🧵 So today we’ve got the Government’s vision for online harms legislation. It’s a landmark day for all of us who’ve worked for this for years. Some quick early (personal!) thoughts:

This is a systemic Duty of Care, with a requirement to risk assess - regularly - for reasonable foreseeable harms and to act on them. Supported by Codes but that serve as guardrails, not a prescriptive checklist
There’s a broad requirement on all services to tackle illegal content and to take measures to protect children. Worried that age assurance may be expected to do a lot of heavy lifting instead of proper moderation for legal but harmful, but we’ll see
The biggest weakness: enforcement measures. Criminal sanctions & named persons have deference value - that’s why industry pushed back strongly. But not for at least 2 years and even then only covering failure to comply with the regulator. If Govt thinks this is really enough...
Investigatory powers are OK (particularly pleased to see the inclusion of skilled persons reviews šŸ˜‰). But the balance between investigatory powers and duties isn’t where it needs to be to drive culture change
It’s a bold and necessary step to have encryption and private messaging services in scope. It reflects the threat vectors for CSA, and regulation wouldn’t appropriately tackle child harms otherwise
An intriguing reference to Ofcom co-designating regulatory powers šŸ¤” But otherwise the Govt approach to user advocacy - leave it to Ofcom, without creating a funded user advocacy body - isn’t a level playing field and needs tightening in the Bill
There’s a MASSIVE gap around arrangements for platforms to tackle the cross-platform nature of risks, and to address material which facilitates CSAM. Regulator needs an approach that recognises the harm ecosystem and adopts an approach earlier in the abuse pipeline
This is an approach which rightly majors on children, but it arguably should have a broader focus for societal harms. We’re getting a real time lesson in disinformation, with the failure of platforms to moderate antivax an emerging and obvious public health risk
Is this world leading? We’ll see the #DSA later today. And on the surface, it has weaker enforcement powers than Ireland. But it’s still an important package, and there’s lots to fight for in the months ahead
One final thought: big shout out to some wonderful people that have worked tirelessly on this in past or current lives: @martha_kirby1 @_rosyrosyrosy @ga_hill @RuschenHannah @CharCallear. Heroes don’t always wear capes, but if you see them, you definitely owe them a pint

More from Government

Let me take a stab at this after years of reporting on Marine One, HMX-1, Continuity of Government, etc. None of this is definitive, but it could help explain what folks are seeing:

1.) HMX-1, which flies the VH-3D and VH-60N 'White Top' helicopters used to move... 1/X


the President and VP around, those helos being called Marine One or Two when either is onboard, need to train. The urban landing zones, including WH and VP Residence, are not simple to get in and out of. So, crews need some currency training. They are not just tasked with... 2/X

moving POTUS and VP to get them around the region and to Andrews AFB for long-haul flights, they are essential to Continuity of Government operations. This means that if a threat were to emerge, they need to be ready to snatch POTUS and VP in minutes. This is partially... 3/X

why they have a full forward operating location at Naval Support Activity Anacostia, just 3 miles from the WH. As such, practice is important and considering the state of things, it is critical now more than in any recent memory. 4/X

2.) Considering what happened last week, including mobs of Trump supporters screaming in unison to hang the VP for doing what the constitution states, absolutely despicable in every way, security has been tightened just as it has been all over. Using the helicopters instead.. 5/X

You May Also Like

The entire discussion around Facebook’s disclosures of what happened in 2016 is very frustrating. No exec stopped any investigations, but there were a lot of heated discussions about what to publish and when.


In the spring and summer of 2016, as reported by the Times, activity we traced to GRU was reported to the FBI. This was the standard model of interaction companies used for nation-state attacks against likely US targeted.

In the Spring of 2017, after a deep dive into the Fake News phenomena, the security team wanted to publish an update that covered what we had learned. At this point, we didn’t have any advertising content or the big IRA cluster, but we did know about the GRU model.

This report when through dozens of edits as different equities were represented. I did not have any meetings with Sheryl on the paper, but I can’t speak to whether she was in the loop with my higher-ups.

In the end, the difficult question of attribution was settled by us pointing to the DNI report instead of saying Russia or GRU directly. In my pre-briefs with members of Congress, I made it clear that we believed this action was GRU.