Big tech companies hold so much of our personal information. From our photos and private messages to our thoughts and connections, we trust these platforms to keep everything safe and private.
But what happens when that trust is broken by a former insider, someone who saw the problems firsthand? That's the strange story of a former Twitter security chief who blew the whistle on what he called reckless cybersecurity policies.
The Man Who Spoke Up
Peiter Zatko, also known by his old hacking name "Mudge," was once a very important person in the world of computer security. He had a long history of finding flaws in systems and helping to fix them. His background made him a unique choice for a top job at a major social media company.
In late 2020, Twitter hired Mudge to be its head of security. His job was to make the platform safer for everyone. He was supposed to fix the company's long-standing security problems and protect its vast amount of user data. However, what he found inside was far worse than he expected.
A History of
Innovation and Concern
Before joining Twitter, Mudge had worked for some big names, including the Pentagon's Defense Advanced Research Projects Agency (DARPA) and Google. He was known for his ethical hacking work and for pointing out *cybersecurity vulnerabilities
- in important systems. This experience gave him a deep understanding of what good security should look like.
He came to Twitter with a clear mission. The company had faced issues before, including a major hack in 2020 that saw high-profile accounts taken over. Mudge was brought in as a fixer, someone with the skills and reputation to overhaul the system. But the challenges he faced from within the company were immense.
Shocking Claims
Against a Tech Giant
After being fired in early 2022, Mudge came forward with a detailed complaint. He claimed Twitter had major, dangerous security problems. These weren't small issues, but fundamental flaws that put millions of users and even national security at risk. He said the company was not honest about its security measures.
His allegations included a long list of concerns. He claimed Twitter did not always delete the data of former users, even when they asked. He also said the company had lied to federal regulators about how well it was protecting user information. These were serious accusations that shook the tech world.
"Twitter was a chaotic mess, a ticking time bomb of security vulnerabilities just waiting to go off," Mudge reportedly stated in his complaint, highlighting the severe risks.
One of the most alarming claims was that Twitter had serious problems with its internal access controls. This meant that too many employees had too much power to access sensitive parts of the system. He also raised concerns about foreign government agents potentially working inside the company, with access to vital data. This *lack of control
- was a huge red flag.
Data at Risk: What Was Exposed?
The whistleblower's claims painted a picture of a company struggling to protect its users. If these claims were true, it meant that a lot of personal and sensitive information could have been exposed. This included things like private messages, location data, and even phone numbers that users thought were secure.