Live data from Hacker News

Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

cnn.com

131–140 of 645 posts

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#131
post #112
post #97

Earlier quoted context omitted.

Not a lot of companies get infiltrated by foreign agents or assets. Access to Twitter, in particular, can help unmasking anonymous sources, sensitive DMs, dissidents - and their locations. And, oh yeah - there is no "conspiracy".

I don't claim Mudge was infiltrating Twitter, nor that his claims to bad security are false, nor that it is not dangerous to use Twitter if you value privacy. Bad security at Twitter, or any other social media is a given. Remember they're in the business of selling personal data. My claim is that this specific story which is most likely true but in no way surprising gets amplified right now because some specific powe…

Or maybe, you know, the media finds this story interesting because this is an extremely visible company with tons of influence on narratives around the world.

Who are these "powerful people"? And why do they care about Twitter so much? Most powerful people aren't even ON Twitter.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#132

Mudge is a very credible source. Interesting to see where this goes. Twitter has gone through more security heads than any high tech company should. Not surprised it’s a chaotic environment.

No he's not. He's literally on the CIA payroll along with the rest of CDC. He has a track record of making up ridiculous stories that serve his task masters. Remember the "Hong Kong Blondes"? Oh right it turned out to be completely fake.

[deleted]

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#133
post #128
post #77

Earlier quoted context omitted.

Why would it be inadmissible? Mudge could be subpeonaed, just like Jack was just subpeonaed.

Indeed, he just was. https://twitter.com/deitaone/status/1562069657582018560 (That account tweets bloomberg alerts)

Wow, that was quick!

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#134

Honestly, can you really trust anything about major social media sites any more? Has Twitter ever been in the news for properly making even a thousand people successful from scratch really ever in the product's life? They have pipelines of exploitation for everyone that gets "discovered" into contractual nightmare deals, they require tons of free labor and costly hurdles just to become notable and visible on the plat…

> only pleasing it's sponsors, investors, and execs

Yea, that's the game. They are a for profit business. This situation will happen every time. Profits over people, line must go up!

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#135

I think it's a pretty open secret that Twitter is a fairly broken company. It's no surprise that their security practices are bad, because all their practices are bad. It's also very difficult to view this in isolation when you have the timeline of (1): Fired in January, nothing happens. (2) Musk makes offer for twitter then reneges. (3) Months before the lawsuit gets decided re-emerges with accusations. What happene…

This was my first thought. TFA claims he started the whistleblower process before the Musk deal was signed. Seems kind of fishy though.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#136

God Mode, from my understanding, allows a Twitter employee to have access to an account and allows for a post to be made, under that account's id, without the account being notified or seeing the post show up in their own timeline. Is this an accurate statement? If so, why did nearly 1000 employees (12% of the workforce) have access to this mode before it was restricted, and what's the business case for that?

Now think about the implications with respect to Twitter DMs that show up in criminal investigations. For instance, consider the Twitter DMs exchanged by Donald Trump, Jr and WikiLeaks. In that particular case, the communication was acknowledged by the party in question, but imagine the two possibilities thousands of employees being able to act on the part of users opens up: 1. Twitter employees could fabricate a cri…

This seems like a huge win for the defense in a case using DMs or Tweets as evidence.

It would be quite easy to argue that a highly-politicized org like Twitter _might_ alter tweets or DMs to implicate someone in the opposing party. That’s reasonable doubt that at least some jurors would buy.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#137
"Twitter has hidden negligent security practices, misled federal regulators about its safety, and failed to properly estimate the number of bots on its platform, according to testimony from the company’s former head of security, the legendary hacker-turned-cybersecurity-expert Peiter “Mudge” Zatko."

"Zatko was fired by Twitter in January and claims that this was retaliation for his refusal to stay quiet about the company’s vulnerabilities. Last month, he filed a complaint with the Securities and Exchange Commission (SEC) that accuses Twitter of deceiving shareholders and violating an agreement it made with the Federal Trade Commission (FTC) to uphold certain security standards. His complaints, totaling more than 200 pages, were obtained by CNN and The Washington Post and published in redacted form this morning."

What a bombshell! Maybe Elon Musk's complaints about Twitter have more merit than anyone expected.

What might the SEC and shareholders do in response?

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#138

I think it's a pretty open secret that Twitter is a fairly broken company. It's no surprise that their security practices are bad, because all their practices are bad. It's also very difficult to view this in isolation when you have the timeline of (1): Fired in January, nothing happens. (2) Musk makes offer for twitter then reneges. (3) Months before the lawsuit gets decided re-emerges with accusations. What happene…

Did you read the article before slinging mud yourself? The whistleblower has been communicating with DC way before EM entered the picture.

Media only got its hands on the leaked material now.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#139

I think it's a pretty open secret that Twitter is a fairly broken company. It's no surprise that their security practices are bad, because all their practices are bad. It's also very difficult to view this in isolation when you have the timeline of (1): Fired in January, nothing happens. (2) Musk makes offer for twitter then reneges. (3) Months before the lawsuit gets decided re-emerges with accusations. What happene…

Apperantly he started the whistleblowing process before any Musk involvement with Twitter.

https://twitter.com/KimZetter/status/1562061556745089025

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#140

Honestly, can you really trust anything about major social media sites any more? Has Twitter ever been in the news for properly making even a thousand people successful from scratch really ever in the product's life? They have pipelines of exploitation for everyone that gets "discovered" into contractual nightmare deals, they require tons of free labor and costly hurdles just to become notable and visible on the plat…

I think it is clear we need more public regulation over these companies, and a lot of the mechanisms need to be embedded in a non-profit / social utility system, given they DIRECTLY impact politics. Anything that democracy is reliant upon should not be subject to private, opaque control.

In the case of data harvesting, data is the most valuable resource. You can control what people want using data. No entity should have unfettered access to data — it is undeniably evil in the truest sense of the word. Which, in the context of my use, means to decay forward progress or to increase aggregated suffering.

They will not fix these issues until the public makes it so painful not to, that they must. As an example, how is Experian still in business after what they’ve done? They should have had a $100 billion+ fine levied against them, and that fine should pierce through limited liability to the extent that the board of directors and C-level staff are liable for it. The company and any owners of it should be bankrupted and living in poverty after what they’ve done.

Until we make PEOPLE liable for the evils they induce on others, this will keep happening. I don’t get limited liability if I went out and murdered someone, why should the PEOPLE running companies have limited liability when they murder millions with pollution, or with financial terrorism? Answer: they shouldn’t.

Post reply on HN