Disclosing software vulnerabilities is in national interest: White House

Advertisement
By Associated Press | Updated: 14 April 2014 10:27 IST
Disclosing vulnerabilities in commercial and open source software is in the national interest and shouldn't be withheld from the public unless there is a clear national security or law enforcement need, President Barack Obama's National Security Council said Saturday.

The statement of White House policy came after a computer bug called "Heartbleed" caused major security concerns across the Internet and affected a widely used encryption technology, the variant of SSL/TLS known as OpenSSL, that was designed to protect online accounts. Major Internet services worked this week to insulate themselves against the bug.

The NSC, which Obama chairs, advises the president on national security and foreign policy matters. Its spokeswoman, Caitlin Hayden, said in a statement Saturday that the federal government was not aware of the Heartbleed vulnerability in OpenSSL until it was made public in a private sector cybersecurity report. The federal government relies on OpenSSL to protect the privacy of users of government websites and other online services, she said.

Advertisement

"This administration takes seriously its responsibility to help maintain an open, interoperable, secure and reliable Internet," she said. "If the federal government, including the intelligence community, had discovered this vulnerability prior to last week, it would have been disclosed to the community responsible for OpenSSL."

The president's Review Group on Intelligence and Communications Technologies, which Obama appointed last year to review National Security Agency surveillance programs and other intelligence and counterterrorism operations, recommended in December that U.S. policy should generally move to ensure that previously unknown vulnerabilities "are quickly blocked, so that the underlying vulnerabilities are patched on U.S. government and other networks."

"The White House has reviewed its policies in this area and reinvigorated an interagency process for deciding when to share vulnerabilities. This process is called the Vulnerabilities Equities Process," Hayden said. "Unless there is a clear national security or law enforcement need, this process is biased toward responsibly disclosing such vulnerabilities."
 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. God of War Spinoff Will Reportedly Feature Tyr, Explore Several Mythologies
  2. Redmi A7 Pro 5G Goes on Sale in India: See Price, Features and Offers
  3. Red Magic 11s Pro Might Launch Soon Globally With These Features
  1. New Einstein Cross Reveals Surprising Galaxy Evolution
  2. Red Magic 11s Pro Global Launch Seems Imminent as Gaming Smartphone Surfaces on Certification Database
  3. Million Dollar Secrets Season 2 OTT Release: Date, Platform, Plot, Cast and What to Expect
  4. Fake Profile Season 3 Out on OTT: Know Where to Stream This Colombian Series Online
  5. Sony Xperia 1 VIII Could Feature a Headphone Jack and Support Wireless Charging, FCC Listing Suggests
  6. Zerion Links Crypto Cyberattack to North Korean Hackers Using AI Tactics
  7. Google’s SynthID AI Watermarking Tech Claimed to Be Reverse-Engineered
  8. Samsung Patent Hints at Triple-Folding Galaxy Z TriFold Wide With Broader Display
  9. Balls Up Out on OTT: Know Where to Stream This American Action-Comedy Film Online
  10. Oppo Reno 16 Pro Series Key Features, Colourways and Other Details Surface Online
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.