Obama administration backs disclosing software vulnerabilities in most cases

The administration said information may be withheld for national security and law enforcement needs

The administration of U.S. President Barack Obama favors disclosing to the public vulnerabilities in commercial and open source software in the national interest, unless there is a national security or law enforcement need, the country's spy agency said.

The government was on Friday countering a news report that said the U.S. National Security Agency knew about the recently identified Heartbleed vulnerability for at least two years and had used it for surveillance purposes.

The administration said the NSA was not aware of Heartbleed until it was made public in a private sector cybersecurity report.

"When Federal agencies discover a new vulnerability in commercial and open source software -- a so-called 'Zero day' vulnerability because the developers of the vulnerable software have had zero days to fix it -- it is in the national interest to responsibly disclose the vulnerability rather than to hold it for an investigative or intelligence purpose," the Office of the Director of National Intelligence said in a statement Friday.

The ODNI statement added that the White House had reviewed its policies in response to the recommendations of the President's Review Group on Intelligence and Communications Technologies, set up to review the surveillance practices of the NSA.

Under an inter-agency process called the Vulnerabilities Equities Process, unless there is a clear national security or law enforcement need, the process is "biased toward responsibly disclosing such vulnerabilities," according to the spy agency.

One of the recommendations in December of the review group was that U.S. policy should ensure that zero-day vulnerabilities are quickly blocked and the underlying vulnerabilities are patched on U.S. government and other networks. The group allowed that in "rare instances," the policy of the government may briefly authorize using a zero-day flaw for intelligence collection after inter-agency review involving all relevant departments at a senior level.

Referring to allegations that the U.S. government introduced "backdoors" into commercially available software, enabling the decryption of apparently secure software, the review group said it was not aware of any such incidents, but advised that the US Government should make it clear that the NSA will not engineer vulnerabilities into "encryption algorithms that guard global commerce."

The Heartbleed vulnerability takes advantage of a problem in certain versions of OpenSSL, a set of encryption tools used for securing Web connections, and could allow a remote attacker to expose critical data such as user authentication credentials and secret keys.

Internet companies rushed to fix the problem, while the Canada Revenue Agency halted online filing of tax returns by the country's citizens as a preventive measure. The CRA's systems were restored on Sunday after applying a "patch" that addresses the vulnerability. "We could not allow these systems back online until we were fully confident they were safe and secure for Canadian taxpayers," said CRA Commissioner Andrew Treusch in a statement. The U.S. Internal Revenue Service said it continued to accept tax returns ahead of an April 15 deadline, as its systems were not affected by Heartbleed

John Ribeiro covers outsourcing and general technology breaking news from India for The IDG News Service. Follow John on Twitter at @Johnribeiro. John's e-mail address is john_ribeiro@idg.com

Join the PC World newsletter!

Error: Please check your email address.

Tags Office of the Director of National IntelligencesecurityU.S. National Security Agencyinternetgovernment

Our Back to Business guide highlights the best products for you to boost your productivity at home, on the road, at the office, or in the classroom.

Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.

John Ribeiro

IDG News Service
Show Comments

Essentials

Lexar® JumpDrive® S57 USB 3.0 flash drive

Learn more >

Microsoft L5V-00027 Sculpt Ergonomic Keyboard Desktop

Learn more >

Mobile

Lexar® JumpDrive® S45 USB 3.0 flash drive 

Learn more >

Exec

Lexar® JumpDrive® C20c USB Type-C flash drive 

Learn more >

Lexar® Professional 1800x microSDHC™/microSDXC™ UHS-II cards 

Learn more >

Audio-Technica ATH-ANC70 Noise Cancelling Headphones

Learn more >

HD Pan/Tilt Wi-Fi Camera with Night Vision NC450

Learn more >

Budget

Back To Business Guide

Click for more ›

Most Popular Reviews

Latest News Articles

Resources

PCW Evaluation Team

Michael Hargreaves

Windows 10 for Business / Dell XPS

I’d happily recommend this touchscreen laptop and Windows 10 as a great way to get serious work done at a desk or on the road.

Aysha Strobbe

Windows 10 / HP Spectre

Ultimately, I think the Windows 10 environment is excellent for me as it caters for so many different uses. The inclusion of the Xbox app is also great for when you need some downtime too!

Mark Escubio

Windows 10 / Lenovo Yoga

For me, the Xbox Play Anywhere is a great new feature as it allows you to play your current Xbox games with higher resolutions and better graphics without forking out extra cash for another copy. Although available titles are still scarce, but I’m sure it will grow in time.

Kathy Cassidy

STYLISTIC Q702

First impression on unpacking the Q702 test unit was the solid feel and clean, minimalist styling.

Anthony Grifoni

STYLISTIC Q572

For work use, Microsoft Word and Excel programs pre-installed on the device are adequate for preparing short documents.

Featured Content

Latest Jobs

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?