Live data from Hacker News

Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

cnn.com

601–610 of 645 posts

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#601

Earlier quoted context omitted.

It's common in lots of software - a form of a "su" command that lets you assume all aspects of a particular user. Usually developed for testing purposes (easiest way to reproduce a problem, after all) and prevents password-sharing. But it can obviously be used for evil, and so it should be heavily logged and flagged.

But the comment says that users wouldn't even see posts from the Twitter employee assuming their account in their own timeline. What legitimate purpose would that serve?

I would assume some kind of "don't disturb the user while testing" but if everyone else sees them ...

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#602
post #317

Earlier quoted context omitted.

Always been a fan of "Heavy Industries".

Yup. I've used that with my normal "last name backwards" company name before. I tend to send Christmas and Birthday gifts to siblings with the company field filled in. "Kinetics," "Orbital Bombardment Division," "Relativistic Research," and assorted other things have made their way in, but "Heavy Industries" just has such a nice ring to it.

I love that Wikipedia says it covers "large and heavy products" and/or "large and heavy equipment".

Such a 5-year old boy way of naming things.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#603

Earlier quoted context omitted.

What like calling a first responder a pedophile?

Thats a major error in judgement. Even billionaires are capable of this

The man injected himself into an ongoing crisis he had little insight into, and when rejected, his ego was so hurt that he used his influence to accuse individuals he knew nothing about if pedophilia, all while they were in the midst of trying to rescue a dozen children from imminent death.

That’s not a “major error in judgement”. That’s the behavior of a completely deranged individual.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#604

Earlier quoted context omitted.

So, in simpler words, they are indeed a pseudo-monopolistic (pseudo means apparent, something very close to but not quite there) social media giant that can indeed censor millions (10% of USA's population is 30 millions) arbitarily and at will ? Ok :) And whether a bakery serves your gay wedding or not is perhaps the most petty and inconsequential thing to be upset about. There are thousands upon thousands of bakerie…

Again, it set a legal precedent and it's a restriction on freedom there shouldn't be a threshold to care

It has to be an impressive kind of hypocrisy to panic about individuals refusing to associate with individuals out of their own free will and freak out hysterically about "restrictions on freedom"... then turn around and cheer on massive corporations censoring individuals with no oversight or recourse.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#605

Earlier quoted context omitted.

Not exactly. The CNN article doesn't say that, and The Verge's piece[1] on this puts it together pretty clearly. >Zatko was fired by Twitter in January and claims that this was retaliation for his refusal to stay quiet about the company’s vulnerabilities. Last month, he filed a complaint with the Securities and Exchange Commission (SEC) that accuses Twitter of deceiving shareholders and violating an agreement it made…

From the complaint (pg 9): > Please note that Mudge began preparing these disclosures in > early March 2022, well before Mr. Musk expressed any > interest in acquiring Twitter, and has not communicated > these disclosures to anyone with a financial interest > in Twitter. Why debate what the timelines implied by various articles are when the primary source is available and makes a clear statement on this matter?

>Why debate what the timelines implied by various articles are when the primary source is available and makes a clear statement on this matter?

Probably because most of us in the chain you're replying to didn't have the time to read an 84-page source document in the middle of a work day (note the time of our comments and how late to this particular chain you are), hoping that a nugget of information like that would be dropped pretty early on in it. Hence my edit at the end, which I had hoped would have made it clear that I was open to being corrected.

But thank you so much for that snarky comment while you clarified things. You're so much better than us for finding that, how could we have ever been so daft? Forgive us?

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#606

Earlier quoted context omitted.

+1. Additionally IP addresses, email and phone numbers can be extremely sensitive if leaked, so security is absolutely paramount. Case in point: imagine the risk to activists or journalists in heavily censored countries.

Please name one time in the history of TCP/IP that leaked IP addresses led to anything at all.

Certainly lead to myself and other shitheads in my youth DoS'ing each other's dialup connections on IRC to settle arguments.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#607

The whistleblowing case is a new dimension. To me as an outsider it implies Agrawal may have also been the manager in his previous technical role for a lot of the tech problems Zatko identified, and what made Agrawal CEO was his ability to leverage these problems to play ball with all the interests in that company and board, while sustaining through neglect some of those concerning practices within the organization.…

Ooof...

> They needed a steady hand who wouldn't be vulnerable to being swayed by principle.

That's my golden quote of the day, time for bed.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#608

Earlier quoted context omitted.

A security concern for the governments, not twitter. It's not twitter's fault that governments are using it as a primary form of communication, nor should it be their responsibility to have amazing uptime just because governments are using their platform.

It's a national security concern (and international?) if Twitter can be compromised by nefarious actors and/or brought down via said compromised access. The idea that this isn't worthy of whistleblowing because Twitter is a corporation is insane. There are countless examples in the last year of Twitter being used for communication during a crisis.

Ludicrous, but this is the situation... holy cow, imagine a future where TikTok likes, determine the outcome of an election.

You can watch it live in 2024, when all of social media has morphed into TikTok clones.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#609

The "whistleblower" is Mudge? Ok, I didn't care before, but if Mudge is putting his reputation on the line, this is probably actually serious and legit. Literally the entire security community knows and looks up to Mudge. If anyone finds out that anything he said was bullshit, it will get blasted from the rooftops and he'll become a laughing stock. He would have to want the rest of his career to be working for morons…

Indeed... the "fired for poor performance" is about the biggest red flag, and a clear euphamism for "fired for user centric principles."

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#610
post #158

Earlier quoted context omitted.

What scenario would justify that feature existing though? Why would they need to make posts from arbitrary accounts?

It's common in lots of software - a form of a "su" command that lets you assume all aspects of a particular user. Usually developed for testing purposes (easiest way to reproduce a problem, after all) and prevents password-sharing. But it can obviously be used for evil, and so it should be heavily logged and flagged.

I worked in finance and we are brick-walled from real production data. There's obviously a way around it, but it is not a function you can pull out the company toolbox.

This is a clear breach of infosec if there's a $#%*# su to post as Waldo and Waldo can't see that post.

In fact it seems ONLY possible to do _evil_ with that feature.

Post reply on HN