Live data from Hacker News

Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

cnn.com

101–110 of 645 posts

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#101
post #67
post #42

Earlier quoted context omitted.

The fun thing about social media is that reporters can back up any narrative they want. “People are upset about X”, “Gen Z is doing X”, “Millenails are killing X”. Find two people and it's a confirmed trend!

I saw a reddit post today that "Disney fans are furious that Avatar was temporarily pulled from Disney Store" and the top 500 comments were like "No one is furious". Here, I'll give it a go: "Environmentalists are furious that Bill Gates kills mosquitos"

I did a quick Twitter search, and unfortunately your story isn't supported by any tweets I can find. Good news: you get to write a story about conspiracy theories about Gates and mosquitoes instead though! https://twitter.com/lorijean333/status/1561224522166067201?s...

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#102
post #36

Eh, you could take out Twitter and insert many other company names and it'll still hold true. And those companies hold so much more sensitive data about you than Twitter. I know of insurance companies that have help desk employees with domain admin access. And all crippling ransomware attacks take advantage lax permissions. This is rampant. How is this a story?

Cybersecurity is one of my roles I suppose (small place with an operations team of approximately 2.5), and I have to say that I have no idea what proper security is supposed to mean today; it's very hard for me to tell the marketing from best practice now. It seems like what most products really are is an ass covering service so you can tell your leadership and your customers that you did the right things. Basically…

I've recently gotten a lot of good guidance on security best practice from a new boss. A great place to start is the CIS 18 critical security controls. They cover most things for protecting an organization.

Walk through the controls list, see where you compare to the controls and sub-controls and then start to establish a path forward.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#103
post #73

Earlier quoted context omitted.

Two problems with this: 1) Like a car mechanic, these people get paid to sell you solutions and they are incentivized to sell you more. 2) Plenty or honest people have biases because of what they do. If you spend all day thinking about security you might be overly concerned about things that are actually not that risky. This isn’t to say that there aren’t great people working in the field. But it’s daunting from an o…

It's still comes down to a matter of urgency or value perception. You don't want your doctor to overlook any problems just because they are rare because your health is really valuable.

With the example of the doctor you run into the nocebo effect - you can spend a lot of time tracking down things that turn out to be of very low value which ends up causing more harm than good. To painfully extend the metaphor you could have an overly aggressive password policy and end up having users reusing passwords or writing them down.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#104
post #36

Eh, you could take out Twitter and insert many other company names and it'll still hold true. And those companies hold so much more sensitive data about you than Twitter. I know of insurance companies that have help desk employees with domain admin access. And all crippling ransomware attacks take advantage lax permissions. This is rampant. How is this a story?

Cybersecurity is one of my roles I suppose (small place with an operations team of approximately 2.5), and I have to say that I have no idea what proper security is supposed to mean today; it's very hard for me to tell the marketing from best practice now. It seems like what most products really are is an ass covering service so you can tell your leadership and your customers that you did the right things. Basically…

I’m a security engineer and nobody knows what’s best practice. Everyone is making it up at this point, and security is still a nascent field. Most companies don’t even have a security team.

I think it’s still not clear how you should build a security org, and if you should at all (should security be part of normal workstreams of your devs?)

Btw I wrote about my experience in https://securityhandbook.io/

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#105
post #42

Earlier quoted context omitted.

I think that Twitter is very much the tail that wags the dog. Sure, 1 out of 50 normal people may use it, but nearly 1 out of 1 reporters use it. Those reporters often quote opinions on it as if they are representative of the larger public, even if the tweet they quote is by someone with 10 followers and no stars.

The fun thing about social media is that reporters can back up any narrative they want. “People are upset about X”, “Gen Z is doing X”, “Millenails are killing X”. Find two people and it's a confirmed trend!

I saw this happen live and I couldn't believe it. There was this Netflix movie last year called "Kate" that has a white female assassin killing a lot of asian people (it takes place in Tokyo). There were a handful of articles (first in places like Yahoo news and then sites like Slate.com) written about how this is racist and they all quoted people on twitter. Since I was following this movie heavily, I saw the tweets come in real time and the subsequent articles written a day later. In the end it all started from one tweet from a random user which then spread into a small handful other people making a similar comment and then leaving it at that. These tweets then got turned into multiple articles. I could not believe how crazy the whole thing was.

The original tweet author did not give permission for her thoughts to be published in so many articles and apparently endured a lot of harassment(She indicated this on subsequent tweets). She eventually deleted the tweet.

This was the original tweet: "Shame on Netflix for this. After this past year especially, to then release a film that is literally white people murdering Asian people based on stereotypes and fetishization??? Hard pass.”

If you google that quote you'll see how many articles quote that tweet.

There were no winners in this whole saga. The movie takes place in Tokyo so of course asian men are going to be the bad guys. So Netflix endured negative press for nothing. The press didn't actually change anything about the film, it obviously pissed off enough people that it caused them to start looking for the tweet author to harass her and finally she deleted her tweet. Who were the winners? The site owners making the money I guess. The whole thing really shows how much of a joke online media is. When regular establishment press is not that good either, what are people to do?

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#106

Mudge is a very credible source. Interesting to see where this goes. Twitter has gone through more security heads than any high tech company should. Not surprised it’s a chaotic environment.

No he's not. He's literally on the CIA payroll along with the rest of CDC.

He has a track record of making up ridiculous stories that serve his task masters. Remember the "Hong Kong Blondes"? Oh right it turned out to be completely fake.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#107
post #2

It is rather disconcerting how a platform that is apparently rather integral to the discourse of today is in the hands of a single private company. It doesn't matter who owns it, if it's Musk or someone else, the fact that it's at the whims of a private company, is the primary channel for discourse, and is something legislatures cannot even comprehend because of their age, should have alarm bells going off. Coupled w…

Ahh they typical brigade is definitely in effect even above this post... A bunch of comments to suppress the real ones made, just like what happens on Twitter regularly.

I had to scroll down past the posts dismissing the issues to get to this one. The news at this point is also conveniently not trending on Twitter even though I am pretty sure a lot more people are Tweeting about it than about Doja Cat right now (who is trending).

I also didn't even see the article, tweeted by CNN, even though I follow them on Twitter.

We're officially chest deep in the era where nothing popular on the Internet is trustworthy nor credible, and where nothing works as expected.

My solution is the same as it always has been... Never respect them enough to enter your real (government) name, and never post anything that you can't afford to have compromised. There is no end to what modern data greed will use your data for.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#108
post #63

Earlier quoted context omitted.

Cybersecurity is one of my roles I suppose (small place with an operations team of approximately 2.5), and I have to say that I have no idea what proper security is supposed to mean today; it's very hard for me to tell the marketing from best practice now. It seems like what most products really are is an ass covering service so you can tell your leadership and your customers that you did the right things. Basically…

Corporate robots don't care. They have gotten away with so much for so long, they live in their own disconnected reality. When things break some of them cash out. Others find someone to blame. They don't pay a price at all. And the cycle continue. In China atleast people are scared of the govt. In the west its a total joke how no one is ever held responsible.

No post body was provided.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#109
post #2

It is rather disconcerting how a platform that is apparently rather integral to the discourse of today is in the hands of a single private company. It doesn't matter who owns it, if it's Musk or someone else, the fact that it's at the whims of a private company, is the primary channel for discourse, and is something legislatures cannot even comprehend because of their age, should have alarm bells going off. Coupled w…

> the primary channel for discourse Primary for whom? If you polled 50 people on the streets of NYC, I bet fewer than 3 would say they actively use twitter. Now do the same for Des Moines, IA and you maybe get 1?

Except that a lot of those 50 people instead consume all kinds of other "news media" who by now regularly use Twitter as a source, so they are still indirectly affected by Twitter even if they don't actively use it.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#110
post #95

By the CNN piece it seems like twitter hired a community figure - which is a common mistake that leads to bad performance evaluation. Public figures are trained on being public figures, they not necessarily are the best folks to build a security organization. OTOH there seems to be some frustration from both sides regarding performance and if it gets public our hackerman will have a rough time being exposed. I don't…

Nobody seems to know how you can build a successful security org

Building a successful security organization is very easy, it just starts higher up the food chain than whatever experts you hire to do it. Security is a cultural practice, it's not a feature, it's not a bolt-on. To the extent that your security organization influences and receives buy-in from your corporate culture, becoming a part of your organization's identity, it will be successful.
Post reply on HN