Business

Twitter hides major flaws from regulators: ex-security chief

Whistleblower reveals ‘extreme, egregious’ gaps of obsolete servers, vulnerable softwares, frequent hacking attempts

Updated 3 years ago · Published on 24 Aug 2022 10:00AM

Twitter hides major flaws from regulators: ex-security chief
Twitter ex-worker Peiter Zatko warns of obsolete servers, software vulnerable to computer attacks and executives seeking to hide the number of hacking attempts present in the giant social media platform. – AFP pic, August 24, 2022

WASHINGTON – Twitter misled users and US regulators about “extreme, egregious” gaps in its online protections, the platform’s ex-security chief claimed in whistleblower testimony that could impact the court fight over Elon Musk’s buyout bid.

Peiter Zatko’s complaint, which was published yesterday by US media, also accused Twitter of significantly underestimating the number of fake and spam accounts – a crucial point in Musk’s argument for trying to cancel his US$44 billion (RM196 billion) deal to own the platform.

Zatko’s filing to authorities including market watchdog Securities and Exchange Commission accuses Twitter of “negligence, willful ignorance, and threats to national security and democracy.”

The ex-worker, who Twitter says was fired for poor performance, warns of obsolete servers, software vulnerable to computer attacks and executives seeking to hide the number of hacking attempts, both from US authorities and from the company's board of directors.

The hacker-turned-executive, who goes by the nickname “Mudge,” also claims that Twitter prioritises growing its user base over fighting spam and bots, the filing says.

In particular, Zatko accuses the platform and its chief executive Parag Agrawal of issuing untrue statements on account numbers because “if accurate measurements ever became public, it would harm the image and valuation of the company.”

His filing argues that because Twitter reports a tally of users based on who can be reached by advertising – not the actual number of accounts – the true magnitude of spam bots is effectively unknown to the public.

Twitter fired back at its former worker, saying Zatko was fired in January for “ineffective leadership and poor performance.”

“What we’ve seen so far is a false narrative about Twitter and our privacy and data security practices that is riddled with inconsistencies and inaccuracies and lacks important context,” the firm said in a statement.

The “opportunistic timing” of the allegations appears “designed to capture attention and inflict harm on Twitter, its customers and its shareholders,” the statement continued.

A redacted version of the filing was dated July 6, nearly a week before Twitter launched its lawsuit to try to force Musk to close the buyout deal and which is set for trial in mid-October.

Zatko’s legal team called the characterisations of his work and departure from Twitter as “false”, noting he was fired after clashing with the new CEO Agrawal.

‘Dangerous security risks’

The issue of fake accounts is at the heart of the legal battle between Twitter and Tesla chief Musk.

The billionaire has repeatedly accused the company of minimising the number of bot accounts on its platform, and he tweeted yesterday “spam prevalence *was* shared with the board, but the board chose not disclose that to the public…”

Musk is relying on the bot argument to justify abandoning his buyout deal and avoid paying severance, but Twitter’s lawsuit has asserted that it’s too late because the parties already have an agreement.

CNN reported that Zatko has not been in contact with Musk, and that he had begun the whistleblower process before there was any sign of the billionaire’s involvement in Twitter.

“We have already issued a subpoena for Mr. Zatko, and we found his exit and that of other key employees curious in light of what we have been finding,” Musk’s lawyer Alex Spiro told AFP.

The markets were not thrilled with Tuesday’s news and Twitter shares closed down over 7% for the day.

Zatko was hired in late 2020 by the founder and former boss of Twitter, Jack Dorsey, after a massive hack that saw the accounts of major users including Joe Biden, Barack Obama, reality star Kim Kardashian and Musk himself compromised.

Before joining Twitter, Zatko held senior positions at Google and payments processing firm Stripe as well as Darpa, the technological research arm of the Pentagon.

US lawmakers immediately raised concerns about the allegations in Zatko’s filing and have pledged to look into them.

“If these claims are accurate, they may show dangerous data privacy and security risks for Twitter users around the world,” Senator Dick Durbin said in a statement. – AFP, August 24, 2022

Related News

Malaysia / 5mth

Albert Tei or Chegubard, who is the real 'whistleblower'? Azam Baki explains

Malaysia / 11mth

Albert Tei - MACC shielding ‘sharks’, and going after the small fries

Opinion / 11mth

Whistleblower protection: Laws, rights and responsibilities in reporting misconduct

Malaysia / 1y

Sabah mining scandal: Individual not protected under Whistleblower Act

World / 1y

Trump administration seeks approval to fire whistleblower agency head

Malaysia / 1y

Fahmi urges media to cooperate in police probes into news sources

Spotlight

Malaysia

Grandfather charged with raping 12-year-old granddaughter

Malaysia

MACC application to stop Na'imah managing assets in Jersey to be heard on August 13

Malaysia

AI-powered probe uncovers SOCSO fraud syndicate exploiting disabled, identity thefts

Malaysia

Salesman pleads guilty to slashing motorcyclist, causing severe injuries

Malaysia

AirAsia warns job seekers of fake recruitment website stealing personal data, demanding fees

Malaysia

Malaysia Stadium Corporation CEO charged over alleged RM1m bribery solicitation

Malaysia

Johor MB to defend state seat in upcoming polls

By Alfian Z.M. Tahir

You may be interested

Business

US dollar surges to three-month high as Fed signals possible rate hike

Business

US dollar weakens as markets await Warsh's first Fed decision

Business

Greenback surges to thirteen month high

Business

Oil prices slide as US-Iran peace deal raising hopes of supply recovery

Business

KPJ posts strong FY2025 performance, sets sights on next growth phase

By Alfian Z.M. Tahir

Business

Brent crude plummets below US$80 as US-Iran peace deal hopes eclipse Wall Street AI slump