Anonymous ID: 4d49d3 Nov. 23, 2022, 8:23 p.m. No.17803642   🗄️.is đź”—kun   >>3651 >>3656 >>3657 >>3658

https://www.grassley.senate.gov/imo/media/doc/ceg_to_twitter_security_review.pdf

 

Elon Musk

Chief Executive Officer

Twitter, Inc.

 

Dear Mr. Musk:

According to recent testimony and records provided to the Senate Judiciary Committee

by former Twitter, Inc. head of security, Peiter Zatko, at least 4,000 Twitter employees have

broad access to platform components that could allow them to impermissibly track an individual

user’s geo-location, IP address, email, phone number, and online activity.1 His testimony made

clear that a compromised Twitter employee working on behalf of a foreign power could use this

access to collect data on Americans and even hack other parts of a user’s phone to access files,

photos, or conversations that could then be used to extort, blackmail, or collect intelligence.2

These are significant security failures that Twitter must immediately address and fix. On

September 12, 2022, Senator Durbin and I posed a series of questions to your predecessor;

however, he failed to answer them citing the ongoing litigation with you as an excuse. The

allegations made by Mr. Zatko relate to activity that occurred prior to your ownership of Twitter.

Now that you have completed your acquisition of Twitter, you are uniquely positioned to provide

answers to Congress where your predecessor failed. Accordingly, I request that you answer the

questions in the enclosed September 12, 2022, letter and that you perform a threat assessment of

Twitter’s security protocol to better protect user data and privacy.

 

As you are aware, Twitter has a history of security concerns. For instance, in July 2020,

several high school students conducted a phishing scheme to successfully steal the login

information of Twitter employees which allowed them to take over the accounts for thenpresidential candidate Joe Biden, former President Barack Obama, and yourself.

3 The ease at ….

Anonymous ID: 4d49d3 Nov. 23, 2022, 8:25 p.m. No.17803651   🗄️.is đź”—kun   >>3657

>>17803642 part 1

 

…which these students were able to circumvent Twitter’s security protocols in order to obtain

access highlights the weaknesses in Twitter’s security.4

 

According to Mr. Zatko, Twitter has already been infiltrated by foreign agents.5

In his testimony, he revealed that the FBI recently notified Twitter that they had at least one Chinese

agent on the payroll.6 Separately, Mr. Zatko told the Committee that he believes that the

Republic of India was able to place at least one foreign asset within the company.7

He also testified to Twitter’s lack of concern over foreign agents being on the payroll when he recalled a

specific conversation with a Twitter executive in which they reportedly said, “Well, since we

already have one, what does it matter if we have more? Let’s keep growing the office.”8

 

In the hands of a foreign agent embedded at Twitter, a foreign adversary could use their

access to personal data to track down pro-democracy dissidents within their country or spy on

Americans. This has actually happened in the past. In 2019, two Twitter employees were

indicted by the Department of Justice for using their position at Twitter to access private user

data and give it to Saudi Arabia.9

These foreign agents were able to access and provide personal

information on more than 6,000 individuals of interest to the Saudi government.10

 

Mr. Zatko also informed the Committee that a foreign agent could use impermissibly

acquired personal data to launch a targeted cyber-attack against specific individuals via malware,

which would then potentially allow access to sensitive parts of a user’s phone.11 Furthermore,

this information could be shared or sold on underground online forums or to foreign

governments by agents without the person’s knowledge.12 Mr. Zatko also noted another

approach, albeit less likely: a foreign agent working within Twitter could insert malicious code

in Twitter’s code base to allow them to hack an individual’s phone or account.13

 

Twitter collects vast amounts of data on American citizens. Americans have a vested

interest in ensuring that their private data is secure, and that the companies which they have

entrusted with their private data have not been infiltrated by foreign agents. In the hands of a

foreign adversary, this data is a gold mine of information that could be used against American

interests. Twitter has a responsibility to ensure that the data is protected and doesn’t fall into the

hands of foreign powers.

 

Accordingly, no later than December 15, 2022, I request that you answer the September

12, 2022, letter and perform a threat assessment of Twitter’s current security posture and systems

to better protect user data and privacy. Lastly, I request that you brief Committee staff on the

findings of the assessment.

 

Thank you for your attention to this important matter.

 

Sincerely,

Charles E. Grassley

Anonymous ID: 4d49d3 Nov. 23, 2022, 8:31 p.m. No.17803666   🗄️.is đź”—kun   >>3679

>>17803469

was at the mall today….lulu lemon had that fucking flag in the window.

 

Spouse anon made the mistake of asking me which flag it was…

 

I did not squander the opportunity to say in a full voice that it was the pedophile flag.