Heads up.
www.oxfordstudent.com/2018/10/26/transphobic-tweets-linked-to-oxford-sociology-professor/
"The Twitter account, named Henry Wimbush and still online at the time of publication, has been tweeting statements such as “transphobia is a word created by fascists, and used by cowards, to manipulate morons” since first Tweeting in January.
"it was found that the account in question could be linked to a partial phone number and Yahoo! email using freely available data and by making use of Twitter’s various functions. The Yahoo! email itself is also linked to a phone number ending in the same numbers as those previously identified, while also revealing that it is connected to the" [partially redacted email]
How this hack works:
go to twitter.com/login
click 'forgotten your password'
type in your username, or a third party's username
you will get a message something like this:
We found the following information associated with your account.
Text a code to my phone ending in 12.
Email a link to ab*********@a.**
Note that:
- the last digits of the phone number can be used to tie your account to any phone number, since there are obviously 100 different combinations, so if it matches a phone number known by the doxer, it essentially identifies you
- I'm not clear exactly how much information is given on email addresses in every case, but at a minimum you get the first two letters of the username (before the @), the first two letters of the domain name (the bit after the @), and the exact length of both parts of the address.
So for example, if you signed up, anonymously, to Twitter using the email address justine*@mumsnet.com, then it would show to any attacker ju******@mu.** if they tried to recover it in order to dox the owner.
The use of this feature in order to dox people most likely constitutes an offence under the Computer Misuse Act s1 as the use of this feature to dox people is clearly not authorised by Twitter, and I would encourage those affected to report the people involved to the police.
Hence I am not repeating the criminally obtained dox of the person, and I would encourage people NOT the repeat the name in this thread.
Note that this doxing follows quite soon from Aimee Challenor boasting of outing Miranda Yardley's Twitter account using the same means.
Whether there are more serious offences committed is hard to say, as the doxing itself is obviously a preparatory act to having people fired, harassed, threatened, family & children harassed, and so on, but the doing so is not necessarily planned by the original doxer so it would be hard to prove a more serious offence.
I would advise those who are on Twitter and are not using their real name to create a gmail/yahoo/other anonymous webmail account, matching the twitter username (so if you are @ARealRadFem on Twitter, make a yahoo mail account [email protected]). In terms of the phone verification that's a little trickier as the 1/100 last two digits is VERY outing if they have a suspicion who you are, but otherwise completely useless. I have had some luck in the past with adding an extra digit (so if you are 07812 456789, you can add an extra digit on like this 07812 4567890, and verification phone calls still work), but YMMV on that.