Live data from Hacker News

Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

cnn.com

41–50 of 645 posts

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#41
OK, so their security is a mess, as many commenters have pointed out, they are one of many companies.

What I can't figure out is what's this guy's beef that he went revealing all this? Was he fired or demoted or something and thought to get his own back?

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#42

Earlier quoted context omitted.

> the primary channel for discourse Primary for whom? If you polled 50 people on the streets of NYC, I bet fewer than 3 would say they actively use twitter. Now do the same for Des Moines, IA and you maybe get 1?

I think that Twitter is very much the tail that wags the dog. Sure, 1 out of 50 normal people may use it, but nearly 1 out of 1 reporters use it. Those reporters often quote opinions on it as if they are representative of the larger public, even if the tweet they quote is by someone with 10 followers and no stars.

The fun thing about social media is that reporters can back up any narrative they want. “People are upset about X”, “Gen Z is doing X”, “Millenails are killing X”. Find two people and it's a confirmed trend!

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#43

Earlier quoted context omitted.

> the primary channel for discourse Primary for whom? If you polled 50 people on the streets of NYC, I bet fewer than 3 would say they actively use twitter. Now do the same for Des Moines, IA and you maybe get 1?

I think that Twitter is very much the tail that wags the dog. Sure, 1 out of 50 normal people may use it, but nearly 1 out of 1 reporters use it. Those reporters often quote opinions on it as if they are representative of the larger public, even if the tweet they quote is by someone with 10 followers and no stars.

It annoys me to see this. Quoting tweets is the laziest form of journalism. But to be fair to journalists, finding a couple of real world people and quoting their opinions as if they are representative of the larger public isn’t any more rigorous.

And it’s possible to cherry-pick people to push any narrative you want. Like the NYT talking about how GenZ is very pro-life, quoting several pro-life youngsters. Meanwhile buried somewhere in that long article is the lede - only 20% of GenZ is pro-life.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#44

Earlier quoted context omitted.

> the primary channel for discourse Primary for whom? If you polled 50 people on the streets of NYC, I bet fewer than 3 would say they actively use twitter. Now do the same for Des Moines, IA and you maybe get 1?

People with outsized influence over politics, for example.

No post body was provided.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#45

OK, so their security is a mess, as many commenters have pointed out, they are one of many companies. What I can't figure out is what's this guy's beef that he went revealing all this? Was he fired or demoted or something and thought to get his own back?

Look at Mudge's track record. He didn't become a security legend by staying quiet about problems, and if Twitter wasn't willing to address it internally...

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#46
post #36

Eh, you could take out Twitter and insert many other company names and it'll still hold true. And those companies hold so much more sensitive data about you than Twitter. I know of insurance companies that have help desk employees with domain admin access. And all crippling ransomware attacks take advantage lax permissions. This is rampant. How is this a story?

> How is this a story?

Cynically, because it's twitter, and it's trendy amongst a certain subset of the population to bash social media in general and twitter in particular. And I think your point is fair.

(FWIW, I think social media has if not caused, then certainly exacerbated, some major problems at individual, societal, and global levels, but by no means do I think twitter is the biggest contributor. I don't think we'd see the kind of unconstructive political polarisation we're seeing in the US and UK and perhaps, to a lesser extent, within the EU, without it.)

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#47
post #39

Earlier quoted context omitted.

First, servers generally run on operating systems. No one with any serious knowledge would use the phrase run on software. Second, does this guy have any actual tech knowledge at all? He doesn't list what operating system they are running or what security updates he is expecting. It doesn't sound great but I assure you I've probably seen worse on systems used by the literal federal government to conduct official busi…

> Second, does this guy have any actual tech knowledge at all? He doesn't list what operating system they are running or what security updates he is expecting. "This guy": https://en.wikipedia.org/wiki/Peiter_Zatko

Then he should be in an even better position to specify what the actual issues are in details and not some abstract garbage. You could summarize the information there as.. "Momma, servers bad. Need encryption. Need updates."

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#48
From Wikipedia: “He was the most prominent member of the high-profile hacker think tank the L0pht.”

That’s quite a generous take. There were plenty of excellent hackers in the 90s, but “L0pht” just seemed like the PR friendly one that could go on good morning America.

Can’t tell if this is real or just a 90s security person trying to stay relevant after being fired.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#49
post #45

OK, so their security is a mess, as many commenters have pointed out, they are one of many companies. What I can't figure out is what's this guy's beef that he went revealing all this? Was he fired or demoted or something and thought to get his own back?

Look at Mudge's track record. He didn't become a security legend by staying quiet about problems, and if Twitter wasn't willing to address it internally...

"Zatko says, he believes he is doing the job he was hired to do for a platform he says is critical to democracy. "Jack Dorsey reached out and asked me to come and perform a critical task at Twitter. I signed on to do it and believe I'm still performing that mission," he said."

Seems like a legit answer.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#50
post #45

OK, so their security is a mess, as many commenters have pointed out, they are one of many companies. What I can't figure out is what's this guy's beef that he went revealing all this? Was he fired or demoted or something and thought to get his own back?

Look at Mudge's track record. He didn't become a security legend by staying quiet about problems, and if Twitter wasn't willing to address it internally...

Everyone should watch L0phts congressional testimony.
Post reply on HN