Friday 4 December 2015

The TPP’s ban on source-code disclosure requirements: bad news for information security

The secretly negotiated Trans Pacific Partnership is 2,000 pages’ worth of regulatory favors for various industries, but one that stands out as particularly egregious is the ban on rules requiring source-code disclosure.

Hardly a day goes by without a researcher discovering critical flaws in devices ranging from hospital cardio servers to home alarm systems. Source code disclosure is an important step in making these devices more secure, allowing for independent scrutiny and auditing of tools that could literally kill us if their programming contains undisclosed defects.

TPP’s ban on code auditing ties the hands of the countries that sign onto it, forbidding their legislatures and regulators from making rules that require vendors to disclose their source-code for regulatory approval or legal importation. For the full article click here 



from critical infrastructure alliance http://ift.tt/1Q4FCty
via IFTTT

No comments:

Post a Comment