Live data from Hacker News

Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

cnn.com

121–130 of 645 posts

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#121
post #63

Earlier quoted context omitted.

Cybersecurity is one of my roles I suppose (small place with an operations team of approximately 2.5), and I have to say that I have no idea what proper security is supposed to mean today; it's very hard for me to tell the marketing from best practice now. It seems like what most products really are is an ass covering service so you can tell your leadership and your customers that you did the right things. Basically…

Corporate robots don't care. They have gotten away with so much for so long, they live in their own disconnected reality. When things break some of them cash out. Others find someone to blame. They don't pay a price at all. And the cycle continue. In China atleast people are scared of the govt. In the west its a total joke how no one is ever held responsible.

Yikes, I wouldn't boast about being scared of a govt. That's on the cusp of being fascist.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#122
post #112
post #97

Earlier quoted context omitted.

Not a lot of companies get infiltrated by foreign agents or assets. Access to Twitter, in particular, can help unmasking anonymous sources, sensitive DMs, dissidents - and their locations. And, oh yeah - there is no "conspiracy".

I don't claim Mudge was infiltrating Twitter, nor that his claims to bad security are false, nor that it is not dangerous to use Twitter if you value privacy. Bad security at Twitter, or any other social media is a given. Remember they're in the business of selling personal data. My claim is that this specific story which is most likely true but in no way surprising gets amplified right now because some specific powe…

Or the current Twitter drama is precisely why it is an interesting story for the media.

That said, given foreign influence campaigns in the news in the last 6 years, this would’ve been news then too. I’m sure it was news back in 2010 when the FTC ordered it to fix the problems.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#123

Quoted post unavailable.

The article states he has had no contact with Musk and that the whistleblowing started before Musk attempted his takeover of Twitter ..

On the other hand, if you want to fan the conspiracy flames, he does have strong ties to Dorsey (via Stripe and Twitter) and Dorsey has always been Team Musk, especially re: the takeover.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#124
post #75

"The whistleblower also says Twitter executives don't have the resources to fully understand the true number of bots on the platform, and were not motivated to." I imagine this hurts Twitter's defense against Musk from pulling out of the takeover deal, or, is this whistleblower's account inadmissible?

> I imagine this hurts Twitter's defense against Musk from pulling out of the takeover deal Not really because they have consistently said "this is what we do, it's a finger in the air estimate based on sampling, it might be right, it might be wildly wrong, there's no agreed methodology for this". For someone to then go "they don't fully understand the true number of bots! GOTCHA!" is dumb because it's literally just…

So many people don’t understand this. It’s not even clear if Musk does.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#125
post #75

"The whistleblower also says Twitter executives don't have the resources to fully understand the true number of bots on the platform, and were not motivated to." I imagine this hurts Twitter's defense against Musk from pulling out of the takeover deal, or, is this whistleblower's account inadmissible?

It's probably not coincidence that that piece is in there ...

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#126
post #75

"The whistleblower also says Twitter executives don't have the resources to fully understand the true number of bots on the platform, and were not motivated to." I imagine this hurts Twitter's defense against Musk from pulling out of the takeover deal, or, is this whistleblower's account inadmissible?

It truly doesn't matter, given Musk waived due diligence. Unless the number of bots is enormous (think 75% or more) then it won't make a material difference.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#127
I think it's a pretty open secret that Twitter is a fairly broken company. It's no surprise that their security practices are bad, because all their practices are bad. It's also very difficult to view this in isolation when you have the timeline of (1): Fired in January, nothing happens. (2) Musk makes offer for twitter then reneges. (3) Months before the lawsuit gets decided re-emerges with accusations.

What happened that caused him to suddenly start whistleblowing now, and not in January? Was it the same thing that caused Ken Paxton in Texas to start investigating Twitter?

This just looks like pretty plain mud-slinging from Musk's team to be honest. Especially since the Whistleblower seems to basically be blowing the whilst on himself.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#128
post #77
post #75

"The whistleblower also says Twitter executives don't have the resources to fully understand the true number of bots on the platform, and were not motivated to." I imagine this hurts Twitter's defense against Musk from pulling out of the takeover deal, or, is this whistleblower's account inadmissible?

Why would it be inadmissible? Mudge could be subpeonaed, just like Jack was just subpeonaed.

Indeed, he just was. https://twitter.com/deitaone/status/1562069657582018560

(That account tweets bloomberg alerts)

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#129
The whistleblowing case is a new dimension. To me as an outsider it implies Agrawal may have also been the manager in his previous technical role for a lot of the tech problems Zatko identified, and what made Agrawal CEO was his ability to leverage these problems to play ball with all the interests in that company and board, while sustaining through neglect some of those concerning practices within the organization. Twitter's product isn't technology, it's an uncertified slot machine that pays out in political influence, and there are a lot of big interests depending on their cut of it. They needed a steady hand who wouldn't be vulnerable to being swayed by principle, and that's the one thing you don't keep hackers around for, imo.

If I were betting, nothing is ever really systemically broken in large orgs, it just works for someone you can't see. This is a factor everywhere and not necessarily at Twitter. Shitty process? Cui bono. Unverifiable systems? Cui bono. Deniable and unaccounted-for access to God-mode data? Cui bono. Repudiable numbers reporting? Cui bono. Bizarre political posturing? Cui bono, etc.

Post reply on HN