Live data from Hacker News

Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

cnn.com

571–580 of 645 posts

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#571
post #3

This excerpt is frightening: > About half of the company's 500,000 servers run on outdated software that does not support basic security features such as encryption for stored data or regular security updates by vendors

I suspect this will be the norm going forward.

Big tech was taken over by bean counters long ago, the fact that it’s all running on duct tape and popsicle sticks under the hood will come back to bite us when we have a digital Pearl Harbor event.

China will invade Taiwan and the first shot won’t be physical, it will be activating the 30 years of assets they grew in AWS/GCP/cloudfare/level3/AT&T/Etc

Most of their HR/engineering departments are completely retarded. They’ll hire any H1B who passes l33t code that accepts $50k under market rate then give them repo access in a few weeks. Our soulless megacorps are beyond easy to penetrate by hostile intelligence.

The CIA/NSA/FBI, you know the groups who we pay billions per year for and they take half my income to fund will of course not catch any of this.

The FBI is too busy manufacturing domestic terrorist, the NSA is too busy hacking American companies, and the CIA is too busy importing drugs to actually secure our country from foreign attack. Why? Because it’s been so long since we were actually attacked they believe it can’t happen so why not loot Rome in the mean time?

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#572
post #384

Earlier quoted context omitted.

I met Mudge once in my career early on (I was at VA Linux systems circa 1999ish) and I found him intense, an apex intellect, but absolutely affable and self-aware. He never struck me then, or in any interview or write up since, that he's impulsive, or prone to taking actions like what he's done to Twitter, in a cavalier way. He saw something bad and thinks something should be done to address it. He likely made that d…

Yeah - comparing mudge's history with the email the Twitter CEO sent to internal employees and the situation seems crazy? Always hard to know from the outside, but this paired with Jack leaving seemingly frustrated with the board looks really bad. I know people have thought Twitter was mismanaged for a while, but seems like it's a lot worse than I thought it was (and the CEO seems more vindictively bad than I would h…

> Plus the total lack of principles around speech and just doing whatever Russia, India, or KSA wants?

Twitter is most definitely not doing whatever Russia wants. It's markedly hostile to Russia and frequently removes "pro-Russia" acocunts, which speaks to your initial point, that it has a total lack of principles around speech.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#573
post #91
post #3

This excerpt is frightening: > About half of the company's 500,000 servers run on outdated software that does not support basic security features such as encryption for stored data or regular security updates by vendors

I think it's also important to recognize how much of a "check the box" security control encryption at rest has become for many vendors/GRC teams. A lot of times, the encryption at rest control only has the capability to prevent somebody from physically detaching the disk and trying to mount it with their own machine and access the data that way. In a world where many companies now run their workloads on public cloud…

Finally, someone points out the emperor has no clothes. When customers first started requesting encryption at rest, it didn’t make any sense to me — the threats it mitigates aren’t worth worrying about if you’re using public cloud.

So it is just a checkbox then.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#574
post #314

Is it just me, or does some of this feel less whistleblower-y and more petty? For example: > The company also lacks sufficient redundancies and procedures to restart or recover from data center crashes, Zatko's disclosure says, meaning that even minor outages of several data centers at the same time could knock the entire Twitter service offline, perhaps for good. That said, this is Mudge. I have a lot of respect for…

Ah yes - the minor outage of several data centers...

Next you'll tell me that Twitter would't survive global thermonuclear war.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#575
Call me paranoid but this is just too convenient.

In the next two months we have Elon’s Twitter trial where he’s expected to get railed. Despite waiving due diligence in his commitment to purchase Twitter he’s repeatedly made the claim without evidence that Twitter has made material misrepresentations about bots to him and investors. That would be fraud if true.

So right before the trial a “whistleblower” comes forward and makes claims that support Elon’s narrative. Weird. It’s just a little too convenient for me not to be at least skeptical.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#576
post #427

Earlier quoted context omitted.

Musk posted a meme explaining why he pulled out. https://twitter.com/elonmusk/status/1546344529460174849

If Musk actually believes this represents anything it puts his IQ in the single digit - low double digits range.

So what you're saying is that an idiot can become the richest man in the world without being born into it?

How often has that happened in the entire history?

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#577

Earlier quoted context omitted.

Did you read the article before slinging mud yourself? The whistleblower has been communicating with DC way before EM entered the picture. Media only got its hands on the leaked material now.

Not exactly. The CNN article doesn't say that, and The Verge's piece[1] on this puts it together pretty clearly. >Zatko was fired by Twitter in January and claims that this was retaliation for his refusal to stay quiet about the company’s vulnerabilities. Last month, he filed a complaint with the Securities and Exchange Commission (SEC) that accuses Twitter of deceiving shareholders and violating an agreement it made…

From the complaint (pg 9):

  > Please note that Mudge began preparing these disclosures in
  > early March 2022, well before Mr. Musk expressed any 
  > interest in acquiring Twitter, and has not communicated 
  > these disclosures to anyone with a financial interest 
  > in Twitter.
Why debate what the timelines implied by various articles are when the primary source is available and makes a clear statement on this matter?

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#578

> FOREIGN THREATS: Twitter is exceptionally vulnerable to foreign government exploitation in ways that undermine US national security, and the company may even have foreign spies currently on its payroll, the disclosure alleges. This is a very strange article to me. When I think of Twitter and government influence, I think of the overwhelming pro-Washington bias. I think of the "state-affiliated media" tags that some…

There's been at least one Saudi spy found working at Twitter and convicted: https://nypost.com/2022/08/09/ex-twitter-employee-ahmad-abou... > Saudi citizen Ali Alzabarah, who worked as an engineer at Twitter, used their positions to access confidential Twitter data about users, their email addresses, phone numbers and IP addresses, the latter of which be used to identify a user’s location Internal data security pract…

The line between "spy" and foreign-lobby operative is pretty blurry when it comes to KSA/Israel/etc. Look at Jonathan Pollard.

I would be surprised if there were an actual Chinese/Russian/Iranian spy working at Twitter.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#579

Earlier quoted context omitted.

What like calling a first responder a pedophile?

Thats a major error in judgement. Even billionaires are capable of this

Doubling down is worse than error in judgement.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#580
post #120
post #36

Eh, you could take out Twitter and insert many other company names and it'll still hold true. And those companies hold so much more sensitive data about you than Twitter. I know of insurance companies that have help desk employees with domain admin access. And all crippling ransomware attacks take advantage lax permissions. This is rampant. How is this a story?

Because it's CNN and they like to make headlines with some bogus whistleblower that is concerned that some die-hard trumpers are going to hack top companies and create some kind of mass hysteria. Just the usual fear mongering in the news media to get views.

Just type the word mudge into Google. ‘Bogus whistleblower’ tho
Post reply on HN