Cyberscoop

Trump turns to private sector in offensive hacking operations memo


President Donald Trump signed a national security memorandum Wednesday that lays the groundwork for private sector companies to take a larger role in helping law enforcement carry out offensive hacking operations against transnational criminal organizations.

The White House said sustained fraud and other cyber-enabled campaigns from transnational criminal organizations (TCOs) warranted the memo, and cited a fraud-focused executive order from March as only the first step.

”This memorandum expands the fight against TCO-perpetrated cybercrime by incorporating the ingenuity of the private sector,” it reads.

Under the memorandum, a federal coordination center “shall create, manage, and maintain a Program to authorize Participating Companies … to conduct Cyber Surveillance Operations and Cyber Effects Operations against foreign Cyber-Enabled Transnational Criminal Organizations (CE-TCOs), under the control and oversight of the Federal Government“ that would be “part of lawful investigatory, protective, or intelligence operations carried out by Federal law enforcement.”

Participating companies would have to sign contracts with the Justice Department or Department of Homeland Security to “undergo rigorous vetting.” It would also allow participating companies to sign commercial agreements with other private sector entities to receive threat information. And participating companies’ agreements with federal, state and local governments would be geared toward identifying threats, and proposing cyber operations to the coordination center to address those threats.

The program would have to adhere to existing laws, according to the memo. That includes the Computer Fraud and Abuse Act, the main federal anti-hacking statute that prior proposals to open private sector participation in hacking operations would have amended. The memo mandates oversight to evaluate companies’ technical proficiency, ensures both small and large companies can participate, and requires regular reporting to federal officials.

In recent years, there has been some sentiment in conservative circles to authorize “letters of marque” for private-sector cyber firms similar to those for early-U.S. sea privateers. Some have suggested the government could lean on more private sector cyber experts to conduct offensive operations.

But there also has been deep concern in cyber circles about giving the private sector too much leeway in offensive operations, from industry condemnation of “hack back” legislative proposals that would authorize steps that are currently illegal as a dangerous precedent that critics fear could open cyberspace to wider chaos.

One former Cyber Command official, Jason Kitka, criticized several elements of the memorandum, calling it “a perpetual motion machine for billable threats” in a social media post.

But a former top White House cyber official during Trump’s first term, Galvanick co-founder Josh Steinman, cheered the development. 

Cyber pioneer Chris Wysopal, now co-founder of Veracode, called it “a pretty big shift in US cyber policy” that nonetheless stopped short of going as far as other “hack back” proposals.

Written by Tim Starks

Tim Starks is senior reporter at CyberScoop. His previous stops include working at The Washington Post, POLITICO and Congressional Quarterly. An Evansville, Ind. native, he’s covered cybersecurity since 2003. Email Tim here: tim.starks@cyberscoop.com.



Source link