Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Except this is not expecting perfection, it is expecting a level of security that can prevent children, literal children, from walking right through it. Which would not even be a problem except for the fact that this is far, far less than what Twitter has led their average user and stockholder to believe. To illustrate my point, if Twitter told the truth in big bold print at the top of every page so every user knows: "Determined teenagers can take over your account at any time." do you think this might outrage their users or harm their stock price? Did Twitter at any point say anything that might indicate that this is the truth of the matter and that would not be easily misconstrued by users? The evidence indicates yes, they would be outraged, and no, they at no point ever said anything that would lead anybody to believe that this was possible and hilariously easy. So, it hardly matters that maybe they or anybody else (say the FBI) can not provide a high level of security, what matters is that they committed material fraud in egregiously misrepresenting their product security to their users and stockholders.


Exactly. At least one of these kids used their personal gmail account on the hacking forum. These are not advanced hackers.


They've done more than you, and majority of others, though.


And robbers have done more robbing than me too. It's not a competition I'm interested in entering.


One underestimates the capability of determined teenagers at one's peril.


And many of them live in what amounts to a serviced apartment above a restaurant.

Idle hands.


> expecting a level of security that can prevent children, literal children, from walking right through it

Well, that's your problem.


Oh believe me, I am under no illusion about that fact. My point is that the average user is completely unaware of it and Twitter, like most other companies, has gone to great lengths to obscure this material fact from their users and stockholders. If they told their users and stockholders, in no uncertain terms, the level of security they actually provide, which is massively different than what the users and stockholders believe, then I would not fault them for upholding their promises even if they are lackluster.

The problem is that they have not revealed the massive discrepancy between the common expectation and the truth which I, and I suspect most people, would consider to be fraud. Some might argue that they did not guarantee the common expectation and therefore it is the consumers problem for engaging in wishful thinking, but that is frankly a ridiculous argument. We generally expect, and the law codifies, certain requirements on the consumer-business relationship which effectively amount to: "Consumers have certain reasonable expectations based on common sense, you can't just willy-nilly toss those in a contract and blame the consumer for not reading a 100 page contract where you get to sacrifice their first born in fine-print every time they buy bananas." I do not believe the law exactly codifies this form of fraud, but I think most would agree that a massive discrepancy between consumer expectation and the truth should be clearly communicated (the larger the discrepancy the more clearly/loudly) and acting otherwise should be at the least in the general vicinity of fraud.

In my opinion, the discrepancy is sufficiently large that it should constitute either criminal fraud or gross negligence depending on how aware Twitter was as to their own internal security. If they were aware, they engaged in fraud given they made no effort to properly inform anyone of their security. If they were not aware, they are grossly negligent in that they could not observe such a massive discrepancy between their beliefs and the truth. To anybody who reads this and says that this is a "heads I win, tails you lose" situation, I say that this is a result of the ridiculous discrepancy. If it were less ridiculous, like say a small group of organized hackers or a top-flight hacker, it would probably not qualify as gross negligence in Twitter's case if they were unaware, though it might still be fraud depending on the expectations laid out.

Incidentally, this reasoning scales to other cases people have mentioned like nuclear power plants or banks where people have certain expectations on their security which are likely different and more stringent than Twitter. The important thing is not that they all have the same high level of security, it is that the expectation matches reality and the reality is properly communicated.


My point was that there is no such level of security. It was a joke.


I mean determined teenagers created FB so...




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: