HackerOne urges U.S. to advocate for research protections in UN cybercrime treaty
Full article668 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
The company responsible for bug bounty platforms warns in a letter to top U.S. officials that the treaty’s vague language could undermine ethical security research.
Listen to this article
0:00
Learn more.
HackerOne has expressed serious concerns over the recently proposed UN Convention Against Cybercrime, which the company says lacks strong protections for good-faith security researchers.
In an open letter sent to Secretary of State Antony Blinken, Attorney General Merrick Garland, and United States Agency for International Development Administrator Samantha Power, Ilona Cohen, chief legal and policy officer for HackerOne, highlighted the role independent security has in the industry, and laments the treaty’s failure to align with U.S. policies that shield good-faith efforts from prosecution.
While the convention aims to enhance international collaboration against cybercriminals, Cohen writes that its vague terminology could inadvertently suppress ethical research activities. Nations with underdeveloped cybercrime laws might adopt the treaty’s language, potentially leading to increased risks for researchers, especially those operating in authoritarian regimes. Cohen warns that without explicit protections, countries may misapply the treaty, squeezing the space for legitimate security work.
The company urges the United States to push for revisions that explicitly safeguard ethical hacking within the treaty text or, at a minimum, to encourage other nations to embed these protections into their own legal systems. As a possible strategy, HackerOne suggests incorporating these protections into the cybersecurity capacity-building efforts led by U.S. agencies or conditioning aid on the assurance that governments will not prosecute ethical researchers.
“Taking these and other steps to protect good faith security research will help ensure that policymakers around the world are aware of the treaty’s implications for security research and encourage them to adapt their legal frameworks to support, rather than hinder, ethical hacking,” Cohen wrote. “By doing so, nations can foster a cooperative environment where the essential work of security researchers is valued and encouraged, ultimately strengthening our collective defenses against cyber threats.”
HackerOne is a renowned platform that connects businesses with a global community of ethical hackers to help identify and fix security vulnerabilities. It facilitates bug bounty programs and vulnerability disclosure, allowing organizations to strengthen their security posture by tapping into the expertise of thousands of security researchers. It has set up and maintained bug bounty programs for the U.S. Department of Defense, Spotify and Uber, among many other organizations.
The treaty has advanced toward a General Assembly vote, despite facing criticism from tech companies, human rights advocates, and some U.S. Congress members. A full vote will take place at a UN General Assembly meeting in December.
You can read the full letter below.
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Technology
Threats
Chinese espionage groups swarm to exploit triple-link chain of zero-days
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/un-cybercrime-treaty-hackerone-letter-security-research/