Live data from Hacker News

Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

cnn.com

31–40 of 645 posts

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#31

Earlier quoted context omitted.

I wonder if they're running Ubuntu on 32-bit hardware

or RHEL 6

I wish this was a joke. I know of systems running multibillion dollar companies that are still using rhel6.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#32
post #3

This excerpt is frightening: > About half of the company's 500,000 servers run on outdated software that does not support basic security features such as encryption for stored data or regular security updates by vendors

First, servers generally run on operating systems. No one with any serious knowledge would use the phrase run on software. Second, does this guy have any actual tech knowledge at all? He doesn't list what operating system they are running or what security updates he is expecting. It doesn't sound great but I assure you I've probably seen worse on systems used by the literal federal government to conduct official business and store sensitive information on. All government cares about is having remediation plans in place.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#33
post #3

This excerpt is frightening: > About half of the company's 500,000 servers run on outdated software that does not support basic security features such as encryption for stored data or regular security updates by vendors

The "does not support basic security features such as encryption for stored data" unquoted line of reporting is almost certainly not what Mudge wrote and is likely not literally true.

That 500k servers in Twitter infra are missing patches certainly is true and what was likely in the original was a statement that stored data that should have been encrypted at rest was not, and/or that acceptable standards for data at rest encryption, a relatively rapidly moving freight train, were not maintained.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#34
post #3

This excerpt is frightening: > About half of the company's 500,000 servers run on outdated software that does not support basic security features such as encryption for stored data or regular security updates by vendors

It is also frightening that they need half a million servers.

The JVM is a hungry beast.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#35
post #3

This excerpt is frightening: > About half of the company's 500,000 servers run on outdated software that does not support basic security features such as encryption for stored data or regular security updates by vendors

Wasn't it them that had a bug that exposed users' passwords in plain text a few years back?

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#36
Eh, you could take out Twitter and insert many other company names and it'll still hold true. And those companies hold so much more sensitive data about you than Twitter.

I know of insurance companies that have help desk employees with domain admin access. And all crippling ransomware attacks take advantage lax permissions.

This is rampant. How is this a story?

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#37
post #36

Eh, you could take out Twitter and insert many other company names and it'll still hold true. And those companies hold so much more sensitive data about you than Twitter. I know of insurance companies that have help desk employees with domain admin access. And all crippling ransomware attacks take advantage lax permissions. This is rampant. How is this a story?

At least you get it. I've seen worse on actual government systems.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#38
post #3

This excerpt is frightening: > About half of the company's 500,000 servers run on outdated software that does not support basic security features such as encryption for stored data or regular security updates by vendors

Just do it the Zuck way: "If you make an FB app, you can read all user's data and their friends' data, but click here to promise that you won't do that and you won't use the data to subvert democracies...".

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#39
post #3

This excerpt is frightening: > About half of the company's 500,000 servers run on outdated software that does not support basic security features such as encryption for stored data or regular security updates by vendors

First, servers generally run on operating systems. No one with any serious knowledge would use the phrase run on software. Second, does this guy have any actual tech knowledge at all? He doesn't list what operating system they are running or what security updates he is expecting. It doesn't sound great but I assure you I've probably seen worse on systems used by the literal federal government to conduct official busi…

> Second, does this guy have any actual tech knowledge at all? He doesn't list what operating system they are running or what security updates he is expecting.

"This guy": https://en.wikipedia.org/wiki/Peiter_Zatko

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#40
post #12

I hate being asked to hand over my phone number for 2FA or similar protections. Or facing the choice between deleting all my DMs or risking them being compromised on account no E2E support. Then again, even if you delete something, there's no knowing what their data retention handling is.

I think it's safe to assume most anything you delete from a web app gets a deleted boolean or timestamp field set and the content persists in the database indefinitely.

In my experience I've found it rare that user content is ever actually permanently deleted for various reasons.

Post reply on HN