Eric Geller Profile picture
Aug 26, 2019 3 tweets 3 min read Read on X
Scoop: Bipartisan activist coalition (incl. @FreedomWorks @DefendOurVotes @RSI @Public_Citizen @CommonCause @LWV) asks Congress to hold hearings with voting technology vendors — using subpoenas if necessary, given vendors' reticence. subscriber.politicopro.com/article/2019/0…
ES&S and Dominion both ducked last year's SRC hearing that sought "vendor perspectives." Of the big three, only Hart showed up.

The letter cites numerous instances of product vulnerabilities and questionable corporate conduct that Congress could press the vendors to explain.
Among the stories cited in this letter to illustrate the need to hold vendors accountable:

apnews.com/e5e070c31f3c49…
nytimes.com/2018/02/21/mag…
mcclatchydc.com/latest-news/ar…
apnews.com/cbc30e6a059a41…

• • •

Missing some Tweet in this thread? You can try to force a refresh
 

Keep Current with Eric Geller

Eric Geller Profile picture

Stay in touch and get notified when new unrolls are available from this author!

Read all threads

This Thread may be Removed Anytime!

PDF

Twitter may remove this content at anytime! Save it as PDF for later use!

Try unrolling a thread yourself!

how to unroll video
  1. Follow @ThreadReaderApp to mention us!

  2. From a Twitter thread mention us with a keyword "unroll"
@threadreaderapp unroll

Practice here first or read more on our help page!

More from @ericgeller

Apr 15
Resharing my story about Microsoft.

One thing I wish I could have expanded upon in my story is how the Biden admin's secure-by-design strategy has left the USG unprepared to wield any sort of influence over Microsoft, even as the company doesn't meet SBD expectations. (cont'd)
As one cyber expert told me, "There are good regulators and good enforcement mechanisms around [federal] IT procurement on security ... and the fact that CISA and the SBD team have chosen not to connect that work to those other entities has left it in a very limited position."
This expert, who requested anonymity to speak candidly, bemoaned the fact that the Biden White House isn't framing secure-by-design as a set of actual requirements for selling tech to govt. "Instead, they've chosen to pursue a principled public-interest approach."
Read 7 tweets
Apr 15
The U.S. government has a Microsoft problem.

Market dominance, inertia, and savvy PR have almost completely insulated the hack-plagued company from meaningful oversight, even as Biden officials preach corporate accountability.

My new @WIRED story: wired.com/story/the-us-g…
Image
I asked cyber experts, lawmakers, fmr govt officials, & employees of Microsoft's competitors why the company has struggled w/ security and why those woes haven't threatened its business.

Their comments and criticisms mirrored the recent findings of the Cyber Safety Review Board. Image
Why has Microsoft experienced so many high-profile hackers recently?

Because, experts said, MSFT has underinvested in the security improvements needed to protect both its legacy products and cloud services from modern threats.

Several recent hacks suggest major negligence. Image
Read 24 tweets
Feb 29
The House Homeland maritime security subcommittee is holding a hearing on U.S. port cybersecurity:

The hearing, w/ witnesses from DHS, USCG, & Transportation Command, comes a week after a big Biden admin push on port cybersecurity: homeland.house.gov/hearing/subcom…
Subcommittee chair Carlos Gimenez says U.S. ports' use of Chinese-made equipment "introduces significant supply chain vulnerabilities into our maritime transportation system."
Gimenez on Biden's recent port cyber initiatives: "I commend the administration in this initial action, but I know that more must be done."
Read 18 tweets
Oct 30, 2023
Biden has signed his AI executive order. As we await its release, here's what the fact sheet says about "the most sweeping actions ever taken to protect Americans from the potential risks of AI systems"... 🧵whitehouse.gov/briefing-room/…
Developers of any LLMs with the potential to pose serious risks will have to red-team them for safety and security issues—based on standards developed by NIST—and share the results with the government. Biden is using the Defense Production Act for this. Image
DHS will require critical infrastructure operators to meet these standards, though it's unclear what that means (banning their use of LLMs with bad red-team results?).

There will be a new AI Safety and Security Board and a new focus on AI threats to critical infrastructure.
Read 6 tweets
Sep 22, 2023
This week’s #Ahsoka episode was one of the finest episodes of Disney Star Wars TV so far. Sabine emerges as the real main character, Thrawn and Ezra’s long-awaited introductions absolutely deliver, and it’s no coincidence that Ahsoka’s best ep yet barely features Rosario Dawson.
Let's start with Sabine, because she continues to be far and away the best character. Natasha Liu Bordizzo must be exhausted from carrying this show on her shoulders.
NLB continues to nail Sabine's personality. When Baylan encourages her to engage in self-reflection, she quips, “I try to avoid that.” We see how her brashness and constant need to be active are coping mechanisms to suppress her inner turmoil, anxiety, and self-doubt.
Read 63 tweets
Aug 9, 2023
.@lilyhnewman is moderating a Black Hat keynote with @CISAJen and @VZhora. Image
@lilyhnewman @CISAJen @VZhora Zhora says Ukraine has observed “a shift" in Russian cyberattacks "from disruptive and chaotic attacks to more focused activity [like] cyber espionage and data collection."
Zhora: "In recent weeks, we discovered activity … in the networks of Ukraine’s armed forces. So, Russian forces targeting our situational awareness system … in order to gain information that, to their opinion, can give them advantage on the battlefield."
Read 8 tweets

Did Thread Reader help you today?

Support us! We are indie developers!


This site is made by just two indie developers on a laptop doing marketing, support and development! Read more about the story.

Become a Premium Member ($3/month or $30/year) and get exclusive features!

Become Premium

Don't want to be a Premium member but still want to support us?

Make a small donation by buying us coffee ($5) or help with server cost ($10)

Donate via Paypal

Or Donate anonymously using crypto!

Ethereum

0xfe58350B80634f60Fa6Dc149a72b4DFbc17D341E copy

Bitcoin

3ATGMxNzCUFzxpMCHL5sWSt4DVtS8UqXpi copy

Thank you for your support!

Follow Us!

:(