Live data from Hacker News

Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

cnn.com

531–540 of 645 posts

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#531
post #291

The whistleblowing case is a new dimension. To me as an outsider it implies Agrawal may have also been the manager in his previous technical role for a lot of the tech problems Zatko identified, and what made Agrawal CEO was his ability to leverage these problems to play ball with all the interests in that company and board, while sustaining through neglect some of those concerning practices within the organization.…

Part of the allegation seems to be that the beneficiaries may be foreign state actors who have infiltrated the organization. Not particularly shocking as they'd have to be incompetent to not try to infiltrate a major communications platform, and if the internal controls are as bad as alleged (and has exposed in some of the prior hacks, e.g. the control panel screenshots) they'd have to be incompetent to fail.

A friend I trust quit after being at twitter only a few weeks specifically because of the atrocious lack of internal security controls. When I spoke to them the first thought I had was “this sounds like a gold mine for spies”, so this story today makes perfect sense to me.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#532

> FOREIGN THREATS: Twitter is exceptionally vulnerable to foreign government exploitation in ways that undermine US national security, and the company may even have foreign spies currently on its payroll, the disclosure alleges. This is a very strange article to me. When I think of Twitter and government influence, I think of the overwhelming pro-Washington bias. I think of the "state-affiliated media" tags that some…

>I think of the "state-affiliated media" tags that somehow don't apply to RFE/RL and BBC.

More importantly they don't point out things like CNN being owned by AT&T. Ever wonder why CNN doesn't cover why AT&T can be so awful? There's your answer. MSBNC is owned by this massive entertainment conglomerate: https://en.wikipedia.org/wiki/NBCUniversal_Television_and_St... CBS is owned by this entertainment conglomerate: https://en.wikipedia.org/wiki/List_of_assets_owned_by_Paramo... ABC is owned by Disney (wonder why their copyright pushing insanity is never covered negatively there?

Most people seem to assume that mainstream news is just an independent journalistic organization beholden only to itself, that truth is important, and delivering the news to the viewers are priorities. Something that is wildly untrue for almost all of them. Their corporate owned and those corporations have their own agendas that aren't aligned with the average American in the slightest.

>I think of the countless heterodox/dissident accounts that have been banned or silenced on the platform.

They banned satire accounts for wrongthink.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#533

Earlier quoted context omitted.

I read the full whistle-blower complaint, and the whole story from his perspective (and the crazy statement from Agrawal) looks like it's not B. Instead, it looks like it was a culture clash with his manager. He seems to have tried to escalate things to people above Agrawal nearly constantly. He was hired by Jack Dorsey, and felt accountable to him and to the board, but he reported to Agrawal, who believed that Mudge…

> I read the full whistle-blower complaint The content of the complaint is all that matters, and it should be judged on its own merits. It never matters who said what, and attempting to make it matter is ad hominem fallacy; it is what is said that matters. That said, I can't quite fathom why Twitter's cybersecurity matters any more than the cybersecurity of any of the myriad of online forums, HN included: the "data"…

The algorythms are not public, and as the public square of present, Twitter essentially drives public discourse... especially when a large portion of the legacy media has been reduced to sourcing their stories and directly quoting from Twitter.

Secondly, private messages between people are not public either. Opening that data up or allowing it to be read or manipulated by other entities will drive a lot of outrage and the data contained within is important!

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#534

Earlier quoted context omitted.

They are intentionally vague for legal and security reasons.

What legal and security reasons exactly?

They could probably sue him under his employment contract for breach of confidentiality

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#535

Millenials and GenZ may have no idea who Mudge is. I, however, almost lost my first job out of college at a bank because I ran l0phtcrack against our Windows NT 4 server to see if it could crack passwords. I showed my boss, and he pulled me aside into another room and tore my head off for irresponsibly running this tool against a production server. He said I could have been fired if this got out, but he covered my as…

I did the same thing on a server for a major department store chain in the '90s. I booted a Linux diskette and copied the SAM file to it. I also ran l0phtcrack, or John the Ripper on a 486 (?) PC in my apartment. I think I bought a rainbow table and something else to expand the iterations it would use on the hashes. I let it run for over a week and had a couple of thousand clear passwords. This was for every store we…

So you copied the auth file off company servers

and cracked it on personal systems

and you kept the files and cracked passwords? Not just kept around, but archived?

Dude.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#536

Millenials and GenZ may have no idea who Mudge is. I, however, almost lost my first job out of college at a bank because I ran l0phtcrack against our Windows NT 4 server to see if it could crack passwords. I showed my boss, and he pulled me aside into another room and tore my head off for irresponsibly running this tool against a production server. He said I could have been fired if this got out, but he covered my as…

Actions speak louder than words. For him to file this complaint now, after Musk pulled out of his Twitter purchase, makes any truthful statements pretty low value to Musk’s case. Does Twitter need better security? Yeah. Will Twitter get embarrassed? Yeah? Will this testimony show Musk completely miffed his due diligence while building up a huge loan package that would have sent most of Twitter’s revenue to debt servi…

This is incorrect. The complaint was filed _before_ musk even showed interest in Twitter

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#537
post #435
post #427

Earlier quoted context omitted.

Musk posted a meme explaining why he pulled out. https://twitter.com/elonmusk/status/1546344529460174849

granted, I'm not entirely certain Musk wants to pull out vs. getting a better price/discount on the purchase...

No post body was provided.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#538
post #120
post #36

Eh, you could take out Twitter and insert many other company names and it'll still hold true. And those companies hold so much more sensitive data about you than Twitter. I know of insurance companies that have help desk employees with domain admin access. And all crippling ransomware attacks take advantage lax permissions. This is rampant. How is this a story?

Because it's CNN and they like to make headlines with some bogus whistleblower that is concerned that some die-hard trumpers are going to hack top companies and create some kind of mass hysteria. Just the usual fear mongering in the news media to get views.

Hard to know where to start with this nonsense. Suffice it to say I'm impressed: every single part of what you just said is wrong.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#539

Earlier quoted context omitted.

If you read the document "Security Chief's Final Report to Twitter" on the Washington Post article ( https://www.washingtonpost.com/technology/interactive/2022/t... ), you will see that 'god mode' just means they have IPMI access to servers.

"just"? What percentage of Google engineers do you think have IPMI access to servers?

Yeah I’m not sure the “just” is justified, and it’s not good but it’s certainly different than being able to send tweets as a particular user. IPMI access was typically only given to SREs.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#540
post #148

Twitter CEO's response to employees which denies none of the claims made by CNN & WaPo* https://twitter.com/donie/status/1562069281545900033 * https://www.washingtonpost.com/technology/interactive/2022/t... edit: the PDFs from * https://www.washingtonpost.com/technology/interactive/2022/t... https://www.washingtonpost.com/technology/interactive/2022/t... https://www.washingtonpost.com/technology/interactive/2022/t...…

Page 9/84 in the "whistleblower_disclosure.pdf" are about Elon Musk's claims of fake twitter accounts and bots. Good lord, this does not look pretty for Twitter.

Having skimmed that section, it hurts, not helps Musk. It's basically complaining that Twitter is prioritizing accurate, quantifiable metrics that directly impact finances over woolly, unquantifiable "platform health." Worse, executives are motivated to be honest about their metrics!

He's complaining that Twitter isn't measuring what he wants it to measure, which doesn't help, because it isn't saying that Twitter is actually lying about its metrics (and, as noted, it's indirectly implying that Twitter isn't lying).

Post reply on HN