Live data from Hacker News

Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

cnn.com

591–600 of 645 posts

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#591
post #421

Earlier quoted context omitted.

I dunno, pointing out that something has a poor architecture and pointing out that something has severe, known, and ignored security issues feels different.

Availability is the A in the CIA triad. DR and resilience in general is part of security.

That's never actually the case in an org chart, though. A CISO may require that a DR plan exists, but they're not the ones in charge of implementing it.

Also, if they can handle a primary datacenter outage, they have a working DR plan. If I was working on an infrastructure team and was told I needed to handle multiple, simultaneous datacenter outages, I'd start looking for another job.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#592
post #346

Earlier quoted context omitted.

I don't know Mudge and neither does 99.9% of the public. His timing here is suspect. If these problems existed for so long, why now?

He just got fired in January. Preparing a 200-page legal document with references and accounts takes time. It had been submitted some time ago, it's only now that CNN got a hold of a copy.

A 200 page document may take some time, but we don't know how the document is even formatted. Have they even released a copy? It could be 200 pages but only 20 pages of basic accusations with no real details for all we know, just pandering to congress and a bunch of email threads trying to indicate something without any context. I still would advise everyone to withhold judgement at this time.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#593

Earlier quoted context omitted.

What legal and security reasons exactly?

They could probably sue him under his employment contract for breach of confidentiality

We won't know until we see the documents. Right now it is a bunch of basic accusations that don't provide much depth.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#594
post #576

Earlier quoted context omitted.

If Musk actually believes this represents anything it puts his IQ in the single digit - low double digits range.

So what you're saying is that an idiot can become the richest man in the world without being born into it? How often has that happened in the entire history?

[deleted]

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#595

Earlier quoted context omitted.

I read the full whistle-blower complaint, and the whole story from his perspective (and the crazy statement from Agrawal) looks like it's not B. Instead, it looks like it was a culture clash with his manager. He seems to have tried to escalate things to people above Agrawal nearly constantly. He was hired by Jack Dorsey, and felt accountable to him and to the board, but he reported to Agrawal, who believed that Mudge…

> He was hired by Jack Dorsey, and felt accountable to him and to the board, but he reported to Agrawal, who believed that Mudge had a responsibility to follow the chain of command very rigidly. With $10mm cash bonuses on the table it’s extremely obvious why Agrawal would insist on being MITM

Would Agrawal get cash bonuses? If ... Under what conditions? (Anywhere to read about that?)

Aha, eg:

https://www.dailymail.co.uk/news/article-10258453/Twitters-n...

So his performance bonuses is more than 10x his salary - incentives to fake good numbers and hide the bad stuff, indeed!

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#596

Earlier quoted context omitted.

It's a national security concern (and international?) if Twitter can be compromised by nefarious actors and/or brought down via said compromised access. The idea that this isn't worthy of whistleblowing because Twitter is a corporation is insane. There are countless examples in the last year of Twitter being used for communication during a crisis.

That's ridiculous. If I created a service and the government happened to start using it, my service being taken down should not be labeled a national security issue against me. The national security issue would be the government deciding to rely on my service.

For all the first amendment protectors out there - the government forcing a private company to comply with some mythical security / uptime standard so it can propagandise its population - that is an actual violation.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#597
post #561

Earlier quoted context omitted.

That's because decentralized networks are expensive and can't handle spam unless you make receiving messages opt-in, and then you can't @ people like you can on Twitter.

You can @ people on Mastodon with @user@domain.tld. I have yet to receive spam on my Mastodon or XMPP address (which I treat like my telephone number).

To have spam, you must first have users.

My can and string communications network doesnt have any spam either.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#598
post #569

Earlier quoted context omitted.

I saw this happen live and I couldn't believe it. There was this Netflix movie last year called "Kate" that has a white female assassin killing a lot of asian people (it takes place in Tokyo). There were a handful of articles (first in places like Yahoo news and then sites like Slate.com) written about how this is racist and they all quoted people on twitter. Since I was following this movie heavily, I saw the tweets…

It’s hard to read your comment, and the zeitgeist, and then conclude a nonviolent end is the most likely outcome. These aren’t ideas that can be peacefully mediated.

There might be a huge wave of people just ignoring online news and deleting social media(ie. disconnecting). That could very well be the end state for many people. In the above example, if the tweet authors had restricted their account visibility to people only they know, then possibly the articles would never have been written. If enough people get burned out they might just walk away.

Ironically the white female actress who plays the assassin in the film: Mary Elizabeth Winstead was herself a victim of massive online targeting and harassment.

She had already once deleted her public accounts in protest after the famous iCloud hacks in the early 10s because people were ogling her private nude photos and then harassing her about it after she scolded "the internet". She came back a few years later only to delete everything all over again in 2017 when she got non stop barrage after she went through a bad divorce. Its tough for actors who are in the business of selling themselves to just walk away from all public social media.

I think people who weren't into tech and who came of age before the internet became mainstream might be the first people to disconnect from this social media nonsense. She was early 80s and homeschooled to focus all her waking moments on becoming an actress. Gen-Z/Alpha might never disconnect. Have they ever known anything different? It will be interesting to see what happens.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#599

OK, so their security is a mess, as many commenters have pointed out, they are one of many companies. What I can't figure out is what's this guy's beef that he went revealing all this? Was he fired or demoted or something and thought to get his own back?

Why assume the whistleblowing was done for negative reasons?

There's the beef https://www.bloomberg.com/news/articles/2022-08-23/twitter-w...

He was fired January last for alleged poor performance. Totally can see now why it's all come to light, less the altruistic urge to make things secure, and more the old case of flipping the bird to a former boss.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#600
post #559

Earlier quoted context omitted.

Can you elaborate? I'm very curious how they develop software.

Without getting into details, AFAICT they do not use any typical high-assurance software stacks, such as Ada or Spark or such that might be typical in avionics, like Airbus software. The use off-the-shelf tools like C++ and LLVM.

Not to rain on your parade, but neither do any of the other automotive companies. Ada and SPARK is amazing, but I don't think I've seen it used outside aerospace/defence.
Post reply on HN