• About Us
  • Privacy Policy
  • Contact Us
  • Home
  • Bitcoin
  • Ethereum
  • Cryptocurrency
    • Altcoin
    • Litecoin
  • Blockchain
  • Regulation
  • Market
  • Prices
  • ICO
No Result
View All Result
Cryptounfold
No Result
View All Result
Home Blockchain

Voatz Calls for Restrictions on Independent Cybersecurity Research in Supreme Court Brief

by admin
September 4, 2020
in Blockchain
0
0
SHARES
7
VIEWS
Share on FacebookShare on Twitter


Related Posts

Regulators Are Paying Attention to UST

Market Wrap: Cryptos Decline Amid Choppy Trading, DeFi Tokens Underperform

Las criptomonedas deberían cumplir con las mismas normas que las finanzas regulares, dice el G7

Bitcoin Returns Above $30K; Resistance at $35K

Blockchain voting startup Voatz argued that bug bounty programs concerning cybersecurity should be operated under strict supervision in a “friend of the court” brief before the Supreme Court of the United States (SCOTUS).

Voatz weighed in Thursday on Van Buren v. United States, a Supreme Court case examining whether it is a federal crime for someone to access a computer “for an improper purpose” if they already have permission to access other files on that computer.

Nathan Van Buren, the petitioner in the case, is a former Georgia police officer who was charged under the Computer Fraud and Abuse Act (CFAA) after looking up a license plate for an acquaintance. Van Buren claims that a lower court ruling which upheld his conviction could be taken to mean that “any ‘trivial breach’” of a computer system could be a federal crime.

The case’s scope appears to have broadened, addressing not just breaches, but how the CFAA itself can be interpreted. The question listed on SCOTUS briefs reads:

“Whether the evidence was sufficient to establish that petitioner, a police sergeant, exceeded his authorized access to a protected computer to obtain information for financial gain, in violation of 18 U.S.C. 1030(a)(2)(C) and (c)(2)(B)(i), when in exchange for a cash payment, he searched a confidential law-enforcement database for information about whether a particular person was an undercover police officer.”

The U.S., the respondent, argued the case is “poor vehicle” for examining whether the CFAA is too broad, and said in its brief that SCOTUS review isn’t even warranted.

In its brief, Voatz says that the CFAA does not need to be narrowed, and some breaches of computer systems are necessary. However, the firm argues that researchers looking into potential vulnerabilities should specifically check with the companies they are evaluating prior to doing so, and should only proceed with authorization from the companies.

“Bug bounty programs are highly effective,” Voatz wrote. “They are extremely widespread in the technology industry, and even outside that industry, one survey in 2019 reported that 42 percent of companies outside of the technology industry were running a crowdsourced cybersecurity program.”

The brief may come in response to another filed by a group of security researchers who argue the CFAA has indeed “been interpreted too broadly,” which is holding back computer security efforts. This brief criticizes Voatz among its other arguments.

Broad rules

Voatz has notably faced criticism from cybersecurity researchers, including by a team at MIT who published a report in February claiming Voatz had insufficient transparency and that its internal systems faced a number of vulnerabilities. Voatz has disputed the claims in the report. 

Trail of Bits, another cybersecurity firm tapped by Voatz to conduct an audit of its systems, confirmed the MIT researchers’ claims in a subsequent report.

Voatz has tussled directly with researchers as well. Late last year, U.S. Attorney Mike Stuart announced that the FBI was looking into “an unsuccessful attempted intrusion” into Voatz, which was likely caused by a University of Michigan student or students participating in a security course. 

In its brief, Voatz said the “students’ ill-advised activity” was reported to West Virginia officials because the company could not distinguish between their research and an actual hostile attack. 

“Regardless of the particulars, however, the West Virginia incident illustrates the harm caused by attacking, or ‘researching,’ critical infrastructure without proper access or authorization especially in the middle of an election,” Voatz wrote.

Non-malicious researchers trying to break into digital tools “imposes significant additional costs” to organizations, the legal brief said, and could harm public confidence.

Jake Williams, who founded Rendition Security, told CNET that a “vast majority” of cybersecurity researchers likely do not have authorization, meaning Voatz’s support for a broad CFAA would “100% make it more difficult” for researchers.

Voatz’s brief comes a day after it published a press statement claiming the Michigan Democratic Party used its app during a recent party convention when voting for a number of positions. The Michigan Democratic Party did not immediately return a request for comment.

Contrary views

Voatz’s arguments aside, its brief makes a number of citations and claims which seem to lack context.

Voatz says it has been used in 70 elections, including state and municipal elections, and claims in the brief that it is considered “critical infrastructure” by the Department of Homeland Security.

The elections include West Virginia (which announced in March it would not be using Voatz for its upcoming elections) and Utah County (whose clerk and auditor received a $1,500 campaign donation from Overstock CEO Jonathan Johnson, who is also the president of Voatz investor Medici Ventures).

The company has said it’s meeting requirements by Pro V&V, a federal Voting System Test Laboratory, but according to Politico cybersecurity reporter Eric Geller, “the report is meaningless” because the standards were set years ago and the evaluation was not objective.

Eddie Perez, the global director of tech development at the Open Source Election Technology Institute, wrote that the Election Assistance Commission (EAC), the federal entity that accredited Pro V&V, doesn’t actually have any national standards for remote voting systems.

The EAC itself released a statement saying “these test reports should not be viewed as implicit approval by either the [voting system test laboratories] or the EAC that the evaluated systems are compliant with the [voluntary voting system guidelines] standard or are equivalent to an EAC-certified voting system.”

“Currently these programs are organized by Voatz itself, but in the past some were conducted through a vendor such as HackerOne Inc.,” the brief said. It did not mention that HackerOne severed ties with Voatz in March.

What’s more, HackerOne founder and CTO Alex Rice said on Twitter that “we support the opposing arguments made by” the Electronic Frontier Foundation (EFF), which calls for a narrowing of the CFAA, unlike Voatz, which cited HackerOne in the brief.

Similarly, Casey Ellis, founder and CTO of crowdsourced security platform Bugcrowd, which Voatz cited a number of times, also wrote that he signed off on and supported the EFF’s brief, and not Voatz’s.

Both Rice and Ellis said Voatz did not contact them prior to filing the brief.

Disclosure

The leader in blockchain news, CoinDesk is a media outlet that strives for the highest journalistic standards and abides by a strict set of editorial policies. CoinDesk is an independent operating subsidiary of Digital Currency Group, which invests in cryptocurrencies and blockchain startups.





Source link

Tags: CallsCourtCybersecurityIndependentResearchRestrictionsSupremeVoatz

Popular

Press Release

Knox Wire Uses Distributed Ledger Technology to Improve Real-Time Gross Settlement Service

by admin
March 26, 2022
0

Blockchain technology has infiltrated every industry in recent years, making them safer and more effective. Now, it has reached the...

Read more

Elimobile Launches the First Tokenized Telco, Partners with Elite Token to Create a Celebrity Powered Ecosystem

May 16, 2022

Users of "Fitcoin", A Mobile Fitness App, Are Rewarded for Staying Fit

May 16, 2022

Brainwashing! The hot music of tiktok was released by VOOPOO!

May 17, 2022

Crypto payment solution provider Fat Cat Killer is launching its token “Killer” on May 17, 2022

May 17, 2022

About

We publish a comprehensive news feed covering all news relevant to the crypto user, covering main industry news, politics and regulation as well as consumer-level “news you can use” (practical stuff), including handy DIY tips, links to useful tools, unbiased reviews and opinions revolving around cryptocurrency. Simple logic and real-world examples are preferred before technical jargon and personal rants.

Follow us

Categories

  • Altcoin
  • Bitcoin
  • Blockchain
  • Cryptocurrency
  • Ethereum
  • Litecoin
  • Market
  • Press Release
  • Regulation
  • Uncategorized

Recent Posts

  • Heroes of NFT Unveils its First Collectible NFT Card Game on Avalanche
  • Solidproof Delivers New and Efficient Auditing Solutions
  • Stoned Apes Crew to Unleash Nuked Apes Collection NFTs
  • Porta Network Successfully Launches Relay Chain Testnet
  • About Us
  • Privacy Policy
  • Contact Us

© 2020 cryptounfold.org

No Result
View All Result
  • Home
  • Bitcoin
  • Ethereum
  • Cryptocurrency
    • Altcoin
    • Litecoin
  • Blockchain
  • Regulation
  • Market
  • Prices
  • ICO

© 2020 cryptounfold.org

  • MMS Cash TokenMMS Cash Token(MCASH)$1.000.00%
  • bitcoinBitcoin(BTC)$49,095.002.28%
  • ethereumEthereum(ETH)$3,384.05-0.62%
  • HEXHEX(HEX)$0.1290085.45%
  • cardanoCardano(ADA)$2.18-2.77%
  • tetherTether(USDT)$1.00-0.27%
  • binancecoinBinance Coin(BNB)$425.46-0.83%
  • SolanaSolana(SOL)$166.52-1.81%
  • rippleXRP(XRP)$1.04-1.73%
  • usd-coinUSD Coin(USDC)$1.000.74%