genderequalitygoals

genderequalitygoals

Friday, 2 September 2022

[New post] Did Twitter disregard fundamental safety precautions? A cybersecurity professional clarifies a whistleblower’s allegations

Site logo image PerceptivX posted: " Twitter's former security chief, Peiter "Mudge" Zatko, filed a whistleblower complaint with the Securities and Exchange Commission in July 2022, accusing the microblogging platform company of serious security failings. The accusations amplified the ongoi" PerceptivX

Did Twitter disregard fundamental safety precautions? A cybersecurity professional clarifies a whistleblower's allegations

PerceptivX

Sep 2

Twitter's former security chief, Peiter "Mudge" Zatko, filed a whistleblower complaint with the Securities and Exchange Commission in July 2022, accusing the microblogging platform company of serious security failings. The accusations amplified the ongoing drama of Twitter's potential sale to Elon Musk.

Zatko spent decades as an ethical hacker, private researcher, government adviser and executive at some of the most prominent internet companies and government offices. He is practically a legend in the cybersecurity industry. Because of his reputation, when he speaks, people and governments normally listen – which underscores the seriousness of his complaint against Twitter.

As a former cybersecurity industry practitioner and current cybersecurity researcher, I believe that Zatko's most damning accusations center around Twitter's alleged failure to have a solid cybersecurity plan to protect user data, deploy internal controls to guard against insider threats and ensure the company's systems were current and properly updated.

Zatko also alleged that Twitter executives were less than forthcoming about cybersecurity incidents on the platform when briefing both regulators and the company's board of directors. He claimed that Twitter prioritized user growth over reducing spam and other unwanted content that poisoned the platform and detracted from the user experience. His complaint also expressed concerns about the company's business practices.

CNN interviewed Twitter whistleblower Peiter "Mudge" Zatko.

Alleged security failures

Zatko's allegations paint a disturbing picture of not only the state of Twitter's cybersecurity as a social media platform, but also the security consciousness of Twitter as a company. Both points are relevant given Twitter's position in global communications and the ongoing struggle against online extremism and disinformation.

Perhaps the most significant of Zatko's allegations is his claim that nearly half of Twitter's employees have direct access to user data and Twitter's source code. Time-tested cybersecurity practices don't allow so many people with this level of "root" or "privileged" permission to access sensitive systems and data. If true, this means that Twitter could be ripe for exploitation either from within or by outside adversaries assisted by people on the inside who may not have been properly vetted.

Zatko also alleges that Twitter's data centers may not be as secure, resilient or reliable as the company claims. He estimated that nearly half of Twitter's 500,000 servers around the world lack basic security controls such as running up-to-date and vendor-supported software or encrypting the user data stored on them. He also noted that the company's lack of a robust business continuity plan means that should several of its data centers fail due to a cyber incident or other disaster, it could lead to an "existential company ending event."

These are just some of the claims made in Zatko's complaint. If his allegations are true, Twitter has failed Cybersecurity 101.

Concerns over foreign government interference

Zatko's allegations might also present a national security concern. Twitter has been used to spread disinformation and propaganda in recent years during global events like the pandemic and national elections.

For example, Zatko's report stated that the Indian government forced Twitter to hire government agents, who would have access to vast amounts of Twitter's sensitive data. In response, India's at-times hostile neighbor Pakistan accused India of trying to infiltrate the security system of Twitter "in an effort to curb fundamental freedoms."

Given Twitter's global footprint as a communications platform, other nations such as Russia and China could require the company to hire its own government agents as a condition of allowing the company to operate in their country. Zatko's allegations about Twitter's internal security raise the possibility of criminals, activists, hostile governments or their supporters seeking to exploit Twitter's systems and user data by recruiting or blackmailing its employees may well present a national security concern.

Worse, Twitter's own information about its users, their interests and who they follow and interact with on the platform could facilitate targeting for disinformation campaigns, blackmail or other nefarious purposes. Such foreign targeting of prominent companies and their employees has been a major counterintelligence worry in the national security community for decades.

Opposition party members in India protest Twitter's temporary ban of their leader. The whistleblower's allegations include Twitter acquiescing to Indian government demands that the company employ government agents.

Fallout

Whatever the outcome of Zatko's complaint in Congress, the SEC or other federal agencies, it already is part of Musk's latest legal filings as he tries to back out of his purchase of Twitter.

Ideally, in light of these disclosures, Twitter will take corrective action to improve the company's cybersecurity systems and practices. A good first step the company could take is reviewing and limiting who has root access to its systems, source code and user data to the minimum number necessary. The company should also ensure that its production systems are kept current and that it is effectively prepared to contend with any type of emergency situation without significantly disrupting its global operations.

From a broader perspective, Zatko's complaint underscores the critical and sometimes uncomfortable role cybersecurity plays in modern organizations. Cybersecurity professionals like Zatko understand that no company or government agency likes publicity for cybersecurity problems. They tend to think long and hard about whether and how to raise cybersecurity concerns like these – and what the potential ramifications might be. In this case, Zatko says his disclosures reflect "the job he was hired to do" as head of security for a social media platform that he says "is critical to democracy."

For companies like Twitter, bad cybersecurity news often results in a public relations nightmare that could affect share price and their standing in the marketplace, not to mention attract the interest of regulators and lawmakers. For governments, such revelations can lead to a lack of trust in the institutions created to serve society, in addition to potentially creating distracting political noise.

Unfortunately, how cybersecurity problems are discovered, disclosed and handled remains a difficult and sometimes controversial process, with no easy solution both for cybersecurity professionals and today's organizations.

Richard Forno has received research funding related to cybersecurity from the National Science Foundation (NSF) and the Department of Defense (DOD) during his academic career, and sits on the advisory board of BlindHash, a cybersecurity startup focusing on remedying the password problem.

Comment

Unsubscribe to no longer receive posts from PerceptivX.
Change your email settings at manage subscriptions.

Trouble clicking? Copy and paste this URL into your browser:
https://perceptivx.com/did-twitter-disregard-fundamental-safety-precautions-a-cybersecurity-professional-clarifies-a-whistleblowers-allegations/

Powered by WordPress.com
Download on the App Store Get it on Google Play
at September 02, 2022
Email ThisBlogThis!Share to XShare to FacebookShare to Pinterest

No comments:

Post a Comment

Newer Post Older Post Home
Subscribe to: Post Comments (Atom)

GOOD TROUBLE - ON SALE NOW

Abolish ICE & More from Blessed Bee by HP ͏ ‌     ͏ ‌     ͏ ‌     ͏ ‌     ͏ ‌     ͏ ‌     ͏ ‌     ͏ ‌     ͏ ‌     ͏ ‌    ...

  • [New post] “You Might Go to Prison, Even if You’re Innocent”
    Delaw...
  • Autistic Mental Health Conference 2025
    Online & In-Person ͏     ­͏     ­͏     ­͏     ­͏     ­͏     ­͏     ­͏     ­͏     ­͏     ­͏     ­͏     ­͏     ­͏     ­͏     ­͏     ­͏    ...
  • [Blog Post] Principle #16: Take care of your teacher self.
    Dear Reader,  To read this week's post, click here:  https://teachingtenets.wordpress.com/2025/07/02/aphorism-24-take-care-of-your-teach...

Search This Blog

  • Home

About Me

GenderEqualityDigest
View my complete profile

Report Abuse

Blog Archive

  • January 2026 (36)
  • December 2025 (52)
  • November 2025 (57)
  • October 2025 (65)
  • September 2025 (71)
  • August 2025 (62)
  • July 2025 (59)
  • June 2025 (55)
  • May 2025 (34)
  • April 2025 (62)
  • March 2025 (50)
  • February 2025 (39)
  • January 2025 (44)
  • December 2024 (32)
  • November 2024 (19)
  • October 2024 (15)
  • September 2024 (19)
  • August 2024 (2651)
  • July 2024 (3129)
  • June 2024 (2936)
  • May 2024 (3138)
  • April 2024 (3103)
  • March 2024 (3214)
  • February 2024 (3054)
  • January 2024 (3244)
  • December 2023 (3092)
  • November 2023 (2678)
  • October 2023 (2235)
  • September 2023 (1691)
  • August 2023 (1347)
  • July 2023 (1465)
  • June 2023 (1484)
  • May 2023 (1488)
  • April 2023 (1383)
  • March 2023 (1469)
  • February 2023 (1268)
  • January 2023 (1364)
  • December 2022 (1351)
  • November 2022 (1343)
  • October 2022 (1062)
  • September 2022 (993)
  • August 2022 (1355)
  • July 2022 (1771)
  • June 2022 (1299)
  • May 2022 (1228)
  • April 2022 (1325)
  • March 2022 (1264)
  • February 2022 (858)
  • January 2022 (903)
  • December 2021 (1201)
  • November 2021 (3152)
  • October 2021 (2609)
Powered by Blogger.