/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Whistleblower complaint: Twitter's ex-head of security Peiter Zatko alleges the company misled the FTC over its security plans, did not protect users, and more

Washington Post

Context & Ripple Effects

The allegations expand a dispute already documented in the earlier complaint coverage from product and operational concerns into a question of whether Twitter's security commitments to the FTC matched its internal practices. A companion report also tied the complaint to alleged weak controls over sensitive user data through an India-related hiring demand.

Twitter's leadership subsequently issued a public rejection of Zatko's account, while employee interviews in related coverage described some allegations as lacking context. The dispute therefore became a contest over both the company's security record and the credibility of the whistleblower's evidence.

First-order effects

  • Twitter must defend its security planning and user-protection practices against allegations that directly implicate its commitments to the FTC.
  • Peiter Zatko's complaint puts Twitter's internal security decisions under scrutiny from the FTC, employees, and public officials, even as the company disputes his account.

Second-order effects

  • Twitter's executive rebuttal and conflicting employee accounts shift attention toward documentation and corroboration, rather than allowing either the complaint or the company's denial to settle the record alone.
  • The allegation concerning potential access to sensitive user data broadens the dispute from compliance planning to platform exposure to government-linked personnel.

Third-order effects

  • The subsequent Senate testimony shows how security whistleblower claims at major platforms can move from an employer-regulator dispute into congressional oversight.
  • If such complaints continue to surface, platforms' security representations to regulators will face more pressure to be demonstrable through internal controls rather than high-level plans.

The trend: Platform security is becoming an accountability issue spanning whistleblowers, regulators, corporate leadership, and lawmakers.

Discussion

  • Vox Sara Morrison on x
    Twitter's whistleblower problem is way bigger than Elon Musk's bot complaints
  • @donie Donie O'Sullivan on x
    NEW: First time Twitter CEO @paraga weighs in on whistleblower story. Sending this message to staff this morning. https://twitter.com/...
  • @alsutton Al Sutton on x
    If you are wondering if the stuff about Twitter security being lapse is just one person complaining, you might be interested to know that, 18 months after being let go from the company, I've not been removed from their employees GitHub commiters group. https://github.com/... http…
  • @elonmusk Elon Musk on x
    [Image of Jiminy Cricket: “Give a little whistle"]
  • @donie Donie O'Sullivan on x
    BREAK A former Twitter executive, its head of security, has turned whistleblower. He alleges grave security problems at the company that he says are a risk to national security and democracy. His first TV interview here: https://www.cnn.com/... https://twitter.com/...
  • @kimzetter Kim Zetter on x
    Twitter says Mudge is “disgruntled employee,” who was fired for poor performance/leadership. But there's probably no security exec with more ethics, more credibility than Mudge. He worked for gov for years, his wife is former NSA. I wrote about them here: https://theintercept.com…
  • @gerritd Gerrit De Vynck on x
    oh, and apparently Twitter almost went down for good in 2021 https://twitter.com/...
  • @justinhendrix Justin Hendrix on x
    The document says the company was so overwhelmed by misinformation in the 2020 election that it relied on internal “volunteers” and was distracted from other threats. https://twitter.com/...
  • @igb Ian Brown on x
    I remember when Mudge had us send Twitter kernel and OS reports to a rando buddy of his in Texas.
  • @caseynewton Casey Newton on x
    Holy shit https://t.co/wGcjgqsLJj https://t.co/TKeNLLnyFK
  • @benedictevans Benedict Evans on x
    It is possible to believe both that Elon Musk's case against Twitter is mostly bullshit, and also believe that Twitter is an extraordinarily badly run and dysfunctional company.
  • @kimzetter Kim Zetter on x
    PSA: When someone contacts you to ask your opinion of the Twitter whistleblower story, you don't have to give an opinion. Especially if you're not a security expert. You also don't have to have an opinion if you don't know enough facts yet. It's okay to just say “I don't know.”
  • @kimzetter Kim Zetter on x
    It was clear when Mudge left Twitter something was wrong. Now he's blowing whistle. Says company doesn't properly delete data, too many staff access central controls/sensitive info; senior execs cover up vulns; some staff may be working for foreign intel https://www.cnn.com/...
  • @nicoleperlroth Nicole Perlr🌻th on x
    When @jack was dividing his time between Twitter and Square, I asked him about the fact security researchers were constantly finding gaps in their security. I never forgot his reply: “Those guys like to whine a lot.” Security is a culture and it requires buy-in from the top. http…
  • @senatordurbin Senator Dick Durbin on x
    The whistleblower's allegations of widespread security failures at Twitter, willful misrepresentations by top executives to government agencies, and penetration of the company by foreign intelligence raise serious concerns. https://twitter.com/...
  • @nicoleperlroth @nicoleperlroth on x
    Maybe @twitter's board made a mistake relying on a CEO who also happened to be CEO of another $100B+ company? Just a thought. https://twitter.com/...
  • @frankpallone Rep. Frank Pallone on x
    As Chairman of @EnergyCommerce, I'm carefully reviewing this whistleblower disclosure and assessing next steps. These allegations are alarming and reaffirm the need to pass my comprehensive privacy legislation to protect Americans' online data. #ADPPA https://twitter.com/...
  • @robertmlee Robert M. Lee on x
    Hey @Twitter while y'all deal with the @dotMudge allegations resorting to a smear campaign against him is a really stupid idea. His character, skills, leadership, etc. are some of the most beloved and well documented in the community. Your response is telling. Focus on the facts.
  • @riskybusiness Patrick Gray on x
    Jesus... can open, worms everywhere. You basically can't find anyone more credible than @dotMudge in infosec so this is a massive deal https://cnn.com/...
  • @nicoleperlroth @nicoleperlroth on x
    By reverting to “disgruntled” and “poor performance,” Twitter PR and @paraga grossly underestimated how well respected @dotmudge is at the highest levels of gov, cybersecurity, etc. Shot themselves in the foot big time. https://twitter.com/...
  • @justinhendrix Justin Hendrix on x
    The Post published docs brought forward by the whistleblower, including a 24 page internal assessment of how the company handles threats including disinformation. It finds the company operates “in a constant state of crisis”. https://twitter.com/...
  • @b_fung Brian Fung on x
    NEW: Twitter execs have tried to conceal enormous security vulnerabilities that put users, investors and even US national security at risk, according to a damning new whistleblower report by the company's former head of security: https://www.cnn.com/...
  • @hackingdave Dave Kennedy on x
    I've followed @dotMudge and have known him for years. He's in my top 5 people that I look up to in this industry and one of the folks who energized me to be where I am today in my career. His credentials/career are second to none. This is concerning if he is raising this.
  • @kimzetter Kim Zetter on x
    “About half of the company's 500,000 servers run on outdated software that does not support basic security features such as encryption for stored data or regular security updates by vendors”
  • @jkosseff Jeff Kosseff on x
    This is very bad, particularly in light of the 2011 FTC agreement. I'm sure that we'll hear more in the next few months. https://twitter.com/... https://twitter.com/...
  • @kaitlancollins Kaitlan Collins on x
    Huge exclusive from @donie & co: Twitter has major security problems that pose a threat to users' personal info, shareholders, national security & democracy, per a whistleblower disclosure alleging one or more employees may be working for a foreign intel. https://www.cnn.com/...
  • @erratarob Robᵉʳᵗ Graham on x
    This statement alone is how you know Mudge is at fault here. “Updated software” is a cybersecurity fetish promoted by Holy Warriors. There's actually no need for such servers to be kept up-to-date. https://twitter.com/...
  • @migueldeicaza Miguel de Icaza on x
    Way worse than originally reported. Read the internal report on security from Mudge and the whistleblower filing, link below. Twitter has the security of a mom and pop bodega. And the new CEO covered it up from the board and regulators. https://www.washingtonpost.com/ ...
  • @walterkirn Walter Kirn on x
    This kind of thing must be assumed now, in all social media environments. https://twitter.com/...
  • @carnage4life Dare Obasanjo on x
    Every big company is actually a dumpster fire behind the scenes but this truly takes the cake. https://twitter.com/...
  • @erratarob Robᵉʳᵗ Graham on x
    🧵I'm reading through the documents. I'm pretty sure that I would take Twitter's side in this dispute. Mudge has some valid concerns here and there, but it's overwhelmed by the infosec attitude of Cybersecurity being some sort of Moral Crusade. https://dy1ywzohuuzsd.cloudfront.net…
  • @troyhunt Troy Hunt on x
    Oh boy: https://twitter.com/...
  • @ashleevance Ashlee Vance on x
    Chef's kiss to this Twitter whistleblower photo in the Post. He's such a good hacker that he's in the matrix https://twitter.com/...
  • @ahtraelnashar @ahtraelnashar on x
    Ranking member of Senate Intelligence Committee @marcorubio statement to me on Twitter whistleblower: https://twitter.com/...
  • @thezedwards Zach Edwards on x
    Interesting process to redact an external audit so that you can't be held accountable to the findings: “Twitter counsel explicitly told Mudge that this was intended to hide the findings and prevent them from becoming known internally or externally” https://twitter.com/...
  • @cbouzy Christopher Bouzy on x
    “The whistleblower also says Twitter executives don't have the resources to fully understand the true number of bots on the platform...” Several times, I went on the record and said the less than 5% number was BS. https://www.cnn.com/... https://twitter.com/...
  • @litmoose Moose on x
    Only two things I will say on this: 1. I believe Mudge. 2. Do. Not. Put. Any. Sensitive. Intel. On. Social. Media. Don't transmit your personal info in DM's, don't discuss work, don't don't dont. <3 https://www.cnn.com/...
  • @dalitdiva Dalit Diva on x
    We need accountability from @Twitter on the issues raised by this whistleblower. @paraga what is your response for millions of Indian users whose data and safety were compromised? https://www.washingtonpost.com/ ...
  • @karaswisher Kara Swisher on x
    Odd thing: most of the best know CISOs and cyber voices i folo have been pretty silent on this.
  • @senmarkey Ed Markey on x
    We can't let Twitter and Big Tech break the rules again and again. Whistleblower allegations that Twitter has repeatedly failed to take basic security measures and misled investors, regulators, and the public demand immediate action. We need accountability now. https://twitter.co…
  • @jordanschachtel @jordanschachtel on x
    Whistleblowers blow the whistle on the government to bring information to the people. They do not report people to the government. Keep this in mind when you see reports about a Facebook or Twitter whistleblower. It's a state-run op to empower the state & steal your rights.
  • @ewerickson Erick Erickson on x
    “Zatko also alleges that Twitter's top executives have misled users, regulators and even the company's own board about the condition of its information security.” https://www.cnn.com/...
  • @smdiehl Stephen Diehl on x
    Honestly, Twitter probably should not exist. I don't see any path towards it ever being either a sustainable business or a net positive in the world. The only saving grace is that it's less malign force than Facebook, which isn't saying much. https://techcrunch.com/...
  • @kantrowitz Alex Kantrowitz on x
    From the Twitter whistleblower doc: “Executives are incentivized to avoid counting spam bots as mDAU, because mDAU is reported to advertisers, and advertisers use it to calculate the effectiveness of ads.” This point does not help Elon Musk at all. It hurts him. https://twitter.c…
  • @rasmus_kleis Rasmus Kleis Nielsen on x
    “A constant state of crisis that does not support the company's broader mission of protecting authentic conversation.” A lot of damning allegations in Twitter whistleblower complaint obtained by @josephmenn @lizzadwoskin @Cat_Zakrzewski (screenshot below) https://www.washingtonpo…
  • @eff @eff on x
    The Twitter whistleblower complaint raises questions about how well the company is managing security and employees' access to production systems handling user data. https://www.washingtonpost.com/ ...
  • @kennwhite Kenn White on x
    That speculation is explicitly contradicted by Mudge's attorney (and founder of the whistleblower foundation) who's on record asserting that the process “began before there was any indication of Musk's involvement with Twitter.” https://www.cnn.com/... https://twitter.com/...
  • @faizsays Faiz Siddiqui on x
    NEW: Former head of security accuses Twitter of “Lying about Bots to Elon Musk,” though he provides little hard evidence of his claim in a whistleblower complaint. 6 legal experts say allegations of misleading shareholders could bolster Musk's case. https://www.washingtonpost.com…
  • @rupakchatto Rupak Chattopadhyay on x
    Incredible story. Sour grapes from #bezos for failing to crack the Indian market?? Of course for most who have grown up in the global south, @washingtonpost has about the same credibility as @engpravda https://twitter.com/...
  • @gossithedog Kevin Beaumont on x
    .@dotMudge has gone in hard on Twitter. https://www.washingtonpost.com/ ...
  • @meenakandasamy @meenakandasamy on x
    These revelations (first Facebook now Twitter) are explosive but the state and ruling party apparatus in Delhi have mastered the art of spectacle to such a degree that any discussion about this will be diverted by some thing else. https://twitter.com/...
  • @malwarejake Jake Williams on x
    #HugOps to anyone on the Twitter security and compliance teams who has to deal with the fallout of this. I stand with Mudge in any case. His allegations are credible and everyone always knew “poor performance” was code for “advocating to do things right.” https://www.cnn.com/...
  • @b_fung Brian Fung on x
    Among its allegations, the disclosure obtained by CNN claims half of Twitter employees, including all engineers, enjoy excessive access to the live Twitter product and user data, and coding/testing happens right in the product rather than in a sandbox: https://www.cnn.com/...
  • @juanandres_gs J. A. Guerrero-Saade on x
    Symptoms of Twitter's security dysfunction are visible from the outside but here they are laid bare by a hacker hero @dotMudge. Foreign agents, unpatched systems, widespread unchecked access, and of course no insensitive to curtail spam, bots, or disinfo. https://www.washingtonpo…
  • @blackamazon @blackamazon on x
    Mind you while folks were laughing and “high powered non profits and “experts” were meeting with Twitter and calling us stupid Twitter it self knew it wasn't meeting the goal AND y'all kept lionizing folks inside for making a. Come up off of ignoring it https://twitter.com/...
  • @sassycrass @sassycrass on x
    Hey, @Twitter @TwitterSupport. Hey. Hey, girl. I first asked y'all to hire me to clean this up for y'all 8 years ago. I would have asked for $85K per annum - ceiling. Meanwhile? Ignoring and disrespecting me and my friends just MIGHT have cost you $44 billion. https://twitter.com…
  • @migueldeicaza Miguel de Icaza on x
    I will take Mudge's word over any executive and board member at twitter. This is a Standard & Poor AAA-graded shitshow. https://twitter.com/...
  • @hypatiadotca Leigh Honeywell on x
    Good morning to west coast folks waking up to the Twitter whistleblower news. Twitter's damage control throws Mudge under the bus real hard. Not sure who _could_ be an effective leader when they only get 50 words out of their boss in 1+ years, though https://twitter.com/...
  • @cbouzy Christopher Bouzy on x
    This message from Twitter's CEO to his staff sounds Trumpian. Wow... https://twitter.com/...
  • @cat_zakrzewski Cat Zakrzewski on x
    More from Congress: Sen. Blumenthal sends a letter to the FTC, calling Lina Khan to investigate the Twitter allegations and bring enforcement actions — including fines https://www.documentcloud.org/ ...
  • @0xmatt @0xmatt on x
    The sole comment I will make on the current drama is that it is possible and rational to have trust & respect for both Mudge (former) AND Lea (current). Lea's credibility and attempts to hire for positive impact are not lessened by Mudge's revelations.
  • @mmasnick Mike Masnick on x
    Not yet sure what to make of all the Mudge disclosures, many of which sound credible. But his whistleblowing report on the whole Musk, Agrawal bit stuff is just as misleading as he claims Agrawal was. Everyone is talking about different things.
  • @annmlipton @annmlipton on x
    This is certainly well timed for Musk, I must say. https://twitter.com/...
  • @mims Christopher Mims on x
    The October Musk/Twitter trial is an event horizon beyond which no prognosticator can see the future https://twitter.com/...
  • @davepell Dave Pell on x
    I want Elon not to own Twitter. I want Twitter run by an adult who thinks they are the best person to run Twitter. Today's whistle blower assertions seem like a step in the right direction.
  • @cat_zakrzewski Cat Zakrzewski on x
    NEW: In an explosive whistleblower complaint, Twitter's former security chief claims the company deceived regulators and its own board about its defenses against hackers and efforts to fight spam. w/ @josephmenn and @lizzadwoskin https://www.washingtonpost.com/ ...
  • @melissaryan Melissa Ryan on x
    Ooof. Justin's Twitter thread has all the highlights and they're not good at all. https://twitter.com/...
  • @kimzetter Kim Zetter on x
    “John Tye, founder of Whistleblower Aid and Zatko's lawyer, told CNN that Zatko has not been in contact with Musk, and said Zatko began the whistleblower process before there was any indication of Musk's involvement with Twitter.”
  • @jeremiahg Jeremiah Grossman on x
    It just became substantially harder for Twitter to recruit top security talent.
  • @nataliaantonova Natalia Antonova on x
    My fellas and fly ladies, this is why I keep telling you that Twitter DMs are not secure. Don't share sensitive info via Twitter DMs. https://twitter.com/...
  • @jstrauss @jstrauss on x
    Now do Experian! https://twitter.com/...
  • @lizzadwoskin Elizabeth Dwoskin on x
    This has big implications for the Musk trial, though ?? how it will play out cause a) the biggest revelations are about security b) the spam section is largely recollections, not docs. Still gonna be massive. https://www.washingtonpost.com/ ...
  • @thepacketrat Sean Gallagher on x
    Deep respect for @dotMudge , and I personally experienced some of the problems with @Twitter's platform security 2 years ago...and honestly, this is what I would have expected. Hard to root for anybody in the Musk/Twitter battle, because both sides are 🗑️ https://www.washingtonpo…
  • @caseynewton Casey Newton on x
    Jack's dereliction of duty here is amazing https://twitter.com/...
  • @quinnypig Corey Quinn on x
    It's unclear to me that Twitter's comms folks adequately thought this cunning plan all the way through. https://twitter.com/...
  • @hackingdave Dave Kennedy on x
    “Mr. Zatko was fired from his senior executive role at Twitter for poor performance and ineffective leadership over six months ago,” the Twitter spokesperson said. ^ total bullshit
  • @typemrt Maurice Turner on x
    Difficult to imagine a long-time hacker going to Congress, DOJ, FTC, & SEC as a whistleblower just for being disgruntled. If @dotMudge is right about Twitter leadership's view of security, then it's going tough to fix. https://twitter.com/...
  • @clancynewyork Eileen Clancy on x
    In information security, Mudge is a living legend. Top engineers, even those who are typically contrarian, respect his brilliance and ethics. This is a big deal. https://twitter.com/...
  • @mktwgoldstein Steve Goldstein on x
    ‘By reporting bots only as a percentage of mDAU, rather than as a percentage of the total number of accounts on the platform, Twitter obscures the true scale of fake and spam accounts on the service, a move Zatko alleges is deliberately misleading.’ $TWTR $TSLA https://twitter.co…