Live data from Hacker News

Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

cnn.com

51–60 of 645 posts

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#51
post #36

Eh, you could take out Twitter and insert many other company names and it'll still hold true. And those companies hold so much more sensitive data about you than Twitter. I know of insurance companies that have help desk employees with domain admin access. And all crippling ransomware attacks take advantage lax permissions. This is rampant. How is this a story?

Cybersecurity is one of my roles I suppose (small place with an operations team of approximately 2.5), and I have to say that I have no idea what proper security is supposed to mean today; it's very hard for me to tell the marketing from best practice now. It seems like what most products really are is an ass covering service so you can tell your leadership and your customers that you did the right things.

Basically we work on keeping everything patched and try not to create any obvious issues. Honestly, I think the best thing we have going for us is obscurity.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#52
post #48

From Wikipedia: “He was the most prominent member of the high-profile hacker think tank the L0pht.” That’s quite a generous take. There were plenty of excellent hackers in the 90s, but “L0pht” just seemed like the PR friendly one that could go on good morning America. Can’t tell if this is real or just a 90s security person trying to stay relevant after being fired.

[deleted]

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#53
post #36

Eh, you could take out Twitter and insert many other company names and it'll still hold true. And those companies hold so much more sensitive data about you than Twitter. I know of insurance companies that have help desk employees with domain admin access. And all crippling ransomware attacks take advantage lax permissions. This is rampant. How is this a story?

> How is this a story? Cynically, because it's twitter, and it's trendy amongst a certain subset of the population to bash social media in general and twitter in particular. And I think your point is fair. (FWIW, I think social media has if not caused, then certainly exacerbated, some major problems at individual, societal, and global levels, but by no means do I think twitter is the biggest contributor. I don't thin…

My reasoned mind says it's due to the recent disclosure in Twitter due to linking of phone numbers to people, while my other mind says it's Elon finding anything to make Twitter give up their case.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#54
post #48

From Wikipedia: “He was the most prominent member of the high-profile hacker think tank the L0pht.” That’s quite a generous take. There were plenty of excellent hackers in the 90s, but “L0pht” just seemed like the PR friendly one that could go on good morning America. Can’t tell if this is real or just a 90s security person trying to stay relevant after being fired.

Whether or not it was high profile before they went on talk shows and before congress... it's definitely a high profile (historic) group now because they went on talk shows and before congress. :)

High profile doesn't mean best it just means high profile.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#55
post #43

Earlier quoted context omitted.

I think that Twitter is very much the tail that wags the dog. Sure, 1 out of 50 normal people may use it, but nearly 1 out of 1 reporters use it. Those reporters often quote opinions on it as if they are representative of the larger public, even if the tweet they quote is by someone with 10 followers and no stars.

It annoys me to see this. Quoting tweets is the laziest form of journalism. But to be fair to journalists, finding a couple of real world people and quoting their opinions as if they are representative of the larger public isn’t any more rigorous. And it’s possible to cherry-pick people to push any narrative you want. Like the NYT talking about how GenZ is very pro-life, quoting several pro-life youngsters. Meanwhile…

Ironically, social media has played a big role in the rise of cheap clickbait journalism.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#58
post #36

Eh, you could take out Twitter and insert many other company names and it'll still hold true. And those companies hold so much more sensitive data about you than Twitter. I know of insurance companies that have help desk employees with domain admin access. And all crippling ransomware attacks take advantage lax permissions. This is rampant. How is this a story?

Did you actually read it? The story isn't some handwaving about companies in general having bad security. It's that Twitter's former head of security is blowing the whistle on "reckless and negligent cybersecurity policies" including deliberately misleading government regulators and its own board about various issues, and concerns about foreign espionage and disinformation.

If you don't know how that's a story I don't know how to explain it to you, I can only assure you many people will find it extremely newsworthy.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#59
post #36

Eh, you could take out Twitter and insert many other company names and it'll still hold true. And those companies hold so much more sensitive data about you than Twitter. I know of insurance companies that have help desk employees with domain admin access. And all crippling ransomware attacks take advantage lax permissions. This is rampant. How is this a story?

Cybersecurity is one of my roles I suppose (small place with an operations team of approximately 2.5), and I have to say that I have no idea what proper security is supposed to mean today; it's very hard for me to tell the marketing from best practice now. It seems like what most products really are is an ass covering service so you can tell your leadership and your customers that you did the right things. Basically…

Consult with a security firm or specialist and they should be able to steer you in the right direction.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#60
post #3

This excerpt is frightening: > About half of the company's 500,000 servers run on outdated software that does not support basic security features such as encryption for stored data or regular security updates by vendors

First, servers generally run on operating systems. No one with any serious knowledge would use the phrase run on software. Second, does this guy have any actual tech knowledge at all? He doesn't list what operating system they are running or what security updates he is expecting. It doesn't sound great but I assure you I've probably seen worse on systems used by the literal federal government to conduct official busi…

My first thought was the hypervisor layer.
Post reply on HN