The Centre for Cyber Security Belgium has just enacted nation-wide vulnerability disclosure policies and a reporting framework, including several obligations for security researchers such as:
a) You must limit yourself strictly to the facts necessary to report a vulnerability – you must not act beyond what is necessary and proportionate to verify the existence of a vulnerability
b) You must act without fraudulent intent or design to harm
c) As soon as possible after the discovery of the potential vulnerability, you must inform the organization responsible for the system, process or control of the vulnerability
You can read the announcement here, and the policy here.
Chloe Messdaghi, Managing Director at Impactive Partners had this comment:
“Belgium is offering a good example of where every country needs to be with their vulnerability disclosure policies. Unfortunately, the US is still piecing together our VDP legal framework, although in 2022, the DOJ revised its policies under the Computer Fraud and Abuse Act (CFAA) to help protect “good-faith” security research from being prosecuted, and the US Army actively encourages researchers to participate in its VDP.
“With cyber threats growing exponentially over the last several years, it’s past time to actually require that certain types and sizes of organizations across the US – and especially including all Federal agencies and NGOs – have robust protective, active vulnerability disclosure policies. VDPs have been viewed by security-aware organizations as must-have for many years. The thing to remember is that EVERYONE in both the public and private sector is now a target, and virtually everyone has exploitable, exposed assets they need to find and fix before a threat actor finds them – this is why we need VDPs.
“Remember back in 2021 when the UN disclosed a data breach exposing over 100K UNEP records? We applauded Sakura Samurai’s team – what they did was worthy of it! This was successful because the UN’s vulnerability disclosure policy was transparent – that’s why they decided to look for the vulnerabilities. There was a sense of trust that they would be recognized, not persecuted. This was a great example of how vulnerability disclosure policies work, and underscored the value of working closely with independent researchers, i.e., hackers.”
Christopher Vaughan, VP, Technical Account Management at Tanium follows up with this comment:
“This is a welcomed development and having such laws in place will make Belgium a more secure country as a whole. Further, it will help position Belgium as go-to destination for security research with a corresponding benefit of cultivating a greater number of homegrown talent.
“We can also expect to see some ambiguity around what’s considered legal and not. There isn’t a huge sample size of where policies such as this have been enacted on a national level, so it will be interesting to see a program of this scale in action.
I really like the fact that Belgium is doing this and I hope that other countries will do something similar as actions like this will make us all safer.
In An Attempt To Bolster Ad Revenues, Elon Musk Allows Weed Ads Onto Twitter
Posted in Commentary with tags Twitter on February 17, 2023 by itnerdThe desperation is strong with Elon Musk.
I say that because Twitter, who really needs money from advertisers is now allowing cannabis ads onto the platform:
The company previously only allowed ads for hemp-derived CBD (Cannabidiol) topical products, while rival platforms Facebook, Instagram, and TikTok hold fast to a “no cannabis advertising policy” since marijuana is illegal at the federal level.
A nationwide push toward allowing the sale of recreational cannabis has been ongoing. As of January 2023, 31 states and the District of Columbia have decriminalized low-level marijuana possession offenses, and recreational weed is legal in 21 states, D.C., and Guam.
“As the cannabis industry has expanded, so too has the conversation on Twitter,” the company says(Opens in a new window). “In certain US states we have taken measures to relax our Cannabis Ads policy to create more opportunities for responsible cannabis marketing—the largest step forward by any social media platform.”
Moving forward, Twitter will allow advertisers to promote brand preference and informational cannabis-related content for CBD, THC (Tetrahydrocannabinol), and cannabis-related products and services. Some restrictions do apply: Advertisers must be licensed and pre-authorized, and may only target customers over the age of 21 in certain jurisdictions.
I guess when about half your advertisers have stopped advertising on your platform, you’ll take money from any source that will give it to you. Now to be clear, I am not saying that cannabis is bad or anything like that. What I am saying is that if every other social media platform doesn’t allow this product to be advertised on their platforms, there must be a logical reason behind that. And Elon is so desperate for cash that he’s clearly ignoring whatever logical reason that might exist in terms of restricting cannabis advertising on Twitter. Thus I fully expect that besides seeing Elon’s Tweets flooding your Twitter feeds, I also expect weed ads to flood your feeds as well.
Groovy.
1 Comment »