By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
CryptoCommunityCryptoCommunity
  • Home
  • General
  • Blockchain
  • Crypto
  • DeFi
  • Metaverse
  • NFT
Search
  • BTC
  • ETH
  • USDT
  • USDC
  • BNB
  • BUSD
  • ADA
  • XRP
  • SOL
  • DOGE
  • DOT
  • MATIC
Reading: Twitter whistleblower says platform was unable to guard against insider threats on January 6 – TechCrunch
Share
Aa
CryptoCommunityCryptoCommunity
Aa
  • Home
  • General
  • Blockchain
  • Crypto
  • DeFi
  • Metaverse
  • NFT
Search
  • Home
  • General
  • Blockchain
  • Crypto
  • DeFi
  • Metaverse
  • NFT
Follow US
© 2022 Foxiz News Network. Ruby Design Company. All Rights Reserved.
CryptoCommunity > Blog > General > Twitter whistleblower says platform was unable to guard against insider threats on January 6 – TechCrunch
General

Twitter whistleblower says platform was unable to guard against insider threats on January 6 – TechCrunch

admin Published August 23, 2022
Last updated: 2022/08/23 at 9:22 PM
Share
SHARE

[ad_1]

Among the many damning allegations in the newly released Twitter whistleblower complaint, is the disquieting revelation that Twitter was unable to seal its production environment to guard against any potential insider threats amid the January 6 attack on the U.S. Capitol. Twitter’s former head of security Peiter “Mudge” Zatko has accused Twitter of serious cybersecurity negligence in an expansive new complaint filed with the Federal Trade Commission (FTC), U.S. Securities and Exchange Commission (SEC), and Justice Department. Among allegations that range from poor data protection to FTC violations, the complaint indicates Twitter lacked the ability to protect itself if any of its own employees went rogue.

This issue was discovered on January 6, after a violent mob attacked the U.S. Capitol Building. As a precaution, Zatko had wanted to lock down Twitter’s internal systems and found that was not an option.

Zatko said he asked the executive in charge of engineering how Twitter could seal its production environment to keep it protected from any internal threats from staff who may have supported the rioters. The complaint explains that Zatko didn’t want any employees to access or potentially damage the production environment as the Capitol attack was underway.

What he found, however, was that such a lockdown wasn’t just difficult — it was allegedly impossible.

“All engineers had access,” the complaint states. “There was no logging of who went into the environment or what they did. When Mudge [Peiter Zatko] asked what could be done to protect the integrity and stability of the service from a rogue or disgruntled engineer during this heightened period of risk he learned it was basically nothing. There were no logs, nobody knew where data lived or whether it was critical, and all engineers had some form of critical access to the production environment,” the complaint reads.

Twitter hired Zatko in late 2020 to lead the security division following a high-profile attack that compromised the Twitter accounts of several high-profile individuals, including Joe Biden, Bill Gates and Elon Musk. During Zatko’s time at Twitter, the security professional claims to have witnessed a company that lacked basic security controls and procedures, and where around 5,000 people — or half of Twitter’s staff at the time — had been given access to “sensitive live production systems and user data” in order to do their jobs.

This goes against standard engineering and security principles which typically lock down access to live production environments. Engineers at tech companies of Twitter’s size would normally utilize staging environments and test data, as opposed to live customer data. Twitter did not, Zatko found. Instead, he discovered that employees built, tested and developed new software directly in production with live customer data and other sensitive information, he said. In addition, much of this access wasn’t monitored or logged, the complaint indicates.

As a result of Twitter’s compromised security, Zatko says it was vulnerable to insider threats during the Capitol insurrection.

The complaint also highlights how Twitter’s lack of logging could have allowed employees to take various actions without being caught. Twitter’s issues around proper logging were already known thanks to the New York State Department of Financial Services (DFS) investigation into the July 15, 2020 hack into the Twitter accounts of cryptocurrency firms and other well-known figures. DFS had discovered that Twitter lacked adequate cybersecurity protections, including “adequate access controls and identity management, and adequate security monitoring.”

In addition, the complaint points out Twitter didn’t have a chief information security officer (CISO) at the time of the 2020 Twitter hack — then the largest hack of a social media platform in history. Zatko had flagged this in the complaint as one of the ways Twitter was in violation of its 2011 FTC Consent Order. (The FTC order had come about after multiple other security incidents in 2009 had allowed hackers to take administrative control of Twitter’s systems. Under the terms of the FTC agreement, Twitter was ordered to establish and maintain a comprehensive information security program that would be assessed by an outside auditor.)

The complaint states Twitter didn’t have either a CISO or an executive versed in information security and privacy engineering when it was attacked in 2020 — just months before the Capitol attack. The company had lost its previous security chief, Mike Convertino, in December 2019 after he left to join a cyber resilience firm, Arceo. Twitter didn’t bring on a replacement until late September 2020, when it hired Rinki Sethi, previously of cloud data management company Rubrik, to serve as CISO. That meant Twitter went for a good part of a year leading up to January 6 without a chief information security officer.

Zatko later joined Twitter in November 2020 to head security.

In the absence of a CISO, Parag Agrawal — then Twitter’s Chief Technology Officer, now CEO — was the key decision maker for correcting the security vulnerabilities exposed by the 2020 Twitter hack, the complaint said.

Later, both Zatko and Sethi were among those who left the company when Agrawal shook up Twitter’s executive leadership in January of this year after he took over as CEO following Jack Dorsey’s November 2021 departure. Twitter then appointed Lea Kissner as CISO on an interim basis after Sethi left.

Twitter has dismissed Zatko’s whistleblowing as a “false narrative” that’s “riddled with inconsistencies and inaccuracies,” in statements made to the press — including those provided to TechCrunch.

Agrawal has also sent this same message in a memo to company employees, included below.



[ad_2]

You Might Also Like

Revyze is building the TikTok of educational videos

YouTube ends the test asking users to get a premium subscription to watch 4K videos

Who is going to buy Cadillac’s $300,000 hand-built EV?

Don’t let today’s software rally improve your mood

Daily Crunch: Kanye West reaches agreement to acquire social media platform Parler

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
[mc4wp_form]
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
admin August 23, 2022
Share this Article
Facebook TwitterEmail Print
Share
Previous Article Elrond Network Watch: Consider This Before Filling Up Your Wallet With EGLD
Next Article As our populations age, this startup is turning live-in care into a gig-economy platform – TechCrunch

Latest News

earn bitcoins fast
How to earn bitcoins fast
crypto
Cryptocurrency is a Scam or Not
How to Tell If a Cryptocurrency is a Scam or Not
crypto
Losing In Cryptocurrency Trading
Tips to Avoid Losing In Cryptocurrency Trading
crypto
Sell Products Online with Bitcoins
How to Sell Products Online with Bitcoins – The Ultimate Guide
crypto

You Might also Like

Revyze is building the TikTok of educational videos

6 Min Read

YouTube ends the test asking users to get a premium subscription to watch 4K videos

2 Min Read

Who is going to buy Cadillac’s $300,000 hand-built EV?

4 Min Read

Don’t let today’s software rally improve your mood

1 Min Read

Crypto Community

  • Home
  • Crypto Calculator
  • Blog
  • Contact Us
  • Privacy Policy
  • Disclaimer
  • Terms and Conditions

Real time Cryptocurrency

  • Crypto Prices
  • Dogecoin price
  • Shibainu coin price
  • Bitcoin Price
  • Cardano Price
  • Litecoins Price

Cryptocurrency Price USD

  • Bitcoin price USD
  • Ethereum price USD
  • Tether price USD
  • BNB Price USD
  • Cardano Price USD
  • Solana Price USD
  • Peps coin Price USD
  • floki inu Price USD
  • SIA coin Price USD
CryptoCommunityCryptoCommunity
Follow US

© 2022 Cryptos Community All Rights Reserved. All logos and images used on this website are registered trademarks of their respective companies. All Rights Reserved. Cryptos Community is not liable for inaccuracies, errors, or omissions found herein. For the removal of copyrighted images, trademarks, or other issues, Contact Us. 


Removed from reading list

Undo
Welcome Back!

Sign in to your account

Lost your password?