Live data from Hacker News

Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

cnn.com

281–290 of 645 posts

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#281
post #75

"The whistleblower also says Twitter executives don't have the resources to fully understand the true number of bots on the platform, and were not motivated to." I imagine this hurts Twitter's defense against Musk from pulling out of the takeover deal, or, is this whistleblower's account inadmissible?

> I imagine this hurts Twitter's defense against Musk from pulling out of the takeover deal Not really because they have consistently said "this is what we do, it's a finger in the air estimate based on sampling, it might be right, it might be wildly wrong, there's no agreed methodology for this". For someone to then go "they don't fully understand the true number of bots! GOTCHA!" is dumb because it's literally just…

Also, Musk repeatedly said publicly that he wanted to buy the platform specifically to address the issue of bot accounts.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#282
post #212

Earlier quoted context omitted.

The fraud that Mudge alleges in this article, for instance?

We’re missing the connection to Musk here. Care to enlighten us about your theory?

There seems to be the impression that "waiving due diligence" in an acquisition is some license for the seller to defraud the potential buyer without recourse.

If Mudge's allegations are true that Twitter has been defrauding the public in their reporting, failing to abide by the terms of a federal consent decree, and generally turning a blind eye to real problems to prop up their image, then "waived due diligence" or not, Musk has an out from the acquisition, and cause for a significant tort claim.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#283
I wish CNN would just air their interview in full instead of splicing his answers into 5 second soundbites with editorialized voiceover framing. I'm infinitely less interested in CNN's reporter's summation of the issue than that of the veteran security analyst at the heart of the story.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#284
post #144

Earlier quoted context omitted.

> I imagine this hurts Twitter's defense against Musk from pulling out of the takeover deal Not really because they have consistently said "this is what we do, it's a finger in the air estimate based on sampling, it might be right, it might be wildly wrong, there's no agreed methodology for this". For someone to then go "they don't fully understand the true number of bots! GOTCHA!" is dumb because it's literally just…

The really damning part of the whistleblower's statements isn't about the bots, it's about Twitter executives misleading the board of directors and stockholders. That's what could aid Musk at trial.

[deleted]

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#285

Millenials and GenZ may have no idea who Mudge is. I, however, almost lost my first job out of college at a bank because I ran l0phtcrack against our Windows NT 4 server to see if it could crack passwords. I showed my boss, and he pulled me aside into another room and tore my head off for irresponsibly running this tool against a production server. He said I could have been fired if this got out, but he covered my as…

l0phtcrack? "Now that's a name I've not heard in a long time." Wow I thought the name Mudge seemed slightly familiar.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#286

Earlier quoted context omitted.

>> It's Twitter. What possible serious security implications could possibly warrant everyone in Washington getting into a frenzy? Considering how widely used Twitter is, at this point we can comfortably assume that most politicians and political operatives, even high profile ones, must have very sensitive information in their Twitter DM inboxes.

> must have very sensitive information in their Twitter DM inboxes. I doubt that, and if they really do, they should be either trained or exposed pronto. Twitter is an entertainment platform.

You've described the way it ostensibly should be.

My guess is that the reality is almost perfectly in opposition to what you've described. Anything that introduces plausible deniability is going to be of a major benefit.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#287

Millenials and GenZ may have no idea who Mudge is. I, however, almost lost my first job out of college at a bank because I ran l0phtcrack against our Windows NT 4 server to see if it could crack passwords. I showed my boss, and he pulled me aside into another room and tore my head off for irresponsibly running this tool against a production server. He said I could have been fired if this got out, but he covered my as…

It's Twitter. What possible serious security implications could possibly warrant everyone in Washington getting into a frenzy? All you do is make public comments that have zero value. And if this is indeed serious, where the fuck have we landed?

I can think of a few accounts that, with a single tweet, could move markets, inflame tensions, or kick off multiple cycles of misinformation. For many of these large, influential accounts, Twitter is effectively the same as an official press release.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#288
post #75

"The whistleblower also says Twitter executives don't have the resources to fully understand the true number of bots on the platform, and were not motivated to." I imagine this hurts Twitter's defense against Musk from pulling out of the takeover deal, or, is this whistleblower's account inadmissible?

Musk needs twitter to have willfully misrepresented and concealed, not merely to have had estimates that they admitted were nothing more than estimates.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#289

Earlier quoted context omitted.

[flagged]

I don't remember conservatives threatening Twitter to censor "dangerous" views or "misinformation" or telling who to ban.

They push for censorship of pornographic material, which is less dangerous than misinformation about vaccines.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#290
post #177

Earlier quoted context omitted.

He tried to change things and was stopped by people actually in power (CEO, the board). Being head of security means nothing if you aren't allowed to do your job. He was also there for less than 2 years. If you read the article, you'll find that Twitter has had awful security practices since at least 2010.

How do you know that? The only way you'd find out is if there is a lawsuit that exposes said information. Everyone here is assuming because they want to believe Twitter is an evil behemoth. I'm not suggesting they are wrong, but this guy could have done the bare minimum for all we know thinking his status gave him basically a free income to do almost nothing. I would wait until more information comes out before makin…

I'm relaying information from the article based on the 200-page document sent to government agencies. Everything else is speculation based on nothing.
Post reply on HN