The Department of Defense is continuing to break barriers, both metaphoric and digital.
Following announcements regarding the expansion of what has been touted as a successful bug bounty program, DoD has released additional details about the Hack the Pentagon initiative.
According to statements released by both DoDand its commercial partner in the effort, HackerOne, the Pentagon unveiled a new vulnerability disclosure policy, which provides a “
legal avenue for security researchers to find and disclose vulnerabilities in any DoD public-facing systems,” a statement read.
According to HackerOne, this program will take place on
any public-facing website owned, operated or controlled by DoD, including web applications hosted on those sites.
“The Vulnerability Disclosure Policy is a ‘see something, say something’ policy for the digital domain,” Defense Secretary Ash Carter said. “We want to encourage computer security researchers to help us improve our defenses. This policy gives them a legal pathway to bolster the department’s cybersecurity and ultimately the nation’s security.”
The Pentagon noted that this new program underwent significant legal review by the Department of Justice’s Criminal Division to ensure this legal pathway. The DoD Vulnerability Disclosure Policy is “a laudable way to help computer security researchers use their skills in an effective, beneficial, and lawful manner to reduce security vulnerabilities,” Assistant Attorney General Leslie Caldwell said.
While the program does not include bounty awards, it is designed to give security researchers clear guidelines for conducting vulnerability discovery activities directed at Department of Defense web properties, and submitting discovered vulnerabilities to DoD, HackerOne said.
“Information submitted to DoD under this policy will be used for defensive purposes – to mitigate or remediate vulnerabilities in our networks or applications, or the applications of our vendors,” HackerOne continued.
Among the guidelines of the new initiative HackerOne provided:
- Our activities are limited exclusively to – (1) Testing to detect a vulnerability or identify an indicator related to a vulnerability; or (2) Sharing with, or receiving from, DoD information about a vulnerability or an indicator related to a vulnerability.
- You do no harm and do not exploit any vulnerability beyond the minimal amount of testing required to prove that a vulnerability exists or to identify an indicator related to a vulnerability.
- You do not exfiltrate any data under any circumstances.
- You do not intentionally compromise the intellectual property or other commercial or financial interests of any DoD personnel or entities, or any third parties.
- You do not publicly disclose any details of the vulnerability, indicator of vulnerability, or the content of information rendered available by a vulnerability, except upon receiving explicit written authorization from DoD.
- You do not conduct denial of service testing.
Lauding the practice of bug bounty programs outside the government as standard, Carter, in a post on the popular blogging website Medium, wrote: “By allowing outside researchers to find holes and vulnerabilities on several sites and subdomains, we freed up our own cyber specialists to spend more time fixing them than finding them. The pilot showed us one way to streamline what we do to defend our networks and correct vulnerabilities more quickly.”
During the Nov. 16 CyberCon conference in Washington hosted by Federal Times and C4ISRNET, Lisa Wiswell, digital security lead at the Defense Digital Service, noted that while the Hack the Pentagon challenge was intentionally “less sexy than you would want in a real challenge,” it was a proof of concept to build upon, adding that it only looked at five static websites. The vulnerabilities discovered through this effort, she said, were low-hanging fruit, bad cyber hygiene discoveries.
Wiswell also touted the new Hack the Army initiative announced by Army Secretary Eric Fanning, which will expand the Pentagon’s initiative focusing on operational Army networks and open up the hacking to government personnel – not just vetted security researchers and hackers.
DoD also paired their vulnerability disclosure announcement with the news that registration for Hack the Army is now open. Hackers can register to be invited to participate in this initiative. The scope for Hack the Army, including websites and databases will be shared with registered and invited hackers as the challenge approaches, HackerOne said.




