Live data from Hacker News

Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

cnn.com

171–180 of 645 posts

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#171

"Twitter has hidden negligent security practices, misled federal regulators about its safety, and failed to properly estimate the number of bots on its platform, according to testimony from the company’s former head of security, the legendary hacker-turned-cybersecurity-expert Peiter “Mudge” Zatko." "Zatko was fired by Twitter in January and claims that this was retaliation for his refusal to stay quiet about the com…

His complaints don't hold merit because he entered into a binding agreement to buy Twitter after waiving due diligence rights. Zatko was fired in January. Musk had and waived his chance to discover these things. It's too late now.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#172
post #163

"Twitter has hidden negligent security practices, misled federal regulators about its safety, and failed to properly estimate the number of bots on its platform, according to testimony from the company’s former head of security, the legendary hacker-turned-cybersecurity-expert Peiter “Mudge” Zatko." "Zatko was fired by Twitter in January and claims that this was retaliation for his refusal to stay quiet about the com…

>What might the SEC and shareholders do in response? If shareholders believe this, they can do a variety of things such as sell the stock (smaller holders), or demand answers from leadership that go beyond "Yeah, we're secure" (bigger holders such as Saudi Arabia).

Some options that shareholders would have in the situation where investors were knowingly deceived by false disclosures of a publicly traded company are missing from this response.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#173

Earlier quoted context omitted.

> Especially since the Whistleblower seems to basically be blowing the whilst on himself. Whistleblowers are by definition insiders.

Yes, but that's not the point here. A typical whistleblower would say "There were security problems, and the head of security ignored them." Here, it's "I was the head of security, and security was shitty. I was doing a shitty job, and that's a terrible scandal!"

Its more like "I was head of security and the CEO blocked me and tried preventing me reporting the true state of affairs to the board."

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#174

"Twitter has hidden negligent security practices, misled federal regulators about its safety, and failed to properly estimate the number of bots on its platform, according to testimony from the company’s former head of security, the legendary hacker-turned-cybersecurity-expert Peiter “Mudge” Zatko." "Zatko was fired by Twitter in January and claims that this was retaliation for his refusal to stay quiet about the com…

His complaints don't hold merit because he entered into a binding agreement to buy Twitter after waiving due diligence rights. Zatko was fired in January. Musk had and waived his chance to discover these things. It's too late now.

>waiving due diligence rights

Pop legal quiz - does "waving due diligence rights" during an acquisition remove the other party's liability for fraud they've committed against the prospective buyer?

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#176

Millenials and GenZ may have no idea who Mudge is. I, however, almost lost my first job out of college at a bank because I ran l0phtcrack against our Windows NT 4 server to see if it could crack passwords. I showed my boss, and he pulled me aside into another room and tore my head off for irresponsibly running this tool against a production server. He said I could have been fired if this got out, but he covered my as…

Ah yes, Lopht Heavy Industries. Indispensable tools at the time.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#177

Earlier quoted context omitted.

> Especially since the Whistleblower seems to basically be blowing the whilst on himself. Whistleblowers are by definition insiders.

Yes, but that's not the point here. A typical whistleblower would say "There were security problems, and the head of security ignored them." Here, it's "I was the head of security, and security was shitty. I was doing a shitty job, and that's a terrible scandal!"

He tried to change things and was stopped by people actually in power (CEO, the board). Being head of security means nothing if you aren't allowed to do your job. He was also there for less than 2 years. If you read the article, you'll find that Twitter has had awful security practices since at least 2010.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#179

I think it's a pretty open secret that Twitter is a fairly broken company. It's no surprise that their security practices are bad, because all their practices are bad. It's also very difficult to view this in isolation when you have the timeline of (1): Fired in January, nothing happens. (2) Musk makes offer for twitter then reneges. (3) Months before the lawsuit gets decided re-emerges with accusations. What happene…

This was my first thought. TFA claims he started the whistleblower process before the Musk deal was signed. Seems kind of fishy though.

Maybe, just maybe, Twitter is actually a poorly run company and it's not a conspiracy.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#180
I've been hearing about Mudge for decades. It's actually a bit ... heartbreaking ... to see him looking so corporate, but we all age, don't we?

I doubt he was fired for being bad at his job. But I'll bet he was fired for getting in people's faces. That was basically his calling card for years. Why is anyone surprised?

I guess Twitter thought they could hire the cachet, without hiring the man.

I remember an Apple WWDC, way back when. It may have been in the 1980s, as it was in San Jose.

They hired Ken Kesey to drive his bus to San Jose, and give a speech. The party theme was "Hippies," so he fit right in.

So they thought.

He got up on stage, and started talking about taking acid, and counterculture.

The shepherd's crook came right out, and yanked him off the stage.

I heard they had a big fight with him, because they wanted him to leave his Magic Bus, parked in the courtyard.

He drove off in it.

Smart people that make waves are not easy to control. If you are used to herding around mediocre sheep, you'll probably have a hard time with the wolves.

Post reply on HN