4

4 comments

[–] CDanger 1 points (+1|-0)

Title sounds interesting, and the summary for a bug bounty is uncharacteristically sane for the government. But as we know the bills content and what it actually involves can be two different things. Halfway expecting the text to require citizens to give up passwords or something lol

[–] [Deleted] 0 points (+0|-0)

I kind of thought the bug bounty bit might be a bit dumb depending on how it's implemented. For open source software that's great. Offering a reward to any old schmuck to try to hack a govt. platform is dumb as hell though. It basically lets them practice then sell it to a foreign govt. All how it's implemented I guess. I just worry about them letting jackasses like Debbie Wasserman Schultze's IT guys work on this.

[–] CDanger 1 points (+1|-0)

Yeah, it'll probably be bungled. I don't see why a bug bounty couldn't work even for governments. Nothing is stoping people from attacking gov sites now and selling the vulnerability to a foreign government. What it does it produce an incentive for vulnerabilities to be disclosed and fixed instead of hoarded. These sort of responsible programs also help so that things like this don't happen.

[–] antikaon [OP] 0 points (+0|-0)

To require the Secretary of State to design and establish a Vulnerability Disclosure Program (VDP) to improve Department of State cybersecurity and a bug bounty program to identify and report vulnerabilities of internet-facing information technology of the Department of State, and for other purposes.