Brave Warned the U.S. Government of Security Issues in an Open Letter


Brave has been on a mission. A mission to secure the internet for users around the world. Security is a priority for the Brave team--warning regulatory bodies, those vulnerable to web attacks, and further prevent any risks to web users is effectively a motto at Brave.

This motto has been proven time and time again through research, development, and finally product releases such as Brave Browser.

Brave is taking this productivity a level further, and is now in the business of warning U.S. government officials (congressional members & members of the U.S. Senate). Brave has indicated to U.S. government officials, that their web habits as they know to be safe today, really aren't safe at-all.

I've provided the letter below, as provided by the Brave team on: https://brave.com/malvertising-homeland-security/

Letter:

_______________________________________________

The Hon. Ron Johnson, Chairman, Homeland Security and Homeland Security and Governmental Affairs Committee
The Hon. Gary Peters. Ranking Member, Homeland Security and Homeland Security and Governmental Affairs Committee
The Hon. Bennie G. Thompson, Chairman,  House Homeland Security Committee
The Hon. Mike Rogers, Ranking Member, House Homeland Security Committee

13 November 2019

Re: “Malvertising” cybersecurity threat to US federal agency and employee devices. 

Dear Senator Johnson, Senator Peters, Congressman Thompson, and Congressman Rogers,

I represent Brave, a rapidly growing Internet browser based in San Francisco. Brave’s CEO, Brendan Eich, is the inventor of JavaScript, and co-founded Mozilla/Firefox. Brave is headquartered in San Francisco. I write to urge action to protect federal agency and employee computers and devices from cyberattacks by foreign state actors and criminals through “malvertising”.

This issue has been the subject of public guidance from the National Security Agency, which I attach for your convenience.

The NSA warned in June 2018 that foreign state actors can execute software on US government computers by buying targeted ads and including malicious code in the body of the ad being delivered. Government computers and devices are vulnerable to these malvertising attacks because the web browsers used by government agencies do not automatically block such ads.

The NSA warns that “web browsers present a major cyber security risk” and that “‘malvertising’ allows a malicious actor to target users based on location, interests, browsing habits, and system specific identifiers…”.

In 2017, Senator Wyden requested that the Department of Homeland Security issue a binding operational directive to require that all agencies block internet ads containing executable code. Senator Wyden renewed this call again in December 2018. These letters are also attached herewith for your convenience.

Two years have passed since Senator Wyden highlighted the acute threat posed by malvertising. Indeed, as the NSA notes, “advertising has been a known malware distribution vector for over a decade”. Despite this, computers and devices at federal agencies remain vulnerable. It should not be possible for a foreign spy to pull out a credit card and buy the ability to run executable software code on US Government devices.

Individual employees appear to have to decide for themselves whether to take measures to protect their organizations from malvertising cyberattack. The table below shows the diverse range of protection provided by web browsers.

Given the serious national security threat posed by advertisements, and the advertising industry’s failure to meaningfully address this threat, we urge your Committees to direct the Department of Homeland Security and the National Institute of Standards and Technology to review the vulnerability of web browsers to malvertising, and guide federal agencies on what browsers expose them to risk.

Download table (PDF)

In 2018 the NSA recommended that all federal agencies “address malvertising by blocking potentially malicious, internet-based advertisements”. Every federal employee should be provided with a web browser that blocks the malvertising threat by default. It is now time to make this mandatory.

Allow me to take this opportunity to draw to your attention that Brave 1.0 launches on all platforms today.

Sincerely,

 

 

Dr Johnny Ryan

Chief Policy & Industry Relations Officer
Brave Software Inc.

CC:
Senator Ron Wyden.
General Paul M. Nakasone, Director,US National Security Agency.
Christopher Krebs, Director, US Cybersecurity and Infrastructure Security Agency.
Dr. Walter G. Copan, Director, US National Institute of Standards and Technology.

_______________________________________________

 

This letter, provided by the Brave team makes me proud to be both a Brave/BAT user, but a BAT holder, and a future content creator as well (utilizing Brave of course)!

The ethical ideas that motivate the team over at Brave to keep moving forward with their project on a fundamental, and game-changing level.

U.S. regulators owe it to Brave to take what they're saying seriously, as the team is a seriously intelligent set of individuals.

How do you rate this article?

0


Generative Capital
Generative Capital

Builder, & Product/Growth Consultant


Blockchain Simplified
Blockchain Simplified

Blockchain is an increasingly popular technology--A technology that has and continues to captivate a wide-spectrum of demographic in a short period of time. Stay up to date with everything blockchain related & Follow Today!

Publish0x

Send a $0.01 microtip in crypto to the author, and earn yourself as you read!

20% to author / 80% to me.
We pay the tips from our rewards pool.