Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies
cnn.com
cnn.com
Mudge knows the implications of "whistleblowing". He has been a security consultant and even testified to Congress. He's not some noob that doesn't understand security or how systems work together to provide services like disclosure to FTC. The idea that Twitter PR can pooh-pooh away his concerns is shockingly stupid.
I think Twitter is in real trouble here.
Such a 5-year old boy way of naming things.
A) an old hand and doesn’t know how to run a security program with the tech today
B) a strong tech hire who can’t lead a program.
But Mudge is still… Mudge, and he’s also proven his ability to collaborate so if he was a bull in a china shop a twitter, that would be surprising.
There’s also a broader trend here of well known security leads that originate from that time working at social media and leaving quickly, like Alex Stamos, who also u-turned out of Facebook.
So are the odds higher that Mudge did a bad job, or this set of companies are not great internally and old guard security leads are pointing it out? The twitter CEO letter framing him as a bad employee doesn’t address this context.
I worked with Mudge (not super close, but enough to see how he worked across teams etc) and can certainly say this is not the case. At least when I saw him Mudge was excellent at the program leadership aspect of his role. At one point he ended up a DARPA PM. You can't go from L0pht to DARPA without getting really good at working with other people and leading projects.
While he was always a notable presence, he was also never prone to drama, and very good at having ego when it was important but never letting it get in the way.
Additionally all of the details sound like every KPI chasing consumer facing tech company I've ever worked with. I think we all know a few very competent people who have stood up to leadership at insane tech companies and ultimately gotten fired for it.
https://www.cnn.com/videos/business/2022/08/23/peiter-mudge-...
I mean, if an auditor publicly reports an audit finding that is ignored by the company and his ethics demand its reporting, is he branded a "whistleblower"? I do not think so, instead it is an "auditor finding". Why does that not apply here?
It kind of dovetails with how pathetically organized IT in general is from a professional standpoint. Lawyers, Doctors, ... ?Accountants? and the like have centuries-codified procedures, principles, and the like for ethics. You generally don't get to hire one of those and tell them how to breach ethics (now, there are a lot of corrupt lawyers and a lot of corrupt accountants see: Arthur Andersen).
The exploit industry has the 0day and x days of forewarning process, so there is that, but the fact a security consultant/professional gets accused of whistleblowing when... um, isn't that sort of the point? You hire a security consultant kind of like an auditor. And if auditors find major failings and they aren't addressed, aren't they supposed to report them?
I'm pretty sure the security IT industry does not have even accountant levels of professional conduct and organizations.
As IT subsumes and infiltrates, now to the point that fundamental bill of rights / human rights are dependent on secure and functioning IT systems, it gets... a bit more important. Arguably more important than the ethics around accountants and doctors. Lawyers, because they deal with the law, are probably more important still, but it shows that IT security may be rising in import to that level.
[0] Companies want the letter to say whatever their regulators and/or contractual obligations demand that it say.
Twitter is a publicly held company.
I'm sure there are conflicts of interest and some degree of confidentiality for auditors and clients, but there is a fundamental public interest of disclosure, at a minimum to the government, in the event of irregularities.
From the SEC:
"In addition, we will continue to focus on auditors. As the Supreme Court noted nearly 30 years ago in U.S. v. Arthur Young & Co., 465 U.S. 805 (1984), auditors play a crucial role in the financial reporting process by serving as the “public watchdog.” So, it is important that we carefully monitor their work and ensure that they fully comply with their professional obligations. If there is a significant restatement or if we learn about improper accounting from a whistleblower, our proactive efforts, or the media, then you can expect that we will scrutinize not only the CEO, CFO and Controller, but also the engagement partner, engagement quality reviewer, and the auditing firm as a whole. We are going to probe the quality of the audit and determine whether the auditors missed or ignored red flags, whether they have proper documentation, and whether they followed professional standards.
And it is important to remember that our ability to bring Rule 102(e) bars against auditors extends beyond instances where there are accounting irregularities at a public company. Our Rule 102(e) program is remedial in nature and meant to protect the integrity of the Commission’s processes. As a result, we can and have investigated auditors when their audits fail to meet the most basic standards, regardless of whether there was an actual problem with the auditing client. By pursuing actions over these bad audits, we can fully leverage the Division’s resources and close off access to those who shirk their responsibilities as gatekeepers to the securities markets."
-------From there you can see legal and institutional gravitas, ethics, and expectations of accountants and auditors of public companies. That's kind of what I'm getting at re: elevating security and certain IT roles to higher responsibility and codification.
Now, is this a smear attempt by Jack Dorsey in relation to the Elon Musk lawsuit? Eh, maybe.
https://www.investor.gov/introduction-investing/general-reso...
(search for "resign")
The SEC quote is about requiring auditors to meet their professional standards. Those standards require them to follow certain processes, things like needing to see evidence for certain things, and not both preparing the books and auditing them, and require that they not issue letters they don't actually agree with. Those standards do not require informing the public or regulators about problems they find.
There's certainly something to be said for having some codified professional standards for infosec professionals, but if public or regulator notice is something you think is important to be in those standards you shouldn't model them off of the standards for auditors, because auditors have no such professional responsibility.
* L0pht / @stake: security research, red teaming, and source code auditing, IIRC.
* BBN: research.
* NFR: technical advisory board.
* DARPA: Managing a program that provided grants for new security products and tools.
* Google ATAP: Google's "invention studio".
* CyberUL: Testing of security products.
None of these jobs really suggest a background in building a security program. I've worked with some large companies in a similar space to Twitter building their security programs and you can spend the first 6-12 months just trying to justify the new budget. Often that money has to come from another team or teams and he would have to justify that. He was apparently only there roughly a year.Again, I don't doubt Mudge's bonafides. I don't doubt his security knowledge. But this job was nothing like any he's had in the past.
I also don't doubt his claims. Everything he's stated is almost certainly true. It does take more than a year to fix most of these problems and I wonder if he just got frustrated with the political battles that occur in these situations.
Decades of experience as a rebellious hacker? Well, that's not commercial experience. Founded a security consultancy? Too small, they just don't know how to operate in a large bureaucracy. Worked at a secretive company as an individual contributor? They've been completely silent in public, clearly they haven't achieved anything interesting in years. Working elsewhere as an individual contributor? They just don't know how to build a team. Decades as a senior manager at a huge multinational corporation? Out of touch bullshitter, stale coding skills, doesn't know how we really do things these days.
He seems to have tried to escalate things to people above Agrawal nearly constantly. He was hired by Jack Dorsey, and felt accountable to him and to the board, but he reported to Agrawal, who believed that Mudge had a responsibility to follow the chain of command very rigidly.
I have previously had managers who want you to rigidly follow the chain of command, and if you are a "hacker" type, they are a shock (and you are a shock to them). They are often very interested in controlling information that goes upward and how mandates flow downward through them (both to control their reputation and make sure everyone gets information in "proper context"), to the point that they see it as an attack on their position to even speak with their manager. A "hacker" would rather put the information in front of the people who need it, instead of filtering it through the hierarchy.
At the first opportunity Agrawal had to clean house, he cleaned out Mudge because he didn't want to work with him. House cleaning is normal for a new CEO. From Agrawal's perspective, Mudge did a terrible job, since he wanted to circumvent Agrawal.
With $10mm cash bonuses on the table it’s extremely obvious why Agrawal would insist on being MITM
Aha, eg:
https://www.dailymail.co.uk/news/article-10258453/Twitters-n...
So his performance bonuses is more than 10x his salary - incentives to fake good numbers and hide the bad stuff, indeed!
Agrawal's memo, in contrast, reeks of insecurity. The combination of how he's treated mudge and Rishi Sunak and the potential consequences of this complaint (particularly if FTC investigates and finds Twitter has not been following the consent decree) boxes him into a corner -- he won't be able to recruit the talent to solve these security problems and will be seen as an impediment to compliance/mitigation. I could easily see the FTC et al insisting on his resignation as part of a settlement. It's an own-goal.
The content of the complaint is all that matters, and it should be judged on its own merits. It never matters who said what, and attempting to make it matter is ad hominem fallacy; it is what is said that matters.
That said, I can't quite fathom why Twitter's cybersecurity matters any more than the cybersecurity of any of the myriad of online forums, HN included: the "data" simply isn't all that important; it is all public, it is all talk, and talk, as we know, is cheap. Say Twitter is completely overrun by foreign state actors who delete everything. The outrage is going to be minimal. "Dang, I really enjoyed mouthing off on Twitter. Oh, well."
That's not what's dangerous.
Instead, dangerous things include manipulating the algorithms so that "news" of ones choice get lots of visibility. Then a foreign state can influence the elections
I think this is bollocks. 23% of Americans say they use Twitter. 61% of Americans voted in the last Presidential election. So with my bad math, say a foreign state somehow gets every possible Twitter users vote going their way, at best it's going bamboozle 14% of weak-minded Americans. That's at best, the perfect and unbeatable score. The reality is that most Twitter users are not obsessed with the platform, and most Americans are not on the fence with their votes. This concern is not really supportable.
In addition to that, the manipulators / nation states don't attack only via Twitter, and, everything combined ...
Secondly, private messages between people are not public either. Opening that data up or allowing it to be read or manipulated by other entities will drive a lot of outrage and the data contained within is important!
When gaming services leak IPs, they too can get DDoS'ed. E.g. during tournaments or when someone is losing their match.
Seriously, so what? Twitter's IP does not affect national security.
>and as the public square of present, Twitter essentially drives public discourse...
This is being awfully kind to a platform that 77% of Americans have absolutely nothing to do with.
>especially when a large portion of the legacy media has been reduced to sourcing their stories and directly quoting from Twitter.
Ah, legacy media, conservative politispeak for CBS, NBC, ABC, CNN, etc. Can't get away from Twitter on the major networks anymore, it's Twitter all the time? Just what in the heck are you talking about? Turn the news on sometime. The only reason for Twitter to be in the news is Elon Musk (previously, Trump). Or, you know, give one example of a major news outlet using Twitter as source for a story. Real journalists do not do that. They use legitimate sources.
> Secondly, private messages between people are not public either. Opening that data up or allowing it to be read or manipulated by other entities will drive a lot of outrage and the data contained within is important!
Absurd. No one cares what you say in private to a complete stranger you'll never meet.
Governments and their respective departments (at all levels: federal, state, local, etc.) communicate with their constituents via social media, Twitter in particular as well as via the media outlets that will report on said statements from Twitter.
Change the algorythm such that those messages no longer reach people and you can bet the respective countries will pass legislation and puninitive measures against Twitter.
>This is being awfully kind to a platform that 77% of Americans have absolutely nothing to do with
Except I outlined some of the other ways people interact with Twitter, even without accounts. You seem to be incredulous that other forms of media rely on Twitter... You should look a bit closer next time you turn the TV on.
I just did and there was a segment about Russia playing titled "'Slower burn' of Russia's economy has begun". Guess where almost all of the footage they aired came from? Twitter. Guess how the reporters are finding people on the ground to interview? Twitter. Guess how analysts are keeping abreast of military developments (e.g. troop movement, statements released by governments, etc.)? Twitter.
>Absurd. No one cares what you say in private to a complete stranger you'll never meet.
Many service providers conduct customer service via DMs these days. My ISP's preffered lines of contact are Twitter and WhatsApp. Even if we take a step back, do you truly believe that there are no people sharing sensitive information between each other via private messages?
Now looking at the chaos, damage control and the PR disaster that is happening at Twitter HQ after this, I have zero confidence in whatever Twitter HQ and the CEO is saying other than admitting their total incompetency towards how they handle information security at the company. All attempts to make this disaster disappear will not only fail, but will eventually backfire.
So what else was Twitter lying about?
There is nothing more evident about the fatal flaws in social media than when news concerning a platform is suppressed on the cited platform.
It highlights the failure of democracy they always purport, and it shows that they really shouldn't display a social "trending" page, because it is subject constantly to the politics and profit making of each platform.
Twitter's trending timeline had long been regarded as an accurate beacon of real life trends, but that really needs to be reevaluated by everyone as the company has regularly displayed "somewhat questionable" behavior in how they manage timelines alone. There is no real way this wouldn't trend somehow on Twitter in my opinion, as it's been on the front page of CNN and many other sites for a long time now.
The security breaches are factual, they have published many incidences of it themselves over years... Their actual reputation for lax security is what works against them most, but it's all on record.
I just looked at the Trending panel and "Mudge" is #12 for me, with 4333 tweets. #11 is "Taco Tuesday", with 4172 tweets. #7 is "Virgo" with 98,500 tweets. So I'm not seeing a lot of evidence of suppression. I think it's just a pretty niche story. I think the allegations are important and worth investigating, but the specific nature of them looks way more interesting to tech insiders than general-audience users.
If you follow tech personalities, there's a higher chance you'll see the news.
On my music account on Twitter, I don't follow tech personalities and tech news outlets, but I do follow CNN Breaking News, and nothing about this major story has popped up all day long.
This is how the Twitter trending timeline is artificially baked... This story is a very big deal for everyone on Twitter, yet only a fraction of its user base will see the story. Privacy is important to every user on the platform, you'd think Twitter leadership at least would be trying to get a grip on the story first within the platform in a very public manner.
It happens on every major social platform at key points too, highlighting the conflict in their ability to maintain proper social credibility as platforms that report on trends that news channels and other institutions regularly cite.
You seem to be saying that people should be interested in this story. I'm not sure I agree, but I definitely believe most Twitter users won't be. Is it a good headline? Sure. But does it have much direct and immediate relevance to their personal lives? Not for most Twitter users.
Sure.
Just an opinion mind you, but not from a hater or a "dunce".
This is a huge story of significant relevance to Twitter and all users on the platform.
"Suppressing unfavorable news" these days is just as big and profitable an industry as disinformation is.
- This Congress is ill-equipped to understand tech, much less hold it accountable. As long as the people are happy, Congress is happy.
- Lord knows the people are ill-equipped to get how bad this is. They already watched this company allow a rogue employee to shut off the account of the President of the United States (before they chose to do it as policy; https://www.washingtonpost.com/news/the-switch/wp/2017/11/02...) and watched this company deploy a username-to-telephone lookup service publicly where they'd intended to deploy a security protocol (https://www.ghacks.net/2022/08/08/twitter-confirms-that-a-da...). The public doesn't understand why they should care.
- The only group who could really hold Twitter accountable are shareholders, but why should they care if the public and Congress don't? The money will roll in either way.
Unless they've managed to commit an SEC violation (in which case, slap on the wrist incoming), there are no consequences for this kind of bad behavior until someone powerful gets seriously hurt. I'm glad Mudge is doing the right thing, but extremely pessimistic much will come of it. My recommendation is to shed Twitter as a user.
I never understood why tech people have such a strange enamor towards Twitter. Can’t be an industry power dev without it. Can’t start a company without it. Having a healthy Twitter following is often more important than having actual users—even to investors. Twitter is digital hype.
I agree. It’s time to replace Twitter. The only question is what exactly is it that anchors people to the platform? Even though it’s hard to imagine, we know that news motivates people (it happened with the WhatsApp -> Signal exodus). Where’s the “Signal for Twitter” we can all migrate to?
If the key is not just creating a social platform, but also a hype engine, maybe what a competitor needs to realize is that hype doesn’t happen in a vacuum. You have to do silly algorithmic things so that content can go viral. Maybe the secret is to be open about how you manufacture hype rather than do it behind closed doors? Maybe in a way that people can verify it was done fairly?
If I had to take a stab, it's a combination of networking effects (obviously), simplicity and the short text limit, which forces authors to mostly be concise and optimize for a 140 character attention span. This is also supercharged by the fact that you can (mostly) access everything anonymously - if I'm linked to Twitter, I know I can read/watch it and it will mostly be concise. I don't even bother clicking a link to FB, for example.
There's an article I was introduced to yesterday: Do We Need a New Digital Regulatory Agency in the U.S.?
It argues that it it is the agencies and the experts within the agencies that need to become more technologically literate to be able to advise creation and implement the laws that have tech impacts.
Congress isn't supposed to be experts on subjects, they're supposed to be the representatives of their people with occasional domain knowledge in certain areas of importance to their constituents. We can't (and shouldn't) expect every member of congress to be an IT expert.
https://techpolicy.press/do-we-need-a-new-digital-regulatory... ( https://news.ycombinator.com/item?id=32555365 )
I agree that, generally, it would be better for the US to have a better regulatory mechanism for large tech companies, but the consent decree is likely a strong tool in this particular case.
"This" congress? There are institutional level problems, here.
> - The only group who could really hold Twitter accountable are shareholders, but why should they care if the public and Congress don't? The money will roll in either way.
This might be what does it because is it true that the money is and will keep really rolling in? Twitter doesn't pay a dividend and is it reasonable to expect that the company's stock value should increase that much going forward?
Twitter's gross profit numbers aren't as large as you'd think given the household name recognition of the brand. You might be as surprised as I was to discover that meme-stocks like AMC and GameStop are approximately the same size as Twitter in terms of gross profit. Perhaps Twitter is just as much of a big name but ailing dinosaur as those businesses? Or if you want to make comparisons within social media, isn't it surprising that Snap's ~$2.8 billion cap gross profit is right up there with Twitter's ~$3.2 billion. How did that happen? It is also interesting that snap's market cap is only 2/3rds of Twitters despite a much closer delta between the two companies reported profits.
On the whole, things aren't looking too good for the social media right now, take for example facebook losing active users YoY. I often wonder what zeitgeist web properties are going to be remembered as a BIG thing that receded in popularity in the course of about a decade, say like bell-bottom denim jeans from the 60s or disco music from the 70s. Could it be social media for the 2010s?
Anyhow if they aren't paying dividends and they aren't able to keep growing at pace with expectations what exactly are they delivering in terms of value to shareholders?
Given that the allegations are about defrauding shareholders by actively deceiving them and sweeping things under the rug. Twitter's shareholders might be better off revolting against the current leadership to recoup their loses than to look the other way and let this slide.
All you do is make public comments that have zero value.
And if this is indeed serious, where the fuck have we landed?
Considering how widely used Twitter is, at this point we can comfortably assume that most politicians and political operatives, even high profile ones, must have very sensitive information in their Twitter DM inboxes.
I doubt that, and if they really do, they should be either trained or exposed pronto. Twitter is an entertainment platform.
My guess is that the reality is almost perfectly in opposition to what you've described. Anything that introduces plausible deniability is going to be of a major benefit.
My feed is still filled with how all of our public service problems must be caused by the 1-2% that were put on unpaid leave for refusing to disclose their vaccination status. I’m sure the 1-2% could help, but the issues are much larger than that.
I'm not defending Twitter, I don't engage with it at all.
Investors always have the option to ignore rumors.
What I'm trying to say is, you might be able to discredit Twitter, but you won't fix investors trying to invest ahead of the news.
And if some investors lose money then so what? That is an acceptable outcome. Let them suffer, I have zero sympathy.
I agree with you that we have landed in not a great place.
Without it sounding like an endorsement or defense of the guy… I never would have believed without seeing it, just how furious this made the media and other politicians. That you have a guy come in who said forget the system, I’m going talk to the people directly (and say some dumb things now and then).
I still attest that some of the Trump hate is solely because groups of people that control the narrative in the US were excluded from creation and forced to be on narrative-adjustment.
Agreed, this isn’t a good place. One platform should not have this level of influence.
Lol, did the same thing for a government entity I was working for, also without prior permission. It showed 1/4 of the people used the name of the entity as there password, including 2 users with domain admin credentials. Both of the domain admins weren't even IT people, there were the director and his assistant, who demanded to be admins, because they were 'admin' within the org.
In my case, I didn't get scolding, but probably should have. As you're prior boss said, it was not good to do it on a running production server. Now a restored backup running on a private network...
In that talk he told of his time at Intel and running crack on a shiny new sparc and all the problems that caused.
The focus of it was a "how not to get into trouble as a contractor".
Somewhere, I've still got my pink camel book with duct taped edges (for durability) with his signature on the inside title page.
He never struck me then, or in any interview or write up since, that he's impulsive, or prone to taking actions like what he's done to Twitter, in a cavalier way. He saw something bad and thinks something should be done to address it.
He likely made that decision because the culture at Twitter is as bolloxed as he states (maybe worse), and that it's one thing to fire a guy, but to do so to hide damning truths, and expect that person to just accept their fate AND let you get away with it without a cost is in this day and age, a farcical hope. Your "Mudge knows the implications of "whistleblowing". He has been a security consultant and even testified to Congress. He's not some noob that doesn't understand security or how systems work together to provide services like disclosure to FTC. The idea that Twitter PR can pooh-pooh away his concerns is shockingly stupid." is spot-on.
I know people have thought Twitter was mismanaged for a while, but seems like it's a lot worse than I thought it was (and the CEO seems more vindictively bad than I would have guessed).
Plus the total lack of principles around speech and just doing whatever Russia, India, or KSA wants? Including hiring foreign agents? Also covering up bad security issues in reporting? It'll be interesting to see what happens from here as more comes out.
The internal Twitter email: https://twitter.com/austen/status/1562150058727919616?s=21&t...
I'm no fan of Musk (he's truly worked very hard to be the most provacatively pustulent punkass of tech) but that doesn't mean that Twitter leadership is any better. Just not as well PR'd.
Dorsey himself was mostly an imbecile who drank too much of his own Kool Aid. Twitter has for years been the standard bearer for the most opaque, and incoherent content management; from user feedback to bots, just a village with only idiots. It was eventually going to catch up to them, the question now is to whom does the bulk of the suffering land on, not whether it lands or not.
He waived all of that to force Twitter to agree to the deal (because it'd be basically impossible for the board to reject it). This made sense at the time, because the board was looking for ways to weasel out of it because (imo) they politically don't like Musk. Then the market crashed and suddenly he was overpaying a ton for Twitter, then he complains about bots (this isn't new information from when he made the deal).
Whether or not the bots thing is true isn't even relevant based on the deal he put forward.
I think he earnestly wanted to buy Twitter for principled reasons around speech which I agree with. He structured the deal in such a way where Twitter's board couldn't reject it (because it was so favorable to shareholders). Then when the market tanked the deal way overpriced Twitter, but he had already committed to it so he's trying everything to get out of it. I suspect he actually believes the things he's arguing (he's always seemed pretty earnest to me), I just think he's wrong in this case and it's mostly driven by motivated reasoning.
That doesn't mean Twitter isn't a disaster, just that they're in the right with regard to him having to close the deal.
That's not how business valuations work (it's how speculation works). If Twitter was fairly valued by Elon Musk before the crash then it would be fairly valued now - the fundamentals of the business haven't changed.
That's a big if - I think a lot of this stuff is more speculation than any sort of fundamental cash flow valuation. A lot Twitter's actual value (its network effect and influence) is hard to measure anyway.
Some "fundamentals" of a business like twitter's value are:
1. Product/market fit, finances, etc. What you mean by "fundamentals" I think.
2. How easy it is for them to raise money (i.e. the "public sentiment" of VC towards their company and the industry)
3. How likely it is for regulation to stifle their growth, which is a derivative of public sentiment.
4. How much shares can be sold for, i.e. the public sentiment about how much it's worth.
5. Predicted future sentiment of their users and of advertisers, both of which impact expected future revenue.
2-5 all change with public sentiment, and a market crash changes public sentiment of many companies at once.
It's self-evident that elon musk is overpaying more now than before unless you insist that twitter's value is not actually related to 2-5 above, or 2-5 above should have been trivially predictable 100% accurately already as part of its "fundamentals", both of which seem obviously silly.
Implicitly, this was always, "I'm going to trade X% of Tesla for 100% of Twitter." Then the valuation of both Twitter and Tesla dropped, so to the extent that you think the "value" of a business is wholly determined by its fundamentals, then okay, they're both still the same "value" but now have lower prices.
Except that he hadn't sold the Tesla yet, so he was trading Tesla (at new lower price) for Twitter (at old higher price), and if you previously thought that X% of Tesla was worth Twitter, and Twitter is still worth the same thing, it's now X+Y% of Tesla.
Of course, it's not like the fundamentals of Twitter didn't change. Twitter's revenue comes from advertising, and it's entirely reasonable to believe that it was actually materially affected by the economic downturn, not just in terms of the speculation of the stock, but by how the business functions.
(None of this is to take the position that Musk ought to be able to back out of the deal: if the market had gone even hotter and now Musk could've traded less than X% of Tesla for the agreed upon, now conservative price for Twitter, it's not like the deal would've been renegotiated.)
Twitter is a tyre pyre, but he should have thought about that before putting ink on that deal.
How often has that happened in the entire history?
Profoundly dumb people have been heads of state, CEOs etc. So why not the richest person in the world?
Alternative suggestion would be that he doesnt actually believe that the reason he is trying not to buy twitter is the reason he was buying twitter.
It's simple to explain away - other people have appointed heads of state. And I have not heard of an idiot (in medical sense) top20 Forbes list CEO who's also been there since day 1 (i.e. the founder, not some figurehead appointed by a board for an arbitrary reason).
Can you appoint yourself the strongest person in the world or the fastest 100m runner in the world?
[0]While someone like the Saudi king or Putin can in theory allocate their respective states' funds to themselves and thus become the richest, that would simply be converting power into money, and not a result of some kind of entrepreneurial ability.
>If 5 billion people flip coins all day long one of them will eventually flip only heads all day.
This argument is flawed since that would assume a person would win some money every time they flipped correctly, when in reality nobody is going to pay anyone for succeeding in a flip. And applying that directly to business also breaks down because it is self-evident that the ways to lose money greatly outnumber the ways to gain money.
A lot of stuff is still going on legacy stacks that Ada was created to replace
High assurance comes from the overall systems design and testing, not the software itself. Afterall, radiation can cause any piece of software, including those written in Ada, to completely skip instructions.
I tend to like people that blow up social norms and conventions
That’s not a “major error in judgement”. That’s the behavior of a completely deranged individual.
That's quite a large exaggeration. I can think of some much much worse things that an actual "completely deranged individual" would do.
Musk was butthurt and lashed out. That does not equal "completely deranged individual"
When you have the kind of audience and pull he has, unless you are totally daft to it (which he shows no sign of) then yes it's very abusively deranged.
Lashed out in a way where, given his influence, he could easily ruin the person's life. Which is bad in and of itself. But he did it while the man was actively involved in trying to save a dozen children from immediate death. And then doubled down later.
That is deranged.
Twitter is most definitely not doing whatever Russia wants. It's markedly hostile to Russia and frequently removes "pro-Russia" acocunts, which speaks to your initial point, that it has a total lack of principles around speech.
Twitter is going to be in a lot of hot water now, and I can't imagine Musk isn't going to milk this to the last drop.
Then I clicked through and saw it was Mudge.
Ah jeez.
Will this testimony show Musk completely miffed his due diligence while building up a huge loan package that would have sent most of Twitter’s revenue to debt service? The timeline is what matters.
Those were wild times.
I was going to send the information to our security people in another state but decided it probably wouldn't be a wise thing to do.
I come across the HDD where I have this stuff archived every now and then and it makes me smile. This was also in the "Free Kevin" days.
and cracked it on personal systems
and you kept the files and cracked passwords? Not just kept around, but archived?
Dude.
For anyone wanting to explore 90's security nostalgia, it's worth a read. For anyone wanting to learn where hacktivism comes from, it's worth a read. For anyone wanting to learn about how security consulting has evolved over the years, it's worth a read.
Mudge is a very cool and capable individual. I am slightly surprised that Twitter would ignore someone of his talent and respect, and choose to air their dirty laundry in this manner. It's as if they have no idea who they hired. That, or C-levels think they can outpay $$$ any PR against Twitter to control the narrative. Either way, if Mudge is whistleblowing, there's probably some bad shit going down.
If I were betting, nothing is ever really systemically broken in large orgs, it just works for someone you can't see. This is a factor everywhere and not necessarily at Twitter. Shitty process? Cui bono. Unverifiable systems? Cui bono. Deniable and unaccounted-for access to God-mode data? Cui bono. Repudiable numbers reporting? Cui bono. Bizarre political posturing? Cui bono, etc.
Not particularly shocking as they'd have to be incompetent to not try to infiltrate a major communications platform, and if the internal controls are as bad as alleged (and has exposed in some of the prior hacks, e.g. the control panel screenshots) they'd have to be incompetent to fail.
> They needed a steady hand who wouldn't be vulnerable to being swayed by principle.
That's my golden quote of the day, time for bed.
> The company also lacks sufficient redundancies and procedures to restart or recover from data center crashes, Zatko's disclosure says, meaning that even minor outages of several data centers at the same time could knock the entire Twitter service offline, perhaps for good.
That said, this is Mudge. I have a lot of respect for the guy, and I believe what he says. I'll chalk the pettiness up to this article being a summary of a more complete document that I'd like to read at some point.
I mean if it were true that seems pretty negligent. If that were the entire extent of the whistleblower complaint (not sure if complaint is the right term?), I would agree, but it seems as though there are some significant issue raised in the rest of the report.
You can watch it live in 2024, when all of social media has morphed into TikTok clones.
Also, if they can handle a primary datacenter outage, they have a working DR plan. If I was working on an infrastructure team and was told I needed to handle multiple, simultaneous datacenter outages, I'd start looking for another job.
Gov (a term that ranges from your head of state down your county dog-catcher,) needs to get off these services asap. Twitter, TikTok, Instagram, FB are all modern versions of your old AOL Keyword.
Today we have ActivityPub, a W3C recommendation, which would be a great alternative.
I added that "disgruntled" part but... who gets fired for poor performance and doesn't become at least slightly disgruntled?
Next you'll tell me that Twitter would't survive global thermonuclear war.
He wasn't responsible for disaster recovery, or reliability, yet he was reporting to the board (going above his reporting chain), telling them that the company wasn't doing enough because it can't handle _multiple_ data center outages at once? Very, very few companies could handle that. If twitter can handle their primary datacenter failing, then they do have a working DR plan. They aren't lying. Is the DR plan to Mudge's liking? Obviously not, but his idea of a DR plan is out of line with what the vast majority of the industry considers a reasonable DR plan.
Similarly, mDAU vs user/bot numbers aren't lies. The company switched their reporting metric. They're accurately reporting their growth metric to the board, and to the shareholders. The raw user numbers could actually matter to the board/shareholders, but the board could have required them to report them and didn't. Just because they aren't reporting the metric you'd prefer them to report doesn't mean they're lying to anyone.
There are a number of legitimate complaints in the disclosure related to poor security practices, but many of them feel like internal problems that don't rise to the level of crimes. Sadly, he may have had a hard time moving the needle on those issues because he was spending his time fighting everyone.
He's a gifted engineer, and may even be a gifted leader, but that doesn't mean he was doing a good job in the culture he was working in. I read the whole document, and the majority feels like someone running headfirst into bad cultural issues and burning out while making enemies.
https://twitter.com/donie/status/1562069281545900033
* https://www.washingtonpost.com/technology/interactive/2022/t...
edit: the PDFs from *
https://www.washingtonpost.com/technology/interactive/2022/t...
https://www.washingtonpost.com/technology/interactive/2022/t...
https://www.washingtonpost.com/technology/interactive/2022/t...
cover letter: https://s3.documentcloud.org/documents/22161666/twitter-whis...
latest reaction from Capitol Hill: https://www.washingtonpost.com/technology/2022/08/23/twitter...
>Nobody at the Valley's unicorns seemed too concerned with security. (I asked Jack Dorsey that year whether he worried about the fact that hackers were continually pointing out holes in Twitter and in his new pay-ment start-up, Square. "Those guys like to whine a lot," he replied.)
https://twitter.com/nicoleperlroth/status/156204856902836633...
The way it's framed ("Twitter lied to Elon Musk about bots") makes me suspicious of the whistleblowers' motives here. I know he's some kind of legend around these parts but I've never heard of him, so I'm just going by what I've learned today. Seems like propaganda to me, intended to maximally damage twitter and/or curry favor with Musk.
("Argawal's reasoning might appear a bit circular since, by definition, mDAU is more or less Twitter's best approximation of the set of accounts that aren't bots. And Agrawal is not exactly trying to help readers understand the bait-and-switch nature of his answer." - page 13/84)
He's complaining that Twitter isn't measuring what he wants it to measure, which doesn't help, because it isn't saying that Twitter is actually lying about its metrics (and, as noted, it's indirectly implying that Twitter isn't lying).
Is this an accurate statement?
If so, why did nearly 1000 employees (12% of the workforce) have access to this mode before it was restricted, and what's the business case for that?
Thing is, now that it’s possible for Twitter, Twitter can never brush off this suspicions again.
We’re literally not sure, by using Twitter, that we see the speech of that person.
For instance, consider the Twitter DMs exchanged by Donald Trump, Jr and WikiLeaks. In that particular case, the communication was acknowledged by the party in question, but imagine the two possibilities thousands of employees being able to act on the part of users opens up:
1. Twitter employees could fabricate a criminal conspiracy by creating messages between multiple Twitter accounts.
2. A criminal conspiracy can now use the "Wasn't me, must have been some random Twitter employees" defense.
It would be quite easy to argue that a highly-politicized org like Twitter _might_ alter tweets or DMs to implicate someone in the opposing party. That’s reasonable doubt that at least some jurors would buy.
But that turns into "there was a sizeable conspiracy to fabricate evidence", as opposed to "a random person out of 2000 got bored, had a grudge, decided to have a laugh, and was acting alone".
I could see this being billed as a feature of a privacy-forward chat platform. Messages are slipped into conversations without either party having actually sent them and no way to tell whether they were real or not.
Eg. simple things like tracking-busters where it randomly clicks links in headless chrome to fool the algorithm, p2p vpns where you use a random user’s IP address to randomize who made what request, etc.
There is also a school of thought that you should periodically publish private keys for plausible deniability (“was it me, or did someone sign that after I published the key”).
Could be thwarted by some kind of "source" database column/field/value that says "this is a tweet made by God mode"
Whether Twitter has that field, if it is internal only, and if they would share it with the public/a court of law, I have no clue
1. No employees have direct, immediate access to user accounts or data.
2. Only a small number of employees should ever be able to gain access to user accounts or data, for the purpose of resolving issues directly affecting said accounts or data.
3. Access is only granted to one specific user account at a time, and only for a limited amount of time.
4. Access to a user account requires at least one other person to sign off on the access-grant.
5. Every operation performed upon a user account -- viewing a field, modifying a field -- is logged in a place the people from #2 and #4 do not have access to.
6. Access logs are routinely audited for perfidy.
7. Gaining accesses to user accounts or interacting with them in a way that is not necessary or attempting to circumvent the above process must be a don't-bother-cleaning-out-your-desk-we'll-do-it-for-you offense.
With policies in place like that, you reduce the insider risk to user accounts. You need multiple people directly involved in secretly accessing or taking over a user account, and you potentially need dozens of others (the potential auditors) to be complicit. The more people you have involved, the more likely it is someone shuts it down, or at least blows the whistle on it when shit hits the fan.
If someone can just get drunk one night, open up a user account, tweet something, then SSH over to the audit server and drop the rows from the access log indicating what they did, and there's no way to even prove something happened, let alone who did it.
Usually developed for testing purposes (easiest way to reproduce a problem, after all) and prevents password-sharing. But it can obviously be used for evil, and so it should be heavily logged and flagged.
This is a clear breach of infosec if there's a $#%*# su to post as Waldo and Waldo can't see that post.
In fact it seems ONLY possible to do _evil_ with that feature.
Literally the entire security community knows and looks up to Mudge. If anyone finds out that anything he said was bullshit, it will get blasted from the rooftops and he'll become a laughing stock. He would have to want the rest of his career to be working for morons and be ostracized from his friends and community to make this shit up.
Primary for whom? If you polled 50 people on the streets of NYC, I bet fewer than 3 would say they actively use twitter. Now do the same for Des Moines, IA and you maybe get 1?
Here, I'll give it a go: "Environmentalists are furious that Bill Gates kills mosquitos"
If there's no evidence for my claim it must be evidence of censorship, because certainly I can't be wrong.
The original tweet author did not give permission for her thoughts to be published in so many articles and apparently endured a lot of harassment(She indicated this on subsequent tweets). She eventually deleted the tweet.
This was the original tweet: "Shame on Netflix for this. After this past year especially, to then release a film that is literally white people murdering Asian people based on stereotypes and fetishization??? Hard pass.”
If you google that quote you'll see how many articles quote that tweet.
There were no winners in this whole saga. The movie takes place in Tokyo so of course asian men are going to be the bad guys. So Netflix endured negative press for nothing. The press didn't actually change anything about the film, it obviously pissed off enough people that it caused them to start looking for the tweet author to harass her and finally she deleted her tweet. Who were the winners? The site owners making the money I guess. The whole thing really shows how much of a joke online media is. When regular establishment press is not that good either, what are people to do?
These aren’t ideas that can be peacefully mediated.
Ironically the white female actress who plays the assassin in the film: Mary Elizabeth Winstead was herself a victim of massive online targeting and harassment.
She had already once deleted her public accounts in protest after the famous iCloud hacks in the early 10s because people were ogling her private nude photos and then harassing her about it after she scolded "the internet". She came back a few years later only to delete everything all over again in 2017 when she got non stop barrage after she went through a bad divorce. Its tough for actors who are in the business of selling themselves to just walk away from all public social media.
I think people who weren't into tech and who came of age before the internet became mainstream might be the first people to disconnect from this social media nonsense. She was early 80s and homeschooled to focus all her waking moments on becoming an actress. Gen-Z/Alpha might never disconnect. Have they ever known anything different? It will be interesting to see what happens.
What about twitter makes this situation special?
And it’s possible to cherry-pick people to push any narrative you want. Like the NYT talking about how GenZ is very pro-life, quoting several pro-life youngsters. Meanwhile buried somewhere in that long article is the lede - only 20% of GenZ is pro-life.
Twitter has a lot of journalist users so, yes, it does tend to move the whole dog.
Facebook is a great platform for actually getting normal people to see our content and invite them along to our meetings and such. Twitter, on the other hand, has a far more niche audience - but I know for a fact that the niche audience includes several state legislators who follow us and interact with our tweets, and we've gotten several press stories via contacts we've made with journalists over Twitter.
If you've got a message to get out there, it's a highly strategic platform.
[0] https://staltz.com/the-web-began-dying-in-2014-heres-how.htm...
What prevents that from catching on at scale is, the "big boys", like MS, FB or Google, mostly not playing ball and never implementing these in their own messaging platforms, to keep their gardens neatly walled from each other.
As intraplatform exchange is not really in-line with what most of these platforms are striving for these days; Interactions with their own platforms and the advertisers on it.
I have yet to receive spam on my Mastodon or XMPP address (which I treat like my telephone number).
My can and string communications network doesnt have any spam either.
Unpopular opinion: I think it's awesome that a private company has created a platform like Twitter. It's kind of like comparing a private amusement park with a public park: one has roller coasters, water slides and an arcade... the other has a swingset and a nice field of dried up grass.
> the fact that it's at the whims of a private company
How is this worse than at the whims of the crown?
> there is an environment that is ripe for the encroachment of digital rights
I love that were even talking about having digital rights.
How is this worse than at the whims of the crown?
The tiny detail that we're not having a crown anymore.
I had to scroll down past the posts dismissing the issues to get to this one. The news at this point is also conveniently not trending on Twitter even though I am pretty sure a lot more people are Tweeting about it than about Doja Cat right now (who is trending).
I also didn't even see the article, tweeted by CNN, even though I follow them on Twitter.
We're officially chest deep in the era where nothing popular on the Internet is trustworthy nor credible, and where nothing works as expected.
My solution is the same as it always has been... Never respect them enough to enter your real (government) name, and never post anything that you can't afford to have compromised. There is no end to what modern data greed will use your data for.
Not true. If anything Twitter is a cancer on our discourse that should be disdained, not something that should be enshrined as a fixture into our lives.
> About half of the company's 500,000 servers run on outdated software that does not support basic security features such as encryption for stored data or regular security updates by vendors
Wait until you hear about the large cloud provider running RHEL5... (I worked at said provider).
> allows too many of its staff access to the platform's central controls and most sensitive information without adequate oversight
It'd be even easier if you find an employee who's on the same political team as you.
It's one of the reasons I disliked Twitter forcing the use of mobile numbers for 2FA, they're just not sufficiently trustworthy. And I have an account under my real name! If I were a political dissident etc that just feels like an insane idea.
"This guy": https://en.wikipedia.org/wiki/Peiter_Zatko
That 500k servers in Twitter infra are missing patches certainly is true and what was likely in the original was a statement that stored data that should have been encrypted at rest was not, and/or that acceptable standards for data at rest encryption, a relatively rapidly moving freight train, were not maintained.
One definition is "the underlying disk is encrypted". This is true, by default, of virtually all cloud environments these days. But it really only protects you against physical access to the storage media, which actually is far from the top threat.
The other, more useful/meaningful definition, is "we encrypt everything at the application layer before it is placed into the DB, and all decryption requests are logged by user". For example, using an envelope encryption scheme to encrypt data before it is stored in a DB, and upon retrieval decrypting the data with a call to something like KMS. In that environment you can literally give readonly DB access to all your developers and not have to worry about PII being exposed. If hackers somehow got access to your DB, they wouldn't be able to read sensitive data, and if they also managed to get access to your KMS credentials, any attempts to decrypt the data would be tracked and logged.
My point is that when many companies say "we encrypt your data", they are usually just talking about the first thing, but that doesn't really provide that much additional security. The second definition is really what you should be doing.
The thing is FDE essentially only protects your data when your machine is powered off. Once your machine is booted and you've logged in any block level encryption ceases to be relevant, because to get to the point of running your machine has to have loaded in the relevant key material to decrypt. From that point on user space code no longer sees a difference between encrypted and decrypted drives. In other words FDE is not relevant is you lose a powered on device (post login if relevant to the platform), and you're the kind of person people are actively targeting (I recall recently? the content of someone's phone or such being dumped by the FBI because they grabbed it while it was being used).
That's why modern OS's have different key classes, there's the lowest level which is just FDE, but you can have higher levels where requesting key material essentially just gives you a handle to that material. Then the OS, or preferably hardware with a much less complex OS, manages those handles and invalidates them according to policy rules. e.g you may want your phone to have access to your address book while your phone is locked, which does not mean you need your call history available as well.
The policies provided by OSs tend to be fairly simple because it's better to have an easy to understand API that is easy to use and hard to screw up than a more "powerful" API that is easy to screw up and hard to use (the latter resulting in people simply not encrypting things at all). e.g iOS/macOS only has the following file protections when you create files: "NSFileProtectionComplete", "NSFileProtectionCompleteUnlessOpen", "NSFileProtectionCompleteUntilFirstUserAuthentication", "NSFileProtectionNone", but they're very easy to understand.[1]
I tried to find the android equivalent but I don't know the terminology that's used and I just get linked to instructions on using AES, so if someone could link the correct doc I'd appreciate it.
[1] https://support.apple.com/guide/security/data-protection-cla... and https://support.apple.com/guide/security/keychain-data-prote...
From https://www.washingtonpost.com/technology/interactive/2022/t..., page 6:
"..more than half of Twitter's 500,000 servers are running out-of-date operating systems so out of date that many do not support basic privacy and security features and lack vendor support. More than quarter of the 10,000 employee computers have software updates disabled! More than half of Twitter employees have access to Twitter's production environment -- unheard of in a company the age and importance of Twitter, where nearly all employees have access to systems or data they should not. At Twitter engineers work on live data when building and testing software because Twitter lacks testing and stage environments; work is conducted instead in production and with live data..
"This did not happen overnight. To get where Twitter is today took.. many years.. required repeated downplaying of problems, selective reporting, and leadership ignorance around basic security expectations and practices."
If you're trying to prevent an actor who has gained a foothold on a box/network from seeing plaintext data that is actually in use by the actual production system at that very moment, you're looking for a much stronger type of control - probably some sort of client-side encryption or obfuscation/tokenization
So it is just a checkbox then.
Big tech was taken over by bean counters long ago, the fact that it’s all running on duct tape and popsicle sticks under the hood will come back to bite us when we have a digital Pearl Harbor event.
China will invade Taiwan and the first shot won’t be physical, it will be activating the 30 years of assets they grew in AWS/GCP/cloudfare/level3/AT&T/Etc
Most of their HR/engineering departments are completely retarded. They’ll hire any H1B who passes l33t code that accepts $50k under market rate then give them repo access in a few weeks. Our soulless megacorps are beyond easy to penetrate by hostile intelligence.
The CIA/NSA/FBI, you know the groups who we pay billions per year for and they take half my income to fund will of course not catch any of this.
The FBI is too busy manufacturing domestic terrorist, the NSA is too busy hacking American companies, and the CIA is too busy importing drugs to actually secure our country from foreign attack. Why? Because it’s been so long since we were actually attacked they believe it can’t happen so why not loot Rome in the mean time?
Even in what I'd guess is an "ideal" situation, of tractable technical&process problems, and genuine buy-in from the C-suite for solving/improving them, there's still going to be dynamics/politics to navigate.
I also hear of a lot of much-less-than-ideal situations.
In my experience I've found it rare that user content is ever actually permanently deleted for various reasons.
advertising, controlling executives, and government spying
How do you make those people interested in it though?
(If they weren't, originally when you hired them.)
Adding the right KPI? What'd those be
What if they aren't any bright, just have a good self confidence?
>Zatko’s complaint says he believed the Indian government had forced Twitter to put one of its agents on the payroll, with access to user data at a time of intense protests in the country. The complaint said supporting information for that claim has gone to the National Security Division of the Justice Department and the Senate Select Committee on Intelligence. Another person familiar with the matter agreed that the employee was probably an agent.[1]
[1] https://www.washingtonpost.com/technology/interactive/2022/t...
I know of insurance companies that have help desk employees with domain admin access. And all crippling ransomware attacks take advantage lax permissions.
This is rampant. How is this a story?
Cynically, because it's twitter, and it's trendy amongst a certain subset of the population to bash social media in general and twitter in particular. And I think your point is fair.
(FWIW, I think social media has if not caused, then certainly exacerbated, some major problems at individual, societal, and global levels, but by no means do I think twitter is the biggest contributor. I don't think we'd see the kind of unconstructive political polarisation we're seeing in the US and UK and perhaps, to a lesser extent, within the EU, without it.)
Except like the linkedin "hack" which was just a scrape of peoples profiles, the twitter "hack" was someone running phone numbers through the "upload you contacts and find your friends account" feature.
They are both barely stories, except to remind people that posting stuff publicly is public.
>They are both barely stories, except to remind people that posting stuff publicly is public.
The reoccurring issue is that Twitter and other companies are convincing (and often forcing) you to do something unsafe like linking your phone number, while telling you that your data will be kept private and at the same time opting you in by default, or aggressively marketing, an option that compromises your security.
I'm sure you may be smart enough to know this compromises your anonymity, allows stalkers to find your phone number, etc. but the 99% of users wont.
Linking everything to a phone number is a major dark pattern that benefits the corporations while compromising the user. So rightfully, these malicious and harmful practices should be called out.
Twitter has some 200+ million daily active users and should act like it.
The reason there isnt "leak" from google is because they dont offer the functionality to look up your account by your phone number.
Basically we work on keeping everything patched and try not to create any obvious issues. Honestly, I think the best thing we have going for us is obscurity.
1) Like a car mechanic, these people get paid to sell you solutions and they are incentivized to sell you more.
2) Plenty or honest people have biases because of what they do. If you spend all day thinking about security you might be overly concerned about things that are actually not that risky.
This isn’t to say that there aren’t great people working in the field. But it’s daunting from an outsiders perspective.
You don't want your doctor to overlook any problems just because they are rare because your health is really valuable.
Develop an empirical understanding of risk management. While we can't predict the future, through well established techniques and adequate resourcing, professionals can achieve consistent results that are far better than random guessing. Risk management principles drive not just corporate stragegy writ large, but entire industries like banking and insurance.
They have gotten away with so much for so long, they live in their own disconnected reality.
When things break some of them cash out. Others find someone to blame. They don't pay a price at all. And the cycle continue.
In China atleast people are scared of the govt. In the west its a total joke how no one is ever held responsible.
Citizens should respect Government, and Government should fear citizens?
I think we are straying away from both of these at the moment.
[1] - Of course, this isn't the complete picture: China has a penchant for arbitrarily dealing a heavy hand to law-abiding companies/persons.
Walk through the controls list, see where you compare to the controls and sub-controls and then start to establish a path forward.
I think it’s still not clear how you should build a security org, and if you should at all (should security be part of normal workstreams of your devs?)
Btw I wrote about my experience in https://securityhandbook.io/
Some time back, I got a copy of "A Practical Guide for Policy Analysis: The Eightfold Path to More Effective Problem Solving" so that I could properly quote back the use of best practices.
https://en.wikipedia.org/wiki/Best_practice
With most times people are looking at best practices, they skip to the decide step without defining the problem - that's even been done here. Is there a best practice for non-cybersecurity at private business? Well, yes - but first, what is the problem that is trying to be solved? There's no "get this book of everything to do and you're good". On the other hand a "we have customer data that includes PII data, we need to secure the data and prevent casual examination of it in house" is a problem that can be looked at and a best practice can be found.
The best practices involve a survey of looking at other organizations and seeing what they have done - what worked and what didn't.
> Part IV "Smart (Best) Practices" Research - Understanding and Making Use of Whatlook Like Good Ideas from Somewhere Else
> It is only sensible to see what kinds of solutions have been tried in other jurisdictions, agencies, or locales. You want to look for those that appear to have worked pretty well, try to understand exactly how and why they may have worked, and evaluate their applicability to your own situation. IN many circles, this is known as "best practices" research. Simple and commonsensical as this process sounds, it represents many methodological and practical pitfalls. The most important of these is relying on anecdotes and on very limited empirical observations for your ideas. To some extent, these are - one hopes - supplemented by smart theorizing. This method is never perfectly satisfactory, but in the real world the alternative is not usually more empiricism but, rather, no thoughtless theorizing.
> Develop Realistic Expectations
> Semantic Tip First, don't be mislead by the word best in so-called best practice research. Rarely will you have any confidence that some helpful-looking practice is actually the best among all those that address the same problem or opportunity. The extensive and careful research needed to document a claim of best will almost never have been done. Usually, you will be looking for what, more modestly, might be called "good practices."
---
A "here is a list of all the best practices, follow these" is the wrong way to try to use best practices but rather relabeled cargo cult security.
Also, build a risk matrix of security risks the company can face by impact vs likelihood of the risk happening. Get someone senior to sign off on it.
Use the NIST CSF and the risk registry with senior leadership support to guide the work you do.
Itll be easier if you think about security as understanding your risk posture as an org, and that risk is either fixed at your level, carefully escalated to outside your teams for a fix, or labeled and accepted risk. security teams should never be the ones to accept risk, so get a a manager to see and acknowledge in writing whenever it’s decided to just roll with a known vuln you’re Unable to fix without more time/money/tech. Try to fix as many risks as possible at your level as to not build an alarmist rep. Then, that leaves space to escalate into cross-team fixes (and you can point to the NIST CSF and the risk register with a senior leader’s sit side as a baseline reason for why they need to fix it).
Do you have runbooks for your systems? (describes how to operate the system normally.)
What about playbooks? (how to handle errors)
Have you game-day-ed various failures? How long does it take you to restore everything from backup? What order do you bring your systems up?
What level of monitoring do you have on your systems? Can you spot unusual activity? How quickly?
What sorts of firewalls? Say "system X" is compromised. How far could damage spread from there?
Obscurity won't protect you when cybercrime is a business model.
You do have a pretty good idea then. Sadly, this is exactly what it looks like at the moment: because business decisions are made by clueless dummies, there’s no way to sell a proper product; to make money you need to focus on snake oil instead.
If you don't know how that's a story I don't know how to explain it to you, I can only assure you many people will find it extremely newsworthy.
Maybe I'm a bit jaded by what I've seen, but that doesn't seem too far off from normal American business culture. Deflection and manipulation seem to be par for the course. It's why lobbyist exist. Companies want permission to do/not do the things they're not currently allowed/required to do.
The ones that get caught are normally a few bad actors that whistle blow. The companies where it's ingrained in their culture get away with it. Of course...this is all my own experience :)
Because it's being publicly revealed.
If the lax security you describe at other companies were also revealed, maybe more would be done to fix it.
And, oh yeah - there is no "conspiracy".
My claim is that this specific story which is most likely true but in no way surprising gets amplified right now because some specific powerful people wanted it so.
That said, given foreign influence campaigns in the news in the last 6 years, this would’ve been news then too. I’m sure it was news back in 2010 when the FTC ordered it to fix the problems.
Who are these "powerful people"? And why do they care about Twitter so much? Most powerful people aren't even ON Twitter.
Are they enamored with him - for sure, are they in his actual pocket? Doubt it.
Bro. It's not every day that literally Mudge, who has -no doubt- seen his fair share of shit-shows, whistleblows on an employer.
Well, it's on the front page of CNN right now for starters, so that means it's probably significant to a lot of people...
If you have a business, you most likely need to promote it on Twitter, or to at least reserve an account there so that someone else won't impersonate you. You also need to do that on almost all other major social platforms.
If you have a business or personal account on Twitter, your direct messages, the data the system generates about your preferences and interests, your geo-coordinates, and everything you post, including control of how your account works can apparently be accessed by too many people within the company.
It's a pretty big deal for anyone that uses the platform citing all that... Not something that should just be "left to it's own devices" because everyone else is doing the same. All cases of data abuse/misuse should be addressed, but addressing one this big would also be a pretty big deal.
https://www.ftc.gov/news-events/news/press-releases/2011/03/...
That said, all these stories are important to the public.
When you fire both your chief of security and your CISO months after you hire them, it's weird. Even if your chief of security had personal failings, why fire his boss? If the boss falls on her sword for direct, that certainly makes me think to take what their saying seriously.
> The complaint from former head of security Peiter Zatko, a widely admired hacker known as “Mudge,” depicts Twitter as a chaotic and rudderless company beset by infighting, unable to properly protect its 238 million daily users including government agencies, heads of state and other influential public figures.
this is a fun read. I've long said that government agencies, heads of state and other influential public figures are obvious candidates for running their own ActivityPub installations (or in paying competent people to do that, which shockingly Twitter, Inc. could be in the business of hosting/selling).
Sounds like a match made in heaven for "government agencies, heads of state and other influential public figures."
He has a track record of making up ridiculous stories that serve his task masters. Remember the "Hong Kong Blondes"? Oh right it turned out to be completely fake.
This is a very strange article to me. When I think of Twitter and government influence, I think of the overwhelming pro-Washington bias.
I think of the "state-affiliated media" tags that somehow don't apply to RFE/RL and BBC.
I think of the countless heterodox/dissident accounts that have been banned or silenced on the platform.
I think of the "hacked materials" warning label that was invented to discredit a particularly damning story about a covert disinformation campaign involving Reuters and BBC.
I think of Twitter's complete tolerance of the obvious platform abuse by the textbook troll farm known as "NAFO".
I think of the revolving door between the federal government and policy/compliance positions at large tech companies including Twitter, of which Mudge is one of many.
My tinfoil hat is whispering that this story is part of a broader campaign to put pressure on Twitter to be even more compromised by the federal government and intelligence agencies. I just don't see how this "foreign threat" narrative lines up with the reality of how effectively managed Twitter has become over the past few years.
Realistically though, Mudge probably just has a huge hacker ego and is butthurt that he was caught slackin'.
This doesn't seem like he was "butthurt and caught slackin'." The tone of the report seems like he's frustrated that he was hired to do a job, and not given the resources / authority to make the necessary sweeping changes. Perhaps someone with a more political approach could have influenced leadership better. But they hired an extremely technical person, not an extremely political person.
> Saudi citizen Ali Alzabarah, who worked as an engineer at Twitter, used their positions to access confidential Twitter data about users, their email addresses, phone numbers and IP addresses, the latter of which be used to identify a user’s location
Internal data security practices could probably have helped limit his access
I would be surprised if there were an actual Chinese/Russian/Iranian spy working at Twitter.
And I think of AWS announcing a massive data loss, Kim-Jong Un tweeting "Nukes have been launched" and the US president tweeting about an impeding Yellowstone explosion. If you want to really f up the country in a big way, Twitter is a great way. With how much verification some journalists do, the news will have secondary 'sources' outside Twitter within minutes for free.
Even without going to such lengths, the activities and rough locations of US officials will already be massively valuable to any foreign power. Facebook had papers where they managed to guess an individuals health based on their typing patterns, just imagine what you could do with all of the Twitter analytics.
More importantly they don't point out things like CNN being owned by AT&T. Ever wonder why CNN doesn't cover why AT&T can be so awful? There's your answer. MSBNC is owned by this massive entertainment conglomerate: https://en.wikipedia.org/wiki/NBCUniversal_Television_and_St... CBS is owned by this entertainment conglomerate: https://en.wikipedia.org/wiki/List_of_assets_owned_by_Paramo... ABC is owned by Disney (wonder why their copyright pushing insanity is never covered negatively there?
Most people seem to assume that mainstream news is just an independent journalistic organization beholden only to itself, that truth is important, and delivering the news to the viewers are priorities. Something that is wildly untrue for almost all of them. Their corporate owned and those corporations have their own agendas that aren't aligned with the average American in the slightest.
>I think of the countless heterodox/dissident accounts that have been banned or silenced on the platform.
They banned satire accounts for wrongthink.
From Twitter spokeswoman Rebecca Hahn:
Hahn said that Twitter fired Zatko after 15 months “for poor performance and leadership.”
Hahn added that Twitter has tightened up security extensively since 2020, that its security practices are within industry standards, and that it has specific rules about who can access company systems.[1]
2020 was of course the year that Zatko was hired by former CEO Dorsey. So security tightened up "extensively" on Zatko's watch but he was fired for "for poor performance and leadership"?
This only seems to support Zatko's(and many others) assertion that Twitter is a giant shit show of chaos.
[1] https://www.washingtonpost.com/technology/interactive/2022/t...
I can't even get someone from Twitter Comms to pop into the Twitter subreddit to engage with users there.
Rebecca Hahn doesn't even have a Twitter account afaik.
>"Details: The communications lead role has been vacant since last November, but it's been led by Twitter CMO Leslie Berland on an interim basis for the past seven months. Hahn, who technically started last week, will report to Berland."[1]
The VP of Global Communications at Twitter role was vacant for 7 months and the person finally hired doesn't seem to have a visible Twitter presence after 6 weeks on the job? At a time when the company is practically a daily news story? You couldn't make this shit up.
[1] https://www.axios.com/2022/07/12/twitter-rebecca-hahn-commun...
I doubt he was fired for being bad at his job. But I'll bet he was fired for getting in people's faces. That was basically his calling card for years. Why is anyone surprised?
I guess Twitter thought they could hire the cachet, without hiring the man.
I remember an Apple WWDC, way back when. It may have been in the 1980s, as it was in San Jose.
They hired Ken Kesey to drive his bus to San Jose, and give a speech. The party theme was "Hippies," so he fit right in.
So they thought.
He got up on stage, and started talking about taking acid, and counterculture.
The shepherd's crook came right out, and yanked him off the stage.
I heard they had a big fight with him, because they wanted him to leave his Magic Bus, parked in the courtyard.
He drove off in it.
Smart people that make waves are not easy to control. If you are used to herding around mediocre sheep, you'll probably have a hard time with the wolves.
Point being, Mudge is a very well respected cyber security professional, not some "hippy hacker" from years past. Which makes me even more willing to give his accusations weight, because this is not a case of someone who doesn't "get" corporate environments.
But he has definite history of being quite willing to speak truth to power. Not having had any personal interactions with him, I can only go on the [many] stories I've heard.
Again, conjecture based on what I could extract from the froth, but mundane enough for me that alternatives (shocking displays of X) start requiring extraordinary evidence.
As head of X, maintaining good relationships is part of your job. It's actually the biggest part of your job.
There’s many facets to these types of jobs, and these types of teams.
I suspect that he was a “known quantity,” when he was hired, and acted as he was expected to act, by the person that hired him.
Jack Dorsey had his own issues, and pleasing him may not have counted for much, after the new folks took over.
I do have issues with declaring that someone at that level is being fired “with cause,” especially someone that knows where the bodies are buried. This goes double, for someone well-known for doing well in other environments. Usually, there’s some kind of “golden handcuffs,” and the firee simply “leaves to spend more time with their family.”
Regardless of his faults, they set themselves up for this. From here, it appears to be a rather petty personality spat that may end up hurting a whole bunch of folks.
So yes, you are correct, but the person at fault may not be Mudge.
* They can be utterly ineffectual, ideally while looking good in the press and maintaining good relations across the company. The latter is easy when you never have to ask anyone to do anything.
* They can be effective, which requires the ability to draw on and coordinate resources far beyond security. Their ability to do this is reliant entirely on the support and backing they get from the top. This will make people angry, because it's inevitably going to lead to reshuffling priorities and making choices people dislike. It's possible to maintain good relationships while doing this, if you have strong backing and you at need to convincingly be empathetic about people's feeling while they do what you security and privacy demand.
* They can be ineffectual while trying work across the org and negotiate without backing. Eventually this just pisses people off because you're constantly asking for things and they just want you to go away.
As a security leader, your ability to maintain good relationships while being effective is contingent on how much backing you get. If you're not backed sufficiently, you cannot do both, and then you have to make awkward choices.
1. A higher-ranked person (e.g. Agrawal) is screwing up in some way (e.g. not addressing security issues)
2. A lower-ranked person (e.g. Mudge) tries to get the problem fixed (e.g. addressing the security issues)
3. The higher-ranked person refuses, and it turns into a conflict
4. The lower-ranked person gets blamed for "not maintaining good relationships" or "being hard to work with" or something like that.
See this article: https://lethain.com/hard-to-work-with/
To be clear, maintaining good relationships is very important. Good relationships are the lubricant that keeps the machine running smoothly; if someone has poor social skills or doesn't make an effort to maintain good relationships, they'll cause unnecessary friction, and they'll end up wasting time and effort on a conflict when they could have solved by problem by maintaining a better relationship.
But, not every conflict is an unnecessary conflict that could have been solved by maintaining a better relationship! Sometimes people refuse to fix problems, and the only options are to apply pressure to them or let the problem go unfixed. Sometimes "lack of lubricant" isn't the reason the machine is broken.
(One way to see this is to note that Agrawal did not maintain a good relationship with Mudge. If maintaining good relationships is part of the job, did Agrawal fail at his job? Or do you think only the lower-ranked person is responsible for maintaining good relationships?)
He's stated that you can work to change the system from the outside or from within and he chose the latter.
I'll see if there's any kind of historical document. Apple's earlier WWDCs were not the high-production-value events that you see these days.
They often had celebrities give keynotes and speeches. They had Douglas Adams and Harry Anderson.
It was pretty campy. The staff dressed up in tie-dyes (and some had wigs), and handed us strings of beads, as we came in.
I imagine this hurts Twitter's defense against Musk from pulling out of the takeover deal, or, is this whistleblower's account inadmissible?
Mudge could be subpeonaed, just like Jack was just subpeonaed.
(That account tweets bloomberg alerts)
Not really because they have consistently said "this is what we do, it's a finger in the air estimate based on sampling, it might be right, it might be wildly wrong, there's no agreed methodology for this".
For someone to then go "they don't fully understand the true number of bots! GOTCHA!" is dumb because it's literally just pointing out exactly what they've said in their SEC filings since 2013.
I don't understand how you can look at his public behavior and think anything else. The only alternative is that he thought doing shitty things was a rational way to improve his situation, and I personally think that's a worse option
Nobody said it was easy, but it's certainly harder if you don't try.
They've been filing their methodology for bot counting with the SEC since 2013.
If they're not making a "meaningful effort" and it materially affected the stock price in some way, either the SEC or a shareholder would have gone "HOLD ON SHENANIGANS O'CLOCK", surely?
It can't be that the entire world was A-OK with Twitter's bot counting until June 2022 when a man claiming to want to buy Twitter to fix the bot problem got cold feet on a market drop...
And to give Musk an out, which is what this tangent is about, not only do they need to have actually lied, the lies need to have had a VERY substantial effect on the price of the company.
The bot thing simply does not help Musk get out of the deal he's made. That is not the same thing as "Twitter are great at dealing with bots and have been very transparent about how they do it", but that's not the bar that has to be cleared here.
No, they haven’t. They describe at a very high level the amount of sampling they do (100 accounts a day? Really, that’s it?), but don’t discuss the methodology used, such as what they use as signals and indicators of botness. That’s not “filing their methodology“, it’s covering their arses.
True, but probably quite successful. So this will most likely not save Musk.
Today's question on your statistics 101 exam:
You have a population of 100 million people. You estimate that the true probability of some statistic is about 5%. What sample size do you need to be 95% sure that you are within 5% of the correct answer? Answer: 73.
(No really, this kind of question is absolutely going to be in a Stats 101 class. And sample sizes really don't need to be that big to be accurate.)
1. "Finger in the air estimate based on sampling", aka. "don't read too much into it"
2. "Not more than 5%"
3. "Methodology can't be understood externally"
However, there's enough here, provided by a highly-credible technical expert, and under consideration by the US Congress, that Musk's litigation team has a strong opportunity to find at least something that holds up as a material misrepresentation, even if relatively minor, and then link it to the broader effect of this document, which could very well rise to the level of a material adverse effect.
So, where bots are concerned, bad but not disastrous; for everything else -- well, let's just say that Musk's litigation team are burning incense to the gods this morning, while a whole bunch of Twitter execs are going to be spending the next few weeks getting grilled by their own retained counsel, at an even more exorbitant hourly rate than they were paying before.
From a purely legal perspective, this really shouldn't matter much. As has been pointed out many times, Musk explicitly waived due diligence when he signed the contract. Also, it's still laughable to think that Musk's real reason for wanting to get out of the deal is the bot problem (instead of the obvious reason of the market tanking), when Musk himself made the argument that a big benefit of him buying Twitter is that he would be able to clean up the bot problem in the first place.
From the court-of-public-opinion, though, I think it does give Musk more leverage for a negotiated settlement to get out of the deal, which is really what he wants. I don't think Musk really thinks he can win in Delaware, but the longer he drags things out and the more pain he causes Twitter the more incentive they have to negotiate cancelling the deal.
>Musk lawyer Alex Spiro said they want to talk to Twitter whistleblower. “We have already issued a subpoena for Mr. Zatko, and we found his exit and that of other key employees curious in light of what we have been finding.”
…
>I can see private repos, yes.
…
>A Twitter employee, Chris Banes, has claimed "that nothing internal or private is hosted on GitHub. It’s all just open source code.". Here is a picture of a private, active, repo I had access to until about 50 minutes ago. Chris's statement is incorrect.
Right now breaches don’t cost much and cause a lot of harm. Companies have no incentive to drive the speed limit and listen to their engineers.
Because investing in IT security usually has no apparent profit incentives, so most companies leadership will consider it something of very little importance funding wise.
Particularly in the current climate where even minor hacks, and simple ransomware infections, are regularly made out as some kind of "act of God"/allegedly done by some super advanced "state actor", to create the narrative how it just wasn't preventable with the resources of a private company.
Which outsources all the responsibility to ominous intangible parties based on wonky, and often politically motivated, attribution, while holding nobody responsible for running outdate software in exploitable combinations, thus creating the problem in the very first place.
Twitter board = Incompetent, Liars, Corporate cronies.
Which of these two sources do YOU believe is more reliable? Yeah. That's gonna be the general consensus.
Mudge-1 / Twitter-0
In the next two months we have Elon’s Twitter trial where he’s expected to get railed. Despite waiving due diligence in his commitment to purchase Twitter he’s repeatedly made the claim without evidence that Twitter has made material misrepresentations about bots to him and investors. That would be fraud if true.
So right before the trial a “whistleblower” comes forward and makes claims that support Elon’s narrative. Weird. It’s just a little too convenient for me not to be at least skeptical.
He appears to indicate precisely what it's public, like the 5% bots but then goes to into the usual obscure "I know it's not that number and the structure is incentivized in the wrong way.."
Obviously he has an axe to grind and I wouldn't be shocked if Elon was directly involved with this, but I'm not sure this vagueness holds in court..
https://www.justice.gov/opa/pr/former-twitter-employee-found...
Also seeing various weird topics on twitter like kpop or other random things always made me wonder how much artificial bot boosting was done for those who had money to pay the bot net.
In Korea a blogger was able to see how BTS fans or "bots" were able to game the music ranking. What's interesting to me is how they seemingly correlate with wumaos as well.
I don't have solid evidence but it appears that much of the "stan" (kpop mob on social media) are very much politically aware and push a certain side of the spectrum.
All of this makes for some bizarre dynamics and I'm afraid that youngsters who are caught up in the craze don't know that they are being manipulated by very large crowd that behaves in bot like behavior or are herded into specific political flashpoints without understanding the underlying nuances.
For example, tiktok was recently outed to run keyloggers, and those genz who are "stanning" are also likely sending back all these crucial data points. This is not a conspiracy theory but the very reality that we are dealing with that those who do not share our values and way of life are able to not only cast a wide surveillance of its most vulnerable demographic but manipulate reality for them in all sorts of ways to identify "enemies of the movement" and overwhelm them.
What disturbs me most is that there is this disjointed, water-and-oil dynamism between the two political spectrums engaged in this toxic social media warfare aimed at sowing discord and turning its masses to feel ill, with society, stability and question everything we have.
It is this unwitting participation by the genz of the grander ulterior motives and agendas highlighted by special interest groups that have overlapping values with foreign states that know what strings to pull and the silence in response that worries me.
America's hostile nations know they cannot beat it militarily and they have developed very imaginative and creative asymmetric solutions to subvert and sabotage it from within, and the current state of this side vs that side makes it impossible to formulate a collective bipartisan response to steer the ship in the right direction.
We are not taking this issue of weaponized social media seriously and we see this first hand by how little enforcement/recourse there is for data privacy breach. We know that privacy of the individual is one of THE key pillars of open society and unfortunately the waters are murky and there is no guidance anymore.
In a few decades we will see what the result of this trojan horse experiment is but the current trajectory is not looking good. Gen Z suffer from the highest rate of mental health issues, have access to unprecedented amount of information and foreign subversion. When I realized your own flag is becoming a symbol of hatred, we reached a potentially irreversible stage of complexity and with that only increases risks.
This is also likely why Twitter makes it very hard to scroll to tweets at the beginning of when a trend started, and why timestamps are not really shown for the beginning of a trend to the public.
People absolutely do that, just because they think it's fun.
Even with FB's automated tools (which are surprisingly good), we still have to "prune" ~10 bot accounts per day.
If we weren't strict about this, in a year 25% of our group would be bot accounts.
And you're afraid of getting interesting insights from and interacting with bots ... ?
If you have a platform as prominent as Twitter, making it onto the trending timeline can be very profitable for musicians. The same major industry artists regularly trend on Twitter because they command most of the profit, and then often use a percentage of that for paid and bot promotion. It's just my opinion, but Twitter facilitates and permits that bad behavior regularly because they profit off of the activity too.
There is not much more frustrating than being a creator or artist and competing with major industry forces that have unlimited funding and internal contacts within Twitter that ensure that trending is on rails daily. It's not only bots, it's the sponsored and sanctioned control of what trends that is a hallmark of the platform.
https://www.cnn.com/videos/business/2022/08/23/peiter-mudge-...
DMs should be BYO provider
"Zatko was fired by Twitter in January and claims that this was retaliation for his refusal to stay quiet about the company’s vulnerabilities. Last month, he filed a complaint with the Securities and Exchange Commission (SEC) that accuses Twitter of deceiving shareholders and violating an agreement it made with the Federal Trade Commission (FTC) to uphold certain security standards. His complaints, totaling more than 200 pages, were obtained by CNN and The Washington Post and published in redacted form this morning."
What a bombshell! Maybe Elon Musk's complaints about Twitter have more merit than anyone expected.
What might the SEC and shareholders do in response?
If shareholders believe this, they can do a variety of things such as sell the stock (smaller holders), or demand answers from leadership that go beyond "Yeah, we're secure" (bigger holders such as Saudi Arabia).
Mudge also raises a number of allegations not pertaining to bots, including that Twitter has deliberately failed to abide by the terms of a federal consent decree. If proven out, that fact alone would constitute material adverse affect.
Pop legal quiz - does "waving due diligence rights" during an acquisition remove the other party's liability for fraud they've committed against the prospective buyer?
What fraud though?
If Mudge's allegations are true that Twitter has been defrauding the public in their reporting, failing to abide by the terms of a federal consent decree, and generally turning a blind eye to real problems to prop up their image, then "waived due diligence" or not, Musk has an out from the acquisition, and cause for a significant tort claim.
Musk literally tweeted about the « bot problem » on Twitter before the acquisition.
Not the bot complaints, anyway, because "failed to properly estimate the number of bots on its platform" has been covered off by Twitter's consistent "this is how we estimate by sampling, it's a finger in the air guess, could be right, could be miles off, there's no standard methodology for this" stance in their SEC filings since 2013 (which no-one has questioned until now, mind.)
Anything Elon or crypto related is still being spammed heavily with giveaway/impersonation bots. Nothing has changed. The spam/bot problem is as bad now as it has ever been, and likely is worse than assumed, because it includes not just obvious spam accounts, but legit accounts that have been taken over by spammers or repurposed for spamming. So there is a % of accounts which are obvious bots and than another % accounts that exhibit bot-like behavior. Given how much time Elon spends on twitter and his first-hand experience with scammers using his name and spamming his comments, I think his assessment is probably more accurate compared to what twitter is claiming.
While one may (not wrongly) think that this is a bad idea in general (unless you subscribe to post-privacy), I think it is our duty as a society to protect those who don't have a full grasp on the implications of bad IT security.
In my opinion, fines for cyber security violations should be swift and harsh (GDPR goes in the right direction in terms of how high the fines are, but it is barely enforced). From my POV that is the only thing that will force companies to actually invest in cybersecurity. Maybe there should even be a law mandating security reviews if you handle any PII.
Has any one gong through the Washington Post story and the PDFs and found the real issueS?
What happened that caused him to suddenly start whistleblowing now, and not in January? Was it the same thing that caused Ken Paxton in Texas to start investigating Twitter?
This just looks like pretty plain mud-slinging from Musk's team to be honest. Especially since the Whistleblower seems to basically be blowing the whilst on himself.
Media only got its hands on the leaked material now.
>Zatko began the whistleblower process before there was any indication of Musk’s involvement
Define "Began the whistleblower process". Because that seems like an extremely fuzzy way of saying this. And even if you accept that he was genuinely a whistleblower in good faith trying to do this, which I'm perfectly willing to accept, the fact it's coming out in public now is still convenient timing.
It does say
>The disclosure, sent last month
Which means that the actual firm date we have coincides perfectly with Musk's legal wranglings.
>Zatko was fired by Twitter in January and claims that this was retaliation for his refusal to stay quiet about the company’s vulnerabilities. Last month, he filed a complaint with the Securities and Exchange Commission (SEC) that accuses Twitter of deceiving shareholders and violating an agreement it made with the Federal Trade Commission (FTC) to uphold certain security standards. His complaints, totaling more than 200 pages, were obtained by CNN and The Washington Post and published in redacted form this morning.
So, breaking it down more concisely:
1.) Fired in January
2.) Musk tries to buy Twitter in early April
3.) Complaint filed with SEC in July by Mudge ("way [after] EM entered the picture")
4.) WaPo published redacted, 200-page report today
[1]https://www.theverge.com/2022/8/23/23317857/twitter-whistleb...
Edit: This is not an endorsement of mud-slinging, just an attempt to make sure everyone knows what actually happened and when, at least as best we can discern at this point.
> Please note that Mudge began preparing these disclosures in
> early March 2022, well before Mr. Musk expressed any
> interest in acquiring Twitter, and has not communicated
> these disclosures to anyone with a financial interest
> in Twitter.
Why debate what the timelines implied by various articles are when the primary source is available and makes a clear statement on this matter?Probably because most of us in the chain you're replying to didn't have the time to read an 84-page source document in the middle of a work day (note the time of our comments and how late to this particular chain you are), hoping that a nugget of information like that would be dropped pretty early on in it. Hence my edit at the end, which I had hoped would have made it clear that I was open to being corrected.
But thank you so much for that snarky comment while you clarified things. You're so much better than us for finding that, how could we have ever been so daft? Forgive us?
Apologies for having offended you.
It's not fair to you, and I'm sorry. Hope ya have a great rest of the week. :)
And much good luck with your situation.
Here’s hoping you overcome the things you are struggling with!
According to his lawyer as reported by someone on Twitter. IIRC, lawyers make statements that guilty clients are innocent all the time.
If he was working with Musk help him wiggle out of the Twitter deal, it would fatally undermine the goal for to come out publicly about the relationship. I'm skeptical unless they can provide verifiable 3rd party evidence (e.g. some document filed before the deal).
Whistleblowers are by definition insiders.
A typical whistleblower would say "There were security problems, and the head of security ignored them."
Here, it's "I was the head of security, and security was shitty. I was doing a shitty job, and that's a terrible scandal!"
But if I were a betting man, I do think both Twitter and Mudge's respective track records would place me in Mudge's camp.
I did find one say that the complaint was already in progress before Musk's deal, and Musk rightly tried to subpoena Mudge for his recent exit. It does sound reasonable that the bot comment was added in light of the fiasco with Musk's deal.
I've been in that situation at a previous job. The infrastructure for our service was set up so that EC2 instances would start up and pull their code from a central repo. But this repo was open to the world and did not require authentication. It was only a matter of time before some malicious user discovered this and our proprietary server code got leaked.
It took weeks of hounding and escalating until something changed, and at first all they did was change the security groups to limit where you could connect from, and even the first patch merely limited it to a few /8 and /16 CIDRs that covered massive swaths of AWS-owned IPs. They still didn't require authentication.
1. You find out all the problems. 2. You can't fix all of them (many reasons here, not all malicious) and are setup to take the fall.
Rinse and repeat.
Immediately thought of this item that came up in my Twitter news feed last week [0]
>> "Elon Musk went to Kevin McCarthy’s Party last night in Wyoming—to celebrate Liz Cheney’s loss. While speaking at the MAGA party, Musk asked everyone to deny that he was there. Musk made sure that no press was allowed anywhere near the property — then people started posting selfies"
I'm sure Musk wasn't there to privately insult the Republican leaders by acting like they're the ugly person that they'll date in private but don't want anyone knowing about — he's almost surely seeking some kind of influence/benefit.
Maybe coincidence, but I certainly wonder about the purpose?
[0] https://twitter.com/FriendEden100/status/1559974086264209414
CEO of company defends organization and says previous employee has ulterior motives... Not okay, I hate big tech companies.
See a trend here?
Seems like a legit answer. No need to accuse people of slinging mud.
I think you’re gonna need more than Musk Derangement Syndrome fueled conspiracy theories to make your accusations stick here.
I'm not going to claim some big conspiracy here, but I do find this beyond coincidence.
I don't think that this is coming out now because Mudge is acting on behalf of Elon. I think Elon's Twitter bid (and ensuing drama and upcoming lawsuit) and this revelation are part of the same agenda. For better or worse, it looks like influential powers that be are going to take down/over Twitter.
Let them, Twitter can't get any worse.
At the very least, lets get to the bottom of the bot problem and expose these companies who rely on bot activity to drive their MAU numbers and as a result, their inflated valuations.
The rest of these expectations are entirely on the users. If people take security as seriously as they proclaim, they should not have registered. To now demand meticulous access controls sounds a bit neglectful to me...
Has Twitter ever been in the news for properly making even a thousand people successful from scratch really ever in the product's life?
They have pipelines of exploitation for everyone that gets "discovered" into contractual nightmare deals, they require tons of free labor and costly hurdles just to become notable and visible on the platform, they extort people promoting their independent work for ad money, they don't protect anyone's privacy, they are VERY MANIPULATIVE in multiple (psychological) ways, they offer very little support or fairness when accounts are compromised, hijacked, or stolen, and they impose a stranglehold on information through lobbies and suppression of independent art and music.
Social media took over the Internet after they wooed everyone into the ideal that they would operate fairly. Now that they have captured full attention, they have turned on users and they offer very little to anyone who doesn't pay, and can't offer reliable security to anyone. There are some serious "God Complexes" going on with having access to the personal data these systems harvest ON EVERYONE in conjunction with mobile devices.
I really hate to say it would actually probably make me feel better if most of the large data monitoring sites/apps went away rather than stayed in place, because they make almost every aspect of the Internet work against us all.
Twitter has had several opportunities to fix how it operates. The platform also generates tons in annual revenue to fix how it operates. Twitter has lots of employees that could fix how it operates. Twitter has also had numerous security breaches, and it regularly causes tons of stress for users. Twitter continues to focus on only pleasing it's sponsors, investors, and execs year after year and repeatedly stretching the promises it was built upon.
I can't say I want to see this whale fail, but I won't miss it if it does.
Yea, that's the game. They are a for profit business. This situation will happen every time. Profits over people, line must go up!
In the case of data harvesting, data is the most valuable resource. You can control what people want using data. No entity should have unfettered access to data — it is undeniably evil in the truest sense of the word. Which, in the context of my use, means to decay forward progress or to increase aggregated suffering.
They will not fix these issues until the public makes it so painful not to, that they must. As an example, how is Experian still in business after what they’ve done? They should have had a $100 billion+ fine levied against them, and that fine should pierce through limited liability to the extent that the board of directors and C-level staff are liable for it. The company and any owners of it should be bankrupted and living in poverty after what they’ve done.
Until we make PEOPLE liable for the evils they induce on others, this will keep happening. I don’t get limited liability if I went out and murdered someone, why should the PEOPLE running companies have limited liability when they murder millions with pollution, or with financial terrorism? Answer: they shouldn’t.
It's the best chance we have to stop this horrible trend. Companies have shown repeatedly that they are not trust-worthy nor responsible enough to self regulate.
You're making a distinction without making a difference. Regulating public forums for their content outside of illegal content has never been not abused. The UK is learning this the hard way with the police "checking the thinking" of netizens.
If you think companies are bad, then imagine politicians. I can switch off to another social media but I can't switch out to another state.
For what it's worth, as someone running a high-five-digits account, it is possible to get notable on Twitter - you just have to put in a ton of work to make quality content people are actually interested in.
Hard work for free does not make sense in this type of post-pandemic world we live in... It's too "Marie Antoinette-esque" of people to say it's anywhere near reasonable.
There was the Arab Spring (https://en.m.wikipedia.org/wiki/Arab_Spring), where it played a significant role.
I mean, surely, it some people were successful, but success of warlords intending to genocide blacks in Lybia or starting a new violent caliphate or kidnapping boys en masse to be child soldiers is not the sort or success I want to be enabled with technology.
Go tell that to Raytheon and Blackwater as well.
Could you ever trust them? Honest question.
I mean, it's not really doing a good job of any of that either.
Everyone in this shameful industry knows that literally any company in the US would get shredded in such a vigorous audit and the silliest part is that twitter is a fucking shitposting platform that doesn't have my SSN or financial data so equating it to equifax in any way is absolutely laughable.
That’s quite a generous take. There were plenty of excellent hackers in the 90s, but “L0pht” just seemed like the PR friendly one that could go on good morning America.
Can’t tell if this is real or just a 90s security person trying to stay relevant after being fired.
High profile doesn't mean best it just means high profile.
The reach of HN on the tech world is highly influential, and for sure it is weaponized in "communication wars" across actors with different interests.
EDIT: that doesn't mean that the given information is necessarily false, it is just presented at the right time, to promote one view of the world. Also when Twitter hit bottom some years ago several HN submissions remind us how they declined being purchased by Facebook etc, and social network giants have a large track of understanding how such information flows and influences people.
So it may just be another event which will drive Twitter's price down even further and make it a _worse_ deal for him.
From Bloomberg "The buyers could only back out of the agreement in the case of a material adverse effect, a high bar that excludes issues like market volatility or industry challenges." (https://www.bloomberg.com/news/newsletters/2022-07-13/elon-m...).
I suppose one could argue that the Whistleblower's report is "material adverse affect", something I'm sure will come out in the trial.
So about a few hours.
*Walter Bloomberg @DeItaone ELON MUSK’S LEGAL TEAM HAS SUBPOENAED PEITER “MUDGE” ZATKO, TWITTER’S FORMER HEAD OF SECURITY - CNN 8:30 AM · Aug 23, 2022·TweetDeck
I don't doubt this, but the source is someone with fairly deep ties to the US intelligence services. Why should he be allowed a job and not people with ties to foreign agencies?
TLDR; Someone like Twitter, Google or Facebook should have 'some of our employees are malicious and sophisticated' as part of their threat model.
Or they will use money or kompromat to turn existing employees.
I would estimate there is a 100% chance that every one of those companies listed, has multiple employees who work for or are sources for US domestic and foreign intelligence services.
It should be expected and part of their internal systems that people only have access to the shared drives they are meant to.
What are you basing this on?
It seems more probable that this security leader failed to get buy in from the engineering teams, or that there was some technical debt that he couldn't get past.
What I can't figure out is what's this guy's beef that he went revealing all this? Was he fired or demoted or something and thought to get his own back?
Seems like a legit answer.
He was fired January last for alleged poor performance. Totally can see now why it's all come to light, less the altruistic urge to make things secure, and more the old case of flipping the bird to a former boss.