arrow_upward

Thread Rating:
  • 0 Vote(s) - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5
Twitter annoyance - phone verifications out of the blue! What does this mean?
#1
We have a Twitter account at another host that one of the Admin put lots of work in.  It was started in 2017 before the advent of TweetDeck, which meant that the account login and password had to be shared by the owner and the Admin who did the work, rather than giving the Admin Admin access.  Now of course it's much easier with TweetDeck, but then it was different.

When we tried to access the account a week ago, all of a sudden there is a popup from Twitter asking for verification by phone only, ending in two digits that the owner says is definitely not his phone number.  The annoying part was that the popup didn't even give an alternative option for e-mail verification, only phone verification.  Then to make it even more suspenseful, when I tried to do a password reset request as a Plan B to get past verification, I discovered that our Twitter account stopped receiving Twitter Notifications at our e-mail address since November last year.  It stopped on 24 November 2018.  I then went like a tooth comb through WHM e-mail lists, and looks as though the emails haven't been blocked or junked as they're nowhere to be found.  They just haven't been received.

I'm almost certain the account has not been hacked. If it had, I'm sure something would have looked different in the tweets and stood out. All of it looks as it normally looks.

So during all of that when I checked tracking - this is what I received, and here I'm lost.  What does this mean?  Not sure if I understand wrongly, but isn't this a routing system through Google that is for apps?  So could it be the routing system that is a problem for us, and is there a way to sort this out - like is there anything on our end we can do to make sure we receive those notifications?

This is the tracking numbers:

[Image: 2QJ6wiz.png]

Now what was interesting is that we have received an e-mail from Google in Ireland - [email protected].  Not sure whether this is significant.  The notification e-mails from [email protected] that we haven't received come from California in the US (says so in the footer of their notifications).
Terminal
Thank you to Post4VPS and VirMach for my awesome VPS 9!  
#2
are you sure none else has changed the number in the mean time. like if someone was handling your responsibilities before you.

last resort might be contacting customer care for help.

this really sks. i gotta check my old accounts and delete the ones i dont use anymore. thanks for the heads up.
#3
(01-16-2019, 09:17 AM)rudra Wrote: are you sure none else has changed the number in the mean time. like if someone was handling your responsibilities before you.

last resort might be contacting customer care for help.

this really sks. i gotta check my old accounts and delete the ones i dont use anymore. thanks for the heads up.
I think I've found the problem.  Maybe you can enlighten me here.  In November 2018 this host changed servers from a dedicated server in France (OVH) to a VPS in Germany (Contabo).  Now when that happens, does that have an effect on the DKIM and SPF?  As the name servers of course changed, and the DNS also changed completely.

The Twitter notifications completely stopped at the same time.  So could that be the reason that the Twitter notifications also stopped?

Also, I then did a check with https://toolbox.googleapps.com/apps/checkmx/  and this was the result!

Note that there are DKIM and SPF records in the WHM for the domain - but maybe after the server change last November something happened so they aren't working any longer, or am I misreading the Google checker?

[Image: rMcq1MZ.png]
Terminal
Thank you to Post4VPS and VirMach for my awesome VPS 9!  
#4
yes. i say you just follow those help links and. make changes accordingly. clearly the records exist. but not the ones google system is expecting them to be.

that check is very helpful. aaah google guys. they almost always think of things people might need and implement them...
#5
I think Twitter asked everyone to change passwords because of a vulnerability end of last year. Don't remember the exact time But I remember changing passwords of all my important Twitter accounts. Now if Admin is sure that phone No. is not his than that is something to think about. But basic questions you need to ask your self is,

Why Does Phone number is different (if the owner is sure its not his) ? So someone must have changed it.

Why email verification doesn't show ? Someone has used that phone No. to verify the account.

Why u haven't received notifications since end of the last year ? Same person might have change the email...

I think you might want to contact Twitter. The account might be compromised or might not. Still it's worth the try, Here is the form,

https://help.twitter.com/forms


-
I'm stuck to bed with lots of antibiotics because of a leg problem so having hard time doing posts these days. Its now I miss having a Laptop. haha
#6
(01-17-2019, 12:39 PM)xdude Wrote: I think Twitter asked everyone to change passwords because of a vulnerability end of last year. Don't remember the exact time But I remember changing passwords of all my important Twitter accounts. Now if Admin is sure that phone No. is not his than that is something to think about. But basic questions you need to ask your self is,
Aha .... then that explains the security probes.

(01-17-2019, 12:39 PM)xdude Wrote: Why Does Phone number is different  (if the owner is sure its not his) ? So someone must have changed it.

Why email verification doesn't show ? Someone has used that phone No. to verify the account.

Why u haven't received notifications since end of the last year ? Same person might have change the email...
I don't think the account was hacked, as it looks OK, so only thing I can think is that someone forgot they had that phone number.  The account was started in the days before TweetDeck when it wasn't possible for the owner to add users, so every one shared in the same login and password.  Making it into a regional thing too.  

I'm no expert of Google App Mail, but closest I could get are the MX records I made a print screen off that showed up when I did a troubleshoot track of [email protected] - which is the twitter mail account that works with accounts.  

[Image: 2QJ6wiz.png]

I then discovered those records belong to Google App.  Possibly when a user ticks phone in the settings then the mail works with Google App and expects Google App MX records at its destination - which there were not so possibly Twitter notifications have been bounced back.

So my theory is that Twitter - probably during that security scare - made some changes that included for phones to work with Google Apps mail.  This means that they deal different with mail by phone than mail through browser - and quite a number of users must have been caught up in it too. I'm almost certain we're not the only ones caught this way.  When I checked cpanel Forum, there were discussions by WHM owners who were trying to get the best of the two worlds with their mail by dealing with an external exchange - i.e. Google apps, as well as having mail on the server - which is quite an art - like cpanel acrobatics.  

Anyway, the lesson for me out of this is that when one has a Twitter account, to be careful about the preference for phone or desktop as looks as though Twitter is dealing different with the two.

I've put support requests to Twitter in a number of places.  They say it takes a week or more to receive a reply - so not sure whether they'll be able to help.  


(01-17-2019, 12:39 PM)xdude Wrote: I'm stuck to bed with lots of antibiotics because of a leg problem so having hard time doing posts these days. Its now I miss having a Laptop. haha
Hope it gets fixed soon! Smile
Terminal
Thank you to Post4VPS and VirMach for my awesome VPS 9!  


Possibly Related Threads…
Thread
Author
Replies
Views
Last Post
7,482
07-31-2018, 01:50 PM
Last Post: AwesomeCoolDude
19,299
01-15-2018, 05:53 PM
Last Post: Vuluts

person_pin_circle Users browsing this thread: 1 Guest(s)
Sponsors: VirMach - Host4Fun - CubeData - Evolution-Host - HostDare - Hyper Expert - Shadow Hosting - Bladenode - Hostlease - RackNerd - ReadyDedis - Limitless Hosting