Welcome to DU! The truly grassroots left-of-center political community where regular people, not algorithms, drive the discussions and set the standards. Join the community: Create a free account Support DU (and get rid of ads!): Become a Star Member Latest Breaking News General Discussion The DU Lounge All Forums Issue Forums Culture Forums Alliance Forums Region Forums Support Forums Help & Search

highplainsdem

(48,974 posts)
Sun Mar 26, 2023, 08:18 PM Mar 2023

Twitter Says Parts of Its Source Code Were Leaked Online

Source: NY Times

Parts of Twitter’s source code, the underlying computer code on which the social network runs, were leaked online, according to a legal filing, a rare and major exposure of intellectual property as the company struggles to reduce technical issues and reverse its business fortunes under Elon Musk.

Twitter moved on Friday to have the leaked code taken down by sending a copyright infringement notice to GitHub, an online collaboration platform for software developers where the code was posted, according to the filing. GitHub complied and took down the code that day. It was unclear how long the leaked code had been online, but it appeared to have been public for at least several months.

Twitter also asked the U.S. District Court for the Northern District of California to order GitHub to identify the person who shared the code and any other individuals who downloaded it, according to the filing.

-snip-

The executives were only recently made aware of the source code leak, the people briefed on the internal investigation said. One concern is that the code includes security vulnerabilities that could give hackers or other motivated parties the means to extract user data or take down the site, they said.

-snip-

Read more: https://www.nytimes.com/2023/03/26/technology/twitter-source-code-leak.html



People at Twitter suspect the leaker is a former employee unhappy with Musk (which should narrow it down to only several thousand people). The Times quotes a threat analyst at Emsisoft saying the best way to avoid insider risk is to keep employees happy, which Musk has failed at.

The GitHub user who leaked the code posted only that one message and used the handle FreeSpeechEnthusiast. Musk likes to call himself a "free speech absolutist."
15 replies = new reply since forum marked as read
Highlight: NoneDon't highlight anything 5 newestHighlight 5 most recent replies
Twitter Says Parts of Its Source Code Were Leaked Online (Original Post) highplainsdem Mar 2023 OP
Hey, Elon! PJMcK Mar 2023 #1
Just when you thought it couldn't get any worse for Twitter. paleotn Mar 2023 #2
... 2naSalit Mar 2023 #11
Those ponies have left the barn and are free to roam. erronis Mar 2023 #3
Open-Source is the most vulnerability plagued software out there, infiltrated by hackers. TheBlackAdder Mar 2023 #12
This flash news report moniss Mar 2023 #4
LOL! highplainsdem Mar 2023 #8
I guess that no one ever told that John Galt wannabe that what goes around comes around. LudwigPastorius Mar 2023 #5
+1 2naSalit Mar 2023 #9
Heckuva job, Elon! Heckuva job! Initech Mar 2023 #6
It's a mystery! Mawspam2 Mar 2023 #7
Aww... 2naSalit Mar 2023 #10
Yeah, that's what happens.. tonekat Mar 2023 #13
How do we know Musk himself didn't leaked it to someone and they leaked it? LiberalFighter Mar 2023 #14
Was it one of the core algorithms? Or just the UX code for user settings page? NullTuples Mar 2023 #15

PJMcK

(22,034 posts)
1. Hey, Elon!
Sun Mar 26, 2023, 08:27 PM
Mar 2023

Wow.

This is most likely the result of your draconian measures when you fired critical staff. Didn’t you anticipate any blowback? The code could have been leaked by someone inside Twitter with access to the code, someone you pissed off. That possibility didn’t occur to you? You really don’t understand people and they work for you, dumbass. Piss them off at your own— and your stockholders’— peril.

Perhaps you’re not a master of the universe after all. You’re much like that other moron, Trump. You’ve seriously damaged your own brand.

We’ll done, Elon.

erronis

(15,241 posts)
3. Those ponies have left the barn and are free to roam.
Sun Mar 26, 2023, 08:45 PM
Mar 2023

The proprietary walled-garden companies cannot keep their stuff secret forever. It will out.

The best software out there now is open-source. It is purposefully visible and can be forked and modified. Thousands of skeptical eyeballs are far better than 10-20 within a corporate "QA" department.

TheBlackAdder

(28,188 posts)
12. Open-Source is the most vulnerability plagued software out there, infiltrated by hackers.
Mon Mar 27, 2023, 02:51 AM
Mar 2023

.

Sonotype did several reviewed of the Open-Source community and found that almost no one reviews OS Code other than hackers, Nation State actors and sometimes college academia. It is a complete fallacy that OS code is reviewed by people to ensure quality. It turns out that people just assume others are reviewing the code and use it. This is causing a lot of problems in almost every data center because companies are trying to go on the cheap and use free source code.

To make matters worse, every major Open-Source project is infiltrated by hackers and nation state actors that are injecting vulnerabilities into the projects. Sonotype gave up trying to assess the amount of code section inserted after it detected several hundred million. It estimates that the OS community has over 1.2 Billion access points and rogue inserts.

Private code is the best, compiled with special compilers and assemblers so it makes their code harder to disassemble and follow.

Spring framework holds the title for the most problem plagued OS project. While they are trying to clean up their code, they still hold that title after four years of clean-up efforts. Just look at the major hacks around the world, and a majority of them are sites and companies using open-source. After-all, hackers and others know exactly what the code is and, if the companies use standard compiler or assemblers, it makes it easy to penetrate and leverage. You'd have to scrounge the Sonotype site for the reports.

.

moniss

(4,229 posts)
4. This flash news report
Sun Mar 26, 2023, 10:00 PM
Mar 2023

has just been received by Not Really Bright Moves News: Dateline....... San Francisco........Self described genius Elon Musk has announced that he has constructed a reward for the perpetrators of the Twitter source code leak. He announced this afternoon that if the offenders will turn themselves in he will drop all charges and provide each of them with a new Tesla set to permanently function in self-driving mode. It is not clear at this point whether this "reward" is anything other than a punishment in disguise.

LudwigPastorius

(9,137 posts)
5. I guess that no one ever told that John Galt wannabe that what goes around comes around.
Sun Mar 26, 2023, 11:35 PM
Mar 2023

Hopefully, this will make him want to fuck off to Mars faster.

Mawspam2

(729 posts)
7. It's a mystery!
Mon Mar 27, 2023, 12:19 AM
Mar 2023
People at Twitter suspect the leaker is a former employee unhappy with Musk (which should narrow it down to only several thousand people). 


So that basically means any current of former employee. Clearly, Ewrong needs to fire all remaining employees, especially the ones who live in their offices since they have too much access to his precious code!

NullTuples

(6,017 posts)
15. Was it one of the core algorithms? Or just the UX code for user settings page?
Mon Mar 27, 2023, 03:49 PM
Mar 2023

Either way, it's still something to get under Elon's skin, and that's a good thing in my opinion.

Latest Discussions»Latest Breaking News»Twitter Says Parts of Its...