Thursday, September 21, 2023
  • About Us
  • Contact Us
  • Write for Us
Digital Tech Blog
  • Home
  • News
  • Tech
  • Business
  • Cryptocurrency
  • Lifestyle
  • Contact Us
  • Write for Us
No Result
View All Result
Digital Tech Blog
  • Home
  • News
  • Tech
  • Business
  • Cryptocurrency
  • Lifestyle
  • Contact Us
  • Write for Us
No Result
View All Result
Digital Tech Blog
No Result
View All Result
Home Business

Twitter whistleblower testifies to Senate of major security flaws: ‘They don’t know what they have’

585
SHARES
3.2k
VIEWS
Share on FacebookShare on Twitter


The whistleblower says a Chinese government spy is working at Twitter

Twitter’s former security chief Peter “Mudge” Zatko testified before a Senate panel on Tuesday that his former employer prioritized profits over addressing security concerns that he said put user information at risk of falling into the wrong hands.

“It’s not an exaggeration to say that an employee of the company could take over the accounts of all the senators in this room,” Zatko told members of the Senate Judiciary Committee, less than a month after his whistle-blowing complaint was made public .

Zatko testified that Twitter lacks basic security measures and has a lax approach to data access among employees, exposing the platform to major risks. As he wrote in his complaint, Zatko said he believes an Indian government agent managed to become an employee at the company, an example of the consequences of lax security practices.

Peter “Mudge” Zatko, former head of security at Twitter, testifies before the Senate Judiciary Committee on Twitter’s data security, on Capitol Hill, September 13, 2022 in Washington, DC.

Kevin Deitch | Getty Images

The testimony adds fuel to criticism from lawmakers that big tech platforms are putting revenue and growth goals ahead of consumer protections. While many companies have gaps in their security systems, Twitter’s unique position as a de facto public square amplified Zatko’s revelations, which took on added significance given Twitter’s litigation with Elon Musk.

Musk tried to buy the company for $44 billion, but then tried to back out of the deal, claiming Twitter should have been more forthcoming with information about how it calculated its percentage of spam accounts. A judge in the case recently said Musk could revise his counterclaims to address issues raised by Zatko.

A Twitter spokesperson disputed Zatko’s testimony and said the company uses access controls, background checks and monitoring and detection systems to control access to data.

“Today’s hearing only confirms that Mr. Zatko’s allegations are riddled with inconsistencies and inaccuracies,” the spokesman said in a statement, adding that the company’s hiring was independent of foreign influence.

Here are the main takeaways from Zatko’s testimony

Lack of control over data

The Twitter logo is seen on the screen of a Redmi phone in this photo illustration in Warsaw, Poland on August 23, 2022.

Nurphoto | Getty Images

According to Zatko, Twitter’s systems are so disorganized that the platform cannot say for sure whether it has completely deleted users’ data. That’s because Twitter hasn’t tracked where all that data is stored.

“They don’t know what data they have, where he lives or where he comes from, so it’s not surprising that they can’t protect him,” Zatko said.

Karim Hijazi, CEO of cyber-intelligence firm Prevailion, said large organizations like Twitter often experience “infrastructure drift” as people come and go and different systems are sometimes neglected.

“Over time, it looks a bit like somebody’s garage,” said Hijazi, who previously served as director of intelligence at Mandiant, now owned by Google. “The problem now is that unlike a garage where you can go into a garage and start taking it apart kind of methodically… you can’t just delete the database because it’s a mosaic of new and old information.”

Removing some parts without knowing for sure whether they are critical parts could risk bringing down the broader system, Hijazi said.

But security experts expressed surprise at Zatko’s testimony that Twitter didn’t even have an environment for testing updates, an intermediate step that engineers can take between a development environment and a production environment to fix problems with its code before to play it live.

“It was quite surprising for a big tech company like Twitter not to have the basics,” Hijazi said. Even the tiniest little startups in the world that launched seven and a half weeks ago have a development environment, a staging environment, and a production environment.”

Chris Lehman, CEO of SafeGuard Cyber ​​and former vice president of FireEye, said “it would be shocking to me” if it were true that Twitter did not have a staging environment.

He said the “most mature organizations” will have this step in place to prevent the systems from breaking the live website.

“Without a stage environment, you create more opportunities for mistakes and problems,” Lehmann said.

Broad employee access to user information

The silhouette of an employee is seen below the Twitter Inc logo

David Paul Morris | Bloomberg | Getty Images

Zatko said the lack of understanding of where the data lives means employees also have far more access than they should to Twitter’s systems.

“It doesn’t matter who has the keys if you don’t have locks on the doors,” Zatko said.

Engineers, who make up a large part of the company, get access to Twitter’s live testing environment by default, Zatko said. He said this kind of access should be limited to a smaller group.

Because so many employees have access to sensitive information, the company is vulnerable to problematic activities such as bribery and hacking, Hijazi and Lehmann said.

US regulators don’t scare companies into compliance

Federal Trade Commission headquarters in Washington, DC

Kenneth Kiesnoski/CNBC

One-time fines, which often result from settlements with U.S. regulators such as the Federal Trade Commission, are not enough to incentivize stricter security practices, Zatko testified.

Zatko told Sen. Richard Blumenthal, D-Conn., that a $150 million settlement like the one Twitter reached with the Federal Trade Commission in May over allegations it misrepresented how it used contact information to target ads would be insufficient , to deter the company from poor security practices.

The company, he said, would be much more concerned about European regulators, who could impose more permanent measures.

“While I was there, the concern was really only about a significantly higher amount,” Zatko said. “Or if it would have been a greater risk of institutional restructuring. But that amount wouldn’t matter much while I was there.’

Peter “Mudge” Zatko, former head of security at Twitter, testifies before the Senate Judiciary Committee on Twitter’s data security, on Capitol Hill, September 13, 2022 in Washington, DC.

Kevin Deitch | Getty Images

Despite the flaws, users shouldn’t necessarily feel pressured to delete their accounts, Zatko and other security experts said.

“People can always choose to just disconnect,” Lehmann said. “But the reality is that social media platforms are platforms for dialogue. And they are the new town square. It serves the public good. I think it would be bad if people just stopped using it.”

Hijazi said there was no point in hiding.

“That’s impossible nowadays,” he said. “However, I think the naivete to believe that these organizations are really in control of this and actually have protected information is wrong.”

Subscribe to CNBC on YouTube.

WATCHING: The changing face of privacy in a pandemic

The changing face of privacy in a pandemic

Share this:

  • Click to share on Facebook (Opens in new window)
  • Click to share on Twitter (Opens in new window)
  • Click to share on Pinterest (Opens in new window)
  • Click to share on LinkedIn (Opens in new window)
  • Click to share on Tumblr (Opens in new window)
Tags: Alphabet class ABreaking News: PoliticsBreaking News: Technologybusiness newsElon MuskHackingMovableNational SecuritypoliticsSocial mediaT-Mobile US Inc.technologyTwitter IncVerizon Communications Inc.
Previous Post

More people should watch the weirdest sci-fi show on Netflix

Next Post

NBA Suns owner Robert Sarver suspended for one year due to workplace harassment and use of racial slurs

admin

admin

Related Posts

Home prices continue to rise with ‘striking’ regional differences, says S&P Case Schiller
Business

Home prices continue to rise with ‘striking’ regional differences, says S&P Case Schiller

by admin
July 25, 2023
Johnson & Johnson is reducing its stake in Kenvue by at least 80% with the swap offer
Business

Johnson & Johnson is reducing its stake in Kenvue by at least 80% with the swap offer

by admin
July 24, 2023
The Space Force raises the stakes as rocket companies compete for lucrative military missions
Business

The Space Force raises the stakes as rocket companies compete for lucrative military missions

by admin
July 22, 2023
The CEO of Kenvue says that consumers are spending on branded health products even when they are declining in other areas
Business

The CEO of Kenvue says that consumers are spending on branded health products even when they are declining in other areas

by admin
July 21, 2023
How BMW uses artificial intelligence to make car assembly more efficient
Business

How BMW uses artificial intelligence to make car assembly more efficient

by admin
July 21, 2023
Next Post
NBA Suns owner Robert Sarver suspended for one year due to workplace harassment and use of racial slurs

NBA Suns owner Robert Sarver suspended for one year due to workplace harassment and use of racial slurs

Please login to join discussion

Recommended

Instagram has called on religious leaders to cancel plans for the children’s app

Instagram has called on religious leaders to cancel plans for the children’s app

February 8, 2022
NFT lending continued its surge with over 18k ETH borrowed in January

NFT lending continued its surge with over 18k ETH borrowed in January

February 18, 2023

Categories

  • Business
  • Cryptocurrency
  • Entertainment
  • News
  • Tech

Don't miss it

Amazon leaders were “okay” with people being secretly signed up for Prime, lawsuit alleges
News

Amazon leaders were “okay” with people being secretly signed up for Prime, lawsuit alleges

September 20, 2023
Temple University Says Acting President JoAnne A. Epps Has Died After Collapsing On Stage
News

Temple University Says Acting President JoAnne A. Epps Has Died After Collapsing On Stage

September 19, 2023
McCarthy’s Plan to Avoid a Shutdown Hits Stiff G.O.P. Opposition
News

McCarthy’s Plan to Avoid a Shutdown Hits Stiff G.O.P. Opposition

September 18, 2023
Billionaire investor Mark Cuban loses $870K in crypto scam
News

Billionaire investor Mark Cuban loses $870K in crypto scam

September 17, 2023
Oracle founder Larry Ellison makes first-ever trip to Microsoft headquarters for cloud announcement
News

Oracle founder Larry Ellison makes first-ever trip to Microsoft headquarters for cloud announcement

September 15, 2023
Trump, DeSantis go head-to-head at key conservative group summits in DC
News

Trump, DeSantis go head-to-head at key conservative group summits in DC

September 15, 2023
Digital Tech Blog

Digital Tech Blog is the fastest growing blogging and article sharing platform where you can read interesting technology blogs and other informative articles related to business, news, cryptocurrency, lifestyle, and various other categories to read.

Categories

  • Business
  • Cryptocurrency
  • Entertainment
  • News
  • Tech

Recent News

Amazon leaders were “okay” with people being secretly signed up for Prime, lawsuit alleges

Amazon leaders were “okay” with people being secretly signed up for Prime, lawsuit alleges

September 20, 2023
Temple University Says Acting President JoAnne A. Epps Has Died After Collapsing On Stage

Temple University Says Acting President JoAnne A. Epps Has Died After Collapsing On Stage

September 19, 2023
  • Contact Us
  • Write for Us
  • Privacy Policy
  • Disclaimer

Copyright © 2021-2023 Digital Tech Blog All Rights Reserved.

No Result
View All Result
  • Home
  • News
  • Tech
  • Business
  • Cryptocurrency
  • Lifestyle
  • Contact Us
  • Write for Us

Copyright © 2021-2023 Digital Tech Blog All Rights Reserved.