Premium
This is an archive article published on September 14, 2022

‘Foreign agents’ went undetected till flagged by someone outside: Zatko

During a hearing at the US Senate Judiciary Committee Tuesday night, Zatko also said that Twitter had a Chinese agent working for the country’s Ministry of State Security on its payroll.

Zatko had previously claimed that he believed “with high confidence” that the Indian government had placed its agents within the company. (File)Zatko had previously claimed that he believed “with high confidence” that the Indian government had placed its agents within the company. (File)

Twitter’s lack of internal security controls meant that the social media company could not track employees who may have been acting as government agents due to inadequate logging activity, Twitter ex-security lead turned whistleblower Peiter Zatko said.

He had previously claimed that he believed “with high confidence” that the Indian government had placed its agents within the company. During a hearing at the US Senate Judiciary Committee Tuesday night, Zatko also said that Twitter had a Chinese agent working for the country’s Ministry of State Security on its payroll.

“Other than the person who I believe with high confidence, to be a foreign agent placed in a position from India, it was only going to be from an outside agency or somebody alerting Twitter that somebody already existed that they would find the person,” Zatko said responding to a question by Senator Dianne Feinstein.

He said that when Twitter learnt of a person inside acting on behalf of a foreign interest as a government agent, “it was extremely difficult to track the people”. “There was a lack of logging and an ability to see what they were doing, what information was being accessed, let alone set steps for remediation and possible reconstitution of any damage,” Zatko told the Committee.

His deposition comes less than a month after Zatko filed an whistleblower complaint with the US Securities and Exchange Commission (SEC) where he had claimed that the Indian government “forced” the social media company to hire one or more individuals who were “government agents” and had unsupervised access to vast amounts of the platform’s user data, among other things.

In August, a former Twitter employee was also found guilty of spying for the Saudi government and handing over user data of suspected dissidents.

During Tuesday’s hearing that lasted for more than two hours, another senator asked Zatko how having an agent could possibly help that government. In a potential reference to India, Zatko said that an agent could get access to people’s phone numbers and email addresses and could potentially know about people and their networks that might have been involved in the farmers protest, for instance.

Story continues below this ad

He said among the data Twitter collects includes: a user’s phone number, the current and past IP addresses that the user is connecting from, current and past email addresses, and the person’s approximate location based on IP addresses, among other things. Aside from collecting this wide trove of data, Zatko claimed that Twitter had access to data of users who have quit the platform since it did not delete their accounts, but merely deactivated them.

Twitter did not respond to an immediate request for comment.

Following Zatko’s revelations, Twitter officials in India were summoned by the Shashi Tharoor-led Parliamentary Standing Committee on Information Technology last month.

Soumyarendra Barik is a Special Correspondent with The Indian Express, specializing in the complex and evolving intersection of technology, policy, and society. With over five years of newsroom experience, he is a key voice in documenting how digital transformations impact the daily lives of Indian citizens. Expertise & Focus Areas Barik’s reporting delves into the regulatory and human aspects of the tech world. His core areas of focus include: The Gig Economy: He extensively covers the rights and working conditions of gig workers in India. Tech Policy & Regulation: Analysis of policy interventions that impact Big Tech companies and the broader digital ecosystem. Digital Rights: Reporting on data privacy, internet freedom, and India's prevalent digital divide. Authoritativeness & On-Ground Reporting: Barik is known for his immersive and data-driven approach to journalism. A notable example of his commitment to authentic storytelling involves him tailing a food delivery worker for over 12 hours. This investigative piece quantified the meager earnings and physical toll involved in the profession, providing a verified, ground-level perspective often missing in tech reporting. Personal Interests Outside of the newsroom, Soumyarendra is a self-confessed nerd about horology (watches), follows Formula 1 racing closely, and is an avid football fan. Find all stories by Soumyarendra Barik here. ... Read More

 

Latest Comment
Post Comment
Read Comments
Advertisement
Loading Taboola...
Advertisement