WebProNews

Tag: Peiter Zatko

  • FTC May Take Action Against Twitter and CEO Over Whistleblower Allegations

    FTC May Take Action Against Twitter and CEO Over Whistleblower Allegations

    Federal Trade Commission Chairwoman Lina Khan opened the door to the possibility of new action against Twitter and CEO Parag Agrawal.

    Peiter “Mudge” Zatko is a well-known hacker who previously served as Twitter’s head of security. Zatko was hired by then-CEO Jack Dorsey before being fired by his successor. Zatko came forward in August to blow the whistle about mismanagement at the company, claiming Twitter and its executives had misled investors about the scope of its bot problem, as well as its security issues.

    Even more concerning, Zatko said the company was in violation of its 2011 settlement with the FTC over security issues. Chairwoman Khan is taking those allegations seriously, opening the door to an investigation into Twitter’s compliance with the terms of the settlement.

    “There has absolutely been a problem with companies treating FTC orders as suggestions,” Khan said during a Senate Judiciary subcommittee hearing, according to MarketWatch. “We have a program underway to really toughen that up.”

    Khan also said she was “extremely disturbed” over the allegations and that the agency would be “looking at this closely.”

    Senator Richard Blumenthal pressed Khan on whether the agency would name Agrawal in any action taken against the company, given Zatko’s claims that Agrawal was aware of the issues and Twitter’s alleged deception.

    “Absolutely,” Khan said. “If we have a basis for naming individuals because we find that they meet the legal standard for that we won’t hesitate to do it.”

  • Twitter Whistleblower Lends Weight to Elon Musk’s Claims

    Twitter Whistleblower Lends Weight to Elon Musk’s Claims

    Peiter Zatko, who served as Twitter’s head of cybersecurity, has filed a complaint with federal agencies and bolstered Elon Musk’s claims.

    Zatko is the famous and well-respected hacker who goes by the handle “Mudge.” He served as Twitter’s cybersecurity head from late 2020, when he was hired by then-CEO Jack Dorsey until he was fired by the current CEO at the beginning of 2022. According to The Washington Post, he claims the company and CEO Parag Agrawal is intentionally misleading investors and regulators about the state of its security and its issues with spam bots.

    “Agrawal’s Tweets and Twitter’s previous blog posts misleadingly imply that Twitter employs proactive, sophisticated systems to measure and block spam bots,” the complaint says. “The reality: mostly outdated, unmonitored, simple scripts plus overworked, inefficient, understaffed, and reactive human teams.”

    That statement, as well as the complaint in general, will certainly bolster Elon Musk’s case against Twitter. The tech mogul is trying to back out of his deal to purchase the social media company based on his belief the company is not being truthful about the scope of its spam bot issues. He also claims the company has misled investors.

    Read more: Elon Musk Accuses Twitter of Running a ‘Scheme’

    Zatko also claims to have found multiple instances where Twitter was in violation of a 2011 settlement with the FTC, failing to implement security measures and properly protect users, as it had been ordered to do. While Twitter claims to have complied with its obligations, the sheer number of security breaches the company has faced — not to mention the ease with which the breaches occurred — lends weight to Zatko’s claims.

    “If all of that is true, I don’t think there’s any doubt that there are order violations,” David C. Vladeck told the Post in an interview. Vladeck is now a Georgetown Law professor but previously served as director of the FTC’s bureau of consumer protection when the settlement was reached in 2011. “It is possible that the kinds of problems that Twitter faced eleven years ago are still running through the company.”

    The complaint alleges Twitter has exceptionally poor security policies in place, policies that leave the company, its intellectual property, and its customers vulnerable to bad actors. Roughly 30% of the company’s laptops allegedly would not automatically update software to receive the latest security fixes. Even worse, Zatko says thousands of laptops had full copies of Twitter’s source code on them, a scenario that is a dream come true for hackers. Why waste time trying to penetrate a carefully secured and protected programming repository when stealing one of the thousands of available laptops will yield the same result?

    See also: Elon Musk’s Twitter Cancellation Letter

    “It’s near-incredible that for something of that scale there would not be a development test environment separate from production and there would not be a more controlled source-code management process,” Tony Sager, former chief operating officer at the cyberdefense wing of the National Security Agency, told the Post. “Almost any attack scenario is fair game and probably easily executed.”

    The Post interviewed more than a dozen current and former employees for context. While some did say the company deployed extensive measures to fight spam, many agreed with much of Zatko’s complaint regarding the general state of security and dysfunction within the company.

    For his part, Zatko sees blowing the whistle on Twitter as the final step in completing the job he was hired to do.

    “This would never be my first step, but I believe I am still fulfilling my obligation to Jack and to users of the platform,” Zatko said. “I want to finish the job Jack brought me in for, which is to improve the place.”

  • Twitter Hires Famed Hacker ‘Mudge’ to Oversee Security

    Twitter Hires Famed Hacker ‘Mudge’ to Oversee Security

    As it continues to deal with security issues and misinformation, Twitter has hired Peiter Zatko, known as Mudge, as head of security.

    Twitter has dealt with a number of embarrassing security breaches and issues over the last few years. In addition, the platform has struggled to deal with the type of misinformation that has plagued social media platforms.

    To help address these challenges, the company has hired famed hacker Peiter Zatko to fill the new role of head of security. Zatko was one of the leaders of famous hacking group Cult of the Dead Cow. He also worked on some of Google’s special projects and served as a program manager at DARPA.

    According to CNBC, Zatko will report to CEO Jack Dorsey and will examine “information security, site integrity, physical security, platform integrity — which starts to touch on abuse and manipulation of the platform — and engineering.”

    Zatko confirmed the news in a Twitter (appropriately) post:

    While Twitter continues to face significant challenges moving forward, some experts are already praising Zatko’s hiring.

    “I don’t know if anyone can fix Twitter’s security, but he’d be at the top of my list,” said Dan Kaufman, who supervised Zatko at DARPA, via CNBC.