White House authorizes private companies to launch 'hack-back' cyberattacks that destroy data and systems, targeting foreign cybercrime organizations — vetted organizations can now conduct offensive cyber operations

Trump
(Image credit: Getty / Anna Moneymaker)

President Donald Trump signed a presidential memorandum on August 12 establishing the first U.S. program that lets vetted private companies conduct offensive cyber operations, including attacks that destroy data and systems, against foreign cybercrime organizations. Participating firms must post at least $1 million in escrow, forfeited if they break the program's rules, and every operation requires written approval from officials of the Department of Justice and the Department of Homeland Security. Just a few months ago, the administration publicly ruled out this very policy.

In March, Thomas Lind, then a senior adviser at the Office of the National Cyber Director, told a conference the administration had no plans to authorize private offensive operations. "We're not interested in fighting pirates with pirates," Lind said. National Cyber Director Sean Cairncross said the same week that companies running offensive campaigns weren't what the administration meant when it asked industry for more help.

Latest Videos FromTom's Hardware
Luke James
Contributor

Luke James is a freelance writer and journalist.  Although his background is in legal, he has a personal interest in all things tech, especially hardware and microelectronics, and anything regulatory. 

  • COLGeek
    Just remember, when you peer into the darkness, the darkness peers back.

    I am trying to wrap my brain around the rules of engagement and the overall legality of these directives. There are laws regarding these matters that an executive order can't ignore.

    There is also a (possible) matter of liability should one of these efforts go off-kilter (collateral damage).
    Reply
  • SonoraTechnical
    Disappointed that we are going down that rabbit hole. Thought we would take the high road.
    This clearly is reactionary, a knee jerk response, and hasn't been carefully thought out. There will be many unintended consequences.

    signed: unfortunately not surprised

    (my use of we is because I reside in the USA).
    Reply
  • thestryker
    What I find most interesting is that this has already happened in the past, but with much tighter constraints because the companies have been working directly with the FBI. That the guardrail is the DOJ means there's no real guardrail at all when the executive branch is willing to use it as their personal weapon. It also seemingly muddies the waters with regards to legality and oversight. With any luck the order will violate existing laws and the courts will stop it in its tracks before it can get started.

    edit: spelling whoops
    Reply
  • Scase15
    I'm sure there's no way that this could ever possibly escalate out of control. It's definitely a smart idea to paint a target on your back when damn near every power grid and water treatment plant is running on software and hardware that is wildly out of date.

    Real innocent people are going to suffer here but that seems to be par for the course.
    Reply
  • FunSurfer
    The problem with the above comments is that the evil axis that hacks FIRST American companies doesn't have any sense of legality, and battling a war that force legal constraints only on one side, will surely end in a defeat for that side.
    Reply
  • SonoraTechnical
    FunSurfer said:
    The problem with the above comments is that the evil axis that hacks FIRST American companies doesn't have any sense of legality, and battling a war that force legal constraints only on one side, will surely end in a defeat for that side.
    So when everybody stoops to the same level, we all win. Got it!
    Reply