{"id":1175,"date":"2017-05-17T07:31:56","date_gmt":"2017-05-17T15:31:56","guid":{"rendered":"https:\/\/blog.mozilla.org\/netpolicy\/?p=1175"},"modified":"2017-05-17T07:31:56","modified_gmt":"2017-05-17T15:31:56","slug":"working-together-towards-secure-internet-vep-reform","status":"publish","type":"post","link":"https:\/\/blog.mozilla.org\/netpolicy\/2017\/05\/17\/working-together-towards-secure-internet-vep-reform\/","title":{"rendered":"Working Together Towards a more Secure Internet through VEP Reform"},"content":{"rendered":"<p>Today, Mozilla <a href=\"https:\/\/blog.mozilla.org\/wp-content\/uploads\/2017\/05\/Mozilla-PATCHActSupport.pdf\">sent a letter to Congress<\/a> expressing support for an important bill has just been introduced: the Protecting Our Ability to Counter Hacking Act (PATCH Act). You can read more in <a href=\"https:\/\/blog.mozilla.org\/blog\/2017\/05\/17\/improving-internet-security-vulnerability-disclosure\/\">this post from Denelle Dixon<\/a>.<\/p>\n<p>This bill focuses on a relatively unknown, but critical, piece of the U.S. government&#8217;s responsibility to secure our internet infrastructure: the Vulnerabilities Equities Process (VEP). The VEP is the government\u2019s process for reviewing and coordinating the disclosure of vulnerabilities to folks who write code &#8211; like us &#8211; who can fix them in the software and hardware we all use (you can learn more about what we know <a href=\"https:\/\/blog.mozilla.org\/press\/files\/2017\/05\/VEP-WhatWeKnow.pdf\">here<\/a>). However, the VEP is not codified in law, and lacks transparency and reporting on both the process policymakers follow and the considerations they take into account. The PATCH Act would address these gaps.<\/p>\n<p>The cyberattack over the last week &#8211; using the WannaCry exploit from the latest Shadow Brokers release, and exploiting unpatched Windows computers &#8211; only emphasizes the need to work together and make sure that we\u2019re all as secure as we can be. As we said <a href=\"https:\/\/blog.mozilla.org\/blog\/2017\/05\/15\/wannacry-cry-vep-reform\/\">earlier this week<\/a>, these exploits might have been shared with Microsoft by the NSA &#8211; and that would be the right way to handle an exploit like this. If the government has exploits that have been compromised, they must disclose them to software companies before they can be used widely putting users at risk. The lack of transparency around the government\u2019s decision-making processes points to the importance of codifying and improving the Vulnerabilities Equities Process.<\/p>\n<p>We\u2019ve said <a href=\"https:\/\/blog.mozilla.org\/blog\/2016\/09\/13\/cybersecurity-is-a-shared-responsibility\/\">before<\/a> &#8211; many times &#8211; how important it is to work together to protect cybersecurity. Reforming the VEP is <a href=\"https:\/\/blog.mozilla.org\/netpolicy\/2016\/09\/19\/improving-government-disclosure-of-security-vulnerabilities\/\">one key component<\/a> of that shared responsibility, ensuring that the U.S. government shares vulnerabilities that put swaths of the internet at risk. The process was conceived in 2010 to improve our collective cybersecurity, and implemented in 2014 after the Heartbleed vulnerability put most of the internet at risk (for more information, take a look at <a href=\"https:\/\/blog.mozilla.org\/press\/files\/2017\/05\/VEP-History.pdf\">this timeline<\/a>). It\u2019s time to take the next step and put this process into statute.<\/p>\n<p>Last year, we wrote about five important reforms to the VEP we believe are necessary:<\/p>\n<ul>\n<li>All security vulnerabilities should go through the VEP.<\/li>\n<li>All relevant federal agencies involved in the VEP should work together using a standard set of criteria to ensure all risks and interests are considered.<\/li>\n<li>Independent oversight and transparency into the processes and procedures of the VEP must be created.<\/li>\n<li>The VEP should be placed within the Department of Homeland Security (DHS), with their expertise in existing coordinated vulnerability disclosure programs.<\/li>\n<li>The VEP should be codified in law to ensure compliance and permanence.<\/li>\n<\/ul>\n<p>Over the last year, we have seen many instances where hacking tools from the U.S. government have been posted online, and then used &#8211; by unknown adversaries &#8211; to attack users. Some of these included \u201czero days\u201d, which left companies scrambling to patch their software and protect their users, without prior notice. It\u2019s important that the government defaults to disclosing vulnerabilities, rather than hoarding them in case they become useful later. We hope they will instead work with technology companies to help protect all of us online.<\/p>\n<p>The PATCH Act &#8211; introduced by Sen. Gardner, Sen. Johnson, Sen. Schatz, Rep. Farenthold, and Rep. Lieu &#8211; aims to codify and make the existing Vulnerabilities Equities Process more transparent. It\u2019s relatively simple &#8211; a good thing, when it comes to legislation: it creates a VEP Board, housed at DHS, which will consider disclosure of vulnerabilities that some part of the government knows about. The VEP Board would make public the process and criteria they use to balance the relevant interests and risks &#8211; an important step &#8211; and publish reporting around the process. These reports would allow the public to consider whether the process is working well, without sharing classified information (saving that reporting for the relevant oversight entities). This would also make it easier to disclose vulnerabilities through DHS\u2019 existing channels.<\/p>\n<p>Mozilla looks forward to working with members of Congress on this bill, as well as others interested in VEP reform &#8211; and all the other government actors, in the U.S. and around the world, who seek to take action that would improve the security of the internet. We stand with you, ready to defend the security of the internet and its users.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Today, Mozilla sent a letter to Congress expressing support for an important bill has just been introduced: the Protecting Our Ability to Counter Hacking Act (PATCH Act). You can read &hellip; <a class=\"go\" href=\"https:\/\/blog.mozilla.org\/netpolicy\/2017\/05\/17\/working-together-towards-secure-internet-vep-reform\/\">Read more<\/a><\/p>\n","protected":false},"author":1273,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[283198,10137,847,69,141519,46877],"tags":[],"coauthors":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v22.5 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Working Together Towards a more Secure Internet through VEP Reform - Open Policy &amp; Advocacy<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/blog.mozilla.org\/netpolicy\/2017\/05\/17\/working-together-towards-secure-internet-vep-reform\/\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Heather West\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/blog.mozilla.org\/netpolicy\/2017\/05\/17\/working-together-towards-secure-internet-vep-reform\/\",\"url\":\"https:\/\/blog.mozilla.org\/netpolicy\/2017\/05\/17\/working-together-towards-secure-internet-vep-reform\/\",\"name\":\"Working Together Towards a more Secure Internet through VEP Reform - Open Policy &amp; Advocacy\",\"isPartOf\":{\"@id\":\"https:\/\/blog.mozilla.org\/netpolicy\/#website\"},\"datePublished\":\"2017-05-17T15:31:56+00:00\",\"dateModified\":\"2017-05-17T15:31:56+00:00\",\"author\":{\"@id\":\"https:\/\/blog.mozilla.org\/netpolicy\/#\/schema\/person\/fdff0d5bb50c4a81e2743d7f91775d40\"},\"breadcrumb\":{\"@id\":\"https:\/\/blog.mozilla.org\/netpolicy\/2017\/05\/17\/working-together-towards-secure-internet-vep-reform\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/blog.mozilla.org\/netpolicy\/2017\/05\/17\/working-together-towards-secure-internet-vep-reform\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/blog.mozilla.org\/netpolicy\/2017\/05\/17\/working-together-towards-secure-internet-vep-reform\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/blog.mozilla.org\/netpolicy\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Working Together Towards a more Secure Internet through VEP Reform\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/blog.mozilla.org\/netpolicy\/#website\",\"url\":\"https:\/\/blog.mozilla.org\/netpolicy\/\",\"name\":\"Open Policy &amp; Advocacy\",\"description\":\"Mozilla&#039;s official blog on open Internet policy initiatives and developments\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/blog.mozilla.org\/netpolicy\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/blog.mozilla.org\/netpolicy\/#\/schema\/person\/fdff0d5bb50c4a81e2743d7f91775d40\",\"name\":\"Heather West\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/blog.mozilla.org\/netpolicy\/#\/schema\/person\/image\/473697387e4dd4394de2baac8badd43c\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/1cc029c6538a1898f71b01b401691323?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/1cc029c6538a1898f71b01b401691323?s=96&d=mm&r=g\",\"caption\":\"Heather West\"},\"description\":\"Heather works on security, cybersecurity, data governance, and privacy in the digital age at Mozilla, maker of the Firefox browser. At the intersection of public policy and technology, she is part policy-to-tech translator, part product consultant, and part long-term Internet strategist. She works with stakeholders and policymakers in DC as well as global product and policy teams and was recognized as one of the 2014 Forbes 30 Under 30 in Law and Policy. She helped found the public policy team at CloudFlare, a website performance and security company, served as global and Federal privacy and security issue expert on Google\u2019s public policy team, and started her career working on government technology, privacy, and identity management at the public interest group Center for Democracy and Technology. She holds a B.A. in Computer Science and Cognitive Science from Wellesley College with concentrations in philosophy and legal studies, and is a Certified Information Privacy Professional (CIPP\/US). She is also recognized as a Christian Science Monitor Passcode Influencer.\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Working Together Towards a more Secure Internet through VEP Reform - Open Policy &amp; Advocacy","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/blog.mozilla.org\/netpolicy\/2017\/05\/17\/working-together-towards-secure-internet-vep-reform\/","twitter_misc":{"Written by":"Heather West","Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/blog.mozilla.org\/netpolicy\/2017\/05\/17\/working-together-towards-secure-internet-vep-reform\/","url":"https:\/\/blog.mozilla.org\/netpolicy\/2017\/05\/17\/working-together-towards-secure-internet-vep-reform\/","name":"Working Together Towards a more Secure Internet through VEP Reform - Open Policy &amp; Advocacy","isPartOf":{"@id":"https:\/\/blog.mozilla.org\/netpolicy\/#website"},"datePublished":"2017-05-17T15:31:56+00:00","dateModified":"2017-05-17T15:31:56+00:00","author":{"@id":"https:\/\/blog.mozilla.org\/netpolicy\/#\/schema\/person\/fdff0d5bb50c4a81e2743d7f91775d40"},"breadcrumb":{"@id":"https:\/\/blog.mozilla.org\/netpolicy\/2017\/05\/17\/working-together-towards-secure-internet-vep-reform\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/blog.mozilla.org\/netpolicy\/2017\/05\/17\/working-together-towards-secure-internet-vep-reform\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/blog.mozilla.org\/netpolicy\/2017\/05\/17\/working-together-towards-secure-internet-vep-reform\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/blog.mozilla.org\/netpolicy\/"},{"@type":"ListItem","position":2,"name":"Working Together Towards a more Secure Internet through VEP Reform"}]},{"@type":"WebSite","@id":"https:\/\/blog.mozilla.org\/netpolicy\/#website","url":"https:\/\/blog.mozilla.org\/netpolicy\/","name":"Open Policy &amp; Advocacy","description":"Mozilla&#039;s official blog on open Internet policy initiatives and developments","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/blog.mozilla.org\/netpolicy\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/blog.mozilla.org\/netpolicy\/#\/schema\/person\/fdff0d5bb50c4a81e2743d7f91775d40","name":"Heather West","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/blog.mozilla.org\/netpolicy\/#\/schema\/person\/image\/473697387e4dd4394de2baac8badd43c","url":"https:\/\/secure.gravatar.com\/avatar\/1cc029c6538a1898f71b01b401691323?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/1cc029c6538a1898f71b01b401691323?s=96&d=mm&r=g","caption":"Heather West"},"description":"Heather works on security, cybersecurity, data governance, and privacy in the digital age at Mozilla, maker of the Firefox browser. At the intersection of public policy and technology, she is part policy-to-tech translator, part product consultant, and part long-term Internet strategist. She works with stakeholders and policymakers in DC as well as global product and policy teams and was recognized as one of the 2014 Forbes 30 Under 30 in Law and Policy. She helped found the public policy team at CloudFlare, a website performance and security company, served as global and Federal privacy and security issue expert on Google\u2019s public policy team, and started her career working on government technology, privacy, and identity management at the public interest group Center for Democracy and Technology. She holds a B.A. in Computer Science and Cognitive Science from Wellesley College with concentrations in philosophy and legal studies, and is a Certified Information Privacy Professional (CIPP\/US). She is also recognized as a Christian Science Monitor Passcode Influencer."}]}},"_links":{"self":[{"href":"https:\/\/blog.mozilla.org\/netpolicy\/wp-json\/wp\/v2\/posts\/1175"}],"collection":[{"href":"https:\/\/blog.mozilla.org\/netpolicy\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.mozilla.org\/netpolicy\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.mozilla.org\/netpolicy\/wp-json\/wp\/v2\/users\/1273"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.mozilla.org\/netpolicy\/wp-json\/wp\/v2\/comments?post=1175"}],"version-history":[{"count":0,"href":"https:\/\/blog.mozilla.org\/netpolicy\/wp-json\/wp\/v2\/posts\/1175\/revisions"}],"wp:attachment":[{"href":"https:\/\/blog.mozilla.org\/netpolicy\/wp-json\/wp\/v2\/media?parent=1175"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.mozilla.org\/netpolicy\/wp-json\/wp\/v2\/categories?post=1175"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.mozilla.org\/netpolicy\/wp-json\/wp\/v2\/tags?post=1175"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/blog.mozilla.org\/netpolicy\/wp-json\/wp\/v2\/coauthors?post=1175"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}