• Home
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • XRP
    • Litecoin
    • Altcoin
    • Cardano
    • Tether
    • DOGE
    • Solano
    • XLM
    • DOT
    • XDC
    • SHIBA
    • BNB
    • Ape
    • HBAR
    • QNT
  • Blockchain
  • Regulation
  • Market
  • Live
    • Prices
    • ICO
  • Meta
    • NFT
  • Technical Analysis
    • XRP
    • BTC
    • XLM
    • ADA
    • TETHER
    • ETC
    • ETH
    • DOGE
    • LTC
  • Exchange
  • Mining
Tuesday, May 30, 2023
  • Login
  • Register
Coin24h.com
  • Home
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • XRP
    • Litecoin
    • Altcoin
    • Cardano
    • Tether
    • DOGE
    • Solano
    • XLM
    • DOT
    • XDC
    • SHIBA
    • BNB
    • Ape
    • HBAR
    • QNT
  • Blockchain
  • Regulation
  • Market
  • Live
    • Prices
    • ICO
  • Meta
    • NFT
  • Technical Analysis
    • XRP
    • BTC
    • XLM
    • ADA
    • TETHER
    • ETC
    • ETH
    • DOGE
    • LTC
  • Exchange
  • Mining
No Result
View All Result
  • Home
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • XRP
    • Litecoin
    • Altcoin
    • Cardano
    • Tether
    • DOGE
    • Solano
    • XLM
    • DOT
    • XDC
    • SHIBA
    • BNB
    • Ape
    • HBAR
    • QNT
  • Blockchain
  • Regulation
  • Market
  • Live
    • Prices
    • ICO
  • Meta
    • NFT
  • Technical Analysis
    • XRP
    • BTC
    • XLM
    • ADA
    • TETHER
    • ETC
    • ETH
    • DOGE
    • LTC
  • Exchange
  • Mining
No Result
View All Result
Coin24h.com
No Result
View All Result
Ledger Nano X - The secure hardware wallet
ADVERTISEMENT

Voatz Calls for Restrictions on Independent Cybersecurity Research in Supreme Court Brief

4 September 2020
in Blockchain
Reading Time: 5 mins read
A A
0
189
SHARES
1.5k
VIEWS
Share on FacebookShare on Twitter
cryptotrader
ADVERTISEMENT


Blockchain voting startup Voatz argued that bug bounty programs concerning cybersecurity should be operated under strict supervision in a “friend of the court” brief before the Supreme Court of the United States (SCOTUS).

Voatz weighed in Thursday on Van Buren v. United States, a Supreme Court case examining whether it is a federal crime for someone to access a computer “for an improper purpose” if they already have permission to access other files on that computer.

Nathan Van Buren, the petitioner in the case, is a former Georgia police officer who was charged under the Computer Fraud and Abuse Act (CFAA) after looking up a license plate for an acquaintance. Van Buren claims that a lower court ruling which upheld his conviction could be taken to mean that “any ‘trivial breach’” of a computer system could be a federal crime.

The case’s scope appears to have broadened, addressing not just breaches, but how the CFAA itself can be interpreted. The question listed on SCOTUS briefs reads:

“Whether the evidence was sufficient to establish that petitioner, a police sergeant, exceeded his authorized access to a protected computer to obtain information for financial gain, in violation of 18 U.S.C. 1030(a)(2)(C) and (c)(2)(B)(i), when in exchange for a cash payment, he searched a confidential law-enforcement database for information about whether a particular person was an undercover police officer.”

The U.S., the respondent, argued the case is “poor vehicle” for examining whether the CFAA is too broad, and said in its brief that SCOTUS review isn’t even warranted.

In its brief, Voatz says that the CFAA does not need to be narrowed, and some breaches of computer systems are necessary. However, the firm argues that researchers looking into potential vulnerabilities should specifically check with the companies they are evaluating prior to doing so, and should only proceed with authorization from the companies.

“Bug bounty programs are highly effective,” Voatz wrote. “They are extremely widespread in the technology industry, and even outside that industry, one survey in 2019 reported that 42 percent of companies outside of the technology industry were running a crowdsourced cybersecurity program.”

The brief may come in response to another filed by a group of security researchers who argue the CFAA has indeed “been interpreted too broadly,” which is holding back computer security efforts. This brief criticizes Voatz among its other arguments.

Broad rules

Voatz has notably faced criticism from cybersecurity researchers, including by a team at MIT who published a report in February claiming Voatz had insufficient transparency and that its internal systems faced a number of vulnerabilities. Voatz has disputed the claims in the report. 

Trail of Bits, another cybersecurity firm tapped by Voatz to conduct an audit of its systems, confirmed the MIT researchers’ claims in a subsequent report.

Voatz has tussled directly with researchers as well. Late last year, U.S. Attorney Mike Stuart announced that the FBI was looking into “an unsuccessful attempted intrusion” into Voatz, which was likely caused by a University of Michigan student or students participating in a security course. 

In its brief, Voatz said the “students’ ill-advised activity” was reported to West Virginia officials because the company could not distinguish between their research and an actual hostile attack. 

“Regardless of the particulars, however, the West Virginia incident illustrates the harm caused by attacking, or ‘researching,’ critical infrastructure without proper access or authorization especially in the middle of an election,” Voatz wrote.

Non-malicious researchers trying to break into digital tools “imposes significant additional costs” to organizations, the legal brief said, and could harm public confidence.

Jake Williams, who founded Rendition Security, told CNET that a “vast majority” of cybersecurity researchers likely do not have authorization, meaning Voatz’s support for a broad CFAA would “100% make it more difficult” for researchers.

Voatz’s brief comes a day after it published a press statement claiming the Michigan Democratic Party used its app during a recent party convention when voting for a number of positions. The Michigan Democratic Party did not immediately return a request for comment.

Contrary views

Voatz’s arguments aside, its brief makes a number of citations and claims which seem to lack context.

Voatz says it has been used in 70 elections, including state and municipal elections, and claims in the brief that it is considered “critical infrastructure” by the Department of Homeland Security.

The elections include West Virginia (which announced in March it would not be using Voatz for its upcoming elections) and Utah County (whose clerk and auditor received a $1,500 campaign donation from Overstock CEO Jonathan Johnson, who is also the president of Voatz investor Medici Ventures).

The company has said it’s meeting requirements by Pro V&V, a federal Voting System Test Laboratory, but according to Politico cybersecurity reporter Eric Geller, “the report is meaningless” because the standards were set years ago and the evaluation was not objective.

Eddie Perez, the global director of tech development at the Open Source Election Technology Institute, wrote that the Election Assistance Commission (EAC), the federal entity that accredited Pro V&V, doesn’t actually have any national standards for remote voting systems.

The EAC itself released a statement saying “these test reports should not be viewed as implicit approval by either the [voting system test laboratories] or the EAC that the evaluated systems are compliant with the [voluntary voting system guidelines] standard or are equivalent to an EAC-certified voting system.”

“Currently these programs are organized by Voatz itself, but in the past some were conducted through a vendor such as HackerOne Inc.,” the brief said. It did not mention that HackerOne severed ties with Voatz in March.

What’s more, HackerOne founder and CTO Alex Rice said on Twitter that “we support the opposing arguments made by” the Electronic Frontier Foundation (EFF), which calls for a narrowing of the CFAA, unlike Voatz, which cited HackerOne in the brief.

Similarly, Casey Ellis, founder and CTO of crowdsourced security platform Bugcrowd, which Voatz cited a number of times, also wrote that he signed off on and supported the EFF’s brief, and not Voatz’s.

Both Rice and Ellis said Voatz did not contact them prior to filing the brief.

Disclosure

The leader in blockchain news, CoinDesk is a media outlet that strives for the highest journalistic standards and abides by a strict set of editorial policies. CoinDesk is an independent operating subsidiary of Digital Currency Group, which invests in cryptocurrencies and blockchain startups.





Source link

Related articles

Crypto Storage Firm Qredo's Revamped Self-Custody Wallet Goes Live

Crypto Storage Firm Qredo's Revamped Self-Custody Wallet Goes Live

30 May 2023
Bitcoin (BTC) Headed for First Monthly Loss Since December 2022

Bitcoin (BTC) Headed for First Monthly Loss Since December 2022

30 May 2023
Cryptohopper
ADVERTISEMENT
[crypto-donation-box]
Tags: callscourtCybersecurityIndependentResearchRestrictionsSupremeVoatz
Share76Tweet47
Ledger Nano X - The secure hardware wallet
Previous Post

XRP: The Cryptocurrency I Am Most Bullish On And Why Ripple Makes This An Extraordinary Opportunity – Seeking Alpha

Next Post

$0.22: Ripple (XRP) Bears Aim Big After Recent Slide Below $0.25

Related Posts

Crypto Storage Firm Qredo's Revamped Self-Custody Wallet Goes Live

Crypto Storage Firm Qredo's Revamped Self-Custody Wallet Goes Live

30 May 2023
0

The New Qredo remains aimed at the institutional crypto market, but now it's low-cost and open to anyone, says COO...

Bitcoin (BTC) Headed for First Monthly Loss Since December 2022

Bitcoin (BTC) Headed for First Monthly Loss Since December 2022

30 May 2023
0

The leading cryptocurrency by market value traded near $27,800 at press time, a 7.5% rise from lows under $25,900 registered...

Optimism Token (OP) Prices Slide 7% Ahead of $580M OP Unlock, Doubling Token Supply

Optimism Token (OP) Prices Slide 7% Ahead of $580M OP Unlock, Doubling Token Supply

30 May 2023
0

Early investors are likely sitting on significant gains and could choose to take profits, contributing to immense selling pressure. As...

Bitcoin's Short-Term Holders Are Again Selling at Profit

Bitcoin's Short-Term Holders Are Again Selling at Profit

29 May 2023
0

Short-term holders' renewed profitability is a positive signal for near-term price action, according to on observer. Source link

Arbitrum Based Jimbos Protocol Scurries for Revival After $7M Exploit

Arbitrum Based Jimbos Protocol Scurries for Revival After $7M Exploit

29 May 2023
0

Version 2 of Jimbos protocol was attacked over the weekend for $7.3 million, just days after going live. Source link

Load More
Next Post

$0.22: Ripple (XRP) Bears Aim Big After Recent Slide Below $0.25

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

We publish a comprehensive news feed covering all news relevant to the crypto user, covering main industry news, politics and regulation as well as consumer-level “news you can use” (practical stuff), including handy DIY tips, links to useful tools, unbiased reviews and opinions revolving around cryptocurrency. Simple logic and real-world examples are preferred before technical jargon and personal rants.

Categories

  • Altcoin
  • ApeCoin
  • Bitcoin
  • Blockchain
  • BNB
  • Cardano
  • Cryptocurrency
  • DOGE
  • DOT
  • Ethereum
  • HBAR
  • Litecoin
  • Market
  • Meta News
  • Mining
  • NFT
  • QNT
  • Regulation
  • SHIBA
  • Solano
  • Tether
  • Uncategorized
  • XDC
  • XLM
  • XRP

What’s New Here!

  • What do the Long-Term Technicals Predict for Solana (SOL) Tuesday?
  • Is Polygon a Good Crypto to Buy? Dogecoin Down 3% as Big Eyes Coin Counts Days Until Presale End
  • Stronghold Digital Mining Reaches Hash Rate Milestone of 3.0 EH/s

Newsletter

  • About Us
  • Privacy Policy
  • Contact Us

© 2022 coin24h.com

No Result
View All Result
  • Home
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • XRP
    • Litecoin
    • Altcoin
    • Cardano
    • Tether
    • DOGE
    • Solano
    • XLM
    • DOT
    • XDC
    • SHIBA
    • BNB
    • Ape
    • HBAR
    • QNT
  • Blockchain
  • Regulation
  • Market
  • Live
    • Prices
    • ICO
  • Meta
    • NFT
  • Technical Analysis
    • XRP
    • BTC
    • XLM
    • ADA
    • TETHER
    • ETC
    • ETH
    • DOGE
    • LTC
  • Exchange
  • Mining

© 2020 coin24h.com

Welcome Back!

Login to your account below

Forgotten Password? Sign Up

Create New Account!

Fill the forms below to register

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In
  • bitcoinBitcoin(BTC)$28,003.000.37%
  • ethereumEthereum(ETH)$1,914.240.56%
  • tetherTether(USDT)$1.000.13%
  • binancecoinBNB(BNB)$314.250.12%
  • usd-coinUSD Coin(USDC)$1.000.06%
  • rippleXRP(XRP)$0.505.09%
  • cardanoCardano(ADA)$0.3830630.97%
  • staked-etherLido Staked Ether(STETH)$1,911.760.51%
  • dogecoinDogecoin(DOGE)$0.0734870.34%
  • matic-networkPolygon(MATIC)$0.91-1.61%
  • solanaSolana(SOL)$21.302.89%
  • tronTRON(TRX)$0.076961-0.77%
  • polkadotPolkadot(DOT)$5.500.55%
  • litecoinLitecoin(LTC)$93.201.90%
  • binance-usdBinance USD(BUSD)$1.00-0.05%
  • shiba-inuShiba Inu(SHIB)$0.000009-0.40%
  • avalanche-2Avalanche(AVAX)$14.730.41%
  • daiDai(DAI)$1.00-0.11%
  • wrapped-bitcoinWrapped Bitcoin(WBTC)$27,992.000.29%
  • uniswapUniswap(UNI)$5.201.02%
  • chainlinkChainlink(LINK)$6.630.40%
  • leo-tokenLEO Token(LEO)$3.53-0.85%
  • cosmosCosmos Hub(ATOM)$10.880.19%
  • okbOKB(OKB)$47.520.69%
  • moneroMonero(XMR)$153.57-1.27%
  • ToncoinToncoin(TON)$1.85-2.90%
  • ethereum-classicEthereum Classic(ETC)$18.470.41%
  • stellarStellar(XLM)$0.0906131.69%
  • bitcoin-cashBitcoin Cash(BCH)$115.70-0.28%
  • internet-computerInternet Computer(ICP)$4.940.07%
  • filecoinFilecoin(FIL)$4.885.14%
  • true-usdTrueUSD(TUSD)$1.000.15%
  • lido-daoLido DAO(LDO)$2.214.43%
  • AptosAptos(APT)$8.551.20%
  • hedera-hashgraphHedera(HBAR)$0.0533730.80%
  • quant-networkQuant(QNT)$113.725.06%
  • ArbitrumArbitrum(ARB)$1.24-0.57%
  • crypto-com-chainCronos(CRO)$0.0607730.15%
  • vechainVeChain(VET)$0.0209162.49%
  • nearNEAR Protocol(NEAR)$1.650.42%
  • GGTKNGGTKN(GGTKN)$0.1121180.75%
  • apecoinApeCoin(APE)$3.23-1.07%
  • the-graphThe Graph(GRT)$0.1289693.38%
  • algorandAlgorand(ALGO)$0.1530200.29%
  • the-sandboxThe Sandbox(SAND)$0.561.73%
  • paxos-standardPax Dollar(USDP)$1.000.10%
  • eosEOS(EOS)$0.912.04%
  • fraxFrax(FRAX)$1.00-0.16%
  • EdgecoinEdgecoin(EDGT)$1.000.13%
  • aaveAave(AAVE)$67.780.19%