Live data from Hacker News

Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

cnn.com

361–370 of 645 posts

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#361

I think it's a pretty open secret that Twitter is a fairly broken company. It's no surprise that their security practices are bad, because all their practices are bad. It's also very difficult to view this in isolation when you have the timeline of (1): Fired in January, nothing happens. (2) Musk makes offer for twitter then reneges. (3) Months before the lawsuit gets decided re-emerges with accusations. What happene…

If you've worked for any major F500 Enterprise, this is all par for the course. Currently on a contract with a healthcare giant, while security is pretty tight because HIPPA, generally everything else is chaotic. I'm going to speculate that Twitter is probably worse than the mean, but at pretty much every large company that operates massive pieces of software, youre gonna get a ton of chaos by default.

[deleted]

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#362
post #353
post #337

Earlier quoted context omitted.

There's a simpler explanation. He is doing this for profit. I don't buy all the speculation that he approached the SEC out of some professional obligation or simply to spite the Twitter leadership. As a former executive he most likely still holds stock and having the price plunge is not exactly in his interest unless the pay-off from whistleblowing is high enough. Given his high profile, he just burned all bridges ca…

You don’t understand the value of reputation.

I don't think you understand what it means to burn all bridges. He is literally unhireable right now in any corporate context. You are naive if you believe he is doing this out of some hacker ethos.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#363

Earlier quoted context omitted.

> If the executives did not make a meaningful effort to count them They've been filing their methodology for bot counting with the SEC since 2013. If they're not making a "meaningful effort" and it materially affected the stock price in some way, either the SEC or a shareholder would have gone "HOLD ON SHENANIGANS O'CLOCK", surely? It can't be that the entire world was A-OK with Twitter's bot counting until June 2022…

The "methodology" is that people look at 100 accounts a day and determine whether they are bots. They have never disclosed any of the signals that go into this determination. You have a lot of faith in the immediately efficient market here.

The point is that they have not claimed anything regarding this in their filings that isn't true, not whether or not you think they've been clear and detailed enough to answer the question properly.

And to give Musk an out, which is what this tangent is about, not only do they need to have actually lied, the lies need to have had a VERY substantial effect on the price of the company.

The bot thing simply does not help Musk get out of the deal he's made. That is not the same thing as "Twitter are great at dealing with bots and have been very transparent about how they do it", but that's not the bar that has to be cleared here.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#364

Earlier quoted context omitted.

I agree. I grant It’s possible Mudge is A) an old hand and doesn’t know how to run a security program with the tech today B) a strong tech hire who can’t lead a program. But Mudge is still… Mudge, and he’s also proven his ability to collaborate so if he was a bull in a china shop a twitter, that would be surprising. There’s also a broader trend here of well known security leads that originate from that time working a…

I read the full whistle-blower complaint, and the whole story from his perspective (and the crazy statement from Agrawal) looks like it's not B. Instead, it looks like it was a culture clash with his manager. He seems to have tried to escalate things to people above Agrawal nearly constantly. He was hired by Jack Dorsey, and felt accountable to him and to the board, but he reported to Agrawal, who believed that Mudge…

> He was hired by Jack Dorsey, and felt accountable to him and to the board, but he reported to Agrawal, who believed that Mudge had a responsibility to follow the chain of command very rigidly.

With $10mm cash bonuses on the table it’s extremely obvious why Agrawal would insist on being MITM

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#365

Earlier quoted context omitted.

You’re ascribing the worst possible motives to someone based on your hatred of Elon Musk. Someone who has no known relationship with Musk, who has claimed publicly they started this process before Musk was involved with twitter, and who is a long standing and well regarded figure in the infosec world. I think you’re gonna need more than Musk Derangement Syndrome fueled conspiracy theories to make your accusations sti…

> You’re ascribing the worst possible motives to someone based on your hatred of Elon Musk. I'm not going to claim some big conspiracy here, but I do find this beyond coincidence. I don't think that this is coming out now because Mudge is acting on behalf of Elon. I think Elon's Twitter bid (and ensuing drama and upcoming lawsuit) and this revelation are part of the same agenda. For better or worse, it looks like inf…

>it looks like influential powers that be are going to take down/over Twitter

Let them, Twitter can't get any worse.

At the very least, lets get to the bottom of the bot problem and expose these companies who rely on bot activity to drive their MAU numbers and as a result, their inflated valuations.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#366

Honestly, can you really trust anything about major social media sites any more? Has Twitter ever been in the news for properly making even a thousand people successful from scratch really ever in the product's life? They have pipelines of exploitation for everyone that gets "discovered" into contractual nightmare deals, they require tons of free labor and costly hurdles just to become notable and visible on the plat…

> only pleasing it's sponsors, investors, and execs Yea, that's the game. They are a for profit business. This situation will happen every time. Profits over people, line must go up!

Yes and part of the profits are generated by their fake MAU numbers (bots). They are fraudulent above all else.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#367

I've been hearing about Mudge for decades . It's actually a bit ... heartbreaking ... to see him looking so corporate, but we all age, don't we? I doubt he was fired for being bad at his job. But I'll bet he was fired for getting in people's faces. That was basically his calling card for years . Why is anyone surprised? I guess Twitter thought they could hire the cachet, without hiring the man. I remember an Apple WW…

> I doubt he was fired for being bad at his job. But I'll bet he was fired for getting in people's faces. As head of X, maintaining good relationships is part of your job. It's actually the biggest part of your job.

When you make someone head of security, there are a handful of ways they can go about it:

* They can be utterly ineffectual, ideally while looking good in the press and maintaining good relations across the company. The latter is easy when you never have to ask anyone to do anything.

* They can be effective, which requires the ability to draw on and coordinate resources far beyond security. Their ability to do this is reliant entirely on the support and backing they get from the top. This will make people angry, because it's inevitably going to lead to reshuffling priorities and making choices people dislike. It's possible to maintain good relationships while doing this, if you have strong backing and you at need to convincingly be empathetic about people's feeling while they do what you security and privacy demand.

* They can be ineffectual while trying work across the org and negotiate without backing. Eventually this just pisses people off because you're constantly asking for things and they just want you to go away.

As a security leader, your ability to maintain good relationships while being effective is contingent on how much backing you get. If you're not backed sufficiently, you cannot do both, and then you have to make awkward choices.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#368
post #36

Eh, you could take out Twitter and insert many other company names and it'll still hold true. And those companies hold so much more sensitive data about you than Twitter. I know of insurance companies that have help desk employees with domain admin access. And all crippling ransomware attacks take advantage lax permissions. This is rampant. How is this a story?

It is certainly rampant. Amazon, for example: https://www.wired.com/story/amazon-failed-to-protect-your-da...

That said, all these stories are important to the public.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#369

Earlier quoted context omitted.

If the executives did not make a meaningful effort to count them, that is fairly damning, given how much the stock price swings on the count. Nobody said it was easy, but it's certainly harder if you don't try.

> If the executives did not make a meaningful effort to count them They've been filing their methodology for bot counting with the SEC since 2013. If they're not making a "meaningful effort" and it materially affected the stock price in some way, either the SEC or a shareholder would have gone "HOLD ON SHENANIGANS O'CLOCK", surely? It can't be that the entire world was A-OK with Twitter's bot counting until June 2022…

How is it any harder than giving users a captcha?

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#370

Earlier quoted context omitted.

I don't remember conservatives threatening Twitter to censor "dangerous" views or "misinformation" or telling who to ban.

They push for censorship of pornographic material, which is less dangerous than misinformation about vaccines.

What's the problem with making public pages SFW?
Post reply on HN