Earlier quoted context omitted.
I wonder if they're running Ubuntu on 32-bit hardware
or RHEL 6
Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies
31–40 of 645 posts
Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies
#32This excerpt is frightening: > About half of the company's 500,000 servers run on outdated software that does not support basic security features such as encryption for stored data or regular security updates by vendors
Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies
#33This excerpt is frightening: > About half of the company's 500,000 servers run on outdated software that does not support basic security features such as encryption for stored data or regular security updates by vendors
That 500k servers in Twitter infra are missing patches certainly is true and what was likely in the original was a statement that stored data that should have been encrypted at rest was not, and/or that acceptable standards for data at rest encryption, a relatively rapidly moving freight train, were not maintained.
Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies
#34This excerpt is frightening: > About half of the company's 500,000 servers run on outdated software that does not support basic security features such as encryption for stored data or regular security updates by vendors
It is also frightening that they need half a million servers.
Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies
#35This excerpt is frightening: > About half of the company's 500,000 servers run on outdated software that does not support basic security features such as encryption for stored data or regular security updates by vendors
Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies
#36I know of insurance companies that have help desk employees with domain admin access. And all crippling ransomware attacks take advantage lax permissions.
This is rampant. How is this a story?
Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies
#37Eh, you could take out Twitter and insert many other company names and it'll still hold true. And those companies hold so much more sensitive data about you than Twitter. I know of insurance companies that have help desk employees with domain admin access. And all crippling ransomware attacks take advantage lax permissions. This is rampant. How is this a story?
Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies
#38This excerpt is frightening: > About half of the company's 500,000 servers run on outdated software that does not support basic security features such as encryption for stored data or regular security updates by vendors
Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies
#39This excerpt is frightening: > About half of the company's 500,000 servers run on outdated software that does not support basic security features such as encryption for stored data or regular security updates by vendors
First, servers generally run on operating systems. No one with any serious knowledge would use the phrase run on software. Second, does this guy have any actual tech knowledge at all? He doesn't list what operating system they are running or what security updates he is expecting. It doesn't sound great but I assure you I've probably seen worse on systems used by the literal federal government to conduct official busi…
"This guy": https://en.wikipedia.org/wiki/Peiter_Zatko
Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies
#40I hate being asked to hand over my phone number for 2FA or similar protections. Or facing the choice between deleting all my DMs or risking them being compromised on account no E2E support. Then again, even if you delete something, there's no knowing what their data retention handling is.
In my experience I've found it rare that user content is ever actually permanently deleted for various reasons.