Whistleblower Accuses Twitter of Cybersecurity Negligence

Twitter app logo is seen in this illustration taken on August 22, 2022. (Reuters)
Twitter app logo is seen in this illustration taken on August 22, 2022. (Reuters)
TT

Whistleblower Accuses Twitter of Cybersecurity Negligence

Twitter app logo is seen in this illustration taken on August 22, 2022. (Reuters)
Twitter app logo is seen in this illustration taken on August 22, 2022. (Reuters)

A former head of security at Twitter alleged that the company misled regulators about its cybersecurity defenses, privacy protections and its ability to detect and root out fake accounts, according to a whistleblower complaint filed with US officials.

The revelation could create serious legal and financial problems for the social media platform, which is currently attempting to force Tesla CEO Elon Musk to consummate his $44 billion offer to buy the company.

Peiter Zatko, Twitter's security chief until he was fired early this year, filed complaints last month with the US Securities and Exchange Commission, the Federal Trade Commission and the Department of Justice. The legal nonprofit Whistleblower Aid, which is working with Zatko, confirmed the authenticity of a redacted copy of the complaint posted online by the Washington Post.

Among Zatko's most serious accusations is that Twitter violated the terms of a 2011 FTC settlement by falsely claiming that it had strong security measures in place to protect the security and privacy of its users. Zatko also accuses the company of deceptions involving its handling of “spam" or fake accounts, an allegation that is at the core of Musk's attempt to back out of the Twitter takeover.

Shares of Twitter Inc. slid 5.4% Tuesday. Zatko didn't immediately respond to a request for comment Tuesday. But he told the Post he “felt ethically bound” to come forward.

Better known by his hacker handle “Mudge,” Zatko is a highly respected cybersecurity expert who first gained prominence in the 1990s and later worked in senior positions at the Pentagon’s Defense Advanced Research Agency and Google.

He joined Twitter at the urging of then-CEO Jack Dorsey in late 2020, the same year the company suffered an embarrassing security breach involving hackers who broke into the Twitter accounts of world leaders, celebrities and tech moguls, including Musk, in an attempt to scam their followers out of bitcoin.

Twitter said in a prepared statement Tuesday that Zatko was fired for “ineffective leadership and poor performance” and said the “allegations and opportunistic timing appear designed to capture attention and inflict harm on Twitter, its customers and its shareholders.” The company called his complaint “a false narrative” that is “riddled with inconsistencies and inaccuracies and lacks important context.”

Zatko's attorneys, Debra Katz and Alexis Ronickher, said Twitter's claim about his poor performance is false and that he repeatedly raised concerns about “grossly inadequate information security systems” with top executives and Twitter's board of directors. The lawyers said that in late 2021, after the board was given “whitewashed” information about those security problems, Zatko escalated his concerns, “clashed” with CEO Parag Agrawal and board member Omid Kordestani and was fired two weeks later.

The 84-page complaint describes a broken corporate culture at Twitter that lacked effective leadership and where Zatko said top executives practiced “deliberate ignorance” of pressing problems. His description of Dorsey’s leadership style is particularly scathing, saying the Twitter founder was “extremely disengaged” during the last months of his tenure as CEO to the point where he would not even speak during meetings on complex issues facing the company.

Zatko said he heard from colleagues that Dorsey would remain silent for “days or weeks.” Dorsey announced he was stepping down as Twitter CEO in November 2021.

The disclosure says Twitter offered no monetary incentives for improving security and platform integrity, although the company did offer $10 million bonuses last year for top executives who could generate short-term user growth.

Among Zatko’s damning accusations of cybersecurity malpractice: Software and security updates were disabled on more than a third of employees’ computers -- unduly exposing them to malware -- and it was common for people to install “whatever software they wanted on their work systems.” Such lapses are typically considered cardinal sins in cybersecurity.

Whistleblower Aid said it is legally precluded from sharing Zatko's statement. The same group worked with former Facebook employee Frances Haugen, who testified to Congress last year after leaking internal documents and accusing the social media giant of choosing profit over safety.

A spokesperson for the US Senate's intelligence committee, Rachel Cohen, said the committee has received Zatko's complaint and "is in the process of setting up a meeting to discuss the allegations in further detail. We take this matter seriously.”

Sen. Dick Durbin, an Illinois Democrat, said in a prepared statement that if the claims are accurate, “they may show dangerous data privacy and security risks for Twitter users around the world.”

Among the most alarming complaints is Zatko’s allegation that Twitter knowingly allowed the Indian government to place its agents on the company payroll where they had “direct unsupervised access to the company’s systems and user data.”

A 2011 FTC complaint noted that Twitter’s systems were full of highly sensitive data that could allow a hostile government to find precise location data for specific users and target them for violence or arrest.

Zatko also describes “deliberate ignorance” by Twitter executives on counting the millions of accounts that are automated “spam bots" or otherwise have no value to advertisers because there is no person behind them.

Alex Spiro, an attorney representing Musk in his effort to back out of his Twitter acquisition deal, said lawyers have issued a subpoena for Zatko. “We found his exit and that of other key employees curious in light of what we have been finding,” Spiro wrote in an email Tuesday. Spiro said Zatko and Musk have not been in contact at any time this year.



PIF, Google Cloud Partner to Establish AI Hub in Saudi Arabia

The partnership will emphasize joint research on Arabic language models and Saudi-specific AI applications. - SPA
The partnership will emphasize joint research on Arabic language models and Saudi-specific AI applications. - SPA
TT

PIF, Google Cloud Partner to Establish AI Hub in Saudi Arabia

The partnership will emphasize joint research on Arabic language models and Saudi-specific AI applications. - SPA
The partnership will emphasize joint research on Arabic language models and Saudi-specific AI applications. - SPA

PIF and Google Cloud announced on Wednesday a strategic partnership to establish a global artificial intelligence (AI) hub near Dammam, in Saudi Arabia's Eastern Region.
According to a press release issued by the PIF, the landmark partnership, signed at the 8th edition of the Future Investment Initiative (FII8), further positions Saudi Arabia as a global AI hub and a top destination for enterprises and startups. This collaboration aims to enhance the Saudi workforce by offering AI programs to millions of students and professionals, supporting the national objective of growing the information and communication technology (ICT) sector by 50%.
Under this partnership, customers will be able to leverage Google Cloud’s technology to drive growth across industries and expand the capacity for AI application delivery. Businesses and their consumers can anticipate improved AI application quality and data services, delivered locally and with greater efficiency, SPA reported.
Subject to regulatory approvals, the partnership will emphasize joint research on Arabic language models and Saudi-specific AI applications. Enabled by Google Cloud’s substantial investment and expertise in custom silicon, this high-performance infrastructure will feature the latest tensor processing unit (TPU) and graphics processing unit (GPU) accelerators, along with the Vertex AI platform—Google Cloud’s specialized development environment for building generative AI applications.
The release added atht this collaboration underscores Saudi Arabia’s attractiveness for major tech initiatives. Investors are drawn to the nation’s strategic location at the crossroads of three continents, its advanced infrastructure, its access to fast-growing Middle Eastern markets, and the potential for reliable and affordable renewable energy to support the AI hub.
Governor of PIF Yasir Al-Rumayyan said, “We are delighted to welcome this new Google Cloud AI hub to Saudi Arabia. This partnership demonstrates PIF’s dedication to fostering an AI-friendly environment through investments in human capital and technology, upskilling thousands with cutting-edge tools to support our sustainable and innovative infrastructure goals. Saudi Arabia is a prime location for global tech partners, as PIF brings both sector expertise and a long-term approach to investment.”
Meanwhile, President and Chief Investment Officer of Alphabet and Google Ruth Porat added, “This strategic partnership will accelerate the adoption of AI in the local language and across industries—including healthcare, retail, financial services, and more—for enterprises and startups in Saudi Arabia, across the Middle East, Africa, and worldwide. As part of Saudi Arabia’s vibrant technology ecosystem, we aim to create highly skilled jobs for Saudis and provide opportunities for global businesses to drive growth through cloud adoption.”
Technology is one of PIF’s priority investment sectors, enabling critical areas of the economy, including entertainment, financial services, healthcare, transportation, logistics, utilities, and renewables. PIF’s telecom, communications, and technology investments include the Saudi Information Technology Company (SITE), which delivers digital and cyber services through national talent, and iot squared, a company specializing in the Internet of Things.
To advance Arabic-language models, PIF and Google Cloud will explore enhancing the Arabic-language capabilities of Gemini, Google’s generative AI model family, by integrating additional Arabic datasets with Google Cloud’s technology. This will provide local businesses, researchers, and developers the opportunity to incorporate these models into their systems, enabling sophisticated Arabic-language AI agents and applications.
Preliminary research commissioned by Google Cloud and conducted by tech policy advisory firm Access Partnership estimates the new AI hub could contribute a cumulative $71 billion to Saudi Arabia’s GDP over eight years. Increased economic activity from AI adoption is expected to support the creation of thousands of highly skilled direct and indirect jobs.
These investments expand on Google Cloud’s existing presence in Saudi Arabia, which includes the Dammam cloud region, launched last year as part of Google Cloud’s global network of 40 regions.