The Twitter whistleblower story is worse than you think
kolide.com
kolide.com
I think everyone with experience has, which makes me wonder who the target audience is here.
Generally they do.
Because during an exposure incident they often have to deal with regulators who punish them much more than the market will.
Experian leaked basically every American's SSN and credit history, and they got off with a $22m settlement.
One of the banks I recently worked at flipped the model from heavily restricting what users and systems can do to allowing them to do anything (including admin access for developers) and aggressively monitoring them.
In comparison my current bank needed 4 weeks and manager approvals to get a mouse driver installed.
I have yet to work for a company that has IT security and IT management in the same org.
Which is insane.
Why are companies empowering someone to say "No" (CISO), without requiring that same individual to justify not saying "Yes"?
If a user requests a tool, IT sec/management should be leaning in and asking "What can we provide you will that will satisfy this need?"
Instead, and I assume my experience generalizes to everyone who's worked in regulated tech, the response is "No, that's not approved" and ends the conversation.
This is just my rambling thoughts, not sure if I have a main point, but realizing this pattern has certainly contributed to my personal sense of disillusionment.
The job that the security org is doing for the board/owners/etc is controlling risk because they don't trust if their IT org says "everything is totally fine", and consider it likely that if the decision about whether to implement some activity or not is left purely to the IT org, then the convenience of implementation will override the level of risk control that the board/owners desire, so they choose to put these controls in a separate organization, empowering someone to say "Not until you do all this unwelcome work to implement it to the standards the company has chosen", preventing all the many mid-managers to save their effort or their costs by cutting corners at the expense of risks to "someone else's" money.
Of course, having these functions together is much more efficient in many ways! But the principal-agent problem is very real, especially so in large organizations, so that's why these choices get made this way, designing organizational structures that act as checks and balances on each other, not expecting everyone to magically cooperate for the greater good.
It has not been my experience that this is what most IT security orgs say in practice.
It's usually "No, unless we do it" followed by "And we don't have time to do it."
Which is fundamentally because they're a cost center, and typically staffed like one.
That's bogus. Having the policies be in the same org as the provider just makes sense. You can run a separate security auditing department if you're keen to do that, nothing is stopping you. You can have independent oversight while you don't totally hamstring your organization.
Those auditors aren't also the ones approving expenditures, are they?
I once worked a very short stint as an external dev at a private bank (6 weeks).
The side entrance we used had a revolving door-style airlock with enough space for a single person to stand, protected by a card reader using unlabelled RFID-style cards.
This was obviously to ensure that for every person entering, there was exactly 1 card swipe, no one could hold the door for anyone else, etc.. Real claustrophobic in there, to the point where it was impossible to step through the revolving door, you had to do stutter steps while the door revolved around you.
So obviously this airlock was broken at least 60% of the time. Its replacement was a normal door next to it, which was left completely open instead.
If by good you mean: the company would have no problems putting in their advertising the number the CISO knows about how much it would cost to completely invalidate their security and their customers and investors would be happy, or at least non-livid, if they were told; then none in the Fortune 500.
If by good you mean: somewhere where that number is more than $1M, the smallest unit that appears on their 10-Ks which usually use millions as their smallest unit, then probably none in the Fortune 500. If you raise it to $10M, then without a doubt there are none.
If by good you mean: "better" than other companies, but still trapped in a valley with the horde of hungry bears faster than them, then who cares, the bears are still going to eat them soon.
But why should we even worry about security on social media sites? I really have zero sympathy for people who upload private data to those companies and then complain when it gets hacked. What the hell did they expect? Twitter was never under any legal or contractual requirement to provide good security for user data.
Generally? I cannot say. This was around the corner from me, and is an anecdote.
https://en.wikipedia.org/wiki/Waikato_District_Health_Board_...
IN the news at the time the cause was "somebody clicked on a link they shouldn't have"
In reality the cause was comprehensive failure of computer professionals (like us) to do their job, and an unbelievable lack of accountability
Compare with this: https://en.wikipedia.org/wiki/CTV_Building
We have nothing like the accountability that civil engineers face. This will hopefully not last so we get a chance to do our jobs properly
"Good" is ambigious,but there are privacy laws that do apply to twitter (especially but not exclusively in the eu)
Private data can be something as simple as DMs between people, which if leaked can cause plenty of trouble (an example that comes to mind is streamers having to deal with a lot of drama from their fanbase because leaks revealed they were acquainted with a streamer of the opposite gender).
On top of that with so many government officials and company CEOs on the platform it should be pretty obvious why access to the backend should be carefully controlled. There already was that incident a few years ago where someone got access to the backend via social engineering and tweeted out crypto scams from high profile accounts like Musk, Biden, Bezos, Apple etc.
- The corporate spyware wasn't used enough
- Engineers had too much access to code
- Employees were allowed to install personal software on their computer
That's it? Twitter is guilty of running a chill office? Is there any actual vulnerability?
Drums beating for a war on 'Shadow IT' (and for an even more adversarial relationship between IT and Engineering) sounds pretty alarming for sure
1) I don't think having a single mono-repo and everyone having access is a major security concern. 2) Employees should only run corporate approved software.
considering he only worked there for 8 months, I doubt how much his information is credible.
There isn't anything ground breaking security-wise in this article, and the headline is definitely a lot of Trunped up hyperbole.
The blog "take" could be about any tech or Fortune 500 company.
Strange times we live in.
Engineers having full control over their dev machines up to and including preventing system updates is not ideal; but not out of the norm for tech. Poor data access controls, and out of date server fleets (where I'd expect updates to be pretty automated) are far more worrying to me.
any amateur can run some automated scanners and issue security diktats to the rest of the organization
"you can't convince someone who doesn't want convincing" is also a weak cop-out that would be totally unacceptable as an attitude of the head of anything. As head of IT Security, part of your JOB is convincing people who aren't convinced (easily played off as 'they don't want convincing' by people who fail to convince them)
if a head of IT Security came to me as a CEO and lamented "the organization isn't doing what I tell them to do", I feel like an appropriate question is, "what do you plan to do about it?" or "what options do you have in mind to get them to?" Every CEO knows security is a pain, they hire executives in order to delegate pains away
What happens when head of security tells the CEO that necessary, important security changes will cut their revenue by 30%?
in your example, the CEO might continue to listen while the head of security explains why it's worth more than that 30% loss to secure the systems
examples might include the cost of lawsuits, the cost of regulatory action, the risk of actual harm to people (customers or otherwise), the cost of reputational damage, etc... security has to economically justify its internal projects just like every other department does
Is that still the failure of head of security?
In this scenario, I feel like you've only left room for head of security failure and not CEO failure. Maybe I did the opposite, but it's based on mudge's long track record. Agrawal doesn't really have a track record outside of being promoted at near record pace to CEO in a company.
if you don't have a benefit that outweighs the stock dumping like that (in other words, in the CEO's opinion, is the probability of bad stuff happening, multiplied by the downside of it happening, greater than that 30% drop?) then your proposal simply isn't something that should be done
that's not to say the CEO hasn't failed by hiring an executive who can't do their job when it requires soft skills and persuasion
Let's look at a CEO of a cigarette company in the 1940s. The head of health comes to him with strong evidence that cigarettes cause lung cancer and are slowly killing their users. What would the appropriate action for a CEO be? Or for the head of health? Is the head of health a failure if he can't convince the CEO that they shouldn't be selling cigarettes? I don't think so. Because the head of the company might care more about money than about giving people cancer, and that is his choice to make.
Yeah, maybe the company may hit some rough times later, but if the CEO just hides this report, then the CEO can keep making money, and maybe the shit won't hit the fan until the CEO is already retired or dead.
Instead of stopping the sale of tobacco and shuttering the business, the CEO fires the head of health. Then, the head of health goes to a newspaper as a whistleblower saying that tobacco causes cancer and the CEO knows about it. In what world is the head of health a failure here?
an analogy in ITSEC would be knowledge of an actual (not potential) ongoing user data exfiltration and hiding knowledge of that
most ITSEC scenarios are not this, but rather a failure to explain why the potential loss of doing nothing is worse than the actual loss of doing something, just like a CRO must explain why the potential loss of not entering a market is worse than the cost of entering it
If you had an out-of-date version of the OS you’d be cut off from the VPN. Pretty standard stuff.
My intent was pointing out that engineers with high level access to their dev machines is pretty common in tech. Not that other controls like policy enforcement are also often absent in tech (esp in larger companies). Hard to know how common that is -- seems unusual at least in big tech.
I've worked in 3 Fortune 250 blue chip companies. My experience is that senior management is doing just enough about security to check the boxes that the trade press -- and the consultants they say we should hire -- say we need to check to have enough legal coverage to weather a possible lawsuit.
Given that Yahoo! had their ENTIRE user database hacked, and VISA, and endless other examples of major personal data breaches, and that none of these things ever results in anything more than a slap on the wrist, I'd say that even these paltry box-checking efforts are probably a waste of money.
I don't know how this situation would be materially any different at a "FAANG" company versus a 100-year-old manufacturing company.
I read through the actual whistleblower complaint and to be honest I was shocked as well. If true, the security on their laptops was extremely lax or nonexistent. My current and previous companies will not let me install what I want on my laptop. Even something as innocuous as Signal is not allowed and I'm too scared to push the issue. I basically assume that everything I do is being watched and keylogged which actually makes life a lot easier for me.
The idea that Twitter would allow anything to be installed is kind of shocking to be honest. It sounds like they're not taking their place of prestige in the Internet hierarchy very seriously.
The fact that Mudge couldn't lock things down after Jan 6 or that there wasn't adequate logging etc is also extremely shocking. I would love to hear Twitter's side of it and the reason why it wasn't a priority. Was it because Jack Dorsey had taken his eye off the ball and was a missing leader that lead to this? Or was it Parag Agrawal's poor leadership as CTO and CEO? It certainly sounds like he was an obstacle in the way of Mudge, which doesn't sit well with me at all.
For what it’s worth, AWS has the same somewhat lax policies about installing software on company laptops.
That’s not a diss to AWS security mind you, I’m sure it’s top of the line.
GP was talking like this alone was gross negligence, implying that this is different from the rest of the industry. That doesn't seem to be the case.
On the machines people use for Livesite support ("Secure Access Workstations") it's a different story. Those bad-boys are locked down from the supply chain through day-to-day use.
Top of the line security looks like door locks with daily changing codes and number pads with lcds on them that scramble the order of the digits. It looks like regular searches of your effects as you leave the building, badged and guarded entrances that operate like airlocks, security that roams the building and leaves your manager a nasty note if the wrong documents are left in the open on your desk along with a computer and network that actually won’t let you install software. This was my first job and it felt normal.
Good risk management means knowing when to accept a risk. Twitter was too lax, but the opposite millitary approach would also be the wrong choice for something like twitter.
But top of the line security anywhere is not "meh, install whatever you want on the company laptop". And any company handing private communication and responsible for making social network decisions does need fairly good security to protect against compromised employees and compromised company hardware. That looks like solid policies for installing software, centralized management of hardware, and written policies that are well thought out, audited, and followed.
Finance, medicine, defense, ecommerce, etc. all have industry or government regulations for these kinds of security polices and compliance, it seems like social media companies are the wild west and clear signs of problems and abuse have come up repeatedly.
No, they probably don't need to go through your bags with random checks to see if you're exfiltrating classified materials or warn you about wearing your company badge visibly when you go out to lunch to avoid spies.
You are sure. Whew!
Terrified am I
Remember when Twitter got real big because of the Arab Spring? Free Speech is good? How is “Twitter” supposed to know what to “lock down” and what to allow for good?
it's absurd to me that you'd need to put every library through compliance even if it has very straight forward OSS licenses.
There was specific software everyone could install with a service request, non-standard software could also be requested, temporary rights to usual stuff could be requested as could permanent access to those rights.
It was just annoying for me, but I could see it being a significant impediment for some people in some situations.
They just don't want you granting admin permissions to an email that you inadvertently clicked a strange links on, or some virus laden craking tools, you shouldn't be running.
It's understandable, but super annoying. Yeah, it'll probably question my long term view of the company.
Security and convenience are opposing forces. Security and reliability not so much.
My plea to all of us is get used to it. People's piece of mind (at the least) depends on us doing our job, and as this story is an example of us failing.
The age of programmers winging it should be long gone. We are professionals with responsibilities. Our jobs are not for our pleasure or satisfaction (even when they are fun and satisfying)
Mēh. Perhaps. But then Enterprise IT is not doing its job.
You should not bring your own tools to do this sort of job. We need to be professionals, not enthusiastic amateurs.
We work with "Enterprise IT" not against them.
It’s not hostile for an employer to want to protect themselves from employee mistakes and there are ways to do this without invading an employees privacy.
Or you do keep it up to date and suddenly it exposes your device to new vulnerabilities.
Our industry is on a very bad way
Most (but not all) had some sort of asset management tool and/or antivirus as standard on computers, but nearly all provided exceptions to having that functional/installed.
I, and I expect many developers, likely select companies with IT policies that avoid potentially harming individual productivity.
Abuse of that trust was a fireable offense and someone did get fired for it.
Except all the developers just got permission to install virtual box, and ran another OS inside virtual box that they could and did do whatever they wanted to.
This didn't improve security past not locking down devices, it substantially hurt it, but it was also the only way anything got done.
I work in finance and we get all these audits and questionnaires from regulators, insurers, intermediaries, clients, etc. and many of them are straight out of the 90s.
For example, when we replaced the VPN with a zero trust system, we got a ton of pushback. It didn't matter that the ZT implementation provided stronger guarantees than the VPN ever did as well as doing everything the VPN did. What mattered is that it wasn't called a VPN and they were expecting me to write "Cisco VPN" or similar.
Unfortunately, developers having admin access on their machines triggers so many red flags in these processes. Doesn't matter if you install a load of auditing and remote attestation stuff, admin access is instant ticket to bureaucratic hell.
Locking down the system and then assuming everything is fine is a recipe for disaster.
That being said, Twitter's stance on insider risk was a little too lax for my taste: my colleagues at a big tech were often asked by governments for their work passwords at country borders if the border patrols noticed they worked for the company, and had no choice but to comply. Preventing insider access to systems mitigates this risk to your employees.
I've worked for companies all along that spectrum.
I've found that the locked-down companies tend to be heavily bureaucratic in other ways as well, and in general make my life as a developer less satisfying. I gravitate towards the more liberal companies.
Why do we think that FAANGs set the standard?
Who else would set the standard of security at large internet services? Judgement by a jury of their peers seems fair.
A few years ago, I was part of a group buying a commercial building. Each partner needed to co-sign for their portion of the loan. The bank wanted to know all the assets and liabilities of every partner. I listed all my liabilities and also listed enough assets to cover the liabilities. When the loan officer asked if that was all my assets, I honestly replied no and that I did not intent to list everything I owned.
When I voiced security concerns as the main reason, he assured me that his bank had a secure system that was fool-proof. I just laughed and refused to give him the information he said he needed but obviously didn't. Luckily, they wanted the loan to go through and it did.
Not to excuse the lack of monitoring or fine-grained control, but most engineers having some kind of prod access is what happens at companies where you are oncall for your own services / dev and ops are not separate roles.
How do you ensure you are not a gatekeeper but also keeping company secure? Vetting software installations would be killer for any productivity at that scale I guess. Does it include npm install too which can run scripts or just desktop apps, chrome extensions?
In software development, you need to install software in order to do your job. I've worked at two "big tech" companies, and both of them had a policy of allowing employees (at least in engineering) to have root on their devices and install what they need to do their work. 1. We're intelligent adults and trusted to not fuck everything up, and 2. Internal systems are properly secured against fuck-ups, so a rogue compromised laptop on an internal network should not be able to screw anything up anyway.
Then again, I've worked at smaller companies that thought their perimeter firewall and VPN for employees was adequate security. Once one got onto the internal network, there was no defense in depth. A compromised laptop (not to mention a disgruntled insider) that managed to get onto the internal network could literally wipe everything out.
Half of any company having access to prod is insane, but half of a giant like Twitter is unimaginable to me. It really explains how compromising single employees seems so effective there.
When these bannings get publicized, however, the bad publicity often leads to the "permanent ban" being reversed, with Twitter simply explaining that the original ban "was a mistake". How does this sort of thing happen so often, unless random employees have access to powerful tools that they are not authorized or trained to use?
Maybe, instead of hiring N skilled moderators for $D, they could be hiring N * \delta unskilled moderators for the same price.
This form of civil liability has given us safer cars, home products, machinery, and professional services. Its most often preemptively enforced, not by our court system, but by insurance carriers who insure against the liability.
Please note that I am not claiming that updates are a silver bullet. I am sure if someone managed to obtain credentials that allowed them to release an update for MS Windows, say, and that update installed a keylogger, it would be bad news.
But regular updates at the source code dependency, OS, firmware, networking hardware, device layers, mandatory code review, hardware FIDO/U2F tokens, training on best practices for handling data and for writing and reviewing secure code, use of modern encryption algorithms, encryption of sensitive data at rest, requirements to not store PII without a proven need, requirements to change default passwords (or even better yet - laws mandating non-default passwords at ship time), ongoing anti-phishing training, and the like will all help us stay safer. There are bad actors out there. We all make mistakes. Our industry is maturing at an altogether unacceptably slow rate, IMO - a lot of these techniques are well known in the industry, but they cost money and time to implement, and nobody seems to want to expend that effort until it's too damn late.
I am not a security expert. Just a developer who tries my best to pay attention.
Agreed. In my company, "best practices" means "what I want," "what I'm used to," "what the sales guy is selling", or "what my boss wants."
There is no such thing as "best practices," and certainly no "best security practices."
Such a thing would have to be developed, perhaps by NIST. And even then, it would only exist as a baseline so that middle managers could mark a checkbox off on a list.
The only solution I can think of is to make companies financially liable in a way that actually hurts them. One of the reasons that healthcare companies run around in a HIPAA hysteria is that HIPAA violations can actually cause them great financial harm. The same cannot be said for mot of the tech industry.
Right now there are only ~250 car models available in the US. Each one gets incredible amounts of attention from all sorts of people, both before and after launch. And cars are pretty stable technology. But there's a ton of software out there: 1.8 million entries in Apple's App Store alone. And our tools and technologies are still evolving at a rapid clip. Having to explain each new library to an insurance company functionary sounds like a major brake on innovation to me.
I feel similarly about the Section 230 issue - past a certain size, orgs are large enough to actually be able to be held to account on matters of speech on the platform - but defining that line is challenging and potentially very destructive.
I'm sure there's security issues at Twitter, but I don't see a reason to believe it's so much worse than other companies.
I would argue that it really doesn't matter if Twitter is worse than most other companies, the problem is that none of these companies should be operating with such poor (non-existent) standards. Especially when they have as much data as Twitter. I personally "protect" my tweets so that others, like my employer, cannot see them. There are many more people with so much more sensitive information that are trusting in this system.
This attitude, combined with a pathological inability to state what the practical harms/risks are, is why "privacy advocates" never get anywhere.
That doesn't mean their claims are false. But you should always be skeptical.
The second issue is the trial resulting from Elon Musk walking away from the Twitter acquisition. That acquisition agreement calls for "specific performance", which means Elon pretty much agreed to buy the company no matter what (he waived due diligence). He is expected to have to pay a fortune if not actually buy the company in his trial next month.
So it's at least worth noting that this disclosure happens right at a time when it might help Elon. Maybe unrelated but it's also a hell of a coincidence.
Employees that are fired (or are heading in that direction) can make all sorts of claims to deflect away from the fact that they were or soon would be fired, possibly with cause, possibly not.
The specific claims seem to be a little vauge like not giving employees tools to combat bots. Like what does that even mean? Twitter may have crappy infra for this but does it rise to the level of negligence or even malfeasance? That's not a slam dunk from what I've seen.
Keep an open mind but remain skeptical.
> [Mudge and Sethi] deprioritized Twitter's kernel & OS upgrade and encryption at rest initiatives.
(from Ian Brown, who deserves his good reputation as much as anyone I've met)
Mudge was already an officer of the company, he had much more guaranteed money to gain from just shutting up and staying there.
Think about some of the past whistleblowers from these companies: Frances Haugen, Timnit Gebru, etc. These are all people for whom whistleblowing was a good career move.
Probably also doesn't hurt that he gets to twist the knife into the company that ousted his friend Jack.
>So it's at least worth noting that this disclosure happens right at a time when it might help Elon.
I am having one hell of a time putting these two together.
I'm not sure what your point here is. That the lawsuit can be worth a lot of money doesn't take away from the fact that the SEC has to prove their case in court. How does the value of the settlement raise any question about the legitimacy of the judgement?
That means that being a whistleblower is strictly positive expected value in this case, which means that there is a heavy incentive to find something to blow the whistle about, no matter how flimsy. Additionally, the whistleblower has a strong incentive to add color about how bad these problems are.
People treat whistleblowers as unbiased sources of reliable information, but that could not be further from the truth. If you ask a tobacco salesman if their product has health consequences, they are going to say "no" (unless there is incontrovertible evidence of health consequences) the same way a whistleblower is going to say "this is super bad" about something that happens at a company (unless there is incontrovertible evidence that it was not bad). Understanding the bias of a source is very important.
> This can be worth tens of millions of dollars.
I don't understand why the potential value of the settlement casts any shade on the whistleblower.
I was not commenting on fake whistleblowers doing it in an attempt to trash a company's reputation.
With the Elon lawsuit with Twitter, it presents an opportunity for people to raise their public profile. (Many) Elon stans will be inclined to believe it no matter what. You will have stories written about you. You may well get interviewed or even called as a witness.
So Mudge here has a financial incentive and may want to raise his public profile. This is selective release of information to serve both of those ends. Again, it could still all be true. But always consider the source and what they ahve to gain.
This is just basic media literacy, really.
So me pointing out how Mudge might (and I really do mean "might"; I'm not saying he is biased) be biased should prompt you to see if there any flaws in his claims. If someone is disagreeing with his assertions, look at what they're saying, what their motivations are and if there are any obvious flaws.
I find this a good rule to live by: if someone says someone that agrees with your preconceived notions, whatever those might be, be doubly skeptical.
Is this really a surprise after several high profile cases where Twitter leadership proved to be lacklustre every conceivable way?
Who are these people writing articles like this? Not enable [automatic?] software updates is equivalent to dire problems?
Enabling auto-updates (or, better, controlled pushes of updates via your IT folks) is absolute bare-bones minimum-you-can-do security.
Otherwise, those laptops are all collections of well-known security holes.
A company who isn't doing anything against huge bot/spam problem that can be easily avoided to a great extent as there are obvious patterns in bot/spam behavior isn't a company with good intentions IMHO.
That right there is a forking nuclear showstopper . . . and nevermind the moire broad
>>employees could install “whatever software they want”
Effectively, twitter has zero security. For journalists, or anyone working in an environment that has kinetic consequences (opposition to authoritarian regimes, etc.), it is right up there in the frightening scale...
Its always funny to me to see people pointing at companies for not installing updates, and yet there's always so many people complaining about how Windows is forcing them to update their computers all the time.
Update your darn machines, people!
Furthermore, many Twitter accounts are pseudonymous or anonymous and disclosure of the true identity of the account owner could be scandalous or even physically hazardous.
And, assuming the identity of a famous person on Twitter would also be a powerful tool.
Many B2C / consumer-oriented companies have this "who cares" attitude and it is very toxic to the industry as a whole when it comes to security.
While not sensitive in the traditional sense (ie not credit card info or SSNs) it can still be sensitive for the purposes of the specific users, like business dealings or personal conversations.
So yeah, no shit it's dysfunctional, and insecure, and bad in a million different ways. The fear with facebook is that these incredibly smart, motivated, amoral monsters are going to figure out how to drip dopamine into our brains to manipulate us into destroying western democrcacy so they can advertise more sneakers. The fear with Twitter is that someone trips over the wrong cable and the entire site goes down and never comes back.
I'm not sure 'fear' is the right word there.
This article is like someone telling us that a burning trainwreck is actually not very good thing.
And those people should've been ignored. I feel like I'm the only person who actually used twitter back then and still remembers its original purpose. The restrictive character limit and lack of editing were deliberate features.
The reason they're adding an edit button now is the same reason they relaxed other deliberate restrictions before: money.
It won't though, I think we all know that. The only way it can work is if editing is restricted to within a few minutes of the tweet being posted.
I can already imagine the drama and awkward situations that will inevitably arise from things like editing tweets in response to replies.
EDIT: Misspelled blatant
To have one stagnant social media company which offers you basically the same experience for 10 years has to be a defining feature. Everything else seems to change beyond recognition trying to clone whatever the new fad is.
Twitter has had stability and given users basically the experience they wanted. In any sane world the fact they can't grow a further 10x or morph into the next media juggernaut wouldn't matter if they have hundreds of millions of users who like their platform.
They just need to send someone over to the maintenance shed and reset a few tripped breakers... what could go wrong?
It's not exclusive, though; you can switch to an authenticator like Authy or even a hardware device like Yubikey.
Transcript: https://nsarchive.gwu.edu/sites/default/files/documents/5680...
Fred Thompson (R, TN), Chairman, Committee on Governmental Affairs: …If you gentlemen would come forward… We’re joined today by the seven members of the L0pht, Hacker think Tank in Cambridge Massachusetts. Due to the sensitivity of the work done at the L0pht, they’ll be using their hacker names of Mudge, Weld, Brian Oblivion, Kingpin, Space Rogue, Tan, and Stefan.
…
Sen. Thompson: I am informed that, you think that within 30 minutes the seven of you could make the internet unusable for the entire nation, is that correct?
Mudge: That’s correct. Actually one of us with just a few packets.
Announcing you have the fastest route to other nodes, and then not routing the traffic you receive.
I guess the real question is: Can twitter be saved?
If you're really interested in this stuff, it has been an ongoing centerpiece in Matt Levine's newsletter. Articles are free if you subscribe to the email, but reading prior pieces may require a subscription. e.g. https://news.bloomberglaw.com/securities-law/matt-levines-mo...
As to what he wants, Musk is mercurial enough that I'm not sure that's a meaningful question. Did he want Twitter for a little while? Yes. Did that ever make sense given his other responsibilities? No. Did it make sense to investors? Based on Tesla's stock price slide, definitely not. Is he having buyer's remorse? Clearly. If he got a really good deal on it, might he swing back? Who knows. Is Twitter so badly run that they might do better in somebody else's hands? Yes. Is that person Musk? I doubt it.
So if I were betting on Musk being smart, I'd be that Twitter will charge him a few billion dollars to get out of the deal, which would be better for everybody than Musk taking a $14 billion loss the instant the deal closes (which is is $44 billion bid minus the $30 billion that is Twitter's current market cap). But Musk could well be more prideful than smart, so I'm excited to see how all this turns out.