Live data from Hacker News

Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

cnn.com

471–480 of 645 posts

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#471
If this is true this would be particularly damning

>Zatko’s complaint says he believed the Indian government had forced Twitter to put one of its agents on the payroll, with access to user data at a time of intense protests in the country. The complaint said supporting information for that claim has gone to the National Security Division of the Justice Department and the Senate Select Committee on Intelligence. Another person familiar with the matter agreed that the employee was probably an agent.[1]

[1] https://www.washingtonpost.com/technology/interactive/2022/t...

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#472
This should get the attention of politicians who are probably the most active users of Twitter. Having their contacts, coms, and metadata such as phone location exposed and collected by adversaries is probably a concern for them and our entire political system. Recall how J Edgar Hoover was collecting dirt of every politician to blackmail them to keep his agency funded without oversight. Twitter would have been a wet dream for him.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#473

Millenials and GenZ may have no idea who Mudge is. I, however, almost lost my first job out of college at a bank because I ran l0phtcrack against our Windows NT 4 server to see if it could crack passwords. I showed my boss, and he pulled me aside into another room and tore my head off for irresponsibly running this tool against a production server. He said I could have been fired if this got out, but he covered my as…

I don't because I'm not seeing an organization that will hold them accountable. - This Congress is ill-equipped to understand tech, much less hold it accountable. As long as the people are happy, Congress is happy. - Lord knows the people are ill-equipped to get how bad this is. They already watched this company allow a rogue employee to shut off the account of the President of the United States (before they chose to…

I generally agree that it's unlikely we'll see any serious accountability. However:

> - The only group who could really hold Twitter accountable are shareholders, but why should they care if the public and Congress don't? The money will roll in either way.

This might be what does it because is it true that the money is and will keep really rolling in? Twitter doesn't pay a dividend and is it reasonable to expect that the company's stock value should increase that much going forward?

Twitter's gross profit numbers aren't as large as you'd think given the household name recognition of the brand. You might be as surprised as I was to discover that meme-stocks like AMC and GameStop are approximately the same size as Twitter in terms of gross profit. Perhaps Twitter is just as much of a big name but ailing dinosaur as those businesses? Or if you want to make comparisons within social media, isn't it surprising that Snap's ~$2.8 billion cap gross profit is right up there with Twitter's ~$3.2 billion. How did that happen? It is also interesting that snap's market cap is only 2/3rds of Twitters despite a much closer delta between the two companies reported profits.

On the whole, things aren't looking too good for the social media right now, take for example facebook losing active users YoY. I often wonder what zeitgeist web properties are going to be remembered as a BIG thing that receded in popularity in the course of about a decade, say like bell-bottom denim jeans from the 60s or disco music from the 70s. Could it be social media for the 2010s?

Anyhow if they aren't paying dividends and they aren't able to keep growing at pace with expectations what exactly are they delivering in terms of value to shareholders?

Given that the allegations are about defrauding shareholders by actively deceiving them and sweeping things under the rug. Twitter's shareholders might be better off revolting against the current leadership to recoup their loses than to look the other way and let this slide.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#474

> FOREIGN THREATS: Twitter is exceptionally vulnerable to foreign government exploitation in ways that undermine US national security, and the company may even have foreign spies currently on its payroll, the disclosure alleges. This is a very strange article to me. When I think of Twitter and government influence, I think of the overwhelming pro-Washington bias. I think of the "state-affiliated media" tags that some…

Read the report of the problems he was trying to surface: https://www.washingtonpost.com/technology/interactive/2022/t...

This doesn't seem like he was "butthurt and caught slackin'." The tone of the report seems like he's frustrated that he was hired to do a job, and not given the resources / authority to make the necessary sweeping changes. Perhaps someone with a more political approach could have influenced leadership better. But they hired an extremely technical person, not an extremely political person.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#475

Zatko reported directly to the CEO, as a senior leader you need to take responsibility for your own work. Does anyone believe that in an organization as large as Twitter he didn't have enough resources to solve this? I imagine his budget ran in the tens of millions.

I can very much believe it. A CEO can, if they play their cards right, block the CTO from accomplishing what the CTO set out to do. Budget is not the problem. Approvals and alignment with board members are the problems. And if the CTO still decides to push forward, the CEO can still fire the CTO for underperformance which is exactly what you see in this story.

[deleted]

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#476

> FOREIGN THREATS: Twitter is exceptionally vulnerable to foreign government exploitation in ways that undermine US national security, and the company may even have foreign spies currently on its payroll, the disclosure alleges. This is a very strange article to me. When I think of Twitter and government influence, I think of the overwhelming pro-Washington bias. I think of the "state-affiliated media" tags that some…

What more pressure do you think intelligence agencies would want to enforce? https://www.mintpressnews.com/twitter-hiring-alarming-number...

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#477
You would think that Twitter might have a coherent strategy in place for dealing with the media on this but no. They are trying to discredit Peiter Zatko by stating that he was terminated for performance reasons and yet their spokesperson goes onto to make these completely conflicting statements:

From Twitter spokeswoman Rebecca Hahn:

Hahn said that Twitter fired Zatko after 15 months “for poor performance and leadership.”

Hahn added that Twitter has tightened up security extensively since 2020, that its security practices are within industry standards, and that it has specific rules about who can access company systems.[1]

2020 was of course the year that Zatko was hired by former CEO Dorsey. So security tightened up "extensively" on Zatko's watch but he was fired for "for poor performance and leadership"?

This only seems to support Zatko's(and many others) assertion that Twitter is a giant shit show of chaos.

[1] https://www.washingtonpost.com/technology/interactive/2022/t...

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#478
post #36

Eh, you could take out Twitter and insert many other company names and it'll still hold true. And those companies hold so much more sensitive data about you than Twitter. I know of insurance companies that have help desk employees with domain admin access. And all crippling ransomware attacks take advantage lax permissions. This is rampant. How is this a story?

> How is this a story? Cynically, because it's twitter, and it's trendy amongst a certain subset of the population to bash social media in general and twitter in particular. And I think your point is fair. (FWIW, I think social media has if not caused, then certainly exacerbated, some major problems at individual, societal, and global levels, but by no means do I think twitter is the biggest contributor. I don't thin…

I think you are referring to corporate and state controlled social media. There is a big difference between those platforms and the fediverse instances I am running on a RPI sitting on my desk.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#479

The previous head of security to Zatko talked about fixing these problems. I remember distinctly after the FTC crackdown there were all hands where the discussion came up. I guess these problems were never fixed.

>If you are wondering if the stuff about Twitter security being lapse is just one person complaining, you might be interested to know that, 18 months after being let go from the company, I've not been removed from their employees GitHub commiters[sic] group.

>I can see private repos, yes.

>A Twitter employee, Chris Banes, has claimed "that nothing internal or private is hosted on GitHub. It’s all just open source code.". Here is a picture of a private, active, repo I had access to until about 50 minutes ago. Chris's statement is incorrect.

https://twitter.com/alsutton/status/1562152606096658432

https://twitter.com/alsutton/status/1562116259357024257

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#480
post #158

Earlier quoted context omitted.

What scenario would justify that feature existing though? Why would they need to make posts from arbitrary accounts?

It's common in lots of software - a form of a "su" command that lets you assume all aspects of a particular user. Usually developed for testing purposes (easiest way to reproduce a problem, after all) and prevents password-sharing. But it can obviously be used for evil, and so it should be heavily logged and flagged.

[deleted]
Post reply on HN