«White hackers» may be restricted from accessing data on attack methods

According to experts, the Ministry of Digital Development's new amendments to Article 15.3 of the Federal Law may complicate the work of legitimate cybersecurity specialists

Cybersecurity companies have expressed concern about the amendments of the Ministry of Digital Development, published on August 26 on the regulation.gov portal. The new measures, aimed at combating fraud, propose a ban on the dissemination of information about methods of cyberattacks, which, according to experts, may complicate the work of legitimate cybersecurity specialists.

The amendments propose to amend Article 15.3 of the Federal Law «On Information», prohibiting the dissemination of data intended for unauthorized access to programs. The Ministry of Digital Development insists that the measure is aimed exclusively against cybercriminals and is designed to impede their activities, as well as to more effectively block channels for the distribution of malicious programs.

However, according to representatives of Positive Technologies, such a ban may limit the activities of so-called «white hackers» — specialists who look for vulnerabilities in systems for their further elimination. In their opinion, access to information about attacks is a necessary tool for the work of researchers in the field of information security.

Experts note that the new wording creates legal uncertainty for specialists participating in Bug Bounty programs, where vulnerabilities are searched for a reward. At the moment, legislators are discussing a new version of the draft law on «white hackers», taking into account proposals from business and the expert community.

These amendments are part of the second package of anti-fraud measures, which also includes initiatives to limit the number of bank cards per citizen and transfer records of suspicious telephone conversations to a unified system. A final decision on the document has not yet been made.

Read more materials on the topic:

Money did not return: a new fraud scheme appeared under the guise of testing a payment terminal

Mobile numbers for government services and other state services will begin to be checked for relevance

Scammers use electronic diaries to steal money

Sources
Kommersant

Now on home