Twitter names famed hacker 'Mudge' as head of security
reuters.com
reuters.com
Speculating on what kind of problems Twitter would need that calibre of person for, maybe detecting inevitable AI driven botnets and deepfakes?
Could also see how they need leadership with that tangible cred as a decider function, e.g. the personality cult around Jack might make delegation and scaling their management team a challenge if everyone is trying to find a way to compete for his attention, so they need someone with enough weight that he can legitimately defer to on security issues.
Congrats to all involved. Interesting times.
And for Mudge, for why it might be worth taking on relatively 'simple' problems - money. Money is nice.
There's probably a little bit of housekeeping for infrastructure and operations security. I imagine all of the fun stuff is customer-facing.
As a very expensive consultant I am frequently appalled at how management teams completely ignore their own employees.
Forget about wasteful, these companies can afford consultants. It is just disrespectful to their own staff. Developers and operations guys already know the solution but can't get through layers upon layers of management. And so it takes a guy with salary high enough that he can be allowed to talk to the a high level manager directly, to get the message.
Sometimes they were blindingly obvious things. One employee would drive two bolts, quickly change heads, then drive a third bolt. While the carcass advanced to the next station, the emloyee would change back to the original head and be ready for the next carcass. That employee's suggestion: Make all three bolts the same size so I don't have to change heads.
Of course, that is just a fun anecdote. All such efficiencies have been implemented long ago... for auto assembly. But the point is still valid. Your employees know a ton about your business. Even the ones who do the most mundane tasks. Listen to them. Or... pay a very expensive consultant to listen to them.
One of my friends runs a market research firm that works for big retailers. She says 90% of their work is about producing evidence for the decisions that have already been taken - so they can be implemented without causing complaints.
Some maintenance guy who works the floor knows they don’t need two of them but no one will listen.
There is still room for a highly paid consultant.
Large car companies like GM or Ford hire automation companies to build automation equipment that meets a very specific spec for assembly steps, tolerances, rates, etc. They design components with ease of manufacturing as a significant factor. How something will be assembled is a constant consideration while designing. The product being run on these lines never really changes and human are only used when the the operations are so complex that the equipment doesn't pay for itself in (typically) 2 years. This is very rare, mostly people are only there to keep the machines filled with parts.
In the sequence of
design -> automate -> manufacture
manufacture needs to be much larger than the others have good margins. You can't iterate on design without iterating on automate, so if you change the design a lot it's probably best to avoid trying to automate.Fictional employee. Fictional scenario. But you still assume that the employee isn't smart enough to know why bolts are different sizes and whether a bigger bolt could work in the place of the smaller bolts.
You assume you know more about this fictional car than the fictional employee actually (um, I mean fictionally) building it.
You should apply for management.
Reductively it's CoW snapshots + chroot.
Guess I need to find a new job.
People don't have to hyper-specialize to one specific role.
> There's really no reason to think the person turning the bolt necessarily knows what size the bolt needs to be.
and also steel-manned the final sentence like this:
> In the same way a web dev doesn't need to know how docker works
As such, the (claimed) existence of one person who regularly uses very different skills doesn't disprove what I think jacobsenscott was trying to say.
Example using the same logic as the post we're discussing: Someone flips a coin in another room. It doesn't necessarily have to be heads, so we should assume it's tails.
It sounds like you are not familiar with this disaster:
https://en.wikipedia.org/wiki/Hyatt_Regency_walkway_collapse
There may be a very good reason things are the way they are.
While a good manager can mitigate the problem by cultivating mutual trust, individually and culturally, the problem gets compounded when hierarchies become nested, and the org scales beyond the Dunbar Number.
a consultant can talk to the ceo as an equal.
however, a consultant can also talk to the mail clerk as an equal.
It is not humanly possible to be knowledgable in all the fields of people working directly or indirectly under you. Good managers are not always technically knowledgable . It is useful skill to have, neither it is most important nor is it even essential.
While bad managers tend not to have the knowledge, the worst managers are strong technically but don't have other critical skills needed for the job.
But as a manager, you need to know what your organization is doing and you need to know who to ask.
That is, by very definition, the job of a manager.
i think you hit the nail on the head here. the problem is that the upper management usually arent clueless, they are just better leaders than they are doers...
I've had highly effective managers before, who were trying to get promoted. Just like I've met highly effective developers, who were trying to get promoted. That's orthogonal to making a good product.
They wanted to get promoted because they wanted to be able to be more effective; everything they had control of went very, very well (we were empowered to make decisions, he helped us navigate organizational obstacles, and was the sacrificial lamb for useless meetings). All the issues we ran into were from outside his circle of influence; product had its own reporting hierarchy and they were a mess. Integrations with the rest of the org were more bureaucratic and less capable, and getting them to do anything required getting VP level support on our side, etc. Had he had more sway, we could have executed faster. We directly benefited when he got a title bump.
I think what you mean are those who are putting individual success over team success, and yes, those managers are either evil or incompetent.
http://www.shirky.com/weblog/2013/11/healthcare-gov-and-the-...
Back in the mid-1990s, I did a lot of web work for traditional media. That often meant figuring out what the client was already doing on the web, and how it was going, so I’d find the techies in the company, and ask them what they were doing, and how it was going. Then I’d tell management what I’d learned. This always struck me as a waste of my time and their money; I was like an overpaid bike messenger, moving information from one part of the firm to another. I didn’t understand the job I was doing until one meeting at a magazine company.
The thing that made this meeting unusual was that one of their programmers had been invited to attend, so management could outline their web strategy to him. After the executives thanked me for explaining what I’d learned from log files given me by their own employees just days before, the programmer leaned forward and said “You know, we have all that information downstairs, but nobody’s ever asked us for it.”
I remember thinking “Oh, finally!” I figured the executives would be relieved this information was in-house, delighted that their own people were on it, maybe even mad at me for charging an exorbitant markup on local knowledge. Then I saw the look on their faces as they considered the programmer’s offer. The look wasn’t delight, or even relief, but contempt. The situation suddenly came clear: I was getting paid to save management from the distasteful act of listening to their own employees.
In the early days of print, you had to understand the tech to run the organization. (Ben Franklin, the man who made America a media hothouse, called himself Printer.) But in the 19th century, the printing press became domesticated. Printers were no longer senior figures—they became blue-collar workers. And the executive suite no longer interacted with them much, except during contract negotiations.
This might have been nothing more than a previously hard job becoming easier, Hallelujah. But most print companies took it further. Talking to the people who understood the technology became demeaning, something to be avoided. Information was to move from management to workers, not vice-versa (a pattern that later came to other kinds of media businesses as well.) By the time the web came around and understanding the technology mattered again, many media executives hadn’t just lost the habit of talking with their own technically adept employees, they’d actively suppressed it.
I wonder if some parallels to this story (listening, without contempt) exist within the sphere of political polarization.
https://web.archive.org/web/20140122141413/http://www.shirky...
Tell me about it. On one of my previous jobs I would constantly speak out about what we were doing would cause people to lose hundreds of thousands of USD, and every time I was laughed out of the meeting for "overthinking" things (I guess that's what wanting to do things right is called these days). When one of our customers lost US$200k and nobody had any idea why or how or when I knew that company would be the death of me, and coincidentally I was on the same meeting I planned to use to quit my job.
If anything it taught me that working in finance is not for me :p
They have a long experience of asking the right questions to the right people , filtering out useless inputs, creating the right abstractions strategically from tactical inputs, there are very niche skills, it may be easy for us, but for the non technical manager it is black magic
As a very expensive consultant I'm surprised the reason is not more clear to you. Most managers like to pay consultancy firms so that they can cover their asses.
If they just followed the guidelines of what the McKinsey team said then surely they weren't in the wrong. Whilst if they followed the advice of a subordinate or god forbid made a decision it's on them.
That is to say, he did executive level work. I imagine he’ll do similarly great work at Twitter, setting them up for long term success, just as he did at Stripe
You need tools for your group.
IT wants to use tool MSFT.
Everybody has been using tool X for a while. They like it, but there is issue Y.
How does upper management resolve this?
You don't hire security personnel to address previous breaches.
If those are the hard business/technology management problems (and they are), then try solving those while also securing them.
Security by itself is relatively straightforward: 0days, red teaming, scanning for known vulns, etc. Just like every other aspect of the business, you hire someone to do one specific thing and you've got lots of options.
But then try to infuse security into every single aspect of a business and product, in a way that increases both velocity & quality of product dev, without sacrificing efficient organizational management. There are already a ton of inscrutable complexities between all facets of the organization and its products. Trying to add security to all that is like teaching a juggling elephant to ice skate.
So you need someone who's very good at managing security in the context of all those other problems. That's hard to find. It helps to have people who've seen problems in the same general space from a lot of different angles.
https://www.youtube.com/watch?v=VVJldn_MmMY
Good for him.
It's very interesting work but I haven't seen wide discussion on it so far.
Wrote them on Facebook one day and they tried to sue me
[1] https://blog.haschek.at/2019/threat-vector-legacy-static-web...
What does "tried to sue" mean?
Did they file a suit? Did they threaten to sue but not follow through?
To them you'll likely seem like an overzealous geek that shouldn't mess with their business website. I've experienced this before myself and it's not particularly a good position to be in.
Their site has most likely been technically abandoned, i.e. no one capable is in charge anymore.
It'd be best to talk to the owner, show them your "hack" (change it to cats on your phone and let them verify in their browser) and offer them to fix it for free.
That's how one does these things in our small country. ;-)
but obviously that's not what happened
1. Telling them in person (they didn't understand)
2. Asking for the IT persons Phone number (they didn't give it to me)
3. Leaving my phone number and email (they never contacted me)
4. Notifying the austrian CERT (they never got an answer from the owner)
5. Notifying the press (standard.at posted an article about it, they didn't respond)
6. Writing them on Facebook (ob boy did they respond :D)
But since my first police raid I don't publish anything before letting my lawyer read it. He said if they do press charges they haven't got a chance since I have a paper trail of everything I did and didn't harm them or their site in any way
Warn them once and if they get hacked it's their problem. What's the proverb? You can lead a horse to water but you can't make it drink.
If I come up to you, the owner, and kindly warn you that your doors can easily be unlocked, your reaction would probably be a big thank you. But, I also understand that you are free to answer me to get the hell out of your lawn, because it's none of my business.
Sure I am doing it for your safety, for the safety of your kids, your wifes, and your valuables. I have no ulterior motives.
But, you have the right to not want to listen to all the ways an intruder can come to your house and steal all your stuff. You should have the right to find that information useless, and I don't have any say in that.
Now, warning all the town that your house is not secure enough to try to provoke an answer from you ? What do you think about that ? Really curious.
In the end it turned out that they didn't "not want to listen" the information just never got to the right person (internally) and I talked quite a bit with the owner (after understanding everything he even thanked me) and he said he never got a contact from CERT but I asked them and they said they wrote them twice.
Would this be like offensive cyber security? Or active security?
If youre manipulating the engagement statistics, then you're dealing with a particular type of bad actor...
This is taking me down memory lane.
Beto O’Rourke... What???
If my memory serves me, a bunch of editable PDFs and drop-down selection boxes that gave no clue as to the correct content. Some serial number, depending on your insurance provider, AS234 BD568 and so on. A total mess.
https://web.archive.org/web/20140122141413/http://www.shirky...
L0pht also predicted the offensive potential of BGP black holes.
Sounds more like some solid counter-intelligence people to hire would be good here, rather than straight infosec. But still good hire obviously and I'm sure this sort of thing has been thought out already.
Side note: Getting to hand out grants at DARPA sounds like a fun job.
Really though, Peiter has just been in the bullpen for roles like this for awhile now. There's several people like him ready to be tapped for high-profile roles (Stamos is the best example, though he seems happy where he is).
A thread:
I know that security is harder and requires wide grasp of theory and solid proficiency in practice but you know:
bad algo can almost always be rewritten, leak cannot be reverted.
I'll use this opportunity to advertise stuff:
Try against world class hackers/security engineers
>Capture the Flag (CTF) is a special kind of information security competitions. There are three common types of CTFs: Jeopardy, Attack-Defence and mixed.
>Jeopardy-style CTFs has a couple of questions (tasks) in range of categories. For example, Web, Forensic, Crypto, Binary or something else. Team can gain some points for every solved task. More points for more complicated tasks usually. The next task in chain can be opened only after some team solve previous task. Then the game time is over sum of points shows you a CTF winer. Famous example of such CTF is Defcon CTF quals.
>Well, attack-defence is another interesting kind of competitions. Here every team has own network(or only one host) with vulnarable services. Your team has time for patching your services and developing exploits usually. So, then organizers connects participants of competition and the wargame starts! You should protect own services for defence points and hack opponents for attack points. Historically this is a first type of CTFs, everybody knows about DEF CON CTF - something like a World Cup of all other competitions.
>CTF games often touch on many other aspects of information security: cryptography, stego, binary analysis, reverse engeneering, mobile security and others. Good teams generally have strong skills and experience in all these issues.
I also don't think ctf's are a good model for security questions during interviews. Knowing how to do something securely is not the same as knowing how to exploit a vuln.
Reversing a binary tree on a whiteboard is certainly a bad question to ask. But I would argue, for all intends and purposes still a miles better indicator about future potential than if someone knows how/why TLS work. Yeah you can read that in a book. I can google it. Useless for interviews.
If you are hiring for a position that requires you to implement TLS, sure go for it. But that is not the rule. And what are you going to do after he has implemented TLS? Will he be able to work on something completely different?
So, in other words, exactly like algorithms then?
(Admittedly, candidates are likely to have memorized the algorithm for reversing a binary tree since that is such a common interview question)
Exactly my point. Testing for "how to implement a known algorithm" is much the same as recalling facts about TLS. You're testing recall only.
If you are the interviewer, even if you are asking a standard "how to invert a binary tree" type algorithm question, you hold the cards to keep pushing the bounds for problem solving by extending the question.
If you hire based on knowing how the the internet works (TLS, HTTP, BGP, whatever), then you'll be working with a bunch of people that understand how the internet works.
I know which team I'd rather join.
Now, if I'm hiring a sysop / devop / security engineer, it's going to be differently focused to some extent, but the same principles apply - core knowledge, communication, humility, ability to research.
i though like you before doing interviews
Some of the absolute best engineers that I've worked with take their time to wrap their heads completely around a problem before diving in. They aren't slow thinkers, but they aren't people who excel at these kinds of interviews either.
I've been doing interviews for a long time now and I find it more effective to surface strong opinions about things they've worked on -- good and bad.
I'm not hiring into a feature factory -- I don't care about fast cogs. I'm hiring people who care about what they do and giving them an environment to thrive in.
Meanwhile there's a decent chance of them running into a problem that looks like binary tree manipulation.
Despite all the handwringing about btree reversal, not being able to improvise a solution to that is a much more useful indicator than not being able to describe even the basics of TLS.
A security engineer is just as likely to derive a tls cipher config from first principles instead of googling/looking at ssllabs as a programmer is likely to reverse a binary tree from scratch instead of using a library or searching stack overflow.
Engineers (of any stripe) aren't hired to recite random knowledge, they're hired to know what knowledge is appropriate to apply to a particular situation.
It's probably not even that hard, but I doubt I'd be able to improvise a solution in an interview setting that's nothing like a real work environment. (Memories of trying to work out some kind of graph traversal while someone was basically just staring at me.)
It seems to me that people who are doing this kind of work behind the scenes of a web app aren't really doing web development.
As someone in a public company with actual customers, we have to deal with TLS configuration all the time (as customers come with requirements and being public comes with compliance/security) and it's important to know what we're doing there...
I'm responsible for millions of dollars in infrastructure and the way that I got here was being a web developer who knows how the internet works. And in an engineering organization with hundreds of engineers, most of them tend to come to me first with questions.
I have never once in my career had to reverse a btree.
Security vulns move waaay faster than algos
Setting your security test labs takes way more effort than opening IDE, LeetCode, checking informatic olympics tasks or maybe some book/pdf/write up/wiki
When developing algos you're in your own world meanwhile security often has to mess with other things like software, standards and stuff
e.g you're interested in web sec/hacking, then except understanding of standards (what it allows and what not, etc.) then you have various implementations to care about like web browser - chromium, gecko, ie, safari and stuff. It's a lot of effort!
Let's say that you want to find vulns in PDF parsers/renderers by checking their code source code - I think it'd take a lot of effort to check and understand (let alone exploit) those implementations in two major browsers (I suppose they're different, but I've never checked that)
>I also don't think ctf's are a good model for security questions during interviews
I didn't meant that, sorry if I made it sound as if I expected people to solve CTF tasks during SE interviews
Just wanted to encourage people to do cool stuff :)
It depends a lot on what you're doing of course. I do web application security stuff (glorified xss detector), i've personally felt that the most useful tools by far are the browser dev console and curl, but ymmv.
> I didn't meant that, sorry if I made it sound as if I expected people to solve CTF tasks during SE interviews
>Just wanted to encourage people to do cool stuff :)
Oh i definitely agree, ctfs can be a lot of fun.
Most compromises are credential stuffing.
Advanced security knowledge is not needed for developing software. What you need is a security team that reviews the work your developers produce. That's it.
> bad algo can almost always be rewritten, leak cannot be reverted.
And while a bad algo can be rewritten, bad software often can not. Bad programmers are a disaster for scalable software projects. A leak can not be reverted, but so can't the product you didn't ship because you hired the wrong people. Or the company who goes bankrupt because you weren't able to ship a product.
Building software with security engineers instead of software engineers is like trying to win a Formula One race with Fighter Jet pilots.
You need to know how to avoid common pitfalls (i.e., yeah, maybe nested for-loops with millions of elements per level of iteration, maybe some alarm bells should go off)
Advanced algorithm knowledge is not needed for developing typical business software.
Bad security is a disaster for any public-facing software projects. A product you didn't ship because you hired the wrong people can't be reverted, but neither can a data leak.
Or the company who goes bankrupt because you leaked highly sensitive data.
Etc. etc. ad nauseum.
Would be nice but no, not really. The standards you mentioned are mostly compliance requirements. To be honest, a good chunk of the industry considers them as kind of a joke from a security perspective.
> It's comprehensive and not that hard to learn
Have you even read these standards? I mean, they might be "not hard to learn" but they are far from comprehensive (or specific, depending on which one you are looking at)
> Twitter are not remotely close to operating like that given their recent hacks
Ask literally any security professional you trust, companies compliant with PCI DSS and ISO27k1 get security incidents and breaches all the time just like everyone else and possibly more (given that if they need compliance with these standards they are probably big enough to have very wide/heterogeneous infrastructure/applications portfolio/administration practices/etc). If they claim they don't, that's most likely because their telemetry sucks (so, it still happens they just don't know about it)
The thing to do is familiarize yourself with the OWASP Cheat Sheets directly related to the things you do day-to-day...and to check if the thing you're working on relates to one you're less familiar with.
Please no, but I agree that security questions could be a very good addition. But please let's not replace something used as an under par proxy for the ability to program with something likely even worse.
I don't want to hear the answers. My faith in humanity is already hanging by threads.
I know this is my problem. It's really hard for me to not flip the Bozo Bit. To take both the good along with the bad every person has to offer.
Story time.
I worked near "Chris", a tech lead senior architecture fella. Same product group, different code bases, thank god. I disagreed with pretty much everything Chris said, but I accepted that we're all opinionated and it's more important to be consistent than to be right (correct). So long as his team kept shipping, Chris could do whatever he wants.
Until.
Because Chris was loud, large, older, and a boar -- exemplar of mansplainer -- he was influential. He convinced most of the people within ear shot (half of the floor) that password wallets were a terrible idea. I kept listening, to hear the rationale. Maybe he had a legit reason and I was the clueless noob.
Nope. "Single point of failure. If someone cracks your wallet, you're fully pwned."
Chris is why that product group could not, would not adopt any credentials (secrets) management strategy. It was all wikis and PostIt notes.
Reflecting back, it now occurs to me that hoarding the credentials may have been Chris' gatekeeping power move. Hmmm.
So, the new security guy reports to the guy who handed Trump a blank check to over communicate while serving public office?
> !g how many employees does twitter have?
3,920 employees
ZERO sense. Twitter needs to be dismantled.
I agree with you, but on other grounds.
That's not how Mass psychogenic illness works. That's not how people act. And most of all that's not how Twitter is being engineered.