Google joins chorus against infosec export controls proposal

By
Follow google news

Information sharing on security issues must be allowed.

Google has come out strongly against proposed new export control rules for exploits and software, arguing they could have a disastrous outcome and result in billions of users worldwide becoming less safe as security research is stymied.

Google joins chorus against infosec export controls proposal

In a blog entry co-authored by Google export compliance lawyer Neil Martin and Chrome security team member Tim Willis, the pair say the rules proposed by the US Department of Commerce as part of the Wassenaar Arrangement for weapons control are "dangerously broad and vague".

"The proposed rules are not feasible and would require Google to request thousands - maybe even tens of thousands - of export licenses," Willis and Martin wrote.

Security researchers need a standing exemption from licenses so they can report vulnerabilities, exploits and other controlled information to any vendor, they argued.

"You should never need a license when you report a bug to get it fixed," Willis and Martin said.

Google also criticised the proposed rules as complex and confusing, and said the US trade department's Bureau of Industry and Security should provide "a simple, visual flowchart for everyone to easily understand when they need a license" if the controls are to be implemented.

The rules have to be changed as soon as possible, Google said.

Google's call to modify the proposed infosec exploit controls comes after a group of security vendors banded together in The Coalition for Responsible Cybersecurity, which aims to stop the new regulations.

Add iTnews as your trusted source

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © iTnews.com.au . All rights reserved.
Tags:

Most Read Articles

Poor WA gov M365 security led to $71k theft and children's data breached

Poor WA gov M365 security led to $71k theft and children's data breached

US medical device maker Stryker's Microsoft environment attacked

US medical device maker Stryker's Microsoft environment attacked

Services Australia describes fraud, debt-related machine learning use cases

Services Australia describes fraud, debt-related machine learning use cases

Health and Aged Care CISO retires

Health and Aged Care CISO retires

Log In

  |  Forgot your password?