Live data from Hacker News

Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

cnn.com

71–80 of 645 posts

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#71
post #36

Eh, you could take out Twitter and insert many other company names and it'll still hold true. And those companies hold so much more sensitive data about you than Twitter. I know of insurance companies that have help desk employees with domain admin access. And all crippling ransomware attacks take advantage lax permissions. This is rampant. How is this a story?

[deleted]

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#73
post #59

Earlier quoted context omitted.

Cybersecurity is one of my roles I suppose (small place with an operations team of approximately 2.5), and I have to say that I have no idea what proper security is supposed to mean today; it's very hard for me to tell the marketing from best practice now. It seems like what most products really are is an ass covering service so you can tell your leadership and your customers that you did the right things. Basically…

Consult with a security firm or specialist and they should be able to steer you in the right direction.

Two problems with this:

1) Like a car mechanic, these people get paid to sell you solutions and they are incentivized to sell you more.

2) Plenty or honest people have biases because of what they do. If you spend all day thinking about security you might be overly concerned about things that are actually not that risky.

This isn’t to say that there aren’t great people working in the field. But it’s daunting from an outsiders perspective.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#74

Earlier quoted context omitted.

Then he should be in an even better position to specify what the actual issues are in details and not some abstract garbage. You could summarize the information there as.. "Momma, servers bad. Need encryption. Need updates."

They are intentionally vague for legal and security reasons.

What legal and security reasons exactly?

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#75
"The whistleblower also says Twitter executives don't have the resources to fully understand the true number of bots on the platform, and were not motivated to."

I imagine this hurts Twitter's defense against Musk from pulling out of the takeover deal, or, is this whistleblower's account inadmissible?

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#76
post #3

This excerpt is frightening: > About half of the company's 500,000 servers run on outdated software that does not support basic security features such as encryption for stored data or regular security updates by vendors

Just do it the Zuck way: "If you make an FB app, you can read all user's data and their friends' data, but click here to promise that you won't do that and you won't use the data to subvert democracies...".

To be fair this hasn't been the case for many years.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#77
post #75

"The whistleblower also says Twitter executives don't have the resources to fully understand the true number of bots on the platform, and were not motivated to." I imagine this hurts Twitter's defense against Musk from pulling out of the takeover deal, or, is this whistleblower's account inadmissible?

Why would it be inadmissible?

Mudge could be subpeonaed, just like Jack was just subpeonaed.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#78
post #36

Eh, you could take out Twitter and insert many other company names and it'll still hold true. And those companies hold so much more sensitive data about you than Twitter. I know of insurance companies that have help desk employees with domain admin access. And all crippling ransomware attacks take advantage lax permissions. This is rampant. How is this a story?

Because people with a lot of money are inflating this story to get back at Twitter. It sounds like a conspiracy, but that's the most plausible explanation I have for why this specific whistleblower gets amplified by the media.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#79
For a solid and genuine technical person considering a CISO or CISO-like role, I've had the impression that they have to be very selective where they go.

Even in what I'd guess is an "ideal" situation, of tractable technical&process problems, and genuine buy-in from the C-suite for solving/improving them, there's still going to be dynamics/politics to navigate.

I also hear of a lot of much-less-than-ideal situations.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#80
post #75

"The whistleblower also says Twitter executives don't have the resources to fully understand the true number of bots on the platform, and were not motivated to." I imagine this hurts Twitter's defense against Musk from pulling out of the takeover deal, or, is this whistleblower's account inadmissible?

I am willing to take a shot in the dark on this story, and say that this is the whole point. I don't see why this story would get shared and amplified so much otherwise.
Post reply on HN