{"database": "press", "table": "releases", "rows": [["https://www.king.senate.gov/newsroom/press-releases/icymi-internet-nonprofit-mozilla-backs-kings-call-for-president-to-strengthen-cybersecurity-networks", "ICYMI: Internet Nonprofit Mozilla Backs King&#x2019;s Call for President to Strengthen Cybersecurity Networks", "2016-10-26", "2016", "2016-10", "Independent", "House", "ME", "Angus King", "K000383", "www.king.senate.gov", null, null, "legacy", "ICYMI: Internet Nonprofit Mozilla Backs King\u2019s Call for President to Strengthen Cybersecurity Networks\n\t\t\t\t\n\t\t\t\n\t\t\t\n\t\t\t\n\t\t\t\tWednesday, October 26, 2016\n\t\t\t\n\t\t\t\n\t\n\t\t\t\n\t\t\tBRUNSWICK, ME \u2013 In case you missed it, Mozilla, a global, nonprofit organization dedicated to defending a free and open web, applauded U.S. Senators Angus King (I-Maine) and Martin Heinrich (D-N.M.) for their letter earlier this week calling on President Barack Obama to work with Congress to strengthen the federal government\u2019s ability to detect and repair cyber-vulnerabilities within U.S. networks.\r\nIn a blog post published yesterday, Heather West, a senior public policy representative at Mozilla, echoed Senators King\u2019s and Heinrich\u2019s call to the President and wrote in support of their request to implement a government-wide \u201cBug Bounty\u201d program, which rewards so-called \u201cwhite hat\u201d hackers who detect and report security vulnerabilities.\r\nThe blog post also outlined Mozilla\u2019s proposed reforms to the Vulnerabilities Equities Process (VEP), which serves as the primary process for deciding whether a government entity must disclose to private companies information about security vulnerabilities in their products, or whether the government may withhold the information for law enforcement or intelligence purposes. In their letter, Senators King and Heinrich requested that the Administration establish a comprehensive policy that includes standard criteria for reporting vulnerabilities to the VEP, guidelines for making VEP determinations, clear time limits for each stage of the process, adequate participation of all relevant government agencies, and regular reporting to Congress.\r\n\u201cLast week\u2019s cyber attack on Dyn that blocked access to popular websites like Amazon, Spotify, and Twitter is the latest example of the increasing threats to Internet security, making it more important that we acknowledge cybersecurity is a shared responsibility. Governments, companies, and users all need to work together to protect Internet security,\u201d the blog post stated. \u201cThis is why Mozilla applauds Sens. Angus King Jr. (I-ME) and Martin Heinrich (D-NM) for calling on President Obama to establish enduring government-wide policies for the discovery, review, and sharing of security vulnerabilities.\u201d\r\nMozilla\u2019s complete blog post can be read HERE and is below:\r\n+++\r\nMozilla Asks President Obama to Help Strengthen Cybersecurity\u00a0\r\nLast week\u2019s cyber attack on Dyn that blocked access to popular websites like Amazon, Spotify, and Twitter is the latest example of the increasing threats to Internet security, making it more important that we acknowledge cybersecurity is a shared responsibility. Governments, companies, and users all need to work together to protect Internet security.\r\nThis is why Mozilla applauds Sens. Angus King Jr. (I-ME) and Martin Heinrich (D-NM) for calling on President Obama to establish enduring government-wide policies for the discovery, review, and sharing of security vulnerabilities. They suggest creating bug bounty programs and formalizing the Vulnerabilities Equities Process (VEP) - the government\u2019s process for reviewing and coordinating the disclosure of vulnerabilities that it learns about or creates.\r\n\u201cThe recent intrusions into United States networks and the controversy surrounding the Federal Bureau of Investigation\u2019s efforts to access the iPhone used in the San Bernardino attacks have underscored for us the need to establish more robust and accountable policies regarding security vulnerabilities,\u201d Senators King and Heinrich wrote in their letter.\r\nMozilla prioritizes the privacy and security of users and we work to find and fix vulnerabilities in Firefox as quickly as possible. We created one of the first bug bounty programs more than 10 years ago to encourage security researchers to report security vulnerabilities.\r\nMozilla has also called for five specific, important reforms to the VEP:\r\n \r\nAll security vulnerabilities should go through the VEP and there should be public timelines for reviewing decisions to delay disclosure.\r\nAll relevant federal agencies involved in the VEP must work together to evaluate a standard set of criteria to ensure all relevant risks and interests are considered.\r\nIndependent oversight and transparency into the processes and procedures of the VEP must be created.\r\nThe VEP Executive Secretariat should live within the Department of Homeland Security because they have built up significant expertise, infrastructure, and trust through existing coordinated vulnerability disclosure programs (for example, US CERT).\r\nThe VEP should be codified in law to ensure compliance and permanence.\r\n \r\nThese changes to the discovery, review, and sharing of security vulnerabilities would be a great start to strengthening the shared responsibility of cybersecurity and reducing the countless cyber attacks we see today.\r\n###", 1, "2026-03-30T12:14:52Z", "2026-03-30T12:14:52Z"]], "columns": ["url", "title", "date", "year", "month", "party", "chamber", "state", "member_name", "bioguide_id", "domain", "scraper", "source", "date_source", "text", "has_text", "collected_at", "updated_at"], "primary_keys": ["url"], "primary_key_values": ["https://www.king.senate.gov/newsroom/press-releases/icymi-internet-nonprofit-mozilla-backs-kings-call-for-president-to-strengthen-cybersecurity-networks"], "units": {}, "query_ms": 1.3494559098035097, "source": "dwillis/congress-press", "source_url": "https://github.com/dwillis/congress-press", "license": "MIT", "license_url": "https://github.com/dwillis/congress-press/blob/main/LICENSE"}