{"id":42867,"date":"2024-04-16T23:45:48","date_gmt":"2024-04-17T03:45:48","guid":{"rendered":"https:\/\/mjtsai.com\/blog\/?p=42867"},"modified":"2024-06-18T11:10:49","modified_gmt":"2024-06-18T15:10:49","slug":"twitters-pivot-to-x-com-is-a-gift-to-phishers","status":"publish","type":"post","link":"https:\/\/mjtsai.com\/blog\/2024\/04\/16\/twitters-pivot-to-x-com-is-a-gift-to-phishers\/","title":{"rendered":"Twitter&rsquo;s Pivot to x.com Is a Gift to Phishers"},"content":{"rendered":"<p><a href=\"https:\/\/krebsonsecurity.com\/2024\/04\/twitters-clumsy-pivot-to-x-com-is-a-gift-to-phishers\/\">Brian Krebs<\/a> (<a href=\"https:\/\/news.ycombinator.com\/item?id=39991173\">Hacker News<\/a>):<\/p>\n<blockquote cite=\"https:\/\/krebsonsecurity.com\/2024\/04\/twitters-clumsy-pivot-to-x-com-is-a-gift-to-phishers\/\"><p>On April 9, Twitter\/X began automatically modifying links that mention &ldquo;twitter.com&rdquo; to read &ldquo;x.com&rdquo; instead. But over the past 48 hours, dozens of new domain names have been registered that demonstrate how this change could be used to craft convincing phishing links &mdash; such as <strong>fedetwitter[.]com<\/strong>, which until very recently rendered as <strong>fedex.com<\/strong> in tweets.<\/p><p>[&#8230;]<\/p><p>The apparent oversight by Twitter\/X was cause for amusement and amazement from many former users who have migrated to other social media platforms since the new CEO took over. <strong>Matthew Garrett<\/strong>, a lecturer at U.C. Berkeley&rsquo;s School of Information, <a href=\"https:\/\/infosec.exchange\/@mjg59@nondeterministic.computer\/112243298637438787\">summed up<\/a> the Schadenfreude thusly:<\/p><p>&ldquo;Twitter just doing a &lsquo;redirect links in tweets that go to x.com to twitter.com instead but accidentally do so for all domains that end x.com like eg spacex.com going to spacetwitter.com&rsquo; is not absolutely the funniest thing I could imagine but it&rsquo;s high up there.&rdquo;<\/p><\/blockquote>\n<p>I still go to <tt>twitter.com<\/tt>, which serves links to <tt>twitter.com<\/tt> rather than <tt>x.com<\/tt>. And if I go to <tt>x.com<\/tt> it redirects me to <tt>twitter.com<\/tt>.<\/p>\n\n<p>Previously:<\/p>\n<ul>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2024\/03\/27\/1password-co-tracking-links\/\">1Password.co Tracking Links<\/a><\/li>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2023\/08\/01\/twitter-is-now-x\/\">Twitter Is Now X<\/a><\/li>\n<\/ul>\n\n<p id=\"twitters-pivot-to-x-com-is-a-gift-to-phishers-update-2024-04-24\">Update (2024-04-24): See also: <a href=\"https:\/\/www.schneier.com\/blog\/archives\/2024\/04\/x-com-automatically-changing-link-names-but-not-links.html\">Bruce Schneier<\/a>.<\/p>\n\n<p id=\"twitters-pivot-to-x-com-is-a-gift-to-phishers-update-2024-05-17\">Update (2024-05-17): <a href=\"https:\/\/www.theverge.com\/2024\/5\/17\/23829098\/twitter-x-com-url-links-switch\">Jay Peters and Thomas Ricker<\/a>:<\/p>\n<blockquote cite=\"https:\/\/www.theverge.com\/2024\/5\/17\/23829098\/twitter-x-com-url-links-switch\">\n<p>The social network formerly known as Twitter has officially adopted X.com for all its core systems. That means typing twitter.com in your browser will now redirect to Elon Musk&rsquo;s favored domain, or should.<\/p>\n<\/blockquote>\n\n<p id=\"twitters-pivot-to-x-com-is-a-gift-to-phishers-update-2024-05-20\">Update (2024-05-20): See also: <a href=\"https:\/\/x.com\/DataChaz\/status\/1791449892730094061\">DataChazGPT<\/a>.<\/p>\n\n<p id=\"twitters-pivot-to-x-com-is-a-gift-to-phishers-update-2024-06-18\">Update (2024-06-18): <a href=\"https:\/\/mastodon.social\/@rosyna\/112608424841824919\">Rosyna Keller<\/a>:<\/p>\n<blockquote cite=\"https:\/\/mastodon.social\/@rosyna\/112608424841824919\">\n<p>If you&rsquo;ve ever wondered why Twitter links keep breaking it&rsquo;s because Musk replaced the &ldquo;twitter:&rdquo; in OpenGraph declarations with &ldquo;x:&rdquo;<\/p>\n<\/blockquote>","protected":false},"excerpt":{"rendered":"<p>Brian Krebs (Hacker News): On April 9, Twitter\/X began automatically modifying links that mention &ldquo;twitter.com&rdquo; to read &ldquo;x.com&rdquo; instead. But over the past 48 hours, dozens of new domain names have been registered that demonstrate how this change could be used to craft convincing phishing links &mdash; such as fedetwitter[.]com, which until very recently rendered [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"apple_news_api_created_at":"2024-04-17T03:45:51Z","apple_news_api_id":"509abd50-6264-45d7-904d-8951ab507b83","apple_news_api_modified_at":"2024-06-18T15:10:53Z","apple_news_api_revision":"AAAAAAAAAAAAAAAAAAAAAw==","apple_news_api_share_url":"https:\/\/apple.news\/AUJq9UGJkRdeQTYlRq1B7gw","apple_news_coverimage":0,"apple_news_coverimage_caption":"","apple_news_is_hidden":false,"apple_news_is_paid":false,"apple_news_is_preview":false,"apple_news_is_sponsored":false,"apple_news_maturity_rating":"","apple_news_metadata":"\"\"","apple_news_pullquote":"","apple_news_pullquote_position":"","apple_news_slug":"","apple_news_sections":"\"\"","apple_news_suppress_video_url":false,"apple_news_use_image_component":false,"footnotes":""},"categories":[2],"tags":[1200,1400,49,489,96],"class_list":["post-42867","post","type-post","status-publish","format-standard","hentry","category-technology","tag-phishing","tag-spacex","tag-twitter","tag-url","tag-web"],"apple_news_notices":[],"_links":{"self":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/42867","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/comments?post=42867"}],"version-history":[{"count":5,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/42867\/revisions"}],"predecessor-version":[{"id":43734,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/42867\/revisions\/43734"}],"wp:attachment":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/media?parent=42867"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/categories?post=42867"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/tags?post=42867"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}