Live data from Hacker News

On the Twitter Hack

schneier.com

71–80 of 93 posts

Re: On the Twitter Hack

#71

I really feel like everyone is getting one of the broad points in this discussion wrong. If Twitter is a national security risk because people can hack it to speak in the official voice of prominent leaders, or discover state secrets through direct messages, that is nobody's fault but the government's, for relying on a platform they have no control over for official business. Can you imagine the military complaining…

Obviously government employees shouldn't be using Twitter DMs for unofficial business, but they're more or less required to use Twitter for communications with the public and fundraising. If they don't, they hand way too much of an edge to their competitors. The issue is that we don't want Donald Trump to mysteriously tweet "We're nuking Toronto this afternoon! #MAGA" and have a national security episode trying to figure out if it's a hacker or if he just saw something on Fox News that irked him.

Re: On the Twitter Hack

#72
post #50
post #42

Earlier quoted context omitted.

I mean twitter has plenty of paying customers too? You don't just advertise on there for free.

But like, who’s storing their private budget spreadsheets or a database table with 1M credit card numbers on Twitter?

Why turn down all that free Twitter storage?

Re: On the Twitter Hack

#73

I really feel like everyone is getting one of the broad points in this discussion wrong. If Twitter is a national security risk because people can hack it to speak in the official voice of prominent leaders, or discover state secrets through direct messages, that is nobody's fault but the government's, for relying on a platform they have no control over for official business. Can you imagine the military complaining…

> If Twitter is a national security risk because people can hack it to speak in the official voice of prominent leaders, or discover state secrets through direct messages, that is nobody's fault but the government's, for relying on a platform they have no control over for official business.

I don't see the government relying on it. I see public officials using it as a platform. No coordination is being done (unless it's redundancy), just communication with constituents.

> It was a scandal when Hillary Clinton relied on a private email server.

One problem with using a private email server was because it circumvented FOIA requests. Twitter is open, a private email server is not. We still don't know what 33k of the subpoenaed emails were about that her personal IT guy deleted, other than the ones found on Huma Abedin's laptop.

The other problem of course is having a personal IT staff run your email server with classified secrets (yes there were classified emails). It's not quite the same as having Twitter or the DoD run your security. I mean, the guy (stonetear) was on Reddit asking how to delete emails, I doubt he knew how to protect against state actors.

Re: On the Twitter Hack

#74

I really feel like everyone is getting one of the broad points in this discussion wrong. If Twitter is a national security risk because people can hack it to speak in the official voice of prominent leaders, or discover state secrets through direct messages, that is nobody's fault but the government's, for relying on a platform they have no control over for official business. Can you imagine the military complaining…

> If Twitter is a national security risk because people can hack it to speak in the official voice of prominent leaders, or discover state secrets through direct messages, that is nobody's fault but the government's, for relying on a platform they have no control over for official business. I don't see the government relying on it. I see public officials using it as a platform. No coordination is being done (unless i…

> I don't see the government relying on it.

Ok, then a sizable portion of Schneier's article here is pointless. If it's not a national security risk, then this hack, while a big deal, is not as big a deal as he's saying.

Personally, I think it is much less of a risk than some people seem to be arguing, but much more of a risk than I'd like it to be. I do think someone could cause major real-world problems with national security ramifications by tweeting something from the President's account, and I don't think that should be possible.

Re: On the Twitter Hack

#75
post #71

I really feel like everyone is getting one of the broad points in this discussion wrong. If Twitter is a national security risk because people can hack it to speak in the official voice of prominent leaders, or discover state secrets through direct messages, that is nobody's fault but the government's, for relying on a platform they have no control over for official business. Can you imagine the military complaining…

Obviously government employees shouldn't be using Twitter DMs for unofficial business, but they're more or less required to use Twitter for communications with the public and fundraising. If they don't, they hand way too much of an edge to their competitors. The issue is that we don't want Donald Trump to mysteriously tweet "We're nuking Toronto this afternoon! #MAGA" and have a national security episode trying to fi…

They would not be "required" to use Twitter to keep up with their competitors, if they were all required not to use it for official communications. I'm not saying that politicians should choose to stop using Twitter for official communications, I'm saying Congress should pass a law requiring they not. I think there are already laws on the books around appropriate changes for official communications that could be augmented for this purpose.

Re: On the Twitter Hack

#76

I really feel like everyone is getting one of the broad points in this discussion wrong. If Twitter is a national security risk because people can hack it to speak in the official voice of prominent leaders, or discover state secrets through direct messages, that is nobody's fault but the government's, for relying on a platform they have no control over for official business. Can you imagine the military complaining…

> If Twitter is a national security risk because people can hack it to speak in the official voice of prominent leaders, or discover state secrets through direct messages, that is nobody's fault but the government's, for relying on a platform they have no control over for official business. I don't see the government relying on it. I see public officials using it as a platform. No coordination is being done (unless i…

> I don't see the government relying on it. I see public officials using it as a platform. No coordination is being done (unless it's redundancy), just communication with constituents.

The president regularly announces decisions on Twitter that he has not communicated through any other medium. Here's two major examples:

https://www.theverge.com/2018/3/13/17113950/trump-state-depa...

https://www.theatlantic.com/politics/archive/2019/01/donald-...

Re: On the Twitter Hack

#77

I really feel like everyone is getting one of the broad points in this discussion wrong. If Twitter is a national security risk because people can hack it to speak in the official voice of prominent leaders, or discover state secrets through direct messages, that is nobody's fault but the government's, for relying on a platform they have no control over for official business. Can you imagine the military complaining…

> If Twitter is a national security risk because people can hack it to speak in the official voice of prominent leaders, or discover state secrets through direct messages, that is nobody's fault but the government's, for relying on a platform they have no control over for official business. I don't see the government relying on it. I see public officials using it as a platform. No coordination is being done (unless i…

>Twitter is open, a private email server is not.

In what way is Twitter "open"? Can I FOIA a government official's DM's? I don't see that as likely.

From my standpoint, Clinton's private server is equivalent to Twitter (albeit likely less well-maintained from a security perspective).

To my mind, it's wholly unacceptable for the US government to maintain secret communication platforms outside the reach of FOIA. Working to keep communications off-the-record and out of the public's hands is a betrayal of the public trust.

Re: On the Twitter Hack

#78

I really feel like everyone is getting one of the broad points in this discussion wrong. If Twitter is a national security risk because people can hack it to speak in the official voice of prominent leaders, or discover state secrets through direct messages, that is nobody's fault but the government's, for relying on a platform they have no control over for official business. Can you imagine the military complaining…

But your military example literally happened with edmondo where people jogging around secret military bases were found because that system was breached

Re: On the Twitter Hack

#79
Breaking up monopolies like Twitter may not work. They must be subjected to heavy regulation. They must not censor/block/shadowban any account or tweet. They must open their entire operation to APIs at reasonable costs. They must allow interoperability with any other Twitter clone, tweets from everywhere should be visible across all Twitters.

Follow all this, or pay $1M/day compounding fine.

Re: On the Twitter Hack

#80

Earlier quoted context omitted.

No, that is not the definition of a monopoly. A monopoly is a entity that holds exclusivity to a good or a service.

Interesting. So according to this definition, Google doesn't have a monopoly in the market of Search engines since there is also Bing[1]. What is the word for it then? Highly-dominant player? Edit: looks like I'm not alone to have this definition for a monopoly[2]. [1] https://gs.statcounter.com/search-engine-market-share [2] https://news.ycombinator.com/item?id=23900128

Google could be described as being a member of a search engine oligopoly.
Post reply on HN