Live data from Hacker News

Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

cnn.com

321–330 of 645 posts

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#321
post #262

Earlier quoted context omitted.

Pop legal quiz - define « fraud ». Musk literally tweeted about the « bot problem » on Twitter before the acquisition.

"All multifarious means which human ingenuity can devise, and which are resorted to by one individual to get an advantage over another by false suggestions or suppression of the truth. It includes all surprises, tricks, cunning or dissembling, and any unfair way which another is cheated."

So is Musk guilty of defrauding twitter by using aggressive acquisition tactics as a pretense to get access to internal nonpublic information to use against them?

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#322
I learned a lot about Mudge by reading "Cult of the Dead Cow: How the Original Hacking Supergroup Might Just Save the World."

For anyone wanting to explore 90's security nostalgia, it's worth a read. For anyone wanting to learn where hacktivism comes from, it's worth a read. For anyone wanting to learn about how security consulting has evolved over the years, it's worth a read.

Mudge is a very cool and capable individual. I am slightly surprised that Twitter would ignore someone of his talent and respect, and choose to air their dirty laundry in this manner. It's as if they have no idea who they hired. That, or C-levels think they can outpay $$$ any PR against Twitter to control the narrative. Either way, if Mudge is whistleblowing, there's probably some bad shit going down.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#323
post #114
post #36

Eh, you could take out Twitter and insert many other company names and it'll still hold true. And those companies hold so much more sensitive data about you than Twitter. I know of insurance companies that have help desk employees with domain admin access. And all crippling ransomware attacks take advantage lax permissions. This is rampant. How is this a story?

>This is rampant. How is this a story? Bro. It's not every day that literally Mudge, who has -no doubt- seen his fair share of shit-shows, whistleblows on an employer.

But was he fired by any of those shit shows?

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#324

Earlier quoted context omitted.

How do you know that? The only way you'd find out is if there is a lawsuit that exposes said information. Everyone here is assuming because they want to believe Twitter is an evil behemoth. I'm not suggesting they are wrong, but this guy could have done the bare minimum for all we know thinking his status gave him basically a free income to do almost nothing. I would wait until more information comes out before makin…

We're all speculating here. But if I were a betting man, I do think both Twitter and Mudge's respective track records would place me in Mudge's camp.

I don't know Mudge and neither does 99.9% of the public. His timing here is suspect. If these problems existed for so long, why now?

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#325

Honestly, can you really trust anything about major social media sites any more? Has Twitter ever been in the news for properly making even a thousand people successful from scratch really ever in the product's life? They have pipelines of exploitation for everyone that gets "discovered" into contractual nightmare deals, they require tons of free labor and costly hurdles just to become notable and visible on the plat…

I think it is clear we need more public regulation over these companies, and a lot of the mechanisms need to be embedded in a non-profit / social utility system, given they DIRECTLY impact politics. Anything that democracy is reliant upon should not be subject to private, opaque control. In the case of data harvesting, data is the most valuable resource. You can control what people want using data. No entity should h…

If it impacts politics then it is one more reason not to be regulated by politicians.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#326

Earlier quoted context omitted.

It's Twitter. What possible serious security implications could possibly warrant everyone in Washington getting into a frenzy? All you do is make public comments that have zero value. And if this is indeed serious, where the fuck have we landed?

The last US President used Twitter as his primary way to communicate with the world. That on its own has serious security implications. I agree with you that we have landed in not a great place.

> The last US President used Twitter as his primary way to communicate with the world.

Without it sounding like an endorsement or defense of the guy… I never would have believed without seeing it, just how furious this made the media and other politicians. That you have a guy come in who said forget the system, I’m going talk to the people directly (and say some dumb things now and then).

I still attest that some of the Trump hate is solely because groups of people that control the narrative in the US were excluded from creation and forced to be on narrative-adjustment.

Agreed, this isn’t a good place. One platform should not have this level of influence.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#327

When is mudge going to audit tesla/spacex for "non-compliant kernels", "encryption at rest", etc, etc? Everyone in this shameful industry knows that literally any company in the US would get shredded in such a vigorous audit and the silliest part is that twitter is a fucking shitposting platform that doesn't have my SSN or financial data so equating it to equifax in any way is absolutely laughable.

It does have your phone number though.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#328

I've been hearing about Mudge for decades . It's actually a bit ... heartbreaking ... to see him looking so corporate, but we all age, don't we? I doubt he was fired for being bad at his job. But I'll bet he was fired for getting in people's faces. That was basically his calling card for years . Why is anyone surprised? I guess Twitter thought they could hire the cachet, without hiring the man. I remember an Apple WW…

> I doubt he was fired for being bad at his job. But I'll bet he was fired for getting in people's faces.

As head of X, maintaining good relationships is part of your job. It's actually the biggest part of your job.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#329

Earlier quoted context omitted.

I agree. I grant It’s possible Mudge is A) an old hand and doesn’t know how to run a security program with the tech today B) a strong tech hire who can’t lead a program. But Mudge is still… Mudge, and he’s also proven his ability to collaborate so if he was a bull in a china shop a twitter, that would be surprising. There’s also a broader trend here of well known security leads that originate from that time working a…

> B) a strong tech hire who can’t lead a program. I worked with Mudge (not super close, but enough to see how he worked across teams etc) and can certainly say this is not the case. At least when I saw him Mudge was excellent at the program leadership aspect of his role. At one point he ended up a DARPA PM. You can't go from L0pht to DARPA without getting really good at working with other people and leading projects.…

The subject of security consultants, security departments, and whistleblowing seems to me to be of particular concern.

I mean, if an auditor publicly reports an audit finding that is ignored by the company and his ethics demand its reporting, is he branded a "whistleblower"? I do not think so, instead it is an "auditor finding". Why does that not apply here?

It kind of dovetails with how pathetically organized IT in general is from a professional standpoint. Lawyers, Doctors, ... ?Accountants? and the like have centuries-codified procedures, principles, and the like for ethics. You generally don't get to hire one of those and tell them how to breach ethics (now, there are a lot of corrupt lawyers and a lot of corrupt accountants see: Arthur Andersen).

The exploit industry has the 0day and x days of forewarning process, so there is that, but the fact a security consultant/professional gets accused of whistleblowing when... um, isn't that sort of the point? You hire a security consultant kind of like an auditor. And if auditors find major failings and they aren't addressed, aren't they supposed to report them?

I'm pretty sure the security IT industry does not have even accountant levels of professional conduct and organizations.

As IT subsumes and infiltrates, now to the point that fundamental bill of rights / human rights are dependent on secure and functioning IT systems, it gets... a bit more important. Arguably more important than the ethics around accountants and doctors. Lawyers, because they deal with the law, are probably more important still, but it shows that IT security may be rising in import to that level.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#330

Earlier quoted context omitted.

what I find peculiar about the kpop crowd is how they seemingly appear out of nowhere and on-demand on in political topics to drown out/cancel people who don't like them or share their values. In Korea a blogger was able to see how BTS fans or "bots" were able to game the music ranking. What's interesting to me is how they seemingly correlate with wumaos as well. I don't have solid evidence but it appears that much o…

I think youngsters are very nuanced, actually, but their political tactics are adapted to a full acknowledgement of an algorithm as a player in the political landscape game. Take the teenager who took being dunked on by a republican politician for being fat and used it to make herself viral in raising like 700k for abortion. That's not a kid who is caught up in a craze-- that's a kid who is fully aware of how social…

hmmm I don't know about those particular examples, seem pretty clear cut, and I recognize that they are aware of how to play the game. But what I mean is that certain special interest groups that overlaps with foreign interests seem to be able to continue the youngest and as you put it, the most "apt" userbase to proliferate messaging and goals of that collective.

For example, tiktok was recently outed to run keyloggers, and those genz who are "stanning" are also likely sending back all these crucial data points. This is not a conspiracy theory but the very reality that we are dealing with that those who do not share our values and way of life are able to not only cast a wide surveillance of its most vulnerable demographic but manipulate reality for them in all sorts of ways to identify "enemies of the movement" and overwhelm them.

What disturbs me most is that there is this disjointed, water-and-oil dynamism between the two political spectrums engaged in this toxic social media warfare aimed at sowing discord and turning its masses to feel ill, with society, stability and question everything we have.

It is this unwitting participation by the genz of the grander ulterior motives and agendas highlighted by special interest groups that have overlapping values with foreign states that know what strings to pull and the silence in response that worries me.

America's hostile nations know they cannot beat it militarily and they have developed very imaginative and creative asymmetric solutions to subvert and sabotage it from within, and the current state of this side vs that side makes it impossible to formulate a collective bipartisan response to steer the ship in the right direction.

We are not taking this issue of weaponized social media seriously and we see this first hand by how little enforcement/recourse there is for data privacy breach. We know that privacy of the individual is one of THE key pillars of open society and unfortunately the waters are murky and there is no guidance anymore.

In a few decades we will see what the result of this trojan horse experiment is but the current trajectory is not looking good. Gen Z suffer from the highest rate of mental health issues, have access to unprecedented amount of information and foreign subversion. When I realized your own flag is becoming a symbol of hatred, we reached a potentially irreversible stage of complexity and with that only increases risks.

Post reply on HN