Twitter Warns of Account Hijacking Flaw in Android App, Urges Immediate Updates

Anyone running an older version of the Twitter app on Android might want to reconsider their update phobia. Twitter reports that a flaw in the app could have allowed an attacker to access accounts to see protected data and even post content as if they were the victim. The vulnerability is patched in the latest versions, but that won’t matter if you’ve got automatic updates turned off.
Twitter released scant details of the hack in its recent Privacy Center blog post. It only said that the process to break into an account via the Android app was “complicated” and involved injecting malicious code into restricted storage areas of the app. It did not specify whether or not someone needed physical access to the device, but that’s probably dependent on the availability of other exploits. By chaining several attacks together, it may be possible to remotely compromise the Twitter client.
Regardless of how difficult the attack was, taking over Twitter accounts is a high-reward attack. Someone could use this to push malware on large numbers unsuspecting Twitter users by taking over high-profile accounts. Imagine if Elon Musk’s real Twitter account suddenly tweeted a link to free Bitcoins. A lot of people would click of only out of sheer curiosity.

Twitter pushed out a patch for this update in November. Users on Android 5.0 Lollipop or later should now be on v8.18 or later for full protection. Twitter even went to the effort of releasing an update for Android users on the ancient KitKat version of the OS (v7.93.4), also in November. The company waited until now to ensure most users would be updated. Even the vague explanation from the blog post could point online criminals in the direction of the flaw.
Twitter users with third-party clients are not affected by the bug, nor are those on iOS. You can all continue tweeting without hurriedly checking your client version. Android users on the old version of the official Twitter client should update immediately. It is also generally inadvisable to disable automatic updates in the Play Store. You can (and should) turn on automatic updates in the Play Store settings under “Auto-update apps.” You can choose between Wi-Fi only (the defaut), over any network, and not at all.
Continue reading

Terraria Dev Cancels Stadia Version After Getting Locked Out of Google Account
Re-Logic co-founder Andrew Spinks says Google has banned his account, locking him out of thousands worth of dollars in content. His response is to cancel Terraria for Stadia.

Microsoft Introduces Windows 11: New UI, 64-Bit Only, Mandatory Accounts
Microsoft lifted the lid on Windows 11 today, capping several weeks of speculation, testing, and argument over the size of the OS update and the degree to which it would upend the status quo.

How to Install Windows 11 Home With a Local Account
It's still possible to install Windows 11 with a local account, if you're willing to jump through a few hoops to do it.