Had the recent vulnerability been a different message from, say, a certain prominent Twitter account, there could be very, very, very disastrous results.
Had the recent vulnerability been a different message from, say, a certain prominent Twitter account, there could be very, very, very disastrous results.
What you are really saying here that public officials should only be allowed to publish on approved enterprise communications systems that has the budget to pay for compliance certifications.
I think Facebook and Twitter would love this kind of regulatory capture because it would cement their position, hindering startups from taking over in their space (which, we know, is prone to being out-innovated every 5 years or so).
Having worked professionally in information security for a while now, let me tell you these kinds of certificates mean very little for actual security.
Which set of levers can we pull to achieve the best outcome for everyone, I have no idea. Is it fair to compare this to the current aviation dilemmas? I don't want just anyone building a passenger jet, slapping a compliance sticker on it, and hop on board; very high stakes system. Yet at the same time, it's clear to see how Boeing infected the FAA to simply get their way and lockout newcomers.
* are PCI, PII, SOX, et. al. really that trivial and meaningless?
You are trying to close Pandora's Box.
This was exactly my first thought when I saw Sen. Hawley's open letter to Twitter, aghast at the idea that the President's own account could be affected by this. I share his concern, but not his determination of blame. It is not a private company's job to protect the communications of our government. It is the job of our government's defense and intelligence apparatus. They can't do that job without the requirement for communication to be done through channels they control.
Anything is possible through legislation, I'm not sure this is such a big leap.
Especially when during campaigning it is necessary to grow that kind of following organically and to leverage social media. Saying that the day you get elected that you must disable your online presence feels like the wrong solution.
I do think there should be some higher standard though. I just am not sure what it is. The same threats exist in Email that exist on Twitter in a lot of ways. I can register "JoeBidden.com" and email you about "my" campaign all day. There's no official registration of your "official" domain anywhere. And even if there were, that can be hacked too.
Let's remove the blue checks and make it difficult to know who's legit and who's impersonating people again. Twitter is used way too seriously.
I know that's the opposite of what Twitter as a company wants. But it'd be nice as a user.
AFAIK (the spec is huge) PCI-DSS doesn't have a two-man rule requirement. Twitter is arguably doing everything PCI-DSS requires as its good security hygiene anyways.
Yes, that is the charitable interpretation you could have safely assumed I meant.
I think they probably have a different authorization method. One that might be wholly separate from the ones of regular or blue check mark users.
Likely monitored by the NSA or something like that.