BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: Dragon Tails: Supply-side Security and International
 \n   Vulnerability Disclosure Law\n   When: Friday\, Aug 12\, 18:30 - 18:5
 0 PDT\n   Where: Caesars Forum - Forum 106-110\, 138-139 (Track 2) - [1]Ma
 p\n   Speakers:Trey Herr\,Stewart Scott\n\n   SpeakerBio:Trey Herr \, Dire
 ctor\n   Trey Herr is the director of the Cyber Statecraft Initiative unde
 r the\n   Scowcroft Center for Strategy and Security at the Atlantic Counc
 il.\n   His team works on cybersecurity and geopolitics including cloud\n 
   computing\, the security of the internet\, supply chain policy\, cyber\n
    effects on the battlefield\, and growing a more capable cybersecurity\n
    policy workforce. Previously\, he was a senior security strategist with
 \n   Microsoft handling cloud computing and supply chain security policy a
 s\n   well as a fellow with the Belfer Cybersecurity Project at Harvard\n 
   Kennedy School and a non-resident fellow with the Hoover Institution\n  
  at Stanford University. He holds a PhD in Political Science and BS in\n  
  Musical Theatre and Political Science.\n\n   SpeakerBio:Stewart Scott \, 
 Assistant Director\n   Stewart Scott is an assistant director with the Cyb
 er Statecraft\n   Initiative under the Scowcroft Center for Strategy and S
 ecurity at the\n   Atlantic Council. His work there focuses on systems sec
 urity policy\,\n   including software supply chain risk management\, feder
 al acquisitions\n   processes\, and open source software security. He hold
 s a BA in Public\n   Policy and a minor in Applications of Computing from 
 Princeton\n   University.\n\n   Description:\n   This talk will present a 
 study of the reliance of proprietary and open\n   source software on Chine
 se vulnerability research. A difficult\n   political environment for Chine
 se security researchers became acute\n   when a law requiring vulnerabilit
 y disclosure to government and\n   banning it to all others but the affect
 ed vendor took effect in Sept.\n   2021. No public evaluation of this law'
 s impact has yet been made.\n   This talk will present results of a quanti
 tative analysis on the\n   changing proportion of Chinese-based disclosure
 s to major software\n   products from Google\, Microsoft\, Apple\, and VMW
 are alongside several\n   major open source packages. The analysis will me
 asure change over time\n   in response to evolving Chinese legislation\, s
 ignificant divergence\n   from data on the allocation of bug bounty reward
 s\, and notable trends\n   in the kinds of disclosed vulnerabilities. The 
 Chinese research\n   community’s prowess is well known\, from exploits a
 t the Tianfu Cup\n   to preeminent enterprise labs like Qihoo 360. However
 \, the recent law\n   aiming to give the Chinese government early access t
 o the\n   community’s discoveries—and the government’s apparent\n   
 willingness to enforce it even on high-profile corporations as seen in\n  
  its punishment of Alibaba—demand more thorough scrutiny. This talk\n   
 will address implications for policy and the wider hacker community.\n   '
 \n\n   1. https://defcon.outel.org/consolidated_page.html#CaesarsForumBR\n
 \n\n
DTEND:20220813T015000Z
DTSTART:20220813T013000Z
LOCATION:DC - Caesars Forum - Forum 106-110\, 138-139 (Track 2)
SUMMARY:Dragon Tails: Supply-side Security and International Vulnerability 
 Disclosure Law
END:VEVENT
END:VCALENDAR
