• About Us
  • Privacy Policy
  • Contact Us
Coinpress
No Result
View All Result
  • Home
  • Bitcoin
  • Ethereum
  • Cryptocurrency
    • Altcoin
    • Litecoin
  • Blockchain
  • Regulation
  • Market
  • Prices
  • ICO
  • Home
  • Bitcoin
  • Ethereum
  • Cryptocurrency
    • Altcoin
    • Litecoin
  • Blockchain
  • Regulation
  • Market
  • Prices
  • ICO
No Result
View All Result
coinpress
No Result
View All Result
Home Blockchain

Voatz Calls for Restrictions on Independent Cybersecurity Research in Supreme Court Brief

by admin
September 4, 2020
in Blockchain
0
Voatz Calls for Restrictions on Independent Cybersecurity Research in Supreme Court Brief
0
SHARES
13
VIEWS
Share on FacebookShare on Twitter


Blockchain voting startup Voatz argued that bug bounty programs concerning cybersecurity should be operated under strict supervision in a “friend of the court” brief before the Supreme Court of the United States (SCOTUS).

Voatz weighed in Thursday on Van Buren v. United States, a Supreme Court case examining whether it is a federal crime for someone to access a computer “for an improper purpose” if they already have permission to access other files on that computer.

Nathan Van Buren, the petitioner in the case, is a former Georgia police officer who was charged under the Computer Fraud and Abuse Act (CFAA) after looking up a license plate for an acquaintance. Van Buren claims that a lower court ruling which upheld his conviction could be taken to mean that “any ‘trivial breach’” of a computer system could be a federal crime.

The case’s scope appears to have broadened, addressing not just breaches, but how the CFAA itself can be interpreted. The question listed on SCOTUS briefs reads:

“Whether the evidence was sufficient to establish that petitioner, a police sergeant, exceeded his authorized access to a protected computer to obtain information for financial gain, in violation of 18 U.S.C. 1030(a)(2)(C) and (c)(2)(B)(i), when in exchange for a cash payment, he searched a confidential law-enforcement database for information about whether a particular person was an undercover police officer.”

The U.S., the respondent, argued the case is “poor vehicle” for examining whether the CFAA is too broad, and said in its brief that SCOTUS review isn’t even warranted.

In its brief, Voatz says that the CFAA does not need to be narrowed, and some breaches of computer systems are necessary. However, the firm argues that researchers looking into potential vulnerabilities should specifically check with the companies they are evaluating prior to doing so, and should only proceed with authorization from the companies.

“Bug bounty programs are highly effective,” Voatz wrote. “They are extremely widespread in the technology industry, and even outside that industry, one survey in 2019 reported that 42 percent of companies outside of the technology industry were running a crowdsourced cybersecurity program.”

The brief may come in response to another filed by a group of security researchers who argue the CFAA has indeed “been interpreted too broadly,” which is holding back computer security efforts. This brief criticizes Voatz among its other arguments.

Broad rules

Voatz has notably faced criticism from cybersecurity researchers, including by a team at MIT who published a report in February claiming Voatz had insufficient transparency and that its internal systems faced a number of vulnerabilities. Voatz has disputed the claims in the report. 

Trail of Bits, another cybersecurity firm tapped by Voatz to conduct an audit of its systems, confirmed the MIT researchers’ claims in a subsequent report.

Voatz has tussled directly with researchers as well. Late last year, U.S. Attorney Mike Stuart announced that the FBI was looking into “an unsuccessful attempted intrusion” into Voatz, which was likely caused by a University of Michigan student or students participating in a security course. 

In its brief, Voatz said the “students’ ill-advised activity” was reported to West Virginia officials because the company could not distinguish between their research and an actual hostile attack. 

“Regardless of the particulars, however, the West Virginia incident illustrates the harm caused by attacking, or ‘researching,’ critical infrastructure without proper access or authorization especially in the middle of an election,” Voatz wrote.

Non-malicious researchers trying to break into digital tools “imposes significant additional costs” to organizations, the legal brief said, and could harm public confidence.

Jake Williams, who founded Rendition Security, told CNET that a “vast majority” of cybersecurity researchers likely do not have authorization, meaning Voatz’s support for a broad CFAA would “100% make it more difficult” for researchers.

Voatz’s brief comes a day after it published a press statement claiming the Michigan Democratic Party used its app during a recent party convention when voting for a number of positions. The Michigan Democratic Party did not immediately return a request for comment.

Contrary views

Voatz’s arguments aside, its brief makes a number of citations and claims which seem to lack context.

Voatz says it has been used in 70 elections, including state and municipal elections, and claims in the brief that it is considered “critical infrastructure” by the Department of Homeland Security.

The elections include West Virginia (which announced in March it would not be using Voatz for its upcoming elections) and Utah County (whose clerk and auditor received a $1,500 campaign donation from Overstock CEO Jonathan Johnson, who is also the president of Voatz investor Medici Ventures).

The company has said it’s meeting requirements by Pro V&V, a federal Voting System Test Laboratory, but according to Politico cybersecurity reporter Eric Geller, “the report is meaningless” because the standards were set years ago and the evaluation was not objective.

Eddie Perez, the global director of tech development at the Open Source Election Technology Institute, wrote that the Election Assistance Commission (EAC), the federal entity that accredited Pro V&V, doesn’t actually have any national standards for remote voting systems.

The EAC itself released a statement saying “these test reports should not be viewed as implicit approval by either the [voting system test laboratories] or the EAC that the evaluated systems are compliant with the [voluntary voting system guidelines] standard or are equivalent to an EAC-certified voting system.”

“Currently these programs are organized by Voatz itself, but in the past some were conducted through a vendor such as HackerOne Inc.,” the brief said. It did not mention that HackerOne severed ties with Voatz in March.

What’s more, HackerOne founder and CTO Alex Rice said on Twitter that “we support the opposing arguments made by” the Electronic Frontier Foundation (EFF), which calls for a narrowing of the CFAA, unlike Voatz, which cited HackerOne in the brief.

Similarly, Casey Ellis, founder and CTO of crowdsourced security platform Bugcrowd, which Voatz cited a number of times, also wrote that he signed off on and supported the EFF’s brief, and not Voatz’s.

Both Rice and Ellis said Voatz did not contact them prior to filing the brief.

Disclosure

The leader in blockchain news, CoinDesk is a media outlet that strives for the highest journalistic standards and abides by a strict set of editorial policies. CoinDesk is an independent operating subsidiary of Digital Currency Group, which invests in cryptocurrencies and blockchain startups.





Source link

READ ALSO

The FCA is Listening to the Crypto Community

Consensus 2022 Visitor Guide: Getting Down With DAOs

Tags: CallsCourtCybersecurityIndependentResearchRestrictionsSupremeVoatz

Related Posts

The FCA is Listening to the Crypto Community
Blockchain

The FCA is Listening to the Crypto Community

May 28, 2022
Consensus 2022 Visitor Guide: Getting Down With DAOs
Blockchain

Consensus 2022 Visitor Guide: Getting Down With DAOs

May 28, 2022
UK Crypto Hedge Fund Weathers Market Storm With Arbitrage Strategy
Blockchain

UK Crypto Hedge Fund Weathers Market Storm With Arbitrage Strategy

May 28, 2022
Thoughts From Davos
Blockchain

Thoughts From Davos

May 27, 2022
How the US Can Establish Itself as a Crypto Leader
Blockchain

How the US Can Establish Itself as a Crypto Leader

May 27, 2022
Who Are We in the Metaverse, and How Do We Prove It?
Blockchain

Who Are We in the Metaverse, and How Do We Prove It?

May 27, 2022

POPULAR NEWS

Be The First To Know About Ecoto

Be The First To Know About Ecoto

April 28, 2021
Chainlink to Start Supplying Data for Crypto.com’s DeFi Wallet

What You Should Know About GSX – The World’s First Growth Coin

October 6, 2020
Avalon-WM Review  – Where Every Online Trader Should Trade

Avalon-WM Review – Where Every Online Trader Should Trade

February 19, 2021
Ubisoft Launches Their First NFTs On Tezos

Ubisoft Launches Their First NFTs On Tezos

January 20, 2022

UAS: The Government Actually Delivering Prosperity to Africa

September 22, 2020

EDITOR'S PICK

India may disallow Indians from trading crypto on foreign exchanges

India may disallow Indians from trading crypto on foreign exchanges

December 7, 2021
Russian lawmaker proposes 15% tax on crypto miners

Russian lawmaker proposes 15% tax on crypto miners

February 7, 2022
CoolLaunch's Seed Sale Races Pass The Soft-Cap, As 73% Allotted Token Sells Off, IDO Launchpad MVP To Be Released Soon

Cardano IDO LaunchPad “Coollaunch” Seed Sale Continues to Flourish, 22% Tokens sells Off, IDO Launchpad MVP To Be Released.

May 21, 2022
Central Bank of Brazil Selects Partners to Assist With CBDC

Central Bank of Brazil Selects Partners to Assist With CBDC

March 3, 2022

About

We publish a comprehensive news feed covering all news relevant to the crypto user, covering main industry news, politics and regulation as well as consumer-level “news you can use” (practical stuff), including handy DIY tips, links to useful tools, unbiased reviews and opinions revolving around cryptocurrency. Simple logic and real-world examples are preferred before technical jargon and personal rants.

Follow us

Categories

  • Altcoin
  • Bitcoin
  • Blockchain
  • Cryptocurrency
  • Ethereum
  • Litecoin
  • Market
  • Press Release
  • Regulation
  • Uncategorized

Recent Posts

  • CoinAgenda Launches NiftyAgenda with NFT Gallery Showing and Performance by Pink Floyd’s Scott Page, at CES® AfterParty in Las Vegas
  • NFT Art Museums Are a Good Idea
  • ASTATE – THE INTERSECTION OF INNOVATION, BLOCKCHAIN AND VIRTUAL REALITY
  • KikSwap.com is not another meme token, A cross chain multi staking and spot trading platform on Binance smart chain
  • About Us
  • Privacy Policy
  • Contact Us

© 2020 coinpress.media

No Result
View All Result
  • Home
  • Bitcoin
  • Ethereum
  • Cryptocurrency
    • Altcoin
    • Litecoin
  • Blockchain
  • Regulation
  • Market
  • Prices
  • ICO

© 2020 coinpress.media