Earlier quoted context omitted.
Page 9/84 in the "whistleblower_disclosure.pdf" are about Elon Musk's claims of fake twitter accounts and bots. Good lord, this does not look pretty for Twitter.
To me that part is pretty weak compared to the security disclosures. The "lie" is about whether or not Twitter executives are incentivized to delete bots (later on he says that Twitter is incentivized to keep bots out of mDAU because they don't click on ads so they'd tank the clickthrough rate, kind of blows a whole in Elon Musk's whole thing). In reality I'm sure there are multiple overlapping and contradictory ince…
Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies
511–520 of 645 posts
Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies
#512Earlier quoted context omitted.
A well-timed set of tweets from compromised government and private-sector accounts, coordinated with real stock market activity planned by the attacker such that investors cannot ignore the rumors, could cause a geopolitically significant market panic. This already happened in 2013, and that was with just a single account being compromised: https://business.time.com/2013/04/24/how-does-one-fake-tweet...
In the long run that would be a good thing. It would be an object lesson that investors shouldn't believe anything they read on social media. Investors always have the option to ignore rumors.
What I'm trying to say is, you might be able to discredit Twitter, but you won't fix investors trying to invest ahead of the news.
Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies
#513Earlier quoted context omitted.
Ending the enforcement of Net Neutrality was not about censoring content or subjects.
The specific worry about Net Neutrality was that ISPs would use their monopoly power to censor specific sources and/or self-preference their own businesses. It's something that should have been expanded to large online platforms rather than being disposed of entirely.
Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies
#514Earlier quoted context omitted.
Now think about the implications with respect to Twitter DMs that show up in criminal investigations. For instance, consider the Twitter DMs exchanged by Donald Trump, Jr and WikiLeaks. In that particular case, the communication was acknowledged by the party in question, but imagine the two possibilities thousands of employees being able to act on the part of users opens up: 1. Twitter employees could fabricate a cri…
> 1. Twitter employees could fabricate a criminal conspiracy by creating messages between multiple Twitter accounts. Could be thwarted by some kind of "source" database column/field/value that says "this is a tweet made by God mode" Whether Twitter has that field, if it is internal only, and if they would share it with the public/a court of law, I have no clue
1. No employees have direct, immediate access to user accounts or data.
2. Only a small number of employees should ever be able to gain access to user accounts or data, for the purpose of resolving issues directly affecting said accounts or data.
3. Access is only granted to one specific user account at a time, and only for a limited amount of time.
4. Access to a user account requires at least one other person to sign off on the access-grant.
5. Every operation performed upon a user account -- viewing a field, modifying a field -- is logged in a place the people from #2 and #4 do not have access to.
6. Access logs are routinely audited for perfidy.
7. Gaining accesses to user accounts or interacting with them in a way that is not necessary or attempting to circumvent the above process must be a don't-bother-cleaning-out-your-desk-we'll-do-it-for-you offense.
With policies in place like that, you reduce the insider risk to user accounts. You need multiple people directly involved in secretly accessing or taking over a user account, and you potentially need dozens of others (the potential auditors) to be complicit. The more people you have involved, the more likely it is someone shuts it down, or at least blows the whistle on it when shit hits the fan.
If someone can just get drunk one night, open up a user account, tweet something, then SSH over to the audit server and drop the rows from the access log indicating what they did, and there's no way to even prove something happened, let alone who did it.
Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies
#515It is rather disconcerting how a platform that is apparently rather integral to the discourse of today is in the hands of a single private company. It doesn't matter who owns it, if it's Musk or someone else, the fact that it's at the whims of a private company, is the primary channel for discourse, and is something legislatures cannot even comprehend because of their age, should have alarm bells going off. Coupled w…
Not true. If anything Twitter is a cancer on our discourse that should be disdained, not something that should be enshrined as a fixture into our lives.
Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies
#516Is it just me, or does some of this feel less whistleblower-y and more petty? For example: > The company also lacks sufficient redundancies and procedures to restart or recover from data center crashes, Zatko's disclosure says, meaning that even minor outages of several data centers at the same time could knock the entire Twitter service offline, perhaps for good. That said, this is Mudge. I have a lot of respect for…
It doesn't help that he's a "disgruntled employee who was fired". I added that "disgruntled" part but... who gets fired for poor performance and doesn't become at least slightly disgruntled?
Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies
#517Earlier quoted context omitted.
I saw a reddit post today that "Disney fans are furious that Avatar was temporarily pulled from Disney Store" and the top 500 comments were like "No one is furious". Here, I'll give it a go: "Environmentalists are furious that Bill Gates kills mosquitos"
I did a quick Twitter search, and unfortunately your story isn't supported by any tweets I can find. Good news: you get to write a story about conspiracy theories about Gates and mosquitoes instead though! https://twitter.com/lorijean333/status/1561224522166067201?s...
If there's no evidence for my claim it must be evidence of censorship, because certainly I can't be wrong.
Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies
#518Earlier quoted context omitted.
I read the full whistle-blower complaint, and the whole story from his perspective (and the crazy statement from Agrawal) looks like it's not B. Instead, it looks like it was a culture clash with his manager. He seems to have tried to escalate things to people above Agrawal nearly constantly. He was hired by Jack Dorsey, and felt accountable to him and to the board, but he reported to Agrawal, who believed that Mudge…
I wouldn't paint with too broad of a brush in this instance, however. Yes, mudge is the ur-hacker, but also: he worked at BBN and DARPA (where he was extremely effective) and elsewhere. He probably has the most experience of any technical/hacker on the planet of working with executives in large organizations. Agrawal's memo, in contrast, reeks of insecurity. The combination of how he's treated mudge and Rishi Sunak a…
Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies
#519> FOREIGN THREATS: Twitter is exceptionally vulnerable to foreign government exploitation in ways that undermine US national security, and the company may even have foreign spies currently on its payroll, the disclosure alleges. This is a very strange article to me. When I think of Twitter and government influence, I think of the overwhelming pro-Washington bias. I think of the "state-affiliated media" tags that some…
And I think of AWS announcing a massive data loss, Kim-Jong Un tweeting "Nukes have been launched" and the US president tweeting about an impeding Yellowstone explosion. If you want to really f up the country in a big way, Twitter is a great way. With how much verification some journalists do, the news will have secondary 'sources' outside Twitter within minutes for free.
Even without going to such lengths, the activities and rough locations of US officials will already be massively valuable to any foreign power. Facebook had papers where they managed to guess an individuals health based on their typing patterns, just imagine what you could do with all of the Twitter analytics.
Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies
#520Earlier quoted context omitted.
I'm not sure why any sizeable portion of the public would know _any_ reputable cyber security experts. Twitter's CEO said the firing was due to "the impact on top priority work", and whistleblowing 6 months later isn't a surprising timeline when you need to have long talks with an attorney and get your own work-life situated.
Mudge specifically referenced Musk in his complaint. This isn't just 6 months of due diligence it's targeted and timed for maximum damage.
I did find one say that the complaint was already in progress before Musk's deal, and Musk rightly tried to subpoena Mudge for his recent exit. It does sound reasonable that the bot comment was added in light of the fiasco with Musk's deal.