Live data from Hacker News

Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

cnn.com

251–260 of 645 posts

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#251

Earlier quoted context omitted.

Apperantly he started the whistleblowing process before any Musk involvement with Twitter. https://twitter.com/KimZetter/status/1562061556745089025

> Apperantly he started the whistleblowing process before any Musk involvement with twitter. According to his lawyer as reported by someone on Twitter. IIRC, lawyers make statements that guilty clients are innocent all the time. If he was working with Musk help him wiggle out of the Twitter deal, it would fatally undermine the goal for to come out publicly about the relationship. I'm skeptical unless they can provide…

So instead of taking a statement from the lawyer you think it makes more sense to wildly speculate and make things up? The burden of proof falls on the other side now to prove the whistle blowing started after Musk.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#252

The bots problem is absolutely nightmare issue for a social network. I can't imagine what I'd do if I discovered my network was fake. The whole point of my network is building professional connections and gaining skills for work. Also seeing various weird topics on twitter like kpop or other random things always made me wonder how much artificial bot boosting was done for those who had money to pay the bot net.

> The whole point of my network is building professional connections and gaining skills for work

And you're afraid of getting interesting insights from and interacting with bots ... ?

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#254
post #174

Earlier quoted context omitted.

His complaints don't hold merit because he entered into a binding agreement to buy Twitter after waiving due diligence rights. Zatko was fired in January. Musk had and waived his chance to discover these things. It's too late now.

>waiving due diligence rights Pop legal quiz - does "waving due diligence rights" during an acquisition remove the other party's liability for fraud they've committed against the prospective buyer?

Pop legal quiz - define « fraud ».

Musk literally tweeted about the « bot problem » on Twitter before the acquisition.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#255
post #212

Earlier quoted context omitted.

> the other party's liability for fraud What fraud though?

The fraud that Mudge alleges in this article, for instance?

We’re missing the connection to Musk here. Care to enlighten us about your theory?

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#256
post #158

God Mode, from my understanding, allows a Twitter employee to have access to an account and allows for a post to be made, under that account's id, without the account being notified or seeing the post show up in their own timeline. Is this an accurate statement? If so, why did nearly 1000 employees (12% of the workforce) have access to this mode before it was restricted, and what's the business case for that?

What scenario would justify that feature existing though? Why would they need to make posts from arbitrary accounts?

It's common in lots of software - a form of a "su" command that lets you assume all aspects of a particular user.

Usually developed for testing purposes (easiest way to reproduce a problem, after all) and prevents password-sharing. But it can obviously be used for evil, and so it should be heavily logged and flagged.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#257
post #177

Earlier quoted context omitted.

He tried to change things and was stopped by people actually in power (CEO, the board). Being head of security means nothing if you aren't allowed to do your job. He was also there for less than 2 years. If you read the article, you'll find that Twitter has had awful security practices since at least 2010.

How do you know that? The only way you'd find out is if there is a lawsuit that exposes said information. Everyone here is assuming because they want to believe Twitter is an evil behemoth. I'm not suggesting they are wrong, but this guy could have done the bare minimum for all we know thinking his status gave him basically a free income to do almost nothing. I would wait until more information comes out before makin…

We're all speculating here.

But if I were a betting man, I do think both Twitter and Mudge's respective track records would place me in Mudge's camp.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#258

Earlier quoted context omitted.

If the executives did not make a meaningful effort to count them, that is fairly damning, given how much the stock price swings on the count. Nobody said it was easy, but it's certainly harder if you don't try.

> If the executives did not make a meaningful effort to count them They've been filing their methodology for bot counting with the SEC since 2013. If they're not making a "meaningful effort" and it materially affected the stock price in some way, either the SEC or a shareholder would have gone "HOLD ON SHENANIGANS O'CLOCK", surely? It can't be that the entire world was A-OK with Twitter's bot counting until June 2022…

> They've been filing their methodology for bot counting with the SEC since 2013.

No, they haven’t. They describe at a very high level the amount of sampling they do (100 accounts a day? Really, that’s it?), but don’t discuss the methodology used, such as what they use as signals and indicators of botness. That’s not “filing their methodology“, it’s covering their arses.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#259
post #7

How long before Musk weaponises this in his lawsuit against Twitter?

https://twitter.com/deitaone/status/1562069657582018560

So about a few hours.

*Walter Bloomberg @DeItaone ELON MUSK’S LEGAL TEAM HAS SUBPOENAED PEITER “MUDGE” ZATKO, TWITTER’S FORMER HEAD OF SECURITY - CNN 8:30 AM · Aug 23, 2022·TweetDeck

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#260

>one or more current employees may be working for a foreign intelligence service. I don't doubt this, but the source is someone with fairly deep ties to the US intelligence services. Why should he be allowed a job and not people with ties to foreign agencies?

I don't believe that what Mudge is saying there is all that well quoted or explained. The argument I've heard him make, in other settings, is that companies that are interesting enough will get job applicants that are really moles for intelligence agencies. This is very difficult to stop, and once your company has enough employees, downright impossible. His recommendation however is not to make it impossible for peop…

> Someone like Twitter, Google or Facebook should have 'some of our employees are malicious and sophisticated' as part of their threat model.

I would estimate there is a 100% chance that every one of those companies listed, has multiple employees who work for or are sources for US domestic and foreign intelligence services.

It should be expected and part of their internal systems that people only have access to the shared drives they are meant to.

Post reply on HN