Live data from Hacker News

Mudge is a cyber activist, not a business executive

cybersect.substack.com

1–10 of 40 posts

Re: Mudge is a cyber activist, not a business executive

#2
It seems very obvious that he is an engineer taking advantage of a situation. I don’t blame him I’m sure security is lapsing in the eyes of a life kong security researchers. But as to a lawyer everything is a legal problem and a carpenter a carpentry problem, this is a security issue only to someone in infosec.

Re: Mudge is a cyber activist, not a business executive

#6
The argument falls flat by paragraph 7 of this long rambling piece.

> But there’s no objective evidence of this, only the subjective opinion of Mudge that Twitter wasn’t doing enough for cybersecurity.

...

> specifically that they lied to investors and failed to live up to a 2014 FTC agreement to secure “private” data.

So is it subjective, or objective? Is the 2014 FTC agreement subjective?

And then he just starts pissing into the wind. "He said servers were out of date, but Ret Hat 7 is 8 years old but it's still receiving security patches but I'll just hand wave that away."

> Part of his complaint is that the now-CEO Parag Agrawal pressured him into lying to the board, to claim to the risk committee of the board that security is better than it really was.

...this is against the law.

"Of course Agrawal did. He’s supposed to do that."

This whole article is just rife with logical fallacies, incongruencies, and silliness.

> In contrast, Mudge’s complaint is full of the assertions that he’s objectively right, and Agrawal objectively wrong. And since it’s objective that he was wrong, Agrawal must’ve been lying.

The argument is that Agrawal intentionally misled shareholders. That's objectively wrong.

And, finally:

> What I read here in Mudge’s complaint aren’t the words of an executive, but the words of an activist.

The complaint was written as a whistleblower not as a CISO.

Re: Mudge is a cyber activist, not a business executive

#7
Something I've noticed pre-pandemic: infosec twitter's other personalities seem to have largely agreed to take Robert Graham's opinions with a grain of salt because they tend to fit the definition of "hot take" pretty closely. Not that impressions from "personalities" are how anyone should gauge the validity of someone's opinions, but my impression is likewise that he's mostly known for trolling.

I doubt the claim that it's a PR piece, but I don't doubt the idea that Robert wrote this to troll. It fits pretty closely, so it's probably best to look at it from a practical angle and not get worked up about it. No one even knows if Robert believes half of what he himself writes.

--

stated differently: he's the Armond White of InfoSec Twitter.

--

tl;dr: he's probably trolling.

Re: Mudge is a cyber activist, not a business executive

#8
> In other words, in all likelihood, Twitter is ahead of the norm, ahead of the average, just not up to the same standard set by the leaders in tech.

Really? It came out Twitter doesn't have a dev/staging environment. Source: https://twitter.com/lauren_feiner/status/1569695337190944775 in the same thread, "Twitter can't assure regulators that it's able to delete all data at a user's request because it's unsure where all that data lives"

Earlier we have learned

> “Even a temporary but overlapping outage of a small number of datacenters would likely result in the service [Twitter] going offline for weeks, months, or permanently,” according to Zatko’s whistleblower disclosure. (Twitter has criticized Zatko and broadly defended itself against the allegations, saying the disclosure paints a “false narrative” of the company.)

Quoted in https://www.cnn.com/2022/09/12/tech/twitter-data-center-cali... just yesterday.

All in all, there's a picture here which says Twitter simply doesn't have a handle on its own infra any more, it can't replicate it for dev/staging purposes, it doesn't fully know where the data goes and if it crashed they couldn't rebuild it. You call that ahead of the norm?

Re: Mudge is a cyber activist, not a business executive

#9
Some very good points made in this article but also so many cringey takes. The author is an engineer but compares the user to server ratio at Twitter to Netflix. Those services are so very different and have such vastly different hardware, software, and network requirements I don't even know where to begin.

They dismiss Mudge's comments on lack of disk encryption by saying that anything less than end-to-end encryption is pointless anyways. Again, I don't even really know where to begin. Those features address completely different risks. Not every service can reasonably implement end-to-end encryption while still providing the functionality and support their users want. That doesn't mean they should just ignore encryption altogether. There are other threats out there that are mitigated by encryption at rest. And I think the core of Mudge's complaint here is that too many people have access to private DMs. There are all kinds of security controls to mitigate that threat that it sounds like Twitter isn't using.

> Cybersecurity has the wrong belief that “security” is their highest ethical duty, to the point where they thing it’s good to lie to people for their own good, as long as doing so achieves better security.

Wait, what? I've worked in the industry as long as Mudge has and I've never come to this conclusion. There are many, many security engineers, managers, and execs out there that work hard to earn a great reputation in their field by measuring security against business needs and finding a welcome compromise.

I say this as someone who pointed out when this story first broke that Mudge's background really didn't appear to be well suited to managing security at a huge tech company. I also share the concerns about how equipped he was to deal with executives and board members. But yikes.

Post reply on HN