BACC TRAVEL

In a memo issued in August, the Trump administration announced a program that could authorize some U.S. businesses to pursue government-selected foreign cybercriminals.

In the past, that work has been performed by government agencies.

The presidential memorandum doesn’t fully explain how it would allow a private business to take the lead on work traditionally performed by the U.S. government, like spying or disruptive cyber operations.

U.S. anti-hacking laws broadly bar people and businesses from hacking digital infrastructure, with some exceptions to allow law enforcement work. This memo does not change those laws, but it mandates any participating company be contracted with the federal government.

Nevertheless, the memo presents a dramatic departure from the way America’s private sector currently behaves in cyberspace. If implemented, it would allow some private businesses to disrupt foreign organizations the government says are cybercriminals or gather intelligence on those groups.

“There’s a range of potential targets … like organized crime … people doing money laundering or other criminal activity,” said Joshua Steinman, who served as senior director for cyber policy on the National Security Council during President Trump’s first term.

The nitty gritty

It’s unclear what companies might want to take the government up on this opportunity.

Private corporations have long worked with the federal government to help disrupt cybercriminals, but largely as contractors fulfilling a support role, not digital saboteurs handed a target.

“There are going to be a lot of people out there who see this as an onramp to doing additional work for the United States government,” said Steinman.

That could include smaller firms, venture capital backed startups, and companies looking to get in on potentially lucrative government contracts.

Participating companies would enter contracts with the Department of Justice or the Department of Homeland Security, undergo “rigorous vetting” and set aside $1 million the government can collect if a company doesn’t meet its obligations.

These companies would then get permission to attempt to access the computer networks of foreign groups and take actions that “result in the manipulation, disruption, denial, degradation, or destruction of information systems,” according to the memo.

Much of what that vetting would look like, and the process by which potential targets would be selected, isn’t described in the memo. Nor are the types of disruptive attacks or the legal justification for them.

Opposition from industry

Some in the cybersecurity industry think the memorandum takes the country’s digital defenses in the wrong direction. Paul Rosenzweig is in that camp. He leads a consulting firm in Washington, D.C., and was deputy assistant homeland security secretary for policy under President George W. Bush.

“It’s not an incomparably bad idea, but it’s a bad idea,” said Rosenzweig.

He also says the order doesn’t address the number of practical and legal issues any private actor would have to deal with if they hacked a foreign organization.

The memo wouldn’t allow private businesses to launch cyberattacks on other governments, but many foreign cybercriminals operate in a grey area between state-sponsored and not. Targeting the wrong group could end up inciting an international incident.

The risks of cyberattacks

Americans lose billions of dollars every year to cyberattacks.

Cybercriminals break into private businesses and public utilities alike, threatening to hold data hostage or leak it if they aren’t paid. They steal personal information from victims and manipulate people into transferring them money.

Cyberattacks are also a national security threat. In July, Minnesota reported dozens of local water systems had been targeted in a coordinated attack, which American intelligence links to Iran.

Steinman, the former Trump official, said a faster paced private sector can help the country’s offensive cyber capabilities, as long as it’s done carefully.

The point of this is to get started,” he said, “And I trust that the people that are running it are going to be very measured in their initial efforts to try and build out this capability.”

But others say even if the legal and technical issues in the president’s memo are resolved, it still won’t fix the growing threat of cybercrime — especially in the short term.

“I don’t think you can sort of offense your way to security,” said Wysopal. “There’s always going to be yet another threat actor … the idea that this is going to solve the problem seems really foolish.”

Source: npr.org

Leave a Reply

The Brasilians