Trust in the digital world depends on the security and integrity of data. CDT works to promote democratic values in cybersecurity measures taken in a variety of contexts.
To counter cyberthreats, companies often need to share cyberthreat information among themselves and with governmental entities. This sharing should protect the privacy of personally identifiable information and prohibit the re-purposing of shared information for reasons other than cybersecurity — especially when information is shared with a governmental entity.
CDT promotes the fixing of vulnerabilities in voting systems and in other critical infrastructure. However, it is important to recognize that the evidentiary record does not support claims that recent elections have been “rigged” because those vulnerabilities were exploited.
Independent security researchers play a key role in securing systems and their work should be protected and promoted. CDT encourages companies to offer “bug bounty” programs that reward security researchers who lawfully find security vulnerabilities and notify the company to them so they can be patched before the vulnerability is disclosed to the public.
Likewise, when a governmental entity engaging in surveillance discovers a security vulnerability in a company’s information system, it should generally notify the company promptly so the vulnerability can be patched and its users and data protected against exploit. Any national security exception to this general rule should be both narrow and rare. Vulnerability equities processes should be transparent to the public to promote compliance with notification requirements.
Latest Insights
India’s New Cybersecurity Order Drives VPN Providers to Leave, Chilling Speech and Subjecting More Indians to Government Surveillance
CDT Joins Dozens of Orgs & Cybersecurity Experts on Letter Expressing Concerns with UK’s Online Safety Bill
Proposed Administrative Subpoenas for Cybersecurity Vulnerabilities
Tech Talk: Teaching Data Ethics and Defending Nonprofits Against Cyber Attacks
DOJ Writes to Copyright Office: Security Research is Cool.