GitHub joins industry amicus brief against foreign sovereign immunity for cyber-surveillance firms

GitHub has signed onto an amicus brief in the case NSO v. WhatsApp, opposing the extension of foreign sovereign immunity to private cyber-surveillance companies operating on behalf of foreign governments. The company is joined in the filing by Cisco, Google, LinkedIn, Microsoft, VMware, and the Internet Association, all pushing back against immunity for what the brief calls private sector offensive actors (PSOAs). GitHub argues that such a policy would raise systemic risk across the software ecosystem by encouraging the growth of the cyber-surveillance tools market and expanding government use of those tools, including attacks on individuals and infrastructure.

GitHub frames the issue in terms of its role as a global platform for developer collaboration, where developers use the service to secure software and stay ahead of security threats. The company states that it opposes the hoarding and sale of exploits and attack or surveillance tools, since those tools could be aimed not only at GitHub itself but also at the millions of developers and open source projects that depend on the platform, as well as the broader software supply chain.

GitHub is also calling on governments to help developers cut systemic risk by taking concrete steps, including:

  • Adopting the best tools and practices for secure software development
  • Helping fund open source security projects
  • Adhering to principles that increase trust and security in cyberspace
  • Protecting legitimate security researchers

Granting immunity to cyber-surveillance companies that hoard vulnerabilities for attacks instead of collaborating with upstream maintainers to fix them would be a step in the wrong direction, GitHub concludes.