Live data from Hacker News

Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

cnn.com

631–640 of 645 posts

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#631

Earlier quoted context omitted.

>Why debate what the timelines implied by various articles are when the primary source is available and makes a clear statement on this matter? Probably because most of us in the chain you're replying to didn't have the time to read an 84-page source document in the middle of a work day (note the time of our comments and how late to this particular chain you are), hoping that a nugget of information like that would b…

I didn’t intend any snark, it was an honest question. Apologies for having offended you.

Nah, I think it's my fault. I have realized this week that I'm dealing with a lot of tough shit and haven't been handling it well. I think I've taken to looking for arguments on HN (and other places) as an outlet and, in hindsight, I am pretty sure that was one of those moments.

It's not fair to you, and I'm sorry. Hope ya have a great rest of the week. :)

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#632

Earlier quoted context omitted.

What like calling a first responder a pedophile?

Thats a major error in judgement. Even billionaires are capable of this

lmao the extent to which the tech crowd will defend all of his stupidity and let him get away with a slap on his wrist. He had a megalomaniac ego moment and called some of the greatest heroes to have ever existed pedophiles for being the only people capable of pulling of a rescue like that. One of them died in the rescue efforts. Musk is all the way up his own ass, and this needs to be acknowledged regardless of his supposed "genius".

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#633
post #567

Earlier quoted context omitted.

There's obviously a lot of legacy Ada out there, but would you say it's 'typical' for new code being written? I don't have that sense. There's probably more MISRA C/++ code floating around at this point. I have no idea how compliant SX is, but I've heard mentions of Power of 10 rules and JPL standards. For what it's worth, their track record doesn't seem concerning nowadays.

I think commercial avionics is the only place you still find ada. Cars have been c or c++ even for safety critical for many years. Even defense abandoned ada well over a decade ago, and they invented it right? And medical jumped right on the windows ce bandwagon as soon as it popped up... I feel like a good pipelene with lots of static analysis asan, and really good tests is probably the best you can expect out of sa…

Well, US defense industry got a waiver for C++ in JSF but I'm not sure if call it a success story.

A lot of stuff is still going on legacy stacks that Ada was created to replace

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#634

Earlier quoted context omitted.

I didn’t intend any snark, it was an honest question. Apologies for having offended you.

Nah, I think it's my fault. I have realized this week that I'm dealing with a lot of tough shit and haven't been handling it well. I think I've taken to looking for arguments on HN (and other places) as an outlet and, in hindsight, I am pretty sure that was one of those moments. It's not fair to you, and I'm sorry. Hope ya have a great rest of the week. :)

Thank you for this comment.

And much good luck with your situation.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#635
post #110

Earlier quoted context omitted.

Nobody seems to know how you can build a successful security org

Building a successful security organization is very easy, it just starts higher up the food chain than whatever experts you hire to do it. Security is a cultural practice, it's not a feature, it's not a bolt-on. To the extent that your security organization influences and receives buy-in from your corporate culture, becoming a part of your organization's identity, it will be successful.

> just starts higher up the food chain

How do you make those people interested in it though?

(If they weren't, originally when you hired them.)

Adding the right KPI? What'd those be

What if they aren't any bright, just have a good self confidence?

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#636

Earlier quoted context omitted.

An interesting statement in a thread about widespread security weaknesses.

Security weakness aren’t a problem if you limit yourself to MISRA C techniques. You don’t need modern languages.

We observe very clearly that teams consistently fail to write vuln-free C applications of any meaningful technical or organizational complexity. Following various guidelines empirically does not solve the problem.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#637

Earlier quoted context omitted.

That's not really how auditors work. Auditors either give the client a letter saying what the client wants it to say[0] or decline to provide the client with that letter. They do not go public with their reasons. [0] Companies want the letter to say whatever their regulators and/or contractual obligations demand that it say.

If a public company gets an accounting audited and they find irregularities it is not subject to public disclosure requirements? Twitter is a publicly held company. I'm sure there are conflicts of interest and some degree of confidentiality for auditors and clients, but there is a fundamental public interest of disclosure, at a minimum to the government, in the event of irregularities. From the SEC: "In addition, we…

If a public company's auditors find irregularities they work with the company's management to resolve them. If, eventually, the auditors decide there are irreconcilable differences, they will resign, and provide reasons for their resignation in the resignation letter to the company. At that point, it is up to the company to decide whether or not those findings are significant enough that they need to be released to the public. The SEC will consider any auditor resignation for cause to be significant enough that it has to be disclosed, but that doesn't mean that companies will actually do it, as you can see by a bunch of enforcement actions relating to exactly that:

https://www.investor.gov/introduction-investing/general-reso...

(search for "resign")

The SEC quote is about requiring auditors to meet their professional standards. Those standards require them to follow certain processes, things like needing to see evidence for certain things, and not both preparing the books and auditing them, and require that they not issue letters they don't actually agree with. Those standards do not require informing the public or regulators about problems they find.

There's certainly something to be said for having some codified professional standards for infosec professionals, but if public or regulator notice is something you think is important to be in those standards you shouldn't model them off of the standards for auditors, because auditors have no such professional responsibility.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#638

Earlier quoted context omitted.

Nah, I think it's my fault. I have realized this week that I'm dealing with a lot of tough shit and haven't been handling it well. I think I've taken to looking for arguments on HN (and other places) as an outlet and, in hindsight, I am pretty sure that was one of those moments. It's not fair to you, and I'm sorry. Hope ya have a great rest of the week. :)

Thank you for this comment. And much good luck with your situation.

:)

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#639

Earlier quoted context omitted.

The man injected himself into an ongoing crisis he had little insight into, and when rejected, his ego was so hurt that he used his influence to accuse individuals he knew nothing about if pedophilia, all while they were in the midst of trying to rescue a dozen children from imminent death. That’s not a “major error in judgement”. That’s the behavior of a completely deranged individual.

> completely deranged individual That's quite a large exaggeration. I can think of some much much worse things that an actual "completely deranged individual" would do. Musk was butthurt and lashed out. That does not equal "completely deranged individual"

> Musk was butthurt and lashed out. That does not equal "completely deranged individual"

Lashed out in a way where, given his influence, he could easily ruin the person's life. Which is bad in and of itself. But he did it while the man was actively involved in trying to save a dozen children from immediate death. And then doubled down later.

That is deranged.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#640

Earlier quoted context omitted.

+1. Additionally IP addresses, email and phone numbers can be extremely sensitive if leaked, so security is absolutely paramount. Case in point: imagine the risk to activists or journalists in heavily censored countries.

Please name one time in the history of TCP/IP that leaked IP addresses led to anything at all.

Sure, when popular social media influencers have their IP leaked they get DDoS'ed and are not able to earn a living until they get a new IP. For some ISPs this requires them to lodge a support ticket.

When gaming services leak IPs, they too can get DDoS'ed. E.g. during tournaments or when someone is losing their match.

Post reply on HN