Earlier quoted context omitted.
They are intentionally vague for legal and security reasons.
What legal and security reasons exactly?
Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies
81–90 of 645 posts
Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies
#82Is this an accurate statement?
If so, why did nearly 1000 employees (12% of the workforce) have access to this mode before it was restricted, and what's the business case for that?
Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies
#83Earlier quoted context omitted.
Consult with a security firm or specialist and they should be able to steer you in the right direction.
Two problems with this: 1) Like a car mechanic, these people get paid to sell you solutions and they are incentivized to sell you more. 2) Plenty or honest people have biases because of what they do. If you spend all day thinking about security you might be overly concerned about things that are actually not that risky. This isn’t to say that there aren’t great people working in the field. But it’s daunting from an o…
You don't want your doctor to overlook any problems just because they are rare because your health is really valuable.
Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies
#84Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies
#85God Mode, from my understanding, allows a Twitter employee to have access to an account and allows for a post to be made, under that account's id, without the account being notified or seeing the post show up in their own timeline. Is this an accurate statement? If so, why did nearly 1000 employees (12% of the workforce) have access to this mode before it was restricted, and what's the business case for that?
Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies
#86OK, so their security is a mess, as many commenters have pointed out, they are one of many companies. What I can't figure out is what's this guy's beef that he went revealing all this? Was he fired or demoted or something and thought to get his own back?
Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies
#87I hate being asked to hand over my phone number for 2FA or similar protections. Or facing the choice between deleting all my DMs or risking them being compromised on account no E2E support. Then again, even if you delete something, there's no knowing what their data retention handling is.
I think it's safe to assume most anything you delete from a web app gets a deleted boolean or timestamp field set and the content persists in the database indefinitely. In my experience I've found it rare that user content is ever actually permanently deleted for various reasons.
Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies
#88Eh, you could take out Twitter and insert many other company names and it'll still hold true. And those companies hold so much more sensitive data about you than Twitter. I know of insurance companies that have help desk employees with domain admin access. And all crippling ransomware attacks take advantage lax permissions. This is rampant. How is this a story?
Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies
#89Has Twitter ever been in the news for properly making even a thousand people successful from scratch really ever in the product's life?
They have pipelines of exploitation for everyone that gets "discovered" into contractual nightmare deals, they require tons of free labor and costly hurdles just to become notable and visible on the platform, they extort people promoting their independent work for ad money, they don't protect anyone's privacy, they are VERY MANIPULATIVE in multiple (psychological) ways, they offer very little support or fairness when accounts are compromised, hijacked, or stolen, and they impose a stranglehold on information through lobbies and suppression of independent art and music.
Social media took over the Internet after they wooed everyone into the ideal that they would operate fairly. Now that they have captured full attention, they have turned on users and they offer very little to anyone who doesn't pay, and can't offer reliable security to anyone. There are some serious "God Complexes" going on with having access to the personal data these systems harvest ON EVERYONE in conjunction with mobile devices.
I really hate to say it would actually probably make me feel better if most of the large data monitoring sites/apps went away rather than stayed in place, because they make almost every aspect of the Internet work against us all.
Twitter has had several opportunities to fix how it operates. The platform also generates tons in annual revenue to fix how it operates. Twitter has lots of employees that could fix how it operates. Twitter has also had numerous security breaches, and it regularly causes tons of stress for users. Twitter continues to focus on only pleasing it's sponsors, investors, and execs year after year and repeatedly stretching the promises it was built upon.
I can't say I want to see this whale fail, but I won't miss it if it does.
Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies
#90God Mode, from my understanding, allows a Twitter employee to have access to an account and allows for a post to be made, under that account's id, without the account being notified or seeing the post show up in their own timeline. Is this an accurate statement? If so, why did nearly 1000 employees (12% of the workforce) have access to this mode before it was restricted, and what's the business case for that?
Thing is, now that it’s possible for Twitter, Twitter can never brush off this suspicions again.
We’re literally not sure, by using Twitter, that we see the speech of that person.