{"id":20195,"date":"2022-09-26T16:10:53","date_gmt":"2022-09-27T00:10:53","guid":{"rendered":"https:\/\/www.palada.net\/index.php\/2022\/09\/26\/news-13928\/"},"modified":"2022-09-26T16:10:53","modified_gmt":"2022-09-27T00:10:53","slug":"news-13928","status":"publish","type":"post","link":"https:\/\/www.palada.net\/index.php\/2022\/09\/26\/news-13928\/","title":{"rendered":"Twitter fixes bug that left devices logged in after password reset"},"content":{"rendered":"<p>Twitter says it has fixed a bug that meant users weren&#8217;t logged out of active sessions on all devices after manually resetting their passwords.&nbsp;<\/p>\n<p>Writing on&nbsp;<a rel=\"noreferrer noopener\" href=\"https:\/\/privacy.twitter.com\/en\/blog\/2022\/an-issue-impacting-password-resets\" target=\"_blank\">its blog<\/a>, Twitter said:<\/p>\n<blockquote>\n<p>&#8220;We want to let you know that we recently fixed a bug that allowed Twitter accounts to stay logged in from multiple devices after a voluntary password reset. In order to help ensure the safety and security of everyone that may have been affected, we&#8217;ve proactively logged people who may have been affected out of active sessions.&#8221;<\/p>\n<\/blockquote>\n<p>Staying logged in on multiple devices after explicitly changing an account password is a huge security risk. If someone has breached an account already, that would leave them logged in and able to impersonate the user, rummage through DMs,&nbsp;change the password again, and more.&nbsp;<\/p>\n<p>Twitter says it has logged out all affected users, everywhere.<\/p>\n<blockquote class=\"twitter-tweet\">\n<p lang=\"en\" dir=\"ltr\">We fixed a bug that didn&#8217;t close all active logged in sessions on Android and iOS after an account&#8217;s password was reset. To keep your account safe, we logged some of you out. You can log back in to keep using Twitter.<\/p>\n<p>For more details on what happened: <a href=\"https:\/\/t.co\/OmjLKOe5bs\">https:\/\/t.co\/OmjLKOe5bs<\/a><\/p>\n<p> &mdash; Twitter Support (@TwitterSupport) <a href=\"https:\/\/twitter.com\/TwitterSupport\/status\/1572661999296978944?ref_src=twsrc%5Etfw\">September 21, 2022<\/a><\/p><\/blockquote>\n<p class=\"sample\"> <script async=\"\" src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script> <\/p>\n<p>Twitter&nbsp;says it has reached out to users who might have been affected by the bug. For everyone else, it&#8217;s business as usual.<\/p>\n<p><a href=\"https:\/\/www.malwarebytes.com\/blog\/news\/2022\/09\/twitter-fixes-bug-that-left-devices-logged-in-after-password-reset\" target=\"bwo\" >https:\/\/blog.malwarebytes.com\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<table cellpadding='10'>\n<tr>\n<td valign='top' align='left'>\n<p>Categories: <a href='https:\/\/www.malwarebytes.com\/blog\/category\/news' rel='category tag'>News<\/a><\/p>\n<p>Categories: <a href='https:\/\/www.malwarebytes.com\/blog\/category\/privacy' rel='category tag'>Privacy<\/a><\/p>\n<p>Twitter says it has fixed a bug that meant users weren&#8217;t logged out of active sessions on all devices after manually resetting their passwords. <\/p>\n<table width='100%'>\n<tr>\n<td align=right>\n<p><b>(<a href='https:\/\/www.malwarebytes.com\/blog\/news\/2022\/09\/twitter-fixes-bug-that-left-devices-logged-in-after-password-reset' title='Twitter fixes bug that left devices logged in after password reset'>Read more&#8230;<\/a>)<\/b><\/p>\n<\/td>\n<\/tr>\n<\/table>\n<\/td>\n<\/tr>\n<\/table>\n<p>The post <a rel='nofollow' href='https:\/\/www.malwarebytes.com\/blog\/news\/2022\/09\/twitter-fixes-bug-that-left-devices-logged-in-after-password-reset'>Twitter fixes bug that left devices logged in after password reset<\/a> appeared first on <a rel='nofollow' href='https:\/\/www.malwarebytes.com'>Malwarebytes Labs<\/a>.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10488,10378],"tags":[32,5897],"class_list":["post-20195","post","type-post","status-publish","format-standard","hentry","category-malwarebytes","category-security","tag-news","tag-privacy"],"_links":{"self":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/20195","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=20195"}],"version-history":[{"count":0,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/20195\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=20195"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=20195"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=20195"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}