Unleashing Hackers to Be the US Government’s Bounty Hunters | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #hacker


Cyberwarfare / Nation-State Attacks
,
Fraud Management & Cybercrime

Trump Presidential Memo a Risky Proposition for Corporations and the Internet

Image: Shutterstock/ISMG

Even those who support a White House push to involve the private sector in offensive cyber operations against foreign online crime groups admit that the strategy is laden with risk – for the companies that take part and for the broader global internet.

See Also: Experts Offer Insights from Theoretical to the Realities of AI-enabled Cybercrime

A National Security Presidential Memorandum signed by President Donald Trump last week authorizes companies contracted by the U.S. government to conduct “cyber surveillance and cyber effects operations” against foreign “cyber-enabled transnational criminal organizations” under the “direction, control and oversight of the federal government.”

A number of commentators pointed out that the program was born out of frustration with the government’s lack of success in tackling cybercrime, which continues to rise relentlessly.

“Success in cyberspace seems as elusive as it was in Vietnam or Afghanistan,” wrote former White House cyber official turned Columbia University Professor Jason Healey on LinkedIn.

“Huntress is incredibly interested in this,” said Rich Mozeleski, a company product manager. “But ultimately, we have to protect our customers first and foremost. The ability to go attack the enemy is real nice to have, but we can’t forget our first mandate. So anything that exposes us to risk or would somehow expose our customers to risk is probably a complete no go.”

Nonetheless, Mozeleski is a big supporter of the idea. “I wear two hats,” he told ISMG. One at Huntress, a cybersecurity company focused on the small business sector, and the other as a major in the U.S. Army Cyber Reserve, mobilized periodically to work at Cyber Command.

He said the view was very different from each side of the fence.

“In my day job I see all of this cybercrime affecting small businesses and real people and I can do nothing proactive about it, and when I put on my uniform I have access to a wide range of tools that are arrayed against other targets,” like nation-state threats, he said.

Despite the 60-day deadline in the presidential memo for the program to be designed and implemented, “It’s highly unlikely that we see any sort of outcome from this in the next six months,” he predicted.

Designing a system to provide classified intelligence to companies and that clears a planned operation “so that we’re not turning off the lights at a hospital or something,” will be a very big lift, he said, “Even just getting timely data out of classified systems and handing it to a private company to do something about, there is no muscle for that today.”

The presidential memo limits the targets of potential private sector operations. A cyber-enabled transnational criminal organization is “a foreign group that conducts cyber-enabled crime against the U.S. government, U.S. persons, or U.S. interests,” but is not directly connected to a nation-state adversary.

“This is not hacking back,” said Marcus Sachs, a veteran Department of Defense cybersecurity official who is now senior vice president and chief engineer at the Center for Internet Security. “This is not cyber privateering,” or employing cyber mercenaries like Blackwater.

He likened the presidential memo to the cyber version of bounty hunting because the targets are specifically defined as “not an institutional part of, or wholly operated under the direction of, a foreign government.” Only transnational crime organizations that aren’t direct surrogates for adversary nations are fair game.

“In the physical world, we have private investigators, bounty hunters, repo men. This is well understood,” Sachs told ISMG. When somebody jumps their bail, a bounty hunter can legally detain them, and then turn them over to law enforcement, and get paid.” Private companies with a court order can “legally go repossess a car or truck or boat,” Sachs said, pointing out that under other circumstances the same act would be theft.

Still, “If I was the general counsel of any of these companies, I’d make sure I had absolutely air tight legal proof, signed by some government attorney that says that you are authorized to do these things,” Sachs said. “You don’t want to be hung out to dry.”

The reason companies needed such guarantees, Sachs explained, is that the internet is so interconnected. “The possibility exists that disrupting that adversary may cause other disruptions across the internet. Unintended consequences,” Sachs said, comparing cybercriminals’ use of civilian infrastructure to insurgent groups setting up a missile launcher next to a school or a hospital. “Because they know that proximity will help protect it, would cause us to not necessarily bomb it for fear of killing innocent people.”

“The same thing happens in cyberspace. They’re going to locate themselves close to or within infrastructure, so that if we go after their infrastructure, we’re actually hurting our own infrastructure.”

Edward Amoroso, who worked at Bell Labs and went on to become a senior vice president and CISO of AT&T warned that if other nations reciprocate, “We could be creating a commercial market for cyber-privateering at precisely the moment when AI is making offensive operations faster, cheaper and increasingly autonomous.

“We will regret this,” he concluded.

Actually Doing This Is Harder Than Writing a Memo

The collaboration envisioned by the memo would match private sector agility with government-collected intel, Sachs said. “The private sector has capabilities, has scale, has speed that the government can’t match,” he said. “The government knows where the adversaries are and has the legal powers to go after them.”

Sharing that intelligence would be a complex undertaking, even once a system was established, said retired Air Force Cyber Communications Officer Col. Lance Spencer.

“There are constructs on how to handle classified programs,” and especially the most highly classified ones, known as special access programs, said Spencer, who was a corporate executive after his Air Force career and now has his own shingle out as a board and corporate advisor.

Generally, a single board member would be cleared for the program, so they could “communicate in board thinking and board terms with the rest of the board without divulging classified information,” and enable the board to fulfill its duty to shareholders by assessing the risks, Spencer told ISMG.

Even so, “There’s still a lot of risk. There’s still a lot of trust that has to be established within that framework within a company to make that happen,” Spencer said, adding that access to classified intelligence is granted on a “need to know” basis.

“In a [corporate] reporting chain, not everybody’s going to have that need to know,” he said. First and foremost were the decision-makers, but “people in between the board and that decision maker probably won’t be cleared,” creating a complicated situation for management.

The presidential memo envisages that participants will be required to keep their involvement secret from the public. “But we’re not the only actors and decision-makers in this process,” Spencer said. “The guy who is at the other end of the surveillance or other cyber activities has a vote in this also. They get to decide how they’ll respond and what they might disclose publicly or not. So just because the U.S. government is going to protect identities doesn’t mean the adversary is going to do that.”

Disclosure would create additional risks, both to reputation and of retaliation, said Spencer.

Sachs pointed out that the disclosure of a company’s participation would expose its executives to the risk of retaliation.

At the end of the day, Sachs said, companies will have to make a judgment about the program based on their tolerance for risk and their fiduciary duties.

“Nothing in here is compelling a company to do anything. This would be a choice that a company will make, and many companies may say, ‘No, I don’t want to have anything to do with that. There’s too many liabilities, too many unknowns. It puts my corporation at too much risk.’ Others may be less risk averse, and their legal team says, ‘Yes, let’s try it and see.'”



Click Here For The Original Source.

——————————————————–

..........

.

.