/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Whistleblower complaint: Twitter's ex-head of security Peiter Zatko alleges the company misled the FTC over its security plans, did not protect users, and more

In an explosive whistleblower complaint obtained by The Washington Post, former Twitter security chief Peiter ‘Mudge’ Zatko alleges …

Washington Post

Discussion

  • @donie Donie O'Sullivan on x
    BREAK A former Twitter executive, its head of security, has turned whistleblower. He alleges grave security problems at the company that he says are a risk to national security and democracy. His first TV interview here: https://www.cnn.com/... https://twitter.com/...
  • @rasmus_kleis Rasmus Kleis Nielsen on x
    “A constant state of crisis that does not support the company's broader mission of protecting authentic conversation.” A lot of damning allegations in Twitter whistleblower complaint obtained by @josephmenn @lizzadwoskin @Cat_Zakrzewski (screenshot below) https://www.washingtonpo…
  • @hackingdave Dave Kennedy on x
    “Mr. Zatko was fired from his senior executive role at Twitter for poor performance and ineffective leadership over six months ago,” the Twitter spokesperson said. ^ total bullshit
  • @donie Donie O'Sullivan on x
    NEW: First time Twitter CEO @paraga weighs in on whistleblower story. Sending this message to staff this morning. https://twitter.com/...
  • @typemrt Maurice Turner on x
    Difficult to imagine a long-time hacker going to Congress, DOJ, FTC, & SEC as a whistleblower just for being disgruntled. If @dotMudge is right about Twitter leadership's view of security, then it's going tough to fix. https://twitter.com/...
  • @clancynewyork Eileen Clancy on x
    In information security, Mudge is a living legend. Top engineers, even those who are typically contrarian, respect his brilliance and ethics. This is a big deal. https://twitter.com/...
  • @mktwgoldstein Steve Goldstein on x
    ‘By reporting bots only as a percentage of mDAU, rather than as a percentage of the total number of accounts on the platform, Twitter obscures the true scale of fake and spam accounts on the service, a move Zatko alleges is deliberately misleading.’ $TWTR $TSLA https://twitter.co…
  • @brianhonan @brianhonan on x
    Some interesting comments in this story “Zatko says he found was a company with extraordinarily poor security practices” .. “it was impossible to protect the production environment. All engineers had access. There was no logging of who went into the environment” https://twitter.c…
  • @alecmuffett Alec Muffett on x
    Gosh, deletion wasn't (isn't?) fully automated. Again the comparison of Twitter with Facebook is lacking on the Twitter end. I watched Facebook Deletion Framework (cf: Twitter Project Eraser) being formalised and implemented in ~2014/2015 https://twitter.com/...
  • @alecmuffett Alec Muffett on x
    Many of my peers are fixated on “Facebook == The Great Evil Data Octopus”, but they should realise that in many respects their vitriolic criticisms have worked; e.g. repeated beatings about data deletion → tools being built to formalise data deletion. Now it's Twitter's turn?
  • @vtoubiana Vincent Toubiana on x
    “The whistleblower also alleges Twitter does not reliably delete users' data after they cancel their accounts, in some cases because the company has lost track of the information, and that it has misled regulators about whether it deletes the data as it is required to do” https:/…
  • @wongmjane Jane Manchun Wong on x
    The lack of #DeleteTwitter Tweets after the Twitter whistleblower bombshell report is indicative that we're all stuck on this site
  • @scottnover Scott Nover on x
    I read the entire Twitter whistleblower compliant and the only thing that made me do a double-take was an allegation that the Indian government forced Twitter to put an intelligence agent on its payroll. https://twitter.com/...
  • @hackingdave Dave Kennedy on x
    I've followed @dotMudge and have known him for years. He's in my top 5 people that I look up to in this industry and one of the folks who energized me to be where I am today in my career. His credentials/career are second to none. This is concerning if he is raising this.
  • @justinhendrix Justin Hendrix on x
    Page 1 of many asserting Twitter lied about bots in its disclosure to Elon Musk. This will be very uncomfortable for Twitter's lawyers. https://twitter.com/...
  • @justinhendrix Justin Hendrix on x
    The Post published docs brought forward by the whistleblower, including a 24 page internal assessment of how the company handles threats including disinformation. It finds the company operates “in a constant state of crisis”. https://twitter.com/...
  • @justinhendrix Justin Hendrix on x
    The document says the company was so overwhelmed by misinformation in the 2020 election that it relied on internal “volunteers” and was distracted from other threats. https://twitter.com/...
  • @davetroy Dave Troy on x
    1/Read this story, the whole thing. The litany of allegations is just, well, stunning. Everything from lax internal controls to employing spies, to bending to pressure from Russia. https://www.cnn.com/...
  • @meenakandasamy @meenakandasamy on x
    These revelations (first Facebook now Twitter) are explosive but the state and ruling party apparatus in Delhi have mastered the art of spectacle to such a degree that any discussion about this will be diverted by some thing else. https://twitter.com/...
  • @timcast Tim Pool on x
    Elon finna win that lawsuit https://twitter.com/...
  • @juanandres_gs J. A. Guerrero-Saade on x
    Symptoms of Twitter's security dysfunction are visible from the outside but here they are laid bare by a hacker hero @dotMudge. Foreign agents, unpatched systems, widespread unchecked access, and of course no insensitive to curtail spam, bots, or disinfo. https://www.washingtonpo…
  • @shobz Shoaib Taimur on x
    This does make a lot of sense considering how a lot of Pakistani accounts were targeted. https://twitter.com/...
  • @mattdevost Matt Devost on x
    An example of misaligned incentives that prioritized user growth over improving existing user experience. https://www.washingtonpost.com/ ...
  • @jimhansondc Jim Hanson on x
    I'm hardly a fan of Twitter Execs & Plenty damaging info BUT I read the documents No real evidence of lies or fraud Lots of infighting Lots of bad practices Lots of “You didn't listen to me” BUT That's all the tech firms Where's the censorship info? https://www.washingtonpost.com…
  • @claresduffy Clare Duffy on x
    “Jack Dorsey asked me to come and perform a critical task at Twitter. I signed on to do it and believe I'm still performing that mission.” Twitter's former head of security has become a whistleblower. Much more to come on this. w/ @donie @b_fung https://www.cnn.com/...
  • @jamesrbuk James Ball on x
    “Zatko's complaint says he believed the Indian government had forced Twitter to put one of its agents on the payroll, with access to user data at a time of intense protests in the country.” Bloody *hell*.
  • @jason_kint Jason Kint on x
    Interesting and indeed explosive. Imagine if Facebook would have had a SEC whistleblower in 2015-2018 from its security department (eg Alex Stamos) rather than covering up its scandal until it paid over $5B in 2019 to try to make them go away. Much larger biz and societal risk. h…
  • @pkafka Peter Kafka on x
    CNN's Twitter whistleblower story says it shares the scoop with the Washington Post. Unless I missed it Wapo's story doesn't mention CNN at all. https://twitter.com/...
  • @charlesarthur Charles Arthur on x
    Twitter's former security chief, fired in January, turns whistleblower: says Twitter misled investors, FTC and underplayed spam issues. Twitter says: nope. 84-page complaint has been filed. This is going to be quite the popcorn event. https://www.washingtonpost.com/ ...
  • @josephmenn Joseph Menn on x
    We have also published an alarming external report commission by #Twitter that exposes why it was unable to stop major influence operation.
  • @kevincollier Kevin Collier on x
    Reading Mudge's complaint about Twitter, it's hard to stress how much this bolsters some of Musk's claims about the company failing to fight spam. Comes across either that Musk is unbelievably lucky or he had some insight into such complaints before he filed.
  • @donie Donie O'Sullivan on x
    NEW: Musk lawyer Alex Spiro said they want to talk to Twitter whistleblower. “We have already issued a subpoena for Mr. Zatko, and we found his exit and that of other key employees curious in light of what we have been finding.”
  • @jkosseff Jeff Kosseff on x
    This is very bad, particularly in light of the 2011 FTC agreement. I'm sure that we'll hear more in the next few months. https://twitter.com/... https://twitter.com/...
  • @biannagolodryga Bianna Golodryga on x
    .@vermontgmg's response to security expert Peiter ‘Mudge’ Zatko's allegations against Twitter: “This is a warning from Chuck Yeager saying- I'm worried about the danger of that plane.” https://twitter.com/...
  • @tomgara Tom Gara on x
    Everything's coming up Elon https://twitter.com/...
  • @alecmuffett Alec Muffett on x
    Reading the story about @dotMudge raising a whistleblower complaint against Twitter; it helps explain why I was shocked in a previous job to learn that Twitter bought Smyte outright - bringing them capabilities that I would have presumed they already had... https://twitter.com/..…
  • @migueldeicaza Miguel de Icaza on x
    I will take Mudge's word over any executive and board member at twitter. This is a Standard & Poor AAA-graded shitshow. https://twitter.com/...
  • @kaitlancollins Kaitlan Collins on x
    Huge exclusive from @donie & co: Twitter has major security problems that pose a threat to users' personal info, shareholders, national security & democracy, per a whistleblower disclosure alleging one or more employees may be working for a foreign intel. https://www.cnn.com/...
  • @hexadecim8 @hexadecim8 on x
    The point @dotMudge makes about account security is important. If tweets are considered official record, the security of national security related accounts is as important as any other national security system. https://twitter.com/...
  • @deitaone @deitaone on x
    $TWTR - TWITTER SHARES DOWN 4.5% PREMARKET Ex-Twitter exec blows the whistle, alleging reckless and negligent cybersecurity policies https://cnn.com/...
  • @malwarejake Jake Williams on x
    #HugOps to anyone on the Twitter security and compliance teams who has to deal with the fallout of this. I stand with Mudge in any case. His allegations are credible and everyone always knew “poor performance” was code for “advocating to do things right.” https://www.cnn.com/...
  • @kimzetter Kim Zetter on x
    Twitter says Mudge is “disgruntled employee,” who was fired for poor performance/leadership. But there's probably no security exec with more ethics, more credibility than Mudge. He worked for gov for years, his wife is former NSA. I wrote about them here: https://theintercept.com…
  • @suhasinih Suhasini Haidar on x
    Just in: Twitter whistle blower Zatko's complaint says “he believed the Indian government had forced Twitter to put one of its agents on the payroll, with access to user data at a time of intense protests in the country. ” https://www.washingtonpost.com/ ...
  • @mr_james_c @mr_james_c on x
    Despite having vastly fewer users than Facebook, Twitter has always been a bigger security risk because its media/politics/business-focused user base. https://twitter.com/... https://twitter.com/...
  • @nicoleperlroth Nicole Perlr🌻th on x
    This is very big. @dotMudge, who is incredibly well-respected in the cybersecurity community, alleges @Twitter lacks basic internal security controls, is lying to @elonmusk about the number of fake accounts and bots, and says @paraga fired him for raising red flags. https://twitt…
  • @kimzetter Kim Zetter on x
    “About half of the company's 500,000 servers run on outdated software that does not support basic security features such as encryption for stored data or regular security updates by vendors”
  • @benedictevans Benedict Evans on x
    It's one thing for an ex-employee who wasn't necessarily in the loop to claim a company has huge security holes. It's another thing for the ex, um, Head of Security to say that. https://twitter.com/...
  • @kimzetter Kim Zetter on x
    It was clear when Mudge left Twitter something was wrong. Now he's blowing whistle. Says company doesn't properly delete data, too many staff access central controls/sensitive info; senior execs cover up vulns; some staff may be working for foreign intel https://www.cnn.com/...
  • @_ejvm Enrique Vaamonde on x
    Good luck Twitter. Mudge is well respected and has credibility. https://twitter.com/...
  • @b_fung Brian Fung on x
    NEW: Twitter execs have tried to conceal enormous security vulnerabilities that put users, investors and even US national security at risk, according to a damning new whistleblower report by the company's former head of security: https://www.cnn.com/...
  • @annmlipton @annmlipton on x
    lots of accusations of poor management internally, but that's not a basis to escape the deal either. notice this accusation says the bad proposal was not, in fact, executed: https://twitter.com/...
  • @annmlipton @annmlipton on x
    this is almost exactly what musk alleges in his counter claims. i mean, i am certain his attorneys are capable of coming up with it on their own but it does make you wonder whether they were tipped off, if not by the whistleblower than by someone else https://twitter.com/...
  • @eliclifton Eli Clifton on x
    “Zatko's complaint says he believed the Indian government had forced Twitter to put one of its agents on the payroll, with access to user data at a time of intense protests in the country.” https://www.washingtonpost.com/ ...
  • @riskybusiness Patrick Gray on x
    Jesus... can open, worms everywhere. You basically can't find anyone more credible than @dotMudge in infosec so this is a massive deal https://cnn.com/...
  • @campuscodi Catalin Cimpanu on x
    “Zatko's complaint says he believed the Indian government had forced Twitter to put one of its agents on the payroll, with access to user data at a time of intense protests in the country” via: https://www.washingtonpost.com/ ...
  • @cat_zakrzewski Cat Zakrzewski on x
    “Take a tech platform that collects massive amounts of user data, combine it with what appears to be an incredibly weak security infrastructure and infuse it with foreign state actors with an agenda, and you've got a recipe for disaster,” @ChuckGrassley said.
  • @cat_zakrzewski Cat Zakrzewski on x
    NEW: In an explosive whistleblower complaint, Twitter's former security chief claims the company deceived regulators and its own board about its defenses against hackers and efforts to fight spam. w/ @josephmenn and @lizzadwoskin https://www.washingtonpost.com/ ...
  • @gossithedog Kevin Beaumont on x
    👀👀👀👀👀 https://twitter.com/...
  • @silvermanjacob Jacob Silverman on x
    How can a spam-ridden platform fix itself if execs are incentivizied to increase users no matter what? https://twitter.com/...
  • @b_fung Brian Fung on x
    CNN sent Twitter more than 50 specific questions related to the report, which was sent to the FTC, DOJ, SEC and members of Congress. Twitter provided a number of responses saying, among other things, it has been in compliance with the 2011 FTC order all along. And a statement: ht…
  • @katieharbath Katie Harbath on x
    Huge scoop by ⁦@lizzadwoskin⁩ ⁦@Cat_Zakrzewski⁩ and ⁦@josephmenn⁩ this morning about a whistleblower complaint against Twitter. https://www.washingtonpost.com/ ...
  • @jamesrbuk James Ball on x
    Zatko: “Twitter is grossly negligent in several areas of information security. If these problems are not corrected, regulators, media and users of the platform will be shocked when they inevitably learn about Twitter's severe lack of security basics.”
  • @jamesrbuk James Ball on x
    Zatko was fired in January, but his whistleblower filing is probably the first piece of good news for Musk in his $44 billion lawsuit with Twitter since it was filed. That said, I still think the case will be a *very* difficult one for him.
  • @campuscodi Catalin Cimpanu on x
    ""The company also lacks sufficient redundancies and procedures to restart or recover from data center crashes, Zatko's disclosure says, meaning that even minor outages of several data centers at the same time could knock the entire Twitter service offline, perhaps for good.""
  • @campuscodi Catalin Cimpanu on x
    “About half of the company's 500,000 servers run on outdated software that does not support basic security features such as encryption for stored data or regular security updates by vendors” https://twitter.com/...
  • @b_fung Brian Fung on x
    Among its allegations, the disclosure obtained by CNN claims half of Twitter employees, including all engineers, enjoy excessive access to the live Twitter product and user data, and coding/testing happens right in the product rather than in a sandbox: https://www.cnn.com/...
  • @silvermanjacob Jacob Silverman on x
    Potentially important story about a whistleblower calling out major security problems at Twitter, which leadership has covered up. I think the Saudi spy ring is only a part of this, albeit an important one. https://www.cnn.com/...
  • @oalexanderdk Oliver Alexander on x
    Whistleblower alleging one or more employees at @Twitter probably working for foreign intel. The would not surprise me at all. https://twitter.com/...
  • @cat_zakrzewski Cat Zakrzewski on x
    @josephmenn @lizzadwoskin The whistleblower, Peiter Zatko, is a well-known hacker who goes by Mudge. He says his decision to go public is an extension of his previous work exposing flaws in cybersecurity. @josephmenn has more about his career here https://www.washingtonpost.com/ …
  • @annmlipton @annmlipton on x
    This is certainly well timed for Musk, I must say. https://twitter.com/...
  • @fabiochiusi Fabio Chiusi on x
    “Zatko further alleges that Twitter's leadership has misled its own board and government regulators about its security vulnerabilities, including some that could allegedly open the door to foreign spying or manipulation, hacking and disinformation campaigns” https://twitter.com/.…
  • @wongmjane Jane Manchun Wong on x
    holy s, former Twitter head of security blows the whistle https://www.cnn.com/... https://twitter.com/...
  • @gossithedog Kevin Beaumont on x
    .@dotMudge has gone in hard on Twitter. https://www.washingtonpost.com/ ...
  • @washingtonpost @washingtonpost on x
    The complaint alleges that Chief Executive Parag Agrawal was “lying” when he tweeted in May that the company was “strongly incentivized to detect and remove as much spam as we possibly can.” https://www.washingtonpost.com/ ...
  • @dnvolz Dustin Volz on x
    “The whistleblower document alleges (Twitter) prioritized user growth over reducing spam, though unwanted content made the user experience worse. Executives stood to win individual bonuses of as much as $10 million tied to increases in daily users” https://www.washingtonpost.com/…
  • @washingtonpost @washingtonpost on x
    In addition, the whistleblower complaint says the company prioritized user growth over reducing spam. Executives stood to win individual bonuses of as much as $10 million in part for increases in daily users, and nothing explicitly for cutting spam. https://www.washingtonpost.com…
  • @washingtonpost @washingtonpost on x
    The complaint alleges thousands of employees still had poorly tracked internal access to core company software, a situation that for years had led to embarrassing hacks, including the commandeering of accounts held by Elon Musk and Donald Trump. https://www.washingtonpost.com/ ..…
  • @cat_zakrzewski Cat Zakrzewski on x
    @josephmenn @lizzadwoskin The allegations could factor into the ongoing litigation between the company and Elon Musk, who is trying to prove Twitter broke the contract they made when he agreed to acquire the company https://www.washingtonpost.com/ ...
  • @chancery_daily @chancery_daily on x
    shall we dive into the musk subpoena to jack? it's oddly short-handed, perhaps because they don't want to give away the theory they are chasing? there aren't many specifics, but let's see what we can see— 1/ https://twitter.com/...
  • @claritytoast Nate Anderson on x
    Things are heating up. Looks like Elon Musk officially subpoenaed his friend Jack Dorsey in an effort to prove he oversaw fraud at Twitter. $TWTR https://twitter.com/...
  • @chancery_daily @chancery_daily on x
    last request, but definitely not least — have we seen this concept before? this might be the crux of something re: jack ... the idea of tying mDAU into director or executive comp 👀 /fin https://twitter.com/...
  • @cartoonattorney Harvey Birbman on x
    Since Elon and Jack seem to be friends I'm guessing this is what happened: Jack told Elon ages ago that Twitter bot count is bullshit (along with other details I'm sure). But Jack, being ex-CEO, can't just volunteer damaging information, a subpoena would be required. https://twit…
  • @chancery_daily @chancery_daily on x
    ps — my favorite part of subpoena language is how I'd like to preface all work requests: “all business and excuses being laid aside...” 🤣 also, Dorsey being repped by Munger Tolles & Olson https://twitter.com/...
  • @max_roi Max Roi on x
    @assarsson @KurtWagner8 Elon keeps hitting himself in the face every time he tries to dribble the ball, and when he tried to take a shot he somehow caused a massive tire fire, so he's asking to get a second quarterback assigned to his team.
  • @chancery_daily @chancery_daily on x
    more mDAU identification process document requests 5/ https://twitter.com/...
  • @realmeetkevin Meet Kevin on x
    A subpoena sent by @elonmusk's team to @jack Dorsey might imply Elon's team hasn't yet found a smoking gun of fraud. That bodes well for Twitter and $TWTR. Again, if Elon can prove fraud via below, he will likely win. However, if he cannot find fraud, Elon will own $TWTR soon. ht…
  • @chancery_daily @chancery_daily on x
    this seems potentially interesting — we're going back to January 1, 2019 — kinda makes you wonder about the filing this morning over discovery dates 🤔 3/ https://twitter.com/...
  • @garyblack00 Gary Black on x
    That should scare the $TWTR Board. @Jack knows where all the bodies are buried. @elonmusk $tsla https://twitter.com/...
  • @chancery_daily @chancery_daily on x
    the document requests list is by far the shortest of any of the third-party subpoenas — kind of strikingly so. it's all merger & mDAU in very high-level terms. #3 seems to be going after the same point raised in the briefing we looked at last week re “key metric” 4/ https://twitt…
  • @chancery_daily @chancery_daily on x
    many of the definitions are the standard fare from the other subpoenas in this case — nothing stands out except I thought that Discord had been previously omitted — will have to go back and check in light of the subpoena to Discord this morning... 2/ https://twitter.com/...
  • @anthony Anthony DeRosa on x
    Elon Musk's legal team submitted a subpoena for evidence from former Twitter CEO Jack Dorsey. In April, Dorsey said Musk was “the singular solution I trust” to run Twitter https://www.theverge.com/...
  • @kurtwagner8 Kurt Wagner on x
    Reminder that Jack supported Elon taking a board seat and wrote this tweet in support of Musk on the day the deal was announced [link to @jack's Apr 26 tweet saying “...Elon is the singular solution I trust..."]
  • @sawyermerritt Sawyer Merritt on x
    full article: The notice of subpoena, filed Monday, came amid a flurry of filings that also included notice of subpoenas served by Musk on Kayvon Beykpour, former head of consumer product at Twitter, and Bruce Falck, formerly in charge of revenue product. https://www.bloomberg.co…
  • @caseynewton Casey Newton on x
    The messages between them where Jack pitches Elon on doing this are going to be SO delicious, I can't even tell you https://twitter.com/...