This excerpt is frightening: > About half of the company's 500,000 servers run on outdated software that does not support basic security features such as encryption for stored data or regular security updates by vendors
Wasn't it them that had a bug that exposed users' passwords in plain text a few years back?
Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies
541–550 of 645 posts
Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies
#542Earlier quoted context omitted.
> B) a strong tech hire who can’t lead a program. I worked with Mudge (not super close, but enough to see how he worked across teams etc) and can certainly say this is not the case. At least when I saw him Mudge was excellent at the program leadership aspect of his role. At one point he ended up a DARPA PM. You can't go from L0pht to DARPA without getting really good at working with other people and leading projects.…
The subject of security consultants, security departments, and whistleblowing seems to me to be of particular concern. I mean, if an auditor publicly reports an audit finding that is ignored by the company and his ethics demand its reporting, is he branded a "whistleblower"? I do not think so, instead it is an "auditor finding". Why does that not apply here? It kind of dovetails with how pathetically organized IT in…
[0] Companies want the letter to say whatever their regulators and/or contractual obligations demand that it say.
Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies
#543Earlier quoted context omitted.
> If the executives did not make a meaningful effort to count them They've been filing their methodology for bot counting with the SEC since 2013. If they're not making a "meaningful effort" and it materially affected the stock price in some way, either the SEC or a shareholder would have gone "HOLD ON SHENANIGANS O'CLOCK", surely? It can't be that the entire world was A-OK with Twitter's bot counting until June 2022…
> They've been filing their methodology for bot counting with the SEC since 2013. No, they haven’t. They describe at a very high level the amount of sampling they do (100 accounts a day? Really, that’s it?), but don’t discuss the methodology used, such as what they use as signals and indicators of botness. That’s not “filing their methodology“, it’s covering their arses.
Today's question on your statistics 101 exam:
You have a population of 100 million people. You estimate that the true probability of some statistic is about 5%. What sample size do you need to be 95% sure that you are within 5% of the correct answer? Answer: 73.
(No really, this kind of question is absolutely going to be in a Stats 101 class. And sample sizes really don't need to be that big to be accurate.)
Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies
#544I've been hearing about Mudge for decades . It's actually a bit ... heartbreaking ... to see him looking so corporate, but we all age, don't we? I doubt he was fired for being bad at his job. But I'll bet he was fired for getting in people's faces. That was basically his calling card for years . Why is anyone surprised? I guess Twitter thought they could hire the cachet, without hiring the man. I remember an Apple WW…
Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies
#545Earlier quoted context omitted.
I agree. I grant It’s possible Mudge is A) an old hand and doesn’t know how to run a security program with the tech today B) a strong tech hire who can’t lead a program. But Mudge is still… Mudge, and he’s also proven his ability to collaborate so if he was a bull in a china shop a twitter, that would be surprising. There’s also a broader trend here of well known security leads that originate from that time working a…
I read the full whistle-blower complaint, and the whole story from his perspective (and the crazy statement from Agrawal) looks like it's not B. Instead, it looks like it was a culture clash with his manager. He seems to have tried to escalate things to people above Agrawal nearly constantly. He was hired by Jack Dorsey, and felt accountable to him and to the board, but he reported to Agrawal, who believed that Mudge…
Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies
#546I've been hearing about Mudge for decades . It's actually a bit ... heartbreaking ... to see him looking so corporate, but we all age, don't we? I doubt he was fired for being bad at his job. But I'll bet he was fired for getting in people's faces. That was basically his calling card for years . Why is anyone surprised? I guess Twitter thought they could hire the cachet, without hiring the man. I remember an Apple WW…
That sounds like an interesting story about Ken Kesey, but I can't find any references to it. Have a source?
I'll see if there's any kind of historical document. Apple's earlier WWDCs were not the high-production-value events that you see these days.
They often had celebrities give keynotes and speeches. They had Douglas Adams and Harry Anderson.
Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies
#547Earlier quoted context omitted.
I did the same thing on a server for a major department store chain in the '90s. I booted a Linux diskette and copied the SAM file to it. I also ran l0phtcrack, or John the Ripper on a 486 (?) PC in my apartment. I think I bought a rainbow table and something else to expand the iterations it would use on the hashes. I let it run for over a week and had a couple of thousand clear passwords. This was for every store we…
So you copied the auth file off company servers and cracked it on personal systems and you kept the files and cracked passwords? Not just kept around, but archived? Dude.
Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies
#548Earlier quoted context omitted.
I’m a huge musk fan, but I still think his trying to get out of the Twitter deal is lame buyer's remorse and his arguments are weak. I see it as mostly unrelated to this mudge issue.
Never been a "fan" of a personality, but I used to really like Tesla and SpaceX, but after hearing a little about how their critical software is...not developed like critical software...I am very wary of what kind of engineering is going over there. With Musk deciding to amp up his celebrity with Twitter antics, I just can't respect him any more.
Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies
#549Earlier quoted context omitted.
That sounds like an interesting story about Ken Kesey, but I can't find any references to it. Have a source?
Well, I was there. I think they had the party in some offsite venue. I remember a courtyard, with the Magic Bus, parked in it. I'll see if there's any kind of historical document. Apple's earlier WWDCs were not the high-production-value events that you see these days. They often had celebrities give keynotes and speeches. They had Douglas Adams and Harry Anderson.
It was pretty campy. The staff dressed up in tie-dyes (and some had wigs), and handed us strings of beads, as we came in.
Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies
#550Earlier quoted context omitted.
Yeah - comparing mudge's history with the email the Twitter CEO sent to internal employees and the situation seems crazy? Always hard to know from the outside, but this paired with Jack leaving seemingly frustrated with the board looks really bad. I know people have thought Twitter was mismanaged for a while, but seems like it's a lot worse than I thought it was (and the CEO seems more vindictively bad than I would h…
Yeah, I think we're in lockstep here. I'm no fan of Musk (he's truly worked very hard to be the most provacatively pustulent punkass of tech) but that doesn't mean that Twitter leadership is any better. Just not as well PR'd. Dorsey himself was mostly an imbecile who drank too much of his own Kool Aid. Twitter has for years been the standard bearer for the most opaque, and incoherent content management; from user fee…
I tend to like people that blow up social norms and conventions