Earlier quoted context omitted.
The fun thing about social media is that reporters can back up any narrative they want. “People are upset about X”, “Gen Z is doing X”, “Millenails are killing X”. Find two people and it's a confirmed trend!
I saw a reddit post today that "Disney fans are furious that Avatar was temporarily pulled from Disney Store" and the top 500 comments were like "No one is furious". Here, I'll give it a go: "Environmentalists are furious that Bill Gates kills mosquitos"
Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies
101–110 of 645 posts
Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies
#102Eh, you could take out Twitter and insert many other company names and it'll still hold true. And those companies hold so much more sensitive data about you than Twitter. I know of insurance companies that have help desk employees with domain admin access. And all crippling ransomware attacks take advantage lax permissions. This is rampant. How is this a story?
Cybersecurity is one of my roles I suppose (small place with an operations team of approximately 2.5), and I have to say that I have no idea what proper security is supposed to mean today; it's very hard for me to tell the marketing from best practice now. It seems like what most products really are is an ass covering service so you can tell your leadership and your customers that you did the right things. Basically…
Walk through the controls list, see where you compare to the controls and sub-controls and then start to establish a path forward.
Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies
#103Earlier quoted context omitted.
Two problems with this: 1) Like a car mechanic, these people get paid to sell you solutions and they are incentivized to sell you more. 2) Plenty or honest people have biases because of what they do. If you spend all day thinking about security you might be overly concerned about things that are actually not that risky. This isn’t to say that there aren’t great people working in the field. But it’s daunting from an o…
It's still comes down to a matter of urgency or value perception. You don't want your doctor to overlook any problems just because they are rare because your health is really valuable.
Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies
#104Eh, you could take out Twitter and insert many other company names and it'll still hold true. And those companies hold so much more sensitive data about you than Twitter. I know of insurance companies that have help desk employees with domain admin access. And all crippling ransomware attacks take advantage lax permissions. This is rampant. How is this a story?
Cybersecurity is one of my roles I suppose (small place with an operations team of approximately 2.5), and I have to say that I have no idea what proper security is supposed to mean today; it's very hard for me to tell the marketing from best practice now. It seems like what most products really are is an ass covering service so you can tell your leadership and your customers that you did the right things. Basically…
I think it’s still not clear how you should build a security org, and if you should at all (should security be part of normal workstreams of your devs?)
Btw I wrote about my experience in https://securityhandbook.io/
Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies
#105Earlier quoted context omitted.
I think that Twitter is very much the tail that wags the dog. Sure, 1 out of 50 normal people may use it, but nearly 1 out of 1 reporters use it. Those reporters often quote opinions on it as if they are representative of the larger public, even if the tweet they quote is by someone with 10 followers and no stars.
The fun thing about social media is that reporters can back up any narrative they want. “People are upset about X”, “Gen Z is doing X”, “Millenails are killing X”. Find two people and it's a confirmed trend!
The original tweet author did not give permission for her thoughts to be published in so many articles and apparently endured a lot of harassment(She indicated this on subsequent tweets). She eventually deleted the tweet.
This was the original tweet: "Shame on Netflix for this. After this past year especially, to then release a film that is literally white people murdering Asian people based on stereotypes and fetishization??? Hard pass.”
If you google that quote you'll see how many articles quote that tweet.
There were no winners in this whole saga. The movie takes place in Tokyo so of course asian men are going to be the bad guys. So Netflix endured negative press for nothing. The press didn't actually change anything about the film, it obviously pissed off enough people that it caused them to start looking for the tweet author to harass her and finally she deleted her tweet. Who were the winners? The site owners making the money I guess. The whole thing really shows how much of a joke online media is. When regular establishment press is not that good either, what are people to do?
Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies
#106Mudge is a very credible source. Interesting to see where this goes. Twitter has gone through more security heads than any high tech company should. Not surprised it’s a chaotic environment.
He has a track record of making up ridiculous stories that serve his task masters. Remember the "Hong Kong Blondes"? Oh right it turned out to be completely fake.
Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies
#107It is rather disconcerting how a platform that is apparently rather integral to the discourse of today is in the hands of a single private company. It doesn't matter who owns it, if it's Musk or someone else, the fact that it's at the whims of a private company, is the primary channel for discourse, and is something legislatures cannot even comprehend because of their age, should have alarm bells going off. Coupled w…
I had to scroll down past the posts dismissing the issues to get to this one. The news at this point is also conveniently not trending on Twitter even though I am pretty sure a lot more people are Tweeting about it than about Doja Cat right now (who is trending).
I also didn't even see the article, tweeted by CNN, even though I follow them on Twitter.
We're officially chest deep in the era where nothing popular on the Internet is trustworthy nor credible, and where nothing works as expected.
My solution is the same as it always has been... Never respect them enough to enter your real (government) name, and never post anything that you can't afford to have compromised. There is no end to what modern data greed will use your data for.
Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies
#108Earlier quoted context omitted.
Cybersecurity is one of my roles I suppose (small place with an operations team of approximately 2.5), and I have to say that I have no idea what proper security is supposed to mean today; it's very hard for me to tell the marketing from best practice now. It seems like what most products really are is an ass covering service so you can tell your leadership and your customers that you did the right things. Basically…
Corporate robots don't care. They have gotten away with so much for so long, they live in their own disconnected reality. When things break some of them cash out. Others find someone to blame. They don't pay a price at all. And the cycle continue. In China atleast people are scared of the govt. In the west its a total joke how no one is ever held responsible.
Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies
#109It is rather disconcerting how a platform that is apparently rather integral to the discourse of today is in the hands of a single private company. It doesn't matter who owns it, if it's Musk or someone else, the fact that it's at the whims of a private company, is the primary channel for discourse, and is something legislatures cannot even comprehend because of their age, should have alarm bells going off. Coupled w…
> the primary channel for discourse Primary for whom? If you polled 50 people on the streets of NYC, I bet fewer than 3 would say they actively use twitter. Now do the same for Des Moines, IA and you maybe get 1?
Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies
#110By the CNN piece it seems like twitter hired a community figure - which is a common mistake that leads to bad performance evaluation. Public figures are trained on being public figures, they not necessarily are the best folks to build a security organization. OTOH there seems to be some frustration from both sides regarding performance and if it gets public our hackerman will have a rough time being exposed. I don't…
Nobody seems to know how you can build a successful security org