Twitter shakes up its security team
nytimes.com
nytimes.com
"Mr. Agrawal said the “nature of this situation” limited what he was allowed to share with employees"
Even when things are a bit contentious, companies and C-level execs like CISOs usually come to an agreement and have a joint statement about 'spending time with family' or 'pursuing other endeavors'. This sounds like it was either very one-sided, or something very bad was happening...
I imagine they wouldn't want to cite differences of opinion on security posture as the reason for departing.
More likely they just weren't getting things done fast enough. CISOs come and go - they're a very short lived position.
The best- run companies I've seen with respect to this have regular and frequent security audits and assign tickets to the team who wrote the code, sometimes even to the developer who wrote it. Also, security is built into the continuous integration as much as possible.
I understand why they wouldn't from a personal perspective, however I can imagine situations where this is the right call. For Twitter perhaps not, but I hope the CISO who works at my bank would make this choice if things got bad enough.
I'd be surprised if that warranted the “nature of this situation” language.
Then again, I was at a large company where the CISO managed to get insta-fired in a 1:1 with the CIO. I actually saw the person about two minutes after it happened while they were grabbing their jacket and heading for the door — I don't know what was said, but judging by appearances things got really heated and the CIO had enough. Corporate security appeared shortly to begin boxing things up.
Hard to find longevity or stability in a role that exists to fail
The only way you can really get better security at a company is to have an ingrained security culture. I.e. developers are continually educated on secure coding practices and new threats, code reviews include security checklists, corporate security training includes continual social engineering tests and an atmosphere of continual improvement.
And yes, that stuff does cost money, but that's rarely the resources I see CISO's fight for. Instead, they fight for lots of expensive software, things like useless, shitty WAFs or poorly built "network monitoring" software (which can be a huge threat vector in itself, just see the SolarWinds fiasco).
Like many other comments here, I don't believe security is something you can "bolt on" at a company. Yes, there are specialized roles that a dedicated security team needs to fill, but unless everyone at the company has a true understanding of the value and importance of security vigilance, you're screwed.
I strongly agree though that you can't really bolt on security, it needs to be designed in and part of the culture as much as possible. You'll never get everyone to understand the value though (I wish!).
Can I have a checklist please?
Full stack web dev
Edit: Here I found one https://www.michaelagreiler.com/security-code-review-checkli...
But as list of things to consider, if you already understand what you're doing, its not too bad.
It's probably like the old saw about advertising. Half of all it is useless, we just don't know which half!
So either the company does well and the CMO stays, or not. And the default for most companies is to fail.
I have no idea if that has to do with their day-to-day roles or the specifics of why they were let go, but it is all a bit interesting.
Twitter has been shaking up management for a couple months now. I have no inside knowledge, but this is pretty plausibly just more of the same kind of thing.
Getting fired is all part of the job as an exec in a tech firm, but the messaging is enough out of the norm that it does make one wonder about them refusing to do X or Y, etc.
Into the territory of startup fanfic, I'd assert from Agrawal's perspective, he needs his own team, and a top technologist indexed on engineering competence is overpowered as an individual at that level - and for the agility the CEO will need for the next stage of his company. He needs his own people to execute for him. The company is no longer a startup, and its explosive growth phase is behind it. Now it's an asset to be managed, and doing that is an orthogonal set of skills to building and managing growth, so you need people who operate aligned to a longer horizon. The previous CEO's tactical super-hire isn't necessarily going to be the same asset for a new CEO's strategy.
It's odd to comment on this like its sports writing, but that's effectively what following these companies is. Knowing very little about the individuals, I don't need to mind read, as there are clear external incentives for this that make it a fairly neutral change.
When you inherit a powerful asset like that, as CEO that can be double edged. It's great to have someone that amazing around, but if they can undermine the momentum in your leadership even (especially?) unintentionally, while you're driving a massive organizational change, the choice really makes itself independent of the individual characteristics of the people involved.
Ceasing to work at twitter is probably the least interesting thing Zatko has ever done, so I don't forsee this reflecting on him at all, but before there are drill downs on personalities and culture stuff, it's worth looking at it from straight business incentives.
I have no insight into what's happening at Twitter but if you made me bet, I'd bet against there being any interesting drama here.
And, again: high-level organizational management seems like a weird place to slot Zatko, who seems like he'd be happiest as like, a senior fellow at CSIS or something.
Regarding your reflection on the way you communicated your ideas on this: I found Stratechery extremely insightful and funbexause they approach tech and business from this sort of wonky fan-in-the-stands viewpoint. Over the years it helped me wrap my head around a lot of the weird quirks of business.
What more did you want?
It seemed very unlikely to be credential stuffing or other common things. It seemed more like a rogue inside person or back office hack.
>The Twitter incident began when the hackers connected last year in an online forum focused on buying and selling rare user names, some of the individuals involved told The New York Times at that time. They then broke into Twitter’s systems by tricking employees into providing login information, according to legal filings. The hackers used an administrative tool to take over accounts belonging to political figures and celebrities, including former President Barack Obama, Kanye West and Elon Musk, using the accounts to conduct a Bitcoin scam, the filings said.
https://www.nytimes.com/2021/07/21/technology/twitter-tiktok...
This also isn't a problem limited to governments and politicians. It calls into question the authenticity of every account on Twitter and that includes other important accounts which can cause damage if compromised such as journalists and news organizations.
Anyone with access to Twitter has access to whitehouse.gov. Twitter isn't delivering value here, they are a huge societal risk.
And as a corollary, the people will go to whatever channels exist.
This has been something done many times as mediums change. Newspapers to Radio. Newsreels to Television.
Then to the internet, we started with everyone telling you their AOL keyword. Then the web, and then social media.
If authenticity is the concern, these players (journalists/politicians) should adopt W3C recommendations and stand up social media services from their own web presence.
Many sectors (finance, health care, etc) have all kinds of auditing requirements. I've helped answer some of these audits. It's largely just a bunch of checkboxes for obvious stuff, and in general, isn't how anyone would attack a company that's moderately competent. I've seen and fixed security vulnerabilities in startups that no one else recognized where there, despite passing all these 3rd party audits. I don't know what more could have been done without extremely knowledgeable people look at every aspect of your business in absolute depth that in part only comes from actually working/building it in the first place. Such experts are rare finds, yet the number of companies with computers attached is far greater.
I'm not against legislation, and I think good legislation would look like taking companies such as Equifax out of business. We don't need total incompetence continuing to be central to society's function. But we also need to be realistic about what can be achieved.
But either way, you are getting too bogged down in the specifics of my hypotheticals. Like I said originally I don't have the answer on the perfect solution, but the fact that we didn't use this incident as motivation to have a discussion about potential solutions is disappointing. Can you at least agree with that?
> legislative changes in order prevent that worse version from happening in the future.
I’m not convinced legislation achieve your goal having already seen HIPAA in action in law, the systems behind the scene, and the ways in which compliance works. Is it better than nothing? Sure! Does it actually create truly secure systems? I don’t think so.
If liabilities are severe where companies could go under or people go to jail, then I’m still not sure that would be enough to secure systems because you’re always a 0-day away from breach. But if the result is twitter going under or their CSO jailed, all I think that happens is you remove global competitiveness.
I agree with you more should be done. But perhaps in different ways. For example, requiring everyone to take basic security classes before you can be a software engineer might help. Creating societal incentives where bug bounties are required, white hats cannot go to jail or be sued, DARPA spends big on defensive security strategies, and stating the US will take cyber attacks the same as physical attacks are ways that I think would produce better outcomes (but would risk war).
[0] https://www.google.com/search?q=hacked+site:https://www.redd...
I'm not sure if I buy the internal tool angle here.
Third party app developers are more likely to have been. It's also likely for a third-party dev to have bad intentions.
I periodically review and make sure to disable third-party app access to my Twitter accounts. Who's to say your average celeb is likely to do that?
> We detected what we believe to be a coordinated social engineering attack by people who successfully targeted some of our employees with access to internal systems and tools.
It was social engineering, but still access to internal tools which made this bypass possible.
Sound security practices enable good business, e.g giving teams a paved road (https://www.slideshare.net/diannemarsh/the-paved-road-at-net...) that enables rapid and secure releases in place of gates.
At least from what few accounts I've heard from engineering in Twitter, it doesn't sound like Mr. Agrawal has much faith in this idea, but that just means he'll be the first to go in the event of the next inevitable breach.
Watch it be over something dumb like stolen NFTs.
This guy has a toxic history of narcissistic behavior as reported in several local Indian social Media and he would only seem to suck up to corporate demand and make Twitter more suffocating.
> "heading towards a direction to suit activist investor demands"
and
> "This guy has a toxic history of narcissistic behavior"
"Financial activists" like Carl Icahn or Starboard frequently take > 5% stakes in order to pressure companies to sell themselves to competitors, break themselves apart in order to shed lower-performing divisions, funnel cash to shareholders through dividends or stock buybacks, or reverse policies they see as injurious to the bottom line
CEOs naturally hate this, and activist investors have a reputation -- arguably often well-deserved -- for improving the profitability of their portfolios at the cost of the companies they target. Sometimes this can force companies to walk away from suboptimal strategies -- did AOL really think Patch was going to be a market maker? -- but in many cases their activism simply results in the company's acquisition, aggressive offshoring or deindustrialization, or just straight-up bankruptcy. Icahn, for example, took a heavy position in Blockbuster and was instrumental in forcing them to reinstate late fees and drop plans to enter the streaming market, which left them exceedingly vulnerable when Netflix introduced streaming (the dueling HBR articles on this are well worth reading).
Over the past few decades "social activist investors" have become more common, especially amongst large public sector and union pension plans who have both financial throw-weight and a need to answer to causes somewhat beyond their immediate bottom lines, but in general they are much smaller, and less effective, groups than the usual hedge fund suspects. For example, an organization of decarbonization activists have been trying for years to force ExxonMobil to diversify its energy base beyond hydrocarbons (as other petrochemical firms have done), but they've had notably zero effect on XOM's strategy, despite having an argument based on economics as much as ecology.
https://edition.cnn.com/2022/01/24/investing/peloton-activis...
:D
Maybe you really hate twitter, so you buy into it for $200 million and then use your power on the board to vote down anything good for twitter and vote for anything that is harmful.
Activist investors often don't act in line with financial interest, instead focusing on "activism" even if it costs money.
Don't follow. What does that have to do with anything about the original post?