Live data from Hacker News

Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

cnn.com

311–320 of 645 posts

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#311

Millenials and GenZ may have no idea who Mudge is. I, however, almost lost my first job out of college at a bank because I ran l0phtcrack against our Windows NT 4 server to see if it could crack passwords. I showed my boss, and he pulled me aside into another room and tore my head off for irresponsibly running this tool against a production server. He said I could have been fired if this got out, but he covered my as…

I think it was '96? I was working at Taos Mountain at the time. At that time, Taos had a reasonably close relation to Randal Schwartz ( https://www.oreilly.com/library/view/learning-perl-6th/97814... ) and he gave a talk for contractors which was titled "Just Another (convicted) Perl Hacker".

In that talk he told of his time at Intel and running crack on a shiny new sparc and all the problems that caused.

The focus of it was a "how not to get into trouble as a contractor".

Somewhere, I've still got my pink camel book with duct taped edges (for durability) with his signature on the inside title page.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#312
post #211

Earlier quoted context omitted.

Twitter Inc. is indeed in very serious trouble if you have someone like Mudge whistleblowing. Now looking at the chaos, damage control and the PR disaster that is happening at Twitter HQ after this, I have zero confidence in whatever Twitter HQ and the CEO is saying other than admitting their total incompetency towards how they handle information security at the company. All attempts to make this disaster disappear w…

Well, it's not even trending on Twitter, which is not really surprising. There is nothing more evident about the fatal flaws in social media than when news concerning a platform is suppressed on the cited platform. It highlights the failure of democracy they always purport, and it shows that they really shouldn't display a social "trending" page, because it is subject constantly to the politics and profit making of e…

> There is nothing more evident about the fatal flaws in social media than when news concerning a platform is suppressed on the cited platform.

I just looked at the Trending panel and "Mudge" is #12 for me, with 4333 tweets. #11 is "Taco Tuesday", with 4172 tweets. #7 is "Virgo" with 98,500 tweets. So I'm not seeing a lot of evidence of suppression. I think it's just a pretty niche story. I think the allegations are important and worth investigating, but the specific nature of them looks way more interesting to tech insiders than general-audience users.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#314
Is it just me, or does some of this feel less whistleblower-y and more petty? For example:

> The company also lacks sufficient redundancies and procedures to restart or recover from data center crashes, Zatko's disclosure says, meaning that even minor outages of several data centers at the same time could knock the entire Twitter service offline, perhaps for good.

That said, this is Mudge. I have a lot of respect for the guy, and I believe what he says. I'll chalk the pettiness up to this article being a summary of a more complete document that I'd like to read at some point.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#315

I think it's a pretty open secret that Twitter is a fairly broken company. It's no surprise that their security practices are bad, because all their practices are bad. It's also very difficult to view this in isolation when you have the timeline of (1): Fired in January, nothing happens. (2) Musk makes offer for twitter then reneges. (3) Months before the lawsuit gets decided re-emerges with accusations. What happene…

Mudge: "Jack Dorsey reached out and asked me to come and perform a critical task at Twitter. I signed on to do it and believe I'm still performing that mission," he said." Seems like a legit answer. No need to accuse people of slinging mud.

Jack Dorsey's not there anymore, and the current executives clearly have a different view. So I think the question of "why now and why like this" is still open. Given how many savvy technologists use HN, I'd bet we could put together a list of thousands of companies with concerning-to-reckless security practices. But for better or worse, most of us don't end up getting our concerns on CNN.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#316

I think it's a pretty open secret that Twitter is a fairly broken company. It's no surprise that their security practices are bad, because all their practices are bad. It's also very difficult to view this in isolation when you have the timeline of (1): Fired in January, nothing happens. (2) Musk makes offer for twitter then reneges. (3) Months before the lawsuit gets decided re-emerges with accusations. What happene…

If you've worked for any major F500 Enterprise, this is all par for the course. Currently on a contract with a healthcare giant, while security is pretty tight because HIPPA, generally everything else is chaotic. I'm going to speculate that Twitter is probably worse than the mean, but at pretty much every large company that operates massive pieces of software, youre gonna get a ton of chaos by default.

this was my reaction, too. and I'd add: the legal requirement is basically to have 'industry standard' security; no more and no less. there is no legal requirement to have air tight security (which probably isn't even technically possible at a company of this scale anyway).

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#317

Earlier quoted context omitted.

Ah yes, Lopht Heavy Industries. Indispensable tools at the time.

Always been a fan of "Heavy Industries".

Yup. I've used that with my normal "last name backwards" company name before. I tend to send Christmas and Birthday gifts to siblings with the company field filled in. "Kinetics," "Orbital Bombardment Division," "Relativistic Research," and assorted other things have made their way in, but "Heavy Industries" just has such a nice ring to it.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#318

Earlier quoted context omitted.

If the executives did not make a meaningful effort to count them, that is fairly damning, given how much the stock price swings on the count. Nobody said it was easy, but it's certainly harder if you don't try.

> If the executives did not make a meaningful effort to count them They've been filing their methodology for bot counting with the SEC since 2013. If they're not making a "meaningful effort" and it materially affected the stock price in some way, either the SEC or a shareholder would have gone "HOLD ON SHENANIGANS O'CLOCK", surely? It can't be that the entire world was A-OK with Twitter's bot counting until June 2022…

Shenanigans can go on for a lot longer than 9 years without anyone noticing.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#319

Millenials and GenZ may have no idea who Mudge is. I, however, almost lost my first job out of college at a bank because I ran l0phtcrack against our Windows NT 4 server to see if it could crack passwords. I showed my boss, and he pulled me aside into another room and tore my head off for irresponsibly running this tool against a production server. He said I could have been fired if this got out, but he covered my as…

I don't because I'm not seeing an organization that will hold them accountable. - This Congress is ill-equipped to understand tech, much less hold it accountable. As long as the people are happy, Congress is happy. - Lord knows the people are ill-equipped to get how bad this is. They already watched this company allow a rogue employee to shut off the account of the President of the United States (before they chose to…

> My recommendation is to shed Twitter as a user.

I never understood why tech people have such a strange enamor towards Twitter. Can’t be an industry power dev without it. Can’t start a company without it. Having a healthy Twitter following is often more important than having actual users—even to investors. Twitter is digital hype.

I agree. It’s time to replace Twitter. The only question is what exactly is it that anchors people to the platform? Even though it’s hard to imagine, we know that news motivates people (it happened with the WhatsApp -> Signal exodus). Where’s the “Signal for Twitter” we can all migrate to?

If the key is not just creating a social platform, but also a hype engine, maybe what a competitor needs to realize is that hype doesn’t happen in a vacuum. You have to do silly algorithmic things so that content can go viral. Maybe the secret is to be open about how you manufacture hype rather than do it behind closed doors? Maybe in a way that people can verify it was done fairly?

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#320
Sure the article focuses on Mudge because the's blowing the whistle, but Mudge and Rinki Sethi (ex-CISO) were fired at the same time.

When you fire both your chief of security and your CISO months after you hire them, it's weird. Even if your chief of security had personal failings, why fire his boss? If the boss falls on her sword for direct, that certainly makes me think to take what their saying seriously.

Post reply on HN