0

Twitter whistleblower tells Congress and FTC that a major security problem hasn’...

 1 year ago
source link: https://siliconangle.com/2023/01/24/twitter-whistleblower-tells-congress-ftc-major-security-problem-hasnt-gone-away-elon-musk/
Go to the source link to view the article. You can view the picture content, updated content and better typesetting reading experience. If the link is broken, please click the button below to view the snapshot at that time.

Twitter whistleblower tells Congress and FTC that a major security problem hasn’t gone away under Elon Musk

alexander-shatov-k1xf2D7jWUs-unsplash-1.jpg
POLICY

Twitter Inc. has a new whistleblower who has told Congress and the Federal Trade Commission that engineers at the company still have the use of a controversial tool that gives them godlike powers over content.

According to The Washington Post, which first reported the story today, the whistleblower is saying that a program called “GodMode” is still available to engineers at Twitter. This mode makes it possible to log into an account and write, restore or delete content – a powerful tool indeed.

The program has been available to any engineers who have it on their company laptop. What’s more, the whistleblower said in the new complaint that Twitter doesn’t even have the ability to log who’s used the program.

GodMode was the reason Twitter suffered one of its greatest humiliations in 2020 when, for a short time, the accounts of some of its most high-profile users were hacked. Some of the hijacked accounts belonged to people such as Barack Obama, Joe Biden, Jeff Bezos, Elon Musk and Bill Gates, which at the end of the day wasn’t as disastrous as it could have been. It was later discovered that internal tools had been hacked — namely GodMode.

Twitter later said that it had taken care of such glaring security issues, although during the drama that was Elon Musk’s effort to buy Twitter in 2022, the company’s former head of security Peiter Zatko turned whistleblower. He again embarrassed Twitter when he outlined what he called “extreme, egregious deficiencies” in Twitter’s management of security threats.

Zatko told the FTC and DOJ that nothing had changed after the hack and Twitter was as vulnerable as ever. That wasn’t a good look at a time when Musk himself was slamming the company for various inadequacies.

The new whistleblower says Twitter has told regulators that these matters of lax security have been cleaned up, and there is no longer any apparatus at Twitter affording Engineers God-given powers. “That’s a lie,” he told The Post. “They removed this from one interface, but it still existed in other ways. They just changed the lock on one of the many front doors.”

He explained that GodMode was merely renamed “Privileged Mode,” and all any engineer needs to do to access it is to change some code from “FALSE” to “TRUE,” after which they’ll be warned, “THINK BEFORE YOU DO THIS.”

This hardly seems like airtight security, especially – if the whistleblower is correct – skullduggery could be performed with near-impunity. The Post said it’s possible Twitter could be hit with a $1 billion fine if it’s proved the company has continued to act recklessly where security is concerned.

Photo: Alexander Shatov/Unsplash

A message from John Furrier, co-founder of SiliconANGLE:

Show your support for our mission by joining our Cube Club and Cube Event Community of experts. Join the community that includes Amazon Web Services and Amazon.com CEO Andy Jassy, Dell Technologies founder and CEO Michael Dell, Intel CEO Pat Gelsinger and many more luminaries and experts.

Join Our Community 

Click here to join the free and open Startup Showcase event.

“TheCUBE is part of re:Invent, you know, you guys really are a part of the event and we really appreciate your coming here and I know people appreciate the content you create as well” – Andy Jassy

We really want to hear from you, and we’re looking forward to seeing you at the event and in theCUBE Club.

Click here to join the free and open Startup Showcase event.


About Joyk


Aggregate valuable and interesting links.
Joyk means Joy of geeK