Zach Edwards Profile picture
privacy & data supply chain research / Senior Threat Analyst @SilentPush / politico / #build🔥🕸 ρᔕ𝐞ỮĎ𝔬Ňʸ๓Øᵘ丂 /

Aug 24, 2022, 15 tweets

I've gone through mudge's redacted whistleblower complaint and there are some really spicy sections that relate to ad tech + privacy + foreign intelligence... brief thread of what I think is most interesting (link to documents in tweet below)🌶️🐦🌩️⚖️🧵

First up... folks have known for awhile that tons of Chinese advertisers were/are buying Twitter ads... But no one had pieced it together that those Chinese advertisers would be using ***Twitter Custom Audiences to doxx VPN users who verified with real contact info...** 🚨🥵🥵🚨

"Twitter executives opted to allow Twitter to become more dependent upon revenue coming from Chinese entities even though the Twitter service is blocked in China...."

It seems clear that Twitter is becoming "more dependent" on China.. via.. Twitter advertising. Uhh @congress ??

"After Chinese entities paid money to Twitter, there were concerns within Twitter that the information the Chinese entities could receive would allow them to identify and learn sensitive information about Chinese users who successfully circumvented the block..."

View Through DOX

I would show this in a native twitter ads interface but I'm banned from twitter ads for unknown / probably doing weird stuff reasons. But Twitter's Custom audiences can be built with *emails* (historically phone numbers too) + MobileIDs == DOX risks…

If the Chinese entities had specific lists of people to dox, and had their protonmail emails or androidIDs, they could load those up into twitter ads campaigns w/ custom audiences filled w/ bad data, so that you "accidently" only target 1 person or a small group. == DOXX city

And what Mudge is describing is a common Doxxing scenario -- if you let someone spin up countless custom audience segments, upload countless variations of the same data, don't police them doing weird ass shit with their campaigns, and don't care who pays those bills? DOXX CITY

"...the Chinese entities could receive would allow them to identify and learn sensitive information about Chinese users who successfully circumvented the block,🚨 and other users around the world🚨."

**the Chinese entities uploaded Custom Ad Lists w/ non-Chinese data** 👀🥵🌩️

Do you understand what it means if Twitter isn't policing Chinese entities who run content ad farms from uploading custom audiences with data from people all over the world? And if Twitter lets them run ads with that data? Doxx city Doxx Doxx city 🥵🥵🥵

Twitter apparently used their cookies for "all purposes" (security cookies used for advertising) ++ once told by the French CNIL to change this, they kept it on purposefully for another month "in order to extract maximum profit from French users before rolling out the fix." 😅🫥

"Twitter employees were repeatedly found to be intentionally installing spyware on their work computers at the request of external organizations. Twitter learned of this several times only by accident, or because of employee self-reporting." 👀📴📴

Which external orgs???? 🧐🧐

Interesting process to redact an external audit so that you can't be held accountable to the findings:

"Twitter counsel explicitly told Mudge that this was intended to hide the findings and prevent them from becoming known internally or externally"

"Twitter maintains a list of hateful terms and slurs that cannot be used for ad targeting. But Mudge learned that the list was not "stemming" properly, meaning that even minor variations on slurs were able to be used for targeting for an unknown period..."

uhh who used those??🥶

"...The Indian government forced Twitter to hire specific individual(s) who were government agents... it was believed by the executive team that the Indian government had succeeded in placing agents on the company payroll..."

So Indian spies at Twitter, huh? neat.🙄🥵

Ending this thread w/ :

"Shortly before Mudge was ___ terminated, Twitter received specific information from a U.S. government source that one or more particular company employees were working on behalf of another particular foreign intelligence agency."

g'night, goodluck!🌩️⚖️

Share this Scrolly Tale with your friends.

A Scrolly Tale is a new way to read Twitter threads with a more visually immersive experience.
Discover more beautiful Scrolly Tales like this.

Keep scrolling