44 ms·
Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies
- someonehere 4y agoThe previous head of security to Zatko talked about fixing these problems. I remember distinctly after the FTC crackdown there were all hands where the discussion came up. I guess these problems were never fixed.
- mzs 4y ago>If you are wondering if the stuff about Twitter security being lapse is just one person complaining, you might be interested to know that, 18 months after being let go from the company, I've not been removed from their employees GitHub commiters[sic] group. … >I can see private repos, yes. … >A Twitter employee, Chris Banes, has claimed "that nothing internal or private is hosted on GitHub. It’s all just open source code.". Here is a picture of a private, active, repo I had access to until about 50 minutes ago. Chris's statement is incorrect. https://twitter.com/alsutton/status/1562152606096658432 https://twitter.com/alsutton/status/1562152606096658432 https://twitter.com/alsutton/status/1562116259357024257 https://twitter.com/alsutton/status/1562116259357024257
- 1970-01-01 4y agoGood job mudge! For those that don't know him, Mudge is kind of a big deal in cybersecurity: https://en.wikipedia.org/wiki/Peiter_Zatko https://en.wikipedia.org/wiki/Peiter_Zatko
- bkq 4y agoIt is rather disconcerting how a platform that is apparently rather integral to the discourse of today is in the hands of a single private company. It doesn't matter who owns it, if it's Musk or someone else, the fact that it's at the whims of a private company, is the primary channel for discourse, and is something legislatures cannot even comprehend because of their age, should have alarm bells going off. Coupled with the fact that there is lacking IT education about hardware/software means that there is an environment that is ripe for the encroachment of digital rights, as we've been seeing this past decade.
- core-utility 4y ago> the primary channel for discourse Primary for whom? If you polled 50 people on the streets of NYC, I bet fewer than 3 would say they actively use twitter. Now do the same for Des Moines, IA and you maybe get 1?
- ageitgey 4y agoI think that Twitter is very much the tail that wags the dog. Sure, 1 out of 50 normal people may use it, but nearly 1 out of 1 reporters use it. Those reporters often quote opinions on it as if they are representative of the larger public, even if the tweet they quote is by someone with 10 followers and no stars.
- paulgb 4y agoThe fun thing about social media is that reporters can back up any narrative they want. “People are upset about X”, “Gen Z is doing X”, “Millenails are killing X”. Find two people and it's a confirmed trend!
- beeboop 4y agoI saw a reddit post today that "Disney fans are furious that Avatar was temporarily pulled from Disney Store" and the top 500 comments were like "No one is furious". Here, I'll give it a go: "Environmentalists are furious that Bill Gates kills mosquitos"
- mcintyre1994 4y agoI did a quick Twitter search, and unfortunately your story isn't supported by any tweets I can find. Good news: you get to write a story about conspiracy theories about Gates and mosquitoes instead though! https://twitter.com/lorijean333/status/1561224522166067201?s=20&t=dlwIsKBSXLr8y0UOJ5sOFQ https://twitter.com/lorijean333/status/1561224522166067201?s...
- Signez 4y agoThis excerpt is frightening: > About half of the company's 500,000 servers run on outdated software that does not support basic security features such as encryption for stored data or regular security updates by vendors
- tppiotrowski 4y agoI wonder if they're running Ubuntu on 32-bit hardware
- raverbashing 4y agoor RHEL 6
- taf2 4y agoRHEL5 more likely based on when twitter was founded
- imron 4y agoI wish this was a joke. I know of systems running multibillion dollar companies that are still using rhel6.
- discodave 4y agoHahahaha... Wait until you hear about the large cloud provider running RHEL5... (I worked at said provider).
- kerng 4y agoI wish companies generally would be more transparent - I'd imagine this be the norm at most companies.
- secondcoming 4y agoWhy bother hacking Twitter when it'd be cheaper to bribe an employee to get all the information you want: > allows too many of its staff access to the platform's central controls and most sensitive information without adequate oversight It'd be even easier if you find an employee who's on the same political team as you.
- saagarjha 4y agoSeems like Twitter loves going through the cycle of getting hacked→hiring good talent and focusing on security→losing people and focus→relaxing their stance→getting hacked :(
- Hamuko 4y agoHow long before Musk weaponises this in his lawsuit against Twitter?
- boffinAudio 4y agoHow long before people start conflating this story with Musk in an attempt to discredit both, you mean?
- beeboop 4y agoThe modern equivalent of Godwin's law is mentioning either Tr*mp or El*n in any circumstance possible.
- nudpiedo 4y agoI think it is time to go a bit Meta here, bit I start to subspect that many HN posts are to influence such things, including popular replies to @pmarca etc... when one says Netflix falls because it is not a tech company, the next day at HN comes an article saying how cool and techie it is, etc. The reach of HN on the tech world is highly influential, and for sure it is weaponized in "communication wars" across actors with different interests. EDIT: that doesn't mean that the given information is necessarily false, it is just presented at the right time, to promote one view of the world. Also when Twitter hit bottom some years ago several HN submissions remind us how they declined being purchased by Facebook etc, and social network giants have a large track of understanding how such information flows and influences people.
- lapcat 4y agoOctober 17
- michaelwilson 4y agoIt may appear that this may get Musk off the hook for buying Twitter because "Look how bad they are!" but, as I recall, Musk's problem is that his offer with without contingency - e.g. "Yah, I'll buy it, whatever". So it may just be another event which will drive Twitter's price down even further and make it a _worse_ deal for him. From Bloomberg "The buyers could only back out of the agreement in the case of a material adverse effect, a high bar that excludes issues like market volatility or industry challenges." (https://www.bloomberg.com/news/newsletters/2022-07-13/elon-musk-haunted-in-twitter-deal-by-seller-friendly-concessions https://www.bloomberg.com/news/newsletters/2022-07-13/elon-m...). I suppose one could argue that the Whistleblower's report is "material adverse affect", something I'm sure will come out in the trial.
- pigtailgirl 4y ago-- I've always (since the 90s) used the rule of thumb treat everything on the internet as if it's compromised - I employ low personal security - however i also employ low trust - wouldn't go so far as to blame the users or the platforms - i'd blame both equally - user education is low - false sense of security is high - as the years have gone by - adjustments have been made on my side: comments sections are probably misinformation - emails from people I know may or may not be real - emails from people I don't know are probably not real - use pen and paper for things that need to stay relatively confidential - this is how I was taught to use the internet in the early days - still use it this way today --
- mupuff1234 4y ago
- boffinAudio 4y agoThe article states he has had no contact with Musk and that the whistleblowing started before Musk attempted his takeover of Twitter ..
- chalst 4y agoIt's tinfoil hat territory, but the connection could run the other way in principle: the ex-exec could have been shopping for someone to injure Twitter and cooked up a plot in which Twitter was an innocent victim and Musk a double-crossed coconspirator. Why, it explains Musk's confidence that Twitter was up to something with its fake-account stats... It must be true!
- deleted 4y ago[deleted]
- zimpenfish 4y agoOn the other hand, if you want to fan the conspiracy flames, he does have strong ties to Dorsey (via Stripe and Twitter) and Dorsey has always been Team Musk, especially re: the takeover.
- kmfrk 4y agoI hate being asked to hand over my phone number for 2FA or similar protections. Or facing the choice between deleting all my DMs or risking them being compromised on account no E2E support. Then again, even if you delete something, there's no knowing what their data retention handling is.
- strict9 4y agoI think it's safe to assume most anything you delete from a web app gets a deleted boolean or timestamp field set and the content persists in the database indefinitely. In my experience I've found it rare that user content is ever actually permanently deleted for various reasons.
- beeboop 4y ago> various reasons advertising, controlling executives, and government spying
- thepasswordis 4y agoOr devs who fear some runaway bug.
- DangitBobby 4y agoOr a disgruntled employee or a hack or any of the other reasons you might want deletes to be reversible.
- DaftDank 4y agoI assume that storage has gotten so cheap now that storing everything forever is feasible for companies? I always knew they had to retain content for X period of time, to comply with laws about data retention for criminal investigations, but I always assumed (from reading about it 10+ years ago) that because of how much extra storage space all the "deleted" content would take up, that it wouldn't be feasible for them to do it long-term for everything. I knew that would become a moot point eventually, and I suppose that is now.
- sn0w_crash 4y agoMudge is a very credible source. Interesting to see where this goes. Twitter has gone through more security heads than any high tech company should. Not surprised it’s a chaotic environment.
- ok123456 4y agoNo he's not. He's literally on the CIA payroll along with the rest of CDC. He has a track record of making up ridiculous stories that serve his task masters. Remember the "Hong Kong Blondes"? Oh right it turned out to be completely fake.
- deleted 4y ago[deleted]
- LatteLazy 4y agoIm starting to think social media might not be the best system to store my personal data, maintain our democracy and protect national security...
- Tainnor 4y agoIt's important not to forget that certain Twitter users share incredibly sensitive data over Twitter, increasingly including nudity and sexual acts (sometimes on private profiles or in DMs, so they're not meant to be public). While one may (not wrongly) think that this is a bad idea in general (unless you subscribe to post-privacy), I think it is our duty as a society to protect those who don't have a full grasp on the implications of bad IT security. In my opinion, fines for cyber security violations should be swift and harsh (GDPR goes in the right direction in terms of how high the fines are, but it is barely enforced). From my POV that is the only thing that will force companies to actually invest in cybersecurity. Maybe there should even be a law mandating security reviews if you handle any PII.
- boomboomsubban 4y ago>one or more current employees may be working for a foreign intelligence service. I don't doubt this, but the source is someone with fairly deep ties to the US intelligence services. Why should he be allowed a job and not people with ties to foreign agencies?
- throwaway0asd 4y agoConflict of interest violations. Such violations are absolved through disclosure of known relationships, which cannot occur if persons are keeping ties to foreign intelligence services secret.
- boomboomsubban 4y agoIs maintaining ties with US intelligence services a conflict of interest?
- hibikir 4y agoI don't believe that what Mudge is saying there is all that well quoted or explained. The argument I've heard him make, in other settings, is that companies that are interesting enough will get job applicants that are really moles for intelligence agencies. This is very difficult to stop, and once your company has enough employees, downright impossible. His recommendation however is not to make it impossible for people with ties to foreign agencies to join the company. Instead, it's to minimize the access than any individual mole might have. This would also apply if you consider US intelligence an attacker! TLDR; Someone like Twitter, Google or Facebook should have 'some of our employees are malicious and sophisticated' as part of their threat model.
- vlan0 4y agoEh, you could take out Twitter and insert many other company names and it'll still hold true. And those companies hold so much more sensitive data about you than Twitter. I know of insurance companies that have help desk employees with domain admin access. And all crippling ransomware attacks take advantage lax permissions. This is rampant. How is this a story?
- encryptluks2 4y agoAt least you get it. I've seen worse on actual government systems.
- bartread 4y ago> How is this a story? Cynically, because it's twitter, and it's trendy amongst a certain subset of the population to bash social media in general and twitter in particular. And I think your point is fair. (FWIW, I think social media has if not caused, then certainly exacerbated, some major problems at individual, societal, and global levels, but by no means do I think twitter is the biggest contributor. I don't think we'd see the kind of unconstructive political polarisation we're seeing in the US and UK and perhaps, to a lesser extent, within the EU, without it.)
- zinekeller 4y agoMy reasoned mind says it's due to the recent disclosure in Twitter due to linking of phone numbers to people, while my other mind says it's Elon finding anything to make Twitter give up their case.
- bartread 4y agoFor sure, the phone numbers issue definitely won't have helped, but the whole Elon/Twitter situation is definitely up there. Plus, as I say, it's been sort of trendy to bash them for a while: they're either not doing enough to protect people from harmful content, or they're subverting freedom of speech by, for example, banning Trump, and applying permanent, temporary, or shadowbans to other accounts. I'm not that sympathetic, but they sort of can't win.
- Simon_O_Rourke 4y agoOK, so their security is a mess, as many commenters have pointed out, they are one of many companies. What I can't figure out is what's this guy's beef that he went revealing all this? Was he fired or demoted or something and thought to get his own back?
- detaro 4y agoLook at Mudge's track record. He didn't become a security legend by staying quiet about problems, and if Twitter wasn't willing to address it internally...
- nonameking2026 4y ago"Zatko says, he believes he is doing the job he was hired to do for a platform he says is critical to democracy. "Jack Dorsey reached out and asked me to come and perform a critical task at Twitter. I signed on to do it and believe I'm still performing that mission," he said." Seems like a legit answer.
- aliqot 4y agoEveryone should watch L0phts congressional testimony.
- criddell 4y agoWhy assume the whistleblowing was done for negative reasons?
- Simon_O_Rourke 4y agoThere's the beef https://www.bloomberg.com/news/articles/2022-08-23/twitter-whistleblower-mudge-has-distinguished-cyber-career https://www.bloomberg.com/news/articles/2022-08-23/twitter-w... He was fired January last for alleged poor performance. Totally can see now why it's all come to light, less the altruistic urge to make things secure, and more the old case of flipping the bird to a former boss.
- rhexs 4y agoFrom Wikipedia: “He was the most prominent member of the high-profile hacker think tank the L0pht.” That’s quite a generous take. There were plenty of excellent hackers in the 90s, but “L0pht” just seemed like the PR friendly one that could go on good morning America. Can’t tell if this is real or just a 90s security person trying to stay relevant after being fired.
- deleted 4y ago[deleted]
- eatonphil 4y agoWhether or not it was high profile before they went on talk shows and before congress... it's definitely a high profile (historic) group now because they went on talk shows and before congress. :) High profile doesn't mean best it just means high profile.
- bobabob 4y ago
- tyjen 4y ago"The whistleblower also says Twitter executives don't have the resources to fully understand the true number of bots on the platform, and were not motivated to." I imagine this hurts Twitter's defense against Musk from pulling out of the takeover deal, or, is this whistleblower's account inadmissible?
- lapcat 4y agoWhy would it be inadmissible? Mudge could be subpeonaed, just like Jack was just subpeonaed.
- mrpopo 4y agoI am willing to take a shot in the dark on this story, and say that this is the whole point. I don't see why this story would get shared and amplified so much otherwise.
- zimpenfish 4y ago> I imagine this hurts Twitter's defense against Musk from pulling out of the takeover deal Not really because they have consistently said "this is what we do, it's a finger in the air estimate based on sampling, it might be right, it might be wildly wrong, there's no agreed methodology for this". For someone to then go "they don't fully understand the true number of bots! GOTCHA!" is dumb because it's literally just pointing out exactly what they've said in their SEC filings since 2013.
- 4y ago
- neilv 4y agoFor a solid and genuine technical person considering a CISO or CISO-like role, I've had the impression that they have to be very selective where they go. Even in what I'd guess is an "ideal" situation, of tractable technical&process problems, and genuine buy-in from the C-suite for solving/improving them, there's still going to be dynamics/politics to navigate. I also hear of a lot of much-less-than-ideal situations.
- shrubble 4y agoGod Mode, from my understanding, allows a Twitter employee to have access to an account and allows for a post to be made, under that account's id, without the account being notified or seeing the post show up in their own timeline. Is this an accurate statement? If so, why did nearly 1000 employees (12% of the workforce) have access to this mode before it was restricted, and what's the business case for that?
- dnakxnc 4y ago
- eastbound 4y agoThat explains why some people apologize for things they said would never apologize… Thing is, now that it’s possible for Twitter, Twitter can never brush off this suspicions again. We’re literally not sure, by using Twitter, that we see the speech of that person.
- saalweachter 4y agoNow think about the implications with respect to Twitter DMs that show up in criminal investigations. For instance, consider the Twitter DMs exchanged by Donald Trump, Jr and WikiLeaks. In that particular case, the communication was acknowledged by the party in question, but imagine the two possibilities thousands of employees being able to act on the part of users opens up: 1. Twitter employees could fabricate a criminal conspiracy by creating messages between multiple Twitter accounts. 2. A criminal conspiracy can now use the "Wasn't me, must have been some random Twitter employees" defense.
- bequanna 4y agoThis seems like a huge win for the defense in a case using DMs or Tweets as evidence. It would be quite easy to argue that a highly-politicized org like Twitter _might_ alter tweets or DMs to implicate someone in the opposing party. That’s reasonable doubt that at least some jurors would buy.
- 4y ago
- winternett 4y agoHonestly, can you really trust anything about major social media sites any more? Has Twitter ever been in the news for properly making even a thousand people successful from scratch really ever in the product's life? They have pipelines of exploitation for everyone that gets "discovered" into contractual nightmare deals, they require tons of free labor and costly hurdles just to become notable and visible on the platform, they extort people promoting their independent work for ad money, they don't protect anyone's privacy, they are VERY MANIPULATIVE in multiple (psychological) ways, they offer very little support or fairness when accounts are compromised, hijacked, or stolen, and they impose a stranglehold on information through lobbies and suppression of independent art and music. Social media took over the Internet after they wooed everyone into the ideal that they would operate fairly. Now that they have captured full attention, they have turned on users and they offer very little to anyone who doesn't pay, and can't offer reliable security to anyone. There are some serious "God Complexes" going on with having access to the personal data these systems harvest ON EVERYONE in conjunction with mobile devices. I really hate to say it would actually probably make me feel better if most of the large data monitoring sites/apps went away rather than stayed in place, because they make almost every aspect of the Internet work against us all. Twitter has had several opportunities to fix how it operates. The platform also generates tons in annual revenue to fix how it operates. Twitter has lots of employees that could fix how it operates. Twitter has also had numerous security breaches, and it regularly causes tons of stress for users. Twitter continues to focus on only pleasing it's sponsors, investors, and execs year after year and repeatedly stretching the promises it was built upon. I can't say I want to see this whale fail, but I won't miss it if it does.
- djbusby 4y ago> only pleasing it's sponsors, investors, and execs Yea, that's the game. They are a for profit business. This situation will happen every time. Profits over people, line must go up!
- the_doctah 4y agoYes and part of the profits are generated by their fake MAU numbers (bots). They are fraudulent above all else.
- freeflight 4y agoNot wanting to defend Twitter, but I'm pretty sure the situation is very similar across a whole lot of companies, even those that make security their main business, i.e. FireEye. Because investing in IT security usually has no apparent profit incentives, so most companies leadership will consider it something of very little importance funding wise. Particularly in the current climate where even minor hacks, and simple ransomware infections, are regularly made out as some kind of "act of God"/allegedly done by some super advanced "state actor", to create the narrative how it just wasn't preventable with the resources of a private company. Which outsources all the responsibility to ominous intangible parties based on wonky, and often politically motivated, attribution, while holding nobody responsible for running outdate software in exploitable combinations, thus creating the problem in the very first place.
- elesbao 4y agoBy the CNN piece it seems like twitter hired a community figure - which is a common mistake that leads to bad performance evaluation. Public figures are trained on being public figures, they not necessarily are the best folks to build a security organization. OTOH there seems to be some frustration from both sides regarding performance and if it gets public our hackerman will have a rough time being exposed. I don't think that was a good idea (reporting to SEC would work better IMO).
- markwisde 4y agoNobody seems to know how you can build a successful security org
- mrex 4y agoBuilding a successful security organization is very easy, it just starts higher up the food chain than whatever experts you hire to do it. Security is a cultural practice, it's not a feature, it's not a bolt-on. To the extent that your security organization influences and receives buy-in from your corporate culture, becoming a part of your organization's identity, it will be successful.
- hn_throwaway_99 4y agoI think this is key. If you don't have a good security culture, where people understand and have ingrained proper security practices, you're toast, no matter who else you hire.
- Jensson 4y agoGoogle has good security practices, can implement those in any big corp as they are very straightforward. Mudge previously worked at Google so I'd assume he was hired to help Twitter security get better by implementing some practices from Google. But maybe he was just hired to look like Twitter cared and they didn't really want to change anything.
- markwisde 4y agoConsidering the stories you can read in the security engineer handbook[1] written by FAANG security engineers I’m willing to believe that. [1]: https://securityhandbook.io/ https://securityhandbook.io/
- golemotron 4y ago
- jrm4 4y agoAh yes, came for the obvious response which I essentially do see here. Cybersecurity is awful at twitter, but that's because cybersecurity is awful everywhere.
- SilverBirch 4y agoI think it's a pretty open secret that Twitter is a fairly broken company. It's no surprise that their security practices are bad, because all their practices are bad. It's also very difficult to view this in isolation when you have the timeline of (1): Fired in January, nothing happens. (2) Musk makes offer for twitter then reneges. (3) Months before the lawsuit gets decided re-emerges with accusations. What happened that caused him to suddenly start whistleblowing now, and not in January? Was it the same thing that caused Ken Paxton in Texas to start investigating Twitter? This just looks like pretty plain mud-slinging from Musk's team to be honest. Especially since the Whistleblower seems to basically be blowing the whilst on himself.
- agentultra 4y agoThis was my first thought. TFA claims he started the whistleblower process before the Musk deal was signed. Seems kind of fishy though.
- pb7 4y agoMaybe, just maybe, Twitter is actually a poorly run company and it's not a conspiracy.
- themitigating 4y ago[flagged]
- TeeMassive 4y agoI don't remember conservatives threatening Twitter to censor "dangerous" views or "misinformation" or telling who to ban.
- encryptluks2 4y ago[flagged]
- motohagiography 4y agoThe whistleblowing case is a new dimension. To me as an outsider it implies Agrawal may have also been the manager in his previous technical role for a lot of the tech problems Zatko identified, and what made Agrawal CEO was his ability to leverage these problems to play ball with all the interests in that company and board, while sustaining through neglect some of those concerning practices within the organization. Twitter's product isn't technology, it's an uncertified slot machine that pays out in political influence, and there are a lot of big interests depending on their cut of it. They needed a steady hand who wouldn't be vulnerable to being swayed by principle, and that's the one thing you don't keep hackers around for, imo. If I were betting, nothing is ever really systemically broken in large orgs, it just works for someone you can't see. This is a factor everywhere and not necessarily at Twitter. Shitty process? Cui bono. Unverifiable systems? Cui bono. Deniable and unaccounted-for access to God-mode data? Cui bono. Repudiable numbers reporting? Cui bono. Bizarre political posturing? Cui bono, etc.
- nullc 4y agoPart of the allegation seems to be that the beneficiaries may be foreign state actors who have infiltrated the organization. Not particularly shocking as they'd have to be incompetent to not try to infiltrate a major communications platform, and if the internal controls are as bad as alleged (and has exposed in some of the prior hacks, e.g. the control panel screenshots) they'd have to be incompetent to fail.
- TaylorAlexander 4y agoA friend I trust quit after being at twitter only a few weeks specifically because of the atrocious lack of internal security controls. When I spoke to them the first thought I had was “this sounds like a gold mine for spies”, so this story today makes perfect sense to me.
- jasonm23 4y agoOoof... > They needed a steady hand who wouldn't be vulnerable to being swayed by principle. That's my golden quote of the day, time for bed.
- agentultra 4y agoI still think liability is the tool that will change how we approach security. Right now breaches don’t cost much and cause a lot of harm. Companies have no incentive to drive the speed limit and listen to their engineers.
- thesuperbigfrog 4y ago"Twitter has hidden negligent security practices, misled federal regulators about its safety, and failed to properly estimate the number of bots on its platform, according to testimony from the company’s former head of security, the legendary hacker-turned-cybersecurity-expert Peiter “Mudge” Zatko." "Zatko was fired by Twitter in January and claims that this was retaliation for his refusal to stay quiet about the company’s vulnerabilities. Last month, he filed a complaint with the Securities and Exchange Commission (SEC) that accuses Twitter of deceiving shareholders and violating an agreement it made with the Federal Trade Commission (FTC) to uphold certain security standards. His complaints, totaling more than 200 pages, were obtained by CNN and The Washington Post and published in redacted form this morning." What a bombshell! Maybe Elon Musk's complaints about Twitter have more merit than anyone expected. What might the SEC and shareholders do in response?
- jdhn 4y ago>What might the SEC and shareholders do in response? If shareholders believe this, they can do a variety of things such as sell the stock (smaller holders), or demand answers from leadership that go beyond "Yeah, we're secure" (bigger holders such as Saudi Arabia).
- mrex 4y agoSome options that shareholders would have in the situation where investors were knowingly deceived by false disclosures of a publicly traded company are missing from this response.
- mzs 4y agoTwitter CEO's response to employees which denies none of the claims made by CNN & WaPo* https://twitter.com/donie/status/1562069281545900033 https://twitter.com/donie/status/1562069281545900033 * https://www.washingtonpost.com/technology/interactive/2022/twitter-whistleblower-sec-spam/ https://www.washingtonpost.com/technology/interactive/2022/t... edit: the PDFs from * https://www.washingtonpost.com/technology/interactive/2022/twitter-whistleblower-sec-spam/current_state_assessment.pdf https://www.washingtonpost.com/technology/interactive/2022/t... https://www.washingtonpost.com/technology/interactive/2022/twitter-whistleblower-sec-spam/risk_committee_issues.pdf https://www.washingtonpost.com/technology/interactive/2022/t... https://www.washingtonpost.com/technology/interactive/2022/twitter-whistleblower-sec-spam/whistleblower_disclosure.pdf https://www.washingtonpost.com/technology/interactive/2022/t... cover letter: https://s3.documentcloud.org/documents/22161666/twitter-whistleblower-cover-letter.pdf https://s3.documentcloud.org/documents/22161666/twitter-whis... latest reaction from Capitol Hill: https://www.washingtonpost.com/technology/2022/08/23/twitter-whistleblower-congress-investigation/ https://www.washingtonpost.com/technology/2022/08/23/twitter... >Nobody at the Valley's unicorns seemed too concerned with security. (I asked Jack Dorsey that year whether he worried about the fact that hackers were continually pointing out holes in Twitter and in his new pay-ment start-up, Square. "Those guys like to whine a lot," he replied.) https://twitter.com/nicoleperlroth/status/1562048569028366337 https://twitter.com/nicoleperlroth/status/156204856902836633...
- icelancer 4y agoAgrawal's internal statement about Zatko is insane. My goodness.
- mzs 4y agoI know right! Was the last CEO who wasn't a monster Bill Hewlett?
- systemvoltage 4y agoPage 9/84 in the "whistleblower_disclosure.pdf" are about Elon Musk's claims of fake twitter accounts and bots. Good lord, this does not look pretty for Twitter.
- deleted 4y ago[deleted]
- purpleblue 4y agoMillenials and GenZ may have no idea who Mudge is. I, however, almost lost my first job out of college at a bank because I ran l0phtcrack against our Windows NT 4 server to see if it could crack passwords. I showed my boss, and he pulled me aside into another room and tore my head off for irresponsibly running this tool against a production server. He said I could have been fired if this got out, but he covered my ass, sent out an email requesting everyone reset their passwords, and let me continue working. I learned a good lesson because even though my intentions were good, and it did expose security issues, it was a bit immature and should have been done in a more controlled manner along with the proper clearances. Mudge knows the implications of "whistleblowing". He has been a security consultant and even testified to Congress. He's not some noob that doesn't understand security or how systems work together to provide services like disclosure to FTC. The idea that Twitter PR can pooh-pooh away his concerns is shockingly stupid. I think Twitter is in real trouble here.
- last_responder 4y agoAh yes, Lopht Heavy Industries. Indispensable tools at the time.
- bombcar 4y agoAlways been a fan of "Heavy Industries".
- Syonyk 4y agoYup. I've used that with my normal "last name backwards" company name before. I tend to send Christmas and Birthday gifts to siblings with the company field filled in. "Kinetics," "Orbital Bombardment Division," "Relativistic Research," and assorted other things have made their way in, but "Heavy Industries" just has such a nice ring to it.
- bombcar 4y agoI love that Wikipedia says it covers "large and heavy products" and/or "large and heavy equipment". Such a 5-year old boy way of naming things.
- mrex 4y agoJust to clarify for those who don't catch it in the article: Mudge's whistleblower complaint predates the Musk/Twitter feud entirely.
- zimpenfish 4y agoWhere do you see that info in the Verge article? All I can see is "he filed last month" (which would be July 2022) - the month Musk "officially" backed out and at least a month after he started doing the "I don't want Twitter any more" dance.
- mrex 4y ago"Zatko was fired by Twitter in January and claims that this was retaliation for his refusal to stay quiet about the company’s vulnerabilities."
- zimpenfish 4y agoThat doesn't cover whether or not he had contact with Musk and when he started the whistleblowing process.
- deleted 4y ago[deleted]
- jyrkesh 4y ago> John Tye, founder of Whistleblower Aid and Zatko's lawyer, told CNN that Zatko has not been in contact with Musk, and said Zatko began the whistleblower process before there was any indication of Musk's involvement with Twitter.
- riffic 4y agohe got canned right after the Jack departure.
- tacker2000 4y agoThis is an important point, but why is the media picking it up just now? I guess both sides are starting the usual shit-flinging…
- donohoe 4y agoSo the CNN article lacks any detail really. There are things on the surface that sound bad but without context its impossible tell. Has any one gong through the Washington Post story and the PDFs and found the real issueS?
- ChrisMarshallNY 4y agoI've been hearing about Mudge for decades. It's actually a bit ... heartbreaking ... to see him looking so corporate, but we all age, don't we? I doubt he was fired for being bad at his job. But I'll bet he was fired for getting in people's faces. That was basically his calling card for years. Why is anyone surprised? I guess Twitter thought they could hire the cachet, without hiring the man. I remember an Apple WWDC, way back when. It may have been in the 1980s, as it was in San Jose. They hired Ken Kesey to drive his bus to San Jose, and give a speech. The party theme was "Hippies," so he fit right in. So they thought. He got up on stage, and started talking about taking acid, and counterculture. The shepherd's crook came right out, and yanked him off the stage. I heard they had a big fight with him, because they wanted him to leave his Magic Bus, parked in the courtyard. He drove off in it. Smart people that make waves are not easy to control. If you are used to herding around mediocre sheep, you'll probably have a hard time with the wolves.
- hn_throwaway_99 4y agoI don't think your comparison is apt. Mudge isn't some loose cannon. He worked for the US government as a program manager for DARPA from 2010-2013, then for Google from 2013-2020. You think he looks "corporate" now, just look at his government portrait on his Wikipedia page from a decade ago. Point being, Mudge is a very well respected cyber security professional, not some "hippy hacker" from years past. Which makes me even more willing to give his accusations weight, because this is not a case of someone who doesn't "get" corporate environments.
- ChrisMarshallNY 4y agoI didn't mean that he was a "hippy hacker." Maybe you misinterpreted that, from my story (BTW: Ken Kesey was no slouch, either). My apologies for being unclear. But he has definite history of being quite willing to speak truth to power. Not having had any personal interactions with him, I can only go on the [many] stories I've heard.
- psyc 4y agoIt looks like you're reading several things into GP's comment that he did not write. At least I read it completely differently. I.e. that perhaps Mudge's alleged failure was "not playing ball" regardless of what the particular game might have been in that corporate environment, at that particular time, under/beside those particular execs.
- PedroBatista 4y agoWhile I'm sure Twitter and every social network internal politics suck and are full of sleazy people who hold themselves in very high regard, these accusations seem weak. He appears to indicate precisely what it's public, like the 5% bots but then goes to into the usual obscure "I know it's not that number and the structure is incentivized in the wrong way.." Obviously he has an axe to grind and I wouldn't be shocked if Elon was directly involved with this, but I'm not sure this vagueness holds in court..
- deleted 4y ago[deleted]
- stuckinhell 4y agoThe bots problem is absolutely nightmare issue for a social network. I can't imagine what I'd do if I discovered my network was fake. The whole point of my network is building professional connections and gaining skills for work. Also seeing various weird topics on twitter like kpop or other random things always made me wonder how much artificial bot boosting was done for those who had money to pay the bot net.
- the_lonely_road 4y agoFYI Kpop is "very" popular in some segments of American culture that you just might not cross over with. I experience it frequently in the "Team Fight Tactics" ecosystem which is an E-Sport run by Riot Games (of League of Legends fame) that for some reason contains a very large Asian American population (in relation to their % of the population) and all of them frequently stream Kpop to large audiences. The largest streamer for this game "K3Soju" is one of the top 10 streamers on Twitch frequently pulling in over 20,000 viewers. All of these people are very active on Twitter. I point this out because I doubt things like this going viral on Twitter are necessarily the result of bot networks instead of just the result of corners of the internet that we don't encounter.
- upupandup 4y agowhat I find peculiar about the kpop crowd is how they seemingly appear out of nowhere and on-demand on in political topics to drown out/cancel people who don't like them or share their values. In Korea a blogger was able to see how BTS fans or "bots" were able to game the music ranking. What's interesting to me is how they seemingly correlate with wumaos as well. I don't have solid evidence but it appears that much of the "stan" (kpop mob on social media) are very much politically aware and push a certain side of the spectrum. All of this makes for some bizarre dynamics and I'm afraid that youngsters who are caught up in the craze don't know that they are being manipulated by very large crowd that behaves in bot like behavior or are herded into specific political flashpoints without understanding the underlying nuances.
- the_lonely_road 4y ago
- deleted 4y ago[deleted]
- tschellenbach 4y agoZatko reported directly to the CEO, as a senior leader you need to take responsibility for your own work. Does anyone believe that in an organization as large as Twitter he didn't have enough resources to solve this? I imagine his budget ran in the tens of millions.
- ctrlmeta 4y agoI can very much believe it. A CEO can, if they play their cards right, block the CTO from accomplishing what the CTO set out to do. Budget is not the problem. Approvals and alignment with board members are the problems. And if the CTO still decides to push forward, the CEO can still fire the CTO for underperformance which is exactly what you see in this story.
- deleted 4y ago[deleted]
- tschellenbach 4y agoThey could. But if someone has a cost effective plan to improve security, that's feasible to execute, why would they block it? It doesn't make sense, security issues are important and can cause damage to the business. Their CEO is an engineer, he knows this. It seems more probable that this security leader failed to get buy in from the engineering teams, or that there was some technical debt that he couldn't get past.
- latchkey 4y agoAmazing how little has changed in 20 years... https://www.cnn.com/videos/business/2022/08/23/peiter-mudge-zatko-2000-vault-orig.cnn https://www.cnn.com/videos/business/2022/08/23/peiter-mudge-...
- solarkraft 4y agoYeah, but Elon knew all of it.
- m3kw9 4y agoDoes Musk know Mudge?
- vagabund 4y agoI wish CNN would just air their interview in full instead of splicing his answers into 5 second soundbites with editorialized voiceover framing. I'm infinitely less interested in CNN's reporter's summation of the issue than that of the veteran security analyst at the heart of the story.
- crow_t_robot 4y agoWhen is mudge going to audit tesla/spacex for "non-compliant kernels", "encryption at rest", etc, etc? Everyone in this shameful industry knows that literally any company in the US would get shredded in such a vigorous audit and the silliest part is that twitter is a fucking shitposting platform that doesn't have my SSN or financial data so equating it to equifax in any way is absolutely laughable.
- jwogrady 4y ago
- lkjwlk 4y ago
- TheBlight 4y agoThese days whenever the media bestows "whistleblower" status on someone I become instantly suspicious.
- seydor 4y agoTwitter is like, the 7th season of "Silicon Valley"
- kyrofa 4y agoIs it just me, or does some of this feel less whistleblower-y and more petty? For example: > The company also lacks sufficient redundancies and procedures to restart or recover from data center crashes, Zatko's disclosure says, meaning that even minor outages of several data centers at the same time could knock the entire Twitter service offline, perhaps for good. That said, this is Mudge. I have a lot of respect for the guy, and I believe what he says. I'll chalk the pettiness up to this article being a summary of a more complete document that I'd like to read at some point.
- chipgap98 4y ago> The company also lacks sufficient redundancies and procedures to restart or recover from data center crashes, Zatko's disclosure says, meaning that even minor outages of several data centers at the same time could knock the entire Twitter service offline, perhaps for good. I mean if it were true that seems pretty negligent. If that were the entire extent of the whistleblower complaint (not sure if complaint is the right term?), I would agree, but it seems as though there are some significant issue raised in the rest of the report.
- kyrofa 4y agoI dunno, pointing out that something has a poor architecture and pointing out that something has severe, known, and ignored security issues feels different.
- mzs 4y agoKnocking-out twitter (used by journalists and govs) during a crisis IS a security concern.
- yupper32 4y agoA security concern for the governments, not twitter. It's not twitter's fault that governments are using it as a primary form of communication, nor should it be their responsibility to have amazing uptime just because governments are using their platform.
- jonathankoren 4y agoSure the article focuses on Mudge because the's blowing the whistle, but Mudge and Rinki Sethi (ex-CISO) were fired at the same time. When you fire both your chief of security and your CISO months after you hire them, it's weird. Even if your chief of security had personal failings, why fire his boss? If the boss falls on her sword for direct, that certainly makes me think to take what their saying seriously.
- naltun 4y agoI learned a lot about Mudge by reading "Cult of the Dead Cow: How the Original Hacking Supergroup Might Just Save the World." For anyone wanting to explore 90's security nostalgia, it's worth a read. For anyone wanting to learn where hacktivism comes from, it's worth a read. For anyone wanting to learn about how security consulting has evolved over the years, it's worth a read. Mudge is a very cool and capable individual. I am slightly surprised that Twitter would ignore someone of his talent and respect, and choose to air their dirty laundry in this manner. It's as if they have no idea who they hired. That, or C-levels think they can outpay $$$ any PR against Twitter to control the narrative. Either way, if Mudge is whistleblowing, there's probably some bad shit going down.
- rossdavidh 4y agoIt appears that Dorsey was the one who hired him, and then Dorsey left, which might explain why they act as if "they have no idea who they hired".
- keepquestioning 4y agoThis guy is obviously paid off by Elon
- dehrmann 4y agoAfter the Peter Thiel/Hulk Hogan incident, and especially considering Musk and Thiel are both Paypal mafiosi, it's quite possible.
- bastardoperator 4y agoIf it's your job to address specific issues and you fail to do that, how is that whistleblowing? If this person can't prove they were blowing whistles before termination, well, that's a lot of egg to wear on ones face.
- deleted 4y ago[deleted]
- imchillyb 4y agoMudge = Competent advisor, Cybersecurity expert, Senate special witness. Twitter board = Incompetent, Liars, Corporate cronies. Which of these two sources do YOU believe is more reliable? Yeah. That's gonna be the general consensus. Mudge-1 / Twitter-0
- pphysch 4y ago> FOREIGN THREATS: Twitter is exceptionally vulnerable to foreign government exploitation in ways that undermine US national security, and the company may even have foreign spies currently on its payroll, the disclosure alleges. This is a very strange article to me. When I think of Twitter and government influence, I think of the overwhelming pro-Washington bias. I think of the "state-affiliated media" tags that somehow don't apply to RFE/RL and BBC. I think of the countless heterodox/dissident accounts that have been banned or silenced on the platform. I think of the "hacked materials" warning label that was invented to discredit a particularly damning story about a covert disinformation campaign involving Reuters and BBC. I think of Twitter's complete tolerance of the obvious platform abuse by the textbook troll farm known as "NAFO". I think of the revolving door between the federal government and policy/compliance positions at large tech companies including Twitter, of which Mudge is one of many. My tinfoil hat is whispering that this story is part of a broader campaign to put pressure on Twitter to be even more compromised by the federal government and intelligence agencies. I just don't see how this "foreign threat" narrative lines up with the reality of how effectively managed Twitter has become over the past few years. Realistically though, Mudge probably just has a huge hacker ego and is butthurt that he was caught slackin'.
- nym375 4y agoRead the report of the problems he was trying to surface: https://www.washingtonpost.com/technology/interactive/2022/twitter-whistleblower-sec-spam/risk_committee_issues.pdf https://www.washingtonpost.com/technology/interactive/2022/t... This doesn't seem like he was "butthurt and caught slackin'." The tone of the report seems like he's frustrated that he was hired to do a job, and not given the resources / authority to make the necessary sweeping changes. Perhaps someone with a more political approach could have influenced leadership better. But they hired an extremely technical person, not an extremely political person.
- kornhole 4y agoWhat more pressure do you think intelligence agencies would want to enforce? https://www.mintpressnews.com/twitter-hiring-alarming-number-spooks-secret-agents/281114/ https://www.mintpressnews.com/twitter-hiring-alarming-number...
- riffic 4y agocopy and paste my comment from an earlier post which failed to see HN traction (https://news.ycombinator.com/item?id=32562747 https://news.ycombinator.com/item?id=32562747): > The complaint from former head of security Peiter Zatko, a widely admired hacker known as “Mudge,” depicts Twitter as a chaotic and rudderless company beset by infighting, unable to properly protect its 238 million daily users including government agencies, heads of state and other influential public figures. this is a fun read. I've long said that government agencies, heads of state and other influential public figures are obvious candidates for running their own ActivityPub installations (or in paying competent people to do that, which shockingly Twitter, Inc. could be in the business of hosting/selling).
- mikkergp 4y ago"as a chaotic and rudderless company beset by infighting," Sounds like a match made in heaven for "government agencies, heads of state and other influential public figures."
- awinter-py 4y agoI mean separately from security questions here, it seems not great that 'public social media' platforms are operating their own DMs DMs should be BYO provider
- bogomipz 4y agoIf this is true this would be particularly damning >Zatko’s complaint says he believed the Indian government had forced Twitter to put one of its agents on the payroll, with access to user data at a time of intense protests in the country. The complaint said supporting information for that claim has gone to the National Security Division of the Justice Department and the Senate Select Committee on Intelligence. Another person familiar with the matter agreed that the employee was probably an agent.[1] [1] https://www.washingtonpost.com/technology/interactive/2022/twitter-whistleblower-sec-spam/ https://www.washingtonpost.com/technology/interactive/2022/t...
- kornhole 4y agoThis should get the attention of politicians who are probably the most active users of Twitter. Having their contacts, coms, and metadata such as phone location exposed and collected by adversaries is probably a concern for them and our entire political system. Recall how J Edgar Hoover was collecting dirt of every politician to blackmail them to keep his agency funded without oversight. Twitter would have been a wet dream for him.
- bogomipz 4y agoYou would think that Twitter might have a coherent strategy in place for dealing with the media on this but no. They are trying to discredit Peiter Zatko by stating that he was terminated for performance reasons and yet their spokesperson goes onto to make these completely conflicting statements: From Twitter spokeswoman Rebecca Hahn: Hahn said that Twitter fired Zatko after 15 months “for poor performance and leadership.” Hahn added that Twitter has tightened up security extensively since 2020, that its security practices are within industry standards, and that it has specific rules about who can access company systems.[1] 2020 was of course the year that Zatko was hired by former CEO Dorsey. So security tightened up "extensively" on Zatko's watch but he was fired for "for poor performance and leadership"? This only seems to support Zatko's(and many others) assertion that Twitter is a giant shit show of chaos. [1] https://www.washingtonpost.com/technology/interactive/2022/twitter-whistleblower-sec-spam/ https://www.washingtonpost.com/technology/interactive/2022/t...
- riffic 4y agoTwitter has a comms department but there has been a revolving door of ineffective comms leadership. I can't even get someone from Twitter Comms to pop into the Twitter subreddit to engage with users there. Rebecca Hahn doesn't even have a Twitter account afaik.
- bogomipz 4y agoThat is rich. From July: >"Details: The communications lead role has been vacant since last November, but it's been led by Twitter CMO Leslie Berland on an interim basis for the past seven months. Hahn, who technically started last week, will report to Berland."[1] The VP of Global Communications at Twitter role was vacant for 7 months and the person finally hired doesn't seem to have a visible Twitter presence after 6 weeks on the job? At a time when the company is practically a daily news story? You couldn't make this shit up. [1] https://www.axios.com/2022/07/12/twitter-rebecca-hahn-communications https://www.axios.com/2022/07/12/twitter-rebecca-hahn-commun...
- tdeck 4y agoI did wonder about this ever since the Ahmad Abouammo story broke. How did a media partnerships manager have access to so many random users' private info? That stank of poor access controls: https://www.justice.gov/opa/pr/former-twitter-employee-found-guilty-acting-agent-foreign-government-and-unlawfully-sharing https://www.justice.gov/opa/pr/former-twitter-employee-found...
- rossdavidh 4y agoIt's not just this, but a long series of Twitter-related debacles, that are starting to look less like a company in trouble, and more like a company circling the drain. Do we have any real reason to think Twitter might not be able to survive all this? No one seems to think they're profitable, not even when ad revenue generally was a lot better than the economic environment we're going into. No one who's capable of buying it seems to want to buy it; the reason the poison pill vs. Elon Musk's initial purchase attempt was dropped, is that they checked around and got no other buyers. It's not just the legal and PR problems, it's that there's no $$$ on the other side to make it worth those problems, and we're heading into a "you need to make money" environment. I think they might be circling the drain...
- throwaway892238 4y agoThe "whistleblower" is Mudge? Ok, I didn't care before, but if Mudge is putting his reputation on the line, this is probably actually serious and legit. Literally the entire security community knows and looks up to Mudge. If anyone finds out that anything he said was bullshit, it will get blasted from the rooftops and he'll become a laughing stock. He would have to want the rest of his career to be working for morons and be ostracized from his friends and community to make this shit up.
- jasonm23 4y agoIndeed... the "fired for poor performance" is about the biggest red flag, and a clear euphamism for "fired for user centric principles."
- jmyeet 4y agoCall me paranoid but this is just too convenient. In the next two months we have Elon’s Twitter trial where he’s expected to get railed. Despite waiving due diligence in his commitment to purchase Twitter he’s repeatedly made the claim without evidence that Twitter has made material misrepresentations about bots to him and investors. That would be fraud if true. So right before the trial a “whistleblower” comes forward and makes claims that support Elon’s narrative. Weird. It’s just a little too convenient for me not to be at least skeptical.