Twitch bug may have exposed some users messages to others
20.8.18 securityaffairs
Vulnerebility

A glitch in the live streaming platform Twitch may have exposed some of its users’ private messages to other users. The company is notifying affected users.
The live streaming platform Twitch warning users that a glitch may have exposed some of their private messages to other users.

The company sent out the notifications to some broadcasters informing them that a software bug could have changed access permissions to older messages allowing other users to download them and read them.

The flaw affected recently removed a feature dubbed Messages that have exposed some the messages.

“I reached out to Twitch for a comment, and a company spokesperson says that it has fixed the bug. It also explained that most of the exposed messages were promotional announcements that went out to everyone who subscribes to certain channels. But it’s possible that this also affected private communications featuring more sensitive information as well.” reported VentureBeat.

Twitch email
Copy of the email sent by Twitch obtained by Bleeping Computer

“In May, we removed a legacy feature called Messages and provided users the ability to download an archive of past messages. Due to a bug in the code that generated the message archive files, which has since been fixed, a small percentage of user messages were included in the wrong archives.” reads the statement from Twitch’s spokesperson.

“The primary use case for Messages was promotion; streamers sending out mass communication to subscribers for example, and the majority of messages that were unintentionally provided to another user fall into that category. We have notified users via email and provided them the affected messages for review. Protecting our users’ privacy is important to us and we have taken actions to ensure this kind of error does not happen in the future.”

According to Twitch, the bug only affected the Messages feature, and there were no private messages sent via the Twitch Whisper systems included in these archives.

Twitch users can discover if their messages were accidentally exposed by visiting the website twitch.tv/messages/archive.

Searching on Twitter it is possible to find messages of Twitter users that found messages in their archive belonging to other users.

Elspeth Eastman
@elspetheastman
So uh hey did anyone else get that unsettling email about people possibly downloading your archived Twitch Messages by mistake because I sure did.

“A small percentage of messages were included in the wrong archives”

8:42 PM - Aug 16, 18
60
16 people are talking about this
Twitter Ads info and privacy

kaitlyn, solid
@kaitly_n
at first when i saw my twitch messages were mistakenly sent to other users i was p concerned

so i checked and saw it was just this one.

if anything i should thank @twitch. in fact, everyone can have this message. i'm happy to serve as an example of banning that shit in 2014. 😎

9:22 PM - Aug 16, 18
38
See kaitlyn, solid's other Tweets
Twitter Ads info and privacy
Anyway, Twitch sent a warning message to all affected users.