Live data from Hacker News

Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

cnn.com

481–490 of 645 posts

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#481
post #75

"The whistleblower also says Twitter executives don't have the resources to fully understand the true number of bots on the platform, and were not motivated to." I imagine this hurts Twitter's defense against Musk from pulling out of the takeover deal, or, is this whistleblower's account inadmissible?

This aspect of the story was entirely predictable:

>Musk lawyer Alex Spiro said they want to talk to Twitter whistleblower. “We have already issued a subpoena for Mr. Zatko, and we found his exit and that of other key employees curious in light of what we have been finding.”

https://twitter.com/donie/status/1562056198425288704

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#482

> FOREIGN THREATS: Twitter is exceptionally vulnerable to foreign government exploitation in ways that undermine US national security, and the company may even have foreign spies currently on its payroll, the disclosure alleges. This is a very strange article to me. When I think of Twitter and government influence, I think of the overwhelming pro-Washington bias. I think of the "state-affiliated media" tags that some…

There's been at least one Saudi spy found working at Twitter and convicted: https://nypost.com/2022/08/09/ex-twitter-employee-ahmad-abou...

> Saudi citizen Ali Alzabarah, who worked as an engineer at Twitter, used their positions to access confidential Twitter data about users, their email addresses, phone numbers and IP addresses, the latter of which be used to identify a user’s location

Internal data security practices could probably have helped limit his access

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#483

Earlier quoted context omitted.

> There is nothing more evident about the fatal flaws in social media than when news concerning a platform is suppressed on the cited platform. I just looked at the Trending panel and "Mudge" is #12 for me, with 4333 tweets. #11 is "Taco Tuesday", with 4172 tweets. #7 is "Virgo" with 98,500 tweets. So I'm not seeing a lot of evidence of suppression. I think it's just a pretty niche story. I think the allegations are…

Everyone has a different trending timeline on Twitter which is now more based on who they follow. The trending timeline is "baked" and dictated also by moderators and paid promotion often... It's why topics like "K-POP" trend so much, even for people that don't even listen to it at all. If you follow tech personalities, there's a higher chance you'll see the news. On my music account on Twitter, I don't follow tech p…

Given that you understand Twitter ranks based on interests, what's your evidence that this was "suppressed"? Rather than just ranked according to people's interests?

You seem to be saying that people should be interested in this story. I'm not sure I agree, but I definitely believe most Twitter users won't be. Is it a good headline? Sure. But does it have much direct and immediate relevance to their personal lives? Not for most Twitter users.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#484
post #421

Earlier quoted context omitted.

> The company also lacks sufficient redundancies and procedures to restart or recover from data center crashes, Zatko's disclosure says, meaning that even minor outages of several data centers at the same time could knock the entire Twitter service offline, perhaps for good. I mean if it were true that seems pretty negligent. If that were the entire extent of the whistleblower complaint (not sure if complaint is the…

I dunno, pointing out that something has a poor architecture and pointing out that something has severe, known, and ignored security issues feels different.

Availability is the A in the CIA triad. DR and resilience in general is part of security.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#485

Earlier quoted context omitted.

The last US President used Twitter as his primary way to communicate with the world. That on its own has serious security implications. I agree with you that we have landed in not a great place.

I hope we get to a place where we all agree that a sitting U.S. President should not "tweet." The White House maintains a Press Secretary for a reason. Granted, the current person holding the job is no C.J. Craig.

Both Psaki and Jean-Pierre have been excellent press secretaries. C.J. Craig is a fictional character written to be superhumanly prescient and witty in response to fictional crises.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#486
post #393

Earlier quoted context omitted.

> B) a strong tech hire who can’t lead a program. I worked with Mudge (not super close, but enough to see how he worked across teams etc) and can certainly say this is not the case. At least when I saw him Mudge was excellent at the program leadership aspect of his role. At one point he ended up a DARPA PM. You can't go from L0pht to DARPA without getting really good at working with other people and leading projects.…

I agree with everything you said, but I'd like to play devil's advocate here. Mudge has worked: * L0pht / @stake: security research, red teaming, and source code auditing, IIRC. * BBN: research. * NFR: technical advisory board. * DARPA: Managing a program that provided grants for new security products and tools. * Google ATAP: Google's "invention studio". * CyberUL: Testing of security products. None of these jobs re…

Well, you can devils-advocate anyone into an incompetent.

Decades of experience as a rebellious hacker? Well, that's not commercial experience. Founded a security consultancy? Too small, they just don't know how to operate in a large bureaucracy. Worked at a secretive company as an individual contributor? They've been completely silent in public, clearly they haven't achieved anything interesting in years. Working elsewhere as an individual contributor? They just don't know how to build a team. Decades as a senior manager at a huge multinational corporation? Out of touch bullshitter, stale coding skills, doesn't know how we really do things these days.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#487
post #439

Earlier quoted context omitted.

What's the story with Rishi Sunak? Assuming you mean the candidate for Conservative Party leader and thus UK PM, I wasn't aware of such a connection.

Rinki Sethi. OP meant Rinki Sethi. (CISO of Twitter until January, left at the same time as Mudge)

Oh, yes, thank you! I can't edit my comment anymore, but, yes, Rinki Sethi, apologies for the confusion.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#488
I did wonder about this ever since the Ahmad Abouammo story broke. How did a media partnerships manager have access to so many random users' private info? That stank of poor access controls:

https://www.justice.gov/opa/pr/former-twitter-employee-found...

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#489

Earlier quoted context omitted.

Yeah - but that's dumb bullshit. He can't legally pull out because of that. He waived all of that to force Twitter to agree to the deal (because it'd be basically impossible for the board to reject it). This made sense at the time, because the board was looking for ways to weasel out of it because (imo) they politically don't like Musk. Then the market crashed and suddenly he was overpaying a ton for Twitter, then he…

>I think he earnestly wanted to buy Twitter for principled reasons around speech which I agree with. He structured the deal in such a way where Twitter's board couldn't reject it (because it was so favorable to shareholders). Then when the market tanked the deal way overpriced Twitter, but he had already committed to it so he's trying everything to get out of it. That's not how business valuations work (it's how spec…

One could argue that the value of a company is the sum of net present value of the future free cash flows it can produce. If the market crash is because of peope realizing there is a recession coming for example, it makes sense to update your expectations about the net present value of future cash flows - probably in sum a bit lower than before probably.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#490
post #314

Is it just me, or does some of this feel less whistleblower-y and more petty? For example: > The company also lacks sufficient redundancies and procedures to restart or recover from data center crashes, Zatko's disclosure says, meaning that even minor outages of several data centers at the same time could knock the entire Twitter service offline, perhaps for good. That said, this is Mudge. I have a lot of respect for…

It doesn't help that he's a "disgruntled employee who was fired".

I added that "disgruntled" part but... who gets fired for poor performance and doesn't become at least slightly disgruntled?

Post reply on HN