Naked Security Naked Security

Thought you’d blocked a Twitter user? Here’s how they can still dogpile you

A bug means someone you'd rather avoid on Twitter can still view and retweet your posts, even if you've blocked them

Have you blocked abusive Twitter users?

Well, good luck with that. It turns out that neither you nor President Trump – who’s known for being quick to hit the block button – can stop blocked accounts from replying to your tweets, thanks to a bug that’s making the rounds.

As Motherboard reports, all a blocked person has to do is create an additional, dummy account, toggle over to it to view the messages of whoever blocked them, compose a reply, toggle back to their main account, and then hit reply to engage with that person’s tweets anew.

You won’t see the replies, but the followers of the blocked account will. Which means if you’ve blocked someone who was encouraging abusive behavior from their followers, they can still egg on dogpiles from their main account by retweeting you.

Well, this is curious. The whack-a-mole problem was one of the things Twitter mentioned that it was tackling in July. In February, it had announced that it was giving people more ways to report targeted harassment, including taking steps to identify the whack-a-moles who get suspended only to go off and open new accounts.

In July, Ed Ho, general manager of Twitter’s consumer product and engineering department, said that thanks to these changes, Twitter’s new systems had removed twice the number of repeat offender accounts – the whack-a-moles – over the preceding four months.

And yet here we are. A commenter on our coverage of that announcement said they couldn’t see any improvement:

They recently suspended my account 2 days after I reported another user who was breaking their TOS by using 2 accounts to gang up and harass people (and used both accounts to mass DM me 70+ times in an hour).

Twitter’s internal numbers painted a far rosier picture than many of its users reported. That point was strongly underscored by a report from BuzzFeed, also posted in July, about how Twitter is still slow to respond to incidents of abuse unless they go viral or involve reporters or celebrities.

Basically, when it comes to getting Twitter to pay attention to its own rules against abuse, it pays to know somebody. Otherwise, far too often, troll targets are going to be staring at streams of sewage in their Twitter feeds as the company blithely sends form emails that clearly show that somebody’s asleep at the wheel.

As far as this new bug goes, Motherboard points to an account that Trump blocked late last month: the Party of Reason and Progress (PORP), a nonprofit dedicated to promoting reason and empirically sound decision-making in modern politics.

Blocked? No problem. PORP is still replying to the president’s tweets under the same old blocked account – @TheOfficialPORP – and, Motherboard reports, is receiving more engagement on those tweets than ever. Here’s one from September 1:

PORP told Motherboard’s Louise Matsakis that it’s simple: Twitter’s mobile app lets users toggle between multiple accounts, but it doesn’t account for whether a user has blocked one of those accounts. All you have to do to reply to someone’s tweets, in spite of them having blocked you, is to just pull up their tweet on another account.

The PORP spokesperson:

I literally just respond to [Trump] (reply) from any other account. Then when I’m writing the reply Twitter has a switch accounts function right at the top. Once I switch, the tweet is still there and I press send.

Thus, the blocked account of @TheOfficialPORP can still reply to Trump, just like anybody you or I might block can keep replying to our tweets, spreading their own take on our messages to all their followers – for better or worse.

PORP told me:

Hard to believe it works but it does

Motherboard’s Matsakis said she couldn’t confirm when the bug had started to occur but that she had to update her mobile Twitter app to the latest 7.6 version in order to experience and confirm it. She reached out to Twitter for comment and to ask when the bug will be patched, but it hadn’t replied to her by the time the story was posted on Friday.

What’s the point of a block button that can be evaded so easily? The point of blocking is to spare users from abusive accounts. But if blocked accounts are still out there, still replying to Tweets of those who blocked them, and their followers are still able to interact with the target account… well, it just seems that the block button isn’t doing anything to stop gasoline from being thrown on to the torches of trolls.

Let’s hope Twitter fixes this hole soon.

Leave a Reply

Your email address will not be published. Required fields are marked *