Here’s What the White House Needs to Disclose about its Vulnerabilities Process This Month
Originally posted on New York University School of Law’s Just Security
At a series of events earlier this month, White House Cybersecurity Coordinator Rob Joyce announced that he is preparing to release more information about the Vulnerabilities Equities Process (VEP). Happy Cybersecurity Awareness Month, everybody!
As we’ve discussed before, the VEP is a complicated yet important process that determines whether the government will notify a digital-technology company about a cybersecurity flaw in its product or service, or choose not to disclose the flaw and use it for later hacking or intelligence-gathering purposes. We argued that a legislative solution—not just a less formal interagency review—is needed to govern this high-stakes process, which will have repercussions for cybersecurity, privacy, access to information, and our economic competitiveness. We’ve also argued that much more information about this process should be released to the public.
Joyce’s announcement of the White House’s planned voluntary release of information is a welcome development, and Joyce has said in the past that he is generally pleased with how the current interagency process works. He indicated in his statements earlier this month that the public should expect at least a “charter” (which we take to be a more formal statement of the principles that underlie the process), as well as some basic statistics about how the VEP has been applied up to now to disclose (or delay disclosing) vulnerabilities.
Since the point of the release is to demonstrate the legitimacy and success of the program, we’ve compiled a “punch list” of the types of information we believe the White House should commit to share:
CDT-led Coalition Calls for Transparency for White House AI Framework
CDT and Americans for Responsible Innovation led a broad, bipartisan coalition of over two dozen civil society groups in calling on the White House to release its Framework for review of frontier AI models.
CDT Amicus Brief Calls on Fourth Circuit to Rein In Geofence Warrants
Earlier this year the Supreme Court ruled in Chatrie v United States that the Fourth Amendment protected all cell phone location information, which CDT lauded as a landmark decision, but sent the case back down to the Fourth Circuit to assess the propriety of the geofence warrant at issue.
CDT and Partners Post Floor Alert Opposing CA SB 1013 Automated License Plate Readers Bill
The best way to ensure that Automated License Plate Readers are not abused is to limit the retention of stored data and to keep loopholes to lawful process closed. CA SB 1013 is a step in the wrong direction, and we urge the California legislature to reject this approach.
British Public Oppose Secret Surveillance Powers and Want Strong Protections for Encrypted Communications
CDT released nationally representative polling data revealing that a the British public are broadly concerned about the security, privacy, and free speech consequences of allowing law enforcement to access encrypted communications.