Security News > 2020 > April > Twitter warns users – Firefox might retain private messages

Twitter warns users – Firefox might retain private messages
2020-04-07 12:11

This means that if you accessed Twitter from a shared or public computer via Mozilla Firefox and took actions like downloading your Twitter data archive or sending or receiving media via Direct Message, this information may have been stored in the browser's cache even after you logged out of Twitter.

We started Firefox with a totally empty cache, browsed to twitter.com, and then grabbed a copy of the files Firefox had chosen to keep for later in its cache directory.

Why did Firefox cache data that Twitter surely didn't want it to, as stated by Twitter in the blog post quoted above?

Inquisitive users might indeed trip over old copies of private messages in the cache that they'd reasonably have assumed wouldn't be there.

As far as we can tell, the issue has been sorted out amicably, with Twitter now unambiguously telling Firefox to no-store the offending data, and Firefox accordingly not storing it.


News URL

https://nakedsecurity.sophos.com/2020/04/07/twitter-warns-users-firefox-might-hold-on-to-private-messages/

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Twitter 6 1 7 1 0 9