Twitter “chose to mislead” the public over concerning security issues at the social media company, according to whistleblower Peiter Zatko.
Zatko, who served as Twitter’s head of security until January this year, appeared before the US Senate Judiciary Committee yesterday, less than a month after the release of a damning complaint against his former employer.
In his testimony, Zatko detailed a litany of “egregious” security practices to US lawmakers, suggesting that the social media firm runs out-of-date software on data centre servers and employs inadequate safety processes.
“What I discovered when I joined Twitter was that this enormously influential company was over a decade behind industry security standards,” Zatko said in his opening statement.
“The company’s cybersecurity failures make it vulnerable to exploitation, causing real harm to real people.”
Notably, Zatko highlighted a concerning data security culture at the social media giant. When asked what kinds of data Twitter collects from users, Zatko said the firm doesn’t completely understand the scale of what it collects.
User information gathered by the company includes phone numbers, IP addresses, email addresses, browser information, user languages and approximate location data.
“They don’t know what data they have, where it lives, or where it came from. And so, unsurprisingly, they can’t protect it,” Zatko said.
Zatko noted that thousands of engineers at the company had access to this private information, and that this represented a serious security concern and placed employees at risk of compromise by foreign intelligence assets.
“The employees have to have too much access to too much data and too many systems,” he said.
While Zatko noted that there had been no confirmed cases of ‘doxxing’ due to this access, he warned there was a real risk that Twitter users’ information could be used to harass or target individuals in the real world.
Leadership Failures
Failure of leadership was a key focus throughout Zatko’s testimony. Despite encountering and disclosing repeated security risks, he claimed that executives at the firm purposefully ignored issues.
Zatko said this was, in part, due to the potential negative impact on revenue. He went on to suggest that the incentive-based nature of executive pay schemes meant that some might have wilfully ignored problems.
“Twitter leadership ignored its engineers because key parts of leadership lacked the competency to understand the scope of the problem. But more importantly, their executive incentives led them to prioritise profits over security,” he said.
In his initial complaint last month, Zatko alleged that a number of executives – including current CEO Para Agrawal – “repeatedly discouraged” him from providing accurate information on the true extent of Twitter’s security woes.
The executive team was also accused of having instructed Zatko to present “cherry-picked” and misrepresented data to the board.
Speaking yesterday, Zatko further alluded to the dismissive and damaging culture among executives at the company.
He said: “When I brought concrete evidence of these fundamental problems to the executive team and repeatedly sounded the alarm of the real risks associated with them…the executive team chose instead to mislead its board, shareholders, lawmakers and the public instead of addressing them.”
In particular, Zatko said that executives at the firm purposefully misled regulators about compliance with the Federal Trade Commission in the wake of a 2011 settlement over user privacy.
“Problematic” Revenue Streams
During the two-hour hearing, Zatko was repeatedly questioned over Twitter’s use as a tool by foreign intelligence assets.
Concerns over foreign interference on social media have been in the spotlight after a former Twitter employee was found guilty of passing sensitive information on Saudi activists to government sources.
Zatko revealed that before his dismissal the FBI warned there was “at least one” Chinese government asset “on the payroll” at Twitter.
Upon informing an executive at the social media giant, Zatko said he was met with a dismissive response.
Recommended
- Soar’s Andrew Duncan | Fintech through the pandemic
- Five things you need to know about iOS 16
- 7 emerging IoT tech trends
“And their response was: ‘Well, since we already have one, what does it matter if we have more. Let’s keep growing the office,’” Zatko told the committee.
Continuing the topic of foreign interference, Zatko also claimed that the Indian government attempted to strongarm Twitter into placing agents within the firm.
Although Twitter is banned in China, senators also asked why the social media firm ran advertising from organisations with strong links to the Chinese regime.
According to Zatko, employees had raised concerns over the issue during his time at the firm. However, upon informing relevant executives he was told to find a way to “make the employees more comfortable with this”.
Zatko said he was told it would be “problematic” for Twitter to lose that particular revenue stream despite obvious national security concerns.
“They didn’t know what people they were putting at risk, or what information they were even giving to the [Chinese] government, which made me concerned that they hadn’t thought through the problem in the first place,” he said.
This latest testimony from the Twitter whistleblower could play a crucial role in the forthcoming trial over Elon Musk’s takeover bid. Zatko has been subpoenaed by Musk’s legal team to testify in the trial next month.
Get the latest news from DIGIT direct to your inbox
Our newsletter covers the latest technology and IT news from Scotland and beyond, as well as in-depth features and exclusive interviews with leading figures and rising stars.
To subscribe, click here.





