Jump to content

Hacking the hackers: Draft US bill would allow hacking victims to hack back


steven36

Recommended Posts

But only to a certain extent…

 

original-6c6264a0fba3832644a291b71343ee1

 

A United States representative has proposed a bill that would allow hacking victims to hack back their attackers.

 

On 3 March, Representative Tom Graves (R-Georgia) proposed a discussion draft of what he's calling "ACDC".

 

original-1c38a917c2ed27f0c9f252d2490d59f

 

No, the bill has nothing to do with the "Thunderstruck" Australian rock band. ACDC in this case stands for "Active Cyber Defense Certainty." It's a term that empowers hacking victims to use "limited defensive measures that exceed the boundaries of one's network" to stop and/or identify digital attackers.

 

Essentially, ACDC empowers companies that have experienced digital intrusions to hack back their attackers. But it's important to note there are some limitations. Indeed, the bill limits victims' defensive measures to gathering data about their attackers and sharing that information with law enforcement. It does not allow other activities such as destroying information, causing physical injury to another person, or creating a threat to public safety and/or health.

 

original-746e613ea85ed02970586d8dfa99fd6

 

That's all well and good. I commend Representative Graves for including those provisions in the bill.

However, even "gathering information" can be a slippery slope when it comes to digital attackers that use compromised machines to carry out their dirty work.

A hacking victim might endeavor to identify to whom an infected computer belongs, for example. In so doing, there's a strong possibility they could violate the computer owner's privacy. Worse, they might discover the machine belongs to a company that stores the personal and/or financial information of customers. By viewing that information without authorization, the victim would inadvertently compromise the confidentiality of that company's data.

 

Representative Graves recognizes there are concerns his bill doesn't address. But it's a start. As he explains on his website

 

Quote

:This bill is about empowering individuals to defend themselves online, just as they have the legal authority to do during a physical assault. While the bill doesn’t solve every problem, it’s an important first step. I

hope my bill helps individuals defend themselves against cybercriminals while igniting a conversation that leads to more ideas and solutions that address this growing threat."

 

At this time, interested parties have a chance to provide feedback and make recommendations for the bill. Once they have done so, Representative Graves can move forward and formally introduce the bill to the U.S. House of Representatives.

 

 

By David Bisson

https://www.grahamcluley.com/draft-bill-would-allow-hacking-victims-to-hack-back/

 

Link to comment
Share on other sites


  • Replies 1
  • Views 599
  • Created
  • Last Reply
5 hours ago, steven36 said:

Essentially, ACDC empowers companies that have experienced digital intrusions to hack back their attackers. But it's important to note there are some limitations. Indeed, the bill limits victims' defensive measures to gathering data about their attackers and sharing that information with law enforcement. It does not allow other activities such as destroying information, causing physical injury to another person, or creating a threat to public safety and/or health.

 

First it just allows what is currently going on in large organizations and then it wants to stop what the government does in certain situations.  All in all, it is a useless bill.  The current status quo is working fine.

Link to comment
Share on other sites


Archived

This topic is now archived and is closed to further replies.

  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...