Live data from Hacker News

Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

cnn.com

421–430 of 645 posts

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#421
post #314

Is it just me, or does some of this feel less whistleblower-y and more petty? For example: > The company also lacks sufficient redundancies and procedures to restart or recover from data center crashes, Zatko's disclosure says, meaning that even minor outages of several data centers at the same time could knock the entire Twitter service offline, perhaps for good. That said, this is Mudge. I have a lot of respect for…

> The company also lacks sufficient redundancies and procedures to restart or recover from data center crashes, Zatko's disclosure says, meaning that even minor outages of several data centers at the same time could knock the entire Twitter service offline, perhaps for good. I mean if it were true that seems pretty negligent. If that were the entire extent of the whistleblower complaint (not sure if complaint is the…

I dunno, pointing out that something has a poor architecture and pointing out that something has severe, known, and ignored security issues feels different.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#422

Earlier quoted context omitted.

It's Twitter. What possible serious security implications could possibly warrant everyone in Washington getting into a frenzy? All you do is make public comments that have zero value. And if this is indeed serious, where the fuck have we landed?

The last US President used Twitter as his primary way to communicate with the world. That on its own has serious security implications. I agree with you that we have landed in not a great place.

I hope we get to a place where we all agree that a sitting U.S. President should not "tweet." The White House maintains a Press Secretary for a reason. Granted, the current person holding the job is no C.J. Craig.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#423

Millenials and GenZ may have no idea who Mudge is. I, however, almost lost my first job out of college at a bank because I ran l0phtcrack against our Windows NT 4 server to see if it could crack passwords. I showed my boss, and he pulled me aside into another room and tore my head off for irresponsibly running this tool against a production server. He said I could have been fired if this got out, but he covered my as…

I don't because I'm not seeing an organization that will hold them accountable. - This Congress is ill-equipped to understand tech, much less hold it accountable. As long as the people are happy, Congress is happy. - Lord knows the people are ill-equipped to get how bad this is. They already watched this company allow a rogue employee to shut off the account of the President of the United States (before they chose to…

> This Congress is ill-equipped to understand tech, ...

"This" congress? There are institutional level problems, here.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#424

Earlier quoted context omitted.

Bigger example: Donald Trump called Net Neutrality "Obamacare for the Internet", back when the bug-bear was Comcast rather than FAANG.

Ending the enforcement of Net Neutrality was not about censoring content or subjects.

The specific worry about Net Neutrality was that ISPs would use their monopoly power to censor specific sources and/or self-preference their own businesses. It's something that should have been expanded to large online platforms rather than being disposed of entirely.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#425
post #393

Earlier quoted context omitted.

> B) a strong tech hire who can’t lead a program. I worked with Mudge (not super close, but enough to see how he worked across teams etc) and can certainly say this is not the case. At least when I saw him Mudge was excellent at the program leadership aspect of his role. At one point he ended up a DARPA PM. You can't go from L0pht to DARPA without getting really good at working with other people and leading projects.…

I agree with everything you said, but I'd like to play devil's advocate here. Mudge has worked: * L0pht / @stake: security research, red teaming, and source code auditing, IIRC. * BBN: research. * NFR: technical advisory board. * DARPA: Managing a program that provided grants for new security products and tools. * Google ATAP: Google's "invention studio". * CyberUL: Testing of security products. None of these jobs re…

You left out that he built the security program at Stripe.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#426

Millenials and GenZ may have no idea who Mudge is. I, however, almost lost my first job out of college at a bank because I ran l0phtcrack against our Windows NT 4 server to see if it could crack passwords. I showed my boss, and he pulled me aside into another room and tore my head off for irresponsibly running this tool against a production server. He said I could have been fired if this got out, but he covered my as…

Actions speak louder than words. For him to file this complaint now, after Musk pulled out of his Twitter purchase, makes any truthful statements pretty low value to Musk’s case. Does Twitter need better security? Yeah. Will Twitter get embarrassed? Yeah?

Will this testimony show Musk completely miffed his due diligence while building up a huge loan package that would have sent most of Twitter’s revenue to debt service? The timeline is what matters.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#427
post #412

Earlier quoted context omitted.

Yeah, I think we're in lockstep here. I'm no fan of Musk (he's truly worked very hard to be the most provacatively pustulent punkass of tech) but that doesn't mean that Twitter leadership is any better. Just not as well PR'd. Dorsey himself was mostly an imbecile who drank too much of his own Kool Aid. Twitter has for years been the standard bearer for the most opaque, and incoherent content management; from user fee…

I’m a huge musk fan, but I still think his trying to get out of the Twitter deal is lame buyer's remorse and his arguments are weak. I see it as mostly unrelated to this mudge issue.

Musk posted a meme explaining why he pulled out.

https://twitter.com/elonmusk/status/1546344529460174849

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#428
post #148

Twitter CEO's response to employees which denies none of the claims made by CNN & WaPo* https://twitter.com/donie/status/1562069281545900033 * https://www.washingtonpost.com/technology/interactive/2022/t... edit: the PDFs from * https://www.washingtonpost.com/technology/interactive/2022/t... https://www.washingtonpost.com/technology/interactive/2022/t... https://www.washingtonpost.com/technology/interactive/2022/t...…

Agrawal's internal statement about Zatko is insane. My goodness.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#429
post #186

Earlier quoted context omitted.

Musk's account was among those that were hacked in the 2020 high profile hack. He made the offer in 2022, he therefore can't claim to not have known that twitter's security isn't 100% and really can't use this in court, I guess

The contract Musk signed was very very one sided, from everything I've been reading there's very little Musk can claim that would let him scuttle the deal.

the contract does not allow twitter to commit fraud. Which they have.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#430

Zatko reported directly to the CEO, as a senior leader you need to take responsibility for your own work. Does anyone believe that in an organization as large as Twitter he didn't have enough resources to solve this? I imagine his budget ran in the tens of millions.

I can very much believe it. A CEO can, if they play their cards right, block the CTO from accomplishing what the CTO set out to do. Budget is not the problem. Approvals and alignment with board members are the problems. And if the CTO still decides to push forward, the CEO can still fire the CTO for underperformance which is exactly what you see in this story.

They could. But if someone has a cost effective plan to improve security, that's feasible to execute, why would they block it? It doesn't make sense, security issues are important and can cause damage to the business. Their CEO is an engineer, he knows this.

It seems more probable that this security leader failed to get buy in from the engineering teams, or that there was some technical debt that he couldn't get past.

Post reply on HN