Header Ads

Twitter hires noted hacker 'Mudge' as head of security to tackle vulnerabilities months after several high-profile accounts were hacked

 Social media giant Twitter Inc, under increased threat of regulation and plagued by serious security breaches, is appointing one of the world's best-regarded hackers to tackle everything from engineering missteps to misinformation.

The company on Monday named Peiter Zatko, widely known by his hacker handle Mudge, to the new position of head of security, giving him a broad mandate to recommend changes in structure and practices. Zatko answers to CEO Jack Dorsey and is expected to take over management of key security functions after a 45- to 60-day review.

In an exclusive interview, Zatko said he will examine 'information security, site integrity, physical security, platform integrity - which starts to touch on abuse and manipulation of the platform - and engineering.'

Zatko most recently oversaw security at the electronic payments unicorn Stripe. Before that, he worked on special projects at Google and oversaw handing out grants for projects on cybersecurity at the Pentagon's famed Defense Advanced Research and Projects Agency (DARPA).

Computer hackers from L0pht, a 'hacker think tank,' (left to right) Brian Oblivion, Tan, Kingpin, Mudge, Weld Pond, Space Rougue and Stefan Von Neumann testified in 1998 before the Senate Governmental Affairs hearing on government computer security

Computer hackers from L0pht, a 'hacker think tank,' (left to right) Brian Oblivion, Tan, Kingpin, Mudge, Weld Pond, Space Rougue and Stefan Von Neumann testified in 1998 before the Senate Governmental Affairs hearing on government computer security

Mudge is pictured testifying before the Senate Governmental Affairs hearing on government computer security in 1998

Mudge is pictured testifying before the Senate Governmental Affairs hearing on government computer security in 1998

Zatko's colorful career began in the 1990s, when he simultaneously conducted classified work for a government contractor and was among the leaders of Cult of the Dead Cow, a hacking group notorious for releasing Windows hacking tools in order to goad Microsoft into improving security.

Zatko will answer directly to CEO Jack Dorsey and is expected to take over the management of key security functions

Zatko will answer directly to CEO Jack Dorsey and is expected to take over the management of key security functions

'I don't know if anyone can fix Twitter's security, but he'd be at the top of my list,' said Dan Kaufman, who supervised Zatko at DARPA and now leads the advanced products group at Google.

Stamos, who once worked for Zatko's security consultancy, called him a great fit for a company lacking the financial muscle of Facebook and Google. 'They are going to have to find creative solutions to these problems, and if Mudge is famous for anything in security, it is being creative.'

Zatko said he was committed to improving public conversations on Twitter. He praised a recent move to increase 'friction' by prompting users to comment instead of simply retweeting; a next step could be to force people to understand a long conversation before participating in it, he said.

Zatko said he appreciated Twitter's openness to unconventional security approaches, such as his proposal for confusing bad actors by manipulating the data they receive from Twitter about how people interact with their posts.

'They are willing to take some risks,' Zatko said of his new employer. 'With the challenges of algorithms and algorithmic bias, they are not standing by and waiting until someone else solves the problem.'

Twitter faces numerous security challenges. A year ago, the U.S. government accused two men of spying for Saudi Arabia when they worked at Twitter years earlier, saying that they passed along private information about the kingdom's critics. 

'I don't know if anyone can fix Twitter's security, but he'd be at the top of my list,' said one IT expert. Peiter Zatko aka Mudge is pictured about 20 years ago

'I don't know if anyone can fix Twitter's security, but he'd be at the top of my list,' said one IT expert. Peiter Zatko aka Mudge is pictured about 20 years ago

In July, a group of young hackers tricked employees and won access to internal tools, which let them change account settings and then tweet from the accounts of then-presidential candidate Joe Biden, Microsoft founder Bill Gates and Tesla Chief Executive Elon Musk.

'The data breach this summer was an important reminder of how far Twitter needs to go in building some of the basic security functions necessary to run a service targeted by adversaries much more skilled than the teenagers arrested for that incident,' said Alex Stamos, a former Facebook chief security officer and current Stanford researcher who has helped lead efforts to fight election disinformation.

The FBI is currently leading a federal inquiry into Twitter's security breach that saw hackers hijack high-profile accounts. The company has still not revealed how it happened or to what extent its internal systems were compromised.  

Mike Bloomberg was among the victims of the four-hour attack in July
Joe Biden was among the victims of the four-hour attack in July

Barack Obama , Joe Biden , Bill Gates, Jeff Bezos and Elon Musk were among the victims of the four-hour attack in July

Barack ObamaJoe Biden, Bill Gates, Jeff Bezos and Elon Musk were among the victims of the four-hour attack in July that saw hackers infiltrate Twitter's internal systems and post bogus tweets from the high profile accounts asking people to send bitcoin. 

The scammers received more than $116,000 worth of cryptocurrency, which equates to 12.8 bitcoin, from over 300 people over the four-hour stretch, according to blockchain records. 

Twitter, who have said they are still investigating, has so far indicated at least one of its employees was involved in the attack. 

Twitter CEO Jack Dorsey said he felt 'terrible' following the massive security breach

Twitter CEO Jack Dorsey said he felt 'terrible' following the massive security breach

No comments