New York Times Eliminates Director of Information Security Position
twitter.com
twitter.com
https://www.nytco.com/press/erinmichelle-perri-joins-the-tim...
What you're hoping a newsroom security practice is doing is building source protection systems, like secure dead drops, while also serving an advisory and harm reduction function for the journalists themselves, so that they can safely open attachments and follow URLs and communicate over social networks. In that environment, you can't just say "no, don't do that, do this other secure thing instead", like you can with company staff.
It's a specialized skillset, and one that security teams are not generally good at.
It does seem like they might be cutting staff, though, which doesn't feel all that much better
As others with knowledge of the matter suggest, this may be purely organizational. A title being 'eliminated' doesn't necessarily mean it's function disappears.
Not very relevant, but I interviewed with their product team recently. They seemed very competent and thoughtful.
You would have to know the exact responsibilities this person had, how much time/energy they took, whether or not there was duplication of effort elsewhere, etc.
It is important to know the facts, from both sides. In my mind, at least.
For example, they are hiring a PM on this same team right now. It's very possible they just saw this position as an unnecessary level in the hierarchy.
There's this weird dynamic in Information technology where professionals doing their jobs really well result in there being no problems. When there is no problems there's not much attention and the lack of problems is devalued by management.
Management value teams and managers who heroically solve big problems and issues.
This is why companies can sometimes decide that their best people are not needed cause "all is so quiet" and fire them.
I mean, think about it. Hospitals wouldn't fire the surgeons for consistently executing error-free operations.
TLDR; execs that know something about tech is super important.
Worldwide we are seeing an attack on journalism and the free press. Cutting security resources as a short term profit-boosting exercise can have disastrous consequences. Many people all over the world risk arrest or even death for sharing information with journalists. If they can't be sure that the journalists have an excellent security apparatus backing them, it will be too risky for them to come forward.
There is this odd dynamic where if you need the additional legitimacy of an old media organization to get your story out, there must be something fishy about it. Like it's a palace gossip leak, and nothing with real consequence or risk.
If your story is really worth your safety, there is the much greater risk that editors will spike it, the way they did with pretty much every major whistle blower story of the last decade. Hollywood was protected for years, intelligence leaks were regularly spiked, and often journalists themselves were complicit actors in the official retaliations. I'm sure the NYT will still have a security role of some sort, but the idea that it could actually equip reporters at a corporate level with the tools to do the kind of opsec you need to facilitate stories at the level of the Intercept, Wikileaks, and other insurgent media seems unlikely.
I don't necessarily agree with the poster above, but it is obviously not an instance of trolling, also it is not offensive or damaging to anyone.
Suppressing the symptoms and pretending they don't exist won't make the root cause go away. If anything, it will only make the eventual consequences hit us more violently. People will say that the blow-up was sudden and unexpected, but in fact they've been ignoring the warning signs all along.
This is stating fundamentally that manipulation, propaganda, brainwashing etc does not work. Which is patently false. So obviously there is a spectrum. Seeing as it's very possible to steer people through words, the remaining debate is regarding what is dangerous and not.
Those things have the desired effect only when the manipulated sentiments result in concrete actions such as voting or not voting for someone, buying or not buying something, treating somebody in a certain way, etc.
I want as much as anybody else to block the effects of these menaces. But the way to do it is to block the pathway from propaganda to sentiment to action (to use a pharmacological analogy), not to suppress the sentiment.
The whole idea of the free press depends on supporting the free expression of ideas, sentiments, arguments, and testimonies and only suppressing actually detrimental actions. As Justice Louis Brandeis famously noted, the answer to bad speech is more speech, not less. Start trying to bury some people's ideas just because they might encourage others to behave in a certain way, and it's not a long way from there to book-burning territory.
I'm not trying to twist your words, but does this not entail vote suppression (for example)?
> As Justice Louis Brandeis famously noted, the answer to bad speech is more speech, not less.
While sounding good in theory, the problem with more speech is that what's true doesn't gain as many clicks and eyeballs as what's "engaging". Put that on top of the fact that producing researched quality reporting takes factor X more effort than producing something false that _sounds_ interesting/engaging, and with complete disregard to whether it's true or not.
It then follows that there will always be more low quality news (or in reality non-news aka "crap") to drown out real news, given the basically free transfer costs of the internet.
I wish I was optimistic enough to think that people in aggregate wanted to be educated, but I think our current timeline indicates that is not so. And as long as that's the case, stemming the tides of crap is the only viable option I see, however hard that is to do right.
Book burning was bad because it was suppressive of legitimate ideas. I'm not sure what would have been the association if we only burned books suggesting that eating Tide pods was a good idea.
No, I'm not advocating vote suppression. I'm advocating education. Which, as you said, looks like a lost cause, at least in the United States. But if there's no way to win this war without suppressing and silencing somebody, well, so be it. Letting people consume crap doesn't seem all that bad compared to violating civil rights.
Moreover, the sentiment expressed in the parent post that we've been talking about doesn't seem all that different from your observation that there will always be more crap than real news and that people in general don't want to be educated. They're both statements about the current state of journalism and news consumers, albeit with different kinds of exaggeration and flourish. We could talk all day about the causes of this problem and how we might fix it, but allowing people to vent their frustration about a problem is not part of the problem.
the US media serves at the pleasure of the King. only a fool would attempt to blow the whistle with the NYT (or NPR).
https://en.wikipedia.org/wiki/List_of_Pulitzer_Prizes_awarde...
The NYTimes still does journalism, and still has an important role, but the need for such a direct cybersecurity role seemed diminished (and management seemed to agree) - and would probably get in the way of less sensitive work if you had to put everything past them.
To some others in this thread, "troll," seems to have come to just mean a provocative outsider view.
What most journalists do does not require a higher degree security to achieve it, so yes, that is disappointing.
Reading between the lines (and using common sense) suggests that the NYT does have a security team, only that its focus is larger than just the newsroom. One scenario therefore would be a consolidation of security roles. The "Head of Newsroom Security" position would no longer exist, even if there is/are dedicated people with that portfolio.
It may be that the new NYT CISO feels that newsroom, journalist, and source defense is a) critical and b) better handled by eliminating this role.
Every security person would agree with a). Given the visibility Runa had and the positive PR she created around this unique need, b) is not the outcome one would predict.
There is always more to the story than the headline, but as the NYT knows the headline is important in its own right.
Here, the NYT wrote the wrong headline.
https://www.reddit.com/r/netsec/comments/dc9zia/rnetsecs_q4_...
https://www.nytimes.com/2018/07/24/insider/meet-runa-sandvik...
NYT will come to regret this decision. Hopefully, for their employees/readers/journalists/sources/etc. sake, it's only because of the bad publicity.
https://twitter.com/SarahJamieLewis/status/11867779666063400...
https://twitter.com/fugueish/status/1186779963975843842
https://twitter.com/Pinboard/status/1186781483031089152
https://twitter.com/mik235/status/1186781955183874049
https://twitter.com/dangoodin001/status/1186780837750046721
https://twitter.com/osxreverser/status/1186779010073858048
https://twitter.com/mshelton/status/1186784191427465216
https://twitter.com/josephfcox/status/1186778165798166531
https://twitter.com/0xabad1dea/status/1186785548746346496
https://twitter.com/a_greenberg/status/1186786727530323970
https://twitter.com/evacide/status/1186786743774658562
https://twitter.com/str4d/status/1186787004635205632
https://twitter.com/count3rmeasure/status/118677928069453004...
I think this tweet by Runa just yesterday is a perfect example of why her role was fundamental to the NYT's mission.
> https://twitter.com/runasand/status/1186206876381384704
I'm trying to understand what she's trying to say by this tweet and those screenshots and can't. Could you explain?
In the story on the right, even though the reporter basically gets threats of violence (the pistol), they do not even know who it is that they should be contacting about that.
I guess this illustrates the benefits of having a single point of contact for these types of online security issues that everyone knows to contact.
EDIT: it looks like NYT hired a CISO around August https://www.google.com/amp/s/www.csoonline.com/article/32040...
This definitely sounds like office power politics dragged into the public square. One more reason to hate Twitter.
Like most Leftist media agencies, it's probably seeing some tough times coming up, so it makes sense to cut costs in areas that are not attracting subscribers.
The one thing I don't see being raised anywhere is that it's incredibly common in civil society for folks who are "shrill" (supportive of equality for all races, gender identities, etc) tend to be pushed out for "lack of cultural fit".
I think it's possible to separate those two things and I have this hypothesis that you will get further if you are careful to do so and are less likely to be called "shrill" and pushed out.
Employees that send out critical tweets on the day they are let go are typical in an emotionally driven mode. So, I'm sure we will hear more soon.
Bit of a perspective: Companies sometimes keep security staff but have them report under a director of some IT department. Companies are also horrible just horrible about how they perceive the value of an infosec position, the ROI is you don't get pwned. Period. No money savings,no contribution to the bottom line. Not dissimilar to a good insurance policy. I partly fear because it's up to the whims of some exec or some catch phrase they hear somewhere that changes their perception of what value we bring to the table where as engineers build,admins run systems and fix breaks.
Yeah, NY Times agrees with you. They have a CISO.
https://en.wikipedia.org/wiki/United_States_diplomatic_cable...
(CTRL-F "New York Times")
I am still waiting to hear back from them.
Positions can be eliminated for a number of reasons. Reorgs, personnel issues, and redundancies are just a few possibilities.
Putting your former employer on blast publicly is a good way to show future employers you might lack judgment.
PSA to future anonymous whistleblowers: don't engage the NYT or you are now more likely to be unmasked.
https://gawker.com/here-are-some-top-n-y-times-editors-and-s...
https://www.politico.com/story/2017/05/31/new-york-times-pub...
edit: /s