Disclosing software vulnerabilities is in national interest: White House

Advertisement
By Associated Press | Updated: 14 April 2014 10:27 IST
Disclosing vulnerabilities in commercial and open source software is in the national interest and shouldn't be withheld from the public unless there is a clear national security or law enforcement need, President Barack Obama's National Security Council said Saturday.

The statement of White House policy came after a computer bug called "Heartbleed" caused major security concerns across the Internet and affected a widely used encryption technology, the variant of SSL/TLS known as OpenSSL, that was designed to protect online accounts. Major Internet services worked this week to insulate themselves against the bug.

The NSC, which Obama chairs, advises the president on national security and foreign policy matters. Its spokeswoman, Caitlin Hayden, said in a statement Saturday that the federal government was not aware of the Heartbleed vulnerability in OpenSSL until it was made public in a private sector cybersecurity report. The federal government relies on OpenSSL to protect the privacy of users of government websites and other online services, she said.

"This administration takes seriously its responsibility to help maintain an open, interoperable, secure and reliable Internet," she said. "If the federal government, including the intelligence community, had discovered this vulnerability prior to last week, it would have been disclosed to the community responsible for OpenSSL."

Advertisement

The president's Review Group on Intelligence and Communications Technologies, which Obama appointed last year to review National Security Agency surveillance programs and other intelligence and counterterrorism operations, recommended in December that U.S. policy should generally move to ensure that previously unknown vulnerabilities "are quickly blocked, so that the underlying vulnerabilities are patched on U.S. government and other networks."

"The White House has reviewed its policies in this area and reinvigorated an interagency process for deciding when to share vulnerabilities. This process is called the Vulnerabilities Equities Process," Hayden said. "Unless there is a clear national security or law enforcement need, this process is biased toward responsibly disclosing such vulnerabilities."
 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Redmi Pad 2 Pro 5G Will Launch in India Soon: See Expected Features
  2. OTT Releases of the Week: Thamma, Mrs Deshpande, Nayanam, and More
  3. OnePlus Watch Lite With Up to 10 Days Battery Life Launched: See Price
  4. Xiaomi 17 Ultra With Leica-Tuned Cameras Confirmed to Launch Soon
  5. Hogwarts Legacy Tops 40 Million Copies Sold
  1. Physicists Push Superconducting Diodes to Higher Temperatures
  2. NASA’s Perseverance Rover Poised for Years of Exploration Across Jezero Crater
  3. James Webb Space Telescope Could Illuminate Dark Matter in an Unexpected Way
  4. James Webb Confirms First Runaway Supermassive Black Hole Rocking Through Space
  5. Interstellar Comet 3I/ATLAS to Make Closest Approach to Earth on December 19
  6. The Roofman Now Streaming Online: Everything You Need to Know
  7. Adobe Firefly Platform Updated With New AI Models and Tools, Offers Limited-Time Unlimited Generations
  8. Boat Valour Ring 1 Launched in India With Heart Rate Variability Tracking, Up to 15-Day Battery Life: Price, Features
  9. Call of Duty: Black Ops 7 Was the Best-Selling Game in the US in November, but Trails Battlefield 6 in 2025
  10. Truecaller Voicemail Feature Launched for Android Users in India With Transcription in 12 Regional Languages
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.