Whistle-blower accuses Twitter of cybersecurity negligence
A former head of security at Twitter alleged that the company misled regulators about its cybersecurity defences, privacy protections, and ability to detect and root out fake accounts, according to a whistle-blower complaint filed with US officials.
The revelation could create serious legal and financial problems for the social media platform, which is currently attempting to force Tesla CEO Elon Musk to consummate his US$44 billion offer to buy the company.
Peiter Zatko, Twitter’s security chief until fired early this year, filed complaints last month with the US Securities and Exchange Commission, the Federal Trade Commission (FTC), and the Department of Justice. The legal nonprofit Whistleblower Aid, working with Zatko, confirmed the authenticity of a redacted copy of the complaint posted online by The Washington Post.
Among Zatko’s most serious accusations are that Twitter violated the terms of a 2011 FTC settlement by falsely claiming that it had strong security measures in place to protect the security and privacy of its users. Zatko also accuses the company of deceptions involving its handling of “spam” or fake accounts. This allegation is at the core of Musk’s attempt to back out of the Twitter takeover.
Better known by his hacker handle “Mudge”, Zatko is a highly respected cybersecurity expert who first gained prominence in the 1990s and later worked in senior positions at the Pentagon’s Defense Advanced Research Agency and Google.
The 84-page complaint describes a broken corporate culture at Twitter that lacked good leadership and where Zatko said top executives practised “deliberate ignorance” of pressing problems. His description of Jack Dorsey’s leadership style is particularly scathing, saying the Twitter founder was “extremely disengaged” during the last months of his tenure as CEO to the point where he would not even speak during meetings on complex issues facing the company.
Among Zatko’s damning accusations of cybersecurity malpractice: Software and security updates were disabled on more than a third of employees’ computers — unduly exposing them to malware — and it was common for people to install “whatever software they wanted on their work systems”. Such lapses are typically considered cardinal sins in cybersecurity.
Zatko also describes “deliberate ignorance” by Twitter executives on counting the millions of accounts that are automated “spam bots” or otherwise have no value to advertisers because there is no person behind them.
Alex Spiro, an attorney representing Musk in his effort to back out of his Twitter acquisition deal, said lawyers had issued a subpoena for Zatko. “We found his exit and that of other key employees curious in light of what we have been finding,” Spiro wrote in an e-mail Tuesday. Spiro said Zatko and Musk have not been in contact this year.