2022-09-05 00:00:00

Securityplan|recovery|redundancy|Twitter|updates|whistleblower|Zatko

What small businesses and homes can learn from the Twitter whistleblower

One of the last big decisions Jack Dorsey made before handing over Twitter's CEO responsibilities to Parag Agrawal was to hire a cybersecurity expert to fix the numerous security problems the company has. Peiter "Mudge" Zatko accepted Dorsey's offer, and took the job. After getting to know Twitter's IT operations, he realized he had discovered a house of horrors (from the cybersecurity perspective). In August 2022, Mr Zatko published a 200 page report where he bluntly outlined what was wrong at Twitter. Multiple U.S. authorities are also studying the report, and deeper investigations are expected. We studied the uncovered information to learn how small businesses and home computer users can avoid the mistakes Twitter has made.

The key security points that small businesses and home computer users should take away from the Twitter whistleblower report are responsibility, planning, licensing, and action.

Responsibility

Take true, honest responsibility of all the computers, connected devices and networks you have. When (not if, but when) something goes wrong, such as a ransomware attack locks all data in servers, or someone walks out with the hard disk that contains all the sensitive data, you are responsible for the recovery.

It looks like people in Twitter organization knew about the security problems but carried on, avoiding responsibility and avoiding taking action. In cybersecurity, the key factor is that each and every person behaves responsibly when he or she encounters a phishing attempt, click-this-link request, or is thinking to skip a security update.

Planning

Twitter is a large organization with about 8000 staff that should have a concise a plan how to prevent cyber attacks. Since we know that no one can prevent all attacks, it is also important to have a plan how to recover from security breaches. The faster you recover from a disaster, the faster life returns to normal. Don't be like Twitter, but create your plan by starting from the assumption that you have been hacked. It is an eye-opening exercise.

Licensing

Practically all large organizations are already applying artificial intelligence (AI) and machine learning (ML) into their business processes, Twitter among them. For instance my Twitter account has been locked a few times by a stubborn AI algorithm that believes I have broken the service's Terms of Service. An email message to the support asking them to unlock the account works instantly - no questions asked. I think the only objective for locking the account is to probe if I am a bot.

Anyhow, the whistleblower report claims that Twitter is using machine learning data models and data sets that the company hasn't licensed for their applications. This is a huge risk to take for a business. Ensure all software running in production use has been licensed. Even open source software packages should be checked.

Action

It is a miracle how Twitter has managed to keep on operating without more major security incidents than the ones reported earlier. The whistleblower report describes how half of the company's servers are running on outdated software without any active update processes enabled. The same applies to employee laptops. The company has no redundancy plans to continue operations if, for instance, an entire data center fails. Half of engineers have access to the production system and its data, and there is no way to track if someone does something he shouldn't. Twitter's security and privacy problems discovered in 2011, and sanctioned by authorities, haven't been fixed by 2022.

Small businesses and home computer users can easily do better than Twitter. Simply take action and ensure the vital first steps in every cybersecurity plan have been completed: automatic updates are working, automatic backups are taken, attack prevention is running, recovery processes have been tested, and a redundancy plan reminds how to continue emailing after production accounts have been locked (among other things).


Mr Zatko published his Twitter whistleblower report in August 2022. Its key points has been introduced in many publications, which is why we haven't dived into details of the paper. Read, for instance, Slate or CNN article that both explain the essence of the report.

News

2025-04-23 14:19:00

An unexpected recognition for analog #photography : UNESCO Cultural Heritage designation suggests a renewed appreciation for the craftsmanship and cultural significance of analog methods.https://www.diyphotography.net/analog-photography-recognized-as-intangible-cultural-heritage-by-unesco/


News

2025-04-17 13:18:00

New restriction on Flickr #photo sharing: Free #Flickr accounts will be restricted from downloading original and large-size images. While users will still be able to upload photos of all sizes, free account holders will only be able to download medium and small photos.https://petapixel.com/2025/04/16/flickr-restricting-download-sizes-for-free-accounts/


News

2025-04-16 10:54:00

Morning commute.#streetphotography#travelphotography


News

2025-04-12 09:17:00

The region in #Europe where you will get more #travel days for your euro (or whatever the local currency happens to be). The difference in the average cost is vast between the cheapest and the most expensive European countries.https://klaava.com/here-are-the-cheapest-countries-to-travel-in-europe/


Looks like a perfect spot for a cat to observe the street but no one was home when I passed the window.

2025-04-10 13:35:48

arihak

Looks like a perfect spot for a cat to observe the street but no one was home when I passed the window.


News

2025-04-07 08:50:00

When you take a #photo in RAW format the file is filled with extra data that allows for much richer post-processing, but the #camera world has never actually settled on one standardized RAW format.https://www.theverge.com/tech/640119/camera-raw-spec-format-explained-adobe-dng-canon-nikon-sony-fujifilm


News

2025-04-01 08:39:00

YouTube was the second-biggest media company in the world last year.And in 2025, #YouTube should eclipse #Disney, and become the biggest #media company in the world.https://www.businessinsider.nl/youtube-is-about-to-eclipse-disney-as-the-biggest-media-company-in-the-world/


News

2025-03-28 08:36:00

World Press Photo Contest 2025 ​have just been announced. This year, according to organizers, 59,320 images were submitted for judging, made by 3,778 photographers. #photographyhttps://www.theatlantic.com/photo/2025/03/winners-2025-world-press-photo-contest/682180/


Look around, and love your phone later

2025-03-22 10:17:39

arihak

Look around, and love your phone later


News

2025-03-21 12:50:00

An ancient football stadium?#streetphotography


News

2025-03-11 13:32:00

The World Photography Organisation has announced the category winners and shortlisted photographers for the Sony World #Photography Awards 2025 Open competition.https://www.dpreview.com/articles/0086546939/sony-world-photography-awards-2025-category-winners


News

2025-03-06 16:56:00

Coffee break.#streetphotography


News

2025-02-27 08:22:00

The Sony World #Photography Organisation unveiled the shortlisted entries and finalists in its annual competition’s 10 professional categories.https://edition.cnn.com/2025/02/25/style/sony-world-photography-awards-professional-2025/index.html


Summer heat.

2025-02-26 17:06:07

arihak

Summer heat.


News

2025-02-24 16:42:00

So, Toyota has built a neighborhood for 100 people to live in:Woven City near Mount Fuji is where #Toyota plans to test everyday living with robotics, artificial intelligence and autonomous zero-emissions transportation. #AI #EVhttps://techxplore.com/news/2025-02-rich-cash-japan-automaker-toyota.html


News

2025-02-23 08:46:00

I have written about shady business practices of Airbnb at Klaava.com for years and now ....#Airbnb has turned into a fright show of consumer train wrecks. Every few hours, someone adds a new personally observed outrage to an ongoing litany of allegations, accusations, and perceived swindles.https://www.frommers.com/tips/hotel-news/heres-why-more-and-more-people-are-done-with-airbnb-its-quite-a-list/?utm_source=flipboard&utm_medium=activitypub


News

2025-02-17 17:44:00

In addition to sewing machines and other things, Singer used to make computers.#streetphotography


Breezy beach house

2025-02-13 16:17:25

Breezy beach house


News

2025-02-13 08:29:00

Many of Hong Kong’s basketball courts are located on rooftops. Bell used satellite images to map out potential locations before using his drone to snap photos. #photography #bookhttps://edition.cnn.com/2025/02/12/style/hong-kong-basketball-photography-austin-bell-hnk-intl/index.html


News

2025-02-12 08:39:00

People have nothing better to do than #travel wherever an #influencer tells them to go:A war between a TikTok influencer and Italian ski resorts has escalated after she urged her two million followers to “invade” one destination because she was blamed for causing chaos at another resort. #Italyhttps://edition.cnn.com/2025/02/11/travel/tiktok-hordes-intercepted-by-police-italy-ski-resort/index.html