THE NEW YORK TIMES

Whistleblower says Twitter ‘chose to mislead’ on security flaws

Whistleblower says Twitter ‘chose to mislead’ on security flaws

Twitter’s former top security official told lawmakers at a hearing Tuesday that executives had so heavily prioritized the company’s business that they disregarded concerns about foreign governments infiltrating its operations and misled regulators about its privacy practices.

Peiter Zatko, who was Twitter’s top security official before he was fired in January, testified that the FBI had notified the company during his tenure that “there was at least one agent” of China’s Ministry of State Security “on the payroll inside Twitter.” In another conversation about a possible foreign agent inside Twitter, Zatko recounted, an executive said that because “we already have one, what does it matter if we have more.”

Members of the Senate Judiciary Committee, which convened the hearing, expressed concerns about Zatko’s accusations, which he first made in a whistleblower complaint that became public last month. Sen. Chuck Grassley of Iowa, the top Republican on the committee, said he did not see how Twitter’s CEO, Parag Agrawal, could keep his job if the allegations were true.

“Twitter has a responsibility to ensure that the data is protected and doesn’t fall into the hands of foreign powers,” Grassley said.

Zatko’s testimony added to the turmoil engulfing Twitter as the social media service faces questions about its survival. The company, which is based in San Francisco, has been embroiled in a battle with Elon Musk, Tesla’s CEO, who agreed to buy Twitter for $44 billion in April before trying to back out of the deal. The company has insisted the purchase go forward and has sued Musk, with a trial over the case set for next month.

Twitter’s shareholders voted Tuesday to approve the deal with Musk, even as it remains uncertain whether the acquisition will be completed. The approval was expected; shareholders do not typically reject deals. Twitter said that 98.6% of the votes cast by shareholders approved of the deal, according to a preliminary tally.

The hearing Tuesday showed that “Twitter is acting dangerously and negligently to turn its back on user safety,” said Nora Benavidez, senior counsel at Free Press, an advocacy group that has called for Twitter to do more to combat misinformation.

Twitter denied Zatko’s accusations, saying in a statement, “Today’s hearing only confirms that Mr. Zatko’s allegations are riddled with inconsistencies and inaccuracies.”

Zatko’s whistleblower complaint has become entangled in Musk’s and Twitter’s fight over the company. Musk’s lawyers have seized on Zatko’s statements to back their argument that Twitter misled the billionaire about the volume of spam accounts on the service.

Musk has claimed that he should be able to abandon the Twitter acquisition because the company downplayed the number of fraudulent accounts on the service. Zatko said in his complaint that Agrawal had misled Musk after the billionaire made his concerns known.

A spokesperson for Musk’s legal team did not respond to a request for comment.

At the more than two-hour hearing Tuesday, Grassley said Agrawal had “rejected this committee’s invitation by claiming that it would jeopardize Twitter’s ongoing litigation with Mr. Musk.”

“Many of the allegations directly implicate Mr. Agrawal, and he should be here to address them,” Grassley said.

Zatko, who reached a $7 million settlement with the company after he left, described Twitter executives as unconcerned about possible holes in security, especially when it could endanger the company’s bottom line. He said he had told one executive that he was “confident” there was a foreign agent inside the company.

“And their response was, ‘Well, since we already have one, what does it matter if we have more. Let’s keep growing the office,’” Zatko told lawmakers.

Prosecutors charged two former Twitter employees in 2019 with acting as agents of the government of Saudi Arabia, saying they had used their positions to gain access to information about critics of the Saudi government. A California jury convicted one of them on some of the charges last month; the other man left the country before authorities could arrest him.

During the hearing, Zatko also reiterated that Twitter had misled the Federal Trade Commission about its data practices and that it had violated the terms of a 2011 settlement it had reached with the agency. Twitter misrepresented to the FTC whether it deletes a user’s data when the user leaves, he said. He added that he had not directly been involved in conversations between Twitter and the agency but had been briefed on the discussions by “people involved in the calls.”

Several senators asked whether the regulations governing tech companies were inadequate. Lawmakers have for years considered legislation that would set new privacy and competition rules for the biggest tech platforms. But those efforts have yet to bear fruit.

“Something good will come from this. Do you believe that?” said Sen. Lindsey Graham, R-S.C.

“I hope so,” Zatko said. “I’m basically risking my career and reputation.”

[This article originally appeared in The New York Times.]

Subscribe to our Newsletters

Enter your information below to receive our weekly newsletters with the latest insights, opinion pieces and current events straight to your inbox.

By signing up you are agreeing to our Terms of Service and Privacy Policy.