Where will Hacking Back Against Cyber ​​Crime follow?

[ad_1]

On his first trip abroad since taking office, President Joe Biden is in Europe this week to meet with world leaders, including Russian President Vladimir Putin. There are many important aspects to this story and many tips on how Biden should handle the situation. But a careful aspect of this story includes what can be said and done to curb cybercrime and stop accelerating ransomware attacks?

The Russian government has denied any ransomware involvement, which may be technically true, but many world leaders are urging countries to do more to stop criminals who may be operating within their borders.

Actually, FBI Director Christopher Wray compared the ransomware challenge to 9/11 and called for a coordinated battle throughout society.


I showed up MiTechNews last Monday with Mike Brennan to discuss the global ransomware situation, and what the US can do to address the problems nationally. (Note: It is widely acknowledged that public and private sector companies need to do more to protect themselves as a top priority.)

BACK NOW BACK TO AGENDA?

There have been several articles in the past month calling on organizations to continue attacking or attacking criminals in cyberspace. Indeed, several articles caught my attention this past week:

Idaho News: BSU cyber expert: US must return to ransomware blackmailers
“Eduardo Vasco is the director of the Boise State Institute for Pervasive Government Security, which was created in 2020 to analyze and teach ways to protect our computers and devices from cyber attacks, such as the growing threat of ransomware. Vasco says the challenge facing America now is to play a solid defense while developing a strong attack: in other words, learning to fool around.

American University: Hack-Back: Towards a legal framework for cyber self-defense

“The rights of private entities to use reasonable force have not been extended to cyberspace. Under current law, it is illegal for a victim of a cyber attack to hack, that is, to launch a counterattack aimed at disabling or gathering evidence against This general ban imposes enormous restrictions on the private sector ‘s ability to respond to cyberattacks.Criminalizing self – defense would seem ridiculous to the natural world, but cyberspace blurs traditional notions of ownership, security, self – defense and role.

Forbes: As Ransomware Hackers Sit on Millions of Repulsed Money, the US military is called to back down
The Dutch police undertook the testing and development of the hack. Asked about such violations, Marijn Schuurbiers, deputy head of the Dutch High-Tech Crime Unit, told Forbes that his team was doing similar things that criminals would do, in particular escalating privileges where a computer was hacked and hacked. administrator rights. From that point on, you can basically do whatever you want. And, he added, this could be done on multiple servers at once. … The Biden government is called upon to go even further than those law enforcement agencies and to use the powers of military services such as the US Government. Whether the target has a strategic impact on the country, such as the Colonial Pipeline, or the health care system or the banking system, it does not matter if it is a criminal or a nation state, Williams, a former Pentagon official, added. We must stop saying that our job is to chase the aggressors of the nation state. Our job must be to follow the attackers who have a strategic impact on our country.

Reuters: Exclusive: The US gives ransomware hacking a similar priority to terrorism
The U.S. Department of Justice is raising the issue of ransomware attacks to a similar priority to terrorism following the Colonial Pipeline breach and the growing damage caused by cybercriminals, a senior State Department official said.

Internal guidance sent Thursday to U.S. Attorneys across the country said information about ransomware investigations in the area should be centrally coordinated with a newly formed working group in Washington.

When I published the first article by Idaho News on LinkedIn, reactions were everywhere on the map. Here are some of the notable comments:

Dr. Dave Schippers, Sc.D., CISSP: This is a Pandora box. In a way, I agree with others, I do not. Will my biggest concern turn into a slippery slope? I often wonder – what are the moral consequences of such actions? I am not saying what is or is not moral here. When people start demanding action – we need to evaluate it objectively and look at the long-term pros, cons and moral implications. We must respond rationally and free of emotions to avoid moral dilemmas. These are my initial thoughts.

Chip Block, Vice President and Architectural Architectural Solutions at Evolver, a company Converged Security Solutions, wrote: As the article you wrote a few years ago points out, we have been discussing this issue for a long time. Hack back has turned into a kind of mercenary activity that most people prefer not to talk about. I do not see this clearly changing in terms of responsibility. If attackers use a hospital system to launch their attacks and your return from the hospital destroys you, this is a big legal problem. The reality is that there are some situations that make sense, with DDOS being the primary. Hacking in the middle of a ransomware would be in the category of “incredibly stupid” because it could ruin any chance of getting decryption codes.

Mark Dobson of NextUse wrote: Dan, I think it is a logical and well-established dogma when it threatens to use an attack mix to deter and defend to prevent further aggression.

But, do I think it is inevitable and unavoidable that this will escalate, leading to his concern about where the escalation will stop? When a country destroys Anothers critical infrastructure badly enough that it costs millions / billions to repair or kills 10s / 100s / 1000 people? When does this, in turn, lead to a kinetic response that translates into a declared IRL of war?

You can read the other comments and join the discussion on this LinkedIn thread here:

HACKING BACK IS NOT A NEW ISSUE

As Mark mentioned, this issue has been around for quite some time. It appears to occur more during periods of significant data breaches and / or cyber attacks that appear to cross the line. Here are some previous articles I have written on the subject of piracy:

Can Hacking Back be an effective response in cyberspace? (2016)

“With the exponential growth of data breaches in recent years, the concept of piracy is growing in popularity. Proponents ask: If I can use a weapon of self-defense in my home, why can’t I also crack down on cybercriminals?” Let us look at this hypothesis from different angles.

What can be done? A popular answer is to fight the bad guys. People call it many different things, from cyber-attack capabilities to electronic countermeasures to hacking or hacking.

Hack Back Law: Why the future may look like marijuana legalization (2017)

“Hacking back was on the news in 2017, with new proposed legislation that would legitimize the forms of a more proactive defense for companies. When added to the hacking back activity under public radar right now, it seems likely that some form of legitimacy is inevitable.

In addition, I have heard many trusted experts describe their hacking experiences at various companies and describe legalization (with precautions) as the inevitable next step.

Also, the recent series of significant data breaches, from Equifax to the SEC, for a long a number of other significant data breaches, is causing more public outrage about cyber security than ever before. “

THE FOLLOWING US-RUSSIAN SUMMARY

A few weeks back, this article from The hill suggested that President Biden is stepping up pressure on Russians to prosecute cybercriminals in their own country.

The response to this post on LinkedIn was overwhelming, with Mark Wallace of Data by Design LLC saying, “If the Russians can look you in the eye and deny any involvement with the multiple Novichok (a chemical warfare agent that developed and exclusively occupied by the Russians ») Army) poisonings, I am very sure that they can divert any attempt to accuse them of violation. There is no smoking weapon. The fact that some software units of Russian origin were used in the ransomware attacks does not come millions of miles away from the evidence that the Russian government or its agents were involved. The modules are available to anyone on the Dark Web.

My answer to Mark (and the views on this upcoming summit) was: Good, good points and understandable And yet, as in many situations with opponents spying for decades, there are always 2+ sets of deals. One for public consumption and another behind the scenes.

Many good books on the subject go back to the Cold War. an excellent one I reviewed here: https://www.govtech.com/blogs/lohrmann-on-cybersecurity/book-review-the-spy-in-moscow-station.html.

I agree that they will look us in the eye and I will deny many things as we do to them and others in the public and the UN. Many reasons for this. including black ops, domestic policy, NATO and others.

But I still support the possibility of partial trading behind closed doors. There is no doubt classified details that we can not share on LinkedIn that show Russia’s involvement, according to the FBI. This is too complicated to say the least, and players become dark and wear a lot of hats.

However, I agree, as I concluded, that piracy will not stop because it is one of their best weapons. But pause? Slow? Maybe. Develop? Absolutely.



[ad_2]

picture credit

Related Posts