Live data from Hacker News

Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

cnn.com

401–410 of 645 posts

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#401

Earlier quoted context omitted.

Because a random bakery shop is totally like a pseudo-monopolistic social media giant that can censor millions arbitarily and at will.

it's not a monopoly because there are alternatives, and it only has a 10% market share in the US ( https://gs.statcounter.com/social-media-stats/all/united-sta... ). The bakery also sets precedent as it did go to the supreme court, and it was used as a rallying cry by politicians on the right.

So, in simpler words, they are indeed a pseudo-monopolistic (pseudo means apparent, something very close to but not quite there) social media giant that can indeed censor millions (10% of USA's population is 30 millions) arbitarily and at will ? Ok :)

And whether a bakery serves your gay wedding or not is perhaps the most petty and inconsequential thing to be upset about. There are thousands upon thousands of bakeries in a large city. You can learn how to bake a cake in a weekend and home-bake your wedding cake yourself, or any one of your wedding guests can do this as a wedding gift. You can go to a no-gays-allowed bakery but simply not tell them you're gay, and take a finished cake from them then write your own name and that of the guy you will marry on it yourself. You can not get cake at all and instead get any of the thousand other types of wedding sweets and food.

It's almost like the whole thing is a hilarious non-issue that some people just invented to cry and act like victims about.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#402
post #301

Earlier quoted context omitted.

A well-timed set of tweets from compromised government and private-sector accounts, coordinated with real stock market activity planned by the attacker such that investors cannot ignore the rumors, could cause a geopolitically significant market panic. This already happened in 2013, and that was with just a single account being compromised: https://business.time.com/2013/04/24/how-does-one-fake-tweet...

OK, Twitter needs regulated then. Hardly a private going concern if you are right.

This won't fix the fragility of our economy. It would start a weird exit model for social platforms, though. Get big enough that the US buys you out.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#403

Earlier quoted context omitted.

it's not a monopoly because there are alternatives, and it only has a 10% market share in the US ( https://gs.statcounter.com/social-media-stats/all/united-sta... ). The bakery also sets precedent as it did go to the supreme court, and it was used as a rallying cry by politicians on the right.

So, in simpler words, they are indeed a pseudo-monopolistic (pseudo means apparent, something very close to but not quite there) social media giant that can indeed censor millions (10% of USA's population is 30 millions) arbitarily and at will ? Ok :) And whether a bakery serves your gay wedding or not is perhaps the most petty and inconsequential thing to be upset about. There are thousands upon thousands of bakerie…

Monopoly on what?

There are not thousands of bakeries in any city. Many towns might have none, or one. In that regard, the bakery will have an actual monopoly on baked goods to people living there.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#404
post #7

How long before Musk weaponises this in his lawsuit against Twitter?

How long before people start conflating this story with Musk in an attempt to discredit both, you mean?

The modern equivalent of Godwin's law is mentioning either Tr*mp or El*n in any circumstance possible.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#405
post #384

Millenials and GenZ may have no idea who Mudge is. I, however, almost lost my first job out of college at a bank because I ran l0phtcrack against our Windows NT 4 server to see if it could crack passwords. I showed my boss, and he pulled me aside into another room and tore my head off for irresponsibly running this tool against a production server. He said I could have been fired if this got out, but he covered my as…

I met Mudge once in my career early on (I was at VA Linux systems circa 1999ish) and I found him intense, an apex intellect, but absolutely affable and self-aware. He never struck me then, or in any interview or write up since, that he's impulsive, or prone to taking actions like what he's done to Twitter, in a cavalier way. He saw something bad and thinks something should be done to address it. He likely made that d…

Yeah - comparing mudge's history with the email the Twitter CEO sent to internal employees and the situation seems crazy? Always hard to know from the outside, but this paired with Jack leaving seemingly frustrated with the board looks really bad.

I know people have thought Twitter was mismanaged for a while, but seems like it's a lot worse than I thought it was (and the CEO seems more vindictively bad than I would have guessed).

Plus the total lack of principles around speech and just doing whatever Russia, India, or KSA wants? Including hiring foreign agents? Also covering up bad security issues in reporting? It'll be interesting to see what happens from here as more comes out.

The internal Twitter email: https://twitter.com/austen/status/1562150058727919616?s=21&t...

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#406

Millenials and GenZ may have no idea who Mudge is. I, however, almost lost my first job out of college at a bank because I ran l0phtcrack against our Windows NT 4 server to see if it could crack passwords. I showed my boss, and he pulled me aside into another room and tore my head off for irresponsibly running this tool against a production server. He said I could have been fired if this got out, but he covered my as…

It's Twitter. What possible serious security implications could possibly warrant everyone in Washington getting into a frenzy? All you do is make public comments that have zero value. And if this is indeed serious, where the fuck have we landed?

Considering a journalist was murdered and dismembered due to their lax security not to long ago, I would consider it definitely worth looking into.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#407
post #110

Earlier quoted context omitted.

Building a successful security organization is very easy, it just starts higher up the food chain than whatever experts you hire to do it. Security is a cultural practice, it's not a feature, it's not a bolt-on. To the extent that your security organization influences and receives buy-in from your corporate culture, becoming a part of your organization's identity, it will be successful.

I think this is key. If you don't have a good security culture, where people understand and have ingrained proper security practices, you're toast, no matter who else you hire.

Google has good security practices, can implement those in any big corp as they are very straightforward. Mudge previously worked at Google so I'd assume he was hired to help Twitter security get better by implementing some practices from Google. But maybe he was just hired to look like Twitter cared and they didn't really want to change anything.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#408

Millenials and GenZ may have no idea who Mudge is. I, however, almost lost my first job out of college at a bank because I ran l0phtcrack against our Windows NT 4 server to see if it could crack passwords. I showed my boss, and he pulled me aside into another room and tore my head off for irresponsibly running this tool against a production server. He said I could have been fired if this got out, but he covered my as…

No post body was provided.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#409

Earlier quoted context omitted.

I agree. I grant It’s possible Mudge is A) an old hand and doesn’t know how to run a security program with the tech today B) a strong tech hire who can’t lead a program. But Mudge is still… Mudge, and he’s also proven his ability to collaborate so if he was a bull in a china shop a twitter, that would be surprising. There’s also a broader trend here of well known security leads that originate from that time working a…

I read the full whistle-blower complaint, and the whole story from his perspective (and the crazy statement from Agrawal) looks like it's not B. Instead, it looks like it was a culture clash with his manager. He seems to have tried to escalate things to people above Agrawal nearly constantly. He was hired by Jack Dorsey, and felt accountable to him and to the board, but he reported to Agrawal, who believed that Mudge…

I wouldn't paint with too broad of a brush in this instance, however. Yes, mudge is the ur-hacker, but also: he worked at BBN and DARPA (where he was extremely effective) and elsewhere. He probably has the most experience of any technical/hacker on the planet of working with executives in large organizations.

Agrawal's memo, in contrast, reeks of insecurity. The combination of how he's treated mudge and Rishi Sunak and the potential consequences of this complaint (particularly if FTC investigates and finds Twitter has not been following the consent decree) boxes him into a corner -- he won't be able to recruit the talent to solve these security problems and will be seen as an impediment to compliance/mitigation. I could easily see the FTC et al insisting on his resignation as part of a settlement. It's an own-goal.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#410

Earlier quoted context omitted.

This seems like a huge win for the defense in a case using DMs or Tweets as evidence. It would be quite easy to argue that a highly-politicized org like Twitter _might_ alter tweets or DMs to implicate someone in the opposing party. That’s reasonable doubt that at least some jurors would buy.

Usually these sorts of systems have very detailed logs and those logs are kept for a long time for things like lawsuits. In the hypothetical scenario you're describing the other party would subpoena Twitter and they would corroborate whether or not someone logged as that user or not.

From what the article mentions it sounds like Twitter could very well be lacking those detailed logs and checks...
Post reply on HN