The EFF Sues The NSA For Details On How The Government Discloses Security Flaws
The Electronic Frontier Foundation (EFF) is suing the National Security Agency (NSA) over government disclosure of security flaws that have been uncovered by the intelligence community.
In the wake of the Heartbleed fiasco, and pointed reports that the NSA both knew about the vulnerability and had exploited it, the Office of the Director of National Intelligence (ODNI) denied any prior knowledge of the bug. As the EFF quotes in its lawsuit, the ODNI stated that a policy in place called the “Vulnerabilities Equities Process” is used to decide when to disclose security flaws that it uncovers.
Amid the controversy in April, the White House explained the process the administration uses to disclose cyber vulnerabilities in a post on its blog. But its explanation was vague and flawed.