Earlier quoted context omitted.
It's common in lots of software - a form of a "su" command that lets you assume all aspects of a particular user. Usually developed for testing purposes (easiest way to reproduce a problem, after all) and prevents password-sharing. But it can obviously be used for evil, and so it should be heavily logged and flagged.
But the comment says that users wouldn't even see posts from the Twitter employee assuming their account in their own timeline. What legitimate purpose would that serve?
Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies
601–610 of 645 posts
Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies
#602Earlier quoted context omitted.
Always been a fan of "Heavy Industries".
Yup. I've used that with my normal "last name backwards" company name before. I tend to send Christmas and Birthday gifts to siblings with the company field filled in. "Kinetics," "Orbital Bombardment Division," "Relativistic Research," and assorted other things have made their way in, but "Heavy Industries" just has such a nice ring to it.
Such a 5-year old boy way of naming things.
Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies
#603Earlier quoted context omitted.
What like calling a first responder a pedophile?
Thats a major error in judgement. Even billionaires are capable of this
That’s not a “major error in judgement”. That’s the behavior of a completely deranged individual.
Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies
#604Earlier quoted context omitted.
So, in simpler words, they are indeed a pseudo-monopolistic (pseudo means apparent, something very close to but not quite there) social media giant that can indeed censor millions (10% of USA's population is 30 millions) arbitarily and at will ? Ok :) And whether a bakery serves your gay wedding or not is perhaps the most petty and inconsequential thing to be upset about. There are thousands upon thousands of bakerie…
Again, it set a legal precedent and it's a restriction on freedom there shouldn't be a threshold to care
Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies
#605Earlier quoted context omitted.
Not exactly. The CNN article doesn't say that, and The Verge's piece[1] on this puts it together pretty clearly. >Zatko was fired by Twitter in January and claims that this was retaliation for his refusal to stay quiet about the company’s vulnerabilities. Last month, he filed a complaint with the Securities and Exchange Commission (SEC) that accuses Twitter of deceiving shareholders and violating an agreement it made…
From the complaint (pg 9): > Please note that Mudge began preparing these disclosures in > early March 2022, well before Mr. Musk expressed any > interest in acquiring Twitter, and has not communicated > these disclosures to anyone with a financial interest > in Twitter. Why debate what the timelines implied by various articles are when the primary source is available and makes a clear statement on this matter?
Probably because most of us in the chain you're replying to didn't have the time to read an 84-page source document in the middle of a work day (note the time of our comments and how late to this particular chain you are), hoping that a nugget of information like that would be dropped pretty early on in it. Hence my edit at the end, which I had hoped would have made it clear that I was open to being corrected.
But thank you so much for that snarky comment while you clarified things. You're so much better than us for finding that, how could we have ever been so daft? Forgive us?
Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies
#606Earlier quoted context omitted.
+1. Additionally IP addresses, email and phone numbers can be extremely sensitive if leaked, so security is absolutely paramount. Case in point: imagine the risk to activists or journalists in heavily censored countries.
Please name one time in the history of TCP/IP that leaked IP addresses led to anything at all.
Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies
#607The whistleblowing case is a new dimension. To me as an outsider it implies Agrawal may have also been the manager in his previous technical role for a lot of the tech problems Zatko identified, and what made Agrawal CEO was his ability to leverage these problems to play ball with all the interests in that company and board, while sustaining through neglect some of those concerning practices within the organization.…
> They needed a steady hand who wouldn't be vulnerable to being swayed by principle.
That's my golden quote of the day, time for bed.
Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies
#608Earlier quoted context omitted.
A security concern for the governments, not twitter. It's not twitter's fault that governments are using it as a primary form of communication, nor should it be their responsibility to have amazing uptime just because governments are using their platform.
It's a national security concern (and international?) if Twitter can be compromised by nefarious actors and/or brought down via said compromised access. The idea that this isn't worthy of whistleblowing because Twitter is a corporation is insane. There are countless examples in the last year of Twitter being used for communication during a crisis.
You can watch it live in 2024, when all of social media has morphed into TikTok clones.
Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies
#609The "whistleblower" is Mudge? Ok, I didn't care before, but if Mudge is putting his reputation on the line, this is probably actually serious and legit. Literally the entire security community knows and looks up to Mudge. If anyone finds out that anything he said was bullshit, it will get blasted from the rooftops and he'll become a laughing stock. He would have to want the rest of his career to be working for morons…
Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies
#610Earlier quoted context omitted.
What scenario would justify that feature existing though? Why would they need to make posts from arbitrary accounts?
It's common in lots of software - a form of a "su" command that lets you assume all aspects of a particular user. Usually developed for testing purposes (easiest way to reproduce a problem, after all) and prevents password-sharing. But it can obviously be used for evil, and so it should be heavily logged and flagged.
This is a clear breach of infosec if there's a $#%*# su to post as Waldo and Waldo can't see that post.
In fact it seems ONLY possible to do _evil_ with that feature.