Live data from Hacker News

Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

cnn.com

221–230 of 645 posts

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#221

Earlier quoted context omitted.

> in Twitter due to linking of phone numbers to people Except like the linkedin "hack" which was just a scrape of peoples profiles, the twitter "hack" was someone running phone numbers through the "upload you contacts and find your friends account" feature. They are both barely stories, except to remind people that posting stuff publicly is public.

>..the twitter "hack" was someone running phone numbers through the "upload you contacts and find your friends account" feature. >They are both barely stories, except to remind people that posting stuff publicly is public. The reoccurring issue is that Twitter and other companies are convincing (and often forcing) you to do something unsafe like linking your phone number, while telling you that your data will be kept…

Additionally, Twitter collected PII and then did a bad job protecting it. We don't see a phone-numbers-leaked story like this out of Google, which has had 2FA with phone number deployed for years.

Twitter has some 200+ million daily active users and should act like it.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#222
The bots problem is absolutely nightmare issue for a social network. I can't imagine what I'd do if I discovered my network was fake. The whole point of my network is building professional connections and gaining skills for work.

Also seeing various weird topics on twitter like kpop or other random things always made me wonder how much artificial bot boosting was done for those who had money to pay the bot net.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#223
post #172
post #163

Earlier quoted context omitted.

>What might the SEC and shareholders do in response? If shareholders believe this, they can do a variety of things such as sell the stock (smaller holders), or demand answers from leadership that go beyond "Yeah, we're secure" (bigger holders such as Saudi Arabia).

Some options that shareholders would have in the situation where investors were knowingly deceived by false disclosures of a publicly traded company are missing from this response.

Namely, the ability for shareholders to sue Twitter.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#224
post #7

How long before Musk weaponises this in his lawsuit against Twitter?

It may appear that this may get Musk off the hook for buying Twitter because "Look how bad they are!" but, as I recall, Musk's problem is that his offer with without contingency - e.g. "Yah, I'll buy it, whatever".

So it may just be another event which will drive Twitter's price down even further and make it a _worse_ deal for him.

From Bloomberg "The buyers could only back out of the agreement in the case of a material adverse effect, a high bar that excludes issues like market volatility or industry challenges." (https://www.bloomberg.com/news/newsletters/2022-07-13/elon-m...).

I suppose one could argue that the Whistleblower's report is "material adverse affect", something I'm sure will come out in the trial.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#225

Earlier quoted context omitted.

If the executives did not make a meaningful effort to count them, that is fairly damning, given how much the stock price swings on the count. Nobody said it was easy, but it's certainly harder if you don't try.

> If the executives did not make a meaningful effort to count them They've been filing their methodology for bot counting with the SEC since 2013. If they're not making a "meaningful effort" and it materially affected the stock price in some way, either the SEC or a shareholder would have gone "HOLD ON SHENANIGANS O'CLOCK", surely? It can't be that the entire world was A-OK with Twitter's bot counting until June 2022…

The "methodology" is that people look at 100 accounts a day and determine whether they are bots. They have never disclosed any of the signals that go into this determination. You have a lot of faith in the immediately efficient market here.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#226

Earlier quoted context omitted.

Apperantly he started the whistleblowing process before any Musk involvement with Twitter. https://twitter.com/KimZetter/status/1562061556745089025

I mean I want to give the guy the benefit of the doubt but is the only evidence that was the case this journalist saying "Mudge totally told me he did this before Musk got here I swear."

It doesn't really sound like you want to give him the benefit of the doubt.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#227

Earlier quoted context omitted.

> Especially since the Whistleblower seems to basically be blowing the whilst on himself. Whistleblowers are by definition insiders.

Sure, but it's not normally the guy in charge of security that gets to complain the security isn't good enough.

I seem to read fairly often about security folk (or even plain ol' sysadmins) bemoaning their companies' security, like their presence or oversight is a box checking exercise rather than a real commitment.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#228

Millenials and GenZ may have no idea who Mudge is. I, however, almost lost my first job out of college at a bank because I ran l0phtcrack against our Windows NT 4 server to see if it could crack passwords. I showed my boss, and he pulled me aside into another room and tore my head off for irresponsibly running this tool against a production server. He said I could have been fired if this got out, but he covered my as…

Ah yes, Lopht Heavy Industries. Indispensable tools at the time.

Always been a fan of "Heavy Industries".

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#230

The bots problem is absolutely nightmare issue for a social network. I can't imagine what I'd do if I discovered my network was fake. The whole point of my network is building professional connections and gaining skills for work. Also seeing various weird topics on twitter like kpop or other random things always made me wonder how much artificial bot boosting was done for those who had money to pay the bot net.

FYI Kpop is "very" popular in some segments of American culture that you just might not cross over with. I experience it frequently in the "Team Fight Tactics" ecosystem which is an E-Sport run by Riot Games (of League of Legends fame) that for some reason contains a very large Asian American population (in relation to their % of the population) and all of them frequently stream Kpop to large audiences. The largest streamer for this game "K3Soju" is one of the top 10 streamers on Twitch frequently pulling in over 20,000 viewers. All of these people are very active on Twitter. I point this out because I doubt things like this going viral on Twitter are necessarily the result of bot networks instead of just the result of corners of the internet that we don't encounter.
Post reply on HN