Live data from Hacker News

Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

cnn.com

461–470 of 645 posts

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#461
post #301

Earlier quoted context omitted.

It's Twitter. What possible serious security implications could possibly warrant everyone in Washington getting into a frenzy? All you do is make public comments that have zero value. And if this is indeed serious, where the fuck have we landed?

A well-timed set of tweets from compromised government and private-sector accounts, coordinated with real stock market activity planned by the attacker such that investors cannot ignore the rumors, could cause a geopolitically significant market panic. This already happened in 2013, and that was with just a single account being compromised: https://business.time.com/2013/04/24/how-does-one-fake-tweet...

In the long run that would be a good thing. It would be an object lesson that investors shouldn't believe anything they read on social media.

Investors always have the option to ignore rumors.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#462
post #439

Earlier quoted context omitted.

I wouldn't paint with too broad of a brush in this instance, however. Yes, mudge is the ur-hacker, but also: he worked at BBN and DARPA (where he was extremely effective) and elsewhere. He probably has the most experience of any technical/hacker on the planet of working with executives in large organizations. Agrawal's memo, in contrast, reeks of insecurity. The combination of how he's treated mudge and Rishi Sunak a…

What's the story with Rishi Sunak? Assuming you mean the candidate for Conservative Party leader and thus UK PM, I wasn't aware of such a connection.

Rinki Sethi. OP meant Rinki Sethi. (CISO of Twitter until January, left at the same time as Mudge)

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#463

Earlier quoted context omitted.

The last US President used Twitter as his primary way to communicate with the world. That on its own has serious security implications. I agree with you that we have landed in not a great place.

I hope we get to a place where we all agree that a sitting U.S. President should not "tweet." The White House maintains a Press Secretary for a reason. Granted, the current person holding the job is no C.J. Craig.

I don't agree. The US president (and other politicians) should have a convenient way to communicate directly with the public, without the message being distorted by media organizations. Ideally though it should be a service that can't be censored; Twitter frequently censors users based on the arbitrary whims of their employees.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#464
post #427

Earlier quoted context omitted.

Musk posted a meme explaining why he pulled out. https://twitter.com/elonmusk/status/1546344529460174849

Yeah - but that's dumb bullshit. He can't legally pull out because of that. He waived all of that to force Twitter to agree to the deal (because it'd be basically impossible for the board to reject it). This made sense at the time, because the board was looking for ways to weasel out of it because (imo) they politically don't like Musk. Then the market crashed and suddenly he was overpaying a ton for Twitter, then he…

>I think he earnestly wanted to buy Twitter for principled reasons around speech which I agree with. He structured the deal in such a way where Twitter's board couldn't reject it (because it was so favorable to shareholders). Then when the market tanked the deal way overpriced Twitter, but he had already committed to it so he's trying everything to get out of it.

That's not how business valuations work (it's how speculation works). If Twitter was fairly valued by Elon Musk before the crash then it would be fairly valued now - the fundamentals of the business haven't changed.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#465

Earlier quoted context omitted.

I read the full whistle-blower complaint, and the whole story from his perspective (and the crazy statement from Agrawal) looks like it's not B. Instead, it looks like it was a culture clash with his manager. He seems to have tried to escalate things to people above Agrawal nearly constantly. He was hired by Jack Dorsey, and felt accountable to him and to the board, but he reported to Agrawal, who believed that Mudge…

> I read the full whistle-blower complaint The content of the complaint is all that matters, and it should be judged on its own merits. It never matters who said what, and attempting to make it matter is ad hominem fallacy; it is what is said that matters. That said, I can't quite fathom why Twitter's cybersecurity matters any more than the cybersecurity of any of the myriad of online forums, HN included: the "data"…

I was kind of curious about this as well, though I suppose if a politician’s account was compromised it could cause some pretty major embarrassment or maybe even conflict. Are DMs a thing on Twitter? Having those compromised might be pretty serious too.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#467

Earlier quoted context omitted.

> He was hired by Jack Dorsey, and felt accountable to him and to the board, but he reported to Agrawal, who believed that Mudge had a responsibility to follow the chain of command very rigidly. With $10mm cash bonuses on the table it’s extremely obvious why Agrawal would insist on being MITM

When you think your job is to tell your boss's boss (and their promotion committee) why your boss is doing a bad job, you're not in for a happy time.

Which sucks because plenty of times it's true.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#468

Earlier quoted context omitted.

C has such a bad wrap with the HN crowd...

> C has such a bad wrap with the HN crowd... why?

Can only patch so many buffer overflows, off-by-one errors, format string vulnerabilities, integer overflows, race conditions, use-after-free errors, etc, before it gets to be a bit tiring. Safer alternatives exist.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#469
post #427

Earlier quoted context omitted.

I’m a huge musk fan, but I still think his trying to get out of the Twitter deal is lame buyer's remorse and his arguments are weak. I see it as mostly unrelated to this mudge issue.

Musk posted a meme explaining why he pulled out. https://twitter.com/elonmusk/status/1546344529460174849

He literally said he was buying it to fix the bot problem. It's not like he was unaware that bots existed on twitter.

Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies

#470

Millenials and GenZ may have no idea who Mudge is. I, however, almost lost my first job out of college at a bank because I ran l0phtcrack against our Windows NT 4 server to see if it could crack passwords. I showed my boss, and he pulled me aside into another room and tore my head off for irresponsibly running this tool against a production server. He said I could have been fired if this got out, but he covered my as…

That's a funny story. I have a similar anecdote where I was asked to crack a zip file in a saga related to a dispute with a vendor who gave us a password protected zip file with the deliverables but not the password.

Those were wild times.

Post reply on HN