>"The real security incident here is how did the intercept learn of that ticket as that should really be classified."
Looks like someone from the security or PR departments took a picture of the ticket with their cellphone and sent them to the reporter.
Security tickets are immediately encrypted and locked down. Only a few members have access typically: The person who opened the ticket, anyone with a need-to-know, and people on the IR team. Even director-level employees need to be manually added to security-related tickets to have view permissions.
Out of those two groups, Occam's razor implicates the one with a vested interest in currying favor with reporters.
I obviously wouldn't look in internal ticketing systems and THEN post to my findings to a public forum like HN. For obvious reasons.
2.) > "It seems much more likely this is typical left leaning employee activism that is prevalent at tech companies."
If standard security ticket procedures were followed, it would have been locked down to the security team and the impacted team (i.e. PR/social media).
The comment that it 'seems much more likely that this is typical left leaning employee activism' implies that there aren't left-leaning or activists within the security or PR departments. Which if you believe that... lul...
One of the many reasons I’d never want to work there
Reminds me of this: https://www.nytimes.com/2020/09/13/business/media/the-interc...
> The Intercept scrambled to publish a story on the report, ignoring the most basic security precautions. The lead reporter on the story sent a copy of the document, which contained a crease showing it had been printed out, to the N.S.A. media affairs office, all but identifying Ms. Winner as the leaker.
It strikes me as a sarcastic joke by burnt out security staff. Which would explain why we are hearing about it.
They very much favour proactive reports, and heavily emphasised that they'd rather have a ticket and resolve it as nothing, than not be ticketed at all because you're not sure. Unusual behaviour on a twitter account are most definitely things they'd expect to have reported to them for evaluation, or expect to report themselves if they saw it.
This however, makes it possible to make security reports for political effect - after all, if your guidelines are to report anything suspicious, nobody can fault you for doing just that.
Is it also standard policy at Amazon to leak security reports to the media, or discuss them with journalists after the fact? We both know that's not the case.
Actually rereading it again I would say the source is the person that opened the ticket and not a member of the security team.
If they were taking the matter completely seriously, I would not expect them to consider publicizing it, or discussing the ticket publicly after the fact.