Live data from Hacker News

Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

cnn.com

441–450 of 645 posts

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#441
post #427

Earlier quoted context omitted.

I’m a huge musk fan, but I still think his trying to get out of the Twitter deal is lame buyer's remorse and his arguments are weak. I see it as mostly unrelated to this mudge issue.

Musk posted a meme explaining why he pulled out. https://twitter.com/elonmusk/status/1546344529460174849

The why doesn't matter, he explicitly waived the ability to back out of the deal for any of the reasons he's cited.

Twitter is a tyre pyre, but he should have thought about that before putting ink on that deal.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#442
> FOREIGN THREATS: Twitter is exceptionally vulnerable to foreign government exploitation in ways that undermine US national security, and the company may even have foreign spies currently on its payroll, the disclosure alleges.

This is a very strange article to me. When I think of Twitter and government influence, I think of the overwhelming pro-Washington bias.

I think of the "state-affiliated media" tags that somehow don't apply to RFE/RL and BBC.

I think of the countless heterodox/dissident accounts that have been banned or silenced on the platform.

I think of the "hacked materials" warning label that was invented to discredit a particularly damning story about a covert disinformation campaign involving Reuters and BBC.

I think of Twitter's complete tolerance of the obvious platform abuse by the textbook troll farm known as "NAFO".

I think of the revolving door between the federal government and policy/compliance positions at large tech companies including Twitter, of which Mudge is one of many.

My tinfoil hat is whispering that this story is part of a broader campaign to put pressure on Twitter to be even more compromised by the federal government and intelligence agencies. I just don't see how this "foreign threat" narrative lines up with the reality of how effectively managed Twitter has become over the past few years.

Realistically though, Mudge probably just has a huge hacker ego and is butthurt that he was caught slackin'.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#443

Earlier quoted context omitted.

what I find peculiar about the kpop crowd is how they seemingly appear out of nowhere and on-demand on in political topics to drown out/cancel people who don't like them or share their values. In Korea a blogger was able to see how BTS fans or "bots" were able to game the music ranking. What's interesting to me is how they seemingly correlate with wumaos as well. I don't have solid evidence but it appears that much o…

People don't do that unless they are paid somehow. It's organized activity if you search properly under each time it trends... One or a few accounts will post a keyword or phrase, and then all the subsequent accounts will constantly post with the words spelled exactly the same. Twitter suppresses coordinated activity from many other accounts, and it's against their rules, but somehow they allow it to go on regularly…

This is the most tinfoil hat way to misunderstand young people I've ever seen.

People absolutely do that, just because they think it's fun.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#444
post #148

Twitter CEO's response to employees which denies none of the claims made by CNN & WaPo* https://twitter.com/donie/status/1562069281545900033 * https://www.washingtonpost.com/technology/interactive/2022/t... edit: the PDFs from * https://www.washingtonpost.com/technology/interactive/2022/t... https://www.washingtonpost.com/technology/interactive/2022/t... https://www.washingtonpost.com/technology/interactive/2022/t...…

Page 9/84 in the "whistleblower_disclosure.pdf" are about Elon Musk's claims of fake twitter accounts and bots. Good lord, this does not look pretty for Twitter.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#445

God Mode, from my understanding, allows a Twitter employee to have access to an account and allows for a post to be made, under that account's id, without the account being notified or seeing the post show up in their own timeline. Is this an accurate statement? If so, why did nearly 1000 employees (12% of the workforce) have access to this mode before it was restricted, and what's the business case for that?

If you read the document "Security Chief's Final Report to Twitter" on the Washington Post article (https://www.washingtonpost.com/technology/interactive/2022/t...), you will see that 'god mode' just means they have IPMI access to servers.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#446
post #314

Is it just me, or does some of this feel less whistleblower-y and more petty? For example: > The company also lacks sufficient redundancies and procedures to restart or recover from data center crashes, Zatko's disclosure says, meaning that even minor outages of several data centers at the same time could knock the entire Twitter service offline, perhaps for good. That said, this is Mudge. I have a lot of respect for…

I don't think it's petty; availability of data and systems is a core component of security design.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#447
post #148

Twitter CEO's response to employees which denies none of the claims made by CNN & WaPo* https://twitter.com/donie/status/1562069281545900033 * https://www.washingtonpost.com/technology/interactive/2022/t... edit: the PDFs from * https://www.washingtonpost.com/technology/interactive/2022/t... https://www.washingtonpost.com/technology/interactive/2022/t... https://www.washingtonpost.com/technology/interactive/2022/t...…

Agrawal's internal statement about Zatko is insane. My goodness.

I know right! Was the last CEO who wasn't a monster Bill Hewlett?

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#448
post #262

Earlier quoted context omitted.

"All multifarious means which human ingenuity can devise, and which are resorted to by one individual to get an advantage over another by false suggestions or suppression of the truth. It includes all surprises, tricks, cunning or dissembling, and any unfair way which another is cheated."

So is Musk guilty of defrauding twitter by using aggressive acquisition tactics as a pretense to get access to internal nonpublic information to use against them?

The only honest answer I can give there is, "I don't know". So far as I'm aware, Twitter hasn't alleged that, no evidence has been presented supporting such an allegation, and generally it seems a heavy burden to present a court with convincing evidence of a conspiratorial theory like that, but I can't categorically say what Elon Musk's motives weren't.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#449

Earlier quoted context omitted.

I agree. I grant It’s possible Mudge is A) an old hand and doesn’t know how to run a security program with the tech today B) a strong tech hire who can’t lead a program. But Mudge is still… Mudge, and he’s also proven his ability to collaborate so if he was a bull in a china shop a twitter, that would be surprising. There’s also a broader trend here of well known security leads that originate from that time working a…

I read the full whistle-blower complaint, and the whole story from his perspective (and the crazy statement from Agrawal) looks like it's not B. Instead, it looks like it was a culture clash with his manager. He seems to have tried to escalate things to people above Agrawal nearly constantly. He was hired by Jack Dorsey, and felt accountable to him and to the board, but he reported to Agrawal, who believed that Mudge…

> I read the full whistle-blower complaint

The content of the complaint is all that matters, and it should be judged on its own merits. It never matters who said what, and attempting to make it matter is ad hominem fallacy; it is what is said that matters.

That said, I can't quite fathom why Twitter's cybersecurity matters any more than the cybersecurity of any of the myriad of online forums, HN included: the "data" simply isn't all that important; it is all public, it is all talk, and talk, as we know, is cheap. Say Twitter is completely overrun by foreign state actors who delete everything. The outrage is going to be minimal. "Dang, I really enjoyed mouthing off on Twitter. Oh, well."

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#450
post #174

Earlier quoted context omitted.

His complaints don't hold merit because he entered into a binding agreement to buy Twitter after waiving due diligence rights. Zatko was fired in January. Musk had and waived his chance to discover these things. It's too late now.

>waiving due diligence rights Pop legal quiz - does "waving due diligence rights" during an acquisition remove the other party's liability for fraud they've committed against the prospective buyer?

I think this is spot on - it's still possible to make the contract voidable if you misrepresent what you're selling.
Post reply on HN