Former head of security at Twitter, Peter Zatko, sent an 84-page document to the Securities and Exchange Commission, the Department of Justice and the Federal Trade Commission of the United States, saying that the administration of the social network is misleading regulators about its protection against hackers and spam accounts, writes.
Better known as the hacker " In particular, he said that he had repeatedly warned the employer about the deplorable state of cybersecurity of the platform: more than half of Twitter servers, according to him, are running outdated and dangerous software.. This does not allow the service to provide sufficiently reliable protection against cybercriminals and spammers..
Twitter is extremely vulnerable to exploitation by foreign governments in a way that threatens US national security, Mudge says, and may even employ foreign spies..
A combination of weak cybersecurity controls and poor analytics has repeatedly exposed Twitter to multiple risks from foreign intelligence agencies..
Zatko alleges that Twitter executives, including current CEO Parag Agrawal, are deliberately putting Twitter users and employees at risk, from receiving money from unreliable Chinese sources to offering the company to comply with Russian censorship and surveillance demands..
Journalists took to Twitter for comment, but Twitter did not respond to a question about the risks of foreign intelligence. A spokesman for the company only said that Zatko's allegations are "
Zatko turned over the information he has to authorities last month after what he says months of unsuccessful attempts to sound the alarm on Twitter about the dangers he faces..
According to the document, in the months before Russia invaded Ukraine, Agrawal, then Twitter's chief technology officer, was willing to make significant concessions to the Kremlin in exchange for the opportunity to operate and increase the number of users in Russia..
Though the idea was eventually scrapped, Zatko still sees it as a worrying sign of how far Twitter is willing to go in its pursuit of users..
"
The platform is also in trouble in China, with the company allegedly accepting funding from unnamed "
"
[see_also ids\u003d"
Zatko's 80-page statement outlining his allegations, along with nearly two dozen additional supporting documents, were made public just two weeks after the former Twitter manager was convicted of spying for Saudi Arabia.. He allegedly abused his access to Twitter data to collect information on suspected Saudi dissidents, including phone numbers and email addresses, and allegedly passed this information on to the Saudi government..
[see_also ids\u003d"
This security hole, first discovered in 2019, highlights the seriousness of Zatko's allegations that describe Twitter as an organization with alarmingly weak cybersecurity oversight.. In order to do their job, about half of Twitter employees have excessive permissions that give access to user data.. Every engineer at the company, Zatko claims, has a complete copy of Twitter's source code on their laptop..
The ex-employee's statement also alleges that Twitter has no control over and often does not know what employees can do on their work computers.. Data released by Zatko from Twitter's internal cybersecurity panels shows that four out of 10 employee devices, i.e. thousands of laptops, lack basic protections such as firewalls and automatic software updates.. Employees may also install third party software on their computers, which has repeatedly led to unauthorized third party installation of unauthorized spyware on devices.
Inappropriate access and limited oversight of employee behavior creates opportunities for insider threats, as exemplified by the Saudi operative, but the Saudi government was not alone in seeking more access to Twitter's internal systems, Zatko said..
[see_also ids\u003d"
India, Nigeria, and Russia, with varying degrees of success, sought to get Twitter to hire local workers who could be used as leverage.. Corporate and user data stored on or accessed by employees may be at risk of access or confiscation by local authorities. Workers themselves, or their families, may be threatened or coerced.
U.S. Senate Intelligence Committee spokeswoman Rachel Cohen said the committee has received Zatko's complaint and is working to arrange a meeting "
Senator Dick Durbin, Democrat of Illinois, said the allegations, if true, could represent dangerous data privacy and security risks for Twitter users around the world..
As reported, in July, the microblogging service Twitter experienced a global failure..