Live data from Hacker News

Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

cnn.com

201–210 of 645 posts

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#201
While I'm sure Twitter and every social network internal politics suck and are full of sleazy people who hold themselves in very high regard, these accusations seem weak.

He appears to indicate precisely what it's public, like the 5% bots but then goes to into the usual obscure "I know it's not that number and the structure is incentivized in the wrong way.."

Obviously he has an axe to grind and I wouldn't be shocked if Elon was directly involved with this, but I'm not sure this vagueness holds in court..

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#202
post #75

"The whistleblower also says Twitter executives don't have the resources to fully understand the true number of bots on the platform, and were not motivated to." I imagine this hurts Twitter's defense against Musk from pulling out of the takeover deal, or, is this whistleblower's account inadmissible?

> I imagine this hurts Twitter's defense against Musk from pulling out of the takeover deal Not really because they have consistently said "this is what we do, it's a finger in the air estimate based on sampling, it might be right, it might be wildly wrong, there's no agreed methodology for this". For someone to then go "they don't fully understand the true number of bots! GOTCHA!" is dumb because it's literally just…

If the executives did not make a meaningful effort to count them, that is fairly damning, given how much the stock price swings on the count.

Nobody said it was easy, but it's certainly harder if you don't try.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#203

I think it's a pretty open secret that Twitter is a fairly broken company. It's no surprise that their security practices are bad, because all their practices are bad. It's also very difficult to view this in isolation when you have the timeline of (1): Fired in January, nothing happens. (2) Musk makes offer for twitter then reneges. (3) Months before the lawsuit gets decided re-emerges with accusations. What happene…

Did you read the article before slinging mud yourself? The whistleblower has been communicating with DC way before EM entered the picture. Media only got its hands on the leaked material now.

I read the article, and it doesn't say what you said.

>Zatko began the whistleblower process before there was any indication of Musk’s involvement

Define "Began the whistleblower process". Because that seems like an extremely fuzzy way of saying this. And even if you accept that he was genuinely a whistleblower in good faith trying to do this, which I'm perfectly willing to accept, the fact it's coming out in public now is still convenient timing.

It does say

>The disclosure, sent last month

Which means that the actual firm date we have coincides perfectly with Musk's legal wranglings.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#204

Honestly, can you really trust anything about major social media sites any more? Has Twitter ever been in the news for properly making even a thousand people successful from scratch really ever in the product's life? They have pipelines of exploitation for everyone that gets "discovered" into contractual nightmare deals, they require tons of free labor and costly hurdles just to become notable and visible on the plat…

> Honestly, can you really trust anything about major social media sites any more?

Could you ever trust them? Honest question.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#205

I think it's a pretty open secret that Twitter is a fairly broken company. It's no surprise that their security practices are bad, because all their practices are bad. It's also very difficult to view this in isolation when you have the timeline of (1): Fired in January, nothing happens. (2) Musk makes offer for twitter then reneges. (3) Months before the lawsuit gets decided re-emerges with accusations. What happene…

And they say the Tesla fans are a cult... I'm at a loss for words.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#206
post #95

By the CNN piece it seems like twitter hired a community figure - which is a common mistake that leads to bad performance evaluation. Public figures are trained on being public figures, they not necessarily are the best folks to build a security organization. OTOH there seems to be some frustration from both sides regarding performance and if it gets public our hackerman will have a rough time being exposed. I don't…

I commented on this elsewhere, but Mudge was a program manager at DARPA from 2010-2013 and worked at Google from 2013-2020. This narrative that "Twitter hired a long-haired hippy and he didn't know how to build a security org or work in a corporate environment" ignored the past decade plus of his experience.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#207
post #110

Earlier quoted context omitted.

Nobody seems to know how you can build a successful security org

Building a successful security organization is very easy, it just starts higher up the food chain than whatever experts you hire to do it. Security is a cultural practice, it's not a feature, it's not a bolt-on. To the extent that your security organization influences and receives buy-in from your corporate culture, becoming a part of your organization's identity, it will be successful.

I think this is key. If you don't have a good security culture, where people understand and have ingrained proper security practices, you're toast, no matter who else you hire.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#208

Earlier quoted context omitted.

My reasoned mind says it's due to the recent disclosure in Twitter due to linking of phone numbers to people, while my other mind says it's Elon finding anything to make Twitter give up their case.

> in Twitter due to linking of phone numbers to people Except like the linkedin "hack" which was just a scrape of peoples profiles, the twitter "hack" was someone running phone numbers through the "upload you contacts and find your friends account" feature. They are both barely stories, except to remind people that posting stuff publicly is public.

>..the twitter "hack" was someone running phone numbers through the "upload you contacts and find your friends account" feature.

>They are both barely stories, except to remind people that posting stuff publicly is public.

The reoccurring issue is that Twitter and other companies are convincing (and often forcing) you to do something unsafe like linking your phone number, while telling you that your data will be kept private and at the same time opting you in by default, or aggressively marketing, an option that compromises your security.

I'm sure you may be smart enough to know this compromises your anonymity, allows stalkers to find your phone number, etc. but the 99% of users wont.

Linking everything to a phone number is a major dark pattern that benefits the corporations while compromising the user. So rightfully, these malicious and harmful practices should be called out.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#209

Earlier quoted context omitted.

> I imagine this hurts Twitter's defense against Musk from pulling out of the takeover deal Not really because they have consistently said "this is what we do, it's a finger in the air estimate based on sampling, it might be right, it might be wildly wrong, there's no agreed methodology for this". For someone to then go "they don't fully understand the true number of bots! GOTCHA!" is dumb because it's literally just…

If the executives did not make a meaningful effort to count them, that is fairly damning, given how much the stock price swings on the count. Nobody said it was easy, but it's certainly harder if you don't try.

> If the executives did not make a meaningful effort to count them

They've been filing their methodology for bot counting with the SEC since 2013.

If they're not making a "meaningful effort" and it materially affected the stock price in some way, either the SEC or a shareholder would have gone "HOLD ON SHENANIGANS O'CLOCK", surely?

It can't be that the entire world was A-OK with Twitter's bot counting until June 2022 when a man claiming to want to buy Twitter to fix the bot problem got cold feet on a market drop...

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#210

Millenials and GenZ may have no idea who Mudge is. I, however, almost lost my first job out of college at a bank because I ran l0phtcrack against our Windows NT 4 server to see if it could crack passwords. I showed my boss, and he pulled me aside into another room and tore my head off for irresponsibly running this tool against a production server. He said I could have been fired if this got out, but he covered my as…

I may be _too old_ to know who Mudge is, but I know one of the previous Twitter CISOs, and I believe he quit Twitter, which is a canary sign to me.
Post reply on HN