10 ms·
Matt Levine today: > Surely the highest-variance aspect of the Twitter vs. Musk saga is Zatko’s whistle-blower complaint. If Zatko can make a compelling case t
by dweez 4y ago
Matt Levine today:
> Surely the highest-variance aspect of the Twitter vs. Musk saga is Zatko’s whistle-blower complaint. If Zatko can make a compelling case that Twitter is horribly bad — that its information security is so bad that it violates the law, that it has fraudulently concealed its problems, etc. — then that is probably Musk’s best argument to get out of the deal: Twitter is doing fraud, it has suffered a material adverse effect, etc. If Zatko is just a run-of-the-mill paranoid security researcher who is aggrieved about being fired and making mountains out of molehills, then his complaint will quickly be kicked out of court and won’t affect the Musk deal. Zatko’s credibility — whether he’s telling the truth, and also whether he is exaggerating or underselling the importance of Twitter’s problems — is a key input into your evaluation of Twitter’s stock value. The more credible he is, the less likely it is that Twitter will get $54.20 per share, and the less Twitter will be worth without Musk’s deal.
> So if you are a hedge fund, or an expert-network firm working on behalf of hedge funds, you obviously want to know how credible he is. You might, for instance, want to talk to some of his old coworkers to get a feel for him. You might offer to pay them a lot of money for a one-hour phone call, because you might have a lot of money riding on the Twitter deal, which means specifically that you have a lot of money riding on your evaluation of Zatko’s credibility.
- neonate 4y agohttps://www.bloomberg.com/opinion/articles/2022-09-13/crypto-wants-some-sec-rules https://www.bloomberg.com/opinion/articles/2022-09-13/crypto... https://archive.ph/YoBJQ https://archive.ph/YoBJQ
- anonymouse008 4y agoWell hell, I made the wrong choice at a fork in the road then. If finance is willing to buy a tighter confidence interval based on insight to Mudge’s credibility, then I severely underpriced the potential payout in finance. E-mail is open to those who want tighter intervals re this deal or similar: my new pivot.
- ryandrake 4y agoYea, wow, I had no idea someone would pay that much simply for an ex-employee to spin a bunch of bullshit about their former company or colleague. Incredible! I remember a surreal experience after having left a Silicon Valley tech company. I was contacted over LinkedIn by someone wanting to "do research" about that company. Reading between the lines, he wanted company dirt, secrets, and so on. Having no intention of violating my (very serious) NDA, I declined, but he was insistent and offered to buy me dinner. I figured I could just go, chew my food and not answer questions, so why not get a free meal out of it? We met, I started chowing down, not answering anything, and just treating it like a lovely dinner date. He eventually excused himself to the bathroom, and then disappeared, leaving me with the bill. So, I guess my plan didn't work, but I got a stupid story out of it so I've got that going for me.
- gojomo 4y agoLesson learned: if anyone wants to try the same move, choose someplace where the host pays at the counter, before sitting down with the food. (What are some of the best Bay Area eateries that work that way?)
- linuxlizard 4y agoThat's not just a stupid story, that's an awesome stupid story.
- Scoundreller 4y agohttps://www.nytimes.com/2019/01/28/world/black-cube-nso-citizen-lab-intelligence.html https://www.nytimes.com/2019/01/28/world/black-cube-nso-citi... ?
- dilap 4y agoThis story is fantastic. It's great because the ending is so unexpected, but then on second thought, exactly what you should've expected. Perfect.
- abawany 4y agoYou now know what the status of your payout would have been had you chosen to violate your NDA. There is no honor among thieves, apparently.
- purpleblue 4y agoDuring the dotcom days, when employees had desk phones, some of my coworkers would get unsolicited calls from analysts or other people searching for inside information about our company. They would engage them in conversation, try to become friends with them over months so that they could reveal even the smallest bit of inside information for them. The lengths that people will go to get some sort of information edge to make money, even doing illegal things, is incredible.
- shalmanese 4y agoIs that illegal for analysts? If an employee chooses to share confidential info to any random person, that's a breach of contract for the employee but does the analyst face any culpability?
- distrill 4y agoif they trade on material non public information, then yes that's illegal.
- otikik 4y agoIt will greatly depend on the specifics, I suspect. An analyst hears something being talked about on a different table in a restaurant by chance is legal. An analyst offering money to a retired nuclear weapons defense contractor in order to sell might… suddenly disappear. In between those two extremes? Ask a lawyer, not the internet.
- sangnoir 4y agoInsider trading is illegal even for non-employees. Sharing insider info with a spouse or sibling who trade on it will get all parties involved on trouble with the SEC
- jcrawfordor 4y agoUsually the information these types of analysts are trying to collect isn't really "material nonpublic information" in the somewhat narrow sense of insider trading law. Some of them aren't even in the investing industry but rather work for advisory organizations like Gartner. There's sort of a wide gray area between clear MNPI and information that the company just doesn't publish. Things like employee counts, general product plans, subjective opinions about user feedback, etc.
- Maursault 4y ago> If Zatko can make a compelling case that Twitter is horribly bad I don't doubt his accusations. However, the same could be said for nearly everywhere there is a network. Twitter is high profile, but there are a million businesses most have never heard of that have a similar lack of information security. IOW, Twitter's crappy security is not remotely exceptional because nearly every business with a computer is bad. There are businesses with decent computer, network and information security, but even in those places tight as a drum a disgruntled employee could reek havoc, and I'd be really surprised if Mudge and most of HN wasn't aware of this. Things usually go bad for whistleblowers, it is a shame, but most often it doesn't work out for them. They make movies about the successful whistlebowers, but the unsuccessful are buried. It would have been different had Mudge stepped forward prior to termination, as he would have been able to avail himself of Federal whistleblower protections. I don't think it matters to his credibility, but that this is exactly what Musk wanted to hear is a little, tiny bit suspicious to me. What could Mudge gain from this other than saving face (which really isn't worth much)? What Musk did to Twitter is clearly unethical, as much as I respect him for his successes, it seems obvious his behavior regarding Twitter is irresponsible and many innocent lives and their wallets are being adversely affected. The SEC should look really hard at all this before choosing not to act, because he has manipulated markets for his personal benefit before and got a slap on the wrist.
- groby_b 4y ago> Twitter's crappy security is not remotely exceptional Uh, no. If Mudge's accusations are true, that would speak to exceptionally bad security. Not compared to Joe's Diner around the corner, but certainly for a major player in the tech market.
- Maursault 4y ago> that would speak to exceptionally bad security. The accusations were not exactly specific. You're splitting hairs. IT doesn't generate revenue. Often for this reason, at many large corporate locations, IT departments are spread critically thin, many far thinner than Twitter, which has money to afford experts like Mudge. These companies aren't sexy so they're never ever in the news and they're not on anyone's radar. Any idea how many Windows Server 2012 installations are still in production? Or how many corporate networks are entirely made of Windows 7? Far too many. The state of security in general across the entire American corporate landscape is shit, and even places that don't get compromised, like NSA, still get compromised. In July, Twitter experienced a global outage of ~45 minutes, the longest outage global outage in years. If Twitter was some shocking, never before seen level of insecure, it wouldn't have been 45 minutes, and there'd be a lot more of them. btw, I hate Twitter, Facebook, LinkedIn, et al., and passionately, but it's just not credible to claim that Twitter is the worst of the worst in security, because there is an astounding number of corporations with no security to speak of, like, no IT department, none. "It's something one of the drivers handles for us. He's a real wiz." That kind of thing. At least Twitter not only has an IT department, but also has security personnel. I think if anyone scrutinized, say, Yahoo, they'd find the same thing.
- dehrmann 4y ago> run-of-the-mill paranoid security researcher who is aggrieved about being fired and making mountains out of molehills My metaphorical money is on this, but I'd add "respected" to that list. My literal money stays away from Musk because it's always a shitshow.