
Zatko said that when he arrived at Twitter, he began asking: "Why do they keep having so many security incidents? The same amount year after year … What is fundamentally, under-the-hood broken? Where is the systemic failure?"
One part of the problem, he said, is that Twitter doesn't fully understand all the data it collects from users or why it collects that data.
He cited an internal study conducted by engineers which allegedly found that for only about 20% of the data it collects does the company know "why they got it, how it was supposed to be used, when it was supposed to be deleted." With the remainder of the data, the company often did not know what the data was or why it was being collected, Zatko said. Samples of that unknown data in the study included personally identifying information such as phone numbers and addresses, he claimed.
Zatko also said that bad actors with access to Twitter's system could potentially access and exploit that data because the company doesn't properly understand, and therefore protect, the data it collects.