Live data from Hacker News

Mudge is a cyber activist, not a business executive

cybersect.substack.com

31–40 of 40 posts

Re: Mudge is a cyber activist, not a business executive

#31

Earlier quoted context omitted.

I've worked in multiple sectors for nearly 2 decades: government, energy, transport, retail, finance and software. So I've got a pretty good read on what is a normal level of access. Very small companies and start ups I'd agree often don't have this kind of separation. But if they grow into one of the worlds biggest brands, I would not expect it to be run like a 50 man startup.

Eh, this kind of change usually needs something to go wrong before something is done. Lots of people get outraged when you take privileges from them, even if they probably never should've gotten them to begin with. It's also easy to loose track of your own bias. There is a strong selection bias in employment which makes it look as if all workplaces are similar, simply because a company is more likely to hire you if y…

But a lot has gone wrong at Twitter...

Re: Mudge is a cyber activist, not a business executive

#32

I do not agree with most of the points made in this article. I didn't watch the entire testimony, but what I heard I found worrying. For example, half the company had prod access to user accounts. And there was no way to find out who accessed what. This is not normal, it's a huge red flag. The article claims that it should be perfectly expected that an executive should order someone to lie to the board about the risk…

Or you're just not as experienced as you seem to think you are. > half the company had prod access to user accounts That's pretty normal depending on the size of the company. The chances of that being true is pretty high if it's a smallish upstart with > I've never met any of these stereotypes in the real world, although people do disagree on what is enough. I've encountered several - they were all in the same compan…

> That's pretty normal depending on the size of the company.

Perhaps, as you yourself said, "you're just not as experienced as you seem to think you are".

I have worked in startups and with large enterprises. There is not a _single_ place where any significant percentage had access to prod accounts. That would be a HUGE nono. I have no doubt it happens, but that's not normal.

Re: Mudge is a cyber activist, not a business executive

#34
post #31

Earlier quoted context omitted.

Eh, this kind of change usually needs something to go wrong before something is done. Lots of people get outraged when you take privileges from them, even if they probably never should've gotten them to begin with. It's also easy to loose track of your own bias. There is a strong selection bias in employment which makes it look as if all workplaces are similar, simply because a company is more likely to hire you if y…

But a lot has gone wrong at Twitter...

Sure, but the argument was

> For example, half the company had prod access to user accounts. And there was no way to find out who accessed what. This is not normal, it's a huge red flag.

If that statement was qualified to only include fortune 500 companies I would've agreed with it being a red flag

Re: Mudge is a cyber activist, not a business executive

#35
post #31

Earlier quoted context omitted.

But a lot has gone wrong at Twitter...

Sure, but the argument was > For example, half the company had prod access to user accounts. And there was no way to find out who accessed what. This is not normal, it's a huge red flag. If that statement was qualified to only include fortune 500 companies I would've agreed with it being a red flag

Did you think they were referring to a company other than Twitter?

Re: Mudge is a cyber activist, not a business executive

#36

Earlier quoted context omitted.

Sure, but the argument was > For example, half the company had prod access to user accounts. And there was no way to find out who accessed what. This is not normal, it's a huge red flag. If that statement was qualified to only include fortune 500 companies I would've agreed with it being a red flag

Did you think they were referring to a company other than Twitter?

Yes, the "that's not normal" made it quiet explicitly about the state of the industry in order to single out Twitter to be exceptionally bad in this regard. Which is true in the context of well run companies, but not on the average.

The exceptionally bad ones have no authentication on databases readable to dog-and-world. That's the state of our industry where security is at best an afterthought. By that measure, Twitter is basically average. They give it some lip service and do as little as they can get away with.

Re: Mudge is a cyber activist, not a business executive

#37

I do not agree with most of the points made in this article. I didn't watch the entire testimony, but what I heard I found worrying. For example, half the company had prod access to user accounts. And there was no way to find out who accessed what. This is not normal, it's a huge red flag. The article claims that it should be perfectly expected that an executive should order someone to lie to the board about the risk…

> And there was no way to find out who accessed what. This is not normal, it's a huge red flag

One can argue that it shouldn't be normal, but I assure you that it is extremely normal in most companies. Shared root credentials, no audit logs, or audit logs that you have to grep on individual hosts - these are VERY VERY normal across business.

Re: Mudge is a cyber activist, not a business executive

#38
post #37

I do not agree with most of the points made in this article. I didn't watch the entire testimony, but what I heard I found worrying. For example, half the company had prod access to user accounts. And there was no way to find out who accessed what. This is not normal, it's a huge red flag. The article claims that it should be perfectly expected that an executive should order someone to lie to the board about the risk…

> And there was no way to find out who accessed what. This is not normal, it's a huge red flag One can argue that it shouldn't be normal, but I assure you that it is extremely normal in most companies. Shared root credentials, no audit logs, or audit logs that you have to grep on individual hosts - these are VERY VERY normal across business.

They certainly exist, and I've worked at a few. They were all smaller organisations. I've seen medium sized companies wrestle with it a bit. No large organisation I've worked for had rampant prod access.

Which I guess is why it surprises me that Twitter still operates like that.

Re: Mudge is a cyber activist, not a business executive

#39
post #37

I do not agree with most of the points made in this article. I didn't watch the entire testimony, but what I heard I found worrying. For example, half the company had prod access to user accounts. And there was no way to find out who accessed what. This is not normal, it's a huge red flag. The article claims that it should be perfectly expected that an executive should order someone to lie to the board about the risk…

> And there was no way to find out who accessed what. This is not normal, it's a huge red flag One can argue that it shouldn't be normal, but I assure you that it is extremely normal in most companies. Shared root credentials, no audit logs, or audit logs that you have to grep on individual hosts - these are VERY VERY normal across business.

Normal is probably the wrong word. It’s expected for smaller or less resourced orgs to have immature security and data/access governance programs. But a public company such as Twitter (who has to adhere to Sarbanes Oxley and other regulatory frameworks that drive access control and RBAC)? Not so much.

Re: Mudge is a cyber activist, not a business executive

#40
post #37

I do not agree with most of the points made in this article. I didn't watch the entire testimony, but what I heard I found worrying. For example, half the company had prod access to user accounts. And there was no way to find out who accessed what. This is not normal, it's a huge red flag. The article claims that it should be perfectly expected that an executive should order someone to lie to the board about the risk…

> And there was no way to find out who accessed what. This is not normal, it's a huge red flag One can argue that it shouldn't be normal, but I assure you that it is extremely normal in most companies. Shared root credentials, no audit logs, or audit logs that you have to grep on individual hosts - these are VERY VERY normal across business.

It most likely shouldn't be normal in a company which is used for serious (as in, related to countries' relations or even wars in extreme cases) politics, no matter whether its founders wanted it or not.

It wouldn't be probably an exaggeration to say that ability to post a tweet in someone's name, or ability to see private DMs can have financial effects (scams, frauds of big proportions), or in extreme, yet not unthinkable, circumstances lead to loss of health or life (war, terrorism).

Post reply on HN