Twitter’s former security chief says the company lied about bots and security

Twitter has hidden lax security practices, misled federal regulators about its security and failed to properly estimate the number of bots on its platform, according to testimony from the company’s former security chief, the legendary hacker turned cyber security expert Peiter “Mudge”. ” Zatko. The explosive allegations could have huge consequences, including federal fines and the possible disintegration of Tesla CEO Elon Musk’s bid to buy Twitter.

Zatko was fired by Twitter in January and claims it was in retaliation for his refusal to keep quiet about the company’s vulnerabilities. Last month, it filed a complaint with the Securities and Exchange Commission (SEC) accusing Twitter of misleading shareholders and violating an agreement it made with the Federal Trade Commission (FTC) to maintain certain security standards. Their complaints, totaling more than 200 pages, were obtained by CNN and The Washington Post and published in redacted form this morning.

In an interview with CNN, Zatko said he joined Twitter in 2020 from the legacy of then-CEO Jack Dorsey, just after the company was hit by a massive hack in which the accounts of figures like Barack Obama, Bill Gates and Kanye West were affected. committed Zatko says he joined Twitter because he believes the platform is a “critical resource” for the world, but was disillusioned by CEO Parag Agrawal’s refusal to address the company’s numerous security flaws .

“This would never be my first step, but I think I’m still fulfilling my obligation to Jack and to the users of the platform,” Zatko told The Washington Post about his decision to become a whistleblower. “I want to finish the job Jack set me up for, which is to improve the place.”

Zatko’s disclosures to the SEC contain many damning reports and allegations, but these are some of the most significant:

  • Indiscriminate access A big part of Twitter’s vulnerability is that too many employees have access to critical systems, Zatko says in his complaint. It claims that around half of Twitter’s 7,000 full-time employees have access to users’ sensitive personal data (such as phone numbers) and internal software (to alter how the service works) and that this access is not closely monitor It also alleges that thousands of laptops contain complete copies of Twitter’s source code.

  • Fool the FTC. In 2010, Twitter settled charges with the FTC that it failed to protect consumers’ personal information, a significant and early example of government regulators policing big tech. Zatko’s complaint alleges that Twitter has repeatedly made “false and misleading statements” to users and the FTC, in violation of that agreement.

  • Ignoring bots. Twitter has repeatedly claimed that less than 5 percent of its daily monthly active users are bots, fake accounts or spam. Zatko’s complaint says Twitter’s method of measuring that number is misleading and that executives are incentivized (with bonuses of up to $10 million) to increase user numbers instead of weeding out spambots .

  • Government agents Twitter is a key tool for sharing news and organizing protests, making it a ripe target for governments seeking to crack down on dissent. Zatko’s complaint states that he believes the Indian government forced Twitter to hire a government agent, who then had “access to large amounts of sensitive Twitter data.”

  • Failed to delete. The complaint alleges that Twitter has in the past failed to delete user data when requested because those records are too spread across internal systems to be adequately tracked. A current employee told The Washington Post that the company had just completed a project, known as Project Eraser, to ensure the proper deletion of user data.

In response to Zatko’s complaint, Twitter has accused its former security chief of sensationalizing and selectively presenting information. A spokesperson told CNN:

“Mr. Zatko was fired from his senior executive role at Twitter for poor performance and ineffective leadership more than six months ago. While we have not had access to the specific allegations referred to, what we have seen so far is a narrative about our privacy and data security practices that is filled with inconsistencies and inaccuracies and lacks context important The allegations of Mr. Zatko and the opportunistic timing seem designed to grab attention and hurt Twitter, its customers and its shareholders. Security and privacy have long been company-wide priorities at Twitter, and we still have a lot of work ahead of us.”

Zatko’s allegations are explosive and will have a significant effect on the company. The FTC is currently reviewing the complaint, according to sources cited by The Washington Post, and would likely impose significant fines on Twitter if Zatko’s allegations are proven to be true.

The complaint will also affect the ongoing fight between Musk and Twitter. Musk is currently trying to get out of a $44 billion deal to buy the company, justifying the decision with an accusation that Twitter is lying about the actual number of bot and spam accounts on the platform. While it’s unclear whether Zatko’s complaint affects Musk’s legal argument, it will certainly bolster public perception of his case, which is based on the charge that Twitter is underestimating its bots.

Leave a Comment

Your email address will not be published. Required fields are marked *