'Hacking back' legislation is back in Congress
Full article645 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
The bill would be a huge amendment to the Computer Fraud and Abuse Act.
A bill legalizing companies’ ability to “hack back” after they’ve been attacked is back on track after months of feedback. Let’s unpack.
Reps. Tom Graves, R-Ga., and Kyrsten Sinema, D-Ariz., introduced a modified Active Cyber Defence Certainty (ACDC) Act on Friday allowing companies to “hack back” against hackers in an effort to identify and stop cyberattacks.
The ACDC amends the Computer Fraud and Abuse Act (CFAA), which makes it illegal to access computers without authorization. Companies and individuals would be granted the right to “active defense” using various ways to identify, disrupt and possibly even destroy data in the name of “hacking back.”
“These changes reflect careful analysis and many thoughtful suggestions from a broad spectrum of industries and viewpoints,” Graves said in a statement. “I thank everyone who helped sharpen this idea and improve the legislation. I look forward to continuing the conversation and formally introducing ACDC in the next few weeks.”
The bill allows hacking victims to retaliate and destroy stolen data “if it’s located using the active-defense techniques permitted by this bill and does not result in the destruction of data belonging to another person,” a press release from Graves explained.
Any attack resulting in financial harm or other collateral damage is forbidden.
The newest version of the bill also requires reporting “for entities that use active-defense techniques,” Graves said, except for “beaconing technology” that helps physically locate an attacker.
A sunset clause of two years was also added, meaning that even if ACDC becomes law, this issue is going to be taken up in Congress at least once more.
“The catch is that it is hard to open the door wide enough to make a genuine difference for victims, without opening the door to a host of unintended problems under two big headings: mistaken attribution and unintended collateral impacts,” Bobby Chesney, a professor at the University of Texas School of Law, wrote earlier this year. ” Put more directly, it is not hard to see how the more aggressive forms of active defense might result in harms to innocent parties. Some amount of risk along those lines may be worth it, depending on the benefits also obtained; it’s just awfully hard to know for sure.”
The sunset and reporting requirements are an attempt to meet recommendations from Chesney and others for oversight and re-examination.
Graves urged passing the bill to develop and use new tools that are currently illegal under the CFAA and to disincentivize criminal hacking.
You can read the full bill here.
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Technology
Threats
Chinese espionage groups swarm to exploit triple-link chain of zero-days
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/hack-back-bill-tom-graves-kyrsten-sineman-cfaa/