Peiter Zatko: Mudge's Journey From L0pht to Twitter
On May 19, 1998, seven hackers with names like Space Rogue and Kingpin sat down in front of the Senate Governmental Affairs Committee and told the senators they could take down the internet in about 30 minutes. The one doing much of the talking called himself Mudge.
Peiter Zatko has spent the years since turning that warning into a career. He ran cyber programs at DARPA, held senior security jobs at Motorola, Google and Stripe, and was hired to fix Twitter after teenagers hijacked the accounts of Joe Biden and other famous users.
Then Twitter fired him, and in September 2022 he was back in front of the Senate, this time as a whistleblower. The strangest twist came later: the kid who warned Washington became the man Washington hired. Twice.
Peiter Zatko at a Glance
- A member of the L0pht, the Massachusetts hacker collective of the 1990s, Zatko published "How to write Buffer Overflows" in October 1995, an early paper on the technique.
- On May 19, 1998, he and six fellow L0pht members testified before the Senate, by their handles, that the nation's networks were riddled with holes.
- In 2010 he took an appointed post running cyber programs at DARPA, work that earned him the Office of the Secretary of Defense's medal for exceptional public service.
- Back in industry, he held senior security roles at Motorola, Google and Stripe and co-founded a nonprofit software testing lab with his wife, Sarah Zatko.
- In November 2020 Jack Dorsey hired him as Twitter's head of security after the July 2020 account takeovers; Twitter dismissed him in January 2022.
- His whistleblower disclosures to regulators became public in August 2022, were seized on by Elon Musk in the fight over his $44 billion takeover, and brought Zatko before the Senate Judiciary Committee on September 13, 2022.
- In 2023 he joined the security firm Rapid7 and advised the Cybersecurity and Infrastructure Security Agency part time.
- In June 2024 he returned to DARPA as its chief information officer.
The Life of Peiter Zatko
Mudge's Early Years
Zatko keeps his childhood out of the story, and the public record of him begins in the 1990s in Massachusetts, with a crew of hackers who shared a loft and called themselves the L0pht.
Its members went by handles: Brian Oblivion, Kingpin, Space Rogue, Weld Pond, Tan, Stefan von Neumann and Mudge. What set them apart from the underground was that they published what they found, in security advisories that companies couldn't ignore.
The L0pht
The L0pht's advisories picked apart Unix software, Windows networking and commercial products, and the group's password-auditing tool, L0phtCrack, became a staple of corporate security teams. Mudge was the collective's most visible member.
In October 1995 he wrote up a technique that'd define the next two decades of attacks. How to write Buffer Overflows opens with a disclaimer that it's "really rough" and was written as a reminder to himself, which is how a lot of foundational hacker literature started.
He'd later describe his part in those years as "helping to found the responsible disclosure movement": tell the vendor quietly, and go public only if they refuse to fix it.
Thirty Minutes
By 1998 the group was respectable enough to be invited to Washington. Senator Fred Thompson's committee opened a hearing titled "Weak Computer Security in Government: Is the Public at Risk?" with a warning that the nation's information infrastructure was riddled with vulnerabilities, and then called seven witnesses identified only by their handles.
Alongside them sat Peter Neumann of SRI International, a veteran computer scientist, which told the room the hackers weren't a stunt.
The line everyone remembers came from Mudge: that the L0pht could take down the internet in about 30 minutes. It was meant as a measure of how fragile the whole system was, and the press ran with it. The hearing became the origin story of hackers testifying to Congress.
Advising Presidents
Zatko has said he's advised a sitting president, administrations of both parties, Congress and the intelligence community. In 2010 the advising became a job: he accepted an appointed position running cyber programs for the Defense Department and intelligence community at DARPA, including the Cyber Fast Track effort, which funded small, fast-turnaround security research.
For that work he was awarded the Office of the Secretary of Defense's medal for exceptional public service, which he describes as the highest honor the office can give a non-career civilian.
He then went back to the private sector, with senior security roles at Motorola, Google and Stripe. With his wife, Sarah Zatko, he also co-founded the Cyber Independent Testing Lab, a nonprofit that set out to measure how well software's safety features actually work, on the theory that nobody had ever really checked.
In July 2020 a group of teenagers hijacked the Twitter accounts of Joe Biden and other high-profile users to run a cryptocurrency scam, in what Zatko later called the largest hack of a social media platform in history. Afterward, Jack Dorsey reached out and asked him to assess the company's security and fix it.
He joined in November 2020 with a sprawling brief covering information security, privacy engineering, physical security and IT. What he found, he told the Senate, was a company with "10 years of overdue critical security issues" that wasn't making meaningful progress on them.
Twitter dismissed him in January 2022. He filed disclosures with federal regulators, and in late August 2022 they became public, alleging security failures and misleading statements to the board and regulators. Within days Musk's lawyers were citing them in his attempt to walk away from his $44 billion purchase of the company.
The Whistleblower
On September 13, 2022, Zatko testified before the Senate Judiciary Committee under the heading Data Security at Risk: Testimony from a Twitter Whistleblower. Listed as an independent security consultant, he walked the senators through what he'd seen.
"I did not make my whistleblower disclosures out of spite or to harm Twitter," his written statement said. He framed the decision as the same ethical-disclosure philosophy he'd followed since the L0pht: report quietly, and go public when the institution won't fix the problem.
Musk's purchase went through anyway. Zatko's testimony remains the most detailed public account of what its security looked like just before.
Back to DARPA
Zatko landed at the security firm Rapid7 in January 2023 and later served as an executive in residence there, while also advising the Cybersecurity and Infrastructure Security Agency part time.
Then, in June 2024, he went back to the agency where he'd once run programs, this time as DARPA's chief information officer. He announced it himself that August: "Let's see if we can make an even bigger dent in the universe this second time around."
Peiter Zatko: The Warning Washington Finally Hired
In 1998 the senators listened politely to Mudge and did very little. A quarter century later the government put him in charge of the information systems at its most ambitious research agency.
That's the arc of his story, and of the industry he helped invent: the kids in the loft were right, and it took the institutions decades to admit it.
He said it'd take 30 minutes. It took them 26 years.
QUOTE:
"Amateurs hack systems, professionals hack people."