Live data from Hacker News

Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

cnn.com

111–120 of 645 posts

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#111
post #68

Earlier quoted context omitted.

A world-wide, decentralized, communications platform sounds lovely. Oh wait...

Oh wait?

Oh wait, we already had that, and then we centralized and monopolized the hell out of it [0]

[0] https://staltz.com/the-web-began-dying-in-2014-heres-how.htm...

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#112
post #97
post #78

Earlier quoted context omitted.

Because people with a lot of money are inflating this story to get back at Twitter. It sounds like a conspiracy, but that's the most plausible explanation I have for why this specific whistleblower gets amplified by the media.

Not a lot of companies get infiltrated by foreign agents or assets. Access to Twitter, in particular, can help unmasking anonymous sources, sensitive DMs, dissidents - and their locations. And, oh yeah - there is no "conspiracy".

I don't claim Mudge was infiltrating Twitter, nor that his claims to bad security are false, nor that it is not dangerous to use Twitter if you value privacy. Bad security at Twitter, or any other social media is a given. Remember they're in the business of selling personal data.

My claim is that this specific story which is most likely true but in no way surprising gets amplified right now because some specific powerful people wanted it so.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#113

Earlier quoted context omitted.

> the primary channel for discourse Primary for whom? If you polled 50 people on the streets of NYC, I bet fewer than 3 would say they actively use twitter. Now do the same for Des Moines, IA and you maybe get 1?

I think that Twitter is very much the tail that wags the dog. Sure, 1 out of 50 normal people may use it, but nearly 1 out of 1 reporters use it. Those reporters often quote opinions on it as if they are representative of the larger public, even if the tweet they quote is by someone with 10 followers and no stars.

I'm involved in a community advocacy organisation that uses Twitter, Facebook and Instagram for public engagement.

Facebook is a great platform for actually getting normal people to see our content and invite them along to our meetings and such. Twitter, on the other hand, has a far more niche audience - but I know for a fact that the niche audience includes several state legislators who follow us and interact with our tweets, and we've gotten several press stories via contacts we've made with journalists over Twitter.

If you've got a message to get out there, it's a highly strategic platform.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#114
post #36

Eh, you could take out Twitter and insert many other company names and it'll still hold true. And those companies hold so much more sensitive data about you than Twitter. I know of insurance companies that have help desk employees with domain admin access. And all crippling ransomware attacks take advantage lax permissions. This is rampant. How is this a story?

>This is rampant. How is this a story?

Bro. It's not every day that literally Mudge, who has -no doubt- seen his fair share of shit-shows, whistleblows on an employer.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#115

Earlier quoted context omitted.

Cybersecurity is one of my roles I suppose (small place with an operations team of approximately 2.5), and I have to say that I have no idea what proper security is supposed to mean today; it's very hard for me to tell the marketing from best practice now. It seems like what most products really are is an ass covering service so you can tell your leadership and your customers that you did the right things. Basically…

I’m a security engineer and nobody knows what’s best practice. Everyone is making it up at this point, and security is still a nascent field. Most companies don’t even have a security team. I think it’s still not clear how you should build a security org, and if you should at all (should security be part of normal workstreams of your devs?) Btw I wrote about my experience in https://securityhandbook.io/

Is there even best practice for non-cyber security at private businesses?

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#117
post #63

Earlier quoted context omitted.

Corporate robots don't care. They have gotten away with so much for so long, they live in their own disconnected reality. When things break some of them cash out. Others find someone to blame. They don't pay a price at all. And the cycle continue. In China atleast people are scared of the govt. In the west its a total joke how no one is ever held responsible.

Quoted post unavailable.

Right. Democracy is fake…

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#118
post #75

"The whistleblower also says Twitter executives don't have the resources to fully understand the true number of bots on the platform, and were not motivated to." I imagine this hurts Twitter's defense against Musk from pulling out of the takeover deal, or, is this whistleblower's account inadmissible?

> I imagine this hurts Twitter's defense against Musk from pulling out of the takeover deal

Not really because they have consistently said "this is what we do, it's a finger in the air estimate based on sampling, it might be right, it might be wildly wrong, there's no agreed methodology for this".

For someone to then go "they don't fully understand the true number of bots! GOTCHA!" is dumb because it's literally just pointing out exactly what they've said in their SEC filings since 2013.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#120
post #36

Eh, you could take out Twitter and insert many other company names and it'll still hold true. And those companies hold so much more sensitive data about you than Twitter. I know of insurance companies that have help desk employees with domain admin access. And all crippling ransomware attacks take advantage lax permissions. This is rampant. How is this a story?

Because it's CNN and they like to make headlines with some bogus whistleblower that is concerned that some die-hard trumpers are going to hack top companies and create some kind of mass hysteria. Just the usual fear mongering in the news media to get views.
Post reply on HN