We the undersigned organizations, members of the Hacking Policy Council, respectfully request regulatory guidance from the Office of Foreign Assets Control (OFAC) regarding coordinated vulnerability disclosure processes and sanctions. We urge the Department to clarify organizations’ obligations when receiving a cybersecurity vulnerability disclosure from individuals in “comprehensively sanctioned” countries and regions, and the organization’s ability to ask follow-up questions regarding that vulnerability. Vulnerability disclosures are communications of information, without remuneration, performed to ensure and promote the security of information systems. We commend OFAC for stating in FAQ 448 that the “U.S. government supports efforts by researchers, cybersecurity experts, and network defense specialists to identify, respond to, and repair vulnerabilities that could be exploited by malicious actors.”1 We recognize that this is aligned with the broader U.S. government policy of reducing software vulnerabilities by promoting adoption of coordinated vulnerability disclosure processes in the public and private sectors.2It would be beneficial for OFAC to clarify that such communications from individuals in comprehensively sanctioned areas are not restricted and are exempt from sanctions.

Read Next

Yet Another Blog About “Cyber Operations:” The Trump II Administration’s National Cyber Strategy and Private Sector Collaboration

The recently released National Cyber Strategy provides some insight into questions about the Administration’s approach to offensive cyber policy, and particularly the private sector’s role.

Beyond Buzzwords: What Public Views on Scanning and Encryption Mean for Policymakers

Public support for content scanning and encryption backdoors drops when tradeoffs are made clear. This survey of Nordic countries shows people prioritize privacy and security over harm detection, and lack trust in institutions to govern access.

Center for Cybersecurity Policy and Law to the European Commission: Proposed Measures on Search Data Sharing Raise Security Concerns

The Center for Cybersecurity Policy & Law issued comments in response to DMA.100209 – Alphabet – Article 6(11) -- warning of the security and privacy risks of proposed data sharing requirements.