where I work people are trying their best but dealing with complex systems, memories, and methods of communication. because of this, security issues are sometimes missed, sometimes poorly communicated, and sometimes poorly remediated.
Hiding something often takes years to uncover and by then management has moved on, maybe even to their second company!
Fwiw, I've ended up being "middle management" at a large company, with deep technical background, and I'm trained and incentivized to report, escalate, inform, communicate, share, and otherwise ensure its addressed up the bloody wazoo. I get slapped on the hand for not communicating / informing enough, never for communicating too much. Over 2 decades, I've never seen my executives try to cover something. "Manage the narrative", sure, but that's largely about how they craft a sentence, not about not reporting.
However, I have also witnessed corporate culture in other places (as embedded consultant) where each layer is terrified of layer above, and each layer is heavily punished for reporting "bad news". They were institutionally set up to fail project deployment as risks are not escalated and they proudly plunge forward. They're not sure much top-down knowingly obstructed to hide stuff, as much as electroshock therapied that it's a bad experience. Taking the most cursory log at the most basic logs and saying "whee, no evidence of exploit!!" Would be par for the course :-/
As a non-lawyer, that sure sounds like sketchy advice, even beyond the rest.
Right, but how so? A person or company can get into trouble with things being written down or made known to others. Having a lawyer consider it first is legally prudent and is entirely reasonable and common advice given out to any person (don't speak to police/regulator/other party/internet/newspaper/etc before consulting your lawyer). If you think that's ethically sound advice for a person, then what changes the calculus for a corporation?
> and maybe not the best strategy for the individual if they're being instructed to keep information to themselves instead of passing it up the chain in the company. Is that intended to keep just that employee responsible for whatever mess?
Probably less instructed to keep it to yourself, more encouraged to stick to "official" reporting channels, and then when you do that or come into contact with such issues by other means, more encouragement to use the phone.
And it completely depends on what it is as to the intention I guess. Initially so that the lawyers are able to consider and advise. But sure you aren't paying the lawyer so they are only taking care of your interests so far as that coincides with the company's interests. So if you had a concern that you would be responsible for a legal problem, or are a victim of a criminal or civil legal matter from the company or another person in it, then I would say you should consider discussing that with your own lawyer.
Seems like a fair expectation to have, to me.
Yeah I'd never assume that any of that is true. Sure, there probably are ways twitter could find out if something has been being exploited like evidence in server logs or new batches of accounts showing up for sale on the black market, but I wouldn't trust that they looked for them, or that they looked very hard, or that the person making press statements was told about it either way.
If a company has a financial incentive to not find information it's weird to assume they'd seriously look or be trusted to be honest about what they found.
This is a relatively benign case but the same language is used in other breaches when people should be taking measures like freezing their credit or reviewing financial transactions.
It's one thing to say "My car was stolen", and another to declare "I am unable to determine if it's en route to the Taliban."
The only thing that could happen with the data would be that it is exploited.
The only thing that happens to stolen cars is not going to the taliban.
These are not even similar in nature. They aren't saying "the data was stolen". They also aren't saying "the data was available for exploit we are unable to determine if that occured."
What if they never looked for evidence of unauthorized access? They wouldn't have any!
This is the same as modern science and medicine frequently using this academic phrase, no evidence, when what they mean is that there has been no investigation.
Another thing to mention would be how long in the past you were able to look. E.g. in this case they have found out that the bug was introduced in 2021, were they able to inspect logs covering all of that period or did they only had limited logs/other evidence so it's impossible to know whether anyone used this opportunity or not?
Nothing would have stopped someone from using it. Probably best to assume that they have.
This will be read by optimistically 1% of people, the rest will just catch the summary. This way, you at least get to write the summary.
It could also mean "oh I spent five minutes looking into it and didn't see any evidence"
Otherwise, the reasonable thing to do is to assume that it was exploited, because they have no evidence to show that it wasn't.
The phrase is a psychological trick because it creates the illusion that the burden of proof falls on the other side.
Which is maybe not the worst strategy, but it's going to be pretty exhausting.
I'd suggest that instead we should just expect and enforce a certain amount of openness and honesty from companies when they fuck up in this way, so we can make informed decisions.
In the US and elsewhere, there are already some penalties for covering up a problem, and they should be expanded commensurately with the potential harm.
If there were, call it p, and let q = Π(P), P∈N:P is prime (Eratosthenes showed this is computable)
Then q+1 % 1 modulo every lesser prime, meaning q+1 is prime, and p is thus not the greatest prime.
There you go. We have just proven a negative.
"I have no evidence he murdered someone"
As opposed to
"He might have murdered someone, or not, I just don't have any evidence"
"It's possible he murdered someone I don't have any evidence though"
"I don't have any evidence he murdered someone but that doesn't mean he didn't, I'm just asking questions"
"We left a giant tub filled with cyanide completely unsupervised in front of our door for months. We have no evidence that it was used to murder someone."
Has an entirely different sound to it, no?
"We left a giant tub filled with cyanide completely unsupervised in front of our door for months. We have no evidence that it was used to murder someone."
No one would say that second sentence, if you don't have evidence of something you don't state that because of the set of objects and events that didn't happen is infinite.
"We left a giant tub filled with cyanide completely unsupervised in front of our door for months. We have no evidence that someone accidentally fell into it, an animal died in it, it was used in a bank robbery, someone's cell phone slipped it in............"
"That person owns a gun legally, we have no evidence that he used it to murder someone"
Why not
"
source: I am not a lawyer
I could bring up examples across both sides of the isle. It's all a big game.
Absence of evidence IS some evidence of absence if you look thoroughly. It sure isn't anything of the kind if you haven't actually tried to gather the evidence or are aware of giant holes in what you were able to gather.
How hard they looked is not of any consequence if they can't tell it wasn't exploited.
Isn't that taught in..uh..I dunno, middle school science class?
Just because you don't see the rabbit, doesn't mean it doesn't exist.
https://medicine.uq.edu.au/article/2019/04/you-look-do-not-f...
They should be open and forthcoming about their level of confidence, instead of using the least worrying language they can offer while remaining technically correct.