Slashdot Mirror


Should Private Companies Be Allowed To Hit Back At Hackers? (vice.com)

An anonymous reader quotes a report from Motherboard: The former director of the NSA and the U.S. military's cybersecurity branch doesn't believe private companies should be allowed to hit back at hackers. "If it starts a war, you can't have companies starting a war. That's an inherently governmental responsibility, and plus the chances of a company getting it wrong are fairly high," Alexander said during a meeting with a small group of reporters on Monday. During a keynote he gave at a cybersecurity conference in Manhattan, Alexander hit back at defenders of the extremely common, although rarely discussed or acknowledged, practice of revenge hacking, or hack back. During his talk, Alexander said that no company, especially those attacked by nation state hackers, should ever be allowed to try to retaliate on its own.

Using the example of Sony, which was famously hacked by North Korea in late 2014, Alexander said that if Sony had gone after the hackers, it might have prompted them to throw artillery into South Korea once they saw someone attacking them back. "We can give Sony six guys from my old place there," he said, presumably referring to the NSA, "and they'd beat up North Korea like red-headed stepchild -- no pun intended." But that's not a good idea because it could escalate a conflict, and "that's an inherently governmental responsibility. So if Sony can't defend it, the government has to." Instead, Keith argued that the U.S. government should be able to not only hit back at hackers -- as it already does -- but should also have more powers and responsibilities when it comes to stopping hackers before they even get in. Private companies should share more data with the U.S. government to prevent breaches, ha said.

3 of 141 comments (clear)

  1. No by sexconker · · Score: 4, Interesting

    No, not unless regular people are allowed to do the same.

    1. Re:No by ArmoredDragon · · Score: 3, Interesting

      No...We shouldn't allow vigilantism any more than we should allow companies to retaliate. However when they made this statement:

      Instead, Keith argued that the U.S. government should be able to not only hit back at hackers -- as it already does -- but should also have more powers and responsibilities when it comes to stopping hackers before they even get in. Private companies should share more data with the U.S. government to prevent breaches, ha said.

      I agree with all of this, but only under the condition that is done with a large dose of oversight and policies and protocols that are open to the public. None of this FISA/national security letter crap.

  2. Re:Terrible idea. by CanadianMacFan · · Score: 3, Interesting

    Or company X actually breaks into company Y but goes to them with made up data saying that company Z used systems from X to do it and then proposes that X and Y launch attacks against Z. Meanwhile Z hasn't done anything and gets attacked by two of it's competitors.