Article Details

Scrape Timestamp (UTC): 2024-04-24 19:47:33.010

Source: https://www.theregister.com/2024/04/24/wyden_government_interoperability/

Original Article Text

Click to Toggle View

Shouldn't Teams, Zoom, Slack all interoperate securely for the Feds? Wyden is asking. Doctorow: 'The most amazing part is that this isn't already the way it's done' Collaboration software used by federal government agencies — this includes apps from Microsoft, Zoom, Slack, and Google — will be required to work together and be securely end-to-end encrypted, if legislation proposed by US Senator Ron Wyden (D-OR) passes. That's a big if. Without a lot of bipartisan momentum behind it, his proposal isn't expected to make into law during this election year. Wyden proposed the legislation, the Secure and Interoperable Government Collaboration Technology Act [PDF], on Tuesday. It intends to make products from competing vendors, such as Teams and Zoom, for example, talk to each other more securely. Specifically, it would require the US government's General Services Administration (GSA) to create a list of collaboration technology features used by the federal government. Then the National Institute of Standards and Technology (NIST) would need to identify a set of interoperable standards and requirements for each of these. The legislation would also require that, "to the extent practicable," end-to-end encryption and other technologies to protect government communications from foreign surveillance would have to be built in. These collaboration technologies must also comply with federal record-keeping requirements.  Four years after NIST selects the standards, all collaboration technology purchased by the federal government would be required to communicate using the identified standards, thus ensuring they are interoperable with other products used by federal agencies. And finally, the legislation would require Homeland Security to review these products, and every other year a GSA and Office of Management and Budget working group would review the products in use and suggest updates to the standards. "My bill will secure the US government's communications from foreign hackers, while protecting taxpayer wallets. Vendor lock-in, bundling, and other anticompetitive practices result in the government spending vast sums of money on insecure software," Wyden said in a statement.  "It's time to break the chokehold of big tech companies like Microsoft on government software, set high cybersecurity standards and reap the many benefits of a competitive market," he added.  Stunningly, the bill identifies collaboration systems that would not be subject to the interoperability and security requirements. These include email, voice services, and national security systems. So despite the proposal's attempt at landing a blow on Microsoft's mafia-like hold on government-procured tech, the latest Redmond email security breaches by Chinese and Russian cyberspies probably would have happened even with the Wyden-backed security standards being in place. While those standards would likely face opposition from Big Tech, some digital rights and privacy organizations including Accountable Tech, Demand Progress, Fight for the Future, Proton, Nym, and the Matrix.org Foundation have already endorsed the draft legislation. Author and activist Cory Doctorow has also thrown his support behind the proposal. "Interoperability — the ability to plug something new into a technology, with or without permission from the manufacturer — is the key to defeating Big Tech," he said.  "This bill will require public funds to be spent on technology that anyone can fix, extend, or improve, preventing tech companies from locking in and ripping off the US government," Doctorow added. "The most amazing part is that this isn't already the way it's done."

Daily Brief Summary

MISCELLANEOUS // Proposed Bill Aims for Secure Federal Collaboration Tech

U.S. Senator Ron Wyden has proposed a bill to mandate interoperability and security among federal government collaboration software such as Microsoft Teams, Zoom, and Slack.

The bill, named the Secure and Interoperable Government Collaboration Technology Act, requires end-to-end encryption and adherence to federal record-keeping standards.

The General Services Administration (GSA) and the National Institute of Standards and Technology (NIST) would play key roles in setting interoperable standards and technologies.

The legislation targets reducing government expenditure on software by breaking the monopoly of big tech companies and enhancing competition.

The bill has not garnered significant bipartisan support yet, reducing its chances of passing in an election year.

Homeland Security would be tasked with reviewing these collaboration tools, and standards would be updated biennially based on reviews conducted by a GSA and Office of Management and Budget working group.

Despite the positive reception from digital rights groups and endorsements from figures like Cory Doctorow, it faces potential hurdles from major tech firms.

The proposed standards do not apply to certain technologies such as email, voice services, and national security systems, maintaining certain exclusions in government tech security measures.