
The popular social network Twitter recently discovered a security flaw in its platform that was using users' phone numbers and email addresses for targeted advertising, without their permission
Phone numbers and emails were provided to the platform for account, but the flaw, which now appears to have been fixed, used them to serve ads.
Two-factor authentication numbers were used for advertising
Twitter is asking users to provide their phone numbers and email addresses to set up two-factor authentication, the feature that authenticates a login attempt by sending a unique code to the account holder's number.
The method helps protect accounts from breaches, but in this case, Twitter says the numbers/emails provided for 2FA were used for targeted advertising.
How were phone numbers used?
Twitter, analyzing the bug in a blog post, claimed that it came from its tailored audiences program, which allows advertisers to serve ads using their own marketing lists containing people's numbers and email addresses.
However, as the program progressed, the company found that when advertisers uploaded their list, users were logging in with the numbers and emails they had uploaded for two-factor authentication.
Twitter said the error occurred "inadvertently" and was fixed on September 17.
The company also apologized for the issue, clarifying that no personal information from users was shared with advertisers and pledged that there would be no similar incident in the future.
However, Twitter did not provide information on how many people were affected by this bug.
It should be noted that this is not the first time the social network has been involved in security.
In 2018, the company admitted to storing 330 million users' passwords in plain text and leaking phone numbers, and also breached location data last May.
