Live data from Hacker News

Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

cnn.com

351–360 of 645 posts

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#351

I've been hearing about Mudge for decades . It's actually a bit ... heartbreaking ... to see him looking so corporate, but we all age, don't we? I doubt he was fired for being bad at his job. But I'll bet he was fired for getting in people's faces. That was basically his calling card for years . Why is anyone surprised? I guess Twitter thought they could hire the cachet, without hiring the man. I remember an Apple WW…

> I doubt he was fired for being bad at his job. But I'll bet he was fired for getting in people's faces. As head of X, maintaining good relationships is part of your job. It's actually the biggest part of your job.

The ceo might want you to be a doormat in order to make them look competent. The board, and the users, might disagree.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#352
post #36

Eh, you could take out Twitter and insert many other company names and it'll still hold true. And those companies hold so much more sensitive data about you than Twitter. I know of insurance companies that have help desk employees with domain admin access. And all crippling ransomware attacks take advantage lax permissions. This is rampant. How is this a story?

Did you actually read it? The story isn't some handwaving about companies in general having bad security. It's that Twitter's former head of security is blowing the whistle on "reckless and negligent cybersecurity policies" including deliberately misleading government regulators and its own board about various issues, and concerns about foreign espionage and disinformation. If you don't know how that's a story I don'…

I hear you. All of that is a big deal and should not be taken lighten.

Maybe I'm a bit jaded by what I've seen, but that doesn't seem too far off from normal American business culture. Deflection and manipulation seem to be par for the course. It's why lobbyist exist. Companies want permission to do/not do the things they're not currently allowed/required to do.

The ones that get caught are normally a few bad actors that whistle blow. The companies where it's ingrained in their culture get away with it. Of course...this is all my own experience :)

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#353
post #337

Millenials and GenZ may have no idea who Mudge is. I, however, almost lost my first job out of college at a bank because I ran l0phtcrack against our Windows NT 4 server to see if it could crack passwords. I showed my boss, and he pulled me aside into another room and tore my head off for irresponsibly running this tool against a production server. He said I could have been fired if this got out, but he covered my as…

There's a simpler explanation. He is doing this for profit. I don't buy all the speculation that he approached the SEC out of some professional obligation or simply to spite the Twitter leadership. As a former executive he most likely still holds stock and having the price plunge is not exactly in his interest unless the pay-off from whistleblowing is high enough. Given his high profile, he just burned all bridges ca…

You don’t understand the value of reputation.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#354

God Mode, from my understanding, allows a Twitter employee to have access to an account and allows for a post to be made, under that account's id, without the account being notified or seeing the post show up in their own timeline. Is this an accurate statement? If so, why did nearly 1000 employees (12% of the workforce) have access to this mode before it was restricted, and what's the business case for that?

Now think about the implications with respect to Twitter DMs that show up in criminal investigations. For instance, consider the Twitter DMs exchanged by Donald Trump, Jr and WikiLeaks. In that particular case, the communication was acknowledged by the party in question, but imagine the two possibilities thousands of employees being able to act on the part of users opens up: 1. Twitter employees could fabricate a cri…

> A criminal conspiracy can now use the "Wasn't me, must have been some random Twitter employees" defense.

I could see this being billed as a feature of a privacy-forward chat platform. Messages are slipped into conversations without either party having actually sent them and no way to tell whether they were real or not.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#355
post #211

Earlier quoted context omitted.

Twitter Inc. is indeed in very serious trouble if you have someone like Mudge whistleblowing. Now looking at the chaos, damage control and the PR disaster that is happening at Twitter HQ after this, I have zero confidence in whatever Twitter HQ and the CEO is saying other than admitting their total incompetency towards how they handle information security at the company. All attempts to make this disaster disappear w…

Well, it's not even trending on Twitter, which is not really surprising. There is nothing more evident about the fatal flaws in social media than when news concerning a platform is suppressed on the cited platform. It highlights the failure of democracy they always purport, and it shows that they really shouldn't display a social "trending" page, because it is subject constantly to the politics and profit making of e…

You really think just after paying an FTC fine, staring down SEC actions, and a huge legal fight with Musk…Twitter is going to “suppress” the content to keep this a secret?

Sure.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#357
post #337

Millenials and GenZ may have no idea who Mudge is. I, however, almost lost my first job out of college at a bank because I ran l0phtcrack against our Windows NT 4 server to see if it could crack passwords. I showed my boss, and he pulled me aside into another room and tore my head off for irresponsibly running this tool against a production server. He said I could have been fired if this got out, but he covered my as…

There's a simpler explanation. He is doing this for profit. I don't buy all the speculation that he approached the SEC out of some professional obligation or simply to spite the Twitter leadership. As a former executive he most likely still holds stock and having the price plunge is not exactly in his interest unless the pay-off from whistleblowing is high enough. Given his high profile, he just burned all bridges ca…

I know it's easy being cynical in this day and age, but there are people out there that still operate under a manner of principles. I'd like to think that mudge is one of them.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#358
post #355

Earlier quoted context omitted.

Well, it's not even trending on Twitter, which is not really surprising. There is nothing more evident about the fatal flaws in social media than when news concerning a platform is suppressed on the cited platform. It highlights the failure of democracy they always purport, and it shows that they really shouldn't display a social "trending" page, because it is subject constantly to the politics and profit making of e…

You really think just after paying an FTC fine, staring down SEC actions, and a huge legal fight with Musk…Twitter is going to “suppress” the content to keep this a secret? Sure.

Yea. It works as damage control for credibility, which is under threat not only by the musk suit, but because of the last huge data breach they had.

Just an opinion mind you, but not from a hater or a "dunce".

This is a huge story of significant relevance to Twitter and all users on the platform.

"Suppressing unfavorable news" these days is just as big and profitable an industry as disinformation is.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#359
post #124

Earlier quoted context omitted.

> I imagine this hurts Twitter's defense against Musk from pulling out of the takeover deal Not really because they have consistently said "this is what we do, it's a finger in the air estimate based on sampling, it might be right, it might be wildly wrong, there's no agreed methodology for this". For someone to then go "they don't fully understand the true number of bots! GOTCHA!" is dumb because it's literally just…

So many people don’t understand this. It’s not even clear if Musk does.

Of course he does. He's just grasping at straws to get out of the mess he's created for himself.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#360

Earlier quoted context omitted.

I think it is clear we need more public regulation over these companies, and a lot of the mechanisms need to be embedded in a non-profit / social utility system, given they DIRECTLY impact politics. Anything that democracy is reliant upon should not be subject to private, opaque control. In the case of data harvesting, data is the most valuable resource. You can control what people want using data. No entity should h…

If it impacts politics then it is one more reason not to be regulated by politicians.

Government regulation spans further than just rules engineered by a few politicians, it can be publicly voted upon, and it can dictate minimum standards that are upheld across private business for everyone's safety, which in this case is highly warranted.

It's the best chance we have to stop this horrible trend. Companies have shown repeatedly that they are not trust-worthy nor responsible enough to self regulate.

Post reply on HN