4 ms·
At a public company like Twitter, for SOX compliance reasons, it will be very difficult to find someone that has such permissions, and running anything unusual
by yzmtf2008 7y ago
At a public company like Twitter, for SOX compliance reasons, it will be very difficult to find someone that has such permissions, and running anything unusual can be easily found by auditing. I'd stop with the conspiracy theories.
- lwf 7y agohttps://www.washingtonpost.com/national-security/former-twitter-employees-charged-with-spying-for-saudi-arabia-by-digging-into-the-accounts-of-kingdom-critics/2019/11/06/2e9593da-00a0-11ea-8bab-0fc209e065a8_story.html https://www.washingtonpost.com/national-security/former-twit... In general, most companies want to scope SOX as narrowly as possible. So if you can, only things that your auditors think will affect revenue reporting. Querying ads performance data? Sure, we'll SOXify it. Querying user accounts writ large? "Meh, our engineers need to be productive."
- t34543 7y agoThere are always weaknesses and internal vulnerabilities in every system. If it was from the inside more likely a privileged user was compromised. It could also explain why Twitter is being quiet, especially if the investigation is ongoing.
- nl 7y agoSOX doesn't really stop this kind of prying, and it has happened in the past. https://www.npr.org/2019/11/07/777352750/how-saudi-arabia-used-twitter-to-spy-on-dissidents https://www.npr.org/2019/11/07/777352750/how-saudi-arabia-us...
- RijilV 7y agoSOX is about financial compliance. It is not a computer security standard. I’ve worked for lots of SOX companies as a third party and had root/sqlplus on most of them. There’s really to relationship between SOX and security.