20 ms·
How Saudi Arabia Infiltrated Twitter
- mc32 7y agoI don’t know why they started the blue checkmark. It’s not to verify identity. It’s more like imprimatur (anointed by Twitter as whatever). And that is stupid because it’s basically up to the whims of the company and becomes open to abuse internally and externally.
- uk_programmer 7y agoIIRC it was originally to verify celebs real accounts. Then they said anyone with more than a certain number of followers and now it seems to be just a status symbol.
- goatinaboat 7y agoIt originally was to verify identity. Then they started withdrawing it from controversial figures, as if those people stopped being who they really were overnight. Nowadays it just means “this persons views are endorsed by Twitter staff”.
- chrisseaton 7y ago> Nowadays it just means “this persons views are representative of Twitter staff”. For example both Sanders and Trump have a blue tick. They obviously can’t simultaneously be representative of a majority of Twitter’s staff’s views, can they? And I’d estimate Trump isn’t representative of a substantial number of these west-coast tech workers at all. So that doesn’t seem to hold up.
- mc32 7y agoTrump is a special case in that Twitter said that they would treat heads of state (both foreign and domestic) differently. They might have something internal for accounts with large followings (Kardashians). Assange is an interesting case in that despite renown and following they refuse to give him a check mark and suspended the WL account as well.
- chrisseaton 7y agoOk, excluding heads of state, and even other politicians, are for example the views of Jordan Peterson representative of Twitter employees? Seems unlikely.
- deleted 7y ago[deleted]
- goatinaboat 7y agoI expect his is a holdover from before and it will be revoked as soon as they notice. PS I tweaked my comment after you started to write your reply but before I saw it; the wording is better now but the meaning is basically the same. Sorry!
- danbolt 7y agoI haven't researched it, but I'd assume that Donald Trump had a blue checkmark back when he was widely known as a media personality and landlord.
- SpicyLemonZest 7y agoThat's surely not true. Lots of people have blue checks even though Twitter staff would never endorse their views - Ben Shapiro, Steven Crowder, Candace Owens, and so on.
- wpietri 7y agoYou're correct that it's generally not true. But the grain of truth is that they did punish some notable jerks by removal of verified status: https://money.cnn.com/2017/11/15/technology/twitter-verification-remove-new-policy/index.html https://money.cnn.com/2017/11/15/technology/twitter-verifica... IMHO these were pretty clear anti-abuse actions. But of course those people claim that they were being punished for their views.
- mc32 7y agoI think the claim is a little more nuanced. Basically yes those people went over a line and got punished but at least some claim that others also go over that line but don’t get punished (as often). I don’t know how true that rings.
- chrisseaton 7y ago> It’s not to verify identity. I think that is precisely the purpose. If you’re looking for Donald Trump’s Twitter profile the idea is the blue tick helps you find the right one rather than a parody.
- i_am_nomad 7y agoExcept the blue check can be and has been revoked for reasons that have nothing to do with identity.
- wpietri 7y agoThe original purpose was definitely to verify identity. Since parody accounts are allowed, it's valuable to be able to tell the real X from a parody X. This was especially true early on in Twitter's history. It was also useful in encouraging famous people to get on Twitter. "Look, if you start you own account, we'll clearly distinguish it for you. No more fakes!" And having famous people on Twitter was hugely valuable to encouraging growth. Unfortunately, there's a strong correlation between "useful to verify" and "important", so pretty quickly it became a status symbol, especially for marginally notable people. And some people really like status! It's very similar to the problem Wikipedia has, where they daily have to delete a lot of BS biographies from the would-be famous. This means that the program has been a headache for Twitter for a long time. I know when I worked there in 2017 they announced that they were suspending the program pending a major revamp of how it works. As far as I know nothing came of that; I think they quietly started giving out blue checkmarks again a while back. Personally, what I'd like to happen is that they make it much broader and roll it up in a "Premium Twitter" feature. I pay them $50/year, they verify that I'm who I say I am, get rid of ads, and throw in a few other features. But I doubt that will happen, as IMHO Twitter is incredibly bad at getting anything done.
- mc32 7y agoI agree with your take and suggestions. They probably feel it would dilute the value. As you suggest, they could add “Premium” or “Pro” labels to distinguish people who pay for status. Maybe charge them by audience or reach as well.
- raxxorrax 7y agoI guess it was originally intended to get people to reveal their real identities. Especially for celebrities that often had fake accounts with their name. There are some groups that take it as a warning sign for craziness. Funnily, it often seems they are onto something.
- grandridge 7y agoThey bought a huge chunk?
- Synaesthesia 7y agoMore like, there were Saudi spies within twitter, the company, telling the govt about dissidents.
- Shivetya 7y agoso my question is simple, did twitter engage the FBI or an auditing company to verify the rest of the staff who have access to sensitive data? It would seem to be a concern they would have to follow up on. You can put in all the procedures you want and declare compliance to auditors but it only serves to make paper pushers happy.
- pferde 7y agoI wonder - would such audit be in their interest? Perhaps it's easier for Twitter if foreign dissidents know that Twitter is not safe to use for them, and go elsewhere. Twitter then does not have a risk of politically charged situations, and can peacefully exist by serving the usual harmless inane chatter of general population.
- Natsu 7y agoWhy is this downvoted? It's true: https://qz.com/519388/this-saudi-prince-now-owns-more-of-twitter-than-jack-dorsey-does/ https://qz.com/519388/this-saudi-prince-now-owns-more-of-twi... "Prince Alwaleed Bin Talal Bin Abdulaziz Alsaud, who in 2011 invested $300 million in the social network, now owns 34.9 million shares of Twitter’s common stock, according to a new regulatory filing (pdf)." That is from 2015, but as far as I know he still owns a huge stake in the company. It would seem relevant when discussing SA's influence on Twitter, but I don't see it mentioned in the article for some reason.
- duxup 7y ago
- saber6 7y agoYet another reason why Twitter should be banished to the depths of hell - what a stupid shit-show of a company. I eagerly anticipate their downfall. Just like I did MySpace. And hopefully someday, Facebook. Fuck these parasites.
- tasogare 7y agoIt was never really useful anyway as the noise is exponentially more present than few useful tweets.
- dang 7y agoOK, but please don't post unsubstantive comments to Hacker News. Maybe you don't owe shit-shows of companies better, but you owe this community better if you're commenting here. https://news.ycombinator.com/newsguidelines.html https://news.ycombinator.com/newsguidelines.html
- saber6 7y agoFuck off, faggot.
- baybal2 7y agoI'd also remind that Twitter is surprisingly leaky for Chinese using it, even for people who can get foreign simcards to register an account. API leak is one hypothesis, another one is that they got a mole there too. The same goes to Facebook. A number of FB users got detained in China with no better explanation than MSS getting access to FB's internal information like phone ID and IMSI data in user database. The most probable explanation people have crafted is following: 1. Using internal or external tips, MSS gets user account info of a person of interest 2. Their mole accesses the user database for info on cookies, IMSI, advertising ID and such 3. MSS than cross-references the data with data on the open market, like IMSI databases sold by mobile advertising companies 4. One way ticket to Heilongjiang is issued the next day, once the identity of the person is confirmed using logs of phone companies or ISPs.
- j-c-hewitt 7y agoWhy would a serious government not walk through the open door and take what they needed while their agents collect two salaries? It's just a win-win for foreign intelligence. They would be negligent in their duties to NOT infiltrate US companies with open doors and permissive, trusting internal policies about user data. Then the company can do the liability minimization dance when the FBI comes and points out that they are running a cheap data service for foreign spies. "We, uh, had no idea..."
- meowface 7y agoAbsolutely. It's their job to do this. But what should large tech companies do? Avoid hiring people from certain countries/heritages? Obviously that's not fair and not a good look. Same for putting extra monitoring on them. This is independent of Twitter apparently trying to downplay this and cover it up, which of course is wrong. It just seems like preventing this is really tough unless you state "we won't hire anyone who's lived in, was born in, or whose parents are from China, Iran, Saudi Arabia, or Russia", which is untenable.
- mc32 7y agoInstead of targeted monitoring monitor everyone who has certain level of access regardless of origin? It's not like it's not scalable, obviously they are capable of widescale automation.
- komali2 7y agoI remember serious concerns about Australian citizens suddenly being legally required to be spies for the Australian government regardless of where in the world they're working due to a new anti encryption law sometime in 2016. That and Twitter somehow being caught with their pants down regarding user phone numbers and other personal information makes it all the more important that all the engineers and product people on this site make it very clear to management that the systems must be set up in a way that simply doesn't allow people to access that information. It's morally good and it might prevent you from making the papers as a host of a bunch of spies that got your Chinese, Saudi Arabian, or Turkish users assassinated or jailed.
- girvo 7y agoIn 2018 those laws were actually passed, and there's a tonne of uncertainty around them (which is probably on purpose). It's had a chilling effect on exporting software from Australia, too, at least for two business I've worked with since, though that seems to be warming again lately for better or worse.
- jacques_chester 7y ago> regardless of where in the world they're working I don't think this is correct. The legislation as drafted didn't seem to claim extra-territoriality and courts will basically never interpret legislation as being extra-territorial without an explicit clause. There's also the point that if you are overseas and refuse to comply with a request by ASIO or whathaveyou, they can't legally arrest you outside of Australia. In theory they'd need to ask for your extradition, but that requires equivalent laws to be in operation in the country you're extraditing from. But you'd be at risk of arrest upon returning to Australia. That doesn't stop it from being a terrible law. And it also doesn't stop me from not being a lawyer who isn't giving legal advice.
- duxup 7y agoI worked on a support team for a company that that had some major financal institutions as a customer. We had remote access to their networks at times. My very first day I was amazed how much access I had at will. One day it was announced that a customer had come to us and demanded everyone had to meet X requirements to be able to work on their networks. Not long after another financal institution made a similar request. Some folks inside the company were a bit riled up by the requirements (background checks, some other things). They felt the requirements were absurd. Considering the access we had I thought they weren't strict enough. As just a lowly support dude hired during the dot com boom because the company needed warm bodies (who could do some independent thinking / troubleshooting) ... I had a lot of access. I don't know if they were thinking about spying like this, but I'm always amazed how much access people have to data and etc just from a technical support perspective (forget developers...). Later the company outsourced support to other countries... I'm not even sure you need spies in the US / would know anyone was spying under those circumstances. Support teams are probabbly a hell of a lot cheaper / easier to infiltrate / they get little / poor management / oversight. I saw tons of strange choices by our outsourced technical support staff, every single time I raised concerns it was discarded by something to the effect of "yeah they suck". And that doesn't account for all the financial institutions who outsourced their own direct ops teams to other countries ... I'd call them and if they ever were capable of following instructions 9x out of 10 they'd open up the wrong network / modems / etc.
- carlmcqueen 7y agoThis is a very common answer to these stories on hackernews but this one is from a humble point of view that truly brings home the point. My side is that I worked for a bank on the brokerage side for ten years in different positions. What always struck me was that my access was very carefully controlled, I was a background checked employee and had to meet with compliance once a year, etc etc. However when a law firm asked for anything or consultants said they needed more data they just sent massive data dumps to the network admin guy, no questions further asked. At least not at my pay grade. As I've consulted I ask for only what I need to keep my own risk down but it is always a surprise to my clients I don't want PII I don't need and only the data that my model will help enhance.
- onetimemanytime 7y agoPeople from certain countries are different, they have different values and some loyalties to the old country. IMO, it's wayyy much easier to corrupt people from second or even third world countries, there corruption id the norm. Money is not an issue for a nation state and then they can fix things for family back home etc etc so they are bound to find people that say yes.
- loup-vaillant 7y ago> Ali Alzabarah was panicked. His heart raced as he drove home from Twitter’s San Francisco headquarters in the early evening on Dec. 2, 2015. Ok, how could you possibly know that? That's a pretty good guess, but writing it like it was the start of a novel… fells like read bait, really. Especially given the following: > Alzabarah, Abouammo, and al-Asaker did not respond to requests for comment.
- herendin2 7y agoIn the same article, the FBI quotes his private messages from his email account that same year.
- BryantD 7y agoI was wondering if it was an SRE when the original story came out. I'd be interested in seeing perspectives on how you avoid this scenario. While you could isolate data access by team in many models, you're still going to have engineers who have access to valuable data. Random access audits? But what about the scenario where your database lives on someone else's hardware? I guess you could always decide you want to use your cloud providers FedRAMP-compliant offerings.
- dgellow 7y ago> At 5:17 p.m. he called a handler, identified as Associate-1 in the FBI complaint, who arrived in a white SUV two hours later. Driving around Alzabarah’s neighborhood, the two men called “Foreign Official-l” — al-Asaker, according to the Washington Post — at 7:20 p.m., and again at 7:22 p.m. and 7:31 p.m. They then called Dr. Faisal Al Sudairi, the Saudi consul general in Los Angeles, at 8:30 p.m., 8:38 p.m., and 9:26 p.m. Shortly after midnight, the consul general called Alzabarah back and spoke with him for three minutes. Slightly off-topic: I feel that gives a good idea of how much information can be extracted from very simple metadata (here timestamp and number called) in that kind of context.
- seemslegit 7y agotldr; With money.
- BrandoElFollito 7y agoShit happens (a spy makes his way to your organization). In large companies, especially such as Twitter, there are processes to handle such cases. The process does not include firing the employer first thing in the morning. It includes calling the equivalent of the FBI for your country. The way Twitter failed to handle this case is staggering.