Advertisement

We need your help now

Support from readers like you keeps The Journal open.

You are visiting us because we have something you value. Independent, unbiased news that tells the truth. Advertising revenue goes some way to support our mission, but this year it has not been enough.

If you've seen value in our reporting, please contribute what you can, so we can continue to produce accurate and meaningful journalism. For everyone who needs it.

File photo Alamy Stock Photo
Cyber Security

Whistleblower tells US congress Twitter is ‘plagued by weak cyber defences’

Peiter ‘Mudge’ Zatko told congress that Twitter is “misleading the public, lawmakers” and regulators.

A FORMER SECURITY chief at Twitter has told US congress that the social media platform is plagued by weak cyber defences, privacy threats and an inability to control millions of fake accounts.

Peiter ‘Mudge’ Zatko, a respected cyber security expert, appeared before the US senate judiciary committee to lay out his allegations.

As he began his sworn testimony, Zatko said: “Twitter’s misleading the public, lawmakers” and regulators.

The platform is “over a decade behind the industry’s best standard”, he added.

“This is a big deal for all of us,” he said.

“It doesn’t matter who has keys if there are no locks.”

He was the head of security for the influential platform until he was sacked early this year.

Zatko filed a whistleblower complaint in July with US congress, the justice department, the federal trade commission (FTC) and the securities and exchange commission.

Among his most serious accusations is that Twitter violated the terms of a 2011 FTC settlement by falsely claiming that it had put stronger measures in place to protect the security and privacy of its users.

Senators are clearly alarmed. Dick Durbin, an Illinois Democrat who heads the Judiciary Committee, said Zatko has detailed flaws “that may pose a direct threat to Twitter’s hundreds of millions of users as well as to American democracy”.

He added: “Twitter is an immensely powerful platform and can’t afford gaping vulnerabilities.”

Zatko’s claims could also affect Tesla billionaire Elon Musk’s attempt to back out of his $44 billion deal to acquire the social platform.

Musk claims that Twitter has long underreported spam bots on its platform and cites that as a reason to nix the deal he struck in April.

Many of Zatko’s claims are uncorroborated and appear to have little documentary support.

Twitter has called Zatko’s description of events “a false narrative … riddled with inconsistencies and inaccuracies” and lacking important context.

Zatko also accuses the company of deception in its handling of automated “spam bots”, or fake accounts.

That allegation is at the core of Musk’s attempt to back out of his deal to buy Twitter.

Musk and Twitter are locked in a bitter legal battle, with Twitter having sued Musk to force him to complete the deal.

The Delaware judge overseeing the case ruled last week that Musk can include new evidence related to Zatko’s allegations in the high-stakes trial, which is set to start 17 October.

Senator Charles Grassley, the committee’s ranking Republican, said today that Twitter CEO Parag Agrawal declined to testify at the hearing, citing the ongoing legal proceedings with Musk.

But the hearing is “more important that Twitter’s civil litigation in Delaware,” Grassley said.

Zatko, 51, first gained prominence in the 1990s as an ethical hacker and later worked in senior positions at an elite US defence department research unit and at Google.

He joined Twitter in late 2020 at the urging of then-CEO Jack Dorsey.

Author
Press Association
Your Voice
Readers Comments
1
This is YOUR comments community. Stay civil, stay constructive, stay on topic. Please familiarise yourself with our comments policy here before taking part.
Leave a Comment
    Submit a report
    Please help us understand how this comment violates our community guidelines.
    Thank you for the feedback
    Your feedback has been sent to our team for review.

    Leave a commentcancel