Slashdot Mirror


Should Private Companies Be Allowed To Hit Back At Hackers? (vice.com)

An anonymous reader quotes a report from Motherboard: The former director of the NSA and the U.S. military's cybersecurity branch doesn't believe private companies should be allowed to hit back at hackers. "If it starts a war, you can't have companies starting a war. That's an inherently governmental responsibility, and plus the chances of a company getting it wrong are fairly high," Alexander said during a meeting with a small group of reporters on Monday. During a keynote he gave at a cybersecurity conference in Manhattan, Alexander hit back at defenders of the extremely common, although rarely discussed or acknowledged, practice of revenge hacking, or hack back. During his talk, Alexander said that no company, especially those attacked by nation state hackers, should ever be allowed to try to retaliate on its own.

Using the example of Sony, which was famously hacked by North Korea in late 2014, Alexander said that if Sony had gone after the hackers, it might have prompted them to throw artillery into South Korea once they saw someone attacking them back. "We can give Sony six guys from my old place there," he said, presumably referring to the NSA, "and they'd beat up North Korea like red-headed stepchild -- no pun intended." But that's not a good idea because it could escalate a conflict, and "that's an inherently governmental responsibility. So if Sony can't defend it, the government has to." Instead, Keith argued that the U.S. government should be able to not only hit back at hackers -- as it already does -- but should also have more powers and responsibilities when it comes to stopping hackers before they even get in. Private companies should share more data with the U.S. government to prevent breaches, ha said.

6 of 141 comments (clear)

  1. Terrible idea. by Lordpidey · · Score: 5, Insightful

    One of the most BASIC things to do in hacking, is cover your traces by making it LOOK like you're someone else.

    So, naturally the best way to harm corporation X, would be to hack corporation Y, but leave lots of evidence that it was corporation X, thus causing Y to attack X.

    --
    Some people encrypt by using rot-13 twice. I prefer the more secure method of using rot-1 a total of twenty six times.
    1. Re:Terrible idea. by barc0001 · · Score: 4, Insightful

      Also add to the fact that a lot of people are - to put it bluntly - stupid, and will probably misinterpret the source of an attack, launching a counterattack against an uninvolved 3rd party.

  2. Oh hell no by mhkohne · · Score: 4, Insightful

    These guys can't secure their servers in the most basic ways, and they want to be allowed to do their own target id (I'm supposed to believe they won't screw that up?) and then take offensive action?

    They'll attack the right target perhaps 1 out of 20 events. They'll attack someone at random every so often and then say 'whoops! We screwed up! Sorry!'.

    No, these corporate bozos are not the people we want dealing with such threats.

    --
    A thousand pounds of wood moving at 300 feet per minute. Don't get in the way.
  3. Hell No! by jwhyche · · Score: 5, Insightful

    No company should ever be allowed to take the law in to is own hands. Their response to any such issue should be to close the holes and repair the damage. Let law enforcement handle the rest.

    That is unless we want a ShadowRun type society where corporations can field their own private police forces and armies. But if this came to pass I doubt we would get the magic that came with it.

    --
    I read at +2. If your post doesn't reach that level I will not see or respond to it.
  4. I have bad memory, but... by Locke2005 · · Score: 4, Insightful

    Aren't their documented incidents of retaliation against hackers harming innocent third party internet businesses? That's why we let law enforcement hand out consequences instead of engaging in vigilante justice. (That being said the guys who chased after the Texas church shooter are awesome!)

    --
    I've abandoned my search for truth; now I'm just looking for some useful delusions.
  5. No no no by JustAnotherOldGuy · · Score: 3, Insightful

    Of course, this power would never, ever be abused, right? That would just never happen, right folks?

    And if they accidentally nuke your PC and its data, well..."Oops, real sorry about that. No you can't sue us, it's totally legal! What's that? You want to sue? Great, we'll see your lawyer and raise you 50 lawyers with virtually unlimited funds. See ya in court, sucker."

    No, they should not, because we all fucking know exactly what kind of abuse(s) this will lead to.

    --
    Just cruising through this digital world at 33 1/3 rpm...