▶ 0:12:28e e
▶ 0:13:08this hearing of the subcommittee on Military and Foreign Affairs will come to order uh I want to welcome everyone without objection the chair May declare a recess at any time I recognize myself for the purpose of making an opening statement good morning thank you for joining us today as we confront one of the most pressing National Security challenges of our time cyber Espionage by adversaries targeting our critical infrastructure I'd like to thank our Witnesses for being here today and look forward to our conversation in recent months sophisticated cyber attacks by groups like salt typhoon
▶ 0:13:39have not only compromised networks used by millions of Americans but have threatened the backbone of our national security our nation's critical infrastructure is under attack at a staggering Pace reports indicate that globally cyber attacks against critical infrastructure increased by 30% last year averaging 13 attacks per second in the United States alone over 4 uh 20 million cyber attacks were recorded in just the last year these incidents are not random errors they are part of a coordinated
▶ 0:14:09campaign by a well-funded foreign adversary that exploits vulnerabilities salt typhoon a chines state sponsored hacking group with direct ties to the ccp's intelligent apparatus executed an extensive breach that compromised us telec communication networks this campaign targeted essential communication networks including those operated by industry science like Verizon and AT&T they were able to intercept real-time calls and messaging data from over a million users critically these attacks focused on Gathering intelligence
▶ 0:14:39from high value government and political figures it is vital to emphasize these telecommunication companies are not at fault they are on the defensive against an enemy that employs sophisticated tactics using vulnerabilities and sometimes outdated infrastructure and exploiting weak points in network Management Systems to gain unprecedented access to our critical Communications this is not a failure of the private sector it is a clear signal that our nation must take a more Pro proactive approach the damage control posture
▶ 0:15:10of the previous administration has left us vulnerable to the state sponsored cyber attacks instead of merely reacting after breaches occur we must be Forward Thinking and Resolute National Security is Paramount and it is our government's responsibility to safeguard the American people and the critical infrastructure that we rely on every day now more than ever it is imperative for Congress and federal agencies to join forces with the private sector in establishing a robust unified cybercity strategy legislators have
▶ 0:15:40begun proposing measures to require annual cyber security certifications for telecom companies ensuring they adhere to strict security protocols yet this is only part of the solution we must also invest in a more aggressive offensive capability that deters adversaries from exploiting our vulnerabilities sending a clear message that Espionage against American infrastructure will have severe consequences furthermore the sheer volume of these attacks should serve as a wakeup call for strengthening our infrastructure when our
▶ 0:16:10communication systems integral to to our National Defense emergency services and economic Vitality are compromised it erodes public trust and jeopardizes our Collective safety it is our duty to ensure that our government agencies in collaboration with Private Industry take decisive action to upgrade cyber security measures and hold foreign State actors accountable in closing let me reiterate the threat we face is not a result of negligence from our Telecom telecom companies
▶ 0:16:40but a deliberate strategic maneuver by sophisticated and hostile State actors intent on undermining our national sovereignty this is a call to action for every American who values freedom and security we must fortify our defenses invest in advanced cybercity technology and pursue strong proactive policies that secure our nation's critical infrastructure against these Relentless threats the time to act is now before our adversaries turn these vulnerabilities into tools for even more severe
▶ 0:17:10real world disruption thank you again to our Witnesses for being here today and I look forward to hearing about your experiences in the cyber security field and any recommendations you have regarding our strategic cyber posture and with that I yield to ranking member super Manion for his opening statement thank you chairman Timmons uh thank you for holding this hearing and I agree with much of what you said you know we we must protect our telecommunications infrastructure from our adversaries foreign and domestic and the future of warfare is here now
▶ 0:17:41and programs like salt typhoon are actively infiltrating our networks and gaining access to sensitive information and credentials and I would say salt typhoon is one of the worst breaches our country has ever faced in our Telecom infrastructure and we're still uncovering uh the full breadth and scope of its attacks and this work to protect our Telecom infrastructure is urgent and it's bipartisan and it must be it must be a national priority and so it's deeply troubling that in the midst of this massive cyber security Espionage effort
▶ 0:18:11we're facing our national security advisers are breaking basic protocols that ought to be followed by every person handling sensitive and classified information as we saw last week our national security advisor added a journalist to a signal group chat where top officials shared classified information about an upcoming strike the Administration has not taken responsibility and tried to deflect saying that it isn't a big deal and the mission was a success but this is a big deal and the mission is not a success if the whole world now knows how we did it
▶ 0:18:41how we planned these attacks and where we got the information we've made it much harder and more dangerous for our troops to carry out these missions in the future the administration also keeps saying that the information discussed was not classified but if our war plans right before a strike are not classified I would like it there a review of our classific a system but I'm pretty sure it was classified and either way it was highly sensitive information and put our troops at risk and the American people at risk it also told us who and what we were targeting so if you look
▶ 0:19:12at these texts here it says that they identified a Target walking into an apartment building those texts revealed where we received our intelligence as well it came from our Israeli allies who are now Furious that this Source has been leaked and our allies are already hesitant to share information with us and this Administration and now the Administration has proven that our current national Security leaders cannot be trusted to keep sensitive information safe they'll just take our classified information and text it to whomever shows up in their contact list
▶ 0:19:42the timing of when the planes were taking off what kinds of planes were being used and how we generally plan and conduct strikes like this were also shared in the chat again all this information was sent around using a private third-party app on private phones that we know are targets of salt typhoon and other adver Aries so if the objective of this mission was to lose the trust of all of our allies well then the mission was a success the administration says that accidents happen but an accident is when you text gossip to your boss instead of your work bestie leaking
▶ 0:20:12sensitive military strike information to a journalist is not an accident this is incompetence that puts our lives in danger we need to hold our government leaders to a very high standard and just two days ago the White House said and I quote case closed but I disagree and some others on the Senate side including Republicans agree with that that we have to continue to ask questions about this and I think the American people want answers how prevalent is their use of signal and will we find out whether other information
▶ 0:20:43has been leaked are are phones private phones of these National Security advisers being hacked by Russia Iran or China have any of these devices already been compromised it's pretty clear that we got lucky in figuring out that this is happening because of the added journalists and it's pretty clear that our National Security leaders are using signal all the time for communications like this and so I hope my colleagues on both sides of the aisle today will join me in trying to provide real accountability and oversight over these
▶ 0:21:13actions and we're here to talk about the risk of state sponsored cyber attacks let's confront this most urgent vulnerability and work together to investigate this massive security leak this is inititive of National Security and the safety of every American thank you and I yield thank you uh I'm pleased to welcome an expert panel of witnesses for today's discussion I'd first like to welcome Mr Josh Steinman is the CEO of galvanic a cyber security startup that focuses on protecting critical infrastructure Mr Steinman also served as a senior director
▶ 0:21:44of cyber policy and Deputy assistant to president Trump from 2017 to 2021 secondly I'd like to welcome Dr Edward amaroso who is the CEO of tag infosphere and professor at NYU formerly he was a senior Vice president and chief information security officer at AT&T and has Decades of experience as a leader in cyber security lastly I want to welcome Professor Matt blaze of Georgetown law where he focuses on security and privacy and Computing and communication systems thank you uh I now recognize
▶ 0:22:14Mr sorry I'm going to swear Y in first pursuant to committee rule 9g the witness will witnesses will please stand and raise their right hand thank you do you solemnly swear affirm that the testimony that you are about to give is the truth the whole truth and nothing but the truth so help God let the record show that the witness Witnesses answered in the affirmative thank you please take your seat I now
▶ 0:22:44recognize Mr Steinman for his statement uh thank you Mr chairman and uh the ranking member and all members here for having us here today my name is Joshua Steinman I'm the CEO of galvanic or a critical infrastructure cyber security company previously served in the white house as a senior National Security Council staffer um I have a simple message today and that Echoes some of the messaging that we've already heard
▶ 0:23:14which is that cyber threats to critical infrastructure are not contained to the Telecommunications industry it is an endemic problem across any number of other critical infrastructure sectors those include Transportation water power sewer and the defense industrial base executive uh Branch leaders have for years in open testimony here in Congress talked about the threats from both Russia
▶ 0:23:44China Iran North Korea and others to our critical infrastructure sectors and now is the time for Congress to take action in concert with the executive branch in concert with the new Trump Administration to finally get us on a footing to be able to defend these critical aspects of American Life against foreign cyber actors thank you both for having me and all members thank you thank you I now recognize Dr amaroso for
▶ 0:24:14his opening statement well thank you thanks for the uh invite and I'm looking forward to our discussion today um I do a few things I I run a research and advisory company called tag in New York City that allows me to kind of keep up on an awful lot of current issues in cyber I advise Enterprise government and so on I also teach at NYU um in the um computer science and engineering department also uh have the privilege to try to teach cyber security to law students which can be quite a challenge at times but uh
▶ 0:24:45it's something I enjoy very much but I'm I'm perhaps most known in this industry as someone who spent 31 years at AT&T so I've spent a lifetime protecting critical infrastructure and um last 20 years of my career at AT&T I was in the top job there so a lot of the systems and infastructure and tools that are likely to be referenced perhaps in some of your questions today uh related to Salt typhoon I helped to design and build and put
▶ 0:25:15teams in place to operate so I really do understand how much of this um uh you know works I stepped down from that role several several years ago so I'm happy to hopefully provide some insight there one of the themes I think you'll hear in my comments today is that we need to be thinking about the next problem I think a metaphor comes to mind that I often think about when asked about this topic it's as if we were
▶ 0:25:45driving on a road hitting a bunch of potholes and then you ask us to come and talk about the potholes we don't want to ignore the potholes but it's scarier when there's gigantic sink holes ahead of us and and I think that's the metaphor that makes the most sense here and those sink holes will come from an adversary that increasingly is using Ai and I think again you'll hear in my comments that unless we figure out a way to deal with that
▶ 0:26:16at a national level in a coordinated way and yes Telcom is a big piece of that but there's a lot of other pieces unless we do that then I think we'll look back on salt typhoon as perhaps Child's Play so I look forward to our discussion and I hope my insights today are U helpful to you thanks thank you for that and now recognize Professor blae for his opening statement uh thank you Mr chairman um I I I apologize that I will probably use my five
▶ 0:26:46minutes fully unlike my co-witnesses here um so I am although I in the law school as well as the computer science uh Department I'm here primarily with my technologist haton and I thought I would spend a few minutes uh just discussing the technical context in which salt typhoon was able to happen and I Trac this back to uh 1994 in 1994 Congress enacted um
▶ 0:27:16something called the communications assistance for Law Enforcement Act or Kalia uh which mandated that telecommunication service providers incorporate into their infrastructure capability to support court court authorized uh wirs sometimes called lawful access uh Kalia was a response to concerns from law enforcement that uh newer Digital telef Services might not be compatible with existing at the time wiretap technology
▶ 0:27:46that the government and the police were using what Kalia did was shifted the technical burden for implementing wirs from law enforcement where it had traditionally been for most of the Century into the communications Network itself and what Kalia required was that virtually all switching equipment uh in the public telephone Network must be designed with explicit backdoor capabilities to wiretap
▶ 0:28:16traffic uh so every switch used to serve every customer would thereafter have to be essentially wiretapped ready in case a customer served by that equipment might someday be the subject of a wiretap order uh when Kalia was proposed many technologists myself included raised concerns about the security implications of such a sweeping mandate that it would expose our infrastructure to attack by malicious actors who would find ways
▶ 0:28:46to exploit these new Universal wiretap capabilities against ordinary Americans and American companies and government officials and unfortunately these concerns have over time been proven correct several times and most recently and most spectacularly in the salt typhoon attacks against high value US targets including government officials uh while the Kalia mandates introduced vulnerabilities from the beginning
▶ 0:29:16uh those risks have been greatly Amplified in practice over the more than 30 years since the law was passed uh and are now much more severe than perhaps they were at the start Telecom infrastructure has changed radically over the last 30 years in particular it's become increasingly automated and virtualized in the previous Century provisioning wir Taps generally required the intervention of a
▶ 0:29:47technician with physical access to switching equipment uh that was serving the uh targeted customer uh this effectively served as a safeguard against very large scale unauthorized wiretapping uh that wasn't being um permitted by court orders because a human being was in the loop and would uh be expected to notice a inexplicable uptick in uh surveillance
▶ 0:30:17uh over time these sort of architectural safeguards because of the way the phone system worked in the 1990s have kind of Fallen by the wayside as communication infrastructure has evolved Telecom switches are now um more like data centers uh with uh than they were uh specialized offices run by humans uh they're designed to be remotely programmed configured and managed often over the internet
▶ 0:30:47and at the same time the back hul for wiretaps to law enforcement is no longer through dedicated leas lines but rather through internet connections that anyone potentially could get access to and there are now intermediaries that serve essentially as wiretapping Clearing Houses between law enforcement and Telecom providers effectively all this has expanded the attack surface that has to be defended to prevent tampering with our Communications
▶ 0:31:18infrastructure and unauthorized surveillance by Foreign State actors uh especially at scale the job of the illegal eavesdropper has actually gotten significantly easier uh and to put it bluntly something like T salt typhoon was inevitable uh and will likely happen again unless significant changes are made to our infrastructure and our approach to protecting it thank you thank you for that I now recognize myself for five minutes for
▶ 0:31:48questions Mr Steinman it is widely reported that us critical infrastructure undergos thousands of cyber attacks a day while many of these attacks are not successful is impossible to stop all of them from achieving their goal to begin can you quickly describe the significance of the salt typhoon breach last year and its impact on US National Security yeah uh thank you Mr chairman I would first want to ask for clarification which I fear you may not be able to provide in terms of the language
▶ 0:32:18that we use here so this is a challenge that we faced for many years I fa it in my last job I even face it in my current job which is that when folks say attack I think often they refer to um activities such as probing or other things that I think um don't bear the same weight that the word attack actually does um this also uh goes to another challenge in cyberspace which is that you know many actors um conduct
▶ 0:32:49activities that look like both intelligence collection and then they maintain the capacity to then conduct an operation that may have an impact that impact may be digital that impact especially in this context may be physical so would it be fair to say that instead of using attack you'd prefer to use words like probing monitoring collecting disrupting I would I would defer to my academic colleagues here uh to choose the specific language I would just caution against using the word attack sure um because I'll certainly use that word very specifically to mean
▶ 0:33:19uh creating direct impact to systems yeah yes sir okay all right I appreciate that yep uh so in that case I think uh just to answer your question um we do see critical um bearing an intense degree of scrutiny I guess from foreign actors those foreign actors are reported and again you can you can consult the Director of National intelligence's annual threat assessment to Congress which recites these types
▶ 0:33:49of Frameworks a lot but we see um foreign threat actors deliberately repeatedly regularly and high volume interrogating critical infrastructure facilities um across the United States across the world um the challenge is that many of those critical infrastructure facilities in fact are not well defended uh we could go into the reason why um I think in closing what I would say Mr chairman is uh the internet is a
▶ 0:34:19is a dark and and dangerous place it can be certainly um and our adversaries take advantage of the fact that we've essentially built built out America's critical infrastructure uh from a digital perspective without a sort of wartime footing uh and that means that these types of activities in many cases are purported to have found purchase and what that means is that we do have foreign adversaries sitting on American infrastructure and that gives them
▶ 0:34:50the possibility of being able to at a time and place they're choosing conduct an attack sure thank you for that I thought that our um I'll call it our 9911 because that's when we kind of woke up when we were attacked I thought our 911 was going to be the colonial pipeline attack and um we were days away from catastrophe and it we have allowed our critical infrastructure to be uh basically operate operated by technology and that technology has vulnerabilities
▶ 0:35:20and it's funny because I I was in Congress during the colonial pipeline attack and they um had to call all these 70 and8 year old retirees from all over the country to operate the pipeline with wrenches and these guys knew how to hit it and know what to do next and you know iot was operating the whole thing luckily uh they were able to um determine that the um administrated the administration was actually what was breached as opposed to the operational control so they were able to turn it back on but um but you know Dr amaroso when these types of
▶ 0:35:50state state sponsored attacks and I guess you know salt typhoon is state sponsored the colonial pipeline attack was likely um somebody that was just trying to make some money uh but do you believe that the US government should retaliate against either state sponsored actors or um actors that are operating in countries that are not enforcing the rule of law to show that there's consequences for these kind of behaviors and if so what kind of response do you believe is Justified well it's a good question comes up all Aton last 30 years should we
▶ 0:36:21U say the best uh defense is a good offense right that comes up a lot I think the best defense is a good defense like you you got to play defense I mean whether we decide to retaliate sort of a separate issue but I think it sherks the the the responsibility we have to do a better job right there's there's no question that salt typhoon I feel like we're sort of Lucky in a sense right because we we break down problems into two types of things one's where
▶ 0:36:51they're peing at your stuff and that's never good you know you don't anybody surveilling and pulling data but somehow you feel like you survived that it's not good but if they're disrupting if there's kinetic attacks where buildings have to be evacuated and people's lives are maybe taken I mean that's a a whole another thing so in my opening comment when I sort of Drew the analogy between sort of potholes and sink holes sink holes are
▶ 0:37:21consequential attacks where you cannot ignore what's going on and that's my biggest fear here that I feel like we're headed toward that and now's a good time I think for our whole country for everybody to kind of wake up and say this is something we should pull together and fix something we're you in America we're good at that when we get pissed at something we do pull together and this is a really good opportunity not just for this committee but I think for our whole country to do something about it
▶ 0:37:51thank you for that um I just want to let my colleagues know that we're not going to be super strict on time given the fact that some of us have left um and we want to make sure that we get the most out of this and we will likely be doing a second round of questions at the end um thank you for that and with that I now recognize the gentleman from Virginia Mr Sub Manan for uh five minutes Mr chair I want to enter to the record uh Congressional testimony salt typhoon securing America's Telecom tele Communications information from state sponsored cyber attacks April 2nd
▶ 0:38:21by uh Corey Simpson JD without objection so ordered uh thank you Mr chair uh so the Administration has said that discussing attack plans on Signal uh wasn't a big deal because signal is end to-end encrypted but what does that really mean I just want to explain to people at home um exactly how this encryption works and how how phone works really um so end to end encryption means that after I press the send button on my phone my message is scrambled if you're
▶ 0:38:52using signal and that scrambled version travels to its end destination Anyone who reads needs the message in the middle wouldn't know what I said but what if the hackers aren't trying to intercept my message while it's moving what if they had already hacked the phone itself or hacked my friend's phone who I'm sending the message to so let's take a closer look at how a phone works and you can see here there's a lot of ways a phone can get hacked and Dr blae this is your area of expertise yes or no is it true that hackers
▶ 0:39:22can access information on your phone if you are connected to public Wi-Fi uh under many circumstances yes with personal devices and then can they access your phone and the messages you're sending through a a Bluetooth connection or even a USB port let's say all those expose the phone to vulnerabilities and isn't it true that if I accidentally clicked on let's say a malicious ad or link uh that could download something on my phone that could also make my messages
▶ 0:39:52or what I'm doing on my phone vulnerable that's actually a very common way of attacking phones so so there are even if you're using an end to end encrypted app like signal there are so many ways to hack your phone itself that and America's top National Security officials should know this and they're probably the number one target for many of these types of hacks and it's it's actually it's it's hard to believe that that they would even be using signal there's a reason why we don't put secure information
▶ 0:40:22and classified information on Signal in the first place and just yesterday we found out that uh Mike waltz's team uses Gmail to communicate as well Mr blae is Gmail vulnerable as well if you're sending information classified or sensitive information to and from people I I would say it's probably more uh vulnerable than signal correct uh that's right well Gmail isn't even endtoend encrypted so it's vulnerable to a tax on both the device and the network itself and Google's infrastructure
▶ 0:40:53and has Gmail been infiltrated in the past for National Security information yes uh and can you tell me do you do you remember any instances of that I there I mean there are many many ways to attack a a a Gmail user the most uh common is to obtain their uh passwords or uh other uh access control and uh you know essentially log in as them with full access and this happens so often that it's almost impossible to single out a single instance
▶ 0:41:24but um you know State actors um are notorious for this sort of attack and I I think it's pretty clear that this shouldn't have been happening and if any regular low-level defense or intelligence staff had been involved in anything like this they would have been fired immediately and uh that's that's what really is concerning to me now speaking of firings uh we have actually been laying off a lot of our top cyber Security Experts uh at cisa
▶ 0:41:54and across the government Dr blae what do you think would be the impact of some of these firings on our ability to defend against hostile cyber attacks in the future well you know the um the battle to defend uh our infrastructure is fundamentally uh difficult it's fundamentally a problem that the that the offense side has an advantage uh with because computer systems personal devices the servers that serve them are
▶ 0:42:24all um vulnerable to attacks some of which have not yet been discovered and some of which uh have not yet uh even um uh come into existence but we don't know how to build secure systems in any um top to bottom way so I would say that uh you know having an active defense to identify and fix vulnerabilities from all sectors from the private sector
▶ 0:42:55government and individual users is essential and U Mr chair I asked for unanimous consent to enter in the record an article U dated March 13 20125 people are scared inside sisa as it reels from Trump's Purge without objection so ordered thank you I think it's pretty clear that this shouldn't have happened we need to understand how prevalent the use of thirdparty apps and private phones is when talking about classified or secure
▶ 0:43:25or sensitive information and so we've sent a letter to the administration I hope that we'll get some answers I yield back thank you I now recognize a gentleman from Texas Mr Cloud for five minutes thank you Mr chairman I appreciate you hosting this hearing I appreciate you Witnesses being here I actually came to this hearing thinking that we were going to be able to have a bipartisan hearing on this as as we all agree that CCP is is a tremendous threat that our infrastructure needs protected
▶ 0:43:55um I'm it's surprising again to come to this and and to see the politization of this hearing it seems to be that uh Democrat administrations can use signal but Republicans can't that uh when we have successful attacks against the houthis uh they get overlooked but yet uh when when the Biden Administration withdrawals from Afghanistan and 13 of our servicemen get killed uh that the Dem sit on their hands and don't seem to be concerned about that at all uh we just had a s another
▶ 0:44:25successful attack against the houthi last night so it seems that our Administration is able to unabated uh regardless of the chicken little pie in the sky sky is following stories from our ranking member uh thank you all for being here um Mr Steinman uh could you explain or answer for me would signal messages be susceptible to exposure by the salt attack I'd want to defer to my
▶ 0:44:55uh technical colleague here to the left um obviously uh it's an endend encrypted service you're going to it's going to depend on a wide range of uh variables including is the endpoint compromised uh again I'd defer to the technical experts herea sure I'm happy to U provide a guidance so you're asking whether the in in a sense the Chinese yeah salt typhoon so salt typhoon is a broad
▶ 0:45:25description of an act and one of the things we've learned like um take the n0 cryptography argument that was made earlier um that the uh transmission is is secure between the U endpoints it's using a type of Crypt cryptography called public key cryptography it's a Diffy Helman key exchange it turns out that's actually something that is susceptible to quantum computers and it's entirely possible that
▶ 0:45:55the PRC could a bunch of those in the basement so I I could imagine that even signal is vulnerable to nation state surveillance in real time what we've learned is in our own intelligence Community we've always been 10 to 15 years ahead of where we all think cryptography is so chances are it's kind of scary Russia China and so on are probably a lot further along than we think they are in
▶ 0:46:26crypto that's why I think in general seems to me to fall into the I I appreciated your opening statements where you talked about kind of the potholes of yesterday to where in a sense maybe this didn't fall into that category but more in the what are the sink holes for the future I I thought that was the whole idea that from a security posture whether it be in our typical DOD stance but certainly in cyber security we need to be skating to where the puck is going I agree with you I mean I know where you're going and I I agree I think
▶ 0:46:56China is a better actor than I think we had ever expected at this point I mean just sort of extrapolate back we kind of used to Lampoon they don't know what they're doing and then they got better and then we kind of see salt typhoon and all of us go whoa you know they've gotten pretty good so I think that's a wakeup call whether it would be good enough to break signal whether salt typhoon connects you know we can sit and debate that but I think if you push the puck forward on the
▶ 0:47:26ice a little bit it gets pretty scary where things like even signal that's kind of my point like where we're going is even things you might depend on now are probably not going to be things we can depend on soon so all of us need to think through how we fix that a couple of my big concerns and I may run out of time to get both of them but um you know it's been said if you find yourself in a hole stop digging so while we need to talk about what we can do going forward to kind of build and Harden our infrastructure and and those
▶ 0:47:56kind of things I'm also concerned about what we might be doing already that is allowing access uh you know I wonder we don't know the actors or the group within salt typhoon I think only one has been kind of outed uh the rest we don't know so we don't know where they're getting their training but I do wonder if how many of them were trained here in the United States at our at our universities I wonder about the infrastructure that we get that's you know even most of our phones are made in China for example um
▶ 0:48:26could you speak to that and what we could do to kind of Harden the digg where it is right now and then we can talk about where we need to go great analogy you do you do want to stop digging when you're in a hole I think one of the things that I hear all the time like in the context of Telcom salt typhoon and even the broader issues is we need to find the gaps go find the three five seven gaps and close them I think that that's a Fool's errand like looking for the gaps and
▶ 0:48:57fixing them is not the way we get out of this I think we need to design brand new infrastructure and start finding a way to eventually transition like in in our world we would call that next Generation infrastructure and I think that's something we have to do might sound like a big lift but I don't see any other way this I guess my concern is okay if China's still building the next genin hardware and then importing into the United States do we still have that issue I guess guess that's
▶ 0:49:27what the kind of question I'm asking we avoid I mean like if you take and and if we're still training you know we come up with the latest best practices then we continue to train their cyber Security Experts and send them back home to do Dam I'm against that on the hardwd with that's kind of I guess my concern I don't know it is sensible to your point that for things like Huawei that we stay away from that equipment I think that's wise and I think we've all probably agree with that what's interesting is in salt typhoon they didn't use any Huawei
▶ 0:49:57back doors CU I while I was at AT&T I don't think they they've since G and bought any Huawei equipment so that was not either the front side or even one of the components of the attack so we sort of learned that they don't need that now I'm not saying we should be buying that I'm I'm against that but it was not part of the attack Vector which for a lot of us is kind of thank you we're going to have time for a second round of questions um I now recognize Mr chair uh wanted to enter
▶ 0:50:28something into the record sure asked for gan's consent to enter into the record an article dated March 27th 2025 titled previous administrations were wary of the messaging app signal Trump world has embraced it thank you for that without objection so ordered uh I now recognize the gentleman um from Massachusetts Mr Lynch for five minutes thank you Mr chairman and and thank you for holding this hearing this this is a serious issue this is a serious issue uh
▶ 0:50:59what what bothers me is that it you know raising the issue of of of National Security when our top National Security and defense officials go on an insecure app and they they talk about they they offer actionable intelligence in advance of a milit AR operation in which our sons and daughters
▶ 0:51:29are at risk and then if we raise it in in the oversight committee on a hearing it's politicization that it's it's one thing you know I know a lot of my Republican colleagues over 25 years I I've worked hand inand with a lot of them on on issues of of National Security and uh you know Senator Langford would he was over here uh very ser ious on that issue work with him on a bunch of different things
▶ 0:52:00it's one thing look I I can understand if if Republican members don't want to say anything about what what the Trump Administration did on this and what they continue to do but to but to call it politization and and also to to give a blessing on what they did and call it a success scares the hell out of me if if you think that was a success
▶ 0:52:31going on an insecure line in advance of a military operation and discuss openly on an insecure app the operational details of the forthcoming strikes on Yemen including information systems and and attack sequencing will the Gent okay no I'm not going to yield I I'm offended I'm offended that that members would would say that's politization
▶ 0:53:01when we're trying to protect our sons and daughters in uniform and use this forum are you kidding me are you kidding me that was that was a colossal failure we cannot encourage that we cannot encourage that type of activity on this committee classified briefings we were informed not to use signal we were informed that there are certain protocols that you have to to take up and will the gentleman yield
▶ 0:53:32I'm not yielding no so and and and my colleague got an extra minute on on top of what I'll give you two a minute and 40 so so maybe I'll have time at the at the end to yield here's what it is here here's what gets me it is pointless for us to sit in this committee and and and and try to Grapple with the real issue of of salt typhoon and other threats to our communication systems
▶ 0:54:02if the people in the top don't take it seriously we we can we can talk about all of the the protocols and and debate and devise the the best methods and insist upon upto-date technology and and take all those steps but if if if the vice president JD Vance and National Secretary of Defense Pete hexon and Secretary of State marichel M Michel Rubio and
▶ 0:54:32and Mike walls our national security advisor and Director of National Intelligence telsey gabbin go on an insecure line and talk about operational Intelligence on an line then everything we do here is pointless that's what I'm getting at so so we ought to be able to to talk in a meaningful way and and and and point that out that's right relevant that's important and and they need to know that and and telling them that you were great
▶ 0:55:02and that was a success and look how great you did that's not good that's not good that's not helpful to our national security they made a mistake now you don't have to say that publicly but dear God don't sell them that's the way to way to go nice job great success that's that's insane that's insane for anybody who takes National Security seriously that's what I'm getting at and so our work here
▶ 0:55:32can't be just you know it can't be just you know advice to Democrats when they're in office it has to be guidance as well to others you know it it shows that we're taking our our job seriously and and it's not just for show it's this is this is not politization this is this is National Security this is the real stuff and and there have been and and and I'm happy to hear there have been Republican colleagues
▶ 0:56:02who who are very worried about this and they've said that and they they try to be as respectful as they can to their Republican colleagues and I understand that I get that part but that's a far cry from saying way to go do it again that was successful you know that's it's just uh it it it it does not it does not bode well for for our future and for the work of this committee let me just ask a question quick question Mr blae uh on top of all this uh the Trump Administration has just laid off 130
▶ 0:56:33uh Folks at sisa and and these are these are some of the very best so the private private sector is is Covetous of of uh you know getting some of our our really smart cyber security people uh to work on work for them so when you lay off 130 uh sister um uh Personnel does that help our National Security and and and what what problems does that uh present well I I mean I can tell you that
▶ 0:57:03um sisa uh in both the first Trump Administration and the Biden Administration was an invaluable uh resource in protecting uh critical infrastructure it's a small agency um you know arguably it's been understaffed from the beginning uh but it is essentially the only Clearing House for threat intelligence uh across
▶ 0:57:33uh government and the private sector and uh any diminishment of that capability will harm us all right than thank you Mr blae uh Mr chairman if I have any extra time I would yield it to my to your to to you Mr chairman thank you we'll have an additional round of questions if you'd like to ask additional questions um I now recognize the gentleman from Arizona Mr Bigs for five minutes thank you Mr chairman this is an important hearing appreciate uh you holding it I appreciate the witnesses being here and and you've been able to witness already the politicization
▶ 0:58:04of this of this hearing so it's a it's a crying shame and and Mr styman what I will tell you is um uh I am a Layman and so I will use the term Cyber attack and I may mean probe I may mean disruption but I'm talking about a a malignant actor a malign actor who is trying to do something that is detrimental to some secure system that we have that's what I'm referring to and so uh according to the Internet Security Alliance
▶ 0:58:35thousands of daily attacks cyber attacks put the operational continuity of critical infrastructure at risk and have led to trillions of dollars in economic losses to date meaning that cyber attacks threaten both our national and economic security estimates indicate that 40 to 70% of our private and public sector cyber security Workforce and resources are spent on navigating a patchwork of overlapping contradictory and duplicative Regulatory regimes these contradictory schema are promulgated not only at the international local and federal level but often
▶ 0:59:05between federal agencies themselves every minut spent navigating the bureaucratic morass of conflicting rules is time actually spent away focused away from cyber threats so my question for you and I'll go with you Amarosa um what steps should Congress and the Trump Administration take to harmonize Federal cyber security regulations to ensure that cyber security resources and the Cyber Workforce are focused on protecting American citizens and our critical infrastructure well thank you for the question
▶ 0:59:35and on behalf of every ceso on the planet we'd sure like to see fewer uh Frameworks and regulations the nist cyber security framework which is inversion two is really good and it's almost like a an umbrella standard to most of the other standards that are imposed on a Enterprise security team so I think if you had 50 heads of security across the whole critical infrastructure even midsize and small companies that all agree that simplifying
▶ 1:00:06that to one or two Frameworks would be a really good idea now we use these tools called GRC tools governance risk and compliance tools so we've been able to automate away a lot of the complexity so we we've dealt with it but it would be quite welcome if there was some simplification there do you have any thoughts on how tools like artificial intelligence could be deployed to assist in reviewing and and constructing a framework oh they'd be great I mean everyone in the room here's used chat GPT where you ask
▶ 1:00:36get a complex question you feed this complex thing and say explain this to me well think about complex RS and asking how it might apply to an industry AI is really good at that and and so we've gotten pretty good at dealing with the you you'd use some words like complex suis absolutely accurate we've dealt with that using technology but still it be nice to simplify that I think that would be um it would clean up a lot of the security infrastructure we have in place um Mr blae
▶ 1:01:06Professor Blaise your written testimony outlined the concern that I share that lawful access mandates present risk to me Americans both tools may be abused but both that those tools may be abused or that those lawful access mandates may be exploited by malign actors um and you talked about um encryption and then encryption is not a silver bullet but it is as you discussed an important countermeasure despite years of advocacy that Congress imposed wiretap ready mandates on indents encrypted communication
▶ 1:01:36tools which by the way I really appreciate you raising that in your piece in response to the Salt typhoon attack federal law enforcement agencies issued a series of public reports and statements recommending that Americans utilize encrypted Voice and text communication methods I ask for unanimous consent Mr chairman that one of those the cyber security and INF structure security agency's mobile Communications best practices be entered into the record without objection ordered thank you uh and and back to you
▶ 1:02:06Mr bla would imposing such a mandate expose those communication methods to the same risk pres present without encryption um I mean anten encryption makes communication strictly more secure it's not perfect it's not a Panacea it still leaves us vulnerable to attacks against the end point but what effects Ive endtoend encryption does is essentially removes attacks against the infrastructure such as we saw in um the salt typhoon attacks that have been made public
▶ 1:02:37so far from the equation um essentially signals encryption you know we don't know that it's perfect we don't know that there aren't uh hidden I'm not talking specifically about signal I'll save that for another round of questions sure but you know for example signal um you know we don't know if any of this encryption is perfect we don't know if there's some uh attack that will be discovered uh in in the future but it's probably safe to say that the easiest way to attack an endtoend encrypted uh
▶ 1:03:07communication is by attacking the endpoint that it's it essentially becomes a waste of time to uh attack it through the infrastructure and that's a that's a significant gain so so while we're here Mr chairman if you'll indulge me just real quickly it's been publicly reported that the UK has been putting pressure on Apple to build a lawful access back door into encrypted iCloud backups not unlike what you talked about in the in the 90s Senator Ron weiden and I have raised concerns about this approach with the Trump Administration
▶ 1:03:37specifically asking the administration to put pressure on the UK to back drown or face consequences and I ask unanimous consent that on our February 13th 2025 letter be entered into the record without objection so and so here's the question Professor blae what tools are at the administration's disposal to ensure that our own allies are not taking steps that jeopardize Americans privacy well you know again uh we should encourage the use of endtoend encryption because we use the internet
▶ 1:04:08and Communications for essentially everything about our economy everything about our national security everything about our personal privacy depends on the security of our Communications infrastructure and uh you know so we need to promote the use of endtoend um uh enthusiastically and vigorously and anything uh regulations that mandate things like cryptographic backd doors are a step backwards
▶ 1:04:38from doing that and will make us less safe thank you y back Mr chairman thank you for you for indulging me thank you and I recognize the gentleman from California Mr Garcia for five minutes thank you Mr chairman thank you to our Witnesses for uh for being here um and obviously I think we can all agree that the salt typhoon Acts were very serious deserve a full response clearly China is targeting our networks and we need to step up to prevent them and of course prevent from worse things from happening um but of course I strongly disagree with comments that we should not
▶ 1:05:08be discussing other serious National Security concerns U members of Congress have the absolute right in hearings to ask questions that are of grave National Security concern and the fact that we as the the House minority and Democrats are focused on the serious national security breaches that happened because of secretary hegf and others on the signal Fiasco I think is the right response from us uh the American people demand accountability for the signal disclosures and as a reminder we have not only
▶ 1:05:38defense secretary Pete Heth we have National Security adviser Mike wals the vice president the CIA director our secretary of state marubio treasury secretary and the Director of National Intelligence all debating foreign policy arguing about National strategy and and sharing what is clear clearly War plans even though they'd like to admit say that they weren't on a signal change so this is of absolute importance to this subcommittee and important for us to discuss it of course they're doing all this
▶ 1:06:09while chatting with a reporter we can all agree hopefully our Republican colleagues included that that's totally insane and a level of incompetence and recklessness that should never be in our government now Dr blae uh we've seen this many times this is of course uh one of the one of the updates from secretary heg Seth um Dr blae here we have the SEC the defense secretary laying out exactly when and which planes we're going to fly and when our Pilots would be in danger now Dr Blaise I understand that signal
▶ 1:06:39is a good commercial option to communicate a lot of folks use it but to communicate exact times directives War plans is is absolutely unacceptable would you I know you've said it before but do you agree that this from a national security perspective should not be on this type of unsecured I I have no idea at what level that would be classified but it's certainly sensitive National Security information uh intuitively and and do we agree that secretary hexi or anyone at DOD should
▶ 1:07:09know this correct uh yes any anybody with access to classified information would also uh be briefed and have access to the authorized tools for handling that and so here we have secretary hexi sharing information which exposes our soldiers to Danger even though he should know that information could actually get to our adversaries and remember the best cyber security practices in the world actually don't matter if you're also careless enough to send all of this classified information which I believe is
▶ 1:07:39is is classified straight to an actual reporter so Dr Blaise can you remind us what would happen to an enlisted person or an officer who would leak similar information well I I think you know it it's safe to say that if I did something like that my access to testified information would be immediately revoked I would uh probably be uh terminated immediately and be facing a criminal investigation right so if you're a rank and file member of the military you certainly would would receive severe
▶ 1:08:09punishment a variety of different options yet the secretary of defense is still in his position having committed a offense clearly breach naal National Security protocols and and put American lives in danger any of us said it before will repeat it again he should resign or he should be fired in in addition to that hexi of course we all know has had a numerous other other issues in his past been accused of numerous other things was never qualified to actually do the
▶ 1:08:40job and continues in my opinion to not live up to this enormous mistake that he of course and others others made now I want to also just point out the bombings actually did actually not solve anything attacks from Yemen still continue and the whole episode revealed breath taken incompetence we got lucky this time that no Americans were killed but unless things change we're sitting on a ticking time bomb and I just also want to note because I think it's important that that the CIA director and dni director tulsy gabard who were active participants in the chat have told Congress
▶ 1:09:10under oath that they don't remember basic facts about the conversations they actually had and were involved with of course to avoid any sort of responsibility personally I think they lied to Congress and should be held accountable now we also know this isn't the only time these people have used sign to discuss classified information or other systems and I just want to remind us that the Wall Street Journal just reported that wal quote created an created and hosted multiple other sensitive National Security conversations on Signal with cabinet members and of
▶ 1:09:40course now we're also learning that he's sending information through his personal Gmail account so this is an enormous amount to investigate we absolutely have a right to bring it up in this committee and we need additional accountability and with that I yield back thank you I now recognize the gentleman from Arizona Mr Crane for five minutes thank you Mr chairman for holding this important hearing today thank you guys for coming you guys are probably starting to see why it's tough for us to get anything done up in Washington DC um I do want to defend
▶ 1:10:10my colleague Mr Cloud I don't believe um he ever said that uh you know the signal chat episode was a success I believe he was talking about the strikes against the houthis um I also find it rich that my colleagues on the other side who now claimed to be the accountability and transparency police um said absolutely nothing you know when we pulled out of Afghanistan and uh 13 Marines were killed um amongst other issues so
▶ 1:10:40moving on to this hearing I think it was great Dr amaroso that you talked about potholes and sink holes um you're looking at many of these uh hacks that we've experienced in the past as potholes but you seem more focused on the bigger attacks that will come in the future and you're referring to those as SCS is that correct that's correct sir would you uh would you look at some of the uh individuals
▶ 1:11:11that have hacked into our energy grid as a possible sinkhole scenario yes can you tell us um what your major concerns are when it comes to infrastructure like that disruption yeah wasn't isn't it true that director the former FBI director Ry even talked about that himself you know I'm not sure that's a common point though certainly Mr Steinman do you remember that I believe I do sir yeah what do you think would happen if uh
▶ 1:11:41the CCP or one of our adversaries were to uh take down our energy grid I think it would so incredible chaos I think uh it would be damaging to uh almost every American in the first and in the second order given uh the food supply chains that we use to eat every day uh the energy required to purify water to process sewage Etc and uh respectfully sir I would just offer that uh there have been numerous unclassified statements
▶ 1:12:12by Executive Branch Senior Executives to say that we do have foreign adversaries on that energy grid right absolutely um one of the things that you guys brought up is whoever controls Ai and does the best at implementing it into our cyber security you know will obviously be in the best position can you guys talk to how the United States government is doing and implementing developing Ai and using it within cyber security I I can offer a couple of points I spend a lot
▶ 1:12:42of time on that the first I think everyone should recognize again another analogy if you're human being playing a a a well programmed computer in chess you realize you lose every time right I think everyone gets that so just do you think we can beat a computer at Cyber you you kind of can't and as your adversary starts to really move in that direction you have to do that too now when we think AI fact for any of you if you're thinking
▶ 1:13:12AI the first word that should come to mind is data you have to have data to train systems to learn just like with children they have to be exposed to experiences to learn AI has to be exposed to data and to some sense experience that's the first thing we need need to do as a nation we have a lot of privacy concerns and a lot of um issues of intellectual property and ownership and competition and you've seen some of it in the hearing uh here you know
▶ 1:13:42some of the U the squabbles that we have in our country we have to fix that if we can't fix that then we'll never be able to build like I I've heard the president talk about this big global heal well I think that's a perfectly good metaphor for AI we need to do something that allows us to Pro protect against AI offense and the only way to do that is we have to architect something that makes sense we need to have the right access to data we have that the National Labs involved
▶ 1:14:13and large critical infrastructure has to be involved Academia has to be involved and our and our government leaders need to be working together to help us coordinate something along those lines Mr Steinman you want take that one uh yes sir I would also offer that it might be worth the committee's time to look into um some of the barriers to information sharing that private sector Executives and companies face uh I believe it was mentioned previously around dhs's role as acting
▶ 1:14:43as an Information clearing house but there are a number of barriers uh around liability protection that I believe um in order to adequately address will require congressional action so I would just offer that up as a possible place where you all could do some work thank you I yield back thank you um I request unit's consent that the subcommittee shall have a second round of questions for the members without objection so ordered I now recognize my
▶ 1:15:13for five minutes of questions so I was hoping to talk about salt typhoon more but um I just want to clarify some things about the signal chat issue so there's really three components of it there's the the app signal there's the individuals that are on that are communicating on the apps cell phones and then there's the content and the people that had access to the content so let's talk with signal first blae the salt typhoon attack would signal messages have been susceptible
▶ 1:15:43to the Salt typhoon attack so from what we know about the salt typhoon attack um so far it has been limited to the infrastructure itself took the communication unsecured communication on uh the infrastructure on infastructure they were basically collecting um data that was going through um the infrastructure and because if it was unsecured they would be able to access it and see what it says but if it was secured they would just throw it away because it's ones and zeros that make any sense from that's right
▶ 1:16:13what signal effectively does is means attacks against the infrastructure can't reveal content thank you that's exactly what I wanted you to say um so signal has actually been encouraged to be used by the Department of Homeland Security uh cyber security infrastructure Security Agency s and they actually recommended under the bid Administration for potentially highly targeted individuals to use it so not only is it
▶ 1:16:44um best practice to use endn encrypted it's encouraged to the point where uh when the CIA director uh took his post that were like you need to use signal you can't use anything else so I guess number one signal is secure unless unless the cell phone is compromised so my question Mr bla does it matter what app you're using if the cell phone is compromised um well no uh but let me let me
▶ 1:17:14just uh add a bit of nuance to what you said signal is secure in that it protects the information in transit but but it's one of the reasons it's not authorized for classified National Security uh purposes is it lacks features designed to protect classified information such as um ensuring that the recipient has a clearance and is authorized to receive
▶ 1:17:44correct so but but again signal is secure and an encryption but again it has to go the right person that has to go to the right person so it would be the classified tools would make it impossible for example to inadvertently at a reporter but uh a again if the cell phone is compromised it doesn't matter what app you're using because the cell phone's compromised and um in this case our national security um actors are not have their cell phones checked their cell phones were
▶ 1:18:14not compromised obviously the issue now becomes the content which was not classified was it best practice for a a reporter to be included no had that reporter told the houthis what was going to happen would that be really bad yeah didn't happen I can promise you that this will not happen again um National secur advisor Waltz has indicated that this was an error and I mean listen it's an error that will not be repeated um he is an incredible asset to our national security
▶ 1:18:44team so again there's just a lot of confusion around this signal is a secure ended encrypted app um the cell phones were not compromised a person was added an error and it did not have any impact on the outcome of the operation which was a success so I mean I think the biggest thing here is that I feel like we're my colleagues across the aisle are talking out of both sides of their mouths when they're concerned about this signal chat that had
▶ 1:19:15um no adverse impact on National Security and um did not involve classified information and I can promise you what happen again when we didn't have any hearing on Joe Biden having classified information that he actually had no right to have in his garage um from his time in the Senate Hillary Clinton's I mean classified email private server for days and Joe Biden used a fake email account to correspond with the son's business associates so I guess all of these things I mean we're here to talk about salt typhoon and
▶ 1:19:45what we can do to as Dr amaroso pointed out avoid the sinkhole we've got potholes for days the sinkhole is coming and we need need to be working to make sure that we are ready and I would say that we certainly are not right now so I look forward to working with my colleagues across the aisle to make sure that um our country's critical infrastructure is secure and we got a lot of work to do um with that um I yield back
▶ 1:20:15and I now recognize the gentleman from Virginia Mr Superman for five minutes uh could I uh get unanimous consent first to enter into the record um a couple articles one uh Chinese hackers are said to have targeted phones used by Trump invance this was October 25th um 2024 uh I believe that's New York Times without objection so order
▶ 1:20:45and then the the second was Pentagon staffers Pentagon warned staffers against using signal before White House chat League uh I believe this was Washington Post on Tuesday March 25th 2025 without objection so ordered thank you um Mr chairman um so I um Mr blae have you seen any evidence that the personal devices of the people who are using signal
▶ 1:21:15were compromised or not compromised uh I've seen no evidence one way or the other yeah so we don't actually know if their phones were compromised or not but we do know uh from the articles I just sent into the record that certainly the vice president was already a Target and certainly if I were looking to Target someone I would look at our national security advisors uh and I I just have to say that um I'm glad I haven't heard from the administration much about this being an error but I'm I'm glad I'm hearing it
▶ 1:21:45um from some but you know we have what I really want to hear from the administration is that they made a mistake that they're going to fix it and here the steps are going to take to make corrective actions in fixing what was a serious serious blunder uh and serious leak of National Security intelligence and that's my problem with this is that even if you say that a mistakes happen there there are no steps right now in
▶ 1:22:15fixing this as far as I know and there's no one admitting that they made a mistake and there's nobody telling us what corrective actions are actually being taken how prevalent this issue was I entered into the record earlier about how previous administrations were hesitant to use signal for this very reason that uh our Witnesses are telling us today uh one witness said that that signal could actually
▶ 1:22:46be hacked even though it is encrypted end to end because we now have Quantum Computing that's a really good uh and then uh Mr blae Dr blae has also mentioned that that these systems are vulnerable even setting aide signal itself and we have 13,000 secure facilities across the country and we have staff for every one of these National Security Experts who are there
▶ 1:23:16for the very purpose of making sure that they can communicate anywhere at anytime around the world troop movements and other sensitive classified information and so it's not like we haven't given the administration the resources to communicate securely it's just they decided not to and in doing so I think they've broken at least six laws in in regards to security as well as transparency and uh I think this is a big problem that
▶ 1:23:46the Administration has broken these laws and not admitted any sort of fault or mistake and the response has been to just toss aside as ham or Chicken Little I think was said earlier I I think there needs to be more attention paid to what happened how prevalent it is and what the administration is actually going to do about it and so this is relevant because you know today's hearing is about compromising our
▶ 1:24:18infrastructure but you know if you did a poll I think we have a study of all the Chief information security officers uh I think 80% said that human risk was the number one problem in securing cyber security and and and Telecom information and then I'd actually ask you Mr blae would you agree with that characterization that human error might be the number one concern when it comes to Telecom risks uh th that's probably true although
▶ 1:24:48I I i' quibble a little bit with uh how we how we Define human error a lot of human error is inevitable because of poor design choices for the systems that we use but I guess what I would what I would really like is to just have an investigation into what happened and uh one of the things I'd like to um to share with uh my colleagues is that we've actually asked for an investigation I think only there are only Democrats
▶ 1:25:19on the letter to the administration right now but I know some Senators on the Republican side have I've actually uh openly asked for some sort of Investigation but at least we can get to the bottom of what happened how prevalent this is what we can do to fix it so that it never happens again I I I hear that that's a shared goal and I'd like to see us work together and doing that and so instead of trying to sort of brush this aside as something that isn't a big deal let's admit that it was a big deal
▶ 1:25:49and let's try to take steps to fix it and not just try to cover this up thank you and I yield thank you I now recognize the gentleman from Virginia Mr McGuire for five minutes thank you Mr chairman and thank you to the witnesses for coming here today uh during the attack salt typhoon maintained undetected access for up to 18 months this incident is described as one of the most severe Telecom hacks in US history despite existing public private Partnerships to prevent cyber attacks it seems as though there is still significant
▶ 1:26:19information gaps uh Mr Steinman are there any federal laws or regulatory red tape that prevents or hampers information sharing about hacks between government agencies and the industry uh thank you Congressman I would of course uh defer to Mr amoroso's experience being the former Chief Information Security Officer of AT&T around specific granular uh challenges with information sharing but
▶ 1:26:49I would like to emphasize the point that you made which is that whether it's uh uh questions of liability at the corporate or the individual level um questions of insurance uh insurance policies we saw that in the not Peta Cyber attack where uh and in the um Colonial pipeline attack where we had issues of who would pick up the tab uh when there was a business Interruption process as a result of a Cyber attack that it really is a deep nested issue
▶ 1:27:20let ask a question for droso uh the 2023 National cyber security strategy emphasizes preventing the abuse of us-based infrastructure but it largely omits deterrence Dr Moroso in your view why was deterrance overlooked and how critical do you think it is to incorporate it into the strategy yeah we' uh come up earlier this question of deterrence I mean certainly it helps I mean I'm a I'm an operator so I wouldn't be the person doing the deterrence but if someone's doing it it's going to help
▶ 1:27:50your your your point about um information sharing is an important one you know back in um 96 I remember sitting in this building when we first started talking about it was a a pres PDD 63 it was the first sort of ISAC stuff we were very hopeful that information sharing would solve a lot of problems it kind of hasn't I wish it had and I wish I could tell you that just improving the communications will make things better but I've kind of
▶ 1:28:20given up on that I think it's time now to build a new barn you know what what I mean like I think the one we have has been patched so many times and it's so rickety that you and I are standing looking at it going you know what time to build a new barn well we all know the definition of insanity and you know China believes that everything can be used as a weapon and it should be used as a weapon so how would you propose do Dr amaroso the US increase the cost on China to deter their cyber operations
▶ 1:28:50especially when they seem to act with impunity under the current framework yeah I understand I I obviously deterrence can be done in any number of ways not really my area of specialization you can do with diplomacy you can do it with non-cyber but I think the best deterence of all is to have the best defense on the planet you know if they can't break in then there's no discussion yeah it seems like we're in a reactive position rather than a proactive position on that I would agree I think that's where we are now I think you and I would agree on that
▶ 1:29:20but I'd like to get around that I think there's active defense that's different than deterence you know what I mean sure so uh Congress and President Trump established the cyber security and infrastructure agency in 2018 to protect critical infrastructure and guard against cyber security threats under the bid Administration sisa diverted resources to collude with social media companies to surveil and censor American citizens would you agree with that I don't know anything about that the others might know something but I
▶ 1:29:50Mr Simon yeah that's my understanding sir and how about Mr blae would you agree with that statement I I have no idea how the resources were allocated sure well thank God we got president Trump back in the white house to fix the broken agency and restore it to its congressionally directed Mission but I would ask you um if you wanted to become a subject matter expert in cyber security for the purposes of helping the Trump Administration and I guess I'll start with Mr styman where would you go what would you do to become a subject matter expert so you could better
▶ 1:30:20help make decisions in Congress to help president Trump's America First agenda and protect us from China and other adversaries there's great resources available at the Sans Institute it's a place where I point a lot of aspiring young cyber Security Professionals uh there are classes taught by my two fellow panelists at uh Georgetown in NYU I'm sure they'd love to have you as well uh thank you Dr Oso ditto there's a lot of good resources M absolutely and I'll point out many of my students are here
▶ 1:30:50in the in the gallery awesome and tell me where there where they stent students uh Georgetown with that I Y back thank you thank you I now recognize the gentleman from Texas Mr Cloud for five minutes thank you again chairman and uh one of one of the big concerns I I have is of course we need to secure ourselves against China Harden our infrastructure you know do everything we can to to stand against what they're trying to do uh but we are a free society as well so
▶ 1:31:21I'm always mindful keeping the American people safe is one of our top priorities but keeping them free is actually our top priority uh as as members of Congress and of the government and so um and then we're in the context of as we move to AI as you point out Mr amaroso uh the challenges are going to get Monumental uh when it comes to cyber security and then AI is dependent and developed on big data sets
▶ 1:31:51uh which the CCP has no qualms about uh stealing hacking uh invading personal privacy of their own people and our people uh in order to create these huge data sets and so as we put together solution sets I'm curious about how to keep that that balance uh as we move forward of protecting the American people Mr blae you even talked about the back doors in some of uh
▶ 1:32:21that have been required in some of our Telecom infrastructure which is of a concern to me as well um I wanted to throw that out there and just see see what your thoughts were uh I guess we'll start with you Mr Amarosa if you want to follow sure I mean I'll give you an example so everyone in the room here either uses Microsoft or Google for your from email right pretty much and I'm guessing everybody in the room here would say that doing email is the worst one hour or two hours or three hours of your day right so if you had a piece of AI that did
▶ 1:32:52your email for you and you trusted it and it was worked and it gave you a little list at the end of the day the things that it needed to check in with you then fishing goes away like the fishing risk I there's other attacks that emerge you know malware and your AI agent but the point is that as we upgrade our infrastructure and we do it intelligently we can make some of these attacks go away it's one example there's a lot of things like that but to
▶ 1:33:22do that would require concerted sort of coordinated effort with the email providers with privacy groups with government and so on and so forth that's kind of what I'm talking about but you can diminish the intensity the of these attacks by using technology intelligently Mr Blaze do you want to speak to the the issue of the back doors yeah and and certainly so so more more broadly we are um you know right
▶ 1:33:52now fighting a battle in which the attacker the offense side has the advantage because the systems that we have to defend are incredibly complex new vulnerabilities are found you know every week um and uh the implications of attacks are so far-reaching we can't even uh analyze what the consequences of some of these threats uh will be uh fully
▶ 1:34:22and we will probably be at a disadvantage on defense for a while it's one of the fundamental problems of computer science that we don't know how to build bug-free software and as complexity increases the number of bugs and vulnerabilities also increases along with that and that that is problem a bug is different than a mandated back door that's right and so adding mandated back doors into the equation essentially you know preloads the bugs we don't even have to find
▶ 1:34:52them we we know they're there already uh so you know we will never be able to make our defenses perfect with uh the way we're we're doing things now it's a problem I would love to solve but we can absolutely do better than we're currently doing Mr Simon I wanted to ask you you talked about uh us not being on a wartime footing when it came to our our cyber infrastructure development uh one of the disadvantages you know when we point to our history for example with the the Soviet
▶ 1:35:23Union versus the CCP I've always said at least the Soviet Union was honest with us uh the CCP has pretended to be our friend while they've plan for world domination and certainly our demise uh and used every Avenue including cyber to to be on a war footing against us uh while you know we especially in the previous administration would refuse to a knowledge that as a nation what what does that look like uh using your experience and knowledge base uh
▶ 1:35:53yes congressman I I think that's right I think the Chinese Communist party and their Military Intelligence apparatus are already in a in a in a footing that we would describe as a wartime footing they believe that that's the posture that they should have uh 247 um and they use language to try and communicate to us that they are not in that footing and they use that language deliberately to deceive us and to make us think oh everything's okay we can just sort of uh be friends um they do this while hacking us blatantly
▶ 1:36:23while then denying when they get confronted uh and so I I believe that it's time for us to take a much more aggressive posture that's what we did when I was in the White House during the last Trump Administration uh and I believe that it's the smart thing to do now thank you m CL up on you B thank you uh I now uh Mr Bigs for five minutes thank you Mr chairman and thank you again to the witnesses
▶ 1:36:53for being here um I just have a couple of specific questions and and then then a comment or two and then back to questions so the first question is do know the there were more than a million people essentially victimized in in in the Cyber attack that um has has consumed us today well should have consumed us today do we know if each one of those those Vic victims
▶ 1:37:24because I would say they're all victims were were they each and everyone notified that they were a victim do we know Mr Steinman do you know I don't know congressman and I think it's a great question Mr am M Dr Amarosa Dr blaz I've spent a lifetime with these kinds of large scale attacks and almost always the answer to that question would be no okay and I agree with Dr amaroso yeah I always wonder with my own paranoia you know if I'm in that group somewhere
▶ 1:37:54you know but uh in any event um and that leads me to some some specific questions with regard to to States and working with the fed the Fed so you've all kind of alluded to this there needs to be cooperations needs to be communication these me some kind of uh uh Mutual uh communication about what needs to be done how have the states themselves responded or how are they being treated uh in this
▶ 1:38:25is there let let let me back up is there any kind of working collaboration that really exists today um Mr stman thank you Congressman I would point to some of the bright spots in America's uh cyber security apparatus as uh the National Guard elements that do cyber security um and uh they've done a lot of activity both at home and abroad where they will train uh with
▶ 1:38:55victims of some of the most latest uh attacks is this is this a broad uh what I'm trying to find out is there a broad Coalition a collaboration that's going on I mean or is it the pocket here pocket here siloed here siloed here I've seen it uh state byst state with the state partnership program of National Guard uh cyber elements I do believe that is coordinated uh to some degree the Pentagon but you'd have to dig into that
▶ 1:39:26okay any other comments from Dr em I um I coach a lot of the security leads at the state level and it's a full range you know there's multi-state different groups multi-state isacs and so on coordinating this and that councils groups but they also compete you know they want to be the the top state you know to do cyber but the one thing they all say in common is we have no resources we need more people um I think I've never met a state that says
▶ 1:39:56gosh we're good um so they do need more resources yeah I yeah oh I I I would just point out that it you know the resources of states are uh very much at a disadvantage compared with the national resources that we have of the federal government you know effectively we we never ask we don't ask the state police to repel foreign military invasions um and you know in a lot of cyber security issues that's exactly what we're doing
▶ 1:40:26yeah you know I'm thinking of places like Arizona which has the one of the the largest nuclear facilities in the country in palati and I'm I'm really interested I've talked to them and uh they they're actively trying to you know protect that structure the state is but I'm not sure how whether the resources are there where the Personnel is adequately there and now I'm just going to make a a quick comment here and I have to do this
▶ 1:40:56and I I'm sorry because I wanted to get to more very some very specific issues but I have this this comment has to be made um when you keep 30,000 classified uh emails on a private server in a private home um you might have a bit of a security problem and that's what happened with Hillary Clin and buiss Silence quietude from the left um and and I'm Dr Blaise I'm not trying to put you on the spot
▶ 1:41:26but I am going to put you on the spot because they asked you a question I'm going to ask you a question to follow up so it's not meant to to be an attack at all but with regard to sisa and and the individuals that who've been riffed at sisa I assume you don't have any personal knowledge of any of those P persons any of their qualifications any of their performance capacity any of their uh their skills their training Etc is that fair to say that's fair yeah so um this that's what we mean
▶ 1:41:56when we say this gets politicized they don't know we don't know but what we really wanted to find out today is what happened how do we prevent it how do we work together to stop it and I feel like we've been derailed just a little bit here today and that's unfortunate because both sides profess and want to get to the bottom of this because it is a national security issue and will in fact impact us from actually for generations to come so we've got to get ahead of it like right now
▶ 1:42:27and with that Mr chairman I'll you'll back thank you and I recognize the gentleman from Arizona Mr Crane for five minutes thank you Mr chairman um you know since my colleagues came in here and politicized this event today I want to ask the chairman chairman did you forget to invite the Democrats to this event today I did not no sir that's interesting because as I look down I see a bunch of empty seats and for those um that came in here and talked today you'll note that they asked very few questions about cyber security how to prevent and stop it
▶ 1:42:57they spent most of their time talking about a signal chat and after their comments I hope you all you all noticed that they got up and left they didn't really care what you had to say did you guys notice that okay good I'm glad you did now back to the hearing um a lot for because a lot of us are laying on on this topic a lot of us Wonder how hard is it once you identify a cyber threat that has embedded itself
▶ 1:43:27within your infrastructure systems to either block them kick them out Etc Dr Amoroso yeah can you know someone that um Matt Blaze and I remember K Ken Thompson wrote a paper in 1983 where he taught all of us basically how you do what you just said and make it essentially disappear like it's not completely gone but it's mostly gone gone and and we all kind of freaked out at the time and here we are 40 years later
▶ 1:43:57and we're talking about it but you should kind of accept that if somebody's really good at dropping malware into your infrastructure you're probably not going to find it really yeah well do you think AI will really help us with that I think you have to change the game it'd be like there's a terrible analogy and I apologize but if I could drive a truck bomb into your home and blow the whole place up how do you stop that you don't put defense what you do is you break your home up into a lot of different pieces
▶ 1:44:28suppose your home was a thousand concrete blocks what do you blow up and you'd say well I can't live in a house like that and that's true but Computing works that way we call it virtualization and cloud and so on so it's it's we have to change the game not sort of solve that older problem because you're not going to solve that problem when you guys we've spent a lot of time talking about the CCP in China today because they do have a very robust um cyber security offensive
▶ 1:44:58uh capability but obviously there's other countries out there as well that are hacking into US infrastructure like Iran North Korea Russia Etc when you guys look at the amount of resources that those countries throw into cyber attacking and then you look at what we're spending on that as well how does that how does that measure out Mr Steinman I think it's a great question congressman and it's one that I would encourage uh a significant amount of attention
▶ 1:45:29from the committee on which is you know what are we paying for billions of dollars uh have flowed uh to the various cyber elements of uh the Department of Defense and elsewhere and and what is that producing uh I will say it does produce a lot of good people that are very talented but when we think about capability I I just think there's probably a lot of room for investigation there and thinking about how can we use those dollars effectively and efficiently I would also just like to touch on something that that you seem to raise
▶ 1:45:59which is that and the panelists have raised which is that we have lots of attackers coming at our critical infrastructure and what I would say is by taking a more aggressive posture to go back at those attackers we throw sand in their gears we force them to spend time and effort uh to defend against our counterattacks and those could be ones that are managed at the national level or they could be the the the prickly uh Landing Point inside the company
▶ 1:46:30that those cyber actors are going after and so I I would just offer that there is a lot of opportunity to interrupt um and delay and deny and obfuscate uh when we think about offense I I want to talk real quick M Dr amaroso I know you come from the the corporate world the private sector um when you look at the amount of resources that the corporate and private sector is throwing at um countering cyber security
▶ 1:47:00attacks as opposed to uh the federal government can you give us some sort of comparison and understanding um the differences between what the corporate in private America is doing and what the federal government is doing there's a difference between size and quality right I mean you can throw a bunch of resources if you're doing it wrong then you could double that and it won't make any difference so I think both in corporate and in government we need to improve both need to optimize like in some cases we
▶ 1:47:30don't spend enough time think cryptocurrency that's a place where we should be spending more time like North Korea I think they like fund the whole country by stealing cryptocurrency so there's an area where we've done a very poor job globally protecting ourselves but in other areas we referenced earlier like compliance I mean we have so many resources chasing framework after framework after framework that when you count those resources to your question you could double it it would have no impact so
▶ 1:48:00it's we have to rethink the size and quality it's an optimization question as opposed to do we have enough does that make sense yeah thank you guys I yield back thank you in closing I want to thank our Witnesses once again for their testimony today salt typhoon is an important thing for us to learn from and I guess we got to talk about signal a bunch too luckily signal chats are immune to Salt typhoon as Mr blae pointed out with that I now yield to ranking member sub Manion for closing
▶ 1:48:31remarks uh thank you Mr chairman um just before I go into my closing I want to uh address a couple things one someone mentioned that they didn't know who the sisa employees were what their qualifications were uh they actually many of them live in my district and so I can tell you from um hearing from a few of them they're actually um many of them were fired because they were probationary employees and who are actually very highly qualified in the work they're doing and actually had very good performance records and we had actually um in the past two administrations
▶ 1:49:01including the first Trump Administration been begging Tech talent to come to sisa and come to the federal government and then we fired them all and so uh we're actually a judge actually said that that was illegal and so they're currently on administrative leave but uh it's a big risk to our country when we are chasing away Tech talent in our federal government and so that's what really concerns me and uh second I I still think we need to have an investigation into
▶ 1:49:31what happened with these signal chats if we want to fix the errors if we want to make sure that this mistake doesn't happen again we we we need to know first what happened second what corrective actions are taken uh third if this wasn't classified information we should actually be able to have a secure briefing where we can get the communications from sencom to the SEF on exactly what they were saying and whether that was classified or not and what he shared whether that was classified or not we can do that in a secure briefing room but in either case we need to get to the bottom of what happened
▶ 1:50:01and that doesn't need to be partisan uh but somehow it's become partisan that's disappointing uh I want to end uh by just sharing again constituent stories about um this um signal incident because this really does hit home for many of the veterans and military families that live in my district uh one constituent said that they've worked in National Security for 18 years I've held the highest security clearance for 18 years and for 18 years I've lived a life most people will never understand my promise to defend this nation doesn't stop when I clock out
▶ 1:50:32it permeates every single aspect of my life it affects who I marry who I live with who I date who I'm friends with who I speak to I would be sitting in jail right now if I had done something as braz and Thoughtless and dangerous as what JD Vince Pete hget John Ratcliffe Mike Waltz among others did today a second who a uh son is in the military said that that our nation top defense official shared sensitive troop movements over a commercial social media platform without verifying who is on the other end is not only Reckless it is terrifying our
▶ 1:51:02service members and their families deserve leaders who treat their safety with the gravity it demands this breach not only endangers lives but erodes the trust of those who serve and support our military my son has sworn to defend this country I expect the same level of responsibility Integrity from those in charge I yield back thank you um I guess we're g to start with signal um I think it's important to realize that President Trump said Walt's messed
▶ 1:51:32up so accountability has been acknowledged and a mistake was made um Waltz has again said it was an error himself I think what's important is that no harm resulted from this mistake and I can promise you that it will not happen again so I I appreciate that my colleagues across the aisle want to continue talking about signal but I think what's important is that our Administration is leading in the global community and is holding our um
▶ 1:52:02adversaries accountable and keeping us safe um as to the sisa employees that have lost their jobs we have $36 trillion in debt we're running a$ 1.8 trillion deficit we have to rightsize the fiscal ship in order to address any of the challenges that lie ahead and while it is unfortunate that all of the probationary employees across all of the government um were let go we cannot continue forward on the trajectory we are our
▶ 1:52:32our we just can't afford it we can't afford it so we're having to make these decisions in order to um make sure that we have the American dream for generations to come lastly but certainly not least salt typhoon why we're here so we've had a good conversation about the exposure um obviously the Chinese were able to use outdated infrastructure to gather enormous amounts of unsecured data and they focused it largely on Washington DC because it's our seat of government and because they're able
▶ 1:53:03to um learn what uh we're planning learn learn from the communications between our government officials and I realized that my colleague from Arizona was asking the question of was his data collected if he's communicating on the the the phone or through unsecure text I guarantee it was so you know and they probably were able to figure out that he was a member of Congress and we need to use signal which is funny we need to use signal because it is more secure
▶ 1:53:33um I also want to talk about what I think Dr am amaroso mentioned that we got to have good defense and I agree with him I think that we need to do a much better job and we can do that we got to invest I think the bigger thing I actually on Liberation day as president Trump talks about tariffs for um you know right sizing uh our competitiveness in the global economy I think that we have the opportunity to use tariffs in cyber security by holding our adversaries accountable if if you
▶ 1:54:03breach um critical infrastructure if a foreign adversary or even a a foreign actor that is in a country that's not enforcing the rule of law if they um breach uh a business in the United States if they breach the US government if they breach critical infrastructure we can use we can say all right this is why we believe it's the the Chinese this is the attribution we're going to hold you accountable by using tariffs to extract revenge of some kind to create a a deterrent threat
▶ 1:54:33to make sure that this this doesn't happen again in the case of um the colonial pipeline attack we could give the resources to um whatever country is struggling to enforce the rule of law um in the case of 911 harboring Al-Qaeda was enough for us to physically invade so it's not unreasonable if uh a a terrorist or a foreign state is going to cause
▶ 1:55:03immense damage and threaten our national security that we just use tariffs to hold them accountable to extract economic pain these are the conversations we're going to be having going forward and I think that we need to both invest in a good defense and also uh go on offense and make sure that we're able to use every tool in our toolbox to hold both um nation state actors and um non-state actors accountable that's that's the future and again I just really want to thank the witnesses for being here
▶ 1:55:33uh today this was a very productive conversation and um with that um I'll close uh without objection all members have five legislative days within which to submit materials and additional written questions for the witnesses which will be forwarded to the witnesses if there's no further Business Without objection the subcommittee stands adjourned thank you thank
▶ 1:56:51e e