Posts Tagged: whistleblower

Meta whistleblower tells Senate the company ‘cannot be trusted with our children’

Another Meta whistleblower has testified before Congress regarding safety issues on the company’s platforms. On the same day that Frances Haugen told Congress in 2021 how Meta could fix some of its safety problems, Arturo Béjar, a former director of engineering for Protect and Care at Facebook, sent CEO Mark Zuckerberg and other executives an email regarding the harms that young people may face while using the company’s products.

Two years later, Béjar was the sole witness in a Senate Judiciary subcommittee hearing titled “Social Media and the Teen Mental Health Crisis.” In his testimony, Béjar claimed he was subpoenaed earlier this year to testify regarding emails he sent Meta higher-ups. He said he realized that since he sent them, nothing had changed at the company.

“Meta continues to publicly misrepresent the level and frequency of harm that users, especially children, experience on the platform,” Béjar told the Subcommittee on Privacy, Technology and the Law in prepared remarks. “And they have yet to establish a goal for actually reducing those harms and protecting children. It’s time that the public and parents understand the true level of harm posed by these ‘products’ and it’s time that young users have the tools to report and suppress online abuse.”

Béjar was an engineering director at Meta between 2009 and 2015, during which time he was responsible for protecting Facebook users. He supported a team that worked on “bullying tools for teens, suicide prevention, child safety and other difficult moments that people go through,” according to his LinkedIn profile.

He testified that he initially left Meta feeling “good that we had built numerous systems that made using our products easier and safer.” However, he said that, since they were 14, his daughter and her friends “repeatedly faced unwanted sexual advances, misogyny and harassment” on Instagram. According to The Wall Street Journal, which first reported on Béjar’s claims, he stated that Meta’s systems typically ignored reports they made or responded to say that the harassment they faced didn’t break the rules.

Those issues prompted him to return to Meta in 2019, where he worked with Instagram’s well-being team. “It was not a good experience. Almost all of the work that I and my colleagues had done during my earlier stint at Facebook through 2015 was gone,” Béjar said in his testimony. “The tools we had built for teenagers to get support when they were getting bullied or harassed were no longer available to them. People at the company had little or no memory of the lessons we had learned earlier.”

Béjar claimed that Instagram and internal research teams gathered data showing that younger teens dealt with “great distress and abuse.” However, “senior management was externally reporting different data that grossly understated the frequency of harm experienced by users,” he told senators.

In a 2021 email to Zuckerberg and other executives laying out some of his concerns, Béjar wrote that his then-16-year-old daughter uploaded a car-related post to Instagram only for a commenter to tell her to “get back to the kitchen.” Béjar said his daughter found this upsetting. “At the same time the comment is far from being policy violating, and our tools of blocking or deleting mean that this person will go to other profiles and continue to spread misogyny,” Béjar wrote. “I don’t think policy/reporting or having more content review are the solutions.”

Béjar said that along with his daughter’s experiences with the app, he cited data from a research team indicating that 13 percent of users aged between 13 and 15 reported that they received unwanted sexual advances on Instagram within the previous seven days. While former chief operating officer Sheryl Sandberg offered sympathy toward his daughter for her negative experiences and Instagram head Adam Mosseri asked to set up a meeting, according to Béjar, Zuckerberg never responded to the email.

“That was unusual,” Béjar said in his testimony. “It might have happened, but I don’t recall Mark ever not responding to me previously in numerous communications, either by email or by asking for an in-person meeting.”

Béjar told the Associated Press that Meta has to change its approach to moderating its platforms. This, according to Béjar, would require the company to place a greater onus on tackling harassment, unwanted sexual advances and other issues that don’t necessarily break the company’s existing rules.

He noted, for instance, that teens should be able to tell Instagram that they don’t want to receive crude sexual messages, even if those don’t violate the app’s current policies. Béjar claims it would be easy for Meta to implement a feature through which teens could flag sexual advances that were made to them. “I believe that the reason that they’re not doing this is because there’s no transparency about the harms that teenagers are experiencing on Instagram,” he told the BBC.

Béjar laid out several other steps that Meta could take to reduce harm users face on its platform that “do not require significant investments by the platforms in people to review content or in technical infrastructure.” He added that he believes adopting such measures (which primarily focus on improving safety tools and getting more feedback from users who have experienced harm) would not severely impact the revenues of Meta or other companies that adopt them. “These reforms are not designed to punish companies, but to help teenagers,” he told the subcommittee. “And over time, they will create a safer environment.”

“My experience, after sending that email and seeing what happened afterwards, is that they knew, there were things they could do about it, they chose not to do them and we cannot trust them with our children,” Béjar said during the hearing. “It’s time for Congress to act. The evidence, I believe, is overwhelming.”

“Countless people inside and outside of Meta are working on how to help keep young people safe online,” Meta spokesman Andy Stone told The Washington Post on Tuesday. “Working with parents and experts, we have also introduced over 30 tools to support teens and their families in having safe, positive experiences online. All of this work continues.”

Béjar hopes his testimony will help spur Congress to “pass the legislation that they’ve been working on” regarding the online safety of younger users. Two years ago, Haugen disclosed internal Facebook research indicating that Instagram was “harmful for a sizable percentage of teens.” Growing scrutiny led Meta to halt work on a version of Instagram for kids.

Since Haugen’s testimony, Congress has made some efforts to tackle online safety issues for kids, but those have stuttered. The Kids Online Safety Act (KOSA) twice advanced from a Senate committee (in the previous Congress and earlier this year), but it hasn’t reached a floor vote and there’s no companion bill in the House. Among other things, the bill seeks to give kids aged under 16 the ability to switch off “addictive features and algorithm-based recommendations, as well as having more protections for their data. Similar bills have stalled in Congress.

Last month, attorneys general from 41 states and the District of Columbia sued Meta over alleged harms it caused to young users. “Meta designed and deployed harmful and psychologically manipulative product features to induce young users’ compulsive and extended Platform use, while falsely assuring the public that its features were safe and suitable for young users,” according to the lawsuit. Béjar said he consulted with the attorneys general and provided them with documents to help their case.

“I’m very hopeful that your testimony, added to the lawsuit that’s been brought by state attorneys general across the country … added to the interest that I think is evidenced by the turnout of our subcommitee today, will enable us to get the Kids Online Safety Act across the finish line,” subcommittee chair Sen. Richard Blumenthal (D-CT) told Béjar. Blumenthal, one of KOSA’s original sponsors, expressed hope that other legislation “that can finally break the straitjacket that Big Tech has imposed on us” will be enacted into law.

Over the last few years and amid the rise of TikTok, Meta has once again been focusing on bringing younger users into its ecosystem, with Zuckerberg stating in 2021 (just a couple of weeks after Haugen’s testimony) that the company would refocus its “teams to make serving young adults their North Star rather than optimizing for the larger number of older people.” Recently, the company lowered the minimum age for using its Meta Quest VR headsets to 10 through the use of parent-controlled accounts.

This article originally appeared on Engadget at https://www.engadget.com/meta-whistleblower-tells-senate-the-company-cannot-be-trusted-with-our-children-185616936.html?src=rss

Engadget is a web magazine with obsessive daily coverage of everything new in gadgets and consumer electronics

Twitter merges misinformation and spam teams following whistleblower claims

Twitter is making a major change to its organization after former security head Peiter "Mudge" Zatko accused the company of having lax security and bot problems. According to Reuters, Twitter is merging its health experience team, which is in charge of clamping down on misinformation and harmful content on the website, with its service team. The latter reviews profiles when they're reported and takes down spam accounts. Together, the combined group will be called Health Products and Services (HPS). 

The group will be led by Ella Irwin, who joined the company in June and had previously worked for Amazon and Google. Reuters says Irwin sent a memo to staff members, telling them that HPS with "ruthlessly prioritize" its projects. "We need teams to focus on specific problems, working together as one team and no longer operating in silos," Irwin reportedly wrote. 

In a statement sent to Reuters, a Twitter spokesperson said the reshuffling "reflects [the company's] continued commitment to prioritize, and focus [its] teams in pursuit of [its] goals." A source also told the news organization that the teams dealing with harmful and toxic content have had major staff departures recently. Merging these two teams may be the best way to ensure that all important roles are filled going forward. 

This news comes on the heels of the revelation that Zatko filed a whistleblower complaint against his former employer. In it, he said Twitter has "extreme, egregious deficiencies" when it comes to security and that it prioritizes user growth over cleaning up spam. Shortly after The Washington Post reported on Zatko's complaint, which also raises concerns about national security, lawmakers from both sides of the aisle announced that they're looking into his claims

In an email to employees, Twitter CEO Parag Agrawal defended the company and echoed its spokesperson's statement that Zatko's complaint is a "false narrative that is riddled with inconsistencies and inaccuracies." You can read the whole memo, obtained by Bloomberg, below:

"Team,

There are news reports outlining claims about Twitter’s privacy, security, and data protection practices that were made by Mudge Zatko, a former Twitter executive who was terminated in January 2022 for ineffective leadership and poor performance. We are reviewing the redacted claims that have been published, but what we’ve seen so far is a false narrative that is riddled with inconsistencies and inaccuracies, and presented without important context.

I know this is frustrating and confusing to read, given Mudge was accountable for many aspects of this work he is now inaccurately portraying more than six months after his termination. But none of this takes away from the important work you have done and continue to do to safeguard the privacy and security of our customers and their data. This year alone, we have meaningfully accelerated our progress through increased focus and incredible leadership from Lea Kissner, Damien Kieran, and Nick Caldwell. This work continues to be an important priority for us, and if you want to read more about our approach, you can find a summary here.

Given the spotlight on Twitter at the moment, we can assume that we will continue to see more headlines in the coming days – this will only make our work harder. I know that all of you take a lot of pride in the work we do together and in the values that guide us. We will pursue all paths to defend our integrity as a company and set the record straight.

See you all at #OneTeam tomorrow,

Parag"

Engadget is a web magazine with obsessive daily coverage of everything new in gadgets and consumer electronics

Whistleblower accuses Twitter of being ‘grossly negligent’ towards security

Peiter "Mudge" Zatko, Twitter's former head of security, says the company has misled regulators about its security measures in his whistleblower complaint that was obtained by The Washington Post. In his complaint filed with the Securities and Exchange Commission, the Department of Justice and the Federal Trade Commission, he accuses the company of violating the terms it had agreed to when it settled a privacy dispute with the FTC back in 2011. Twitter, he says, has "extreme, egregious deficiencies" when it comes to defending the website against attackers.

As part of that FTC settlement, Twitter had agreed to implement and monitor security safeguards to protect its users. However, Zatko says half of Twitter's servers are running out-of-date and vulnerable software and that thousands of employees still have wide-ranging internal access to core company software, which had previously led to huge breaches. If you'll recall, bad actors were able to commandeer the accounts of some of the most high-profile users on the website in 2020, including Barack Obama's and Elon Musk's, by targeting employees for their internal systems and tools using a social engineering attack. 

It was after that incident that the company hired Zatko, who used to lead a program on detecting cyber espionage for DARPA, as head of security. He argues that security should be a bigger concern for the company, seeing as it has access to the email addresses and phone numbers of numerous public figures, including dissidents and activists whose lives may be in danger if they are doxxed.

The former security head wrote:

"Twitter is grossly negligent in several areas of information security. If these problems are not corrected, regulators, media and users of the platform will be shocked when they inevitably learn about Twitter’s severe lack of security basics.

In addition, Zatko has accused Twitter of prioritizing user growth over reducing spam by distributing bonuses tied to increasing the number of daily users. The company isn't giving out any bonuses directly tied to reducing spam on the website, the complaint said. Zatko also claims that he could not get a direct answer from Twitter regarding the true number of bots on the platform. Twitter has only been counting the bots that can view and click on ads since 2019, and in its SEC reports since then, its bot estimates has always been less than 5 percent. 

Zatko wanted to know the actual number of bots across the platform, not just the monetizable ones. He cites a source who allegedly said that Twitter was wary of determining the real number of bots on the website, because it "would harm the image and valuation of the company." Indeed his revelation could factor into Twitter's legal battle against Elon Musk after the executive started taking steps to back out of his $ 44 billion takeover. Musk accused Twitter of fraud for hiding the real number of fake accounts on the website and revealed that his analysts found a much higher bot count than Twitter claimed. As The Post notes, though, Zatko provided limited hard documentary evidence regarding spam and bots, so it remains unclear if it would help Musk's case.

When asked why he filed a whistleblower complaint — he's being represented by the nonprofit law firm Whistleblower Aid — Zatko replied that he "felt ethically bound" to do so as someone who works in cybersecurity. Twitter spokesperson Rebecca Hahn, however, denied that the company doesn't make security a priority. "Security and privacy have long been top companywide priorities at Twitter," she said, adding that Zatko's allegations are "riddled with inaccuracies." She also said that Twitter fired Zatko after 15 months "for poor performance and leadership" and that he now "appears to be opportunistically seeking to inflict harm on Twitter, its customers, and its shareholders."

Engadget is a web magazine with obsessive daily coverage of everything new in gadgets and consumer electronics

Whistleblower says Microsoft spent millions on bribes abroad

In an essay published Friday on the whistleblower platform Lioness, former Microsoft manager Yasser Elabd alleged that Microsoft fired him after he alerted leadership to a workplace where employees, subcontractors and government operators regularly engaged in bribery. He further alleges that attempts to escalate his concerns resulted in retaliation within Microsoft by managers, and eventual termination from his role.

Elabd claims in his essay that he worked for Microsoft between 1998 and 2018, and had oversight into a "business investment fund " — essentially a slush fund to "cement longer-term deals" in the Mid-East and Africa. But he grew suspicious of unusual payments to seemingly unqualified partners. After examining several independent audits, he discovered what he believes is a common practice: After setting up a large sale to entities in the region, a "discount" would be baked in, only for the difference between the full-freight cost and discounted fee to be skimmed off and divided between the deal-makers.

“This decision maker on the customer side would send an email to Microsoft requesting a discount, which would be granted, but the end customer would pay the full fee anyway. The amount of the discount would then be distributed among the parties in cahoots: the Microsoft employee(s) involved in the scheme, the partner, and the decision maker at the purchasing entity—often a government official,” Elabd alleged.

The former Microsoft manager gave several examples of suspicious transactions and red flags he witnessed over his two decades working for the company abroad. In one audit, Microsoft gave the Saudi Ministry of the Interior a $ 13.6 million discount which never reached the agency’s doors. In 2015, a Nigerian official complained that the government paid $ 5.5 million for licenses "for hardware they did not possess."

In another example, Qatar’s Ministry of Education paid $ 9.5 million, over a period of seven years, for Microsoft Office and Windows licenses that went unused. Auditors later discovered that employees at that agency didn’t even have access to computers.

“We are committed to doing business in a responsible way and always encourage anyone to report anything they see that may violate the law, our policies, or our ethical standards,” Becky Lenaburg, a VP at Microsoft and deputy general counsel for compliance and ethics, wrote in a statement to The Verge. “We believe we’ve previously investigated these allegations, which are many years old, and addressed them. We cooperated with government agencies to resolve any concerns.”

Elabd claims his attempts to alert managers resulted in his being shouted at by one manager, iced out of certain deals and told by an executive that he had effectively set himself up to be let go after attempting to involve CEO Satya Nadella. After being terminated, Elabd wrote that he brought his documentation before the Securities and Exchange Commission and Department of Justice. He claims the DoJ refused to take up his case. According to Protocol, the SEC dropped the case earlier this month due to a lack of resources.

“As I alleged in my complaint to the SEC, Microsoft is violating the Foreign Corrupt Practices Act, and continues to do so brazenly. And why wouldn’t they?" wrote Elabd. "By declining to investigate these allegations and the evidence I’ve given them, the SEC and DOJ have given Microsoft the green light.”

Engadget is a web magazine with obsessive daily coverage of everything new in gadgets and consumer electronics

NSA whistleblower Snowden, CNN’s Zakaria face off over encryption

A debate on whether the government should have lawful access to encrypted communications and devices saw former NSA contractor Edward Snowden duking it out with CNN host Fareed Zakaria.

The post NSA whistleblower Snowden, CNN’s Zakaria face off over encryption appeared first on Digital Trends.

Mobile–Digital Trends