Live data from Hacker News

Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

cnn.com

61–70 of 645 posts

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#61
post #39

Earlier quoted context omitted.

> Second, does this guy have any actual tech knowledge at all? He doesn't list what operating system they are running or what security updates he is expecting. "This guy": https://en.wikipedia.org/wiki/Peiter_Zatko

Then he should be in an even better position to specify what the actual issues are in details and not some abstract garbage. You could summarize the information there as.. "Momma, servers bad. Need encryption. Need updates."

They are intentionally vague for legal and security reasons.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#62
post #40
post #12

I hate being asked to hand over my phone number for 2FA or similar protections. Or facing the choice between deleting all my DMs or risking them being compromised on account no E2E support. Then again, even if you delete something, there's no knowing what their data retention handling is.

I think it's safe to assume most anything you delete from a web app gets a deleted boolean or timestamp field set and the content persists in the database indefinitely. In my experience I've found it rare that user content is ever actually permanently deleted for various reasons.

> various reasons

advertising, controlling executives, and government spying

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#63
post #36

Eh, you could take out Twitter and insert many other company names and it'll still hold true. And those companies hold so much more sensitive data about you than Twitter. I know of insurance companies that have help desk employees with domain admin access. And all crippling ransomware attacks take advantage lax permissions. This is rampant. How is this a story?

Cybersecurity is one of my roles I suppose (small place with an operations team of approximately 2.5), and I have to say that I have no idea what proper security is supposed to mean today; it's very hard for me to tell the marketing from best practice now. It seems like what most products really are is an ass covering service so you can tell your leadership and your customers that you did the right things. Basically…

Corporate robots don't care.

They have gotten away with so much for so long, they live in their own disconnected reality.

When things break some of them cash out. Others find someone to blame. They don't pay a price at all. And the cycle continue.

In China atleast people are scared of the govt. In the west its a total joke how no one is ever held responsible.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#64
post #36

Eh, you could take out Twitter and insert many other company names and it'll still hold true. And those companies hold so much more sensitive data about you than Twitter. I know of insurance companies that have help desk employees with domain admin access. And all crippling ransomware attacks take advantage lax permissions. This is rampant. How is this a story?

> This is rampant. How is this a story?

Because it's being publicly revealed.

If the lax security you describe at other companies were also revealed, maybe more would be done to fix it.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#66
post #62
post #40

Earlier quoted context omitted.

I think it's safe to assume most anything you delete from a web app gets a deleted boolean or timestamp field set and the content persists in the database indefinitely. In my experience I've found it rare that user content is ever actually permanently deleted for various reasons.

> various reasons advertising, controlling executives, and government spying

Or devs who fear some runaway bug.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#67
post #42

Earlier quoted context omitted.

I think that Twitter is very much the tail that wags the dog. Sure, 1 out of 50 normal people may use it, but nearly 1 out of 1 reporters use it. Those reporters often quote opinions on it as if they are representative of the larger public, even if the tweet they quote is by someone with 10 followers and no stars.

The fun thing about social media is that reporters can back up any narrative they want. “People are upset about X”, “Gen Z is doing X”, “Millenails are killing X”. Find two people and it's a confirmed trend!

I saw a reddit post today that "Disney fans are furious that Avatar was temporarily pulled from Disney Store" and the top 500 comments were like "No one is furious".

Here, I'll give it a go: "Environmentalists are furious that Bill Gates kills mosquitos"

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#68
post #2

It is rather disconcerting how a platform that is apparently rather integral to the discourse of today is in the hands of a single private company. It doesn't matter who owns it, if it's Musk or someone else, the fact that it's at the whims of a private company, is the primary channel for discourse, and is something legislatures cannot even comprehend because of their age, should have alarm bells going off. Coupled w…

A world-wide, decentralized, communications platform sounds lovely. Oh wait...

Oh wait?

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#69
post #3

This excerpt is frightening: > About half of the company's 500,000 servers run on outdated software that does not support basic security features such as encryption for stored data or regular security updates by vendors

First, servers generally run on operating systems. No one with any serious knowledge would use the phrase run on software. Second, does this guy have any actual tech knowledge at all? He doesn't list what operating system they are running or what security updates he is expecting. It doesn't sound great but I assure you I've probably seen worse on systems used by the literal federal government to conduct official busi…

Operating systems are software.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#70

Earlier quoted context omitted.

> How is this a story? Cynically, because it's twitter, and it's trendy amongst a certain subset of the population to bash social media in general and twitter in particular. And I think your point is fair. (FWIW, I think social media has if not caused, then certainly exacerbated, some major problems at individual, societal, and global levels, but by no means do I think twitter is the biggest contributor. I don't thin…

My reasoned mind says it's due to the recent disclosure in Twitter due to linking of phone numbers to people, while my other mind says it's Elon finding anything to make Twitter give up their case.

For sure, the phone numbers issue definitely won't have helped, but the whole Elon/Twitter situation is definitely up there. Plus, as I say, it's been sort of trendy to bash them for a while: they're either not doing enough to protect people from harmful content, or they're subverting freedom of speech by, for example, banning Trump, and applying permanent, temporary, or shadowbans to other accounts. I'm not that sympathetic, but they sort of can't win.
Post reply on HN