Live data from Hacker News

Former Twitter employee convicted of charges related to spying for Saudis

politpost.com

41–50 of 57 posts

Re: Former Twitter employee convicted of charges related to spying for Saudis

#41
post #37
post #27

Earlier quoted context omitted.

Not to defend the incompetent jerks who run Twitter or anything, but only a complete idiot would have ever trusted them with private or damaging information (including metadata such as locations). Twitter never made any reliable, verifiable guarantees about security or internal controls.

It's not a matter of Twitter giving guarantees about optional data. This is PII, which has to be protected legally. Internal controls at a company of the size of Twitter is no longer optional. You don't have to intend malice to be guilty of negligence. Equifax never gave guarantees of security and data safety either, but it's understood that they should be responsible.

Wrong. Under US federal law, Twitter has no legal obligation to protect PII. Internal controls for user data are optional.

https://pro.bloomberglaw.com/brief/data-privacy-laws-in-the-...

To be clear, I am not thrilled with this situation. But even if social networks were legally required to protect PII they would still suffer occasional breaches by advanced persistent threats and state intelligence agencies. Don't post anything important on social media. Just pictures of family vacations and such.

Re: Former Twitter employee convicted of charges related to spying for Saudis

#42

Someone I know had been working for twitter and they said they were blown away at the lack of internal protections built in to the system. I guess it could be a goldmine of data for spies.

applies to pretty much all social media and b2c platforms.

Re: Former Twitter employee convicted of charges related to spying for Saudis

#43

> Ali Alzabarah, another former Twitter employee who was also charged in the scheme, fled the country before he could be arrested Apparently “Alzabarah [is] believed to be in Saudi Arabia” [1]. What the fuck?! Sooner we can decouple from that regime the better in my book. [1] https://www.justice.gov/opa/pr/two-former-twitter-employees-...

how did they try him in absentia? I'm pretty certain that's illegal in the united states.

What led you to believe that the United States can’t try defendants in absentia?

https://www.ojp.gov/ncjrs/virtual-library/abstracts/trial-ab...

Re: Former Twitter employee convicted of charges related to spying for Saudis

#44
post #41
post #37

Earlier quoted context omitted.

It's not a matter of Twitter giving guarantees about optional data. This is PII, which has to be protected legally. Internal controls at a company of the size of Twitter is no longer optional. You don't have to intend malice to be guilty of negligence. Equifax never gave guarantees of security and data safety either, but it's understood that they should be responsible.

Wrong. Under US federal law, Twitter has no legal obligation to protect PII. Internal controls for user data are optional. https://pro.bloomberglaw.com/brief/data-privacy-laws-in-the-... To be clear, I am not thrilled with this situation. But even if social networks were legally required to protect PII they would still suffer occasional breaches by advanced persistent threats and state intelligence agencies. Don't po…

While you may be correct about criminal law, I'm certain this would impact their SOX compliance (https://en.wikipedia.org/wiki/Sarbanes%E2%80%93Oxley_Act) and would put their ability to participate and operate in US securities markets in serious jeopardy.

Re: Former Twitter employee convicted of charges related to spying for Saudis

#45
post #29
post #16

2020: How Saudi Arabia Infiltrated Twitter > When the conversation concluded, management seized Alzabarah’s laptop, put him on administrative leave, and escorted him out of the building. > At 5:17 p.m. he called a handler, identified as Associate-1 in the FBI complaint, who arrived in a white SUV two hours later. Driving around Alzabarah’s neighborhood, the two men called “Foreign Official-l” — al-Asaker, according t…

Will the cops really come and arrest people on the spot for breaching internal company data access protocols? I’m curious about it if the authorities act on it as an urgent situation.

The FBI obviously doesn't enforce internal company policies. However, if the company has evidence that the employee is engaging in serious violations of the Computer Fraud and Abuse Act (CFAA) of 1986, or engaging in espionage for a foreign power, then the FBI might send agents to investigate.

Re: Former Twitter employee convicted of charges related to spying for Saudis

#46
post #41

Earlier quoted context omitted.

Wrong. Under US federal law, Twitter has no legal obligation to protect PII. Internal controls for user data are optional. https://pro.bloomberglaw.com/brief/data-privacy-laws-in-the-... To be clear, I am not thrilled with this situation. But even if social networks were legally required to protect PII they would still suffer occasional breaches by advanced persistent threats and state intelligence agencies. Don't po…

While you may be correct about criminal law, I'm certain this would impact their SOX compliance ( https://en.wikipedia.org/wiki/Sarbanes%E2%80%93Oxley_Act ) and would put their ability to participate and operate in US securities markets in serious jeopardy.

Has an SOX compliance case regarding personal information ever been tried in court?

Re: Former Twitter employee convicted of charges related to spying for Saudis

#47
post #41

Earlier quoted context omitted.

Wrong. Under US federal law, Twitter has no legal obligation to protect PII. Internal controls for user data are optional. https://pro.bloomberglaw.com/brief/data-privacy-laws-in-the-... To be clear, I am not thrilled with this situation. But even if social networks were legally required to protect PII they would still suffer occasional breaches by advanced persistent threats and state intelligence agencies. Don't po…

While you may be correct about criminal law, I'm certain this would impact their SOX compliance ( https://en.wikipedia.org/wiki/Sarbanes%E2%80%93Oxley_Act ) and would put their ability to participate and operate in US securities markets in serious jeopardy.

Wrong again. That law only covers financial controls. It doesn't address user data.

Re: Former Twitter employee convicted of charges related to spying for Saudis

#48
post #47

Earlier quoted context omitted.

While you may be correct about criminal law, I'm certain this would impact their SOX compliance ( https://en.wikipedia.org/wiki/Sarbanes%E2%80%93Oxley_Act ) and would put their ability to participate and operate in US securities markets in serious jeopardy.

Wrong again. That law only covers financial controls. It doesn't address user data.

SOX compliance has expanded in recent years to cover a gamut of Cybersecurity process and policy. Go look it up. I recently compiled all the documentation necessary for a client I am serving in order to pass. It includes handling of PII, access controls for code repositories and production environments, and tools for ensuring code quality like performing static analysis and mitigating DDOS attacks such as a decent WAF.

Re: Former Twitter employee convicted of charges related to spying for Saudis

#49

Earlier quoted context omitted.

While you may be correct about criminal law, I'm certain this would impact their SOX compliance ( https://en.wikipedia.org/wiki/Sarbanes%E2%80%93Oxley_Act ) and would put their ability to participate and operate in US securities markets in serious jeopardy.

Has an SOX compliance case regarding personal information ever been tried in court?

I don't know. I'm a techie assisting w/ audit not finance/legal.

Re: Former Twitter employee convicted of charges related to spying for Saudis

#50
post #47

Earlier quoted context omitted.

Wrong again. That law only covers financial controls. It doesn't address user data.

SOX compliance has expanded in recent years to cover a gamut of Cybersecurity process and policy. Go look it up. I recently compiled all the documentation necessary for a client I am serving in order to pass. It includes handling of PII, access controls for code repositories and production environments, and tools for ensuring code quality like performing static analysis and mitigating DDOS attacks such as a decent WA…

Yes I have looked it up and you obviously have no clue what you're talking about. The law is the law, and regardless of what nonsense some random corporate trainer might have fed you, SOX compliance requirements haven't expanded in recent years. Go read the actual law instead of spreading misinformation.

Some businesses do require their partners to have additional controls on PII handling. But that's purely a business issue and has no relationship to SOX.

Post reply on HN