US Bill Would Force Tech Companies to Disclose Foreign Software Probes

Advertisement
By Reuters | Updated: 25 May 2018 18:00 IST

US tech companies would be forced to disclose if they allowed American adversaries, like Russia and China, to examine the inner workings of software sold to the US military under proposed legislation, Senate staff told Reuters on Thursday.

The bill, approved by the Senate Armed Services Committee on Thursday, comes after a year-long Reuters investigation found software makers allowed a Russian defence agency to hunt for vulnerabilities in software that was already deeply embedded in some of the most sensitive parts of the US government, including the Pentagon, the Federal Bureau of Investigation and intelligence agencies.

Advertisement

Security experts say allowing Russian authorities to conduct the reviews of internal software instructions - known as source code - could help Russia find vulnerabilities and more easily attack key systems that protect the United States.

The new source code disclosure rules were included in Senate version of the National Defence Authorisation Act, the Pentagon's spending bill, according to staffers of Democratic Senator Jeanne Shaheen.

Advertisement

In a statement, Shaheen said that tech companies have a duty to help protect federal software systems.

"This is why the Department of Defence and other federal agencies should know of any potential vulnerabilities relating to a partner company's business practices overseas," she said. The language in the bill mandates those disclosures and "ultimately makes overdue reforms to harden the Department against cyber attacks."

Advertisement

Details of bill, which passed the committee 25-2, are not yet public. And the legislation still needs to be voted on by the full Senate and reconciled with a House version of the legislation before it can be signed into law by President Donald Trump.

If passed into law, the legislation would require companies that do business with the U.S. military to disclose any source code review of the software done by adversaries, staffers for Shaheen told Reuters. If the Pentagon deems a source code review a risk, military officials and the software company would need to agree on how to contain the threat. It could, for example, involve limiting the software's use to non-classified settings.

Advertisement

The details of the foreign source code reviews, and any steps the company agreed to take to reduce the risks, would be stored in a database accessible to military officials, Shaheen's staffers said. For most products, the military notification will only apply to countries determined to be cybersecurity threats, such as Russia and China.

Shaheen has been a key voice on cybersecurity in Congress. The New Hampshire senator last year led successful efforts in Congress to ban all government use of software provided by Moscow-based antivirus firm Kaspersky Lab, amid allegations the company is linked to Russian intelligence. Kaspersky denies such links.

In order to sell in the Russian market, tech companies including Hewlett Packard Enterprise Co , SAP and McAfee have allowed a Russian defence agency to scour software source code for vulnerabilities, Reuters found. In many cases, Reuters found that the software companies had not previously informed US agencies that Russian authorities had been allowed to conduct the source code reviews. In most cases, the US military does not require comparable source code reviews before it buys software, procurement experts have told Reuters.

The companies have said the source code reviews were conducted by the Russians in company-controlled facilities, where the reviewer could not copy or alter the software. McAfee announced last year that it no longer allows government source code reviews. Hewlett Packard Enterprise has said none of its current software offerings have gone through the process.

© Thomson Reuters 2018

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: Apps, US, McAfee
Advertisement

Related Stories

Popular Mobile Brands
  1. Xiaomi TV S Mini LED 75 (2026) Review
  2. Oppo Find X9 Ultra With 200-Megapixel Periscope Camera Launched Globally
  3. Oppo Find X9s Pro Launched With 200-Megapixel Cameras: See Price, Features
  4. Redmi K90 Max Debuts With Active Cooling Fan, 8,550mAh Battery: See Price
  5. Poco M8s 5G Debuts Globally With 7,000mAh Battery: See Price, Features
  6. Microsoft Cuts Xbox Game Pass Prices in India, Global Markets
  7. Vivo X300 FE Roundup: Expected Price in India, Specifications
  8. OnePlus Ace 6 Ultra's Key Specifications Surface via Geekbench Listing
  9. Motorola Razr 2026 Launch Date Teased Alongside Design and Colour Options
  1. Microsoft Cuts Xbox Game Pass Prices in India, Global Markets; Ends Day-One Call of Duty Access
  2. Incoming Apple CEO John Ternus Already Driving AI Overhaul Ahead of Leadership Transition: Report
  3. NASA Shuts Down Voyager 1 Instrument to Extend Mission Life in Deep Space
  4. Oppo Enco Clip 2 With Open-Ear Design, Up to 40 Hours Total Battery Life Launched Alongside Oppo Watch X3 Mini
  5. Vivo Y6t Launched With 6,500mAh Battery, Snapdragon 4 Gen 2 SoC: Price, Specifications
  6. OCBC Partners Lion Global Investors and DigiFT to Launch Tokenised Gold Fund With GOLDX Token
  7. Oppo Pad 5 Pro Launched With 13,380mAh Battery, Snapdragon 8 Elite Gen 5 SoC Alongside Oppo Pad Mini: Price, Features
  8. Redmi K90 Max Launched With Dimensity 9500 SoC, 8,550mAh Battery and Active Cooling Fan: Price, Specifications
  9. Oppo Find X9 Ultra Launched With Snapdragon 8 Elite Gen 5 SoC, 200-Megapixel Periscope Camera: Price, Specifications
  10. Oppo Find X9s Pro Launched With 200-Megapixel Cameras, 7,025mAh Battery: Price, Specifications
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.