GitHub joins amicus brief warning of systemic risk from private sector offensive actors
Today, GitHub joined an amicus brief in NSO v. WhatsApp, opposing the expansion of foreign sovereign immunity to private cyber-surveillance companies that act on behalf of foreign governments. GitHub joined…
Today, GitHub joined an amicus brief in NSO v. WhatsApp, opposing the expansion of foreign sovereign immunity to private cyber-surveillance companies that act on behalf of foreign governments. GitHub joined alongside Cisco, Google, LinkedIn, Microsoft, VMware, and the Internet Association against immunity for private sector offensive actors (PSOAs). Law and policy shape the software ecosystem. A policy of immunity would increase systemic risk to the ecosystem by fostering the cyber-surveillance tools market and expanding the use of such tools by governments, including in attacks on individuals and infrastructure.
At GitHub we are committed to building the global platform for developer collaboration—one that everyone can use to secure the world’s software, together. GitHub helps developers stay ahead of security issues, leverage the community’s security expertise, and use open source securely. GitHub stands against hoarding and selling exploits and attack or surveillance tools. Such tools could be used not only to infiltrate GitHub, but the millions of developers and open source projects which rely on our platform, and the software supply chain which depends on them.
We call on governments to help developers decrease systemic risk, including:
- Adopting the best tools and practices for secure software development
- Helping fund open source security projects
- Adhering to principles that increase trust and security in cyberspace
- Protecting legitimate security researchers
Immunity for cyber-surveillance companies that turn best practices on their heads, hoarding vulnerabilities to use in attacks rather than collaborating with upstream to fix, would be a step in the wrong direction.
Written by
Related posts
Celebrating the GitHub Awards 2024 recipients 🎉
The GitHub Awards celebrates the outstanding contributions and achievements in the developer community by honoring individuals, projects, and organizations for creating an outsized positive impact on the community.
New from Universe 2024: Get the latest previews and releases
Find out how we’re evolving GitHub and GitHub Copilot—and get access to the latest previews and GA releases.
Bringing developer choice to Copilot with Anthropic’s Claude 3.5 Sonnet, Google’s Gemini 1.5 Pro, and OpenAI’s o1-preview
At GitHub Universe, we announced Anthropic’s Claude 3.5 Sonnet, Google’s Gemini 1.5 Pro, and OpenAI’s o1-preview and o1-mini are coming to GitHub Copilot—bringing a new level of choice to every developer.