{"id":72555,"date":"2023-03-31T11:34:09","date_gmt":"2023-03-31T15:34:09","guid":{"rendered":"https:\/\/scoopmedia-develop.go-vip.net\/cyberscoop\/?p=72555"},"modified":"2023-03-31T11:34:09","modified_gmt":"2023-03-31T15:34:09","slug":"software-liability-biden-microsoft-vulnerabilities","status":"publish","type":"post","link":"https:\/\/scoopmedia-develop.go-vip.net\/cyberscoop\/software-liability-biden-microsoft-vulnerabilities\/","title":{"rendered":"Can a White House initiative compel tech companies to write safer code?"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">Microsoft debuted Exchange Server 27 years ago at a time when companies were just beginning to introduce email into the workplace. Allowing companies to run on-premise email servers, Exchange Server was an immediate game changer, helping to usher in a new era of digital communication. But it also brought grave new risks.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Since 1999, security researchers have logged <a href=\"https:\/\/www.cvedetails.com\/product\/194\/Microsoft-Exchange-Server.html?vendor_id=26\" target=\"_blank\" rel=\"noreferrer noopener\">at least 189 vulnerabilities<\/a> in Exchange Server. There are likely many more but that was the first year that researchers began recording such flaws on the <a href=\"https:\/\/www.cve.org\/About\/History#Overview\" target=\"_blank\" rel=\"noreferrer noopener\">CVE List<\/a>. In 2021 alone, Microsoft <a href=\"https:\/\/www.cvedetails.com\/vulnerability-list.php?vendor_id=26&amp;product_id=194&amp;version_id=&amp;page=1&amp;hasexp=0&amp;opdos=0&amp;opec=0&amp;opov=0&amp;opcsrf=0&amp;opgpriv=0&amp;opsqli=0&amp;opxss=0&amp;opdirt=0&amp;opmemc=0&amp;ophttprs=0&amp;opbyp=0&amp;opfileinc=0&amp;opginf=0&amp;cvssscoremin=0&amp;cvssscoremax=0&amp;year=2021&amp;month=0&amp;cweid=0&amp;order=3&amp;trc=31&amp;sha=01b4fd5ef350f387ba6576881c7502e7ecf4ccd0\" target=\"_blank\" rel=\"noreferrer noopener\">disclosed 31 Exchange vulnerabilities<\/a>, its highest annual total. Using four of them, Chinese state-backed hackers utilized Exchange for a sprawling campaign targeting U.S. law firms, think tanks and defense contractors that <a href=\"https:\/\/krebsonsecurity.com\/2021\/03\/at-least-30000-u-s-organizations-newly-hacked-via-holes-in-microsofts-email-software\/\" target=\"_blank\" rel=\"noreferrer noopener\">hit perhaps as many as 30,000 targets<\/a>. And last year, hackers <a href=\"https:\/\/therecord.media\/microsoft-confirms-two-exchange-server-zero-days-are-being-used-in-cyberattacks\" target=\"_blank\" rel=\"noreferrer noopener\">returned to hit Exchange<\/a>, targeting a flaw <a href=\"https:\/\/doublepulsar.com\/proxynotshell-the-story-of-the-claimed-zero-day-in-microsoft-exchange-5c63d963a9e9\" target=\"_blank\" rel=\"noreferrer noopener\">that Microsoft had failed to fix<\/a>.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Over nearly three decades, Exchange vulnerabilities have opened up businesses and government agencies to countless hacks, costing many millions of dollars and putting Americans at risk. Despite these enduring problems, Microsoft faces no real penalties beyond reputational harm for its security failures \u2014 nor do other software companies. When a consumer buys a piece of software, the terms of service will almost always exempt the provider from liability if something goes wrong.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">That could be about to change. In recent weeks, the Biden administration has opened the door to reforming some of the basic economic incentives of the software industry. In its recently released <a href=\"https:\/\/www.whitehouse.gov\/wp-content\/uploads\/2023\/03\/National-Cybersecurity-Strategy-2023.pdf\" target=\"_blank\" rel=\"noreferrer noopener\">cyber strategy<\/a>, the Biden administration called on Congress to develop legislation to develop a software liability regime, one that would allow consumer and businesses to sue software makers if they fail to take proper care in designing the security of their tools. Software companies, if the White House has its way, will no longer be able to disclaim liability for the products they produce.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Building secure products is expensive and time consuming, and many experts have long argued that there is little reason for companies to prioritize security over speed in the development process. \u201cThe economic incentives are all wrong,\u201d says Bruce Schneier, a public interest technologist and the chief security architect at the firm Inrupt. \u201c\u200b\u200bIf you want these companies to spend money on security \u2014 to reduce their earnings \u2014 it has to be worth it.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Three decades after its launch, Microsoft Server Exchange remains buggy, hard to fix and prone to attack, and that has <a href=\"https:\/\/www.wired.com\/story\/microsoft-exchange-server-vulnerabilities\/\" target=\"_blank\" rel=\"noreferrer noopener\">led many security experts to conclude<\/a> that Microsoft simply isn\u2019t putting the necessary resources into maintaining a product that remains a crucial piece of enterprise infrastructure.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In responding to the breaches of 2021, the company\u2019s \u201csecurity and customer support teams worked around the clock to support customers as they updated their systems,\u201d a Microsoft spokesperson said, noting that the company continues \u201cto support on-premises customers to move to a supported and up-to-date version.\u201d&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Errors in code are inevitable. The failure of software makers to put sufficient resources toward security, however, is making it far harder than it should be to harden computer systems, said Trey Herr, who directs the Cyber Statecraft Initiative at the Atlantic Council. \u201cUsers shouldn\u2019t have to be triaging a Swiss cheese product,\u201d he said. &#8220;Software will always have bugs but recurring faults, in the same way, in the same place, in the same product, are an issue of bad development practices.\u201d&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">By embracing liability reform, the Biden administration is trying to shift how big software companies allocate their resources. \u201cLiability is about sharpening the incentives for better development and shifting that burden away from users,&#8221; Herr says.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The past decade of cybersecurity policy discussion in Washington has largely focused on information sharing regimes and voluntary best practices, but with its recently released strategy document, the Biden administration is attempting to usher in a new framework for cybersecurity policy, one focused on more stringent regulation. Overhauling software liability sits at the center of that project.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In rolling out the strategy, Kemba Walden, the acting director of the Office of the National Cyber Director, emphasized that it marks a shift in how Washington thinks about cyberspace: \u201cWe can\u2019t just think in terms of national security, we also have to think of cyberspace in terms of political economy.\u201d&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cRight now we live in the context of first-to-market, not secure-to-market,\u201d Walden said during a recent appearance at the Center for Strategic and International Studies. \u201cWhat we are trying to achieve is a competitive advantage for those that build in security by design.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Achieving that goal, however, requires working with Congress, and that means that the centerpiece of the Biden\u2019s cyber strategy faces a highly uncertain future.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">With Republicans in control of the House of Representatives, passing a regulatory framework is highly unlikely in the near term. After the strategy document\u2019s release, key Republicans in the House of Representatives immediately criticized it as yet another Democratic power grab for the regulatory state. \u201cIt&#8217;s no surprise that this Administration\u2019s desire for more regulation, bureaucracy, and red tape is a consistent theme in the National Cybersecurity Strategy,\u201d Reps. Andrew Garbarino, R-N.Y., who chairs the House Subcommittee on Cybersecurity and Infrastructure Protection, and Mark Greene, R-Tenn., the chair of the House Homeland Security Committee, said <a href=\"https:\/\/garbarino.house.gov\/media\/press-releases\/garbarino-green-statement-release-national-cybersecurity-strategy\">in a joint statement<\/a>.&nbsp;&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This hostile legislative landscape and the thorny technical questions that need answering has Biden administration officials speaking about the passage of a software liability reform package as a long-term project, one that might take up to a decade to shift the burden of securing software from end users to technology companies. Walden says figuring how to get the balance right will require a \u201cmulti-year, multistakeholder process\u201d and help from Congress and software companies.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In writing a software liability policy, the central question that policymakers need to address is how to configure its safe harbor provision. The Biden administration\u2019s strategy document proposes that if companies abide by some set of secure software development rules, then they won\u2019t be subject to liability. By following a higher standard of care, the thinking goes, software companies will tend to build more secure software, and the liability exemption functions as the incentive to get them to abide by that standard.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The offer to the software industry is a simple one: Follow these rules for writing more secure code and you won\u2019t get sued. Exactly what those rules look like will make a big difference as to whether a software liability regime delivers actual security dividends. \u201cThe devil is in the details, and the strategy doesn\u2019t have a lot of them,\u201d Schneier says.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The idea of software liability reform isn\u2019t new \u2014 academics have been <a href=\"https:\/\/www.jstor.org\/stable\/25761785?seq=1\" target=\"_blank\" rel=\"noreferrer noopener\">writing about it for at least 35 years<\/a> and <a href=\"https:\/\/www.schneier.com\/essays\/archives\/2003\/11\/liability_changes_ev.html\" target=\"_blank\" rel=\"noreferrer noopener\">Schneier for the last 20<\/a> \u2014 and secure development frameworks already exist. The National Institute of Standards and Technology <a href=\"https:\/\/csrc.nist.gov\/Projects\/ssdf\" target=\"_blank\" rel=\"noreferrer noopener\">has developed one such set of practices<\/a>. The Business Software Alliance, an industry group, <a href=\"https:\/\/www.bsa.org\/reports\/updated-bsa-framework-for-secure-software\" target=\"_blank\" rel=\"noreferrer noopener\">has built another<\/a>. Microsoft has <a href=\"https:\/\/www.microsoft.com\/en-us\/securityengineering\/sdl\" target=\"_blank\" rel=\"noreferrer noopener\">put together yet another<\/a>.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">But how to marry these technical frameworks with a legal liability regime that manages to address the sprawling software industry represents a huge open question. In an ideal world, a liability regime would force software companies to reduce the amount of sloppy and easily avoidable errors in their code, but as <a href=\"https:\/\/nvlpubs.nist.gov\/nistpubs\/ir\/2016\/NIST.IR.8151.pdf\" target=\"_blank\" rel=\"noreferrer noopener\">a 2016 report from NIST observed<\/a>, \u201cdefining sloppy and easily avoidable is not a trivial matter.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Among other challenges, according to Herr of the Atlantic Council <a href=\"https:\/\/www.lawfareblog.com\/software-liability-just-starting-point\" target=\"_blank\" rel=\"noreferrer noopener\">who has written extensively about the issue<\/a>, are ensuring that a liability regime \u201cdoes not place new burdens open source developers, who have little control over who uses their code in critical applications\u201d and that \u201cliability eventually applies to the whole software industry, including cloud service providers and manufacturers like automotive companies.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cSoftware is software even if it controls your brakes and plays Danny Boy on the radio,\u201d Herr says.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Security researchers broadly agree that it\u2019s important that a future software liability regime does not expose open source software developers to lawsuits, but at the same time, software makers are continuing to ship code that relies on software libraries with known vulnerabilities. \u201cThat\u2019s just no longer acceptable,\u201d says Megan Stifel, the chief strategy officer for the Institute for Security and Technology.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The resource trade-offs between security and other aspects of software development becomes particularly hard to balance for start-up companies. Stifel will sometimes advise startups, and when she brings up the need to address security concerns, \u201cthey sort of look at you like you\u2019re nuts,\u201d she said.&nbsp;&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Biden officials have encapsulated the shift they\u2019re trying to achieve with a pithy phrase \u2014 \u201cyou want to be secure to market, not first to market.\u201d Jeff Greene, who oversaw the defensive cybersecurity portfolio on the National Security Council until July and now works at the Aspen Institute, calls that \u201can unrealistic aspiration in a capitalistic market,\u201d even if security should be a concern for developers.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Since the strategy\u2019s release, Biden officials have emphasized that they want any potential liability regime to focus on big infrastructure providers in the software ecosystem. Anjana Rajan, the assistant national cyber director for technology security, said during an appearance last week at the BSA \u2014 whose members are among those at risk of being sued under a software liability regime \u2014 that when technology start-ups rely on infrastructure companies like Amazon Web Services and Twilio, they should be able to expect that these companies are delivering secure products.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Liability for software vulnerabilities, she argued, should be tuned to the degree of importance a company has in the software ecosystem. \u201cIt\u2019s not a one-size-fits-all solution,\u201d Rajan said. \u201cWe\u2019re going to calibrate responsibility based on your responsibility.\u201d&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Big companies like Microsoft \u2014 with large legal teams accustomed to abiding by regulatory regimes \u2014 are already incorporating the type of secure software development standards that would qualify firms for the safe harbor provision. Taking the example of the Exchange vulnerabilities, as long as Microsoft can demonstrate that it abided by those standards in developing the software, it would not face liability \u2014 at least in theory.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Raising the standard of care in the software industry might result in security improvements in the aggregate, but individual companies may still escape liability so long as they can demonstrate that they comply with the provisions of the safe harbor.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For now, the technology industry responded in surprisingly muted tones to the idea of a liability regime. Henry Young, the director for policy at BSA, described himself as optimistic about how a liability regime might develop. \u201cIn order to sell products and services, customers need to trust them,\u201d he said. \u201cWe might need to drive some of the less security conscious companies to be more security conscious.\u201d&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cI have not spoken to a single person in industry that doesn\u2019t think they can do better,\u201d he added.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Even Microsoft sees the gesture toward liability reform as a positive. \u201cWe welcome the strategy\u2019s aim to ensure that technology providers are accountable for using security best practices when developing and managing software and digital products\u201d Tom Burt, Microsoft\u2019s corporate vice president for customer security and trust, <a href=\"https:\/\/blogs.microsoft.com\/on-the-issues\/2023\/03\/09\/national-cybersecurity-strategy-cyber-readiness\/\" target=\"_blank\" rel=\"noreferrer noopener\">wrote in a blog post<\/a>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Should Congress take up this issue, the stakes of this fight will dramatically increase, as the giant U.S. software industry scrutinizes a proposal that would reshape the legal basis on which it does basis. Briefing reporters after the strategy was released, John Miller, a senior vice president at the Information Technology Industry Council, offered a preview of the argument big business is likely to marshal: \u201cWhenever you start distorting market incentives you could end up getting the opposite result than what you were hoping for.\u201d<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Software liability reform is a centerpiece of the Biden&#8217;s recent national cybersecurity strategy. Implementing it will be a challenge. <\/p>\n","protected":false},"author":595,"featured_media":72731,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"disable_grayscale_images":true,"grayscale_contrast":0,"sponsored_content":false,"display_author_bio":true,"story_type":"","footnotes":""},"categories":[5],"tags":[8,238,739,3962,5225,5728],"people":[],"special-report":[],"authors":[6627],"class_list":["post-72555","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-technology","tag-white-house","tag-microsoft","tag-vulnerabilities","tag-security-research","tag-cisa","tag-biden-administration","author-elias-groll"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v27.8 (Yoast SEO v27.8) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>Can a White House initiative compel tech companies to write safer code? | CyberScoop<\/title>\n<meta name=\"description\" content=\"Software liability reform is a centerpiece of the Biden&#039;s recent national cybersecurity strategy. implementing it will be a challenge.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/scoopmedia-develop.go-vip.net\/cyberscoop\/software-liability-biden-microsoft-vulnerabilities\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Can a White House initiative compel tech companies to write safer code?\" \/>\n<meta property=\"og:description\" content=\"Software liability reform is a centerpiece of the Biden&#039;s recent national cybersecurity strategy. implementing it will be a challenge.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/scoopmedia-develop.go-vip.net\/cyberscoop\/software-liability-biden-microsoft-vulnerabilities\/\" \/>\n<meta property=\"og:site_name\" content=\"CyberScoop\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/cyberscoop\/\" \/>\n<meta property=\"article:published_time\" content=\"2023-03-31T15:34:09+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/scoopmedia-develop.go-vip.net\/cyberscoop\/wp-content\/uploads\/sites\/3\/2023\/03\/GettyImages-1459359048.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1920\" \/>\n\t<meta property=\"og:image:height\" content=\"1211\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"eliasgroll\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@CyberScoopNews\" \/>\n<meta name=\"twitter:site\" content=\"@CyberScoopNews\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/scoopmedia-develop.go-vip.net\\\/cyberscoop\\\/software-liability-biden-microsoft-vulnerabilities\\\/\",\"url\":\"https:\\\/\\\/scoopmedia-develop.go-vip.net\\\/cyberscoop\\\/software-liability-biden-microsoft-vulnerabilities\\\/\",\"name\":\"Can a White House initiative compel tech companies to write safer code? | CyberScoop\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/scoopmedia-develop.go-vip.net\\\/cyberscoop\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/scoopmedia-develop.go-vip.net\\\/cyberscoop\\\/software-liability-biden-microsoft-vulnerabilities\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/scoopmedia-develop.go-vip.net\\\/cyberscoop\\\/software-liability-biden-microsoft-vulnerabilities\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/scoopmedia-develop.go-vip.net\\\/cyberscoop\\\/wp-content\\\/uploads\\\/sites\\\/3\\\/2023\\\/03\\\/GettyImages-1459359048.jpg\",\"datePublished\":\"2023-03-31T15:34:09+00:00\",\"description\":\"Software liability reform is a centerpiece of the Biden's recent national cybersecurity strategy. implementing it will be a challenge.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/scoopmedia-develop.go-vip.net\\\/cyberscoop\\\/software-liability-biden-microsoft-vulnerabilities\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/scoopmedia-develop.go-vip.net\\\/cyberscoop\\\/software-liability-biden-microsoft-vulnerabilities\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/scoopmedia-develop.go-vip.net\\\/cyberscoop\\\/software-liability-biden-microsoft-vulnerabilities\\\/#primaryimage\",\"url\":\"https:\\\/\\\/scoopmedia-develop.go-vip.net\\\/cyberscoop\\\/wp-content\\\/uploads\\\/sites\\\/3\\\/2023\\\/03\\\/GettyImages-1459359048.jpg\",\"contentUrl\":\"https:\\\/\\\/scoopmedia-develop.go-vip.net\\\/cyberscoop\\\/wp-content\\\/uploads\\\/sites\\\/3\\\/2023\\\/03\\\/GettyImages-1459359048.jpg\",\"width\":1920,\"height\":1211,\"caption\":\"The Microsoft logo is visible through a grid of its French headquarters on Jan. 25, 2023 in Issy-les-Moulineaux. (Photo by Chesnot\\\/Getty Images)\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/scoopmedia-develop.go-vip.net\\\/cyberscoop\\\/software-liability-biden-microsoft-vulnerabilities\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/scoopmedia-develop.go-vip.net\\\/cyberscoop\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Can a White House initiative compel tech companies to write safer code?\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/scoopmedia-develop.go-vip.net\\\/cyberscoop\\\/#website\",\"url\":\"https:\\\/\\\/scoopmedia-develop.go-vip.net\\\/cyberscoop\\\/\",\"name\":\"CyberScoop\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/scoopmedia-develop.go-vip.net\\\/cyberscoop\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/scoopmedia-develop.go-vip.net\\\/cyberscoop\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/scoopmedia-develop.go-vip.net\\\/cyberscoop\\\/#organization\",\"name\":\"CyberScoop\",\"url\":\"https:\\\/\\\/scoopmedia-develop.go-vip.net\\\/cyberscoop\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/scoopmedia-develop.go-vip.net\\\/cyberscoop\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/scoopmedia-develop.go-vip.net\\\/cyberscoop\\\/wp-content\\\/uploads\\\/sites\\\/3\\\/2023\\\/01\\\/CyberScoop-Black.png\",\"contentUrl\":\"https:\\\/\\\/scoopmedia-develop.go-vip.net\\\/cyberscoop\\\/wp-content\\\/uploads\\\/sites\\\/3\\\/2023\\\/01\\\/CyberScoop-Black.png\",\"width\":1545,\"height\":186,\"caption\":\"CyberScoop\"},\"image\":{\"@id\":\"https:\\\/\\\/scoopmedia-develop.go-vip.net\\\/cyberscoop\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/cyberscoop\\\/\",\"https:\\\/\\\/x.com\\\/CyberScoopNews\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/cyberscoop\\\/\",\"https:\\\/\\\/www.youtube.com\\\/channel\\\/UCDG2jjHiZ8r97MCVnsaAkXw\"]}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Can a White House initiative compel tech companies to write safer code? | CyberScoop","description":"Software liability reform is a centerpiece of the Biden's recent national cybersecurity strategy. implementing it will be a challenge.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/scoopmedia-develop.go-vip.net\/cyberscoop\/software-liability-biden-microsoft-vulnerabilities\/","og_locale":"en_US","og_type":"article","og_title":"Can a White House initiative compel tech companies to write safer code?","og_description":"Software liability reform is a centerpiece of the Biden's recent national cybersecurity strategy. implementing it will be a challenge.","og_url":"https:\/\/scoopmedia-develop.go-vip.net\/cyberscoop\/software-liability-biden-microsoft-vulnerabilities\/","og_site_name":"CyberScoop","article_publisher":"https:\/\/www.facebook.com\/cyberscoop\/","article_published_time":"2023-03-31T15:34:09+00:00","og_image":[{"width":1920,"height":1211,"url":"https:\/\/scoopmedia-develop.go-vip.net\/cyberscoop\/wp-content\/uploads\/sites\/3\/2023\/03\/GettyImages-1459359048.jpg","type":"image\/jpeg"}],"author":"eliasgroll","twitter_card":"summary_large_image","twitter_creator":"@CyberScoopNews","twitter_site":"@CyberScoopNews","schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/scoopmedia-develop.go-vip.net\/cyberscoop\/software-liability-biden-microsoft-vulnerabilities\/","url":"https:\/\/scoopmedia-develop.go-vip.net\/cyberscoop\/software-liability-biden-microsoft-vulnerabilities\/","name":"Can a White House initiative compel tech companies to write safer code? | CyberScoop","isPartOf":{"@id":"https:\/\/scoopmedia-develop.go-vip.net\/cyberscoop\/#website"},"primaryImageOfPage":{"@id":"https:\/\/scoopmedia-develop.go-vip.net\/cyberscoop\/software-liability-biden-microsoft-vulnerabilities\/#primaryimage"},"image":{"@id":"https:\/\/scoopmedia-develop.go-vip.net\/cyberscoop\/software-liability-biden-microsoft-vulnerabilities\/#primaryimage"},"thumbnailUrl":"https:\/\/scoopmedia-develop.go-vip.net\/cyberscoop\/wp-content\/uploads\/sites\/3\/2023\/03\/GettyImages-1459359048.jpg","datePublished":"2023-03-31T15:34:09+00:00","description":"Software liability reform is a centerpiece of the Biden's recent national cybersecurity strategy. implementing it will be a challenge.","breadcrumb":{"@id":"https:\/\/scoopmedia-develop.go-vip.net\/cyberscoop\/software-liability-biden-microsoft-vulnerabilities\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/scoopmedia-develop.go-vip.net\/cyberscoop\/software-liability-biden-microsoft-vulnerabilities\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/scoopmedia-develop.go-vip.net\/cyberscoop\/software-liability-biden-microsoft-vulnerabilities\/#primaryimage","url":"https:\/\/scoopmedia-develop.go-vip.net\/cyberscoop\/wp-content\/uploads\/sites\/3\/2023\/03\/GettyImages-1459359048.jpg","contentUrl":"https:\/\/scoopmedia-develop.go-vip.net\/cyberscoop\/wp-content\/uploads\/sites\/3\/2023\/03\/GettyImages-1459359048.jpg","width":1920,"height":1211,"caption":"The Microsoft logo is visible through a grid of its French headquarters on Jan. 25, 2023 in Issy-les-Moulineaux. (Photo by Chesnot\/Getty Images)"},{"@type":"BreadcrumbList","@id":"https:\/\/scoopmedia-develop.go-vip.net\/cyberscoop\/software-liability-biden-microsoft-vulnerabilities\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/scoopmedia-develop.go-vip.net\/cyberscoop\/"},{"@type":"ListItem","position":2,"name":"Can a White House initiative compel tech companies to write safer code?"}]},{"@type":"WebSite","@id":"https:\/\/scoopmedia-develop.go-vip.net\/cyberscoop\/#website","url":"https:\/\/scoopmedia-develop.go-vip.net\/cyberscoop\/","name":"CyberScoop","description":"","publisher":{"@id":"https:\/\/scoopmedia-develop.go-vip.net\/cyberscoop\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/scoopmedia-develop.go-vip.net\/cyberscoop\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/scoopmedia-develop.go-vip.net\/cyberscoop\/#organization","name":"CyberScoop","url":"https:\/\/scoopmedia-develop.go-vip.net\/cyberscoop\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/scoopmedia-develop.go-vip.net\/cyberscoop\/#\/schema\/logo\/image\/","url":"https:\/\/scoopmedia-develop.go-vip.net\/cyberscoop\/wp-content\/uploads\/sites\/3\/2023\/01\/CyberScoop-Black.png","contentUrl":"https:\/\/scoopmedia-develop.go-vip.net\/cyberscoop\/wp-content\/uploads\/sites\/3\/2023\/01\/CyberScoop-Black.png","width":1545,"height":186,"caption":"CyberScoop"},"image":{"@id":"https:\/\/scoopmedia-develop.go-vip.net\/cyberscoop\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/cyberscoop\/","https:\/\/x.com\/CyberScoopNews","https:\/\/www.linkedin.com\/company\/cyberscoop\/","https:\/\/www.youtube.com\/channel\/UCDG2jjHiZ8r97MCVnsaAkXw"]}]}},"distributor_meta":false,"distributor_terms":false,"distributor_media":false,"distributor_original_site_name":"CyberScoop","distributor_original_site_url":"https:\/\/scoopmedia-develop.go-vip.net\/cyberscoop","push-errors":false,"jetpack_featured_media_url":"https:\/\/scoopmedia-develop.go-vip.net\/cyberscoop\/wp-content\/uploads\/sites\/3\/2023\/03\/GettyImages-1459359048.jpg","_links":{"self":[{"href":"https:\/\/scoopmedia-develop.go-vip.net\/cyberscoop\/wp-json\/wp\/v2\/posts\/72555","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/scoopmedia-develop.go-vip.net\/cyberscoop\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/scoopmedia-develop.go-vip.net\/cyberscoop\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/scoopmedia-develop.go-vip.net\/cyberscoop\/wp-json\/wp\/v2\/users\/595"}],"replies":[{"embeddable":true,"href":"https:\/\/scoopmedia-develop.go-vip.net\/cyberscoop\/wp-json\/wp\/v2\/comments?post=72555"}],"version-history":[{"count":17,"href":"https:\/\/scoopmedia-develop.go-vip.net\/cyberscoop\/wp-json\/wp\/v2\/posts\/72555\/revisions"}],"predecessor-version":[{"id":72789,"href":"https:\/\/scoopmedia-develop.go-vip.net\/cyberscoop\/wp-json\/wp\/v2\/posts\/72555\/revisions\/72789"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/scoopmedia-develop.go-vip.net\/cyberscoop\/wp-json\/wp\/v2\/media\/72731"}],"wp:attachment":[{"href":"https:\/\/scoopmedia-develop.go-vip.net\/cyberscoop\/wp-json\/wp\/v2\/media?parent=72555"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/scoopmedia-develop.go-vip.net\/cyberscoop\/wp-json\/wp\/v2\/categories?post=72555"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/scoopmedia-develop.go-vip.net\/cyberscoop\/wp-json\/wp\/v2\/tags?post=72555"},{"taxonomy":"people","embeddable":true,"href":"https:\/\/scoopmedia-develop.go-vip.net\/cyberscoop\/wp-json\/wp\/v2\/people?post=72555"},{"taxonomy":"special-report","embeddable":true,"href":"https:\/\/scoopmedia-develop.go-vip.net\/cyberscoop\/wp-json\/wp\/v2\/special-report?post=72555"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/scoopmedia-develop.go-vip.net\/cyberscoop\/wp-json\/wp\/v2\/authors?post=72555"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}