Deleted tweet detection is currently running at reduced
capacity due to changes to the Twitter API. Some tweets that have been
deleted by the tweet author may not be labeled as deleted in the PolitiTweet
interface.
Showing page 518 of 2161.
Eric Geller @ericgeller
@Bing_Chris good call, I'd even go one step further and say people should leak it to me — PolitiTweet.org
Eric Geller @ericgeller
Warner: "I don't think our traditional reporting mechanisms necessarily work." — PolitiTweet.org
Eric Geller @ericgeller
Smith agrees with call for data breach notification law and says at a minimum it should cover tech companies that provide enterprise services. Says liability protection might help make companies feel more comfortable. — PolitiTweet.org
Eric Geller @ericgeller
Cornyn: "I can only imagine the chills that run up and down some people's backs when I say that. … But if we're gonna get our arms around this at all, it seems to me we need to know a lot more than we know under the current [laws]." — PolitiTweet.org
Eric Geller @ericgeller
Cornyn: "It seems to me that there should be an obligation of some sort on the part of a victim of a cyberattack like this to share what they know, what they've learned, with the appropriate authorities." — PolitiTweet.org
Eric Geller @ericgeller
Cornyn comes out in favor of data breach notification legislation, saying he discussed an earlier attempt, Lieberman/Collins, with Collins. — PolitiTweet.org
Eric Geller @ericgeller
Ramakrishna: “We believe that dubbing it simply as a SolarWinds hack is doing injustice to the broader software community and giving us a false sense of security," because supply chain attacks can affect anyone. — PolitiTweet.org
Eric Geller @ericgeller
Warner implies Congress will haul in those other vendors. “There are other brand-name, known IT and software and cloud services [companies] that may have been vulnerable...and their public and active participation — we're going to get working to make sure that takes place.” — PolitiTweet.org
Eric Geller @ericgeller
Smith implies that other vendors know they were hacked but are staying quiet. “There may be other brand-name players that may have been penetrated that not have been as forthcoming [and] are leaving policymakers and potentially customers in the dark.” — PolitiTweet.org
Eric Geller @ericgeller
Warner asks why we still don't know about most of the other non-SolarWinds vectors that the hackers used to breach companies. Smith: "We may never know exactly what the right number [of vectors] is." — PolitiTweet.org
Eric Geller @ericgeller
Kurtz: “The tradecraft and operational security was superb.” "They took particular care to actually conceal their identity." The hackers scrubbed their digital "fingerprints" from their code to make attribution harder. — PolitiTweet.org
Eric Geller @ericgeller
Mandia: “The question really is, where’s the next one, and when are we going to find it?” — PolitiTweet.org
Eric Geller @ericgeller
Rubio: How much sophistication does it take to do a supply chain attack like this? Mandia describes how the backdoor was coded to evade detection and make incident response more challenging. — PolitiTweet.org
Eric Geller @ericgeller
Nothing much interesting from CrowdStrike CEO George Kurtz in his opening statement. Mostly a recitation of basic cybersecurity principles that need to be prioritized going forward. — PolitiTweet.org
Eric Geller @ericgeller
@AlexJamesFitz booo — PolitiTweet.org
Eric Geller @ericgeller
Smith calls for new focus on protecting software build systems; for modernizing IT infrastructure; for enhancing threat intel sharing; and for imposing new breach notification requirements. — PolitiTweet.org
Eric Geller @ericgeller
Smith compares SolarWinds to a burglar who, in the process of breaking into one house, "manages to turn off the alarm system for every home and every building in the entire city." "Everybody's safety is put at risk. And that is what we're grappling with here." — PolitiTweet.org
Eric Geller @ericgeller
Smith: “We haven't seen this kind of sophistication matched with this kind of scale.” He adds, “This was an act of recklessness, in my opinion," because the attacks undermined confidence in software updates that protect vital equipment. — PolitiTweet.org
Eric Geller @ericgeller
Microsoft President Brad Smith says the company has linked SolarWinds to Russia and has "found no evidence that leads us anywhere else." "There's not a lot of suspense at this moment." — PolitiTweet.org
Eric Geller @ericgeller
SolarWinds CEO Sudhakar Ramakrishna didn't say much of interest but promised that SW takes its commitment to security, transparency, and collaboration "very seriously." — PolitiTweet.org
Eric Geller @ericgeller
Mandia says the hackers seemed "more concerned about operational security than mission accomplished." "The minute you could detect these folks and stop them breaking through the door, they sort of evaporated like ghosts until their next operation.” — PolitiTweet.org
Eric Geller @ericgeller
Mandia walked through the attackers' techniques (compromising identity architecture, which makes it hard to detect them) and their goals (stealing emails from specific people and tech cos' source code). — PolitiTweet.org
Eric Geller @ericgeller
FireEye CEO Kevin Mandia on SolarWinds software being the source of the breach: “This was not the first place you'd look. This was the last place you'd look for an intrusion.” — PolitiTweet.org
Eric Geller @ericgeller
Rubio seems open to national data breach law. “Perhaps we should consider mandating certain types of reporting, as the chairman already mentioned, as it relates to cyberattacks.” — PolitiTweet.org
Eric Geller @ericgeller
Rubio: “I caution against the use of certain terms at this time until the facts lead us to the use of terms such as attack and so forth.” — PolitiTweet.org
Eric Geller @ericgeller
"Everything we have seen thus far indicates that at some level, this was an intelligence operation, and a rather successful one," Rubio says. — PolitiTweet.org
Eric Geller @ericgeller
Rubio pushes back on WH saying SW was more disruptive than mere espionage: “While I share this concern — that an operation of this scale with a disruptive intent could have caused mass chaos — those are not the facts that are in front of us." — PolitiTweet.org
Eric Geller @ericgeller
Rubio also asks: Why did the hackers target who they targeted? What did they access and take? What will it take to rebuild networks and increase confidence in them? — PolitiTweet.org
Eric Geller @ericgeller
“The bottom-line question is, how did we miss this?” Rubio says, noting the "insidious" nature of the supply chain attack that took advantage of people's trust in software updates. — PolitiTweet.org
Eric Geller @ericgeller
The difficulty of repelling nation-state hackers "cannot be an excuse for doing nothing to build defenses and making it harder for them to be successful," Warner says. — PolitiTweet.org