Deleted tweet detection is currently running at reduced
capacity due to changes to the Twitter API. Some tweets that have been
deleted by the tweet author may not be labeled as deleted in the PolitiTweet
interface.
Showing page 293 of 2161.
Eric Geller @ericgeller
“The longer delay there is, the more that compromises our capabilities and the projection of power we need to make,” said @C_Painter, who led State's current cyber office as the top U.S. cyber diplomat from 2011 to 2017. — PolitiTweet.org
Eric Geller @ericgeller
Why does the delay matter? Cyber aid projects (like helping allies upgrade network defenses and craft new laws around info sharing and data breach reporting) take time to plan, ratify, and implement. The results can take months or years to materialize. — PolitiTweet.org
Eric Geller @ericgeller
State official said process has “moved much, much faster” than other similar reorgs, but there's no denying that it's taken a long time. Trump admin first proposed new bureau in 2018 but didn't actually start creating it until January 2021 — & then Biden's team paused that work. — PolitiTweet.org
Eric Geller @ericgeller
“We expect the bureau will be up and running within the next few months,” senior State official told me. State's now moving around money and personnel and starting to hire 50 new staffers, which could significantly expand the number of projects the bureau can undertake. — PolitiTweet.org
Eric Geller @ericgeller
Congress approved State's plan for the bureau — which will unite existing teams focused on cybersecurity, digital economy and internet freedom issues — on Jan. 26, a senior dept official told me exclusively. Blinken announced plan last October, State submitted to Hill in Dec. — PolitiTweet.org
Eric Geller @ericgeller
New: @StateDept recently got congressional approval to launch its cyber diplomacy bureau. But years of delays mean its improvements to foreign cyber aid won't be felt for a while — even as crises like Ukraine show how important this aid is. My story (🔒): https://t.co/zmRDdCLDLG — PolitiTweet.org
Eric Geller @ericgeller
@marianne_levine all hail the queen — PolitiTweet.org
Eric Geller @ericgeller
"Bowser has turned to a model that has DCHA undervaluing its own land, allowing developers to lock into ground leases with favorable terms and no money down, and then incentivizing them with tax breaks, subsidies, and...fees that come from public funding sources." — PolitiTweet.org
District Dig @DistrictDig
The Dig is coming in hot with an EXCLUSIVE feature on the reasons behind the pending site visit by @HUDgov to… https://t.co/eeR1ffWF6y
Eric Geller @ericgeller
.@EACgov personnel watch: Mark Robbins, a former OPM general counsel and MSPB vice chair, will serve as the EAC's interim executive director beginning on Feb. 14, following Mona Harrington's departure to join CISA. Robbins previously worked at the EAC as GC from 2010-2012. https://t.co/ekML5ThWki — PolitiTweet.org
Eric Geller @ericgeller
@JennaMC_Laugh @Joseph_Marks_ ❤️ thank you! — PolitiTweet.org
Eric Geller @ericgeller
@eleventhirtyate good thread though — PolitiTweet.org
Eric Geller @ericgeller
@Joseph_Marks_ aww shucks, thanks man — PolitiTweet.org
Eric Geller @ericgeller
Statement of facts from the investigating FBI agent in support of the complaint and arrest warrant: https://t.co/BgTmLtaDpq https://t.co/qcmJsW8k2V — PolitiTweet.org
Eric Geller @ericgeller
New: U.S. arrests New York couple for allegedly conspiring to launder $4.5 billion worth of cryptocurrency stolen in the 2016 Bitfinex hack. Authorities have recovered more than $3.6 billion after seizing files that contained private keys for the couple's bitcoin wallets. https://t.co/jpmeuqHNLl — PolitiTweet.org
Eric Geller @ericgeller
Peters closes the hearing, saying, "The impacts of widespread vulnerabilities need to be better understood, and we need to pass incident reporting legislation to ensure that we actually have a full picture of the threat that we are facing in this country." — PolitiTweet.org
Eric Geller @ericgeller
Rosen asks how OSS community can implement ZTA to limit damage from vuln in OSS. Nalley says OSS developers often don't know how their software will be used. It's end users who need to implement ZTA. He says end users should participate more in OSS communities to offer context. — PolitiTweet.org
Eric Geller @ericgeller
Jacky Rosen: Should federal contractors be required to disclose SBOMs to agency customers? Atlantic Council's Trey Herr: “Yes, senator, absolutely, it should be a basic condition of doing business.” — PolitiTweet.org
Eric Geller @ericgeller
Nalley says that as of mid-January, the main Java OSS component repository (Maven Central) was seeing “around 10,000 downloads per hour” of Log4j, around 30% of which were still for a vulnerable version. — PolitiTweet.org
Eric Geller @ericgeller
Log4j built up to his question by highlighting how China retaliated against the researcher who disclosed the flaws and by noting that China's hacker army is becoming increasingly aggressive. — PolitiTweet.org
Eric Geller @ericgeller
Josh Hawley asks the panel if they know about any attempts by China to exploit the Log4j flaws. No one knows. — PolitiTweet.org
Eric Geller @ericgeller
Nalley: "We've gone back and looked to see whether automated tools could have detected this vulnerability. And we've come to the conclusion that none of the automated tools on the market today would have done so, had they been looking either then or even very recently." — PolitiTweet.org
Eric Geller @ericgeller
James Lankford asks how OSS projects prevent tampering by bad actors. Nalley says project maintainers review all contributions, with the smaller ones getting reviewed more quickly and the larger or "more esoteric" changes getting heavier scrutiny. — PolitiTweet.org
Eric Geller @ericgeller
Hassan: Would it help if CDM included a pilot program to help state & local govts improve network visibility? Miller-Osborn: “Anything that we could do to provide that level of guidance, especially at a cohesive level, would be good and helpful." — PolitiTweet.org
Eric Geller @ericgeller
Maggie Hassan asks how JCDC has helped under-resourced orgs respond to Log4j. Miller-Osborn says JCDC can be "a clearinghouse for giving effective guidance geared towards these mid-to-lower-sized businesses." — PolitiTweet.org
Eric Geller @ericgeller
Peters asks how CISA's JCDC helped with the Log4j response. Arkin: "The information that we got through the JCDC helped us to understand the techniques and attacks that were being observed in the real world, so that we could then marshal our resources in defense of that." — PolitiTweet.org
Eric Geller @ericgeller
Peters asks the witnesses how an incident reporting mandate would help govt and private sector. Miller-Osborn says "there is real policy benefit from sharing cyber incident information, especially if CISA is able to then provide bidirectional benefit" back to industry. — PolitiTweet.org
Eric Geller @ericgeller
Here's the text of the big new omnibus cyber bill from HSGAC, the Strengthening American Cybersecurity Act: https://t.co/IIFAyk645g — PolitiTweet.org
Eric Geller @ericgeller
‼️ HSGAC Chair Gary Peters says that he and ranking member Rob Portman have introduced a bill that combines their c… https://t.co/Wtm4if1r0c
Eric Geller @ericgeller
Palo Alto Networks' Jen Miller-Osborn stresses that the biggest issue revealed by Log4j isn't the patchwork nature of support for OSS, but the inherent vulnerability of software and the need to shift to zero-trust architecture and other solutions that presume compromise. — PolitiTweet.org
Eric Geller @ericgeller
Cisco's Brad Arkin says "competitive pressures" encourage widespread contributions to OSS. If one company is benefitting from an OSS project but not giving back, another company can swoop in and "steer the project in a direction more suited to their interests." — PolitiTweet.org
Eric Geller @ericgeller
"In response to this [incident], we're seeing greatly increased contribution around security auditing and code validation in Log4j and a number of other open source projects," Nalley says. — PolitiTweet.org