Earlier quoted context omitted.
I've worked in multiple sectors for nearly 2 decades: government, energy, transport, retail, finance and software. So I've got a pretty good read on what is a normal level of access. Very small companies and start ups I'd agree often don't have this kind of separation. But if they grow into one of the worlds biggest brands, I would not expect it to be run like a 50 man startup.
Eh, this kind of change usually needs something to go wrong before something is done. Lots of people get outraged when you take privileges from them, even if they probably never should've gotten them to begin with. It's also easy to loose track of your own bias. There is a strong selection bias in employment which makes it look as if all workplaces are similar, simply because a company is more likely to hire you if y…
Mudge is a cyber activist, not a business executive
31–40 of 40 posts
Re: Mudge is a cyber activist, not a business executive
#32I do not agree with most of the points made in this article. I didn't watch the entire testimony, but what I heard I found worrying. For example, half the company had prod access to user accounts. And there was no way to find out who accessed what. This is not normal, it's a huge red flag. The article claims that it should be perfectly expected that an executive should order someone to lie to the board about the risk…
Or you're just not as experienced as you seem to think you are. > half the company had prod access to user accounts That's pretty normal depending on the size of the company. The chances of that being true is pretty high if it's a smallish upstart with > I've never met any of these stereotypes in the real world, although people do disagree on what is enough. I've encountered several - they were all in the same compan…
Perhaps, as you yourself said, "you're just not as experienced as you seem to think you are".
I have worked in startups and with large enterprises. There is not a _single_ place where any significant percentage had access to prod accounts. That would be a HUGE nono. I have no doubt it happens, but that's not normal.
Re: Mudge is a cyber activist, not a business executive
#33What happened was that Twitter hired a famous name to run their security for the clout, then it turns out that was a big misfire
Re: Mudge is a cyber activist, not a business executive
#34Earlier quoted context omitted.
Eh, this kind of change usually needs something to go wrong before something is done. Lots of people get outraged when you take privileges from them, even if they probably never should've gotten them to begin with. It's also easy to loose track of your own bias. There is a strong selection bias in employment which makes it look as if all workplaces are similar, simply because a company is more likely to hire you if y…
But a lot has gone wrong at Twitter...
> For example, half the company had prod access to user accounts. And there was no way to find out who accessed what. This is not normal, it's a huge red flag.
If that statement was qualified to only include fortune 500 companies I would've agreed with it being a red flag
Re: Mudge is a cyber activist, not a business executive
#35Earlier quoted context omitted.
But a lot has gone wrong at Twitter...
Sure, but the argument was > For example, half the company had prod access to user accounts. And there was no way to find out who accessed what. This is not normal, it's a huge red flag. If that statement was qualified to only include fortune 500 companies I would've agreed with it being a red flag
Re: Mudge is a cyber activist, not a business executive
#36Earlier quoted context omitted.
Sure, but the argument was > For example, half the company had prod access to user accounts. And there was no way to find out who accessed what. This is not normal, it's a huge red flag. If that statement was qualified to only include fortune 500 companies I would've agreed with it being a red flag
Did you think they were referring to a company other than Twitter?
The exceptionally bad ones have no authentication on databases readable to dog-and-world. That's the state of our industry where security is at best an afterthought. By that measure, Twitter is basically average. They give it some lip service and do as little as they can get away with.
Re: Mudge is a cyber activist, not a business executive
#37I do not agree with most of the points made in this article. I didn't watch the entire testimony, but what I heard I found worrying. For example, half the company had prod access to user accounts. And there was no way to find out who accessed what. This is not normal, it's a huge red flag. The article claims that it should be perfectly expected that an executive should order someone to lie to the board about the risk…
One can argue that it shouldn't be normal, but I assure you that it is extremely normal in most companies. Shared root credentials, no audit logs, or audit logs that you have to grep on individual hosts - these are VERY VERY normal across business.
Re: Mudge is a cyber activist, not a business executive
#38I do not agree with most of the points made in this article. I didn't watch the entire testimony, but what I heard I found worrying. For example, half the company had prod access to user accounts. And there was no way to find out who accessed what. This is not normal, it's a huge red flag. The article claims that it should be perfectly expected that an executive should order someone to lie to the board about the risk…
> And there was no way to find out who accessed what. This is not normal, it's a huge red flag One can argue that it shouldn't be normal, but I assure you that it is extremely normal in most companies. Shared root credentials, no audit logs, or audit logs that you have to grep on individual hosts - these are VERY VERY normal across business.
Which I guess is why it surprises me that Twitter still operates like that.
Re: Mudge is a cyber activist, not a business executive
#39I do not agree with most of the points made in this article. I didn't watch the entire testimony, but what I heard I found worrying. For example, half the company had prod access to user accounts. And there was no way to find out who accessed what. This is not normal, it's a huge red flag. The article claims that it should be perfectly expected that an executive should order someone to lie to the board about the risk…
> And there was no way to find out who accessed what. This is not normal, it's a huge red flag One can argue that it shouldn't be normal, but I assure you that it is extremely normal in most companies. Shared root credentials, no audit logs, or audit logs that you have to grep on individual hosts - these are VERY VERY normal across business.
Re: Mudge is a cyber activist, not a business executive
#40I do not agree with most of the points made in this article. I didn't watch the entire testimony, but what I heard I found worrying. For example, half the company had prod access to user accounts. And there was no way to find out who accessed what. This is not normal, it's a huge red flag. The article claims that it should be perfectly expected that an executive should order someone to lie to the board about the risk…
> And there was no way to find out who accessed what. This is not normal, it's a huge red flag One can argue that it shouldn't be normal, but I assure you that it is extremely normal in most companies. Shared root credentials, no audit logs, or audit logs that you have to grep on individual hosts - these are VERY VERY normal across business.
It wouldn't be probably an exaggeration to say that ability to post a tweet in someone's name, or ability to see private DMs can have financial effects (scams, frauds of big proportions), or in extreme, yet not unthinkable, circumstances lead to loss of health or life (war, terrorism).