{"id":6234,"date":"2024-11-14T06:00:00","date_gmt":"2024-11-14T12:00:00","guid":{"rendered":"https:\/\/cyberscoop.com\/?p=82595"},"modified":"2024-11-14T06:00:00","modified_gmt":"2024-11-14T12:00:00","slug":"the-un-cybercrime-convention-threatens-security-research-the-us-should-do-something-about-it","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/11\/14\/the-un-cybercrime-convention-threatens-security-research-the-us-should-do-something-about-it\/","title":{"rendered":"The UN cybercrime convention threatens security research. The US should do something about it"},"content":{"rendered":"<p><head> <meta charset=\"UTF-8\"> <meta name=\"viewport\" content=\"width=device-width, initial-scale=1\"> <meta name=\"robots\" content=\"index, follow, max-image-preview:large, max-snippet:-1, max-video-preview:-1\"> <!-- This site is optimized with the Yoast SEO Premium plugin v21.7 (Yoast SEO v21.7) - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ --> <title>The UN cybercrime convention threatens security research. The US should do something about it | CyberScoop<\/title> <meta name=\"description\" content=\"The United Nation's cybercrime treaty's broad and ambiguous language risks stifling vital cybersecurity work.\"> <link rel=\"canonical\" href=\"https:\/\/cyberscoop.com\/un-cybercrime-treaty-threatens-security-research-ilona-cohen-op-ed\/\"> <meta property=\"og:locale\" content=\"en_US\"> <meta property=\"og:type\" content=\"article\"> <meta property=\"og:title\" content=\"The UN cybercrime convention threatens security research. The US should do something about it\"> <meta property=\"og:description\" content=\"The United Nation's cybercrime treaty's broad and ambiguous language risks stifling vital cybersecurity work.\"> <meta property=\"og:url\" content=\"https:\/\/cyberscoop.com\/un-cybercrime-treaty-threatens-security-research-ilona-cohen-op-ed\/\"> <meta property=\"og:site_name\" content=\"CyberScoop\"> <meta property=\"article:published_time\" content=\"2024-11-14T12:00:00+00:00\"> <meta property=\"article:modified_time\" content=\"2024-11-13T18:23:51+00:00\"> <meta property=\"og:image\" content=\"https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/11\/the-un-cybercrime-convention-threatens-security-research-the-us-should-do-something-about-it-5.jpg\"> <meta property=\"og:image:width\" content=\"2121\"> <meta property=\"og:image:height\" content=\"1193\"> <meta property=\"og:image:type\" content=\"image\/jpeg\"> <meta name=\"author\" content=\"Greg Otto\"> <meta name=\"twitter:card\" content=\"summary_large_image\"> <meta name=\"twitter:creator\" content=\"@gregotto\"> <!-- \/ Yoast SEO Premium plugin. --> <link rel=\"dns-prefetch\" href=\"\/\/securepubads.g.doubleclick.net\">\n<link rel=\"dns-prefetch\" href=\"\/\/use.typekit.net\">\n<link rel=\"alternate\" type=\"application\/rss+xml\" title=\"CyberScoop \u00bb Feed\" href=\"https:\/\/cyberscoop.com\/feed\/\">\n<link rel=\"alternate\" type=\"application\/rss+xml\" title=\"CyberScoop \u00bb Comments Feed\" href=\"https:\/\/cyberscoop.com\/comments\/feed\/\"> <link rel=\"stylesheet\" id=\"all-css-2\" href=\"https:\/\/cyberscoop.com\/wp-includes\/css\/dist\/block-library\/style.min.css?m=1731444340g\" type=\"text\/css\" media=\"all\"> <link rel=\"stylesheet\" id=\"all-css-6\" href=\"https:\/\/cyberscoop.com\/wp-content\/mu-plugins\/search\/elasticpress\/dist\/css\/related-posts-block-styles.min.css?m=1730917128g\" type=\"text\/css\" media=\"all\"> <link rel=\"stylesheet\" id=\"all-css-8\" href=\"https:\/\/cyberscoop.com\/wp-content\/themes\/scoopnewsgroup\/dist\/css\/frontend.css?m=1731517106g\" type=\"text\/css\" media=\"all\">\n<link rel=\"stylesheet\" id=\"typekit-css\" href=\"https:\/\/use.typekit.net\/itk2qbh.css?ver=268fd554331a9a76f78c\" media=\"all\"> <link rel=\"https:\/\/api.w.org\/\" href=\"https:\/\/cyberscoop.com\/wp-json\/\"><link rel=\"alternate\" title=\"JSON\" type=\"application\/json\" href=\"https:\/\/cyberscoop.com\/wp-json\/wp\/v2\/posts\/82595\"><link rel=\"EditURI\" type=\"application\/rsd+xml\" title=\"RSD\" href=\"https:\/\/cyberscoop.com\/xmlrpc.php?rsd\">\n<meta name=\"generator\" content=\"WordPress 6.7\">\n<link rel=\"shortlink\" href=\"https:\/\/cyberscoop.com\/?p=82595\">\n<link rel=\"alternate\" title=\"oEmbed (JSON)\" type=\"application\/json+oembed\" href=\"https:\/\/cyberscoop.com\/wp-json\/oembed\/1.0\/embed?url=https%3A%2F%2Fcyberscoop.com%2Fun-cybercrime-treaty-threatens-security-research-ilona-cohen-op-ed%2F\">\n<link rel=\"alternate\" title=\"oEmbed (XML)\" type=\"text\/xml+oembed\" href=\"https:\/\/cyberscoop.com\/wp-json\/oembed\/1.0\/embed?url=https%3A%2F%2Fcyberscoop.com%2Fun-cybercrime-treaty-threatens-security-research-ilona-cohen-op-ed%2F&amp;format=xml\"> <!-- Google Tag Manager --> <!-- End Google Tag Manager --> <link rel=\"icon\" href=\"https:\/\/cyberscoop.com\/wp-content\/uploads\/sites\/3\/2023\/01\/cropped-cs_favicon-2.png?w=32\" sizes=\"32x32\">\n<link rel=\"icon\" href=\"https:\/\/cyberscoop.com\/wp-content\/uploads\/sites\/3\/2023\/01\/cropped-cs_favicon-2.png?w=192\" sizes=\"192x192\">\n<link rel=\"apple-touch-icon\" href=\"https:\/\/cyberscoop.com\/wp-content\/uploads\/sites\/3\/2023\/01\/cropped-cs_favicon-2.png?w=180\">\n<meta name=\"msapplication-TileImage\" content=\"https:\/\/cyberscoop.com\/wp-content\/uploads\/sites\/3\/2023\/01\/cropped-cs_favicon-2.png?w=270\"> <\/head><body class=\"post-template-default single single-post postid-82595 single-format-standard\" id=\"readabilityBody\"> <a href=\"https:\/\/cyberscoop.com\/un-cybercrime-treaty-threatens-security-research-ilona-cohen-op-ed\/#main\" class=\"skip-to-content-link visually-hidden-focusable\">Skip to main content<\/a> <\/p>\n<div class=\"ad ad--top ad--top-desktop\">\n<div class=\"ad__inner\"> <span class=\"screen-reader-text\">Advertisement<\/span> <\/div>\n<\/div>\n<p> <main id=\"main\" role=\"main\" tabindex=\"-1\"> <\/p>\n<div class=\"ad ad--top ad--top-mobile\">\n<div class=\"ad__inner\"> <span class=\"screen-reader-text\">Advertisement<\/span> <\/div>\n<\/div>\n<section id=\"stickybar\" class=\"stickybar stickybar--newsletter js-stickybar\" readability=\"0.82\"> <button class=\"stickybar__close js-stickybar-close\" aria-controls=\"stickybar\"> <svg class=\"icon icon--close\" width=\"21\" height=\"22\" viewBox=\"0 0 21 22\" fill=\"none\"><path d=\"m.822.518-.805.805L9.695 11 .017 20.678l.805.805 9.678-9.678 9.677 9.678.806-.805L11.305 11l9.678-9.677-.806-.805-9.677 9.677L.822.518Z\" fill=\"currentColor\" \/><\/svg> <span class=\"visually-hidden\">Close<\/span> <\/button> <\/section>\n<article class=\"single-article content\">\n<div class=\"single-article__container js-single-article-content\">\n<header class=\"single-article__header \" readability=\"24.641791044776\">\n<div class=\"single-article__header-content\" readability=\"32.97520661157\">\n<ul class=\"single-article__eyebrow\">\n<li class=\"single-article__category\"> <a class=\"single-article__category-link\" href=\"https:\/\/cyberscoop.com\/news\/commentary\/\"> <span>Commentary<\/span> <\/a> <\/li>\n<\/ul>\n<p> The UN treaty&#8217;s broad and ambiguous language risks stifling vital work. <\/p>\n<p> <!-- Listen to this article section --> <!-- Audio Element --><br \/>\n<audio id=\"audio-player\" src=\"https:\/\/wp-tts-cdn.api.scpnewsgrp.com\/cyberscoop\/82595\/english.openai.mp3\"><\/audio> <\/p>\n<div readability=\"11\">\n<div>\n<p>Listen to this article<\/p>\n<p> <!-- Countdown Timer --> <\/p>\n<p>0:00<\/p>\n<\/p><\/div>\n<p> <!-- Tooltip --> <\/p>\n<p> <span id=\"tts-tooltip\">Learn more.<\/span> <span> This feature uses an automated voice, which may result in occasional errors in pronunciation, tone, or sentiment. <\/span> <\/p>\n<\/div>\n<p> <!-- End of audio player --> <\/div>\n<div class=\"single-article__cover-wrap\">\n<figure class=\"single-article__cover\"> <img data-recalc-dims=\"1\" fetchpriority=\"high\" width=\"640\" height=\"360\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/11\/the-un-cybercrime-convention-threatens-security-research-the-us-should-do-something-about-it.jpg?resize=640%2C360&#038;ssl=1\" class=\"single-article__cover-image wp-post-image\" alt=\"cyber norms\" decoding=\"async\" fetchpriority=\"high\" srcset=\"https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/11\/the-un-cybercrime-convention-threatens-security-research-the-us-should-do-something-about-it-5.jpg 2121w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/11\/the-un-cybercrime-convention-threatens-security-research-the-us-should-do-something-about-it-5.jpg?resize=300,168 300w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/11\/the-un-cybercrime-convention-threatens-security-research-the-us-should-do-something-about-it-5.jpg?resize=768,432 768w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/11\/the-un-cybercrime-convention-threatens-security-research-the-us-should-do-something-about-it-5.jpg?resize=1024,576 1024w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/11\/the-un-cybercrime-convention-threatens-security-research-the-us-should-do-something-about-it-5.jpg?resize=1536,864 1536w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/11\/the-un-cybercrime-convention-threatens-security-research-the-us-should-do-something-about-it-5.jpg?resize=2048,1152 2048w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/11\/the-un-cybercrime-convention-threatens-security-research-the-us-should-do-something-about-it-5.jpg?resize=600,337 600w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/11\/the-un-cybercrime-convention-threatens-security-research-the-us-should-do-something-about-it-5.jpg?resize=1200,675 1200w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/11\/the-un-cybercrime-convention-threatens-security-research-the-us-should-do-something-about-it-5.jpg?resize=1500,843 1500w\" sizes=\"(max-width: 1200px) 100vw, 1200px\"><figcaption> The United Nations flag (Getty Images) <\/figcaption><\/figure>\n<\/p><\/div>\n<\/header>\n<div class=\"single-article__content\">\n<div class=\"single-article__content-inner has-drop-cap\"> <html readability=\"63.663014088516\"><body readability=\"127.40809248555\"><\/p>\n<p>The United Nations\u2019 recent adoption of a new cybercrime convention has sparked significant discussion within the global cybersecurity community. While the<a href=\"https:\/\/documents.un.org\/doc\/undoc\/gen\/v24\/055\/06\/pdf\/v2405506.pdf\"> UN Convention Against Cybercrime<\/a> aims to enhance international cooperation to combat malicious hacking, the convention raises serious concerns for those involved in security research and ethical hacking.&nbsp;<\/p>\n<p>The treaty\u2019s provisions related to security research conflict with best practices encouraged by the U.S. government and federal policies that protect good-faith security research from prosecution. Despite these and other concerns, the treaty is expected to receive final approval from the General Assembly by the end of the year.<\/p>\n<p>Though this treaty will not directly alter existing computer crime laws, nations with less-developed cybercrime laws may pass regulations that mirror the text of the UN\u2019s convention, and authoritarian governments may use the flawed text of the convention to justify suppression and censorship of security researchers and others.<\/p>\n<p>Security researchers operating in or collaborating with entities in countries with fewer protections for good-faith security research and ethical hacking may find themselves at heightened risk of potential legal consequences for activities that are both ethical and essential to maintaining global cybersecurity.&nbsp;<\/p>\n<div class=\"ad ad--inline_1 \">\n<div class=\"ad__inner\"> <span class=\"screen-reader-text\">Advertisement<\/span> <\/div>\n<\/div>\n<p>For this reason, it is critically important that the United States work with other countries to encourage the incorporation of protections for such research into national law or law enforcement policies and practices.<\/p>\n<h4 class=\"wp-block-heading\" id=\"h-chilling-innovation-and-reducing-security\"><strong>Chilling innovation and reducing security<\/strong><\/h4>\n<p>Good-faith security researchers, also called ethical hackers, play a crucial role in the fight against cybercrime. These individuals identify vulnerabilities in software, systems, and networks, so that they can be patched or mitigated before malicious actors can exploit them.&nbsp;<\/p>\n<p>Legal frameworks increasingly support the efforts of security researchers by distinguishing them from malicious cybercriminals, reducing legal liability for ethical hacking, and incentivizing organizations to adopt policies to receive vulnerability disclosures. For example, the United States since 2020 has directed all federal agencies to have vulnerability disclosure policies. The U.S. Department of Justice has long recognized the importance of security research and recently announced that it will update its Vulnerability Disclosure Framework, which minimized legal jeopardy for security researchers, to address the reporting of vulnerabilities for AI systems.<\/p>\n<p>However, the UN treaty\u2019s broad and ambiguous language risks stifling this vital work. The treaty obligates countries to criminalize anyone that intentionally gains access to any part of a computer system \u201cwithout right.\u201d While purportedly intended to prevent malicious hacking, the article makes no distinction between cybercriminals and legitimate security testing activities performed by ethical hackers who do not have explicit permission but are working to enhance security.&nbsp;<\/p>\n<div class=\"ad ad--inline_1 \">\n<div class=\"ad__inner\"> <span class=\"screen-reader-text\">Advertisement<\/span> <\/div>\n<\/div>\n<p>The language in the convention also prohibits intercepting non-public transmissions of computer data \u201cwithout right.\u201d This ignores the intent of the intrusion and can implicate independent security professionals who, in the course of their work, may intercept signals to identify or validate security vulnerabilities to protect, not exploit, the data.&nbsp;<\/p>\n<p>It also outlaws the intentional damaging, deletion, or alteration of computer data \u201cwithout right.\u201d This article could be misapplied to ethical hackers who manipulate data as part of a controlled test, such as penetration-testing and red-teaming, to identify weaknesses and improve system defenses.&nbsp;<\/p>\n<p>The treaty criminalizes the intentional and unauthorized hindering of the functioning of a computer system. This could also be detrimental to security research or red-teaming activities, which utilize simulated attacks to identify security weaknesses and improve defenses. Such activities could be considered \u201cinterference\u201d under this broad definition, potentially subjecting ethical hackers to legal risks even when their actions are aimed at enhancing security.<\/p>\n<p>Translating these provisions into criminal laws without explicit protections or clarifications could discourage legitimate security testing, ultimately making systems less secure and more vulnerable to real cyber threats. Rather than promoting the convention\u2019s stated aim of increasing coordination and cooperation, this could lead to inconsistent application and misuse of the treaty, leaving researchers vulnerable in jurisdictions that do not explicitly safeguard good-faith activities.<\/p>\n<h4 class=\"wp-block-heading\" id=\"h-the-path-forward\"><strong>The path forward<\/strong><\/h4>\n<div class=\"ad ad--inline_1 \">\n<div class=\"ad__inner\"> <span class=\"screen-reader-text\">Advertisement<\/span> <\/div>\n<\/div>\n<p>The treaty encourages signatories to recognize the contributions of legitimate security researchers, provided their activities are intended to strengthen and improve security to the extent permitted by law. While this acknowledgment is a positive step, it falls far short of encouraging signatories to establish legal protections for legitimate security research.&nbsp;<\/p>\n<p>Because recognition of security researchers\u2019 vital work is not consistently reflected in the treaty\u2019s restrictions on computer access and use and translated into meaningful protections for researchers, it will be up to member countries to do so in national laws or through guidelines and best practices that companies and law enforcement officials can follow.<\/p>\n<p>While it may be too late to improve the text of this treaty, the United States can and should contribute its knowledge and experience in protecting security research and bring focus and energy to the adoption of similar practices in other countries. This can be accomplished in several ways.&nbsp;<\/p>\n<p>For example, the U.S. Agency for International Development and the State Department could incorporate protections for security research into their cybersecurity capacity-building programs. Alternatively, they could condition digital capacity-building funds on the commitments from governments that they will not prosecute good-faith security researchers.&nbsp;<\/p>\n<p>The U.S. should also partner with nongovernmental capacity-building organizations and like-minded governments to develop and disseminate best practices for implementing the treaty that recognize the importance and benefits of security research and differentiate ethical research from cybercrime.<\/p>\n<div class=\"ad ad--inline_1 \">\n<div class=\"ad__inner\"> <span class=\"screen-reader-text\">Advertisement<\/span> <\/div>\n<\/div>\n<p>Taking these and other steps will help ensure that policymakers around the world are aware of the treaty\u2019s implications for security research and encourage them to adapt their legal frameworks to support, rather than hinder, ethical hacking. By doing so, nations can foster a cooperative environment where the essential work of security researchers is valued and encouraged, ultimately strengthening our collective defenses against cyber threats.<\/p>\n<p><em>Ilona Cohen is the chief legal and policy officer at HackerOne.<\/em><\/p>\n<p> <\/body> <\/p>\n<footer class=\"single-article__footer\" readability=\"0.95283018867925\">\n<div class=\"author-card\" readability=\"7\">\n<div class=\"author-card__avatar\">\n<figure class=\"author-card__image-wrap\"> <img data-recalc-dims=\"1\" decoding=\"async\" class=\"author-card__image\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/11\/the-un-cybercrime-convention-threatens-security-research-the-us-should-do-something-about-it-1.jpg?w=640&#038;ssl=1\" alt=\"Ilona Cohen\"> <\/figure>\n<\/p><\/div>\n<p><h4 class=\"author-card__name\">Written by Ilona Cohen<\/h4>\n<p> Ilona Cohen is the chief legal and policy officer at HackerOne. <\/p>\n<\/p><\/div>\n<div class=\"single-article__tags-container\">\n<h4 class=\"single-article__tags-title\">In This Story<\/h4>\n<\/p><\/div>\n<\/footer>\n<p> <\/html><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"single-article__ads js-single-article-sidebar\">\n<div class=\"ad ad--sidebar js-single-article-sidebar-5 ad--rightrail_1 \">\n<div class=\"ad__inner\"> <span class=\"screen-reader-text\">Advertisement<\/span> <\/div>\n<\/div>\n<div class=\"ad ad--sidebar js-single-article-sidebar-4 ad--rightrail_2 \">\n<div class=\"ad__inner\"> <span class=\"screen-reader-text\">Advertisement<\/span> <\/div>\n<\/div>\n<div class=\"ad ad--sidebar js-single-article-sidebar-3 ad--rightrail_3 \">\n<div class=\"ad__inner\"> <span class=\"screen-reader-text\">Advertisement<\/span> <\/div>\n<\/div><\/div>\n<\/article>\n<div class=\"popular-stories popular-stories--single-post\">\n<div class=\"popular-stories__container\">\n<h2 class=\"popular-stories__title\"> More Scoops <\/h2>\n<div class=\"popular-stories__stories\">\n<div class=\"popular-stories__cards\">\n<article class=\"post-item post-item--popular-stories-cards \" readability=\"18.637223974763\">\n<figure class=\"post-item__thumbnail\"> <a class=\"post-item__thumbnail-link\" href=\"https:\/\/cyberscoop.com\/cybersecurity-deterrence-persistence-richard-harknett-dod-strategy\/\" tabindex=\"-1\"> <img data-recalc-dims=\"1\" loading=\"lazy\" width=\"506\" height=\"337\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/11\/the-un-cybercrime-convention-threatens-security-research-the-us-should-do-something-about-it-2.jpg?resize=506%2C337&#038;ssl=1\" class=\"attachment-ratio-16-9-md size-ratio-16-9-md wp-post-image\" alt=\"cyber flag\" decoding=\"async\" loading=\"lazy\" srcset=\"https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/11\/the-un-cybercrime-convention-threatens-security-research-the-us-should-do-something-about-it-6.jpg 1920w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/11\/the-un-cybercrime-convention-threatens-security-research-the-us-should-do-something-about-it-6.jpg?resize=300,200 300w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/11\/the-un-cybercrime-convention-threatens-security-research-the-us-should-do-something-about-it-6.jpg?resize=768,511 768w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/11\/the-un-cybercrime-convention-threatens-security-research-the-us-should-do-something-about-it-6.jpg?resize=1024,682 1024w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/11\/the-un-cybercrime-convention-threatens-security-research-the-us-should-do-something-about-it-6.jpg?resize=1536,1022 1536w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/11\/the-un-cybercrime-convention-threatens-security-research-the-us-should-do-something-about-it-6.jpg?resize=600,399 600w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/11\/the-un-cybercrime-convention-threatens-security-research-the-us-should-do-something-about-it-6.jpg?resize=252,168 252w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/11\/the-un-cybercrime-convention-threatens-security-research-the-us-should-do-something-about-it-6.jpg?resize=506,337 506w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/11\/the-un-cybercrime-convention-threatens-security-research-the-us-should-do-something-about-it-6.jpg?resize=1014,675 1014w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/11\/the-un-cybercrime-convention-threatens-security-research-the-us-should-do-something-about-it-6.jpg?resize=1266,843 1266w\" sizes=\"auto, (max-width: 506px) 100vw, 506px\"> <\/a><figcaption class=\"screen-reader-text\"> (DoD News \/ Flickr) <\/figcaption><\/figure>\n<header class=\"post-item__meta\" readability=\"3.8585858585859\">\n<h3 class=\"post-item__title\"> <a class=\"post-item__title-link\" href=\"https:\/\/cyberscoop.com\/cybersecurity-deterrence-persistence-richard-harknett-dod-strategy\/\"> America\u2019s allies are shifting: Cyberspace is about persistence, not deterrence <\/a> <\/h3>\n<p> Countries like the United Kingdom, Japan, and Canada are adopting the U.S.&#8217;s proactive cyber strategy to anticipate and mitigate vulnerabilities, reflecting a shift away from deterrence. <\/p>\n<div class=\"post-item__byline\"> <span class=\"post-item__author\"> <span>By <\/span> <a class=\"post-item__author-link\" href=\"https:\/\/cyberscoop.com\/author\/richard-j-harknett-ph-d\/\"> Richard J. Harknett, Ph.D. <\/a> <\/span> <\/div>\n<p><!-- .byline --> <\/header>\n<p><!-- .post-item__meta --> <\/article>\n<article class=\"post-item post-item--popular-stories-cards \">\n<figure class=\"post-item__thumbnail\"> <a class=\"post-item__thumbnail-link\" href=\"https:\/\/cyberscoop.com\/federal-contractor-vulnerability-disclosure-policies-senate-bil\/\" tabindex=\"-1\"> <img data-recalc-dims=\"1\" loading=\"lazy\" width=\"252\" height=\"168\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/11\/the-un-cybercrime-convention-threatens-security-research-the-us-should-do-something-about-it-3.jpg?resize=252%2C168&#038;ssl=1\" class=\"attachment-ratio-16-9-sm size-ratio-16-9-sm wp-post-image\" alt decoding=\"async\" loading=\"lazy\" srcset=\"https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/11\/the-un-cybercrime-convention-threatens-security-research-the-us-should-do-something-about-it-7.jpg 1024w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/11\/the-un-cybercrime-convention-threatens-security-research-the-us-should-do-something-about-it-7.jpg?resize=300,200 300w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/11\/the-un-cybercrime-convention-threatens-security-research-the-us-should-do-something-about-it-7.jpg?resize=768,512 768w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/11\/the-un-cybercrime-convention-threatens-security-research-the-us-should-do-something-about-it-7.jpg?resize=600,400 600w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/11\/the-un-cybercrime-convention-threatens-security-research-the-us-should-do-something-about-it-7.jpg?resize=252,168 252w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/11\/the-un-cybercrime-convention-threatens-security-research-the-us-should-do-something-about-it-7.jpg?resize=505,337 505w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/11\/the-un-cybercrime-convention-threatens-security-research-the-us-should-do-something-about-it-7.jpg?resize=1012,675 1012w\" sizes=\"auto, (max-width: 252px) 100vw, 252px\"> <\/a><figcaption class=\"screen-reader-text\"> Sen. Mark Warner, D-Va., speaks during a press conference in Washington, D.C., on March 20, 2018. From left, Sens. John Cornyn, James Lankford, Susan Collins and Richard Burr listen. (NICHOLAS KAMM\/AFP via Getty Images) <\/figcaption><\/figure>\n<header class=\"post-item__meta\">\n<h3 class=\"post-item__title\"> <a class=\"post-item__title-link\" href=\"https:\/\/cyberscoop.com\/federal-contractor-vulnerability-disclosure-policies-senate-bil\/\"> Vulnerability disclosure policies eyed for federal contractors in Senate bill <\/a> <\/h3>\n<div class=\"post-item__byline\"> <span class=\"post-item__author\"> <span>By <\/span> <a class=\"post-item__author-link\" href=\"https:\/\/cyberscoop.com\/author\/matt-bracken\/\"> Matt Bracken <\/a> <\/span> <\/div>\n<p><!-- .byline --> <\/header>\n<p><!-- .post-item__meta --> <\/article>\n<article class=\"post-item post-item--popular-stories-cards \">\n<figure class=\"post-item__thumbnail\"> <a class=\"post-item__thumbnail-link\" href=\"https:\/\/cyberscoop.com\/europe-cybersecurity-digital-sovereignty\/\" tabindex=\"-1\"> <img data-recalc-dims=\"1\" loading=\"lazy\" width=\"251\" height=\"168\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/11\/the-un-cybercrime-convention-threatens-security-research-the-us-should-do-something-about-it-4.jpg?resize=251%2C168&#038;ssl=1\" class=\"attachment-ratio-16-9-sm size-ratio-16-9-sm wp-post-image\" alt decoding=\"async\" loading=\"lazy\" srcset=\"https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/11\/the-un-cybercrime-convention-threatens-security-research-the-us-should-do-something-about-it-8.jpg 1920w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/11\/the-un-cybercrime-convention-threatens-security-research-the-us-should-do-something-about-it-8.jpg?resize=300,201 300w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/11\/the-un-cybercrime-convention-threatens-security-research-the-us-should-do-something-about-it-8.jpg?resize=768,514 768w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/11\/the-un-cybercrime-convention-threatens-security-research-the-us-should-do-something-about-it-8.jpg?resize=1024,685 1024w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/11\/the-un-cybercrime-convention-threatens-security-research-the-us-should-do-something-about-it-8.jpg?resize=1536,1027 1536w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/11\/the-un-cybercrime-convention-threatens-security-research-the-us-should-do-something-about-it-8.jpg?resize=600,401 600w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/11\/the-un-cybercrime-convention-threatens-security-research-the-us-should-do-something-about-it-8.jpg?resize=251,168 251w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/11\/the-un-cybercrime-convention-threatens-security-research-the-us-should-do-something-about-it-8.jpg?resize=504,337 504w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/11\/the-un-cybercrime-convention-threatens-security-research-the-us-should-do-something-about-it-8.jpg?resize=1009,675 1009w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/11\/the-un-cybercrime-convention-threatens-security-research-the-us-should-do-something-about-it-8.jpg?resize=1261,843 1261w\" sizes=\"auto, (max-width: 251px) 100vw, 251px\"> <\/a><figcaption class=\"screen-reader-text\"> A member of the Peoples Armed Police stands guard in front of the flag of the European Union at the European Delegation before a press conference by European Commission President Ursula von der Leyen on April 6, 2023 in Beijing, China. Von Der Leyen is on a two-day official visit to China and earlier in the day met with Chinese President Xi Jinping, Premier Li Qiang and other senior Chinese government officials (Photo by Kevin Frayer\/Getty Images) <\/figcaption><\/figure>\n<header class=\"post-item__meta\">\n<h3 class=\"post-item__title\"> <a class=\"post-item__title-link\" href=\"https:\/\/cyberscoop.com\/europe-cybersecurity-digital-sovereignty\/\"> Europe is trading security for digital sovereignty <\/a> <\/h3>\n<div class=\"post-item__byline\"> <span class=\"post-item__author\"> <span>By <\/span> <a class=\"post-item__author-link\" href=\"https:\/\/cyberscoop.com\/author\/konstantinos-komaitis\/\"> Konstantinos Komaitis <\/a> <\/span> <\/div>\n<p><!-- .byline --> <\/header>\n<p><!-- .post-item__meta --> <\/article>\n<\/p><\/div>\n<\/p><\/div>\n<p><!-- .popular-stories__stories --> <\/div>\n<p><!-- .popular-stories__inner -->\n<\/div>\n<p><!-- .popular-stories --> <\/p>\n<section class=\"latest-podcasts\">\n<h2 class=\"latest-podcasts__title\"> Latest Podcasts\t<\/h2>\n<\/section>\n<div class=\"top-categories\">\n<div class=\"top-categories__container\">\n<h3 class=\"top-categories__category-title\">Government<\/h3>\n<\/p><\/div>\n<div class=\"top-categories__container\">\n<h3 class=\"top-categories__category-title\">Technology<\/h3>\n<\/p><\/div>\n<div class=\"top-categories__container\">\n<h3 class=\"top-categories__category-title\">Geopolitics<\/h3>\n<\/p><\/div>\n<\/p><\/div>\n<p> <\/main> <\/p>\n<div class=\"ad ad--bottom \">\n<div class=\"ad__inner\"> <span class=\"screen-reader-text\">Advertisement<\/span> <\/div>\n<\/div>\n<div id=\"interstitial\" class=\"welcome__container\"> <button id=\"close-modal-1\" class=\"welcome__clickable_area\"><\/button> <\/p>\n<div class=\"welcome__ad_wrapper\">\n<p> <button id=\"close-modal-3\" class=\"welcome__continue-button\">Continue to CyberScoop<\/button> <\/p>\n<\/p><\/div>\n<\/p><\/div>\n<p> <!-- Start of HubSpot Embed Code --> <!-- End of HubSpot Embed Code --> <\/body> <a href=\"https:\/\/cyberscoop.com\/un-cybercrime-treaty-threatens-security-research-ilona-cohen-op-ed\/\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The UN cybercrime convention threatens security research. The US should<\/p>\n","protected":false},"author":11,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[280,78,302,2807,256],"tags":[284,86,306,2808,262],"class_list":["post-6234","post","type-post","status-publish","format-standard","hentry","category-commentary","category-cybersecurity","category-geopolitics","category-op-ed","category-research","tag-commentary","tag-cybersecurity","tag-geopolitics","tag-op-ed","tag-research"],"featured_image_urls":{"full":"","thumbnail":"","medium":"","medium_large":"","large":"","1536x1536":"","2048x2048":"","chromenews-featured":"","chromenews-large":"","chromenews-medium":""},"author_info":{"display_name":"Cyber Scoop","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/cyberscoop\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/commentary\/\" rel=\"category tag\">Commentary<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/cybersecurity\/\" rel=\"category tag\">Cybersecurity<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/geopolitics\/\" rel=\"category tag\">Geopolitics<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/op-ed\/\" rel=\"category tag\">op-ed<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/research\/\" rel=\"category tag\">Research<\/a>","tag_info":"Research","comment_count":"0","jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/6234","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/11"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=6234"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/6234\/revisions"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=6234"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=6234"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=6234"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}