Live data from Hacker News

Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

cnn.com

391–400 of 645 posts

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#391

Earlier quoted context omitted.

I wonder if they're running Ubuntu on 32-bit hardware

or RHEL 6

Hahahaha...

Wait until you hear about the large cloud provider running RHEL5... (I worked at said provider).

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#392

Millenials and GenZ may have no idea who Mudge is. I, however, almost lost my first job out of college at a bank because I ran l0phtcrack against our Windows NT 4 server to see if it could crack passwords. I showed my boss, and he pulled me aside into another room and tore my head off for irresponsibly running this tool against a production server. He said I could have been fired if this got out, but he covered my as…

In any case your own chief of security coming out and saying your security is crap would be devastating for any company. But when it's a person with credentials list like Mudge's - one can be quite sure he's not just doing it because some disagreement about salary and vacation days, and it would be impossible to dismiss this as "disgruntled employee issue". Twitter would probably try anyway, but it won't work.

Twitter is going to be in a lot of hot water now, and I can't imagine Musk isn't going to milk this to the last drop.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#393

Earlier quoted context omitted.

I agree. I grant It’s possible Mudge is A) an old hand and doesn’t know how to run a security program with the tech today B) a strong tech hire who can’t lead a program. But Mudge is still… Mudge, and he’s also proven his ability to collaborate so if he was a bull in a china shop a twitter, that would be surprising. There’s also a broader trend here of well known security leads that originate from that time working a…

> B) a strong tech hire who can’t lead a program. I worked with Mudge (not super close, but enough to see how he worked across teams etc) and can certainly say this is not the case. At least when I saw him Mudge was excellent at the program leadership aspect of his role. At one point he ended up a DARPA PM. You can't go from L0pht to DARPA without getting really good at working with other people and leading projects.…

I agree with everything you said, but I'd like to play devil's advocate here. Mudge has worked:

  * L0pht / @stake: security research, red teaming, and source code auditing, IIRC.
  * BBN: research.
  * NFR: technical advisory board.
  * DARPA: Managing a program that provided grants for new security products and tools.
  * Google ATAP: Google's "invention studio".
  * CyberUL: Testing of security products.
None of these jobs really suggest a background in building a security program. I've worked with some large companies in a similar space to Twitter building their security programs and you can spend the first 6-12 months just trying to justify the new budget. Often that money has to come from another team or teams and he would have to justify that. He was apparently only there roughly a year.

Again, I don't doubt Mudge's bonafides. I don't doubt his security knowledge. But this job was nothing like any he's had in the past.

I also don't doubt his claims. Everything he's stated is almost certainly true. It does take more than a year to fix most of these problems and I wonder if he just got frustrated with the political battles that occur in these situations.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#394

I've been hearing about Mudge for decades . It's actually a bit ... heartbreaking ... to see him looking so corporate, but we all age, don't we? I doubt he was fired for being bad at his job. But I'll bet he was fired for getting in people's faces. That was basically his calling card for years . Why is anyone surprised? I guess Twitter thought they could hire the cachet, without hiring the man. I remember an Apple WW…

> I doubt he was fired for being bad at his job. But I'll bet he was fired for getting in people's faces. As head of X, maintaining good relationships is part of your job. It's actually the biggest part of your job.

There's a common anti-pattern that goes like this:

1. A higher-ranked person (e.g. Agrawal) is screwing up in some way (e.g. not addressing security issues)

2. A lower-ranked person (e.g. Mudge) tries to get the problem fixed (e.g. addressing the security issues)

3. The higher-ranked person refuses, and it turns into a conflict

4. The lower-ranked person gets blamed for "not maintaining good relationships" or "being hard to work with" or something like that.

See this article: https://lethain.com/hard-to-work-with/

To be clear, maintaining good relationships is very important. Good relationships are the lubricant that keeps the machine running smoothly; if someone has poor social skills or doesn't make an effort to maintain good relationships, they'll cause unnecessary friction, and they'll end up wasting time and effort on a conflict when they could have solved by problem by maintaining a better relationship.

But, not every conflict is an unnecessary conflict that could have been solved by maintaining a better relationship! Sometimes people refuse to fix problems, and the only options are to apply pressure to them or let the problem go unfixed. Sometimes "lack of lubricant" isn't the reason the machine is broken.

(One way to see this is to note that Agrawal did not maintain a good relationship with Mudge. If maintaining good relationships is part of the job, did Agrawal fail at his job? Or do you think only the lower-ranked person is responsible for maintaining good relationships?)

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#395

Earlier quoted context omitted.

I read the full whistle-blower complaint, and the whole story from his perspective (and the crazy statement from Agrawal) looks like it's not B. Instead, it looks like it was a culture clash with his manager. He seems to have tried to escalate things to people above Agrawal nearly constantly. He was hired by Jack Dorsey, and felt accountable to him and to the board, but he reported to Agrawal, who believed that Mudge…

> He was hired by Jack Dorsey, and felt accountable to him and to the board, but he reported to Agrawal, who believed that Mudge had a responsibility to follow the chain of command very rigidly. With $10mm cash bonuses on the table it’s extremely obvious why Agrawal would insist on being MITM

When you think your job is to tell your boss's boss (and their promotion committee) why your boss is doing a bad job, you're not in for a happy time.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#396
post #362
post #353

Earlier quoted context omitted.

You don’t understand the value of reputation.

I don't think you understand what it means to burn all bridges. He is literally unhireable right now in any corporate context. You are naive if you believe he is doing this out of some hacker ethos.

The idea that he is "unhireable" in the security space because of this is rather amusing.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#397

Earlier quoted context omitted.

It's Twitter. What possible serious security implications could possibly warrant everyone in Washington getting into a frenzy? All you do is make public comments that have zero value. And if this is indeed serious, where the fuck have we landed?

>> It's Twitter. What possible serious security implications could possibly warrant everyone in Washington getting into a frenzy? Considering how widely used Twitter is, at this point we can comfortably assume that most politicians and political operatives, even high profile ones, must have very sensitive information in their Twitter DM inboxes.

Whew, I would assume no one is using Twitter DMs. If they are, these should be 100% personal and unimportant. If not, those people should be investigated, not Twitter.

I'm not defending Twitter, I don't engage with it at all.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#398
post #168

Just to clarify for those who don't catch it in the article: Mudge's whistleblower complaint predates the Musk/Twitter feud entirely.

Where do you see that info in the Verge article? All I can see is "he filed last month" (which would be July 2022) - the month Musk "officially" backed out and at least a month after he started doing the "I don't want Twitter any more" dance.

[deleted]

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#399
post #168

Just to clarify for those who don't catch it in the article: Mudge's whistleblower complaint predates the Musk/Twitter feud entirely.

Where do you see that info in the Verge article? All I can see is "he filed last month" (which would be July 2022) - the month Musk "officially" backed out and at least a month after he started doing the "I don't want Twitter any more" dance.

> John Tye, founder of Whistleblower Aid and Zatko's lawyer, told CNN that Zatko has not been in contact with Musk, and said Zatko began the whistleblower process before there was any indication of Musk's involvement with Twitter.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#400

I've been hearing about Mudge for decades . It's actually a bit ... heartbreaking ... to see him looking so corporate, but we all age, don't we? I doubt he was fired for being bad at his job. But I'll bet he was fired for getting in people's faces. That was basically his calling card for years . Why is anyone surprised? I guess Twitter thought they could hire the cachet, without hiring the man. I remember an Apple WW…

> It's actually a bit ... heartbreaking ... to see him looking so corporate, but we all age, don't we?

He's stated that you can work to change the system from the outside or from within and he chose the latter.

Post reply on HN