The Guardian (USA)

Twitter whistleblo­wer: what questions will Peiter Zatko face from lawmakers?

- Dan Milmo Global technology editor

Twitter’s former head of security, Peiter “Mudge” Zatko, will appear in front of lawmakers in Washington on Tuesday. He is expected to give damning evidence of data and informatio­n security failings at the social media platform, having outlined a litany of concerns in a whistleblo­wer complaint last month.

The former hacker, widely respected in his field as an informatio­n security specialist, joined Twitter on 16 November 2020 and was fired on 19 January 2022. His complaint levels allegation­s of incompeten­ce and fraud at Twitter, saying that he uncovered “extreme, egregious deficienci­es by Twitter in every area of his mandate”, including weak controls of employee access to user data and interferen­ce by foreign government­s.

The senate judiciary committee hearing is not directly for the benefit of Elon Musk, who is trying to pull out of a $44bn (£38bn) deal to buy Twitter

and has been given permission to include Zatko’s revelation­s as another reason for walking away. Musk’s lawyers interviewe­d Zatko on 9 September. But if Zatko’s actions are going to have an immediate impact, it will be at a trial in Delaware on 17 October, where Twitter is attempting to force Musk to buy the company under terms he agreed in April.

Here are some questions that Zatko might face on Tuesday.

What is the scale of the informatio­n security problems at Twitter?

This is a catch-all question that is likely to be broken down into multiple parts in terms of lawmaker questions, given the amount of detail in the allegation­s contained within Zatko’s complaint.

He is likely to be asked about several claims, including that Twitter mishandled user email addresses and phone numbers, that more than 50% of its 500,000 data centre servers are running software that is out of date or has other known security problems, and that employees were found to be installing spyware on their work computers at the request of external organisati­ons.

How significan­t is foreign state interventi­on in Twitter?

Zatko’s complaint says he was aware of “multiple episodes” of Twitter being penetrated by foreign intelligen­ce agencies or being complicit in threat to democracie­s. The examples used were the Indian government forced Twitter to hire govern

ment agents who had access to user data and executives allowed the platform to become dependent on revenue coming from Chinese “entities” that then might be able to access informatio­n on users in China who had circumvent­ed a block. The complaint adds that Twitter received “specific informatio­n from a US government source that one or more particular company employees were working on behalf of another particular foreign intelligen­ce agency.”

Lawmakers will want to know if the platform’s output, which plays a highly influentia­l role in politics and media in multiple countries, could be manipulate­d as a consequenc­e.

How significan­t is Twitter’s bot problem?

In a section of the complaint titled “lying about bots to Elon Musk”, Zatko raises questions over Twitter’s approach on bots, essentiall­y arguing that the company does not have a handle on the problem. Lawmakers are expected to ask Zatko what is the true scale of the problem and how it should be tackled.

Musk cited the prevalence of bot accounts on Twitter – which are not operated by humans and are designed to disrupt and manipulate the experience of users – as a key reason for declaring his withdrawal from the takeover.

In his complaint, Zatko says Parag Agrawal, the Twitter chief executive, lied when he tweeted that Twitter execs were “incentivis­ed to detect and remove as much spam as we possibly can”.

The Tesla chief executive claims that Twitter has deliberate­ly miscounted the number of bots on the platform. The company has consistent­ly said that the number of bots on its platforms is less than 5% of its monetisabl­e daily active users (mDAU – accounts that can see adverts and are therefore commercial­ly valuable to the company).

Zatko says there are many millions of active accounts that are not considered mDAU but are part of the average user’s experience on the platform, which makes for a poor quality experience. It does not quite fit Musk’s argument, which is that Twitter deliberate­ly underplays the number of bots among its mDAUs. Zatko says its does not include them in its mDAU total, but just doesn’t get rid of them entirely.

Nonetheles­s, Zatko’s filing claims that management had no appetite to properly measure bot accounts because they were concerned that “if accurate measuremen­ts ever became public, it would harm the image and valuation of the company”. This could at least be material for a shareholde­r lawsuit and, as a whole, Zatko argues vociferous­ly that Twitter cannot cope with bots because it uses “outdated” programs and “understaff­ed” monitoring teams.

How credible are you as a witness?

Twitter has hit back at Zatko’s allegation­s, saying that he was fired by Agrawal for “ineffectiv­e leadership and poor performanc­e”. Referring to his claims, the company added: “What we’ve seen so far is a false narrative about Twitter and our privacy and data security practices that is riddled with inconsiste­ncies and inaccuraci­es and lacks important context. Mr Zatko’s allegation­s and opportunis­tic timing appear designed to capture attention and inflict harm on Twitter, its customers and its shareholde­rs. Security and privacy have long been companywid­e priorities at Twitter and will continue to be.”

Nonetheles­s, Zatko has considerab­le pedigree, having made his name as an ethical hacker who helped organisati­ons identify flaws in their systems before going on to work in senior positions at Google, the payments firm Stripe and the US Department of Defense. This long track record, and a reputation for profession­al rigour, led the then Twitter chief executive, Jack Dorsey, to hire him.

Is there a senior leadership problem at Twitter?

Zatko’s complaint is scathing about management standards at the company. Zatko’s allegation­s against Agrawal include the chief executive instructin­g him in December 2021 to provide documents on informatio­n security to the risk committee of Twitter’s board of directors that Agrawal knew were “false and misleading”. The complaint says that Twitter’s security problems had “developed under Agrawal’s watch”. The complaint raises concerns about the standard of leadership in general, pointing to an “extremely disengaged” Dorsey – who stepped down last year – who spoke a total of 50 words to Zatko in phone conversati­ons over a 12month period.

Has Twitter misled investors?

Zatko’s complaint says: “For years, across many public statements and SEC filings, Twitter has made material misreprese­ntations and omissions, and engaged in acts and practices operating as deceit upon its users and shareholde­rs, regarding security, privacy and integrity.” Twitter disputes this. In terms of the complaint’s impact on the Musk takeover, Brian Quinn, a professor at Boston College Law School, says: “Twitter will likely respond that while they did not disclose that a disgruntle­d employee had made complaints about their security, they did disclose that data security and privacy issues were risks to the business.”

 ?? Photograph: Richard Drew/AP ?? Peiter ‘Mudge’ Zatko’s whistleblo­wer complaint levels allegation­s of incompeten­ce and fraud at Twitter.
Photograph: Richard Drew/AP Peiter ‘Mudge’ Zatko’s whistleblo­wer complaint levels allegation­s of incompeten­ce and fraud at Twitter.
 ?? Photograph: Jim Watson/AFP/Getty Images ?? Elon Musk claims Twitter deliberate­ly underplays the number of bots.
Photograph: Jim Watson/AFP/Getty Images Elon Musk claims Twitter deliberate­ly underplays the number of bots.

Newspapers in English

Newspapers from United States