11 ms·
A Saudi prince's attempt to silence critics on Twitter
- jimbob45 6y agoI don’t like this article because it omits some crucial details that could lead readers down a specific path of thinking. It’s unclear if the inside men, Alzabarah or Abouammo, are living on H-1Bs, full American citizens, or are in the process of immigrating. Depending on the answer to that question, Twitter may need to block the employment of immigrants or citizens to stop this sort of industrial sabotage in the future. Otherwise, every country will try to have their own inside man and Twitter will be forced to overdedicate resources to countering them. If they’d made his citizenship status clear, the solution would be far clearer to readers.
- komali2 6y ago> Depending on the answer to that question, Twitter may need to block the employment of immigrants or citizens to stop this sort of industrial sabotage in the future. Seems to be a bad test. American citizens left to join ISIS, American citizens have formed cults, American citizens have mailed bombs to people. If a Saudi Arabian prince plopped a Hublot into some random kid's hands and said "give me an email," do you think their patriotism would prevent it? I don't think so, actually, didn't the recent crypto scam involve 2 Americans? What you're suggesting sounds like some kind of throwing out the baby with the bathwater, but even more nonsensical. I think a better conclusion is that companies should architect with the assumption that there's a mole, not engage in some kind of border-control nationalist purge.
- 8note 6y agoThat's only a bad test if American citizens should be trusted as hires? I think what he was saying is that twitter should avoid Americans and hire h1bs That way the American government has done some trustworthy checks for you
- _jal 6y agoIn what way is passport color a reliable predictor of trustworthiness?
- jimbob45 6y agoIndividuals are more likely to want to commit espionage for another state if they were born in or are a citizen of that state.
- _jal 6y agoIndividuals are more likely to want to commit espionage when they have money troubles. Why not hire only the already-wealthy? Individuals are more likely to want to commit espionage when they are tempted with sex. Why not demand evidence of membership in closed religious communities to address that?
- awinder 6y agoOn the former, that's absolutely a thing with all sorts of levels to it. Base level is that most companies run background checks including a credit pull. Next level is use of elite academic credentialing, i.e., "we only like to hire from ___". On the latter, because lol that is not going to have the effect you're looking for.
- _jal 6y agoOn the former, I'm quite aware of that. What I'm not aware of is this sort of loyalty screening for low-level employees, as suggested. On the latter, you're getting closer to the point I'm making.
- alricb 6y ago> Next level is use of elite academic credentialing, i.e., "we only like to hire from ___". And that's how you get numbered groups like the Cambridge Five
- deleted 6y ago[deleted]
- elygre 6y agoThis does not feel very important to me. Twitter will need to focus on their process, not their people.
- wefarrell 6y agoIt says in the article that Abouammo is an Egyptian American, so born in the US.
- mcphage 6y ago> If they’d made his citizenship status clear, the solution would be far clearer to readers. This is a complicated problem. I don't think encouraging readers to imagine that there is a simple solution does anybody any favors.
- Kednicma 6y ago> A millenial himself, [MBS] spent his youth eating fast food, playing Age of Empires and first-person shooter games, and keeping up with friends on the internet, according to people who’ve known him since childhood. It's worth remembering that dictators are not inhuman, and they are not so different from us. > Asaker would pay more than $300,000 to Abouammo, deposited in a Lebanese bank account that Abouammo had a relative open for him. “Proactive and reactively we will delete evil, my brother,” Abouammo texted Asaker just before one deposit of $9,911. They structured [0] the bribes to avoid SARs; structuring really does happen. > A third, a Saudi, was “a professional” who used encryption to conceal his identity, though once he signed in without encryption, and Alzabarah was able to track his IP address. > [Alzabarah] spoke with Asaker on an open phone line and communicated via email. > So rather than follow the FBI’s request to keep things quiet to assist the case, Twitter lawyers brought Alzabarah in the following afternoon, accused him of improperly accessing user accounts, and told him he was temporarily suspended. Operational security is hard. Just one slip-up can doom the entire scheme, and here we see those slip-ups from everybody; from the folks being targeted by MBS, from MBS's goons, and from Twitter. [0] https://en.wikipedia.org/wiki/Structuring https://en.wikipedia.org/wiki/Structuring
- erostrate 6y ago> It's worth remembering that dictators are not inhuman, and they are not so different from us. It's also worth remembering we're talking about someone who assassinates his critics and cuts them up into pieces. I would say the "bone saw" aspect outweighs the "playing AoE" aspect and he is very different from us.
- scandox 6y agoThe point is that in his situation we don't know how many apparently "normal" people will start sending bone-saws out into the world.
- jl6 6y ago100% this. It’s also important not to dehumanise history’s bad guys, because that leads to a culture of complacency whereby people think “it could never happen here, because they were monsters and we are not”.
- mabbo 6y agoThis highlights more than ever that whatever customer data your employees have access to, you need to log every single access to it, and have automatic audits- who should be accessing what? What accesses are surprising? Seems like something one could build a SaaS business around- send them reports that <user> accessed <fields> about <customer ID> on <date>, along with a copy of attributes and roles about each user. Service could offer deep dives, querying, reporting, along with ML or rule-based flagging to say "That seems odd". If Twitter can't build the infrastructure needed to do that, I can't imagine how few small companies can do it themselves either.
- dathinab 6y agoIt already exists it part of the process mining+ monitoring box. This kind of system are already used to both optimize business processes and conformance check then by organizations like banks and hospitals. Through tools are currently focused mainly on the use case for process optimization and regulation conformance checking less so for irregularity detection but tools like that exists to. I think to remember SAP has some form of self learning/calibrating irregularity detection "service"/tool. So it's less about creating it then about spending Mony on it and from scratch up analysing your internal thread model. It's quite expensive, some of this software is sold for higher 5 digit numbers even for "small" use-cases.
- mabbo 6y ago> It's quite expensive, some of this software is sold for higher 5 digit numbers even for "small" use-cases. "Your margin is my opportunity" - Jeff Bezos A simple version of this could be done cheaply, and not cost much. API to push events, website to host reports, pay-for-use add-ons for alerts, etc.
- tmpz22 6y agoYou're misidentifying the real problem which is not in the software itself. The real problem is that data needs to be accessed by marketing, analytics, sales, executive, HR, and other parts of the company all the time. It's a human problem managing the impedance of data access blocks... and guess what at most companies the block is seen as a significant cost far greater then the "cost" of PII violations, leaks, or hacks... But go ahead and find a random group of 3 ex-googlers with no domain experience to raise ~$2MM and chase it anyways. Then when you burn through the money you can go back to your FANNG job with a nice raise.
- sneak 6y agoMeanwhile, if you create a new Twitter account today from a VPN and follow 30 people, it will lock you out until you verify a non-VoIP phone number. Removing the number instantly re-locks the account. It’s really immoral that they demand identity-linked PII while running such a loose ship, where anyone with enough money can buy their way in to obtain that PII, track you down, and maybe cut you up with a bone saw. Twitter is complicit in this abuse, considering their explicit technical steps taken to ensure that you cannot use Twitter without exposing yourself to these sorts of criminals in the governments of foreign countries, as well as similar ones in the government of Twitter’s own jurisdiction. > And while Alzabarah’s job entailed maintaining systems to keep Twitter working properly, his position at the company did allow him access to the private information of many users, including their phone numbers, email addresses, and IP addresses. That meant that in some instances, Alzabarah could not only help unmask an anonymous regime critic, but also pinpoint the person’s location.
- save_ferris 6y ago> where anyone with enough money can buy their way in to obtain that PII, track you down, and maybe cut you up with a bone saw. TBF, I think that the vast majority of companies out there are vulnerable to this. I’ve worked for 8 tech companies in my career, none of which did anything beyond a basic background check. Truly mitigating the problem you’re touching on requires a level of vetting and surveillance that you’d typically see applied to intelligence operatives. I think this is similar to how we view infosec generally: those with sufficient resources will be able to penetrate a network, regardless of the design or execution of network security.
- johnyzee 6y agoThis is letting Twitter off the hook. It is not impossible to protect users personal information, even within a company, to a very limited set of people who actually need it, with audits on when and how they are accessing it, and periodic reviews of everyone's access levels. Mature organizations follow specific standards for this kind of stuff. For a company like Twitter, where the privacy of this information literally can mean life or death, it is unforgiveable to not have a better grip on it (cue some non-technical regional bizdev guy having deep access, as per the article).
- mastazi 6y agoIn 2019 there was a massive exodus of Saudi dissidents from Twitter to Parler. I wonder if those people had some intuition of what was going on behind the scenes at Twitter https://www.thedailybeast.com/about-200000-saudi-arabian-users-suddenly-flood-parler-a-pro-trump-twitter-alternative https://www.thedailybeast.com/about-200000-saudi-arabian-use...
- koheripbal 6y agoI'm surprised it took that long when news of Saudi $300MM investment in Twitter came out in 2015. If someone gives you $300MM, you don't say No to them. Indeed, you've likely already said yes.
- smabie 6y agoWhy not? What leverage do the Saudis have against twitter besides not giving them more money?
- cscurmudgeon 6y agoThe big news here is that this could still be happening at Twitter (or other places).
- liability 6y agoWhy hasn't Twitter banned Mohammed bin Salman from their website yet? Surely he has violated their terms of use many times at this point. Do Twitter's rules not apply to him because he's insanely rich?
- mixologic 6y agoDo rules apply to anybody who is insanely rich anymore?
- duncan_bayne 6y agoAnymore? https://en.wikipedia.org/wiki/Chappaquiddick_incident https://en.wikipedia.org/wiki/Chappaquiddick_incident https://en.wikipedia.org/wiki/Henry_VIII https://en.wikipedia.org/wiki/Henry_VIII https://en.wikipedia.org/wiki/Pope_John_XII https://en.wikipedia.org/wiki/Pope_John_XII Wealth and power have insulated those who possess them from the consequences of their actions since forever.
- srazzaque 6y agoYep, I once heard a quote: "rules and laws are like spiderwebs. They are sure to catch insects that cause trouble, but larger animals will just pass on through."
- 082349872349872 6y agohttp://www.perseus.tufts.edu/hopper/text?doc=Perseus:text:2008.01.0063:chapter=5&highlight=laws http://www.perseus.tufts.edu/hopper/text?doc=Perseus:text:20...
- koheripbal 6y agoSaudi Arabia is a major Twitter shareholder.
- shawnz 6y ago
- hellofunk 6y agoVery thrilling read, and the last paragraph sent chills up through my back.
- yboris 6y agoLast paragraph copy/paste: "In May 2017, President Donald Trump made his first overseas visit, a trip to Riyadh. Not long after his arrival, the president toured King Salman’s new anti-terrorism center, which focused on tracking extremists on Twitter. Afterward, the president, his wife, the king, and Abdel-Fattah el-Sisi of Egypt gathered around an illuminated orb at the center of the room and posed for a photo. Standing just outside the frame was the kingdom’s new social media specialist, Ali Alzabarah."
- hellofunk 6y agoSigh. I wondered if someone would come in here and do that. The entire reason I did not paste it myself is because this paragraph has a much different effect on the reader after they have read the rest of the article and understand the backstory. Edit: Thanks for all the upvotes. I'm glad some in the HN crowd appreciate quality over shortcuts and spoilers. (I was starting to get discouraged!)
- ticmasta 6y agoif he played age of empires as religiously as I did, he should have realized nothing beats the long bows of the Britons...
- marlo88 6y agogoth's huskarl unit? They eat arrows.
- upofadown 6y agoThe larger the organization, the more likely that it will leak information...
- nlh 6y agoGreat story and a great read! I googled the characters afterwards, and there are some interesting addendums & updates: Looks like Ahmad Abouammo (Twitter’s former head of Middle East partnerships) was arrested in Seattle in Nov 2019, but Ali Alzabarah's escape to Saudi Arabia was successful (at least in terms of being arrested by the US government): https://www.justice.gov/opa/pr/two-former-twitter-employees-and-saudi-national-charged-acting-illegal-agents-saudi-arabia https://www.justice.gov/opa/pr/two-former-twitter-employees-... BUT, as of a month ago, a filing was made to drop the charges (?!): https://www.theverge.com/2020/7/28/21345794/twitter-employees-saudi-arabia-spies-charges-dropped-case-dismissed https://www.theverge.com/2020/7/28/21345794/twitter-employee... Fascinating case...
- siwatanejo 6y ago> BUT, as of a month ago, a filing was made to drop the charges (?!): And I guess the reason for this might be very related with the last paragraph of the Wired's article...
- milofeynman 6y agoThe Wooing of Jared Kushner: How the Saudis Got a Friend in the White House https://www.nytimes.com/2018/12/08/world/middleeast/saudi-mbs-jared-kushner.html https://www.nytimes.com/2018/12/08/world/middleeast/saudi-mb...
- indigodaddy 6y agoHaven’t the Saudis had a “friend” in the White House for decades?
- blaser-waffle 6y agoaka multiple Bush presidents
- aphroz 6y agoIt seems to be something quite common at Twitter to give information from its users, I have seen interviews where people openly admit that you can find the identity of an account holder if you have friends working there. After the last "hack" it looks like once you are inside their system, there are not many safeguards or auditing.
- jacquesm 6y agoIt would be good if this were an exception but it isn't. The easiest way to gain access to lots of privileged information is to work as support worker for a bank or insurance company.
- DevKoala 6y agoI don't understand why Twitter didn't want to comply with the immediate request from the FBI. Straight up evil.
- wyxuan 6y agofeds sometimes come with less straightforward cases, so I wouldn't say evil, more incompetent
- deleted 6y ago[deleted]
- rmrfstar 6y agoRemember when Saudi Arabia tried to convince Moxie to help them intercept people's Twitter traffic? [1] [1] https://moxie.org/2013/05/13/saudi-surveillance.html https://moxie.org/2013/05/13/saudi-surveillance.html