Remix.run Logo
White House Authorizes Private U.S. Companies to Hack Foreign Cybercrime Groups(whitehouse.gov)
74 points by iamronaldo a day ago | 21 comments
ameliaquining a day ago | parent | next [-]

If you (like me) found this hard to read, Reuters wrote up a decent summary: https://www.reuters.com/world/trump-signed-memo-allow-use-cy...

On a related note, https://mentalwires.tumblr.com/post/622219187310542848/black...

angelofthe0dd a day ago | parent | prev | next [-]

Zero-day hunters and the exploit broker market have been a thing for some time now. The US is one buyer on a world market of exploits. Maybe that's what this is trying to address. Many Nation states already stockpile zero days to use against one another when necessary or useful. I skimmed over the whole thing, and I'm guessing the US government wants to carve out a niche in the international zero-day market by creating a privatized, government-backed body that will collectively share hacking tools and exploits among one another. Membership being contingent on NOT participating in any other zero-day markets nor bargaining with any known exploit brokers.

rbtms a day ago | parent | prev | next [-]

I am less preoccupied about private companies or government contractors able to carry out cyberattacks on foreign targets and more worried about what constitutes a "foreign target" according to the current US administration.

pixl97 a day ago | parent [-]

"Everything and anything "

9 hours ago | parent [-]
[deleted]
michaelfm1211 a day ago | parent | prev | next [-]

This sounds similar to letters of marque and reprisal, which is something I haven't thought of since middle school constitution class until now.

walrus01 a day ago | parent | next [-]

Erik Prince and similar have been trying to get that going again (for actual commercial cargo shipping related activities) for some time now.

Tanoc a day ago | parent | prev | next [-]

It appears like they're trying to make an industry that works outside of conventional bounds. Just like with private military contractors. Not quite privateers like in the 1630s.

addaon a day ago | parent | prev [-]

Except the constitution is clear that issuing letters of marque is reserved for congress, not the executive branch.

ameliaquining 10 hours ago | parent [-]

Also they have been prohibited by customary international law for over 150 years. The people talking about bringing them back are mostly trolling.

iamnothere 8 hours ago | parent [-]

Lately there’s been quite a few things happening that are prohibited by customary international law.

I think the whole concept of international law may be on its last legs, frankly.

Terr_ a day ago | parent | prev | next [-]

What laws made this legal? How as the money appropriated by Congress? What oversight does Congress have?

I'm particularly concerned here because the Republican leadership has already begun insisting they can grant companies total immunity from the all state laws, simply by hiring them with a contract! [0]

With that in mind, how likely are these technical contractors to get tasked with, say, surveilling and hacking supposedly "foreign Antifa"? Perhaps with an extrajudicial slur of "waging psychological warfare" with something that inconveniences the administration, like documenting and sharing videos of Americans getting shot by ICE.

> the NCC shall conduct all Program activities in accordance with the Constitution and all other applicable laws and international obligations of the United States, including section 1030 of title 18, United States Code

Huh? That section [1] is basically the Computer Fraud and Abuse Act. Yes, it's extremely relevant, but how precisely will they subcontract civilian companies to run "sustained cyber campaigns" and also claim those contractors will scrupulously obey the CFAA and never make any kind of unauthorized access or fraud?

Either there's some trick that reconciles the conflict, or the companies can't do very much except get nice big taxpayer checks, or else they're going to break the law...

[0] https://www.wired.com/story/ices-new-detention-contracts-dec...

[1] https://www.law.cornell.edu/uscode/text/18/1030

halJordan 14 hours ago | parent | next [-]

Yes the cfa very clearly spells out what is illegal, and these activities fall into it. It's possible to break the cfa even as government body executing under title 10 or title 50 authority.

wildrhythms a day ago | parent | prev [-]

Snowden tried to tell us.

pogue a day ago | parent | prev | next [-]

This seems like the kind of thing you wouldn't want to announce publicly? But I guess the little man always needs to project power.

burnt-resistor a day ago | parent | prev | next [-]

Vigilantes worked out so well during Reconstruction. But now these are nominally profit-motivated vigilantes. What could possibly go wrong?

bediger4000 a day ago | parent | prev [-]

Those who engage in this better have good insurance. Ruin people's stuff, they're going to sue

halJordan 13 hours ago | parent | next [-]

I think the expectation is far different than reality. This isn't about google's TAG hacking back FIN7. This is about LockMart extending their contract from vulnerability research, to throwing these vulnerabilities. They've wanted this expansion for some time now.

And with cybercom doing literally everything it can to resist becoming a separate service, I guess now is the time interests aligned.

So imagine taking everything that was wrong with the f35's acquisition and technical ownership and supply chain. And shift it wholesale over to cyber. So we're now paying for each exploit's development, and also paying a per use fee at a cost+plus rate, never truly owning anything

VoidWhisperer a day ago | parent | prev | next [-]

With some of these cybercrime groups, being sued is probably the least of their worries..

bediger4000 11 hours ago | parent [-]

These particular cybercrime groups are going to be Lockheed, General Dynamics and Comcast.

Terr_ a day ago | parent | prev [-]

Hmm, the fancy interoffice memo plan says that participants will be required to put at least $1m in escrow... but it doesn't say those funds are for paying liability or damages to people they hurt!

Instead, it's money to be simply forfeited to the US treasury [0] if the contractor breaks some to-be-determined conditions in not-yet-existing contracts. In other words, its a money-hostage for obedience.

[0] At least, that would be the legal default, but I'd watch carefully to make sure it doesn't somehow get stolen into an Executive Branch slush-fund.