Live data from Hacker News

Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

cnn.com

191–200 of 645 posts

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#191

Millenials and GenZ may have no idea who Mudge is. I, however, almost lost my first job out of college at a bank because I ran l0phtcrack against our Windows NT 4 server to see if it could crack passwords. I showed my boss, and he pulled me aside into another room and tore my head off for irresponsibly running this tool against a production server. He said I could have been fired if this got out, but he covered my as…

I agree. I grant It’s possible Mudge is

A) an old hand and doesn’t know how to run a security program with the tech today

B) a strong tech hire who can’t lead a program.

But Mudge is still… Mudge, and he’s also proven his ability to collaborate so if he was a bull in a china shop a twitter, that would be surprising.

There’s also a broader trend here of well known security leads that originate from that time working at social media and leaving quickly, like Alex Stamos, who also u-turned out of Facebook.

So are the odds higher that Mudge did a bad job, or this set of companies are not great internally and old guard security leads are pointing it out? The twitter CEO letter framing him as a bad employee doesn’t address this context.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#192

I think it's a pretty open secret that Twitter is a fairly broken company. It's no surprise that their security practices are bad, because all their practices are bad. It's also very difficult to view this in isolation when you have the timeline of (1): Fired in January, nothing happens. (2) Musk makes offer for twitter then reneges. (3) Months before the lawsuit gets decided re-emerges with accusations. What happene…

Apperantly he started the whistleblowing process before any Musk involvement with Twitter. https://twitter.com/KimZetter/status/1562061556745089025

> Apperantly he started the whistleblowing process before any Musk involvement with twitter.

According to his lawyer as reported by someone on Twitter. IIRC, lawyers make statements that guilty clients are innocent all the time.

If he was working with Musk help him wiggle out of the Twitter deal, it would fatally undermine the goal for to come out publicly about the relationship. I'm skeptical unless they can provide verifiable 3rd party evidence (e.g. some document filed before the deal).

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#193
post #157
post #153

Earlier quoted context omitted.

I know about a certain person who has been doing very unorthodox moves towards the acquisition of Twitter since earlier this year; this person, as well as all the wealthy stakeholders who have a lot to lose if the deal goes through in an unprofitable way, would certainly gain a lot by amplifying this story with a few grands in the pockets of the CNN business editors.

I think you are overestimating the influence of Elon Musk on American media, my friend. Are they enamored with him - for sure, are they in his actual pocket? Doubt it.

Not necessarily the man specifically. Anyone with a high stake in Tesla/SpaceX/long-termist companies and an arm in the media machine who would benefit from this press release.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#194
post #179

Earlier quoted context omitted.

This was my first thought. TFA claims he started the whistleblower process before the Musk deal was signed. Seems kind of fishy though.

Maybe, just maybe, Twitter is actually a poorly run company and it's not a conspiracy.

[flagged]

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#195

I think it's a pretty open secret that Twitter is a fairly broken company. It's no surprise that their security practices are bad, because all their practices are bad. It's also very difficult to view this in isolation when you have the timeline of (1): Fired in January, nothing happens. (2) Musk makes offer for twitter then reneges. (3) Months before the lawsuit gets decided re-emerges with accusations. What happene…

Apperantly he started the whistleblowing process before any Musk involvement with Twitter. https://twitter.com/KimZetter/status/1562061556745089025

I mean I want to give the guy the benefit of the doubt but is the only evidence that was the case this journalist saying "Mudge totally told me he did this before Musk got here I swear."

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#196

Earlier quoted context omitted.

> Especially since the Whistleblower seems to basically be blowing the whilst on himself. Whistleblowers are by definition insiders.

Yes, but that's not the point here. A typical whistleblower would say "There were security problems, and the head of security ignored them." Here, it's "I was the head of security, and security was shitty. I was doing a shitty job, and that's a terrible scandal!"

As others have said, being head of security is meaningless if the people in charge of actually making changes refuse to make the changes you prescribe.

I've been in that situation at a previous job. The infrastructure for our service was set up so that EC2 instances would start up and pull their code from a central repo. But this repo was open to the world and did not require authentication. It was only a matter of time before some malicious user discovered this and our proprietary server code got leaked.

It took weeks of hounding and escalating until something changed, and at first all they did was change the security groups to limit where you could connect from, and even the first patch merely limited it to a few /8 and /16 CIDRs that covered massive swaths of AWS-owned IPs. They still didn't require authentication.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#197

I've been hearing about Mudge for decades . It's actually a bit ... heartbreaking ... to see him looking so corporate, but we all age, don't we? I doubt he was fired for being bad at his job. But I'll bet he was fired for getting in people's faces. That was basically his calling card for years . Why is anyone surprised? I guess Twitter thought they could hire the cachet, without hiring the man. I remember an Apple WW…

I don't think your comparison is apt. Mudge isn't some loose cannon. He worked for the US government as a program manager for DARPA from 2010-2013, then for Google from 2013-2020. You think he looks "corporate" now, just look at his government portrait on his Wikipedia page from a decade ago.

Point being, Mudge is a very well respected cyber security professional, not some "hippy hacker" from years past. Which makes me even more willing to give his accusations weight, because this is not a case of someone who doesn't "get" corporate environments.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#198

Earlier quoted context omitted.

> Especially since the Whistleblower seems to basically be blowing the whilst on himself. Whistleblowers are by definition insiders.

Yes, but that's not the point here. A typical whistleblower would say "There were security problems, and the head of security ignored them." Here, it's "I was the head of security, and security was shitty. I was doing a shitty job, and that's a terrible scandal!"

It's not his responsibility if someone with more power is sabotaging his work. He tried to do his work, realized it was not possible, and escalated to a higher authority. A bit unusual, but technically a way to maybe solve the problem and still do the job at the end.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#199
post #168

Just to clarify for those who don't catch it in the article: Mudge's whistleblower complaint predates the Musk/Twitter feud entirely.

Where do you see that info in the Verge article? All I can see is "he filed last month" (which would be July 2022) - the month Musk "officially" backed out and at least a month after he started doing the "I don't want Twitter any more" dance.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#200
post #121
post #63

Earlier quoted context omitted.

Corporate robots don't care. They have gotten away with so much for so long, they live in their own disconnected reality. When things break some of them cash out. Others find someone to blame. They don't pay a price at all. And the cycle continue. In China atleast people are scared of the govt. In the west its a total joke how no one is ever held responsible.

Yikes, I wouldn't boast about being scared of a govt. That's on the cusp of being fascist.

Isn't the ideal something like:

Citizens should respect Government, and Government should fear citizens?

I think we are straying away from both of these at the moment.

Post reply on HN