Live data from Hacker News

Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

cnn.com

381–390 of 645 posts

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#381

I've been hearing about Mudge for decades . It's actually a bit ... heartbreaking ... to see him looking so corporate, but we all age, don't we? I doubt he was fired for being bad at his job. But I'll bet he was fired for getting in people's faces. That was basically his calling card for years . Why is anyone surprised? I guess Twitter thought they could hire the cachet, without hiring the man. I remember an Apple WW…

[deleted]

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#383
post #75

"The whistleblower also says Twitter executives don't have the resources to fully understand the true number of bots on the platform, and were not motivated to." I imagine this hurts Twitter's defense against Musk from pulling out of the takeover deal, or, is this whistleblower's account inadmissible?

[deleted]

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#384

Millenials and GenZ may have no idea who Mudge is. I, however, almost lost my first job out of college at a bank because I ran l0phtcrack against our Windows NT 4 server to see if it could crack passwords. I showed my boss, and he pulled me aside into another room and tore my head off for irresponsibly running this tool against a production server. He said I could have been fired if this got out, but he covered my as…

I met Mudge once in my career early on (I was at VA Linux systems circa 1999ish) and I found him intense, an apex intellect, but absolutely affable and self-aware.

He never struck me then, or in any interview or write up since, that he's impulsive, or prone to taking actions like what he's done to Twitter, in a cavalier way. He saw something bad and thinks something should be done to address it.

He likely made that decision because the culture at Twitter is as bolloxed as he states (maybe worse), and that it's one thing to fire a guy, but to do so to hide damning truths, and expect that person to just accept their fate AND let you get away with it without a cost is in this day and age, a farcical hope. Your "Mudge knows the implications of "whistleblowing". He has been a security consultant and even testified to Congress. He's not some noob that doesn't understand security or how systems work together to provide services like disclosure to FTC. The idea that Twitter PR can pooh-pooh away his concerns is shockingly stupid." is spot-on.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#385

When is mudge going to audit tesla/spacex for "non-compliant kernels", "encryption at rest", etc, etc? Everyone in this shameful industry knows that literally any company in the US would get shredded in such a vigorous audit and the silliest part is that twitter is a fucking shitposting platform that doesn't have my SSN or financial data so equating it to equifax in any way is absolutely laughable.

[deleted]

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#386
post #2

It is rather disconcerting how a platform that is apparently rather integral to the discourse of today is in the hands of a single private company. It doesn't matter who owns it, if it's Musk or someone else, the fact that it's at the whims of a private company, is the primary channel for discourse, and is something legislatures cannot even comprehend because of their age, should have alarm bells going off. Coupled w…

> the primary channel for discourse Primary for whom? If you polled 50 people on the streets of NYC, I bet fewer than 3 would say they actively use twitter. Now do the same for Des Moines, IA and you maybe get 1?

If you're in any community that is popular/new enough to not use forums, but not large enough to talk outside of twitter, it definitely controls a lot.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#387
post #355

Earlier quoted context omitted.

Well, it's not even trending on Twitter, which is not really surprising. There is nothing more evident about the fatal flaws in social media than when news concerning a platform is suppressed on the cited platform. It highlights the failure of democracy they always purport, and it shows that they really shouldn't display a social "trending" page, because it is subject constantly to the politics and profit making of e…

You really think just after paying an FTC fine, staring down SEC actions, and a huge legal fight with Musk…Twitter is going to “suppress” the content to keep this a secret? Sure.

I don't have any factual evidence on the either side (I don't use Twitter at all, I even have Nitter extension to never visit that site even when linked to) - but I absolutely can believe they'd go for "all in" strategy, and keep messing with the feeds even in light of all that. If they felt they have the right and responsibility to control the information and shape the discussion on the Internet, they'd still feel that now, despite all the "mistakes were made" - in fact, they'd probably feel more urge to control things as they feel more threatened. And why not reduce the "misinformation" about their supposed wrongdoings - when all the most truest information about it has been already disseminated by them, why allow "irresponsible parties" to "misinform" the public? Surely it should be stopped. It's the way they always have been thinking, why would they change now?

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#388
post #301

Earlier quoted context omitted.

It's Twitter. What possible serious security implications could possibly warrant everyone in Washington getting into a frenzy? All you do is make public comments that have zero value. And if this is indeed serious, where the fuck have we landed?

A well-timed set of tweets from compromised government and private-sector accounts, coordinated with real stock market activity planned by the attacker such that investors cannot ignore the rumors, could cause a geopolitically significant market panic. This already happened in 2013, and that was with just a single account being compromised: https://business.time.com/2013/04/24/how-does-one-fake-tweet...

OK, Twitter needs regulated then. Hardly a private going concern if you are right.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#389

Earlier quoted context omitted.

The last US President used Twitter as his primary way to communicate with the world. That on its own has serious security implications. I agree with you that we have landed in not a great place.

> The last US President used Twitter as his primary way to communicate with the world. Without it sounding like an endorsement or defense of the guy… I never would have believed without seeing it, just how furious this made the media and other politicians. That you have a guy come in who said forget the system, I’m going talk to the people directly (and say some dumb things now and then). I still attest that some of…

It wasn't the platform. As you can see, it took some time, but Trump found a way to do the same without Twitter. Despite all the efforts of Big Tech to control the access to public discussion, they still can't make it airtight, and contain somebody of Trump's caliber. Arguably, they have more luck with people of the smaller caliber though. And that's definitely not a good place. It's not about the specific guy, it's about how eager the Big Social turned out to be to control what we think and what we are allowed to talk about.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#390
post #266

Earlier quoted context omitted.

>> It's Twitter. What possible serious security implications could possibly warrant everyone in Washington getting into a frenzy? Considering how widely used Twitter is, at this point we can comfortably assume that most politicians and political operatives, even high profile ones, must have very sensitive information in their Twitter DM inboxes.

ah ah ah so they trust twitter ? the situation is improving at minus light speed...

I won't be surprised that they do. Most politicians are very thoroughly technically ignorant, and have little time or patience to spend on learning technically complex things, and really safe communication means aren't usually very user-friendly.
Post reply on HN