Live data from Hacker News

Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

cnn.com

241–250 of 645 posts

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#241

Earlier quoted context omitted.

>..the twitter "hack" was someone running phone numbers through the "upload you contacts and find your friends account" feature. >They are both barely stories, except to remind people that posting stuff publicly is public. The reoccurring issue is that Twitter and other companies are convincing (and often forcing) you to do something unsafe like linking your phone number, while telling you that your data will be kept…

Additionally, Twitter collected PII and then did a bad job protecting it. We don't see a phone-numbers-leaked story like this out of Google, which has had 2FA with phone number deployed for years. Twitter has some 200+ million daily active users and should act like it.

Decide whether people who have your email address or phone number can find and connect with you on Twitter. If you select yes, then someone with l33t skills can "hack" twitter and type in your email / phone number and get your twitter handle (or just put it in their contacts and click a button in the twitter app aka l33t hax0r skills)

The reason there isnt "leak" from google is because they dont offer the functionality to look up your account by your phone number.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#243

Earlier quoted context omitted.

[flagged]

I don't remember conservatives threatening Twitter to censor "dangerous" views or "misinformation" or telling who to ban.

[flagged]

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#244

Earlier quoted context omitted.

I agree. I grant It’s possible Mudge is A) an old hand and doesn’t know how to run a security program with the tech today B) a strong tech hire who can’t lead a program. But Mudge is still… Mudge, and he’s also proven his ability to collaborate so if he was a bull in a china shop a twitter, that would be surprising. There’s also a broader trend here of well known security leads that originate from that time working a…

> B) a strong tech hire who can’t lead a program. I worked with Mudge (not super close, but enough to see how he worked across teams etc) and can certainly say this is not the case. At least when I saw him Mudge was excellent at the program leadership aspect of his role. At one point he ended up a DARPA PM. You can't go from L0pht to DARPA without getting really good at working with other people and leading projects.…

Even 20 years ago, extremely well spoken and has worked at high political levels...

https://www.cnn.com/videos/business/2022/08/23/peiter-mudge-...

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#245

Millenials and GenZ may have no idea who Mudge is. I, however, almost lost my first job out of college at a bank because I ran l0phtcrack against our Windows NT 4 server to see if it could crack passwords. I showed my boss, and he pulled me aside into another room and tore my head off for irresponsibly running this tool against a production server. He said I could have been fired if this got out, but he covered my as…

It's Twitter. What possible serious security implications could possibly warrant everyone in Washington getting into a frenzy?

All you do is make public comments that have zero value.

And if this is indeed serious, where the fuck have we landed?

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#246

Honestly, can you really trust anything about major social media sites any more? Has Twitter ever been in the news for properly making even a thousand people successful from scratch really ever in the product's life? They have pipelines of exploitation for everyone that gets "discovered" into contractual nightmare deals, they require tons of free labor and costly hurdles just to become notable and visible on the plat…

> Honestly, can you really trust anything about major social media sites any more? Could you ever trust them? Honest question.

Sure you could! (Back when they were new and they wanted to woo you as a user, and when features and functionality worked as expected)... Hah.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#247

I think it's a pretty open secret that Twitter is a fairly broken company. It's no surprise that their security practices are bad, because all their practices are bad. It's also very difficult to view this in isolation when you have the timeline of (1): Fired in January, nothing happens. (2) Musk makes offer for twitter then reneges. (3) Months before the lawsuit gets decided re-emerges with accusations. What happene…

You’re ascribing the worst possible motives to someone based on your hatred of Elon Musk. Someone who has no known relationship with Musk, who has claimed publicly they started this process before Musk was involved with twitter, and who is a long standing and well regarded figure in the infosec world.

I think you’re gonna need more than Musk Derangement Syndrome fueled conspiracy theories to make your accusations stick here.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#248

Millenials and GenZ may have no idea who Mudge is. I, however, almost lost my first job out of college at a bank because I ran l0phtcrack against our Windows NT 4 server to see if it could crack passwords. I showed my boss, and he pulled me aside into another room and tore my head off for irresponsibly running this tool against a production server. He said I could have been fired if this got out, but he covered my as…

It's Twitter. What possible serious security implications could possibly warrant everyone in Washington getting into a frenzy? All you do is make public comments that have zero value. And if this is indeed serious, where the fuck have we landed?

>> It's Twitter. What possible serious security implications could possibly warrant everyone in Washington getting into a frenzy?

Considering how widely used Twitter is, at this point we can comfortably assume that most politicians and political operatives, even high profile ones, must have very sensitive information in their Twitter DM inboxes.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#250

The bots problem is absolutely nightmare issue for a social network. I can't imagine what I'd do if I discovered my network was fake. The whole point of my network is building professional connections and gaining skills for work. Also seeing various weird topics on twitter like kpop or other random things always made me wonder how much artificial bot boosting was done for those who had money to pay the bot net.

FYI Kpop is "very" popular in some segments of American culture that you just might not cross over with. I experience it frequently in the "Team Fight Tactics" ecosystem which is an E-Sport run by Riot Games (of League of Legends fame) that for some reason contains a very large Asian American population (in relation to their % of the population) and all of them frequently stream Kpop to large audiences. The largest s…

what I find peculiar about the kpop crowd is how they seemingly appear out of nowhere and on-demand on in political topics to drown out/cancel people who don't like them or share their values.

In Korea a blogger was able to see how BTS fans or "bots" were able to game the music ranking. What's interesting to me is how they seemingly correlate with wumaos as well.

I don't have solid evidence but it appears that much of the "stan" (kpop mob on social media) are very much politically aware and push a certain side of the spectrum.

All of this makes for some bizarre dynamics and I'm afraid that youngsters who are caught up in the craze don't know that they are being manipulated by very large crowd that behaves in bot like behavior or are herded into specific political flashpoints without understanding the underlying nuances.

Post reply on HN