Slashdot Mirror


Chilling Effect of the Wassenaar Arrangement On Exploit Research

Bismillah writes: Security researchers are confused as to how the export control and licensing controls covering exploits affect their work. The upcoming Wassenaar restrictions were expected to discourage publication of such research, and now it's already started to happen. Grant Wilcox, writing his dissertation for the University of Northumbria at Newcastle, was forced to take a better-safe-than-sorry approach when it came time to release the vulnerabilities he found in Microsoft's EMET 5.1. "No legal consultation on the matter took place, but Wilcox noted that exploit vendors such as Vupen had started to restrict sales of their products and services because of new export control and licensing provisions under the Wassenaar Arrangement. ... Wilcox investigated the export control regulations but was unable to clarify whether it applied to his academic work. The university did not take part. He said the provisions defining which type of exploits and software are and aren't controlled were written in ambiguous language and appeared to contradict each other."

3 of 30 comments (clear)

  1. No shit .... by gstoddart · · Score: 4, Insightful

    These were, in all likelihood, written by industry and handed to government to implement.

    Which means they've been carefully crafted to mean whatever is most advantageous to corporate interests and interpreted however they need it to be interpreted.

    These are noting more than gag laws, designed to block and intimidate people.

    You're not supposed to be able to know when they apply.

    --
    Lost at C:>. Found at C.
    1. Re:No shit .... by Anonymous Coward · · Score: 2, Insightful

      Actually it seems most laws are written that way these days. Very vague and impossible to know what exactly they mean when reading them.

  2. Meanwhile ... by PPH · · Score: 3, Insightful

    ... the market for zero-day exploits continues unabated on the dark net. I guess the cyber criminals haven't gotten any negative feedback concerning Wassenaar restrictions from their legal departments.

    --
    Have gnu, will travel.