Live data from Hacker News

Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

cnn.com

491–500 of 645 posts

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#491

God Mode, from my understanding, allows a Twitter employee to have access to an account and allows for a post to be made, under that account's id, without the account being notified or seeing the post show up in their own timeline. Is this an accurate statement? If so, why did nearly 1000 employees (12% of the workforce) have access to this mode before it was restricted, and what's the business case for that?

Now think about the implications with respect to Twitter DMs that show up in criminal investigations. For instance, consider the Twitter DMs exchanged by Donald Trump, Jr and WikiLeaks. In that particular case, the communication was acknowledged by the party in question, but imagine the two possibilities thousands of employees being able to act on the part of users opens up: 1. Twitter employees could fabricate a cri…

> 1. Twitter employees could fabricate a criminal conspiracy by creating messages between multiple Twitter accounts.

Could be thwarted by some kind of "source" database column/field/value that says "this is a tweet made by God mode"

Whether Twitter has that field, if it is internal only, and if they would share it with the public/a court of law, I have no clue

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#492

You would think that Twitter might have a coherent strategy in place for dealing with the media on this but no. They are trying to discredit Peiter Zatko by stating that he was terminated for performance reasons and yet their spokesperson goes onto to make these completely conflicting statements: From Twitter spokeswoman Rebecca Hahn: Hahn said that Twitter fired Zatko after 15 months “for poor performance and leader…

Twitter has a comms department but there has been a revolving door of ineffective comms leadership.

I can't even get someone from Twitter Comms to pop into the Twitter subreddit to engage with users there.

Rebecca Hahn doesn't even have a Twitter account afaik.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#493
post #68

Earlier quoted context omitted.

Oh wait?

Oh wait, we already had that, and then we centralized and monopolized the hell out of it [0] [0] https://staltz.com/the-web-began-dying-in-2014-heres-how.htm...

That's because decentralized networks are expensive and can't handle spam unless you make receiving messages opt-in, and then you can't @ people like you can on Twitter.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#494

Earlier quoted context omitted.

I don't believe that what Mudge is saying there is all that well quoted or explained. The argument I've heard him make, in other settings, is that companies that are interesting enough will get job applicants that are really moles for intelligence agencies. This is very difficult to stop, and once your company has enough employees, downright impossible. His recommendation however is not to make it impossible for peop…

> Someone like Twitter, Google or Facebook should have 'some of our employees are malicious and sophisticated' as part of their threat model. I would estimate there is a 100% chance that every one of those companies listed, has multiple employees who work for or are sources for US domestic and foreign intelligence services. It should be expected and part of their internal systems that people only have access to the s…

>estimate there is a 100% chance that every one of those companies listed, has multiple employees who work for or are sources for US domestic and foreign intelligence services

What are you basing this on?

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#495
post #451

copy and paste my comment from an earlier post which failed to see HN traction ( https://news.ycombinator.com/item?id=32562747 ): > The complaint from former head of security Peiter Zatko, a widely admired hacker known as “Mudge,” depicts Twitter as a chaotic and rudderless company beset by infighting, unable to properly protect its 238 million daily users including government agencies, heads of state and other influ…

"as a chaotic and rudderless company beset by infighting,"

Sounds like a match made in heaven for "government agencies, heads of state and other influential public figures."

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#496

Earlier quoted context omitted.

Yeah - but that's dumb bullshit. He can't legally pull out because of that. He waived all of that to force Twitter to agree to the deal (because it'd be basically impossible for the board to reject it). This made sense at the time, because the board was looking for ways to weasel out of it because (imo) they politically don't like Musk. Then the market crashed and suddenly he was overpaying a ton for Twitter, then he…

>I think he earnestly wanted to buy Twitter for principled reasons around speech which I agree with. He structured the deal in such a way where Twitter's board couldn't reject it (because it was so favorable to shareholders). Then when the market tanked the deal way overpriced Twitter, but he had already committed to it so he's trying everything to get out of it. That's not how business valuations work (it's how spec…

"If Twitter was fairly valued by Elon Musk before the crash then it would be fairly valued now"

That's a big if - I think a lot of this stuff is more speculation than any sort of fundamental cash flow valuation. A lot Twitter's actual value (its network effect and influence) is hard to measure anyway.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#497

Earlier quoted context omitted.

Yeah - but that's dumb bullshit. He can't legally pull out because of that. He waived all of that to force Twitter to agree to the deal (because it'd be basically impossible for the board to reject it). This made sense at the time, because the board was looking for ways to weasel out of it because (imo) they politically don't like Musk. Then the market crashed and suddenly he was overpaying a ton for Twitter, then he…

>I think he earnestly wanted to buy Twitter for principled reasons around speech which I agree with. He structured the deal in such a way where Twitter's board couldn't reject it (because it was so favorable to shareholders). Then when the market tanked the deal way overpriced Twitter, but he had already committed to it so he's trying everything to get out of it. That's not how business valuations work (it's how spec…

> That's not how business valuations work (it's how speculation works). If Twitter was fairly valued by Elon Musk before the crash then it would be fairly valued now - the fundamentals of the business haven't changed.

Some "fundamentals" of a business like twitter's value are:

1. Product/market fit, finances, etc. What you mean by "fundamentals" I think.

2. How easy it is for them to raise money (i.e. the "public sentiment" of VC towards their company and the industry)

3. How likely it is for regulation to stifle their growth, which is a derivative of public sentiment.

4. How much shares can be sold for, i.e. the public sentiment about how much it's worth.

5. Predicted future sentiment of their users and of advertisers, both of which impact expected future revenue.

2-5 all change with public sentiment, and a market crash changes public sentiment of many companies at once.

It's self-evident that elon musk is overpaying more now than before unless you insist that twitter's value is not actually related to 2-5 above, or 2-5 above should have been trivially predictable 100% accurately already as part of its "fundamentals", both of which seem obviously silly.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#498
post #433

Earlier quoted context omitted.

Knocking-out twitter (used by journalists and govs) during a crisis IS a security concern.

A security concern for the governments, not twitter. It's not twitter's fault that governments are using it as a primary form of communication, nor should it be their responsibility to have amazing uptime just because governments are using their platform.

It's a national security concern (and international?) if Twitter can be compromised by nefarious actors and/or brought down via said compromised access. The idea that this isn't worthy of whistleblowing because Twitter is a corporation is insane. There are countless examples in the last year of Twitter being used for communication during a crisis.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#499
post #158

Earlier quoted context omitted.

What scenario would justify that feature existing though? Why would they need to make posts from arbitrary accounts?

It's common in lots of software - a form of a "su" command that lets you assume all aspects of a particular user. Usually developed for testing purposes (easiest way to reproduce a problem, after all) and prevents password-sharing. But it can obviously be used for evil, and so it should be heavily logged and flagged.

But the comment says that users wouldn't even see posts from the Twitter employee assuming their account in their own timeline. What legitimate purpose would that serve?

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#500
post #492

You would think that Twitter might have a coherent strategy in place for dealing with the media on this but no. They are trying to discredit Peiter Zatko by stating that he was terminated for performance reasons and yet their spokesperson goes onto to make these completely conflicting statements: From Twitter spokeswoman Rebecca Hahn: Hahn said that Twitter fired Zatko after 15 months “for poor performance and leader…

Twitter has a comms department but there has been a revolving door of ineffective comms leadership. I can't even get someone from Twitter Comms to pop into the Twitter subreddit to engage with users there. Rebecca Hahn doesn't even have a Twitter account afaik.

That is rich. From July:

>"Details: The communications lead role has been vacant since last November, but it's been led by Twitter CMO Leslie Berland on an interim basis for the past seven months. Hahn, who technically started last week, will report to Berland."[1]

The VP of Global Communications at Twitter role was vacant for 7 months and the person finally hired doesn't seem to have a visible Twitter presence after 6 weeks on the job? At a time when the company is practically a daily news story? You couldn't make this shit up.

[1] https://www.axios.com/2022/07/12/twitter-rebecca-hahn-commun...

Post reply on HN