Live data from Hacker News

Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

cnn.com

521–530 of 645 posts

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#521

Millenials and GenZ may have no idea who Mudge is. I, however, almost lost my first job out of college at a bank because I ran l0phtcrack against our Windows NT 4 server to see if it could crack passwords. I showed my boss, and he pulled me aside into another room and tore my head off for irresponsibly running this tool against a production server. He said I could have been fired if this got out, but he covered my as…

I did the same thing on a server for a major department store chain in the '90s. I booted a Linux diskette and copied the SAM file to it. I also ran l0phtcrack, or John the Ripper on a 486 (?) PC in my apartment. I think I bought a rainbow table and something else to expand the iterations it would use on the hashes. I let it run for over a week and had a couple of thousand clear passwords. This was for every store west of the Mississippi and included most of the "big-wigs" in our chain.

I was going to send the information to our security people in another state but decided it probably wouldn't be a wise thing to do.

I come across the HDD where I have this stuff archived every now and then and it makes me smile. This was also in the "Free Kevin" days.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#522

Earlier quoted context omitted.

> I imagine this hurts Twitter's defense against Musk from pulling out of the takeover deal Not really because they have consistently said "this is what we do, it's a finger in the air estimate based on sampling, it might be right, it might be wildly wrong, there's no agreed methodology for this". For someone to then go "they don't fully understand the true number of bots! GOTCHA!" is dumb because it's literally just…

The problem I have in assigning credibility to Twitter's position on bots is that they seem to have held multiple seemingly inconsistent positions (all paraphrased): 1. "Finger in the air estimate based on sampling", aka. "don't read too much into it" 2. "Not more than 5%" 3. "Methodology can't be understood externally"

They are completely consistent. They have always said 'no more than 5% according to their sampling' plus a long row of disclaimers and that they sampled based on things like activity and only from monetizeable users, neither of which can be tracked without Twitters internal data on the user.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#523

Earlier quoted context omitted.

> If the executives did not make a meaningful effort to count them They've been filing their methodology for bot counting with the SEC since 2013. If they're not making a "meaningful effort" and it materially affected the stock price in some way, either the SEC or a shareholder would have gone "HOLD ON SHENANIGANS O'CLOCK", surely? It can't be that the entire world was A-OK with Twitter's bot counting until June 2022…

> They've been filing their methodology for bot counting with the SEC since 2013. No, they haven’t. They describe at a very high level the amount of sampling they do (100 accounts a day? Really, that’s it?), but don’t discuss the methodology used, such as what they use as signals and indicators of botness. That’s not “filing their methodology“, it’s covering their arses.

> That’s not “filing their methodology“, it’s covering their arses.

True, but probably quite successful. So this will most likely not save Musk.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#524

Earlier quoted context omitted.

Now think about the implications with respect to Twitter DMs that show up in criminal investigations. For instance, consider the Twitter DMs exchanged by Donald Trump, Jr and WikiLeaks. In that particular case, the communication was acknowledged by the party in question, but imagine the two possibilities thousands of employees being able to act on the part of users opens up: 1. Twitter employees could fabricate a cri…

> A criminal conspiracy can now use the "Wasn't me, must have been some random Twitter employees" defense. I could see this being billed as a feature of a privacy-forward chat platform. Messages are slipped into conversations without either party having actually sent them and no way to tell whether they were real or not.

I’ve heard of similar things to this being discussed…

Eg. simple things like tracking-busters where it randomly clicks links in headless chrome to fool the algorithm, p2p vpns where you use a random user’s IP address to randomize who made what request, etc.

There is also a school of thought that you should periodically publish private keys for plausible deniability (“was it me, or did someone sign that after I published the key”).

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#525
post #2

It is rather disconcerting how a platform that is apparently rather integral to the discourse of today is in the hands of a single private company. It doesn't matter who owns it, if it's Musk or someone else, the fact that it's at the whims of a private company, is the primary channel for discourse, and is something legislatures cannot even comprehend because of their age, should have alarm bells going off. Coupled w…

> the primary channel for discourse Primary for whom? If you polled 50 people on the streets of NYC, I bet fewer than 3 would say they actively use twitter. Now do the same for Des Moines, IA and you maybe get 1?

When twitter logos, accounts, and quotes show up on CNN, Fox, MSNBC etc, it's a primary channel for discourse, even of most people are just lurkers.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#526

Earlier quoted context omitted.

> If the executives did not make a meaningful effort to count them They've been filing their methodology for bot counting with the SEC since 2013. If they're not making a "meaningful effort" and it materially affected the stock price in some way, either the SEC or a shareholder would have gone "HOLD ON SHENANIGANS O'CLOCK", surely? It can't be that the entire world was A-OK with Twitter's bot counting until June 2022…

How is it any harder than giving users a captcha?

Captcha solvers exist and are quite accessible. If solving the problem of bots would be as easy as showing a captcha, we would not have bot problems.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#527

Earlier quoted context omitted.

The specific worry about Net Neutrality was that ISPs would use their monopoly power to censor specific sources and/or self-preference their own businesses. It's something that should have been expanded to large online platforms rather than being disposed of entirely.

As you said, it was a worry, but ending Net Neutrality about enforcing government censorship was never even an argument being made at all by any sides of the issue.

Justice Brett Kavanaugh[0] argued that Net Neutrality specifically violated the 1st Amendment because Comcast should decide what speech they do and don't retransmit.

[0] https://techcrunch.com/2017/05/01/judge-argues-net-neutralit...

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#528

Earlier quoted context omitted.

A security concern for the governments, not twitter. It's not twitter's fault that governments are using it as a primary form of communication, nor should it be their responsibility to have amazing uptime just because governments are using their platform.

It's a national security concern (and international?) if Twitter can be compromised by nefarious actors and/or brought down via said compromised access. The idea that this isn't worthy of whistleblowing because Twitter is a corporation is insane. There are countless examples in the last year of Twitter being used for communication during a crisis.

That's ridiculous. If I created a service and the government happened to start using it, my service being taken down should not be labeled a national security issue against me. The national security issue would be the government deciding to rely on my service.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#529

Earlier quoted context omitted.

Oh wait, we already had that, and then we centralized and monopolized the hell out of it [0] [0] https://staltz.com/the-web-began-dying-in-2014-heres-how.htm...

That's because decentralized networks are expensive and can't handle spam unless you make receiving messages opt-in, and then you can't @ people like you can on Twitter.

We had, and still have, standards to deal with crossplatform messaging, like Jabber or Matrix.

What prevents that from catching on at scale is, the "big boys", like MS, FB or Google, mostly not playing ball and never implementing these in their own messaging platforms, to keep their gardens neatly walled from each other.

As intraplatform exchange is not really in-line with what most of these platforms are striving for these days; Interactions with their own platforms and the advertisers on it.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#530
post #3

This excerpt is frightening: > About half of the company's 500,000 servers run on outdated software that does not support basic security features such as encryption for stored data or regular security updates by vendors

Why bother hacking Twitter when it'd be cheaper to bribe an employee to get all the information you want: > allows too many of its staff access to the platform's central controls and most sensitive information without adequate oversight It'd be even easier if you find an employee who's on the same political team as you.

Or worse:

https://www.usnews.com/news/technology/articles/2022-08-23/i...

Post reply on HN