7 ms·
Eh, you could take out Twitter and insert many other company names and it'll still hold true. And those companies hold so much more sensitive data about you tha
by vlan0 4y ago
Eh, you could take out Twitter and insert many other company names and it'll still hold true. And those companies hold so much more sensitive data about you than Twitter.
I know of insurance companies that have help desk employees with domain admin access. And all crippling ransomware attacks take advantage lax permissions.
This is rampant. How is this a story?
- encryptluks2 4y agoAt least you get it. I've seen worse on actual government systems.
- bartread 4y ago> How is this a story? Cynically, because it's twitter, and it's trendy amongst a certain subset of the population to bash social media in general and twitter in particular. And I think your point is fair. (FWIW, I think social media has if not caused, then certainly exacerbated, some major problems at individual, societal, and global levels, but by no means do I think twitter is the biggest contributor. I don't think we'd see the kind of unconstructive political polarisation we're seeing in the US and UK and perhaps, to a lesser extent, within the EU, without it.)
- zinekeller 4y agoMy reasoned mind says it's due to the recent disclosure in Twitter due to linking of phone numbers to people, while my other mind says it's Elon finding anything to make Twitter give up their case.
- bartread 4y agoFor sure, the phone numbers issue definitely won't have helped, but the whole Elon/Twitter situation is definitely up there. Plus, as I say, it's been sort of trendy to bash them for a while: they're either not doing enough to protect people from harmful content, or they're subverting freedom of speech by, for example, banning Trump, and applying permanent, temporary, or shadowbans to other accounts. I'm not that sympathetic, but they sort of can't win.
- blitzar 4y ago> in Twitter due to linking of phone numbers to people Except like the linkedin "hack" which was just a scrape of peoples profiles, the twitter "hack" was someone running phone numbers through the "upload you contacts and find your friends account" feature. They are both barely stories, except to remind people that posting stuff publicly is public.
- BlueGh0st 4y ago>..the twitter "hack" was someone running phone numbers through the "upload you contacts and find your friends account" feature. >They are both barely stories, except to remind people that posting stuff publicly is public. The reoccurring issue is that Twitter and other companies are convincing (and often forcing) you to do something unsafe like linking your phone number, while telling you that your data will be kept private and at the same time opting you in by default, or aggressively marketing, an option that compromises your security. I'm sure you may be smart enough to know this compromises your anonymity, allows stalkers to find your phone number, etc. but the 99% of users wont. Linking everything to a phone number is a major dark pattern that benefits the corporations while compromising the user. So rightfully, these malicious and harmful practices should be called out.
- shadowgovt 4y agoAdditionally, Twitter collected PII and then did a bad job protecting it. We don't see a phone-numbers-leaked story like this out of Google, which has had 2FA with phone number deployed for years. Twitter has some 200+ million daily active users and should act like it.
- blitzar 4y agoDecide whether people who have your email address or phone number can find and connect with you on Twitter. If you select yes, then someone with l33t skills can "hack" twitter and type in your email / phone number and get your twitter handle (or just put it in their contacts and click a button in the twitter app aka l33t hax0r skills) The reason there isnt "leak" from google is because they dont offer the functionality to look up your account by your phone number.
- kornhole 4y agoI think you are referring to corporate and state controlled social media. There is a big difference between those platforms and the fediverse instances I am running on a RPI sitting on my desk.
- hotpotamus 4y agoCybersecurity is one of my roles I suppose (small place with an operations team of approximately 2.5), and I have to say that I have no idea what proper security is supposed to mean today; it's very hard for me to tell the marketing from best practice now. It seems like what most products really are is an ass covering service so you can tell your leadership and your customers that you did the right things. Basically we work on keeping everything patched and try not to create any obvious issues. Honestly, I think the best thing we have going for us is obscurity.
- nannal 4y agoConsult with a security firm or specialist and they should be able to steer you in the right direction.
- chadash 4y agoTwo problems with this: 1) Like a car mechanic, these people get paid to sell you solutions and they are incentivized to sell you more. 2) Plenty or honest people have biases because of what they do. If you spend all day thinking about security you might be overly concerned about things that are actually not that risky. This isn’t to say that there aren’t great people working in the field. But it’s daunting from an outsiders perspective.
- analyst74 4y agoIt's still comes down to a matter of urgency or value perception. You don't want your doctor to overlook any problems just because they are rare because your health is really valuable.
- SketchySeaBeast 4y agoWith the example of the doctor you run into the nocebo effect - you can spend a lot of time tracking down things that turn out to be of very low value which ends up causing more harm than good. To painfully extend the metaphor you could have an overly aggressive password policy and end up having users reusing passwords or writing them down.
- throwawaylinux 4y agoDid you actually read it? The story isn't some handwaving about companies in general having bad security. It's that Twitter's former head of security is blowing the whistle on "reckless and negligent cybersecurity policies" including deliberately misleading government regulators and its own board about various issues, and concerns about foreign espionage and disinformation. If you don't know how that's a story I don't know how to explain it to you, I can only assure you many people will find it extremely newsworthy.
- vlan0 4y agoI hear you. All of that is a big deal and should not be taken lighten. Maybe I'm a bit jaded by what I've seen, but that doesn't seem too far off from normal American business culture. Deflection and manipulation seem to be par for the course. It's why lobbyist exist. Companies want permission to do/not do the things they're not currently allowed/required to do. The ones that get caught are normally a few bad actors that whistle blow. The companies where it's ingrained in their culture get away with it. Of course...this is all my own experience :)
- trombone5000 4y ago> This is rampant. How is this a story? Because it's being publicly revealed. If the lax security you describe at other companies were also revealed, maybe more would be done to fix it.
- deleted 4y ago[deleted]
- mrpopo 4y agoBecause people with a lot of money are inflating this story to get back at Twitter. It sounds like a conspiracy, but that's the most plausible explanation I have for why this specific whistleblower gets amplified by the media.
- papito 4y agoNot a lot of companies get infiltrated by foreign agents or assets. Access to Twitter, in particular, can help unmasking anonymous sources, sensitive DMs, dissidents - and their locations. And, oh yeah - there is no "conspiracy".
- mrpopo 4y agoI don't claim Mudge was infiltrating Twitter, nor that his claims to bad security are false, nor that it is not dangerous to use Twitter if you value privacy. Bad security at Twitter, or any other social media is a given. Remember they're in the business of selling personal data. My claim is that this specific story which is most likely true but in no way surprising gets amplified right now because some specific powerful people wanted it so.
- dd36 4y agoOr the current Twitter drama is precisely why it is an interesting story for the media. That said, given foreign influence campaigns in the news in the last 6 years, this would’ve been news then too. I’m sure it was news back in 2010 when the FTC ordered it to fix the problems.
- papito 4y agoOr maybe, you know, the media finds this story interesting because this is an extremely visible company with tons of influence on narratives around the world. Who are these "powerful people"? And why do they care about Twitter so much? Most powerful people aren't even ON Twitter.
- mrpopo 4y ago
- deleted 4y ago[deleted]
- mrex 4y ago>This is rampant. How is this a story? Bro. It's not every day that literally Mudge, who has -no doubt- seen his fair share of shit-shows, whistleblows on an employer.
- dehrmann 4y agoBut was he fired by any of those shit shows?
- mrex 4y agoI don't think you understand how poorly attacking Mudge's character or insinuating that he's driven by some unethical ulterior motive is going to work out. Mudge is... he's Mudge. He's a known quantity, and one everyone wishes we had more of. When he says something like this, smart people listen intently.
- 12many 4y agoBecause it's CNN and they like to make headlines with some bogus whistleblower that is concerned that some die-hard trumpers are going to hack top companies and create some kind of mass hysteria. Just the usual fear mongering in the news media to get views.
- winternett 4y ago> This is rampant. How is this a story? Well, it's on the front page of CNN right now for starters, so that means it's probably significant to a lot of people... If you have a business, you most likely need to promote it on Twitter, or to at least reserve an account there so that someone else won't impersonate you. You also need to do that on almost all other major social platforms. If you have a business or personal account on Twitter, your direct messages, the data the system generates about your preferences and interests, your geo-coordinates, and everything you post, including control of how your account works can apparently be accessed by too many people within the company. It's a pretty big deal for anyone that uses the platform citing all that... Not something that should just be "left to it's own devices" because everyone else is doing the same. All cases of data abuse/misuse should be addressed, but addressing one this big would also be a pretty big deal.
- NelsonMinar 4y agoTwitter is under a consent agreement with the FTC about its security practices. Part of the allegations here is that they've been lying to those regulators. https://www.ftc.gov/news-events/news/press-releases/2011/03/ftc-accepts-final-settlement-twitter-failure-safeguard-personal-information-0 https://www.ftc.gov/news-events/news/press-releases/2011/03/...
- thomassmith65 4y agoIt is certainly rampant. Amazon, for example: https://www.wired.com/story/amazon-failed-to-protect-your-data-investigation https://www.wired.com/story/amazon-failed-to-protect-your-da... That said, all these stories are important to the public.
- deleted 4y ago[deleted]