Security research is essential to software safety, but the legal framework around it remains murky. GitHub has filed comments with the U.S. Copyright Office supporting a petition by Professor J. Alex Halderman and others for a broader exemption to the Digital Millennium Copyright Act's (DMCA) anticircumvention provisions. The request seeks a wider safe harbor for good-faith security research under Section 1201 of the DMCA.

The filing is part of the Eighth Triennial Section 1201 Proceeding, which reviews exemptions to the law's prohibition on circumventing technological protection measures. GitHub's comments make four core arguments:

  1. FUD is the enemy. Fear, uncertainty, and doubt surrounding legal exposure chills security research precisely when more of it is needed.
  2. The law's focus is too narrow. Current debates tend to center on academic researchers, but the reality of modern software development means individuals and large corporations alike must conduct security work to protect the software their users depend on. The 22-year-old law did not anticipate this landscape.
  3. Security research and QA overlap. There is substantial overlap between quality assurance and security research, yet the rules require that circumvention be undertaken solely for security research. This endangers developers who may want to build and debug in addition to ensuring their software and computing environments are secure.
  4. Automation must be protected. Modern developers rely on automated tools and virtualization for security testing. With dependency trees often spanning hundreds of packages and supply chain attacks on the rise, developers should not have to worry that using such tooling will be deemed outside the scope of security research because it also serves quality control.

The DMCA's Section 1201 currently leaves developers facing ambiguous rules and the possibility of criminal liability for routine quality assurance work aimed at finding vulnerabilities. GitHub argues this uncertainty keeps legitimate security work from happening, leaving users less safe. The company hopes the Copyright Office will broaden the exemption to reflect how software is actually built and tested today.

The full text of GitHub's comments is available from the Copyright Office.