Observer
  • Business
  • Art
  • Lifestyle
  • Culture
Newsletters
  • Business
    • Finance
    • Media
    • Technology
    • Policy
    • Wealth
    • Insights
    • Interviews
  • Arts
    • Art Fairs
    • Art Market
    • Art Reviews
    • Auctions
    • Galleries
    • Museums
    • Interviews
  • Culture
    • Theater
    • Opera
    • Dance
    • Film
    • Interviews
  • Lifestyle
    • Nightlife & Dining
    • Style
    • Travel
    • Gift Guides
    • Interviews
  • Power Index
    • Nightlife & Dining
    • Business of Art
    • A.I.
    • PR
  • About
    • About Observer
    • Advertise With Us
    • Reprints
Newsletters
Business  •  Technology

Whistleblower Peiter Zatko Says Twitter’s Data Security Is 10 Years Behind Industry Standards

Zatko, Twitter's former security head, told lawmakers Twitter doesn't understand about 80 percent of the data it collects.

By Sissi Cao • 09/13/22 3:30pm
Twitterl whistleblower Peiter Zatko
Peiter “Mudge” Zatko, former head of security at Twitter, testifies before the Senate Judiciary Committee. Photo by Kevin Dietsch/Getty Images

Twitter’s data security practices are at least a decade behind industry standards and the company’s leadership doesn’t seem willing to put in the necessary effort to improve its defenses, Peiter Zatko, Twitter’s former head of security, told lawmakers during a congressional hearing today (Sept. 13).

Sign Up For Our Daily Newsletter

Thank you for signing up!

By clicking submit, you agree to our <a href="http://observermedia.com/terms">terms of service</a> and acknowledge we may use your information to send you emails, product samples, and promotions on this website and other properties. You can opt out anytime.

See all of our newsletters

Zatko, also known by his online handle “Mudge,” testified before the Senate Judiciary Committee today about a set of complaints he filed with regulators in July alleging Twitter lied to the U.S. government regarding its security practices and failed to protect user information.

Zatko was hired by former Twitter CEO Jack Dorsey in November 2020 to oversee the social media company’s security. He was fired in January this year after Parag Agrawal was promoted to CEO to replace Dorsey.

During his time at Twitter, Zatko said he discovered that “this enormously influential company was over a decade behind” industry security standards. “They don’t know what data they have, where it lives, or where it comes from. So, unsurprisingly, they can’t protect it,” he said.

He cited an internal study conducted by Twitter engineers which found the company doesn’t understand about 80 percent of the data it collects, how it’s supposed to be used and when it’s supposed to be deleted.

“This leads to the second problem, which is that the employees then have to have too much access to too much data in too many systems,” Zatko said. “You can think of it this way: it doesn’t matter who has keys if you don’t have any locks on the doors.”

Twitter is a “gold mine” for bad actors

Zatko said Twitter neither has a centralized system that logs activities on its platform nor an environment for testing new softwares before they go live—which are rare in the tech industry. These loopholes could make Twitter “a gold mine” for bad actors, such as foreign spies, said Zatko, who was an intelligence officer at the Department of Defense before joining Twitter.

The company’s management structure also fails to encourage engineers to report problems and bad behavior, Zatko added. “There was a culture of not reporting bad results up, but only reporting good results up. You were rewarded based upon…how you perform in an emergency, not for identifying existing problems and doing the groundwork and keeping the lights on.”

Twitter could not be reached for comment on Zatko’s testimony. The company has previously said allegations in Zatko’s regulatory complaints were riddled with inaccuracies and inconsistencies.

Also today, Twitter shareholders voted to approve Elon Musk’s $44 billion acquisition of the social media company—a deal Musk now wants to walk away from.

Musk, who is in a legal battle with Twitter over the acquisition, appeared to be entertained by the hearing. He tweeted a popcorn emoji this morning while the hearing was live steamed.

Musk recently obtained a court’s approval to introduce Zatko’s complaints to his countersuit against Twitter for violating their merger agreement. He and Twitter are scheduled to face off in Delaware’s Chancery Court for a five-day trial starting October 17.

🍿

— Elon Musk (@elonmusk) September 13, 2022

After the hearing, Zatko said through his attorney he hopes his testimony today “has helped educate the public about just how dire the security and privacy situation is at Twitter and how impacted we all are by these failures.”

Whistleblower Peiter Zatko Says Twitter’s Data Security Is 10 Years Behind Industry Standards
Filed Under: Social Media, Business, Technology, Peiter Zatko, Cybersecurity, Congress, Elon Musk, Twitter
  • SEE ALSO: Why Ford’s Electric F-150 Never Took Off
  • ARTS
    • Art Fairs
    • Art Market
    • Art Reviews
    • Auctions
    • Galleries
    • Museums
  • BUSINESS
    • Energy
    • Finance
    • Media
    • Policy
    • Technology
    • Climate
  • CULTURE
    • Books
    • Dance
    • Film
    • Opera
    • Theater
  • LIFESTYLE
    • Autos
    • Hotels
    • Nightlife & Dining
    • Restaurants
    • Style
    • Travel
  • WEALTH
    • Billionaires
    • Parties
    • Philanthropy
    • Real Estate
  • EXPERT INSIGHTS
    • A.I. Experts
    • Art Market Experts
    • Climate Experts
    • Finance Experts
  • POWER LISTS
    • PR Power List
    • Nightlife & Dining
    • Business of Art
    • A.I. Power List
  • INTERVIEWS
    • Art World
    • Business Leaders
    • Tastemakers
    • Entertainers
  • ABOUT
  • ADVERTISE
  • CONTACT
  • NEWSLETTERS
  • RSS FEEDS
  • SITEMAP
  • TERMS
  • PRIVACY
  • REPRINTS
  • Privacy
  • Terms
  • Cookie Settings
  • Do not sell my data
Powered by WordPress VIP

We noticed you're using an ad blocker.

We get it: you like to have control of your own internet experience.
But advertising revenue helps support our journalism.

To read our full stories, please turn off your ad blocker.
We'd really appreciate it.

How Do I Whitelist Observer?

How Do I Whitelist Observer?

Below are steps you can take in order to whitelist Observer.com on your browser:

For Adblock:

Click the AdBlock button on your browser and select Don't run on pages on this domain.

For Adblock Plus on Google Chrome:

Click the AdBlock Plus button on your browser and select Enabled on this site.

For Adblock Plus on Firefox:

Click the AdBlock Plus button on your browser and select Disable on Observer.com.

Then Reload the Page