Live data from Hacker News

Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

cnn.com

501–510 of 645 posts

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#501
post #168

Just to clarify for those who don't catch it in the article: Mudge's whistleblower complaint predates the Musk/Twitter feud entirely.

This is an important point, but why is the media picking it up just now? I guess both sides are starting the usual shit-flinging…

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#502
post #412

Earlier quoted context omitted.

Yeah, I think we're in lockstep here. I'm no fan of Musk (he's truly worked very hard to be the most provacatively pustulent punkass of tech) but that doesn't mean that Twitter leadership is any better. Just not as well PR'd. Dorsey himself was mostly an imbecile who drank too much of his own Kool Aid. Twitter has for years been the standard bearer for the most opaque, and incoherent content management; from user fee…

I’m a huge musk fan, but I still think his trying to get out of the Twitter deal is lame buyer's remorse and his arguments are weak. I see it as mostly unrelated to this mudge issue.

Never been a "fan" of a personality, but I used to really like Tesla and SpaceX, but after hearing a little about how their critical software is...not developed like critical software...I am very wary of what kind of engineering is going over there. With Musk deciding to amp up his celebrity with Twitter antics, I just can't respect him any more.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#503
post #148

Twitter CEO's response to employees which denies none of the claims made by CNN & WaPo* https://twitter.com/donie/status/1562069281545900033 * https://www.washingtonpost.com/technology/interactive/2022/t... edit: the PDFs from * https://www.washingtonpost.com/technology/interactive/2022/t... https://www.washingtonpost.com/technology/interactive/2022/t... https://www.washingtonpost.com/technology/interactive/2022/t...…

Thanks for posting this. Anyone commenting in this thread really needs to read the report as it paints the picture of their security hygiene. When I read things like 30% of all their endpoints have automatic updates disabled, and 40% reporting out of compliance, I'm picturing a real immature cowboy culture of arrogant developers that think they're above security policies, and no one at the helm to rope them into line. Sounds like they have no security culture, just policies. Security is something that begins with the individual.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#504
post #2

It is rather disconcerting how a platform that is apparently rather integral to the discourse of today is in the hands of a single private company. It doesn't matter who owns it, if it's Musk or someone else, the fact that it's at the whims of a private company, is the primary channel for discourse, and is something legislatures cannot even comprehend because of their age, should have alarm bells going off. Coupled w…

> It is rather disconcerting how a platform that is apparently rather integral to the discourse of today is in the hands of a single private company. Unpopular opinion: I think it's awesome that a private company has created a platform like Twitter. It's kind of like comparing a private amusement park with a public park: one has roller coasters, water slides and an arcade... the other has a swingset and a nice field…

> the fact that it's at the whims of a private company

How is this worse than at the whims of the crown?

The tiny detail that we're not having a crown anymore.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#505
post #322

I learned a lot about Mudge by reading "Cult of the Dead Cow: How the Original Hacking Supergroup Might Just Save the World." For anyone wanting to explore 90's security nostalgia, it's worth a read. For anyone wanting to learn where hacktivism comes from, it's worth a read. For anyone wanting to learn about how security consulting has evolved over the years, it's worth a read. Mudge is a very cool and capable indivi…

It appears that Dorsey was the one who hired him, and then Dorsey left, which might explain why they act as if "they have no idea who they hired".

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#506
It's not just this, but a long series of Twitter-related debacles, that are starting to look less like a company in trouble, and more like a company circling the drain. Do we have any real reason to think Twitter might not be able to survive all this? No one seems to think they're profitable, not even when ad revenue generally was a lot better than the economic environment we're going into. No one who's capable of buying it seems to want to buy it; the reason the poison pill vs. Elon Musk's initial purchase attempt was dropped, is that they checked around and got no other buyers. It's not just the legal and PR problems, it's that there's no $$$ on the other side to make it worth those problems, and we're heading into a "you need to make money" environment. I think they might be circling the drain...

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#507
post #427

Earlier quoted context omitted.

I’m a huge musk fan, but I still think his trying to get out of the Twitter deal is lame buyer's remorse and his arguments are weak. I see it as mostly unrelated to this mudge issue.

Musk posted a meme explaining why he pulled out. https://twitter.com/elonmusk/status/1546344529460174849

He is trying to get out of the deal because he's about to lose billions of dollars buying a pretty crappy company. All this stuff about bots is dishonest nonsense. He could have chosen to do due diligence, and chose not to.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#508
post #439

Earlier quoted context omitted.

What's the story with Rishi Sunak? Assuming you mean the candidate for Conservative Party leader and thus UK PM, I wasn't aware of such a connection.

Rinki Sethi. OP meant Rinki Sethi. (CISO of Twitter until January, left at the same time as Mudge)

Thank you for the clarification, this got me confused too!

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#509
post #319

Earlier quoted context omitted.

I don't because I'm not seeing an organization that will hold them accountable. - This Congress is ill-equipped to understand tech, much less hold it accountable. As long as the people are happy, Congress is happy. - Lord knows the people are ill-equipped to get how bad this is. They already watched this company allow a rogue employee to shut off the account of the President of the United States (before they chose to…

> My recommendation is to shed Twitter as a user. I never understood why tech people have such a strange enamor towards Twitter. Can’t be an industry power dev without it. Can’t start a company without it. Having a healthy Twitter following is often more important than having actual users—even to investors. Twitter is digital hype. I agree. It’s time to replace Twitter. The only question is what exactly is it that an…

> The only question is what exactly is it that anchors people to the platform

If I had to take a stab, it's a combination of networking effects (obviously), simplicity and the short text limit, which forces authors to mostly be concise and optimize for a 140 character attention span. This is also supercharged by the fact that you can (mostly) access everything anonymously - if I'm linked to Twitter, I know I can read/watch it and it will mostly be concise. I don't even bother clicking a link to FB, for example.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#510

God Mode, from my understanding, allows a Twitter employee to have access to an account and allows for a post to be made, under that account's id, without the account being notified or seeing the post show up in their own timeline. Is this an accurate statement? If so, why did nearly 1000 employees (12% of the workforce) have access to this mode before it was restricted, and what's the business case for that?

If you read the document "Security Chief's Final Report to Twitter" on the Washington Post article ( https://www.washingtonpost.com/technology/interactive/2022/t... ), you will see that 'god mode' just means they have IPMI access to servers.

"just"? What percentage of Google engineers do you think have IPMI access to servers?
Post reply on HN