Twitter Is Full of Cybersecurity Mismanagement, Former Security Chief Says

Twitter Blue Subscribers in New Zealand are Getting the Edit Feature First
Twitter Blue users in New Zealand will be the first ones to utilize the platform's edit button.
Photo : Joshua Hoehne on Unsplash

Twitter may not be the bot-free social media platform Elon Musk thought it was, after all.

The company's former head of security has recently accused it of cybersecurity mismanagement and negligence in a rather explosive whistleblower complaint obtained by CNN and The Washington Post

The complaint also contained mentions of the existence of Twitter bots, which could tank Elon Musk's acquisition of the social media platform.

Twitter Whistleblower Complaint Details

Former Twitter security head Peiter "Mudge" Zatko, who was a hacker-turned-cybersecurity expert, released a complaint about Twitter's negligence and mismanagement of its platform's cybersecurity.

Zatko said in the complaint that he filed to the Securities and Exchange Commission that Twitter's CEO, Parang Agrawal, as well as other executives and directors, have committed "extensive legal violations."

These violations include making misleading statements to users, misrepresentations to investors, and acting with "negligence and even complicity" toward efforts by foreign governments to infiltrate the platform, per the New York Times

Zatko also included in his complaint that Twitter lacks basic security controls, as evidenced by its employees' laptops containing the app's source code. A third of these laptops also blocked automatic security fixes, deactivated system firewalls, and had remote desktop access enabled for non-approved purposes, per Tech Crunch

This lax security control results in employees' willful installation of spyware on work computers at the behest of external organizations.

In addition, Zatko also alleges that about 5,000 full-time employees had broad and unmonitored access to Twitter's internal software, allowing them to tap into sensitive data and alter how the service worked.

Read More: Georgia Court's $1.7 Billion Settlement to Families of Two Truck Crash Victims to be Contested by Ford

Furthermore, Zatko alleges that Twitter's leadership has been misleading government regulators about its security vulnerabilities, as well as its unreliable method of deleting users' data after they opt to end their accounts. 

According to Zatko, Twitter is unable to delete user information as well as expected due to it losing track of the information in question. This loss led them to mislead regulators about whether it deletes the data as required. 

Zatko also revealed that Twitter executives don't have the resources and are not motivated enough to fully understand the number of bots on the company's platform.

This revelation may mean that Twitter's leadership is aware that its platform contains bots but denies it, as doing so will ensure a smooth transaction with SpaceX and Tesla CEO Elon Musk.

You may remember that Elon Musk previously announced he would not honor his part of the acquisition agreement he made with Twitter unless Twitter leadership provided him with the exact number of bots on the platform.

Musk wants to make Twitter a place safe enough for its users to use it, and as such, it shouldn't be a place where they feel harassed.

If Zatko's allegations and revelations are true, Twitter can say goodbye to its acquisition deal with Musk.

Who Is Peiter Zatko?

Zatko was once Twitter's head of security under Jack Dorsey, the company's founder. He joined Twitter in 2020 at Dorsey's bequest following the company's encounter with a massive hack that compromised the accounts of public and popular figures like Barack Obama, Bill Gates, and Kanye West. 

Zatko believes that Twitter's platform is a "critical resource" for the world but became disillusioned by Agrawal to tackle the company's security mismanagement and negligence. 

He was allegedly fired in January because he refused to keep his silence about the company's vulnerabilities. 

Related Article: Twitter Users with Verified Phone Numbers Are Getting a New Special Tag

© 2024 iTech Post All rights reserved. Do not reproduce without permission.

Company from iTechPost

More from iTechPost