO. This is actually true. I only watch primeagen when I want to eat something.

    • @TheFinalB055
      @TheFinalB055 7 หลายเดือนก่อน

      @@zweitekonto9654 yeah sooo true 😂

    • @samuraijosh1595
      @samuraijosh1595 7 หลายเดือนก่อน

      @@climber-fd1ww true, true, primeagen is simply for programmers to chill and have a chat

  • @amymo5187
    @amymo5187 6 หลายเดือนก่อน

    Its the funny cause the possible causes really weren't all that unlikely for Twitter, I mean wasn't the Heartbleed exploit from like 2012~ an XSS exploit itself?

  • @Yulenka-
    @Yulenka- 6 หลายเดือนก่อน +2

    Ah yes, Elon Musk, always solving humanity's biggest and most existential problems. What would we do without you (we'll be fine) 🤦🏽‍♀️

  • @Lukie-Boy
    @Lukie-Boy 6 หลายเดือนก่อน

    My own personal website does shady shit but not this bad :O

  • @Taparu2
    @Taparu2 6 หลายเดือนก่อน

    On the web anyone anywhere has always been able to create a link named one thing that links elsewhere.

    • @woahmamaawoogahonkahonka
      @woahmamaawoogahonkahonka 6 หลายเดือนก่อน +2

      But now it’s much, much easier to make and disguise it as a legitimate link.

  • @mathew2214
    @mathew2214 6 หลายเดือนก่อน

    >whatis a test enviroment

  • @sasho_b.
    @sasho_b. 7 หลายเดือนก่อน

    "This is Elon Musk, Tesla's co-founder and CEO"

  • @sirseven3
    @sirseven3 6 หลายเดือนก่อน

    Whe you convert without specifying bounds 😂

  • @CainXVII
    @CainXVII 6 หลายเดือนก่อน

    I don't know if my google credentials are worth much. They are welcome to the 4 videos I made in 7th grade

  • @greensnr1
    @greensnr1 6 หลายเดือนก่อน +3

    the "security vulnerability" is... hyperlinks? It's something you can do with any hyperlink feature? It's embarrassing code but not much of a vulnerability

  • @wheedler
    @wheedler 6 หลายเดือนก่อน

    I like bureacracy.

  • @moover123
    @moover123 6 หลายเดือนก่อน

    let's call it titter from now on

  • @daniloh8113
    @daniloh8113 6 หลายเดือนก่อน

    Security team? Come on this REEKS of a change that elon himself forced them to ship

  • @bomblii
    @bomblii 6 หลายเดือนก่อน

    Moral of the story: Elon can't run a website.

  • @TheFuriousNightFury
    @TheFuriousNightFury 6 หลายเดือนก่อน

    heaven forbid you use the word Twitterpated. would that.... like....

  • @TerabyteTy300
    @TerabyteTy300 7 หลายเดือนก่อน +1

    Ok when he said the word subscribe at 1:20 the subscribe button was highlighting…. That was cool 🤯 and it worked, I subscribed🎉

  • @barb0za0
    @barb0za0 6 หลายเดือนก่อน

    so happy at this elon/twitter hate in the comments lol

  • @charredUtensil
    @charredUtensil 6 หลายเดือนก่อน

    What a clbuttic mistake!

  • @cewla3348
    @cewla3348 6 หลายเดือนก่อน

    100% a regex issue

  • @JonnySolomon
    @JonnySolomon 6 หลายเดือนก่อน

    loved this

  • @als_pals
    @als_pals 6 หลายเดือนก่อน +1

    Twitter has had an xss vulnerability before but thwt was probably over a decade ago

  • @NStripleseven
    @NStripleseven 6 หลายเดือนก่อน

    A clbuttic error.

  • @Luckmann
    @Luckmann 6 หลายเดือนก่อน

    Honestly, you call this trivial, but it's really not. It's fairly serious, especially for the normie market that doesn't even known what a URL is. This fix probably save tons of boomers and zoomers.

  • @anon5992
    @anon5992 7 หลายเดือนก่อน

    classic elon moment

  • @dubz5149
    @dubz5149 6 หลายเดือนก่อน

    LGTM!

  • @DragoNate
    @DragoNate 6 หลายเดือนก่อน

    cross site what now? csrf who?
    i just assumed that twitter, since it was renamed x including the website, basically forced "twitter" to autocorrect to "x", especially with urls, without context.

  • @bookle5829
    @bookle5829 4 หลายเดือนก่อน

    based ublock user

  • @maacpiash
    @maacpiash 6 หลายเดือนก่อน

    Great video, but that was a long intro. We know what XSS and CSRF are 🤷🏽‍♂️