Live data from Hacker News

Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

cnn.com

211–220 of 645 posts

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#211

Millenials and GenZ may have no idea who Mudge is. I, however, almost lost my first job out of college at a bank because I ran l0phtcrack against our Windows NT 4 server to see if it could crack passwords. I showed my boss, and he pulled me aside into another room and tore my head off for irresponsibly running this tool against a production server. He said I could have been fired if this got out, but he covered my as…

Twitter Inc. is indeed in very serious trouble if you have someone like Mudge whistleblowing.

Now looking at the chaos, damage control and the PR disaster that is happening at Twitter HQ after this, I have zero confidence in whatever Twitter HQ and the CEO is saying other than admitting their total incompetency towards how they handle information security at the company. All attempts to make this disaster disappear will not only fail, but will eventually backfire.

So what else was Twitter lying about?

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#212
post #174

Earlier quoted context omitted.

>waiving due diligence rights Pop legal quiz - does "waving due diligence rights" during an acquisition remove the other party's liability for fraud they've committed against the prospective buyer?

> the other party's liability for fraud What fraud though?

The fraud that Mudge alleges in this article, for instance?

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#213
post #168

Just to clarify for those who don't catch it in the article: Mudge's whistleblower complaint predates the Musk/Twitter feud entirely.

Where do you see that info in the Verge article? All I can see is "he filed last month" (which would be July 2022) - the month Musk "officially" backed out and at least a month after he started doing the "I don't want Twitter any more" dance.

"Zatko was fired by Twitter in January and claims that this was retaliation for his refusal to stay quiet about the company’s vulnerabilities."

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#214
post #179

Earlier quoted context omitted.

Maybe, just maybe, Twitter is actually a poorly run company and it's not a conspiracy.

[flagged]

I don't remember conservatives threatening Twitter to censor "dangerous" views or "misinformation" or telling who to ban.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#215

Millenials and GenZ may have no idea who Mudge is. I, however, almost lost my first job out of college at a bank because I ran l0phtcrack against our Windows NT 4 server to see if it could crack passwords. I showed my boss, and he pulled me aside into another room and tore my head off for irresponsibly running this tool against a production server. He said I could have been fired if this got out, but he covered my as…

I don't because I'm not seeing an organization that will hold them accountable.

- This Congress is ill-equipped to understand tech, much less hold it accountable. As long as the people are happy, Congress is happy.

- Lord knows the people are ill-equipped to get how bad this is. They already watched this company allow a rogue employee to shut off the account of the President of the United States (before they chose to do it as policy; https://www.washingtonpost.com/news/the-switch/wp/2017/11/02...) and watched this company deploy a username-to-telephone lookup service publicly where they'd intended to deploy a security protocol (https://www.ghacks.net/2022/08/08/twitter-confirms-that-a-da...). The public doesn't understand why they should care.

- The only group who could really hold Twitter accountable are shareholders, but why should they care if the public and Congress don't? The money will roll in either way.

Unless they've managed to commit an SEC violation (in which case, slap on the wrist incoming), there are no consequences for this kind of bad behavior until someone powerful gets seriously hurt. I'm glad Mudge is doing the right thing, but extremely pessimistic much will come of it. My recommendation is to shed Twitter as a user.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#218
post #36

Eh, you could take out Twitter and insert many other company names and it'll still hold true. And those companies hold so much more sensitive data about you than Twitter. I know of insurance companies that have help desk employees with domain admin access. And all crippling ransomware attacks take advantage lax permissions. This is rampant. How is this a story?

> This is rampant. How is this a story?

Well, it's on the front page of CNN right now for starters, so that means it's probably significant to a lot of people...

If you have a business, you most likely need to promote it on Twitter, or to at least reserve an account there so that someone else won't impersonate you. You also need to do that on almost all other major social platforms.

If you have a business or personal account on Twitter, your direct messages, the data the system generates about your preferences and interests, your geo-coordinates, and everything you post, including control of how your account works can apparently be accessed by too many people within the company.

It's a pretty big deal for anyone that uses the platform citing all that... Not something that should just be "left to it's own devices" because everyone else is doing the same. All cases of data abuse/misuse should be addressed, but addressing one this big would also be a pretty big deal.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#219

I think it's a pretty open secret that Twitter is a fairly broken company. It's no surprise that their security practices are bad, because all their practices are bad. It's also very difficult to view this in isolation when you have the timeline of (1): Fired in January, nothing happens. (2) Musk makes offer for twitter then reneges. (3) Months before the lawsuit gets decided re-emerges with accusations. What happene…

Did you read the article before slinging mud yourself? The whistleblower has been communicating with DC way before EM entered the picture. Media only got its hands on the leaked material now.

Not exactly. The CNN article doesn't say that, and The Verge's piece[1] on this puts it together pretty clearly.

>Zatko was fired by Twitter in January and claims that this was retaliation for his refusal to stay quiet about the company’s vulnerabilities. Last month, he filed a complaint with the Securities and Exchange Commission (SEC) that accuses Twitter of deceiving shareholders and violating an agreement it made with the Federal Trade Commission (FTC) to uphold certain security standards. His complaints, totaling more than 200 pages, were obtained by CNN and The Washington Post and published in redacted form this morning.

So, breaking it down more concisely:

1.) Fired in January

2.) Musk tries to buy Twitter in early April

3.) Complaint filed with SEC in July by Mudge ("way [after] EM entered the picture")

4.) WaPo published redacted, 200-page report today

[1]https://www.theverge.com/2022/8/23/23317857/twitter-whistleb...

Edit: This is not an endorsement of mud-slinging, just an attempt to make sure everyone knows what actually happened and when, at least as best we can discern at this point.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#220

I've been hearing about Mudge for decades . It's actually a bit ... heartbreaking ... to see him looking so corporate, but we all age, don't we? I doubt he was fired for being bad at his job. But I'll bet he was fired for getting in people's faces. That was basically his calling card for years . Why is anyone surprised? I guess Twitter thought they could hire the cachet, without hiring the man. I remember an Apple WW…

I don't think your comparison is apt. Mudge isn't some loose cannon. He worked for the US government as a program manager for DARPA from 2010-2013, then for Google from 2013-2020. You think he looks "corporate" now, just look at his government portrait on his Wikipedia page from a decade ago. Point being, Mudge is a very well respected cyber security professional, not some "hippy hacker" from years past. Which makes…

I didn't mean that he was a "hippy hacker." Maybe you misinterpreted that, from my story (BTW: Ken Kesey was no slouch, either). My apologies for being unclear.

But he has definite history of being quite willing to speak truth to power. Not having had any personal interactions with him, I can only go on the [many] stories I've heard.

Post reply on HN