@Microsoft@satyanadella According to @CISAgov, @Microsoft was responsible for 35 known exploited vulnerabilities in the year since announcing SFI, compared to 29 the year prior. Worse, not better...
https://t.co/mqMyipdVUJ
@Microsoft promised to tie executive pay to cybersecurity performance. Months later @satyanadella’s salary is up 63%, Brad Smith’s 29%, while exploited vulns are already higher now than in 2023, a year after launching its “Secure Future Initiative.”
https://t.co/sJOibQmwdE
@BradSmi testified that @MSFT would “treat security as the most important attribute of product quality.” Yet its security business - which involves upselling security features to customers - surpasses $20 billion annually. What will become of this revenue cash cow?
Bill Gates in 2002: when @MSFT “face[s] a choice between adding features and resolving security issues, we need to choose security.” @BradSmi at @HomelandGOP just made the same pledge in 2024. Why should we believe this time will be different?
@BradSmi’s written testimony talks about “empowering and rewarding every employee to find security issues, report them, help fix them, and encourage broader learning from the process and the results.” So…this wasn’t happening before? @Microsoft
Had the privilege yesterday of moderating a book talk @StanfordLibs with @pahlkadot. Loved this line from her: "Requirements accumulate because laws and policies accumulate." Check out her spicy @washingtonpost oped: https://t.co/7dLy3PdBAh
Lots to like in Charlie Ball's memo https://t.co/QOIl7Y7HyL about security by default, but if you're still upselling security, by definition, security is not the default.
Our founding director Ralf started his Global Digital Governance fellowship @Stanford!
He plans to use Stanford’s #academic
knowledge & networks to expand #smartcity research and Centre’s activities 🗺️
📝 more about his #research topic 👉🏼
https://t.co/m7h41oUTLV
NEW: "Keep the champagne corked," argues @ChorzempaMartin@PIIE in our ongoing Forum on China's tech rectification.
One official's remark that work was "basically complete" actually means increased supervision has become the norm.
https://t.co/UofMzJ4fUo More to come...
The Cyberspace Administration of China today published a draft decision to amend the Cybersecurity Law five years after it took effect in 2017.
We are working on a simple comparison now.
https://t.co/e2iG2gF8zv
@CSISKoreaChair @StanfordCyber @CSIS@mwlippert@VictorDCha@SueMiTerry Interested in learning more about how the Silicon Allies (US; ROK; Japan; Taiwan; EU) can work together on semiconductor resilience? Recent report from @ChaeriPark2 and me: https://t.co/tSXKo0kYNu Key takeaway: focus on building trust.
The Cloudcast - CyberSecurity, Economics and Policy in 2022
https://t.co/EQtCId9oGv
Andy Grotto (@grottoandrew, Researcher @StanfordCyber) & Steve Weber (Prof. Cal Berkeley I-School) talk about the big picture intersection of Cybersecurity, Global Economy and Government policy.
Now out, from @ChaeriPark2 and me: "The Silicon Allies: Achieving Allied Resiliency Against Threats to the Semiconductor Supply Chain." We lay out a vision and strategy for how the U.S., Korea, Japan, Taiwan and Europe can work together. https://t.co/tSXKo0C1Pu
🚨Just released: HAI policy white paper outlining a roadmap for a multilateral AI research institute (MAIRI) bringing international stakeholders together to promote AI R&D collaboration, multidisciplinary AI research, and democracy-affirming AI with human-centric norms & values.
Join us tomorrow at noon, as @GrottoAndrew moderates a discussion on recent developments in cybersecurity law, including pragmatic advice on compliance and litigation strategy & big picture insights on the direction of U.S. cybersecurity policy.
Register: https://t.co/hNlwAX6F91