Back in June, Sen Daines (R,MT) introduced S 2292, the Study on Cyber-Attack Response Options Act. The bill would require DHS to conduct a study on the potential consequences and benefits of amending the Computer Fraud and Abuse Act to allow private companies to take proportional actions in response to an unlawful network breach. No funding is authorized by this bill.
The Study and Report
Section 2(a) of the bill would require DHS to conduct a study on the potential benefits and risk of changing the provisions of 18 USC 1030 to “allow private entities to take proportional actions in response to an unlawful network breach, subject to oversight and regulation by a designated Federal agency.”
Within 180-days of the enactment of this bill, DHS would be required to provide a report to Congress on the findings of the study. The report would “address any impact on national security and foreign affairs” and include recommendations on:
Which Federal agency or agencies may authorize proportional actions by private entities?
What level of certainty regarding the identity of the attacker is needed before such actions would be authorized?
Which entities would be allowed to take such actions and under what circumstances?
What actions would be permissible?
What safeguards should be in place?
Moving Forward
Neither Daines or his sole cosponsor {Sen Whitehouse (D,RI)} are members of the Senate Homeland Security and Governmental Affairs Committee to which this bill was assigned for consideration. This means that it is unlikely that there would be enough influence to see this bill be considered in Committee. While this is only a study and report bill, I believe that this hacking back concept is controversial enough that there might be bipartisan opposition to the bill for a variety of ideological reasons. I do not think that there would be sufficient support to favorably report the bill out of the Committee.
Commentary
The concept of authorizing letters of cyber marque allowing non-governmental entities to legally conduct cyber-attacks on hackers attracts a certain level of support. A wide variety of criminal organizations and semi-governmental APT organizations are conducting operations against public and private targets in this country under the de facto protection of a number of foreign regimes. The federal government is politically constrained from taking actions against these organizations for fear of escalating the response to some higher level of cyber conflict between governments.
The problem with officially supporting such counterattacks would formally acknowledge that semi-official cyber attacks are a legitimate tool that governments are free to use in the cyber realm, taking away any possible claim to the moral high ground in attempting to stop this form of predation. Further, the foreign governments involved are very likely to treat government authorized and supervised attacks as governmental attacks, thus increasing the same risk of escalation that restrains government agencies from attacking these same foreign entities.
Having said all of that, the idea is sure to gain support as the government continues to fail to demonstrate an ability with these foreign cyber adversaries. A comprehensive study of the problem is really necessary to be able to properly address the suggestion. I do not, however, think that DHS is the agency which should be tasked with the study; the implications impact a much wider swath of the government and private sector than what DHS can cover. This is more appropriately a task for the Office of the National Cyber Director.