Get 40% Off
🚨 Volatile Markets? Find Hidden Gems for Serious Outperformance
Find Stocks Now

Exclusive: U.S. bill would force tech companies to disclose foreign software probes

Published 05/24/2018, 07:05 PM
© Reuters. FILE PHOTO: US Senator Jean Shaheen (D-NH) prepares for a conference call at her office on Capitol Hill in Washington

By Joel Schectman

WASHINGTON (Reuters) - U.S. tech companies would be forced to disclose if they allowed American adversaries, like Russia and China, to examine the inner workings of software sold to the U.S. military under proposed legislation, Senate staff told Reuters on Thursday.

The bill, approved by the Senate Armed Services Committee on Thursday, comes after a year-long Reuters investigation https://reut.rs/2kgSpjW found software makers allowed a Russian defense agency to hunt for vulnerabilities in software that was already deeply embedded in some of the most sensitive parts of the U.S. government, including the Pentagon, the Federal Bureau of Investigation and intelligence agencies.

Security experts say allowing Russian authorities to conduct the reviews of internal software instructions -- known as source code -- could help Russia find vulnerabilities and more easily attack key systems that protect the United States.

The new source code disclosure rules were included in Senate version of the National Defense Authorization Act, the Pentagon’s spending bill, according to staffers of Democratic Senator Jeanne Shaheen.

In a statement, Shaheen said that tech companies have a duty to help protect federal software systems.

"This is why the Department of Defense and other federal agencies should know of any potential vulnerabilities relating to a partner company’s business practices overseas," she said. The language in the bill mandates those disclosures and "ultimately makes overdue reforms to harden the Department against cyber attacks."

Details of bill, which passed the committee 25-2, are not yet public. And the legislation still needs to be voted on by the full Senate and reconciled with a House version of the legislation before it can be signed into law by President Donald Trump.

3rd party Ad. Not an offer or recommendation by Investing.com. See disclosure here or remove ads .

If passed into law, the legislation would require companies that do business with the U.S. military to disclose any source code review of the software done by adversaries, staffers for Shaheen told Reuters. If the Pentagon deems a source code review a risk, military officials and the software company would need to agree on how to contain the threat. It could, for example, involve limiting the software’s use to non-classified settings.

The details of the foreign source code reviews, and any steps the company agreed to take to reduce the risks, would be stored in a database accessible to military officials, Shaheen's staffers said. For most products, the military notification will only apply to countries determined to be cybersecurity threats, such as Russia and China.

Shaheen has been a key voice on cybersecurity in Congress. The New Hampshire senator last year led successful efforts in Congress to ban all government use of software provided by Moscow-based antivirus firm Kaspersky Lab, amid allegations the company is linked to Russian intelligence. Kaspersky denies such links.

In order to sell in the Russian market, tech companies including Hewlett Packard Enterprise Co (N:HPE), SAP (DE:SAPG) and McAfee have allowed a Russian defense agency to scour software source code for vulnerabilities, Reuters found. In many cases, Reuters found that the software companies had not previously informed U.S. agencies that Russian authorities had been allowed to conduct the source code reviews. In most cases, the U.S. military does not require comparable source code reviews before it buys software, procurement experts have told Reuters. (Graphic: https://tmsnrt.rs/2J0Mf2C)

3rd party Ad. Not an offer or recommendation by Investing.com. See disclosure here or remove ads .

The companies have said the source code reviews were conducted by the Russians in company-controlled facilities, where the reviewer could not copy or alter the software. McAfee announced last year that it no longer allows government source code reviews. Hewlett Packard Enterprise has said none of its current software offerings have gone through the process.

Latest comments

Risk Disclosure: Trading in financial instruments and/or cryptocurrencies involves high risks including the risk of losing some, or all, of your investment amount, and may not be suitable for all investors. Prices of cryptocurrencies are extremely volatile and may be affected by external factors such as financial, regulatory or political events. Trading on margin increases the financial risks.
Before deciding to trade in financial instrument or cryptocurrencies you should be fully informed of the risks and costs associated with trading the financial markets, carefully consider your investment objectives, level of experience, and risk appetite, and seek professional advice where needed.
Fusion Media would like to remind you that the data contained in this website is not necessarily real-time nor accurate. The data and prices on the website are not necessarily provided by any market or exchange, but may be provided by market makers, and so prices may not be accurate and may differ from the actual price at any given market, meaning prices are indicative and not appropriate for trading purposes. Fusion Media and any provider of the data contained in this website will not accept liability for any loss or damage as a result of your trading, or your reliance on the information contained within this website.
It is prohibited to use, store, reproduce, display, modify, transmit or distribute the data contained in this website without the explicit prior written permission of Fusion Media and/or the data provider. All intellectual property rights are reserved by the providers and/or the exchange providing the data contained in this website.
Fusion Media may be compensated by the advertisers that appear on the website, based on your interaction with the advertisements or advertisers.
© 2007-2024 - Fusion Media Limited. All Rights Reserved.