ZeroHour
CyberScooppublished ()ingested @Bing_Chris

Microsoft-led industry group pledges to not assist government cyberattacks

criticalExploit / PoC exploited in the wildimportance 60
Full article864 words · extracted from cyberscoop.com · click to collapse
Skip to main content

Get our latest cybersecurity news first on Google.

Click here!

The participant companies' principles include not helping any government mount a cyberattack against "innocent citizens and enterprises."

Brad Smith speaks at the Geneva Lecture Series in November in Switzerland. (UN Geneva / Flickr)

A cohort of major technology companies led by Microsoft committed Tuesday to a core set of principles for behavior in cyberspace, including not helping any government mount a cyberattack against “innocent citizens and enterprises.”

For the last several weeks, Microsoft has been seeking support from companies in order to define a common standard of behavior, or norms, for the broader software making community. The announcement was spearheaded by Brad Smith, president and chief legal officer of Microsoft. Smith spoke Tuesday morning at the RSA cybersecurity conference in San Francisco to an audience mostly comprised of cybersecurity industry insiders and marketers.

These norms spelled out in the agreement cover more than government relations. They contain the concept of “collective action” between technology companies to eliminate some of the more expansive cybersecurity threats facing the global economy.

Dubbed the “Cybersecurity Tech Accord,” the agreement showcases the signatures of more than 30 chief executives from some of the largest brand-name technology and cybersecurity firms in the world. Most of these companies are either headquartered in or own a large U.S.-based subsidiary.

The cohort includes representation from cybersecurity companies Symantec, Tenable and TrendMicro, among others.  Non-cybersecurity companies also feature prominently, including Dell, Facebook, Oracle, RSA and VMware.

Google, Apple and Amazon have yet to sign the accord, which remains open for additional commitments. A separate agreement led by European companies Siemens and Airbus was announced in February.

Over the last two years, Smith has been arguing for the creation and acceptance of a so-called “digital Geneva Convention.” Such an agreement would be backed by the private sector, instead of engineered by any overarching governmental body, like the European Union.

Smith’s latest effort follows a year in which hackers from North Korea and Russia were able to successfully adopt leaked NSA hacking tools to conduct sweeping attacks against the private sector.

Smith previously wrote a scorching blog post about the U.S. government’s handling of the leak, which put various Microsoft products at risk.

“Repeatedly, exploits in the hands of governments have leaked into the public domain and caused widespread damage,” Smith wrote. “An equivalent scenario with conventional weapons would be the U.S. military having some of its Tomahawk missiles stolen.”

The accord is important because some prominent American tech companies carry a reputation for working closely with governments to identify targets of criminal investigations. Exactly how the accord defines “innocent” is unclear, however.

Prior reporting by Reuters found that “the NSA paid [cybersecurity company] RSA $10 million to make a now-discredited cryptography system the default in software used by a wide range of Internet and computer security programs.”

Leaked documents from Edward Snowden also showed that historically, governments have occasionally worked closely with large technology vendors to spy on specific targets.

More Scoops

Committee chairman Rep. Mark Green (R-TN) looks on as ranking member Rep. Bennie Thompson (D-MS) speaks during a hearing with the House Committee on Homeland Security on January 30. (Photo by Anna Moneymaker/Getty Images)

Microsoft’s Brad Smith should prepare for ‘ritual punishment’ before House hearing

Some experts are doubtful the Homeland Security Committee testimony and questioning of Microsoft chief Brad Smith will lead to significant change.

Brad Smith, Vice Chair and President at the Microsoft Corporation, arrives for a Senate Judiciary Subcommittee on Privacy, Technology, and the Law oversight hearing to examine legislating artificial intelligence (AI), on Capitol Hill in Washington, DC, on September 12, 2023. (Photo by ANDREW CABALLERO-REYNOLDS / AFP)

House panel leaders call on Microsoft president to testify over security shortcomings

Ukraine, Russia war
Ukrainian Military Forces servicemen of the 92nd mechanized brigade conduct live-fire exercises near the town of Chuguev, in Kharkiv region, on Feb. 10, 2022.(Photo by SERGEY BOBOK/AFP via Getty Images)

Ukraine conflict spurs questions of how to define cyberwar

Latest Podcasts

Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/microsoft-brad-smith-cyber-norms-rsa-2018/