3 ms·
Google has made it a requirement to use hardware keys internally since early 2017 and has noted there have been zero successful phishing attempts since. Twitter
by flarex 6y ago
Google has made it a requirement to use hardware keys internally since early 2017 and has noted there have been zero successful phishing attempts since. Twitter would have done the same if they had competent security staff.
- dlivingston 6y ago> competent security staff Between this breach, the hacking of Jack Dorsey, the “rogue employee” account deactivation of Donald Trump, and I’m sure more that I’m not aware of, would any reasonable IT/security person claim that Twitter takes security seriously? I believe I’m quite right in saying that Twitter as a platform has been one of the most damaging things to happen to our democracy in recent history. Its toxic effects on discourse and polarization are well documented. With that, and the revelation that they couldn’t take security less seriously if they tried, I would implore all reading to delete their Twitter accounts.
- bostik 6y agoTwitter may not have the corporate ability to care about things beyond the horizon. IIRC the first time they posted a profit was less than two years back. Google embarked on their BeyondCorp/zero-trust initiative after the 2009 Chinese APT breach. The teams working on their internal security had firepower and support from the very top of the organisation - and it took them seven years to get from "we want to make entire classes of attacks impossible" to "we can now enforce it". The disappointing truth in tech is that - apart from a few exceptions - security gets only superficial attention, because doing it right is a long-term investment. You need to be reliably profitable for that.