The White House last week made some drastic changes to federal hacking policy, issuing a presidential memorandum that allows vetted private companies to initiate cyberattacks against hacker groups. The announcement reversed previous government policy, which prohibited companies from doing so without a court’s approval.
“American businesses’ innovative capabilities have historically been underutilized in efforts to identify and disrupt criminal networks operating in cyberspace,” the memorandum reads. “Thus, it is the policy of the United States to use all instruments of national power, including the innovative capabilities of the private sector, to combat cybercrime.”
Over the next two months, the government will fill in some of the blanks about the requirements companies will have to meet. But there are larger questions that aren’t likely to be addressed, including what legal protections these companies will receive. For instance, what happens if someone is arrested by a foreign government in connection with a cyberattack?
Liability
On that point, the memo says nothing. And it doesn’t offer much, if any, of a legal shield, though experts argue it should.
“Sending someone into this environment with ambiguous government backing and figuring out their status after they are arrested would be irresponsible,” says Eric O’Neill, a cybersecurity expert, former FBI operative and author of Spies, Lies, and Cybercrime. “But U.S. authorization does not magically erase another country’s laws. A foreign government may consider an intrusion into infrastructure within its borders a crime regardless of what Washington authorized.”
Jud Dressler, head of the Risk Operations Center at cyber risk company Resilience, agrees that the memo grants private-sector firms no special rights. And companies that take part in these operations could put their employees at risk, he says.
“There is no explicit legal entitlement to government assistance,” Dressler told Fast Company. “Participating firms must treat personnel exposure—arrest risk, extradition requests from jurisdictions friendly to the targets, and increased risk of being targeted—as a real operational risk.”
True protection for private firms that launch cyberattacks could be granted by Congress, but the White House memo came days after the House and Senate proposed a cyber letters of marque bill, which would allow the president to commission private hackers. (The bill was introduced by Republican congressmen Mike Lee and Tim Burchett in the Senate and House, respectively.) As it stands, any legal protections for companies, both civil and criminal, are theoretical.
Another area the memo glosses over is exactly who will be doing the hacking. Will it, in fact, be workers at those private companies or embedded government officials?
“One section has federal personnel conducting the operations, another has the companies doing it, and the procedures that should resolve it are due in 60 days,” says Rob T. Lee, Chief AI Officer at SANS Institute. “Until then, nobody can price the personal risk.”
Private sector advantages
There are, of course, some advantages to having private firms take on this role, experts say. Chief among them is visibility. It’s private-sector infrastructure that international hackers attack and utilize. Companies like Google, Microsoft, and Cloudflare see attacks happening before any federal agency does.
In February, for instance, Google was responsible for disrupting a global cyber espionage campaign known as Gridtide by revoking API access. “No government on earth can revoke a Google Sheets API key. That is the structural advantage, and it is not something an agency can buy,” says Lee.
Additionally, the government cannot monitor private networks without specific legal authority, says Dressler.
A presumed advantage of using corporations for this sort of work would be speed, since the private sector typically moves faster and can recruit talent more quickly than the government. That’s not necessarily going to be the case, though.
“This memo requires two Executive Directors, one at Justice and one at Homeland Security, to give written approval on every operations package before a company acts, inside an interagency deconfliction loop,” says Lee. “That is not faster than an interagency process. It is one, with a contractor attached.”
Even if these privateer hackers do prove faster than federal cybersecurity officials, there’s another risk, says O’Neill. Intelligence agencies take a broader view and might allow a hacker to continue their activities in order to catch a bigger operator. Private companies may not realize this and could inadvertently jeopardize those investigations.
“A company may know exactly where a ransomware server is located without knowing that the same server is being watched by the FBI, penetrated by the NSA or sitting inside infrastructure belonging to a foreign intelligence service,” he says. “You never want your tactical success to destroy a larger intelligence operation.”
Hacking escalation?
The bigger fear is that with more sanctioned hacking, there could be an escalation—on both sides—of global cyberwarfare. While the memo includes de-escalation guidelines (i.e., targets must be criminal groups, and no operations can be launched that are likely to cause death or serious injury), there are still risks.
“Once governments formally authorize private companies to conduct offensive cyber operations abroad, other countries will point to that precedent when they do the same thing,” says O’Neill. “And some of our adversaries will operate with considerably fewer restrictions than we will.”
The risks of state-on-state conflict arising from this are murky, but participating companies and their customers could face retaliation. “This memo is a great start, but it is not a substitute for diplomatic and economic pressure on criminal safe havens, or converting more named hackers into defendants,” says Dressler.
The memo also lets companies nominate the targets they want to pursue, which could pose a conflict if they have a commercial interest in those nominations. And when Lee asked last month who audited the disruptor when the attribution was wrong, he got no answer. (That, seemingly, lies in a classified annex attached to the memo.)
“A privateer picked his own targets and kept the prize; here the government picks the target, signs the package, and holds the bond,” he says. “The oversight everyone will argue about in public is the part nobody outside the program can read. That is the question I would keep asking in six months.”
The biggest concern among experts, though, is the precedent this document sets. By sanctioning private firms to carry out cyberattacks, the U.S. could be opening a Pandora’s box it cannot close.
“If we are going to change the rules of the game, we had better understand exactly what happens after the first shot,” says O’Neill.