Infosec big names rally against US voting app maker's bid to outlaw unsanctioned bug hunting via T&Cs
- Reference: 1600132139
- News link: https://www.theregister.co.uk/2020/09/15/voatz_bug_hunting_letter/
- Source link:
Earlier this month, Massachusetts-based Voatz filed an amicus brief in Van Buren v. United States, a [1]case being heard by the US Supreme Court that will determine the scope of the US Computer Fraud and Abuse Act (CFAA), a cybersecurity law long criticized for its ambiguity.
The software outfit, stung by [2]a probe in February that found multiple security weaknesses in the app it supplied for West Virginia's 2018 midterm election, [3]asked the supremes to uphold a lower court decision that interprets the CFAA very broadly.
If the US Supreme Court rules that the verdict in the Van Buren case is correct, it will mean companies can decide for themselves, through policy documents, what constitutes criminal behavior with regard to vulnerability research and other online interactions. Disallowing certain kinds of access through a terms-of-service declaration would make such activity potentially actionable as unauthorized access under the CFAA. In other words, an organization can decide what counts as illegal hacking, meaning harmless prodding around a site or service could land you in court.
Those investigating security issues worry that allowing companies to define the parameters of lawful access will have a chilling effect on bug hunting.
Now, dozens of these individuals, such as Matt Blaze, a professor of computer science and law at Georgetown University, and Lorrie Faith Cranor, professor of computer science and engineering and public policy at Carnegie Mellon University, signed [4]an open letter supporting [5]an amicus brief filed earlier this year by the EFF, the Center for Democracy and Technology, and the Open Technology Institute to reverse the Van Buren ruling.
CFAA latest: Supremes to tackle old chestnut of what 'authorized use' of a computer really means in America [6]READ MORE
The signatories argue that security research is vital and improves the safety and security of systems we depend on for voting, healthcare, transportation, and other aspects of society.
"It is not a given that this vital security work will continue," the letter stated. "A broad interpretation of the CFAA would magnify existing chilling effects, even when there exists a societal obligation to perform such research."
The letter writers went on to chide Voatz for acting in bad faith toward security researchers and misstating its policies toward them. They cited the company's decision to report a student who uncovered a bug in its app to authorities for failing to seek prior authorization, something granted under the corp's bug bounty program. Voatz disagrees with the letter's characterization of these events.
And they then criticized Voatz for claiming that the MIT researchers who found bugs in the Voatz app did so without authorization. The MIT team, the writers of the letter insist, did not need authorization under America's Digital Millennium Copyright Act's security exemption.
"Voatz’s insinuation that the researchers broke the law despite having taken all precautions to act in good faith and respect legal boundaries shows why authorization for this research should not hinge on companies themselves acting in good faith," the letter stated. "To companies like Voatz, coordinated vulnerability disclosure is a mechanism that shields the company from public scrutiny by allowing it to control the process of security research."
[7]Via Twitter , Mike Spectre, one of the co-authors of the MIT report on the Voatz app, pointed to the company as an example for all the policy arguments they're trying to make about the need for CFAA reform.
"Voatz’s unprofessional behavior toward security researchers is exactly why the CFAA needs reform," he wrote. "Voatz’s use is exactly why election systems need better regulation."
In a statement emailed to The Register , a spokesperson for Voatz told us the following regarding its amicus brief and the subsequent open letter against it... ®
We repeat and make it very clear, we were compelled to file this amicus brief because we were falsely cited in previous filings from July 8th, and the example cited is at the very least inaccurate, in that Voatz made no report to the FBI or any other federal authority and no one who participated in our bug bounty programs has ever been reported or included in any client security bulletins. This letter repeats these misstatements. The University of Michigan student was not a participant in our bug bounty program. This was a failed attempt to tamper with a live system during an election.
We’re not advocating to limit anyone’s freedom – we’re saying it’s difficult to distinguish between good and bad faith attacks in the midst of a live election. For everyone’s sake, it’s better to work collaboratively with the organization as bad actors disguise themselves as good actors on a regular basis. All attempts to break into or tamper with an election system during a live election need to be treated as hostile unless prior authorization was specifically granted. Alternately, researchers can use our publicly available test systems which are true replicas of live systems in terms of functionality.
Get our [8]Tech Resources
[1] https://reason.com/2020/04/15/is-the-supreme-court-about-to-take-its-first-big-cfaa-case/
[2] https://www.theregister.com/2020/02/13/voatz_mit_election_app/
[3] https://www.theregister.com/2020/09/04/voatz_supreme_court/
[4] https://disclose.io/voatz-response-letter/
[5] https://www.eff.org/document/amicus-brief-van-buren-v-united-states
[6] https://www.theregister.com/2020/04/20/supreme_court_cfaa/
[7] https://twitter.com/mspecter/status/1305499955520516097?s=20
[8] https://whitepapers.theregister.com/
If he loses, recounting won't change the outcome, he just wants that for show. He needs to throw up a lot of mud so that if he loses he can claim the election was stolen from him - the same scam he was setting up prior to the 2016 election when he was expecting to lose.
He'll get a regular show on Fox News next year where he'll whine and bluster and continue dragging the republican party down the drain with him, until all the investigations that he's no longer able to stop get the goods on him and he's exposed for the giant fraud he always has been.
Only after he's disgraced can the republican party purge his enablers and quit trying to be the party of the angry white man. If they continue down that path into the 2024 election, they will become the Whig party of the 21st century and some new party will spring up to replace them.
Free your mind...
...And the world will follow. This is a classic case of tunnel vision.
If Democracy fails in U.S. it means Civil War II and since the U.S. spends such a large percentage of it's money on weapons it would be a catastrophic civil war. There is no way to fight drones equipped with Hellfire missiles when the best weapons your side can muster are small arms. You cannot defeat a tank battalion with a few dozen AR-15's and Winchester 270's. If the military splits into faction like in the first Civil War there will be more than two sides this time around and their resources would be heavily fragmented. So we would have some people with planes and tanks, others with tanks and ships, and still others with nothing but a few nukes. Complex lifeforms on Earth could not survive such a war.
Anyone who can bother themselves to think about this stuff for a few minutes will come to the same conclusion: Democracy has become Too Big To Fail.
So if security researchers are finding bugs that threaten Democracy they shouldn't be made into outlaws but lauded as heroes. If a company manufacturing technology vital to the Democratic Process cannot tell the difference between Democracy and Capitalism they should be replaced before the harm they can induce out paces their imaginations.
Re: Free your mind...
You most certainly can, just not on the tank batallion's timetable. You appear to have forgotten that almost every single guerrilla / asymmetric war that the US military has taken part in, it has lost.
You have gents locked in cans with limited resources, versus those that are unconstrained in how they approach the situation. Got out to use the loo? Oh, that's two down already. Oh, got out to go sleep? That's more. Slept in the tank? Shame about the flammables or the poison gas or the other fun things that happened. You thought they were air-tight? Naaaah....
In short, most of your post was puffery, and the rest misses the real point. Yet another company is trying to conceal how shit their product is, likely lying about the actual events. Real attackers aren't going to give a shit about whether they've hurt this company's feelings or not, so here's hoping they get completely creamed by the courts.
it will mean companies can decide for themselves
Translation: The company is too busy counting the money rolling in they can't-and-won't fix the vulnerabilities.
Look at it this way, if Donald loses this election, he can use this as a leverage for the recounting of the votes.