Live data from Hacker News

Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

cnn.com

451–460 of 645 posts

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#451
copy and paste my comment from an earlier post which failed to see HN traction (https://news.ycombinator.com/item?id=32562747):

> The complaint from former head of security Peiter Zatko, a widely admired hacker known as “Mudge,” depicts Twitter as a chaotic and rudderless company beset by infighting, unable to properly protect its 238 million daily users including government agencies, heads of state and other influential public figures.

this is a fun read. I've long said that government agencies, heads of state and other influential public figures are obvious candidates for running their own ActivityPub installations (or in paying competent people to do that, which shockingly Twitter, Inc. could be in the business of hosting/selling).

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#452
post #314

Is it just me, or does some of this feel less whistleblower-y and more petty? For example: > The company also lacks sufficient redundancies and procedures to restart or recover from data center crashes, Zatko's disclosure says, meaning that even minor outages of several data centers at the same time could knock the entire Twitter service offline, perhaps for good. That said, this is Mudge. I have a lot of respect for…

for a company that likes to speak of itself as being a valuable piece of communication infrastructure (it isn't, Twitter's a website), this is pretty concerning and shows a lack of seriousness compared to oh, say, the Bell System.

Gov (a term that ranges from your head of state down your county dog-catcher,) needs to get off these services asap. Twitter, TikTok, Instagram, FB are all modern versions of your old AOL Keyword.

Today we have ActivityPub, a W3C recommendation, which would be a great alternative.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#454
post #393

Earlier quoted context omitted.

I agree with everything you said, but I'd like to play devil's advocate here. Mudge has worked: * L0pht / @stake: security research, red teaming, and source code auditing, IIRC. * BBN: research. * NFR: technical advisory board. * DARPA: Managing a program that provided grants for new security products and tools. * Google ATAP: Google's "invention studio". * CyberUL: Testing of security products. None of these jobs re…

You left out that he built the security program at Stripe.

He led the Security team at Stripe for a time, but it was a functioning team before he arrived.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#455

Earlier quoted context omitted.

I think this is key. If you don't have a good security culture, where people understand and have ingrained proper security practices, you're toast, no matter who else you hire.

Google has good security practices, can implement those in any big corp as they are very straightforward. Mudge previously worked at Google so I'd assume he was hired to help Twitter security get better by implementing some practices from Google. But maybe he was just hired to look like Twitter cared and they didn't really want to change anything.

Google also has a very good ingrained security culture. They understand that they hold on to people's most private and critical data, and rock-solid security has to be a cornerstone of their business.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#456
post #213

Earlier quoted context omitted.

Where do you see that info in the Verge article? All I can see is "he filed last month" (which would be July 2022) - the month Musk "officially" backed out and at least a month after he started doing the "I don't want Twitter any more" dance.

"Zatko was fired by Twitter in January and claims that this was retaliation for his refusal to stay quiet about the company’s vulnerabilities."

That doesn't cover whether or not he had contact with Musk and when he started the whistleblowing process.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#457
post #148

Twitter CEO's response to employees which denies none of the claims made by CNN & WaPo* https://twitter.com/donie/status/1562069281545900033 * https://www.washingtonpost.com/technology/interactive/2022/t... edit: the PDFs from * https://www.washingtonpost.com/technology/interactive/2022/t... https://www.washingtonpost.com/technology/interactive/2022/t... https://www.washingtonpost.com/technology/interactive/2022/t...…

Page 9/84 in the "whistleblower_disclosure.pdf" are about Elon Musk's claims of fake twitter accounts and bots. Good lord, this does not look pretty for Twitter.

To me that part is pretty weak compared to the security disclosures. The "lie" is about whether or not Twitter executives are incentivized to delete bots (later on he says that Twitter is incentivized to keep bots out of mDAU because they don't click on ads so they'd tank the clickthrough rate, kind of blows a whole in Elon Musk's whole thing). In reality I'm sure there are multiple overlapping and contradictory incentives at play, but it's not really a falsifiable statement so not really something you can "lie" about.

The way it's framed ("Twitter lied to Elon Musk about bots") makes me suspicious of the whistleblowers' motives here. I know he's some kind of legend around these parts but I've never heard of him, so I'm just going by what I've learned today. Seems like propaganda to me, intended to maximally damage twitter and/or curry favor with Musk.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#458

Earlier quoted context omitted.

I read the full whistle-blower complaint, and the whole story from his perspective (and the crazy statement from Agrawal) looks like it's not B. Instead, it looks like it was a culture clash with his manager. He seems to have tried to escalate things to people above Agrawal nearly constantly. He was hired by Jack Dorsey, and felt accountable to him and to the board, but he reported to Agrawal, who believed that Mudge…

> I read the full whistle-blower complaint The content of the complaint is all that matters, and it should be judged on its own merits. It never matters who said what, and attempting to make it matter is ad hominem fallacy; it is what is said that matters. That said, I can't quite fathom why Twitter's cybersecurity matters any more than the cybersecurity of any of the myriad of online forums, HN included: the "data"…

> Say Twitter is completely overrun by foreign state actors who delete everything.

That's not what's dangerous.

Instead, dangerous things include manipulating the algorithms so that "news" of ones choice get lots of visibility. Then a foreign state can influence the elections

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#459

>one or more current employees may be working for a foreign intelligence service. I don't doubt this, but the source is someone with fairly deep ties to the US intelligence services. Why should he be allowed a job and not people with ties to foreign agencies?

Conflict of interest violations. Such violations are absolved through disclosure of known relationships, which cannot occur if persons are keeping ties to foreign intelligence services secret.

Is maintaining ties with US intelligence services a conflict of interest?

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#460
post #427

Earlier quoted context omitted.

I’m a huge musk fan, but I still think his trying to get out of the Twitter deal is lame buyer's remorse and his arguments are weak. I see it as mostly unrelated to this mudge issue.

Musk posted a meme explaining why he pulled out. https://twitter.com/elonmusk/status/1546344529460174849

If Musk actually believes this represents anything it puts his IQ in the single digit - low double digits range.
Post reply on HN