Deleted tweet detection is currently running at reduced
capacity due to changes to the Twitter API. Some tweets that have been
deleted by the tweet author may not be labeled as deleted in the PolitiTweet
interface.
Showing page 373 of 2161.
Eric Geller @ericgeller
@kristenkbates @BrantRussell I am sad that we won't be able to get hochocs together in New York and chase ghosts and such — PolitiTweet.org
Eric Geller @ericgeller
@kristenkbates @BrantRussell Oh my god it's back — PolitiTweet.org
Eric Geller @ericgeller
[guillotine emoji] — PolitiTweet.org
Gabriel Zucman @gabriel_zucman
Purdue Pharma is dissolved — but its owners get to keep billions shielded from US outreach in offshore trusts… https://t.co/M8bntYOvJv
Eric Geller @ericgeller
absolutely chilling how influential these morons are — PolitiTweet.org
Wild Geerters @steinkobbe
The most popular podcaster in the world being a braindead meathead eating horse paste is a perfect illustration of… https://t.co/ILDuTDurLc
Eric Geller @ericgeller
okay, a little bit of editorializing there, Wikipedia https://t.co/k3eFTnDaxY — PolitiTweet.org
Eric Geller @ericgeller
The mainstream position of the Republican Party is to reject policies that would ameliorate the effects of this idiocy. https://t.co/OQplbQwpLr — PolitiTweet.org
Fenit Nirappil @FenitN
I just... https://t.co/WEd4wNhSLv https://t.co/esC0I2RhFH
Eric Geller @ericgeller
My story on today's House hearing: "Industry support for House cyber incident reporting bill suggests trouble ahead for Senate version" https://t.co/oXiuYa0Bw6 — PolitiTweet.org
Eric Geller @ericgeller
Bigoted scum. — PolitiTweet.org
Sopan Deb @SopanDeb
“A few days later, a parent complained to the district about a photo Whitfield had posted that showed him and his W… https://t.co/pBfVqrPO4X
Eric Geller @ericgeller
The hearing has adjourned. The industry testimony on the House bill showed that there will be plenty of resistance to the Senate bill if it moves forward. The question now is, will the Senate bill's sponsors accommodate industry concerns or double down on their approach? — PolitiTweet.org
Eric Geller @ericgeller
Bushar tells Clarke that security firms like FireEye shouldn't be required to report incidents that they discover on their customers' networks. He says it would betray the customer's trust and discourage companies from seeking security services. Senate bill requires this. — PolitiTweet.org
Eric Geller @ericgeller
It seems like most of the subcommittee isn't attending this hearing. We appear to have just finished the first round of questioning, and the only people who spoke were the subcommittee leaders, full committee chair Bennie Thompson, and three members. — PolitiTweet.org
Eric Geller @ericgeller
Sheila Jackson Lee: How important is it to have bidirectional information sharing? Bushar: "Critical." Denbow: "We feel like when we share with the government, it becomes a landfill of information, with nothing valuable coming back out to us in a timely fashion." — PolitiTweet.org
Eric Geller @ericgeller
Langevin says "a bit concerned about the gap I see" b/w how much CISA needs and how much it would get if companies only had to report confirmed breaches. He says companies might not report staging activity that precedes a ransomware campaign, hampering CISA's response. — PolitiTweet.org
Eric Geller @ericgeller
Bushar says companies won’t wait until they have a complete picture of an attack, but they do need time to confirm that a breach has happened. — PolitiTweet.org
Eric Geller @ericgeller
Jim Langevin: If companies only have to report confirmed breaches, how will we be better positioned to mitigate something like SolarWinds? Mayer: If you have something on the scale of SW, “you’re going to know it when you see it.” And USG will likely already be aware of it. — PolitiTweet.org
Eric Geller @ericgeller
Witnesses are emphasizing the need for narrow rules about what info to share. Hogsett says can't deluge CISA w/ info that it can't process. Mayer says need to avoid “fog of more,” where short deadline prompts companies to quickly share too much info that makes analysis hard. — PolitiTweet.org
Eric Geller @ericgeller
Garbarino asks what should be defined in legislation vs. rulemaking. Denbow and Mayer says that most details should be left to CISA/industry consultations during the rulemaking process. — PolitiTweet.org
Eric Geller @ericgeller
Clarke asks Bushar what info industry needs from CISA. It's much the same as what CISA needs from industry, he says. Industry can combine CISA's insights with its own to better understand adversary behavior. — PolitiTweet.org
Eric Geller @ericgeller
Clarke asks Bushar what info CISA needs from industry. He cites examples such as IOCs, malware samples, info on targeted users and systems, and info on stolen data. — PolitiTweet.org
Eric Geller @ericgeller
AGA's Kimberly Denbow recommends the bill require outreach to sector coordinating councils in developing regulations; ensure regular review of list of covered companies; ensure CISA has enough expert personnel to work w/ industry; and narrow exceptions to ban on info disclosure. — PolitiTweet.org
Eric Geller @ericgeller
USTelecom's Robert Mayer encourages the committee to let federal and industry experts collaborate on reporting thresholds rather than setting them in legislation, since it's "a highly technical exercise." He also recommends provisions to prevent shared information from leaking. — PolitiTweet.org
Eric Geller @ericgeller
On harmonization with existing regulations, Miller recommends encouraging CISA to collect incident information through existing channels and partnerships (e.g. FBI, SEC) whenever possible, rather than creating new reporting channels and processes. — PolitiTweet.org
Eric Geller @ericgeller
ITI's John Miller recommends: "feasible" timelines (≥72 hrs), confidentiality protections (says may need to update 2015 CISA law), harmonize w/ existing regs, "appropriate" reporting thresholds (limit to verified incidents), and limit reporting to impacted entities, not vendors. — PolitiTweet.org
Eric Geller @ericgeller
Heather Hogsett from BPI praises the bill for its scope, its 72-hour minimum for a reporting deadline, its incorporation of privacy protections for shared information, the req to harmonize rules with existing regulations, and the req for govt to share more data w/ industry. — PolitiTweet.org
Eric Geller @ericgeller
Bushar also warns against punitive provisions of incident reporting bills, such as subpoena authority when companies don't report hacks. Subpoenas and other compulsory measures, he says, don't make sense when dealing with what are essentially crime victims. — PolitiTweet.org
Eric Geller @ericgeller
FireEye's Ron Bushar says any reporting requirement should allow for agility and adjustment, given how quickly the cyber threat landscape can change. Companies should have a "reasonable" amount of time to assess an attack before having to report it, he says. — PolitiTweet.org
Eric Geller @ericgeller
Since I rather abruptly mentioned the Senate bill in this tweet, here's the announcement of that bill for those who aren't familiar with it: https://t.co/HHhZ6Snamm It's stacked with powerful sponsors, but what we're seeing today is that industry prefers the House bill. — PolitiTweet.org
Eric Geller @ericgeller
Industry witnesses will implicitly criticize the Senate bill. BPI: 24-hr reporting deadline "would distract from c… https://t.co/kKNvsm5D1Y
Eric Geller @ericgeller
Subcommittee RM Andrew Garbarino: “I've been pleased to see our majority counterparts engage our members in productive conversations on this topic, and I hope we can continue the constructive dialogue here today.” — PolitiTweet.org
Eric Geller @ericgeller
But Clarke adds, "I would certainly be happy to explore whether we need to add language directing CISA to provide additional compliance assistance to small businesses that are determined to be covered entities." — PolitiTweet.org
Eric Geller @ericgeller
House Homeland cyber subcmte chair Yvette Clarke, opening the hearing, says she's heard concerns about compliance challenges for small CI firms. "We do not expect all [CI companies] to be subject to this reporting requirement. Rather, we expect it to apply only to a subset.” — PolitiTweet.org