Apps

Twitter whistleblower says platform was unable to guard against insider threats on January 6

Comment

illustration of twitter logo, padlock pattern and shields
Image Credits: Bryce Durbin / TechCrunch

Among the many damning allegations in the newly released Twitter whistleblower complaint, is the disquieting revelation that Twitter was unable to seal its production environment to guard against any potential insider threats amid the January 6 attack on the U.S. Capitol. Twitter’s former head of security Peiter “Mudge” Zatko has accused Twitter of serious cybersecurity negligence in an expansive new complaint filed with the Federal Trade Commission (FTC), U.S. Securities and Exchange Commission (SEC) and Justice Department. Among allegations that range from poor data protection to FTC violations, the complaint indicates Twitter lacked the ability to protect itself if any of its own employees went rogue.

This issue was discovered on January 6, after a violent mob attacked the U.S. Capitol Building. As a precaution, Zatko had wanted to lock down Twitter’s internal systems and found that was not an option.

Ex-security chief accuses Twitter of cybersecurity mismanagement in an explosive whistleblower complaint

Zatko said he asked the executive in charge of engineering how Twitter could seal its production environment to keep it protected from any internal threats from staff who may have supported the rioters. The complaint explains that Zatko didn’t want any employees to access or potentially damage the production environment as the Capitol attack was underway.

What he found, however, was that such a lockdown wasn’t just difficult — it was allegedly impossible.

“All engineers had access,” the complaint states. “There was no logging of who went into the environment or what they did. When Mudge [Peiter Zatko] asked what could be done to protect the integrity and stability of the service from a rogue or disgruntled engineer during this heightened period of risk he learned it was basically nothing. There were no logs, nobody knew where data lived or whether it was critical, and all engineers had some form of critical access to the production environment,” the complaint reads.

Twitter hired Zatko in late 2020 to lead the security division following a high-profile attack that compromised the Twitter accounts of several high-profile individuals, including Joe Biden, Bill Gates and Elon Musk. During Zatko’s time at Twitter, the security professional claims to have witnessed a company that lacked basic security controls and procedures, and where around 5,000 people — or half of Twitter’s staff at the time — had been given access to “sensitive live production systems and user data” in order to do their jobs.

A hacker used Twitter’s own ‘admin’ tool to spread cryptocurrency scam

This goes against standard engineering and security principles, which typically lock down access to live production environments. Engineers at tech companies of Twitter’s size would normally utilize staging environments and test data, as opposed to live customer data. Twitter did not, Zatko found. Instead, he discovered that employees built, tested and developed new software directly in production with live customer data and other sensitive information, he said. In addition, much of this access wasn’t monitored or logged, the complaint indicates.

As a result of Twitter’s compromised security, Zatko says it was vulnerable to insider threats during the Capitol insurrection.

The complaint also highlights how Twitter’s lack of logging could have allowed employees to take various actions without being caught. Twitter’s issues around proper logging were already known thanks to the New York State Department of Financial Services (DFS) investigation into the July 15, 2020 hack into the Twitter accounts of cryptocurrency firms and other well-known figures. DFS had discovered that Twitter lacked adequate cybersecurity protections, including “adequate access controls and identity management, and adequate security monitoring.”

In addition, the complaint points out Twitter didn’t have a chief information security officer (CISO) at the time of the 2020 Twitter hack — then the largest hack of a social media platform in history. Zatko had flagged this in the complaint as one of the ways Twitter was in violation of its 2011 FTC Consent Order. (The FTC order had come about after multiple other security incidents in 2009 had allowed hackers to take administrative control of Twitter’s systems. Under the terms of the FTC agreement, Twitter was ordered to establish and maintain a comprehensive information security program that would be assessed by an outside auditor.)

The complaint states Twitter didn’t have either a CISO or an executive versed in information security and privacy engineering when it was attacked in 2020 — just months before the Capitol attack. The company had lost its previous security chief, Mike Convertino, in December 2019 after he left to join a cyber resilience firm, Arceo. Twitter didn’t bring on a replacement until late September 2020, when it hired Rinki Sethi, previously of cloud data management company Rubrik, to serve as CISO. That meant Twitter went for a good part of a year leading up to January 6 without a chief information security officer.

Zatko later joined Twitter in November 2020 to head security.

After breach, Twitter hires a new cybersecurity chief

In the absence of a CISO, Parag Agrawal — then Twitter’s chief technology officer, now CEO — was the key decision-maker for correcting the security vulnerabilities exposed by the 2020 Twitter hack, the complaint said.

Later, both Zatko and Sethi were among those who left the company when Agrawal shook up Twitter’s executive leadership in January of this year after he took over as CEO following Jack Dorsey’s November 2021 departure. Twitter then appointed Lea Kissner as CISO on an interim basis after Sethi left.

Twitter has dismissed Zatko’s whistleblowing as a “false narrative” that’s “riddled with inconsistencies and inaccuracies,” in statements made to the press — including those provided to TechCrunch.

Agrawal has also sent this same message in a memo to company employees, included below.

read more about the Twitter whistleblower on TechCrunch

More TechCrunch

Google’s newest startup program, announced on Wednesday, aims to bring AI technology to the public sector. The newly launched “Google for Startups AI Academy: American Infrastructure” will offer participants hands-on…

Google’s new startup program focuses on bringing AI to public infrastructure

eBay’s newest AI feature allows sellers to replace image backgrounds with AI-generated backdrops. The tool is now available for iOS users in the U.S., U.K., and Germany. It’ll gradually roll…

eBay debuts AI-powered background tool to enhance product images

If you’re anything like me, you’ve tried every to-do list app and productivity system, only to find yourself giving up sooner than later because sooner than later, managing your productivity…

Hoop uses AI to automatically manage your to-do list

Asana is using its work graph to train LLMs with the goal of creating AI assistants that work alongside human employees in company workflows.

Asana introduces ‘AI teammates’ designed to work alongside human employees

Taloflow, an early stage startup changing the way companies evaluate and select software, has raised $1.3M in a seed round.

Taloflow puts AI to work on software vendor selection to reduce cost and save time

The startup is hoping its durable filters can make metals refining and battery recycling more efficient, too.

SiTration uses silicon wafers to reclaim critical minerals from mining waste

Spun out of Bosch, Dive wants to change how manufacturers use computer simulations by both using modern mathematical approaches and cloud computing.

Dive goes cloud-native for its computational fluid dynamics simulation service

The tension between incumbents and fintechs has existed for decades. But every once in a while, the two groups decide to put their competition aside and work together. In an…

When foes become friends: Capital One partners with fintech giants Stripe, Adyen to prevent fraud

After growing 500% year-over-year in the past year, Understory is now launching a product focused on the renewable energy sector.

Insurance provider Understory gets into renewable energy following $15M Series A

Ashkenazi will start her new role at Google’s parent company on July 31, after 23 years at Eli Lilly.

Alphabet’s brings on Eli Lilly’s Anat Ashkenazi as CFO

Tobiko aims to reimagine how teams work with data by offering a dbt-compatible data transformation platform.

With $21.8M in funding, Tobiko aims to build a modern data platform

In 1816, French physician René Laennec invented an instrument that allowed doctors to listen to human hearts and lungs. That device — a stethoscope — eventually evolved from a simple…

Eko Health scores $41M to detect heart and lung disease earlier and more accurately

The number of satellites on low Earth orbit is poised to explode over the coming years as more mega-constellations come online, and it will create new opportunities for bad actors…

DARPA and Slingshot build system to detect ‘wolf in sheep’s clothing’ adversary satellites

SAP sees WalkMe’s focus on automating contextual, in-app support as bringing value to its own enterprise customers.

SAP to acquire digital adoption platform WalkMe for $1.5B

The National Democratic Alliance (NDA) has emerged victorious in India’s 2024 general election, but with a smaller majority compared to 2019. According to post-election analysis by Goldman Sachs, JP Morgan,…

Modi-led coalition’s election win signals policy continuity in India – but also spending cuts

Featured Article

A comprehensive list of 2024 tech layoffs

The tech layoff wave is still going strong in 2024. Following significant workforce reductions in 2022 and 2023, this year has already seen 60,000 job cuts across 254 companies, according to independent layoffs tracker Layoffs.fyi. Companies like Tesla, Amazon, Google, TikTok, Snap and Microsoft have conducted sizable layoffs in the…

18 hours ago
A comprehensive list of 2024 tech layoffs

Featured Article

What to expect from WWDC 2024: iOS 18, macOS 15 and so much AI

Apple is hoping to make WWDC 2024 memorable as it finally spells out its generative AI plans.

19 hours ago
What to expect from WWDC 2024: iOS 18, macOS 15 and so much AI

We just announced the breakout session winners last week. Now meet the roundtable sessions that really “rounded” out the competition for this year’s Disrupt 2024 audience choice program. With five…

The votes are in: Meet the Disrupt 2024 audience choice roundtable winners

The malicious attack appears to have involved malware transmitted through TikTok’s DMs.

TikTok acknowledges exploit targeting high-profile accounts

It’s unusual for three major AI providers to all be down at the same time, which could signal a broader infrastructure issues or internet-scale problem.

AI apocalypse? ChatGPT, Claude and Perplexity all went down at the same time

Welcome to TechCrunch Fintech! This week, we’re looking at LoanSnap’s woes, Nubank’s and Monzo’s positive milestones, a plethora of fintech fundraises and more! To get a roundup of TechCrunch’s biggest…

A look at LoanSnap’s troubles and which neobanks are having a moment

Databricks, the analytics and AI giant, has acquired data management company Tabular for an undisclosed sum. (CNBC reports that Databricks paid over $1 billion.) According to Tabular co-founder Ryan Blue,…

Databricks acquires Tabular to build a common data lakehouse standard

ChatGPT, OpenAI’s text-generating AI chatbot, has taken the world by storm. What started as a tool to hyper-charge productivity through writing essays and code with short text prompts has evolved…

ChatGPT: Everything you need to know about the AI-powered chatbot

The next few weeks could be pivotal for Worldcoin, the controversial eyeball-scanning crypto venture co-founded by OpenAI’s Sam Altman, whose operations remain almost entirely shuttered in the European Union following…

Worldcoin faces pivotal EU privacy decision within weeks

OpenAI’s chatbot ChatGPT has been down for several users across the globe for the last few hours.

OpenAI fixes the issue that caused ChatGPT outage for several hours

True Fit, the AI-powered size-and-fit personalization tool, has offered its size recommendation solution to thousands of retailers for nearly 20 years. Now, the company is venturing into the generative AI…

True Fit leverages generative AI to help online shoppers find clothes that fit

Audio streaming service TuneIn is teaming up with Discord to bring free live radio to the platform. This is TuneIn’s first collaboration with a social platform and one that is…

Discord and TuneIn partner to bring live radio to the social platform

The early victors in the AI gold rush are selling the picks and shovels needed to develop and apply artificial intelligence. Just take a look at data-labeling startup Scale AI…

Scale AI founder Alexandr Wang is coming to Disrupt 2024

Try to imagine the number of parts that go into making a rocket engine. Now imagine requesting and comparing quotes for each of those parts, getting approvals to purchase the…

Engineer brothers found Forge to modernize hardware procurement

Raspberry Pi has released a $70 AI extension kit with a neural network inference accelerator that can be used for local inferencing, for the Raspberry Pi 5.

Raspberry Pi partners with Hailo for its AI extension kit