Software Screws Around, Reverse Engineering Finds Out: How Independent, Adversarial Research Informs Government Regulation

No ratings

Presented at ShmooCon 2025 by

For all of the discussion on how best to regulate software platforms and systems, there is little attention paid to how software is held accountable today. What allows agencies like the Federal Trade Commission to effectively police the security and privacy properties of information technology? It is often assumed that independent research–including vulnerability discovery and reverse engineering–plays some role, but its overall prominence has been under examined. We review the past several years of FTC actions in software security and privacy, and show that an enormous amount of the Commission’s work –between a quarter and a third of all FTC actions–owe their discovery directly to the input of independent research. This places independent research as a signicant regulatory partner with the government, and elevates its importance beyond what has been previously assumed. We also examine why this is unsurprising on a theoretical level, drawing from economic theory that explains the phenomenon. Finally, we propose a series of law and policy interventions that can help improve the independent software research ecosystem in light of its important regulatory role, attending to the specic legal concerns of academics, journalists, advocates, and other independent actors.