8 ms·
"We have no evidence that this was exploited" is a standard psychological trick they pull in vulnerability announcements to give an unfounded impression that it
by addingnumbers 4y ago
"We have no evidence that this was exploited" is a standard psychological trick they pull in vulnerability announcements to give an unfounded impression that it hasn't been exploited.
- antisthenes 4y ago"an absence of evidence is not evidence of absence" Isn't that taught in..uh..I dunno, middle school science class? Just because you don't see the rabbit, doesn't mean it doesn't exist.
- themitigating 4y agoNo, that's insane. That means I can just tell people you might have raped someone, I don't have any evidence but that doesn't mean it didn't happen. https://medicine.uq.edu.au/article/2019/04/you-look-do-not-find-why-absence-evidence-can-be-useful-thing# https://medicine.uq.edu.au/article/2019/04/you-look-do-not-f...
- addingnumbers 4y agoThat's why I referred to it as a psychological trick. They should be open and forthcoming about their level of confidence, instead of using the least worrying language they can offer while remaining technically correct.
- Dudeman112 4y agoIt doesn't have to be a psychological trick. Sometimes you don't actually have evidence it was exploited - at which point what are you meant to say?
- jazzyjackson 4y ago"we have no way of knowing" is a much more informative statement than "we have no evidence", but it belies fallibility on the part of the speaker.
- mewpmewp2 4y ago"We have no way of knowing" may not be correct statement. There could always be a way to know that you may have missed. It would be inhuman to claim "we have no way of knowing" in circumstances like this.
- jazzyjackson 4y agoFair enough, perhaps to be more specific they could say "we have not kept sufficiently detailed logs to determine what happened"
- redler 4y ago“We have no evidence” strongly implies some sort of extensive forensic dance was performed, and was fruitless. “We have no way of knowing” sounds much more like epistemological resignation. “Evidence” is a pretty loaded word to use.
- roughly 4y agoWell, “after investigating by <insert actual efforts taken here>, we were unable to find evidence it was exploited” would be a good start, as it would indicate some effort was put into disproving the hypothesis.
- posix86 4y agoI'm 100% certain they did put in actual effort. If you're so keen on knowing, there's a form at the bottom you can use to ask them.
- deleted 4y ago[deleted]
- kadoban 4y agoThen they should share a bit about what they researched and how confident they are one way or another. Seems like a fair expectation to have, to me.
- kbenson 4y agoIt provides close to nothing, because it doesn't indicate whether there was no evidence because there could be no evidence - you keep no logs - or whether there was no evidence in spite of the fact there definitely should be if it was exploited because of copious information kept that would show it.
- lewantmontreal 4y ago’We have no proof this wasn’t exploited’
- deleted 4y ago[deleted]
- Tenobrus 4y agoI mean in practice what it tends to mean is the logs only had a 3 month ttl so really could be either way. "no evidence" implies there is at least a place there could have been evidence, they looked, and didn't find any, which is a weak but nonzero update towards it having not happened. It would be nice if they clarified exactly what they checked.
- autoexec 4y ago> "no evidence" implies there is at least a place there could have been evidence, they looked, and didn't find any Yeah I'd never assume that any of that is true. Sure, there probably are ways twitter could find out if something has been being exploited like evidence in server logs or new batches of accounts showing up for sale on the black market, but I wouldn't trust that they looked for them, or that they looked very hard, or that the person making press statements was told about it either way. If a company has a financial incentive to not find information it's weird to assume they'd seriously look or be trusted to be honest about what they found.
- addingnumbers 4y agoIt would be more honest to say "We aren't able to determine whether it was exploited" which could better brace potentially impacted users for the possibility they might be affected. This is a relatively benign case but the same language is used in other breaches when people should be taking measures like freezing their credit or reviewing financial transactions.
- sangnoir 4y agoHow can anyone make any assertions about unknown unknowns? It's one thing to say "My car was stolen", and another to declare "I am unable to determine if it's en route to the Taliban."
- Lutger 4y agoIts not an unknown unknown. If there's a vulnerability and you're a hot target, you know there's a decent chance of getting exploited.
- upsidesinclude 4y agoThat isn't a reasonable analogy in any way. The only thing that could happen with the data would be that it is exploited. The only thing that happens to stolen cars is not going to the taliban. These are not even similar in nature. They aren't saying "the data was stolen". They also aren't saying "the data was available for exploit we are unable to determine if that occured." What if they never looked for evidence of unauthorized access? They wouldn't have any! This is the same as modern science and medicine frequently using this academic phrase, no evidence, when what they mean is that there has been no investigation.
- execveat 4y agoYou can make positive assertions though. E.g. attack might have been simple in which case it's possible to produce indicators that cover 100% of variants. Or it could have been complex and indicators either don't cover every possible attack or they produce large number of false positives. Another thing to mention would be how long in the past you were able to look. E.g. in this case they have found out that the bug was introduced in 2021, were they able to inspect logs covering all of that period or did they only had limited logs/other evidence so it's impossible to know whether anyone used this opportunity or not?
- throwaway292939 4y agoThe phrasing is a bit more specific.. "At that time, we had no evidence.." It could also mean "oh I spent five minutes looking into it and didn't see any evidence"
- deleted 4y ago[deleted]
- diego_sandoval 4y agoThe burden of proof should fall on them to demonstrate that it wasn't exploited. Otherwise, the reasonable thing to do is to assume that it was exploited, because they have no evidence to show that it wasn't. The phrase is a psychological trick because it creates the illusion that the burden of proof falls on the other side.
- res0nat0r 4y agoYou can't prove a negative.
- bandrami 4y agoThere is no greatest prime number. If there were, call it p, and let q = Π(P), P∈N:P is prime (Eratosthenes showed this is computable) Then q+1 % 1 modulo every lesser prime, meaning q+1 is prime, and p is thus not the greatest prime. There you go. We have just proven a negative.
- mannykannot 4y agoIn which case, the second paragraph applies.
- kadoban 4y agoBut then you might as well just assume everything is compromised, at all times, even if there's been no announcement. They could just not be telling you. Which is maybe not the worst strategy, but it's going to be pretty exhausting. I'd suggest that instead we should just expect and enforce a certain amount of openness and honesty from companies when they fuck up in this way, so we can make informed decisions.
- mannykannot 4y agoWell, yes - this is the dilemma which is not resolved with empty platitudes, even though "you can't prove a negative." In the US and elsewhere, there are already some penalties for covering up a problem, and they should be expanded commensurately with the potential harm.
- deleted 4y ago[deleted]
- JuettnerDistrib 4y agoOther purpose than being a psychological trick, what purpose could pointing out the lack of evidence at the time have? Instead they could have written something like "We found the problem in 2021 and promptly fixed it. We first learned that it has been exploited in 2022."
- asddubs 4y agoI wonder, if you destroy all the evidence this was exploited, can you still claim you don't have any evidence this was exploited? Asking for opinions from non-lawyers only please
- johndhi 4y agohaha. I am a lawyer so sorry, but while you might be able to claim that, you are legally and ethically obligated to also divulge the intentional spoiling of hte evidence.
- justinclift 4y agoAs if the people giving orders at some of these companies care about ethics... ;)
- Lutger 4y agoTo be sure, use a clean room implementation: let IT destroy all the evidence, always. Then legal can claim 'we don't have any evidence'. source: I am not a lawyer
- procombo 4y agoWorks the same way with government. The "I am not aware of ..." is a great trick for when your organization is intentionally silod. The folks who get subpoenaed are left out of detailed info. It's a complete non-statement. I could bring up examples across both sides of the isle. It's all a big game.
- Bedon292 4y agoDon't currently have? Sure. The quote says "At that time, we had no evidence" so I think that would be harder to argue. You could maybe make the case the statement means: At that specific moment we didn't have any evidence because we already destroyed it. But it certainly implies they mean they had not found any before that point in time.
- harry8 4y agoIt would be a lot more convincing if they said they put a team on to it to investigate extensively and didn't find anything indicating it was exploited. Absence of evidence IS some evidence of absence if you look thoroughly. It sure isn't anything of the kind if you haven't actually tried to gather the evidence or are aware of giant holes in what you were able to gather.
- hunter2_ 4y agoI always wonder who "we" refers to in that usage, legally speaking. Does it refer only to a subset of employees / board members who are authorized to speak for the company? Because then even if someone analyzing logs sees something damning, if middle management is trained to stop that knowledge from reaching the top, then those speaking for the company can continue saying "we" didn't know it.
- lrvick 4y agoI have 100% seen this happen.
- johndhi 4y agoreally? what do you mean 'middle management is trained to keep that from getting to the top'? intentional malfeasance? where I work people are trying their best but dealing with complex systems, memories, and methods of communication. because of this, security issues are sometimes missed, sometimes poorly communicated, and sometimes poorly remediated.
- hobs 4y agoAlmost all companies operate with an extremely low level of trust and most places are blame, shame, and ultimately game the system all the way down. Hiding something often takes years to uncover and by then management has moved on, maybe even to their second company!
- t-3 4y agoProbably not 'trained' as much as 'heavily incentivized'. Nobody wants to be the messenger that gets shot for bringing bad news. Much easier to cover up and tell the big boss what they want to hear as long as you can.
- redler 4y agoIt means silos and information hiding are baked in — as a matter of corporate culture — at least in part to preserve the option of plausible deniability for statements like Twitter’s.
- themitigating 4y agoNo, that's a normal statement when there's no evidence something occurred. "I have no evidence he murdered someone" As opposed to "He might have murdered someone, or not, I just don't have any evidence" "It's possible he murdered someone I don't have any evidence though" "I don't have any evidence he murdered someone but that doesn't mean he didn't, I'm just asking questions"
- diffeomorphism 4y agoThat is not a normal statement if it is your company's fault the question even came up. "We left a giant tub filled with cyanide completely unsupervised in front of our door for months. We have no evidence that it was used to murder someone." Has an entirely different sound to it, no?
- pcthrowaway 4y agoMore like the tub was filled with water and "we have no evidence it was used to drown someone (but also we didn't check for floating bodies)"
- rrix2 4y agoor: "keeping fine grained indexed API logs around for months on end is too expensive so we threw out the body with the bathwater"
- lostcolony 4y ago"We left our gun outside, unsecured, but no one has complained they were shot with it and we didn't detect any fingerprints on it when we finally noticed it wasn't locked up properly"
- themitigating 4y agoNow you're claiming they didn't investigate properly which a completely different situation that you also don't have evidence for.
- drivebycomment 4y agoSuppose Twitter did all it could to investigate and found no evidence. What would you rather have Twitter say in that case ?
- addingnumbers 4y ago"We are unable to determine if the vulnerability was exploited." How hard they looked is not of any consequence if they can't tell it wasn't exploited.
- i_s 4y agoSaying there is an absence of evidence (of a leak) isn't useful by itself unless they also indicate whether that is evidence of absence (of a leak). I.e., they should indicate whether it is likely that they would have caught it if a leak had occured (e.g., via extensive logging).
- thayne 4y agoProvide some level of detail on how they looked for evidence. "We have no evidence" could mean "we didn't bother looking for evidence", or "we looked extensively for evidence, but didn't find any." In fact, the company has an incentive not to keep logs or collect evidence specifically so they can truthfully claim they don't have any evidence of a breach
- behringer 4y agoHow many man hours they spent investigating would be good.
- criddell 4y ago"We assume it was exploited and you should too."
- cush 4y agoAbsolutely. That said, it's very very hard sometimes to prove a negative.
- intelVISA 4y agoThe database just dropped itself automagically
- resonious 4y agoYes, potentially a euphemism for "we did not check to see if this was exploited, and thereby have no evidence it was exploited."
- _8j50 4y agoIt's not a trick. Incident response (not vulnerability announcement) is all about evidence. If you can't prove it, it didn't happen. They can probably stil take precautionary measures though which the announcement is part of.