Live data from Hacker News

Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

cnn.com

621–630 of 645 posts

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#621

Earlier quoted context omitted.

The subject of security consultants, security departments, and whistleblowing seems to me to be of particular concern. I mean, if an auditor publicly reports an audit finding that is ignored by the company and his ethics demand its reporting, is he branded a "whistleblower"? I do not think so, instead it is an "auditor finding". Why does that not apply here? It kind of dovetails with how pathetically organized IT in…

That's not really how auditors work. Auditors either give the client a letter saying what the client wants it to say[0] or decline to provide the client with that letter. They do not go public with their reasons. [0] Companies want the letter to say whatever their regulators and/or contractual obligations demand that it say.

If a public company gets an accounting audited and they find irregularities it is not subject to public disclosure requirements?

Twitter is a publicly held company.

I'm sure there are conflicts of interest and some degree of confidentiality for auditors and clients, but there is a fundamental public interest of disclosure, at a minimum to the government, in the event of irregularities.

From the SEC:

"In addition, we will continue to focus on auditors. As the Supreme Court noted nearly 30 years ago in U.S. v. Arthur Young & Co., 465 U.S. 805 (1984), auditors play a crucial role in the financial reporting process by serving as the “public watchdog.” So, it is important that we carefully monitor their work and ensure that they fully comply with their professional obligations. If there is a significant restatement or if we learn about improper accounting from a whistleblower, our proactive efforts, or the media, then you can expect that we will scrutinize not only the CEO, CFO and Controller, but also the engagement partner, engagement quality reviewer, and the auditing firm as a whole. We are going to probe the quality of the audit and determine whether the auditors missed or ignored red flags, whether they have proper documentation, and whether they followed professional standards.

    And it is important to remember that our ability to bring Rule 102(e) bars against auditors extends beyond instances where there are accounting irregularities at a public company.  Our Rule 102(e) program is remedial in nature and meant to protect the integrity of the Commission’s processes.  As a result, we can and have investigated auditors when their audits fail to meet the most basic standards, regardless of whether there was an actual problem with the auditing client. By pursuing actions over these bad audits, we can fully leverage the Division’s resources and close off access to those who shirk their responsibilities as gatekeepers to the securities markets." 

-------

From there you can see legal and institutional gravitas, ethics, and expectations of accountants and auditors of public companies. That's kind of what I'm getting at re: elevating security and certain IT roles to higher responsibility and codification.

Now, is this a smear attempt by Jack Dorsey in relation to the Elon Musk lawsuit? Eh, maybe.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#622

Earlier quoted context omitted.

> Say Twitter is completely overrun by foreign state actors who delete everything. That's not what's dangerous. Instead, dangerous things include manipulating the algorithms so that "news" of ones choice get lots of visibility. Then a foreign state can influence the elections

> Then a foreign state can influence the elections I think this is bollocks. 23% of Americans say they use Twitter. 61% of Americans voted in the last Presidential election. So with my bad math, say a foreign state somehow gets every possible Twitter users vote going their way, at best it's going bamboozle 14% of weak-minded Americans. That's at best , the perfect and unbeatable score. The reality is that most Twitte…

14%, even just 4%, is a lot, can be enough to decide an election. Often the parties are close to 50% each.

In addition to that, the manipulators / nation states don't attack only via Twitter, and, everything combined ...

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#623
post #569

Earlier quoted context omitted.

I saw this happen live and I couldn't believe it. There was this Netflix movie last year called "Kate" that has a white female assassin killing a lot of asian people (it takes place in Tokyo). There were a handful of articles (first in places like Yahoo news and then sites like Slate.com) written about how this is racist and they all quoted people on twitter. Since I was following this movie heavily, I saw the tweets…

It’s hard to read your comment, and the zeitgeist, and then conclude a nonviolent end is the most likely outcome. These aren’t ideas that can be peacefully mediated.

Except, one person telling someone else "I don't like " and other people responding with "Hey yeah I don't like too!" is literally how it has worked forever, even before computers. Newspapers have been running " BAD" or " GOOD" headlines with no or weak backing for literal centuries.

What about twitter makes this situation special?

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#624
post #613

Earlier quoted context omitted.

Of course he does. He's just grasping at straws to get out of the mess he's created for himself.

I don't know. If he did, I feel like he wouldn't have acted so impulsively in his solicitation and outlined that in his contract.

Musk has problems with impulse control. That's why he publicly called a literal hero of dying children a "pedophile". If he didn't have money he would likely not be able to keep friendships functional, because he doesn't know how to interact with other people in a healthy way.

I don't understand how you can look at his public behavior and think anything else. The only alternative is that he thought doing shitty things was a rational way to improve his situation, and I personally think that's a worse option

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#625

> FOREIGN THREATS: Twitter is exceptionally vulnerable to foreign government exploitation in ways that undermine US national security, and the company may even have foreign spies currently on its payroll, the disclosure alleges. This is a very strange article to me. When I think of Twitter and government influence, I think of the overwhelming pro-Washington bias. I think of the "state-affiliated media" tags that some…

> When I think of Twitter and government influence, I think of the overwhelming pro-Washington bias. And I think of AWS announcing a massive data loss, Kim-Jong Un tweeting "Nukes have been launched" and the US president tweeting about an impeding Yellowstone explosion. If you want to really f up the country in a big way, Twitter is a great way. With how much verification some journalists do, the news will have secon…

Trump's presidency should have made it very very clear that relying on a tweet for anything at all is a monumentally stupid idea, and the only reason someone isn't currently taking advantage of that reliance is that they don't think it's worth it to attack you in that way.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#626

Earlier quoted context omitted.

I’ve heard of similar things to this being discussed… Eg. simple things like tracking-busters where it randomly clicks links in headless chrome to fool the algorithm, p2p vpns where you use a random user’s IP address to randomize who made what request, etc. There is also a school of thought that you should periodically publish private keys for plausible deniability (“was it me, or did someone sign that after I publis…

Long live deliberate incompetence! Let's fill the world with a cloud of uncertainty.

It’s deliberate plausible deniability.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#627

Earlier quoted context omitted.

Quoted post unavailable.

An interesting statement in a thread about widespread security weaknesses.

Security weakness aren’t a problem if you limit yourself to MISRA C techniques. You don’t need modern languages.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#628

Earlier quoted context omitted.

The man injected himself into an ongoing crisis he had little insight into, and when rejected, his ego was so hurt that he used his influence to accuse individuals he knew nothing about if pedophilia, all while they were in the midst of trying to rescue a dozen children from imminent death. That’s not a “major error in judgement”. That’s the behavior of a completely deranged individual.

> completely deranged individual That's quite a large exaggeration. I can think of some much much worse things that an actual "completely deranged individual" would do. Musk was butthurt and lashed out. That does not equal "completely deranged individual"

"Musk was butthurt and lashed out. That does not equal "completely deranged individual" "

When you have the kind of audience and pull he has, unless you are totally daft to it (which he shows no sign of) then yes it's very abusively deranged.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#629
post #576

Earlier quoted context omitted.

So what you're saying is that an idiot can become the richest man in the world without being born into it? How often has that happened in the entire history?

If 5 billion people flip coins all day long one of them will eventually flip only heads all day. Profoundly dumb people have been heads of state, CEOs etc. So why not the richest person in the world? Alternative suggestion would be that he doesnt actually believe that the reason he is trying not to buy twitter is the reason he was buying twitter.

>Profoundly dumb people have been heads of state, CEOs etc. So why not the richest person in the world?

It's simple to explain away - other people have appointed heads of state. And I have not heard of an idiot (in medical sense) top20 Forbes list CEO who's also been there since day 1 (i.e. the founder, not some figurehead appointed by a board for an arbitrary reason).

Can you appoint yourself the strongest person in the world or the fastest 100m runner in the world?

[0]While someone like the Saudi king or Putin can in theory allocate their respective states' funds to themselves and thus become the richest, that would simply be converting power into money, and not a result of some kind of entrepreneurial ability.

>If 5 billion people flip coins all day long one of them will eventually flip only heads all day.

This argument is flawed since that would assume a person would win some money every time they flipped correctly, when in reality nobody is going to pay anyone for succeeding in a flip. And applying that directly to business also breaks down because it is self-evident that the ways to lose money greatly outnumber the ways to gain money.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#630

Earlier quoted context omitted.

From the complaint (pg 9): > Please note that Mudge began preparing these disclosures in > early March 2022, well before Mr. Musk expressed any > interest in acquiring Twitter, and has not communicated > these disclosures to anyone with a financial interest > in Twitter. Why debate what the timelines implied by various articles are when the primary source is available and makes a clear statement on this matter?

>Why debate what the timelines implied by various articles are when the primary source is available and makes a clear statement on this matter? Probably because most of us in the chain you're replying to didn't have the time to read an 84-page source document in the middle of a work day (note the time of our comments and how late to this particular chain you are), hoping that a nugget of information like that would b…

I didn’t intend any snark, it was an honest question.

Apologies for having offended you.

Post reply on HN