Live data from Hacker News

Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

cnn.com

91–100 of 645 posts

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#91
post #3

This excerpt is frightening: > About half of the company's 500,000 servers run on outdated software that does not support basic security features such as encryption for stored data or regular security updates by vendors

I think it's also important to recognize how much of a "check the box" security control encryption at rest has become for many vendors/GRC teams. A lot of times, the encryption at rest control only has the capability to prevent somebody from physically detaching the disk and trying to mount it with their own machine and access the data that way. In a world where many companies now run their workloads on public cloud providers who keep their hardware in distributed cages in secure datacenters, this isn't the security control many assume it is.

If you're trying to prevent an actor who has gained a foothold on a box/network from seeing plaintext data that is actually in use by the actual production system at that very moment, you're looking for a much stronger type of control - probably some sort of client-side encryption or obfuscation/tokenization

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#92
post #2

It is rather disconcerting how a platform that is apparently rather integral to the discourse of today is in the hands of a single private company. It doesn't matter who owns it, if it's Musk or someone else, the fact that it's at the whims of a private company, is the primary channel for discourse, and is something legislatures cannot even comprehend because of their age, should have alarm bells going off. Coupled w…

> It is rather disconcerting how a platform that is apparently rather integral to the discourse of today is in the hands of a single private company.

Unpopular opinion: I think it's awesome that a private company has created a platform like Twitter. It's kind of like comparing a private amusement park with a public park: one has roller coasters, water slides and an arcade... the other has a swingset and a nice field of dried up grass.

> the fact that it's at the whims of a private company

How is this worse than at the whims of the crown?

> there is an environment that is ripe for the encroachment of digital rights

I love that were even talking about having digital rights.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#93

Earlier quoted context omitted.

> the primary channel for discourse Primary for whom? If you polled 50 people on the streets of NYC, I bet fewer than 3 would say they actively use twitter. Now do the same for Des Moines, IA and you maybe get 1?

I think that Twitter is very much the tail that wags the dog. Sure, 1 out of 50 normal people may use it, but nearly 1 out of 1 reporters use it. Those reporters often quote opinions on it as if they are representative of the larger public, even if the tweet they quote is by someone with 10 followers and no stars.

> I think that Twitter is very much the tail that wags the dog.

Twitter has a lot of journalist users so, yes, it does tend to move the whole dog.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#94
Not wanting to defend Twitter, but I'm pretty sure the situation is very similar across a whole lot of companies, even those that make security their main business, i.e. FireEye.

Because investing in IT security usually has no apparent profit incentives, so most companies leadership will consider it something of very little importance funding wise.

Particularly in the current climate where even minor hacks, and simple ransomware infections, are regularly made out as some kind of "act of God"/allegedly done by some super advanced "state actor", to create the narrative how it just wasn't preventable with the resources of a private company.

Which outsources all the responsibility to ominous intangible parties based on wonky, and often politically motivated, attribution, while holding nobody responsible for running outdate software in exploitable combinations, thus creating the problem in the very first place.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#95
By the CNN piece it seems like twitter hired a community figure - which is a common mistake that leads to bad performance evaluation. Public figures are trained on being public figures, they not necessarily are the best folks to build a security organization. OTOH there seems to be some frustration from both sides regarding performance and if it gets public our hackerman will have a rough time being exposed. I don't think that was a good idea (reporting to SEC would work better IMO).

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#96

God Mode, from my understanding, allows a Twitter employee to have access to an account and allows for a post to be made, under that account's id, without the account being notified or seeing the post show up in their own timeline. Is this an accurate statement? If so, why did nearly 1000 employees (12% of the workforce) have access to this mode before it was restricted, and what's the business case for that?

Now think about the implications with respect to Twitter DMs that show up in criminal investigations.

For instance, consider the Twitter DMs exchanged by Donald Trump, Jr and WikiLeaks. In that particular case, the communication was acknowledged by the party in question, but imagine the two possibilities thousands of employees being able to act on the part of users opens up:

1. Twitter employees could fabricate a criminal conspiracy by creating messages between multiple Twitter accounts.

2. A criminal conspiracy can now use the "Wasn't me, must have been some random Twitter employees" defense.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#97
post #78
post #36

Eh, you could take out Twitter and insert many other company names and it'll still hold true. And those companies hold so much more sensitive data about you than Twitter. I know of insurance companies that have help desk employees with domain admin access. And all crippling ransomware attacks take advantage lax permissions. This is rampant. How is this a story?

Because people with a lot of money are inflating this story to get back at Twitter. It sounds like a conspiracy, but that's the most plausible explanation I have for why this specific whistleblower gets amplified by the media.

Not a lot of companies get infiltrated by foreign agents or assets. Access to Twitter, in particular, can help unmasking anonymous sources, sensitive DMs, dissidents - and their locations.

And, oh yeah - there is no "conspiracy".

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#98
post #73
post #59

Earlier quoted context omitted.

Consult with a security firm or specialist and they should be able to steer you in the right direction.

Two problems with this: 1) Like a car mechanic, these people get paid to sell you solutions and they are incentivized to sell you more. 2) Plenty or honest people have biases because of what they do. If you spend all day thinking about security you might be overly concerned about things that are actually not that risky. This isn’t to say that there aren’t great people working in the field. But it’s daunting from an o…

Develop sufficient in-house subject matter expertise so that you're not depending on sales consultants to do your cyber program for you.

Develop an empirical understanding of risk management. While we can't predict the future, through well established techniques and adequate resourcing, professionals can achieve consistent results that are far better than random guessing. Risk management principles drive not just corporate stragegy writ large, but entire industries like banking and insurance.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#100
post #95

By the CNN piece it seems like twitter hired a community figure - which is a common mistake that leads to bad performance evaluation. Public figures are trained on being public figures, they not necessarily are the best folks to build a security organization. OTOH there seems to be some frustration from both sides regarding performance and if it gets public our hackerman will have a rough time being exposed. I don't…

Nobody seems to know how you can build a successful security org
Post reply on HN