A Saudi prince's attempt to silence critics on Twitter
wired.com
wired.com
Looks like Ahmad Abouammo (Twitter’s former head of Middle East partnerships) was arrested in Seattle in Nov 2019, but Ali Alzabarah's escape to Saudi Arabia was successful (at least in terms of being arrested by the US government):
https://www.justice.gov/opa/pr/two-former-twitter-employees-...
BUT, as of a month ago, a filing was made to drop the charges (?!):
https://www.theverge.com/2020/7/28/21345794/twitter-employee...
Fascinating case...
And I guess the reason for this might be very related with the last paragraph of the Wired's article...
https://www.nytimes.com/2018/12/08/world/middleeast/saudi-mb...
Removing the number instantly re-locks the account.
It’s really immoral that they demand identity-linked PII while running such a loose ship, where anyone with enough money can buy their way in to obtain that PII, track you down, and maybe cut you up with a bone saw.
Twitter is complicit in this abuse, considering their explicit technical steps taken to ensure that you cannot use Twitter without exposing yourself to these sorts of criminals in the governments of foreign countries, as well as similar ones in the government of Twitter’s own jurisdiction.
> And while Alzabarah’s job entailed maintaining systems to keep Twitter working properly, his position at the company did allow him access to the private information of many users, including their phone numbers, email addresses, and IP addresses. That meant that in some instances, Alzabarah could not only help unmask an anonymous regime critic, but also pinpoint the person’s location.
TBF, I think that the vast majority of companies out there are vulnerable to this. I’ve worked for 8 tech companies in my career, none of which did anything beyond a basic background check.
Truly mitigating the problem you’re touching on requires a level of vetting and surveillance that you’d typically see applied to intelligence operatives. I think this is similar to how we view infosec generally: those with sufficient resources will be able to penetrate a network, regardless of the design or execution of network security.
If you’re a nation state with the resources of Saudi Arabia, it still wouldn’t be impossible to bribe or blackmail an employee who has prod access because companies don’t have much of an eye on employees private lives. They would have the resources and theoretically the incentive to really dig into the social engineering/coercion side of things. You’d be amazed how many people that make incredible salaries are in fairly significant amounts of debt. It’s pretty common in western culture, and that’s a prime opportunity for those kinds of operations.
Access to non-tokenized PII data stores or the small set of systems that require touching untokenized PII should be a very small compartment, with extremely tight min-two-person deployment/introspection controls and minimal change frequency.
Which would be bad enough if it was just a few rogue engineers without oversight, but that they actively fought against the FBI's efforts is galling.
https://en.wikipedia.org/wiki/Chappaquiddick_incident
https://en.wikipedia.org/wiki/Henry_VIII
https://en.wikipedia.org/wiki/Pope_John_XII
Wealth and power have insulated those who possess them from the consequences of their actions since forever.
If someone gives you $300MM, you don't say No to them. Indeed, you've likely already said yes.
Seems like something one could build a SaaS business around- send them reports that <user> accessed <fields> about <customer ID> on <date>, along with a copy of attributes and roles about each user. Service could offer deep dives, querying, reporting, along with ML or rule-based flagging to say "That seems odd".
If Twitter can't build the infrastructure needed to do that, I can't imagine how few small companies can do it themselves either.
This kind of system are already used to both optimize business processes and conformance check then by organizations like banks and hospitals.
Through tools are currently focused mainly on the use case for process optimization and regulation conformance checking less so for irregularity detection but tools like that exists to. I think to remember SAP has some form of self learning/calibrating irregularity detection "service"/tool.
So it's less about creating it then about spending Mony on it and from scratch up analysing your internal thread model.
It's quite expensive, some of this software is sold for higher 5 digit numbers even for "small" use-cases.
"Your margin is my opportunity" - Jeff Bezos
A simple version of this could be done cheaply, and not cost much. API to push events, website to host reports, pay-for-use add-ons for alerts, etc.
But go ahead and find a random group of 3 ex-googlers with no domain experience to raise ~$2MM and chase it anyways. Then when you burn through the money you can go back to your FANNG job with a nice raise.
Here are some of the reasons why this niche isn't a good fit for a low margin business:
These products are complex and require extensive customization to be useful. It's common to require consulting when installing or upgrading them.
Third-party integrations are common; the product that I support integrates with at least 3 third-party services.
The service is valuable to these organizations and they are willing to pay fairly high fees for using it. Why leave money on the table?
Support costs are high due to the complexity of the customer's environment.
Obviously some things like SMS or sending of email need to manipulate this data, but rx/tx of eg sms given a placeholder token could also be similarly siloed, so most technical staff would never have or need access to raw PII like IP, phone, or email.
Unfortunately geolocation for ad targeting and other customization features is still probably going to make a “what country is this user in right now?” possible for most devs/SREs, which is itself a bit of a physical location change traffic leak, but making it near-impossible for most devs or SREs to view untokenized user PII would probably be a huge step in the right direction.
Yes.
Should you have been fired? Depends on how much you abused your privilege and what you did with that information. Your comparison to 1 strike laws and greater crime is pretty rich given the information you improperly accessed could be used to blackmail others, or whatever. It's important to treat such information with the utmost respect. Your cavalier attitude and inability to accept responsibility in this regard may be very common within the tech industry, but such attitudes are also why there is a growing movement to; take data out of the hands of companies, and to harshly punish companies who fail to protect the data on one hand while vacuuming up as much as possible with the other.
I think they make the mistake of presuming this has to go up to 11 on day 1.
Tell the employees you're going to be proactively auditing. Choose a threshold. Interview and potentially fire those employees going over the threshold. Do this until you're done firing people, then increase the threshold and repeat. You will have to fire people, or threaten to, but employees will get the message that the PII-party is over.
To be honest tho - this is the contract that both the company and union agreed to, so bad on the company for being okay and not making this a more serious infraction. I've talked to some of the union stewards about this and they basically said they wanted this data locked down harder. They said it's too easy to access and super temping and wished the company would put more protection around it. Go figure.
I'd be very concerned if there still aren't processes and technical barriers to prevent the majority employees from accessing user data. IP address, phone number, etc. should require top-level authorization to access - not something an engineer or even marketing/sales person can just look up.
Twitter was hacked via social engineering of an employee just last month: https://news.ycombinator.com/item?id=23851275
Wouldn't that just expose user data to an even wider group of people while doing this reporting?
"employee id 1234 accessed "email, password hash, location, birthday" about customer id 6789 on 2020-09-01"
nothing particularly sensitive in there, but makes it easy to audit and check for abnormalities.
It's worth remembering that dictators are not inhuman, and they are not so different from us.
> Asaker would pay more than $300,000 to Abouammo, deposited in a Lebanese bank account that Abouammo had a relative open for him. “Proactive and reactively we will delete evil, my brother,” Abouammo texted Asaker just before one deposit of $9,911.
They structured [0] the bribes to avoid SARs; structuring really does happen.
> A third, a Saudi, was “a professional” who used encryption to conceal his identity, though once he signed in without encryption, and Alzabarah was able to track his IP address.
> [Alzabarah] spoke with Asaker on an open phone line and communicated via email.
> So rather than follow the FBI’s request to keep things quiet to assist the case, Twitter lawyers brought Alzabarah in the following afternoon, accused him of improperly accessing user accounts, and told him he was temporarily suspended.
Operational security is hard. Just one slip-up can doom the entire scheme, and here we see those slip-ups from everybody; from the folks being targeted by MBS, from MBS's goons, and from Twitter.
It's also worth remembering we're talking about someone who assassinates his critics and cuts them up into pieces. I would say the "bone saw" aspect outweighs the "playing AoE" aspect and he is very different from us.
1) "to make something that is not human seem like a person"
2) "to make something less unpleasant and more suitable for people"
With dictators, I think we should try to do 1) but not 2).
[1] https://dictionary.cambridge.org/dictionary/english/humanize
Too late for one group. Go check how much Nazi vampire zombie media exists today.
And assuming the police are normal people too, they are all too happy to carry this out.
Normal people are quite happy to endorse or inflict violence against the enemy. Most of us just aren't in a position of power to do anything about it, though, other than post on Facebook, and write angry letters to the editor.
But give that normal person power over other people and freedom from consequences... And, well, you get something quite repulsive.
I still believe it is important to not be overly cynical. My mental model is that most people are neutral or good. It might be proved wrong say 5% of the time, when people are indeed put in MBS-like position. But the vast majority of the time it will be correct, and it will be much more useful than the cynical model where your normal friends are potential murderers that just lack opportunity. A more correct mental model is not always more useful.
[1] https://en.wikipedia.org/wiki/Situationism_(psychology) [2] https://plato.stanford.edu/entries/moral-character/#MorChaEm...
By insisting that MBS is some sort of specially evil person, I feel that you are devaluing the importance of genuine ethical consideration. I do not disagree with your specific points about his misbehaviour, but I want to emphasize that it is the throne and crown which empower him to do so much harm, and not any sort of blackened and hateful heart.
Or worth considering: https://twitter.com/mccormickprof/status/1278529694355292161
I often hear people say "I cannot imagine X (person I know) can do Y." They have a poor imagination.
People are delusional.
1) Twitter immediately revealing to the employee that they were under investigation
2) The FBI not considering #1 and being prepared to detain Alzabarah if he attempted to flee.
I'm not surprised by twitter but a little disappointed in the FBI.
It’s unclear if the inside men, Alzabarah or Abouammo, are living on H-1Bs, full American citizens, or are in the process of immigrating. Depending on the answer to that question, Twitter may need to block the employment of immigrants or citizens to stop this sort of industrial sabotage in the future. Otherwise, every country will try to have their own inside man and Twitter will be forced to overdedicate resources to countering them.
If they’d made his citizenship status clear, the solution would be far clearer to readers.
Seems to be a bad test. American citizens left to join ISIS, American citizens have formed cults, American citizens have mailed bombs to people. If a Saudi Arabian prince plopped a Hublot into some random kid's hands and said "give me an email," do you think their patriotism would prevent it? I don't think so, actually, didn't the recent crypto scam involve 2 Americans?
What you're suggesting sounds like some kind of throwing out the baby with the bathwater, but even more nonsensical.
I think a better conclusion is that companies should architect with the assumption that there's a mole, not engage in some kind of border-control nationalist purge.
That way the American government has done some trustworthy checks for you
Individuals are more likely to want to commit espionage when they are tempted with sex. Why not demand evidence of membership in closed religious communities to address that?
On the latter, because lol that is not going to have the effect you're looking for.
On the latter, you're getting closer to the point I'm making.
And that's how you get numbered groups like the Cambridge Five
This is a complicated problem. I don't think encouraging readers to imagine that there is a simple solution does anybody any favors.