Mudge is a cyber activist, not a business executive
cybersect.substack.com
cybersect.substack.com
For example, half the company had prod access to user accounts. And there was no way to find out who accessed what. This is not normal, it's a huge red flag.
The article claims that it should be perfectly expected that an executive should order someone to lie to the board about the risk the company is exposed to. Apparently this is Mudge's fault for not pushing back hard enough.
And then there's the rant against the "cyber security crusader", for whom nothing but perfect security is enough. Sounds like a perfectly annoying character, along with the architecture astronauts I guess. I've never met any of these stereotypes in the real world, although people do disagree on what is enough.
So it's either trolling us, or just not very good. Or both.
> half the company had prod access to user accounts
That's pretty normal depending on the size of the company.
The chances of that being true is pretty high if it's a smallish upstart with <50 employees.
> I've never met any of these stereotypes in the real world, although people do disagree on what is enough.
I've encountered several - they were all in the same company. It got so bad that multiple people quit and others were going to, until the people in question where "promoted" to a position where they weren't in the decision loop anymore.
Very small companies and start ups I'd agree often don't have this kind of separation. But if they grow into one of the worlds biggest brands, I would not expect it to be run like a 50 man startup.
It's also easy to loose track of your own bias. There is a strong selection bias in employment which makes it look as if all workplaces are similar, simply because a company is more likely to hire you if you've worked in a similarly run one before.
> For example, half the company had prod access to user accounts. And there was no way to find out who accessed what. This is not normal, it's a huge red flag.
If that statement was qualified to only include fortune 500 companies I would've agreed with it being a red flag
The exceptionally bad ones have no authentication on databases readable to dog-and-world. That's the state of our industry where security is at best an afterthought. By that measure, Twitter is basically average. They give it some lip service and do as little as they can get away with.
Perhaps, as you yourself said, "you're just not as experienced as you seem to think you are".
I have worked in startups and with large enterprises. There is not a _single_ place where any significant percentage had access to prod accounts. That would be a HUGE nono. I have no doubt it happens, but that's not normal.
One can argue that it shouldn't be normal, but I assure you that it is extremely normal in most companies. Shared root credentials, no audit logs, or audit logs that you have to grep on individual hosts - these are VERY VERY normal across business.
Which I guess is why it surprises me that Twitter still operates like that.
It wouldn't be probably an exaggeration to say that ability to post a tweet in someone's name, or ability to see private DMs can have financial effects (scams, frauds of big proportions), or in extreme, yet not unthinkable, circumstances lead to loss of health or life (war, terrorism).
They dismiss Mudge's comments on lack of disk encryption by saying that anything less than end-to-end encryption is pointless anyways. Again, I don't even really know where to begin. Those features address completely different risks. Not every service can reasonably implement end-to-end encryption while still providing the functionality and support their users want. That doesn't mean they should just ignore encryption altogether. There are other threats out there that are mitigated by encryption at rest. And I think the core of Mudge's complaint here is that too many people have access to private DMs. There are all kinds of security controls to mitigate that threat that it sounds like Twitter isn't using.
> Cybersecurity has the wrong belief that “security” is their highest ethical duty, to the point where they thing it’s good to lie to people for their own good, as long as doing so achieves better security.
Wait, what? I've worked in the industry as long as Mudge has and I've never come to this conclusion. There are many, many security engineers, managers, and execs out there that work hard to earn a great reputation in their field by measuring security against business needs and finding a welcome compromise.
I say this as someone who pointed out when this story first broke that Mudge's background really didn't appear to be well suited to managing security at a huge tech company. I also share the concerns about how equipped he was to deal with executives and board members. But yikes.
I mean.. they created a "God mode" for their service. It pretty much tells you where their entire approach to security of user data sits.
Disk encryption protects against disposal or theft of physical storage. Companies like Twitter will be replacing disks all the time.
The argument that nothing less than an end-to-end encrypted system is worth doing is also flawed. No, don't lock the windows and keep leaving the key under the mat, since we don't live in a castle.
He attacks cyber activists for blocking business because security is not perfect. It seems he would rather have no security if it isn't perfect.
I should add that our customer data was encrypted at-rest but we shredded the disks to remove any doubt that on-demand debug logging potentially leaked sensitive data. New managers and directors thought this was a waste of money but as the sales people could attest to, this process paid for itself many times over.
Really? It came out Twitter doesn't have a dev/staging environment. Source: https://twitter.com/lauren_feiner/status/1569695337190944775 in the same thread, "Twitter can't assure regulators that it's able to delete all data at a user's request because it's unsure where all that data lives"
Earlier we have learned
> “Even a temporary but overlapping outage of a small number of datacenters would likely result in the service [Twitter] going offline for weeks, months, or permanently,” according to Zatko’s whistleblower disclosure. (Twitter has criticized Zatko and broadly defended itself against the allegations, saying the disclosure paints a “false narrative” of the company.)
Quoted in https://www.cnn.com/2022/09/12/tech/twitter-data-center-cali... just yesterday.
All in all, there's a picture here which says Twitter simply doesn't have a handle on its own infra any more, it can't replicate it for dev/staging purposes, it doesn't fully know where the data goes and if it crashed they couldn't rebuild it. You call that ahead of the norm?
https://www.vice.com/en/article/akvmke/facebook-doesnt-know-...
I wonder if ordinary citizens can make that same claim when it comes to their stuff - "No, officer, I don't even know whether there are any drugs in my possession because I don't even know what is in my house and where"
And? Dev/staging is fine for enterprises that don't have to operate at Internet scale, think having a build script means they have CI/CD, and are doing waterfall development even if they call it agile. For truly Internet-scale services the cost/benefit of trying to build a staging environment that would have any usefulness doesn't pencil out. Canary deploys with well thought-out rollback plans works fine.
Like monorepos, this approach to ops might seem strange if you've only worked at small companies, and even then it's something reasonable people can disagree about. But I'm not convinced it's a useful discussion to have with an 88 year old senator. And it's not a sign that a company doesn't take engineering or security seriously, or that it has no idea what it's doing.
Re: resiliency, one of Twitter's datacenters is offline right now and twitter.com is up (https://www.cnn.com/2022/09/12/tech/twitter-data-center-cali.... So clearly the "small number" mudge is referring to is greater than one. Beyond that, yes, I'm absolutely sure that the loss of a "small number" of datacenters could take twitter offline and even result in permanant data loss (the data is in datacenters too!), because that statement is true of literally all tech companies. Twitter's expected uptime is a bunch of 9s. It's not 100.0%. The fact that it's not 100% is not evidence it "simply doesn't have a handle on its own infra any more".
And FWIW, resiliency appears to be pretty high for Twitter relative to the rest of the industry. They were down for 40 minutes early this summer, and haven't had an outage > 1 hour for 6 years (https://www.theguardian.com/technology/2022/jul/14/twitter-e...). Facebook (which I think most of us think of as pretty good at engineering, relative to the clown show most people seem to think Twitter is) was offline for 5.5 hours last year (https://en.wikipedia.org/wiki/2021_Facebook_outage).
I doubt the claim that it's a PR piece, but I don't doubt the idea that Robert wrote this to troll. It fits pretty closely, so it's probably best to look at it from a practical angle and not get worked up about it. No one even knows if Robert believes half of what he himself writes.
--
stated differently: he's the Armond White of InfoSec Twitter.
--
tl;dr: he's probably trolling.
Based on what? According to the writer, mudge's long experience of growing up before everyone became money obsessed apparently.
Flip it the other way round the writer demands all execs to be short term profit driven cucks or not worthy of a seat.
Can't tell if the writer is just an idiot or a gigabrain mudge supporter.
Very well said
> But there’s no objective evidence of this, only the subjective opinion of Mudge that Twitter wasn’t doing enough for cybersecurity.
...
> specifically that they lied to investors and failed to live up to a 2014 FTC agreement to secure “private” data.
So is it subjective, or objective? Is the 2014 FTC agreement subjective?
And then he just starts pissing into the wind. "He said servers were out of date, but Ret Hat 7 is 8 years old but it's still receiving security patches but I'll just hand wave that away."
> Part of his complaint is that the now-CEO Parag Agrawal pressured him into lying to the board, to claim to the risk committee of the board that security is better than it really was.
...this is against the law.
"Of course Agrawal did. He’s supposed to do that."
This whole article is just rife with logical fallacies, incongruencies, and silliness.
> In contrast, Mudge’s complaint is full of the assertions that he’s objectively right, and Agrawal objectively wrong. And since it’s objective that he was wrong, Agrawal must’ve been lying.
The argument is that Agrawal intentionally misled shareholders. That's objectively wrong.
And, finally:
> What I read here in Mudge’s complaint aren’t the words of an executive, but the words of an activist.
The complaint was written as a whistleblower not as a CISO.
Might be, I don't know. So I ask.
At this stage it would be best to just wait until things are settled before drawing conclusions.