{"id":2264,"date":"2014-09-17T01:21:49","date_gmt":"2014-09-17T01:21:49","guid":{"rendered":"http:\/\/jolt.richmond.edu\/?p=2264"},"modified":"2019-03-08T19:52:27","modified_gmt":"2019-03-09T00:52:27","slug":"cyber-security-active-defense-playing-with-fire-or-sound-risk-management","status":"publish","type":"post","link":"https:\/\/blog.richmond.edu\/jolt\/2014\/09\/17\/cyber-security-active-defense-playing-with-fire-or-sound-risk-management\/","title":{"rendered":"Cyber Security Active Defense:  Playing with Fire or Sound Risk Management?"},"content":{"rendered":"<p><a href=\"http:\/\/jolt.richmond.edu\/v20i4\/article12.pdf\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-128\" src=\"http:\/\/jolt.richmond.edu\/files\/2012\/05\/pdf_icon1.gif\" alt=\"pdf_icon\" width=\"16\" height=\"16\" \/>DownloadPDF<\/a><\/p>\n<p style=\"text-align: center\">Cite as: Sean L. Harrington, <em>Cyber Security Active Defense: Playing with Fire or Sound Risk Management?<\/em>, 20 Rich. J.L. &amp; Tech. 12 (2014), http:\/\/jolt.richmond.edu\/v20i4\/article12.pdf.<\/p>\n<p style=\"text-align: center\">\u00a0Sean L. Harrington*<\/p>\n<p style=\"text-align: center\"><em>Trying to change its program<\/em><\/p>\n<p style=\"text-align: center\"><em>Trying to change the mode . . . crack the code<\/em><\/p>\n<p style=\"text-align: center\"><em>Images conflicting into data overload<\/em>[1]<\/p>\n<h2 style=\"text-align: center\"><\/h2>\n<h2 style=\"text-align: center\">\u00a0<strong>I. Introduction<\/strong><\/h2>\n<p>[1]\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 \u201cBanks Remain the Top Target for Hackers, Report Says,\u201d is the title of an April 2013 <em>American Banker <\/em>article.[2] Yet, no new comprehensive U.S. cyber legislation has been enacted since 2002,[3] and neither legislative history nor the statutory language of the Computer Fraud and Abuse Act (CFAA) or Electronic Communications Privacy Act (ECPA) make reference to the Internet.[4] Courts have nevertheless filled in the gaps\u2014sometimes with surprising results.<\/p>\n<p>[2]\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Because state law, federal legislative proposals, and case law all are in a continuing state of flux, practitioners have found it necessary to follow these developments carefully, forecast, and adapt to them, all of which has proved quite challenging. As the title of this Comment suggests, deploying sound cyber security practices is not only equally as challenging, but also \u201crisky,\u201d which may seem counterintuitive in light of the fact that intent of cyber security programs is to manage risk, not create it.[5]<\/p>\n<p>[3]\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Cyber security risks concern exploits made possible by technological advances, some of which are styled with familiar catch-phrases: \u201ce-Discovery,\u201d \u201csocial media,\u201d \u201ccloud computing,\u201d \u201cCrowdsourcing,\u201d and \u201cbig data,\u201d to name a few. Yet, long before the term \u201ccloud computing\u201d became part of contemporary parlance, Picasa used to store photos in the cloud (where the \u201ccloud\u201d is a metaphor for the Internet).[6] This author has been using Hotmail since 1997 (another form of cloud computing). As the foregoing examples illustrate, the neologisms were long predated by their underlying concepts.<\/p>\n<p>[4]\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 One of the latest techno-phrases du jour is \u201chack back.\u201d[7] The concept isn\u2019t new, and the term has been \u201ccommon\u201d parlance at least as far back as 2003.[8] \u201cHack back\u201d\u2014sometimes termed \u201cactive defense,\u201d \u201cback hacking,\u201d \u201cretaliatory hacking,\u201d or \u201coffensive countermeasures\u201d (\u201cOCM\u201d)\u2014has been defined as the<\/p>\n<p style=\"padding-left: 30px\">\u201cprocess of identifying attacks on a system and, if possible, identifying the origin of the attacks.\u201d Back hacking can be thought of as a kind of reverse engineering of hacking efforts, where security consultants and other professionals try to anticipate attacks and work on adequate responses.\u201d[9]<\/p>\n<p>A more accurate and concise definition might be \u201cturning the tables on a cyberhacking assailant: thwarting or stopping the crime, or perhaps even trying to steal back what was taken.\u201d[10] One private security firm, renowned for its relevant specialization, defines active defense, in pertinent part, as \u201cdeception, containment, tying up adversary resources, and creating doubt and confusion while denying them the benefits of their operations.\u201d[11] Some have proposed\u2014or carried out\u2014additional measures, such as \u201cphotographing the hacker using his own system\u2019s camera, implanting malware in the hacker\u2019s network, or even physically disabling or destroying the hacker\u2019s own computer or network.\u201d[12]<\/p>\n<p>[5]\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Back hacking has been a top-trending technology topic over the past year, prompted in part by the controversial Report of the Commission on the Theft of American Intellectual Property (\u201cIP Commission Report\u201d),[13] and has been debated on blogs, symposium panels, editorials, and news media forums by information security professionals and lawyers alike. One with the potential to grab practitioners\u2019 attention was a panel of attorneys David Navetta and Ron Raether\u2014both well regarded in the information security community\u2014discussing the utility and propriety of such practices. One opined that, if the circumstance is exigent enough, a company may take \u201cmeasures into [its] own hands,\u201d and that it would, \u201cnot likely be prosecuted under the CFAA, depending on the exigency of the circumstances.\u201d[14] The other reasoned that hack back \u201ctechnically violates the law, but is anyone going to prosecute you for that? Unlikely.\u201d[15] He noted, \u201c[i]t provides a treasure trove of forensic information that you can use,\u201d and continued, \u201c[w]ith respect to the more extreme end of hack back, where you are actually going to shut down servers, I think there is a necessity element to it\u2014an exigency: if someone\u2019s life is threatened, if it appears that there is going to be a monumental effect on the company, then it might be justified.\u201d[16] In 2014 at the most recent RSA conference, where the \u201chackback\u201d debate continued, the presentation was billed, in part, with the proposition, \u201c[a]ctive defense should be viewed as a diverse set of techniques along a spectrum of varying risk and legality.\u201d[17] And, other commentators have urged that \u201coffensive operations must be considered as a possible device in the cyber toolkit.\u201d [18]<\/p>\n<p>[6]\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Most commentators and scholars, however, seem to agree that \u201chack back\u201d is not only \u201crisky,\u201d but is also not a viable option for a variety of reasons.[19] Hack backs and other surreptitious cyber acts incur the risks of criminal liability, civil liability, regulatory liability, professional discipline, compromise of corporate ethics, injury to brand image, and escalation. One practitioner quoted by the LA Times exclaimed, \u201c[i]t&#8217;s not only legally wrong, it&#8217;s morally wrong.\u201d[20] James Andrew Lewis, a senior fellow at the Center for Strategic and International Studies, characterized hacking back as \u201ca remarkably bad idea that would harm the national interest.\u201d[21] The Cyber Intelligence Sharing and Protection Act, a major cybersecurity bill passed by the House in April 2013, contained an amendment that specifically provided that the bill did not permit hacking back.[22] Representative Jim Langevin (RI-D), who authored the amendment, explained, \u201c[w]ithout this clear restriction, there is simply too much risk of potentially dangerous misattribution or misunderstanding of any hack-back actions.\u201d[23] Further, the private security firm renowned for its active defense strategies, mentioned <em>ante,<\/em> has attempted to distance itself from the phrases such as \u201chack back\u201d and \u201cretaliatory hacking,\u201d preferring instead the broader phrase \u201cactive defense.\u201d[24] Another example of the importance of subtleties in word choice may be \u201cCountermeasure,\u201d where some appear to have conflated the word with the concept of active defense.[25]<\/p>\n<h2 style=\"text-align: center\"><\/h2>\n<h2 style=\"text-align: center\"><strong>II. Active Defense Approaches<\/strong><\/h2>\n<p>[7]\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Self-defense is not an abstraction created by civilization, but a law spawned by nature itself, and has been justified since antiquity.[26] It has been regarded since the early modern period as available to redress injuries against a state\u2019s sovereign rights.[27] There is little question cyber-attacks against a designated critical infrastructure are attacks against a state\u2019s sovereign rights,[28] because much of civilian infrastructure is both a military and national asset.[29] Accordingly, the focus of 2014 NATO International Conference on Cyber Conflict (\u201cCyCon\u201d) is active cyber defense, including implications for critical infrastructure.[30] Likewise, a project sponsored by NATO\u2019s Cooperative Cyber Defense Centre of Excellence is set to publish a report in 2016 that establishes acceptable responses to pedestrian or quotidian cyber-attacks against nations, whereas its predecessor, regarded as an academic text, focused on cyber-attacks against a country that are physically disruptive or injurious to people and possible responses under the UN charter and military rules.[31] Both works are based on the concepts of self-defense and, under certain circumstances, preemptive \u201canticipatory self-defense.\u201d[32]<\/p>\n<p>[8]\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 The questions that scholars, policymakers, information security experts, and corporate executives have struggled with, however, is at what threshold do such attacks warrant the protection of the state,[33] whether a private corporation may respond in lieu of or in concert with protection by the state, and to what extent such collusion constitutes excessive entanglement between the private and public sector. Implicit in these questions is whether the government is willing and able to develop a modern and adaptable regulatory and criminal law framework and to allocate adequate law enforcement resources to confront the problem.[34] Because, at the time of this writing, it is widely perceived that the government is not yet willing and able,[35] victims often do not report suspected or actual cyber-attacks, and have resorted to inappropriate self-help, deploying their own means of investigating and punishing transgressors.[36] As one commentator posits,<\/p>\n<p style=\"padding-left: 30px\">With regard to computer crime, some might argue that the <em>entire<\/em> investigative process be outsourced to the business community. Historically, the privatization of investigations has assisted public law enforcement by allowing them to concentrate on other responsibilities, and has prevented their resources from being allocated in too sparse a manner to be useful.\u201d [37]<\/p>\n<p>Awaiting the ultimate resolution of these questions, American corporations have developed an array of active defense tactics. Below are a few of the more common examples of those, and the corresponding challenges:<\/p>\n<h3>\u00a0A. <strong>Beaconing<\/strong><\/h3>\n<p>[9]\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Beaconing is one of the most cited active defense techniques, and one mentioned in the IP Commission Report (along with \u201cmeta-tagging,\u201d and \u201cwatermarking\u201d) as a way to enhance electronic files to \u201callow for awareness of whether protected information has left an authorized network and can potentially identify the location of files in the event that they are stolen.\u201d[38] A benign version of beaconing is the use of so-called Web bugs.[39] A Web bug is a link\u2014a surreptitious file object\u2014commonly used by spammers and placed in an e-mail message or e-mail attachment, which, when opened, will cause the e-mail client or program will attempt to retrieve an image file object from a remote Web server and, in the process, transmit information that includes the user\u2019s IP address and other information.[40] This transmission is not possible \u201cif the user did not preconfigure the e-mail client or program to refrain from retrieving images or HTML content from the Internet,\u201d or if the user\u2019s e-mail client blocks externally-hosted images by default.[41] \u201cThis information becomes available to the sender either through an automated report service (<em>e.g., <\/em>ReadNotify.com) or simply by monitoring traffic to the Web server.\u201d[42] In one project demonstrating the use advocated by the IP Commission Report, researchers employed such technology in decoy documents to track possible misuse of confidential documents.[43] So, is beaconing legal?<\/p>\n<p>[10]\u00a0\u00a0\u00a0\u00a0\u00a0 <em>The Wall Street Journal <\/em>(the \u201c<em>Journal<\/em>\u201d) quoted Drexel University law professor Harvey Rishikof\u2014who also is co-chairman of the American Bar Association\u2019s Cybersecurity Legal Task Force\u2014as saying the legality of beaconing is not entirely clear.[44] Rishikof is quoted as saying, \u201c\u2018[t]here&#8217;s the black-letter law, and there&#8217;s the gray area. . . . Can you put a beacon on your data? Another level is, could you put something on your data that would perform a more aggressive action if the data was taken?\u2019\u201d[45] The article went on to suggest more aggressive strategies such as \u201cinserting code that would cause stolen data to self-destruct or inserting a program in the data that would allow a company to seize control of any cameras on the computers where the data were being stored.\u201d[46] The<em> Journal<\/em>, citing an anonymous Justice Department source, further reported that, \u201c[i]n certain circumstances beaconing could be legal, as long as the concealed software wouldn&#8217;t do other things like allow a company to access information on the system where the stolen data were stored.\u201d[47]<\/p>\n<p>[11]\u00a0\u00a0\u00a0\u00a0\u00a0 Another important consideration is the fact that beaconing may fall within one of the active defense definitions (<em>supra<\/em>) as \u201cdeception.\u201d[48] Although deception is recognized as both a common and effective investigative technique,[49] the problem is the possibility that the activities of the investigator could be imputed under Model Rule of Professional Conduct 5.3 to one or more attorneys responsible for directing or approving of those activities.[50] Under Model Rule 8.4(c), neither an attorney nor an attorney\u2019s agent under his or her direction or control may \u201cengage in conduct involving dishonesty, fraud, deceit, or misrepresentation.\u201d[51] Although the question of whether deception, as contemplated in Rule 8.4, exists in the context of incident response or network forensics investigations is not well settled,[52] most states have held \u201c[t]here are circumstances where failure to make a disclosure is the equivalent of an affirmative misrepresentation.\u201d[53] A few state bar associations have already addressed similar technology-related ethical pitfalls. The Philadelphia Bar Association Professional Guidance Committee advised in Opinion 2009\u201302 that an attorney who asks an agent (such as an investigator) to \u201cfriend\u201d a party in Facebook in order to obtain access to that party\u2019s non-public information, would violate, among others, Rule 5.3 of the Pennsylvania Rules of Professional Conduct.[54] Likewise, the Association of the Bar of the City of New York Committee on Professional and Judicial Ethics issued Formal Opinion 2010\u20132, which provides that a lawyer violates, among others, New York Rules of Professional Conduct Rule 5.3, if an attorney employs an agent to engage in the deception of \u201cfriending\u201d a party under false pretenses to obtain evidence from a social networking website.[55]<\/p>\n<h3><strong>B. Threat Counter-Intelligence Gathering<\/strong><\/h3>\n<p>[12]\u00a0\u00a0\u00a0\u00a0\u00a0 One of the most seemingly-innocuous active defense activities is intelligence gathering. Security analyst David Bianco defines threat intelligence as \u201c[c]onsuming information about adversaries, tools or techniques and applying this to incoming data to identify malicious activity.\u201d[56] Threat intelligence gathering ranges from everything from reverse malware analysis and attribution to monitoring inbound and outbound corporate e-mail to more risky endeavors.[57] Some security experts claim to frequent \u201cInternet store fronts\u201d for malware, \u201cafter carefully cloaking [their] identity to remain anonymous.\u201d[58] The reality, however, is that gaining access to and remaining on these black market fora requires the surreptitious visitor either to: (1) participate (\u201cpay to play\u201d); (2) to have developed a reputation over months or years, or founded the underground forum <em>ab initio<\/em>;or (3) to have befriended or been extended a personal invitation by an established member. The first two of these three activities implies that the participant would have co-conspirator or accomplice liability in the underlying crimes. Another risk is, if the site is reputed to also purvey child pornography, a court may find that the site visitor acquired possession (even as temporary Internet cache) of the contraband knowingly, even if the true intent of lurking was to gather intelligence.[59] Another obvious risk is that surreptitious monitoring of hacker sites using false credentials or representations is an act of deception which, for the reasons more fully set forth above, could create disciplinary liability for any attorneys who are involved or acquiesce to the activity.<\/p>\n<h3><strong>C. Sinkholing<\/strong><\/h3>\n<p>[13]\u00a0\u00a0\u00a0\u00a0\u00a0 Sinkholing is the impersonation of a botnet command-and-control server in order to intercept and receive malicious traffic from its clients.[60] To accomplish this, either the domain registrar must redirect the domain name to the investigator\u2019s machine (which only works when the connection is based on a DNS name), or the Internet Service Provider (ISP) must redirect an existing IP address to the investigator\u2019s machine (possible only if the investigator\u2019s machine is located in the IP range of the same provider), or the ISP must redirect all traffic destined for an IP address to the investigator\u2019s machine, instead (the \u201cwalled garden\u201d approach).[61]<\/p>\n<p>[14]\u00a0\u00a0\u00a0\u00a0\u00a0 Sinkholing involves the same issues of deception discussed <em>ante,<\/em> but also relies on the domain registrar\u2019s willingness and legal ability to assist. As Link and Sancho point out in their paper <em>Lessons Learned While Sinkholing Botnets\u2014Not as Easy as it Looks!<\/em>,\u201c[u]nless there is a court order that compels them to comply with such a request, without the explicit consent of the owner\/end-user of the domain, the registrar is unable to grant such requests.\u201d[62] Doubtless they were referring to the Wiretap Act (Title 1 of the Electronic Communications Privacy Act), which generally prohibits unconsented interception (contemporaneous with transmission), disclosure, or use of electronic communications.[63] Further, a federal district court recently ruled that intentionally circumventing an IP address blacklist in order to crawl an otherwise-publicly available website constitutes \u201caccess without authorization\u201d under the CFAA.[64] Link and Sancho continue that registrars have little incentive to assist because it does not generate revenue, and note that sinkholing invites distributed denial of service (\u201cDDoS\u201d) retaliation which could affect other customers of a cloud-provided broadband connection<em>.<\/em>[65] Finally, sinkholing is likely to collect significant amounts of data, including personally identifiable information (\u201cPII\u201d). The entity collecting PII is likely to be subject to the data privacy, handling, and disclosure laws of all the jurisdictions whence the data came.<\/p>\n<h3><strong>D. Honeypots<\/strong><strong><br \/>\n<\/strong><\/h3>\n<p>[15]\u00a0\u00a0\u00a0\u00a0\u00a0 A honeypot is defined as \u201ca computer system on the Internet that is expressly set up to attract and \u2018trap\u2019 people who attempt to penetrate other people\u2019s computer systems.\u201d[66] It may be best thought of as \u201can information system resource whose value lies in unauthorized or illicit use of that resource.\u201d[67] Honeypots do arguably involve deception, but have been in use for a comparatively long time, and are generally accepted as a valid information security tactic (therefore, relatively free from controversy). The legal risks, historically, have been identified as: (1) potential violations of the ECPA;[68] and (2) possibly creating an entrapment defense for the intruder.[69] Neither of these is applicable here, because, respectively: (1) the context of the deployment discussed herein is the corporate entity as the honeypot owner (thus, a party to the wire communication); and (2) the corporate entity is not an agent of law enforcement, and, further, the entrapment defense is only available when defendant was not predisposed to commit the crime (here, a hacker intruding into a honeypot is predisposed).[70] Nevertheless, Justice Department attorney Richard Salgado, speaking at the Black Hat Briefings, did reportedly warn that the law regarding honeypots is \u201cuntested\u201d and that entities implementing devices or networks designed to attract hackers could face such legal issues as liability for an attack launched from a compromised honeypot.[71] This possibility was discussed six years ago:<\/p>\n<p style=\"padding-left: 30px\">If a hacker compromises a system in which the owner has not taken reasonable care to secure and uses it to launch an attack against a third party, the owner of that system may be liable to the third party for negligence. Experts refer to this scenario as \u201cdownstream liability.\u201d Although a case has yet to arise in the courts, honeypot operators may be especially vulnerable to downstream liability claims since it is highly foreseeable that such a system be misused in this manner.[72]<\/p>\n<p>Another honeypot risk is the unintended consequence of becoming a directed target because the honeypot provoked or attracted hackers to the company that deployed it, which hackers might otherwise have moved on to easier targets. Another is that an improperly configured honeypot could ensnare an innocent third party or customer and collect legally-protected information (such as PII). If that information is not handled according to applicable law, the owner of the honeypot could incur statutory liabilities therefor.[73] And yet another scenario is one that, perhaps, only a lawyer would recognize as a risk: \u201c[i]f you have a honeypot and do learn a lot from it but don\u2019t remedy or correct it, then there\u2019s a record that is discoverable and that you knew you had a problem and didn\u2019t [timely] fix it.\u201d[74]<\/p>\n<p>[16]\u00a0\u00a0\u00a0\u00a0\u00a0 Finally, there are uses for honeypots which, when regarded as a source of revenue by its owners, have the potential to cause substantial injury to brand image and reputation, and possibly court sanctions: one law firm has been accused of seeding the very copyrighted content it was retained to protect, which the firm used as evidence in copyright suits it prosecuted.[75] Because of these alleged activities, the firm has been labelled a \u201ccopyright troll.\u201d[76] The allegations, if proved true, also appear to involve acts of deception, discussed <em>ante,<\/em> which may subject the firm\u2019s attorneys to attorney disciplinary proceedings.[77] Further, the firm\u2019s attorneys may incur other possible liabilities, such as vexatious and frivolous filing sanctions, abuse of process, barratry, or champerty.[78]<\/p>\n<h3><strong>E. Retaliatory Hacking<\/strong><\/h3>\n<p>[17]\u00a0\u00a0\u00a0\u00a0\u00a0 A common belief for why corporations have little to fear in the way of prosecution for retaliatory hacking is, \u201ccriminals don\u2019t call the cops.\u201d[79] Nevertheless, there is little debate that affirmative retaliatory hacking is unlawful,[80] even if done in the interests of national security.[81] Although there may be \u201clittle debate,\u201d there is debate.[82]The views of many passionate information security analysts could be summed up by authors John Strand and Paul Asadoorian, who argue, \u201c[c]urrently, our only defense tools are the same tools we have had for the past 10+ years, and they are failing.\u201d[83] David Willson, the owner and president of Titan Info Security Group, and a retired Army JAG, contends that using \u201cautomated tools outside of your own network to defend against attacks by innocent but compromised machines\u201d is not gaining unauthorized access or a computer trespass, and he asks, \u201c[i]f it is, how is it different from the adware, spam, cookies, or others that load on your machine without your knowledge, or at least with passive consent?\u201d[84] Willson provides a typical scenario and then examines the statutory language of the CFAA and offers some possible arguments\u2014but notes his arguments bear stretch marks (and he makes no offer of indemnification should practitioners decide to use them).[85]<\/p>\n<p>[18]\u00a0\u00a0\u00a0\u00a0\u00a0 Willson is not alone in searching for leeway within the CFAA. Stewart Baker, former NSA general counsel, argues on his blog,<\/p>\n<p style=\"padding-left: 30px\">Does the CFAA, prohibit counterhacking? The use of the words \u201cmay be illegal,\u201d and \u201cshould not\u201d are a clue that the law is at best ambiguous. . . . [V]iolations of the CFAA depend on \u201cauthorization.\u201d If you have authorization, it\u2019s nearly impossible to violate the CFAA . . . [b]ut the CFAA doesn\u2019t define \u201cauthorization.\u201d . . . The more difficult question is whether you\u2019re \u201cauthorized\u201d to hack into the attacker\u2019s machine to extract information about him and to trace your files. As far as I know, that question has never been litigated, and Congress\u2019s silence on the meaning of \u201cauthorization\u201d allows both sides to make very different arguments. . . . [C]omputer hackers won\u2019t be bringing many lawsuits against their victims. The real question is whether victims can be criminally prosecuted for breaking into their attacker\u2019s machine.[86]<\/p>\n<p>Other theories \u2014and assorted arguments bearing stretch marks\u2014 analogize retaliatory hacking as subject to the recapture of chattels privilege,[87] entry upon land to remove chattels,[88] private necessity,[89] or even the castle doctrine.[90] Jassandra K. Nanini, a cybersecurity law specialist, suggests applying the \u201csecurity guard doctrine\u201d as an analogy.[91] She posits that, if private actors act independently of law enforcement and have a valid purpose for their security activities that remains separate from law enforcement, then incidental use of evidence gained through those activities by law enforcement is permissible, even if the security guard acted unreasonably (as long as he remained within the confines of the purpose of his employer\u2019s interests).[92] As applied, Nanini explains the analogy as follows:<\/p>\n<p style=\"padding-left: 30px\">If digital property were considered the same as physical, cyber security \u00a0\u00a0\u00a0\u00a0\u00a0 guards could \u201cpatrol\u201d client networks in search of intruder footprints, and based on sufficient evidence of a breach by a particular hacker, perhaps indicated by the user\u2019s ISP, initiate a breach of the invader\u2019s network in order to search for compromised data and disable its further use. Even more aggressive attacks designed to plant malware in hacker networks could be considered seizure of an offensive weapon, comparable to a school security guard seizing a handgun from a malicious party. Such proactive defense could use the hacker\u2019s own malware to corrupt his systems when he attempts to retrieve the data from the company\u2019s system. Certainly all of these activities are within the scope of the company\u2019s valid interest, which include maintaining data integrity, preventing use of stolen data, and disabling further attack. . . . Similarly, companies may wholly lack any consideration of collecting evidence for legal recourse, keeping in step with the private interest requirement of the private security guard doctrine in general. All hack-backs could be executed without any support or direction from law enforcement, opening the door to utilization \u00a0\u00a0\u00a0\u00a0\u00a0 of evidence in a future prosecution against the hacker. [93]<\/p>\n<p>The foregoing theories notwithstanding, what is clear is that obtaining evidence by use of a keylogger, spyware, or persistent cookies likely is violative of state and federal laws<em>,<\/em> such asthe CFAA or ECPA.[94] The CFAA, last amended in 2008, criminalizes anyone who commits, attempts to commit, or conspires to commit an offense under the Act, including offenses such as knowingly accessing without authorization a protected computer (for delineated purposes) or intentionally accessing a computer without authorization (for separately delineated purposes).[95] Relevant statutory phrases, such as \u201cwithout authorization\u201d and \u201caccess,\u201d have been the continuing subject of appellate review.[96] One federal court, referring to both the ECPA and CFAA, pointed out that \u201cthe histories of these statutes reveal specific Congressional goals\u2014<em>punishing destructive hacking<\/em>, preventing wiretapping for criminal or tortious purposes, securing the operations of electronic communication service providers\u2014that are carefully embodied in these criminal statutes and their corresponding civil rights of action.\u201d[97] At least one court has held that the use of persistent tracking cookies is a violation of the Electronic Communications Privacy Act.[98] Congress is currently considering reform to the CFAA, as well as comprehensive privacy legislation that would, in some circumstances, afford a private right of action to consumers whose personal information is collected without their consent. [99]<\/p>\n<p>[19]\u00a0\u00a0\u00a0\u00a0\u00a0 Regardless of the frequency with which retaliatory hacking charges have been brought, one issue that has not yet been included in the debate involves illegally obtained evidence that is inadmissible. This matters because bringing suit under the CFAA or ECPA is a remedy that corporate victims have recently invoked increasingly.[100]<\/p>\n<p>[20]\u00a0\u00a0\u00a0\u00a0\u00a0 Another liability \u2014the one most frequently cited\u2014 is that of misattribution and collateral damage:<\/p>\n<p style=\"padding-left: 30px\">[E]ncouraging digital vigilantes will only make the mayhem worse. Hackers like to cover their tracks by routing attacks through other people\u2019s computers, without the owners\u2019 knowledge. That raises the alarming prospect of collateral damage to an innocent bystander\u2019s systems: imagine the possible consequences if the unwitting host of a battle between hackers and counter-hackers were a hospital\u2019s computer.[101]<\/p>\n<p>Likewise, Representative Mike Rogers (R-MI), sponsor for the Cyber Intelligence Sharing and Protection Act (CISPA) and Chair of the House Permanent Select Committee on Intelligence, warned private corporations against going on the offensive as part of their cyber security programs: \u201cYou don&#8217;t want to attack the wrong place or disrupt the wrong place for somebody who didn&#8217;t perpetrate a crime.\u201d[102] Contemplate the civil liabilities that one could incur if, in an effort to take down a botnet through self-help and vigilantism, the damaged computers belonged to customers, competitors, or competitors\u2019 customers. Aside from the financial losses and injury to brand reputation and goodwill, implicated financial institutions could expect increased regulatory scrutiny and could compromise government contracts subject to FISMA.<\/p>\n<p>[21]\u00a0\u00a0\u00a0\u00a0\u00a0 Yet another frequently discussed liability is that of escalation: cybercrime is perpetrated by many different attacker profiles of persons and entities, including cyber-terrorists, cyber-spies, cyber-thieves, cyber-warriors, and cyber-hactivists.[103] Because the purported motivation of a cyber-hactivist is <em>principle<\/em>, retaliation by the corporate victim may be received as an invitation to return fire and escalate. Similarly, \u201c[e]ncouraging corporations to compete with the Russian mafia or Chinese military hackers to see who can go further in violating the law . . . is not a contest American companies can win.\u201d[104] Conversely, the motivation of a cyber-thief is <em>principal and interest,<\/em> so retaliation by the target might be taken as a suggestion to move on to an easier target. Because the perpetrators are usually anonymous, the corporate victim has no way to make a risk-based and proportional response premised upon the classification of the attacker as nation-state, thief, or hactivist.<\/p>\n<p style=\"padding-left: 30px\">[I]n cyberspace attribution is a little harder. On the playground you can see the person who hit you . . . well, almost always[,] . . . in cyberspace we can track IP addresses and TTPs from specific threat actors, which smart analysts and researchers tell us is a viable way to perform attribution. I agree with them, largely, but there\u2019s a fault there. An IP address belonging to China SQL injecting your enterprise applications is hardly a smoking gun that Chinese APTs are after you. Attackers have been using others\u2019 modus operandi to mask their identities for as long as spy games have been played. Attackers have been known to use compromised machines and proxies in hostile countries for as long as I can remember caring\u2014to \u201cbounce through\u201d to attack you. Heck, many of the attacks that appear to be originating from nation-states that we suspect are hacking us may very well be coming from a hacker at the coffee house next door to your office, using multiple proxies to mask their true origin. This is just good OpSec, and attackers use this method all the time, let\u2019s not kid ourselves.[105]<\/p>\n<p>If, without conclusive attribution and intelligence, the corporate victim is unable to make a risk-based and proportional response, it may be reasonable to question whether retaliatory hacking is abandoning the risk-based approach to business problems exhorted by FFIEC,[106]PCI,[107]and the NIST Cybersecurity Framework?[108] \u201cIf we start using those sort of [cyber weapons], it doesn&#8217;t take much to turn them against us, and we are tremendously vulnerable,\u201d said Howard Schmidt, a former White House cyber security coordinator.[109]<\/p>\n<p>[22]\u00a0\u00a0\u00a0\u00a0\u00a0 Then there is the often overlooked issue of professional ethics\u2014not for the attorney<em>\u2014<\/em>but for the information security professional.\u201cEthics,\u201d a term derived from the ancient Greek <em>ethikos <\/em>(\u1f20\u03b8\u03b9\u03ba\u03cc\u03c2), has been defined as \u201ca custom or usage.\u201d[110] Modernly, ethics is understood to be \u201c[professional] norms shared by a group on a basis of mutual and usually reciprocal recognition.\u201d[111] The codes of ethics provide articulable principles against which one\u2019s decision-making is objectively measured, and serve other important interests, including presenting an image of prestige and credibility for the organization and the profession,[112] eliminating unfair competition,[113] and fostering cooperation among professionals.[114]<\/p>\n<p>[23]\u00a0\u00a0\u00a0\u00a0\u00a0 Many information security professionals are certified by the International Information Systems Security Certification Consortium ((ISC)<sup>2\u00ae<\/sup>). The (ISC)<sup>2\u00ae <\/sup> Committee has recognized its responsibility to provide guidance for \u201cresolving good versus good, and bad versus bad, dilemmas,\u201d and \u201cto encourage right behavior.\u201d[115] The Committee also has the responsibility to discourage certain behaviors, such as raising unnecessary alarm, fear, uncertainty, or doubt; giving unwarranted comfort or reassurance; consenting to bad practice; attaching weak systems to the public network; professional association with non-professionals; professional recognition of, or association with, amateurs; or associating or appearing to associate with criminals or criminal behavior.[116] Therefore, an information security professional bound by this code who undertakes active defense activities that he or she knows or should know are unlawful, or proceeds where the legality of such behavior not clear, may be in violation the Code.<\/p>\n<p>[24]\u00a0\u00a0\u00a0\u00a0\u00a0 It would stand to reason that, an organization that empowers, directs, or acquiesces to conduct by its employees that violates the (ISC)Code of Ethics may violate its own corporate ethics or otherwise compromise its ethical standing in the corporate community\u2014or not: when Google launched a \u201csecret counter-offensive\u201d and \u201cmanaged to gain access to a computer in Taiwan that it suspected of being the source of the attacks,\u201d[117] tech sources praised Google\u2019s bold action.[118]<\/p>\n<p>[25]\u00a0\u00a0\u00a0\u00a0\u00a0 Nevertheless, corporate ethics is an indispensable consideration in the hack back debate. The code of ethics and business conduct for financial institutions should reflect and reinforce corporate values, including uncompromising integrity, respect, responsibility and good citizenship. As noted above, retaliatory hacking is deceptive and has been characterized as reckless, and even Web bugs are commonly associated with spammers. Corporate management must consider whether resorting to techniques pioneered by and associated with criminals or spammers has the potential to compromise brand image in the eyes of existing and prospective customers. Similarly, to the extent that financial corporations are engaging in active defense covertly,[119] corporate management must consider whether customers\u2019 confidence in the security of their data and investments could be shaken when such activities are uncovered. Will customers wonder whether their data has been placed at risk because of escalation? Will shareholders question whether such practices are within the scope of good corporate stewardship?<\/p>\n<h2><\/h2>\n<h2 style=\"text-align: center\"><strong>III. Alternatives to Retaliatory Hacking<\/strong><\/h2>\n<p>[26]\u00a0\u00a0\u00a0\u00a0\u00a0 The obvious argument in support of active defense is that the law and governments are doing little to protect private corporations and persons from cybercrime, which has inexorably resulted in resort to self-help,[120] and those who vociferously counsel to refrain from active defense often have little advice on alternatives. At the risk of pointing out the obvious, one counsels, \u201c\u2018when you look at active defense, we need to focus on reducing our vulnerabilities.\u2019\u201d[121]<\/p>\n<p>[27]\u00a0\u00a0\u00a0\u00a0\u00a0 Alternatives to hacking back are evolving, and one of the more promising is the pioneering threat intelligence gathering and sharing from the Financial Services Information Sharing and Analysis Center (\u201cFS-ISAC\u201d), which collects information about threats and vulnerabilities from its 4,400 FI members, government partners, and special relationships with Microsoft<sup>\u00ae<\/sup>, iSIGHT Partners<sup>SM<\/sup>, Secunia, <em>et al.<\/em>, anonymizes the data, and distributes it back to members.[122] In addition to e-mail alerts and a Web portal, FS-ISAC holds regular tele-conferences during which vulnerability and threat information is discussed, and during which presentations on current topics are given.[123] The FS-ISAC recently launched a security automation project to eliminate manual processes to collect and distribute cyber threat information, according to Bill Nelson, the Center\u2019s director.[124] The objective of the project is to significantly reduce operating costs and lower fraud losses for financial institutions, by consuming threat information on a real-time basis.[125]<\/p>\n<p>[28]\u00a0\u00a0\u00a0\u00a0\u00a0 Although, as <em>American Banker <\/em>wryly observes, \u201c[b]ankers have never been too keen on sharing secrets with one another,\u201d[126] dire circumstances have catalyzed a new era of cooperation, paving the way for the success of the cooperative model developed by the FS-ISAC\u2014even before its current ambitious automation project, which has resulted in successful botnet takedown operations.[127] An illustrative example is the Citadel malware botnet takedown, where Microsoft\u2019s Digital Crimes Unit, in collaboration with the FS-ISAC, the Federal Bureau of Investigation, the American Bankers Association, NACHA\u2014The Electronic Payments Association, and others, executed a simultaneous operation to disrupt more than 1,400 Citadel botnets reportedly responsible for over half a billion dollars in losses worldwide.[128] With the assistance of U.S. Marshals, data and evidence, including servers, were seized from data hosting facilities in New Jersey and Pennsylvania, and was made possible by a court ordered civil seizure warrant from a U.S. federal court.[129] Microsoft also reported that it shared information about the botnets\u2019 operations with international Computer Emergency Response Teams, which can deal with elements of the botnets outside U.S. jurisdiction, and the FBI informed enforcement agencies in those countries.[130] Similar, more recent, operations include one characterized as \u201cmajor takedown of the Shylock Trojan botnet,\u201d which botnet is described as \u201can advanced cybercriminal infrastructure attacking online banking systems around the world,\u201d that reportedly was coordinated by the UK National Crime Agency (NCA), and included Europol, the FBI, BAE Systems Applied Intelligence, Dell SecureWorks, Kaspersky Lab and the UK&#8217;s GCHQ,[131] and another takedown operation that targeted the much-feared Cryptolocker.[132]\u00a0\u00a0 Following the FS-ISAC model, the retail sector has taken the \u201chistoric decision\u201d to share data on cyber-threats for the first time through a newly-formed Retail Cyber Intelligence Sharing Center (R-CISC),[133] and the financial services and retail sectors formed a cross-partnership.[134]<\/p>\n<p>[29]\u00a0\u00a0\u00a0\u00a0\u00a0 Finally, at the time of this publication, a draft Cybersecurity Information-Sharing Act of 2014, advanced by Chairman Dianne Feinstein (D-CA) and ranking member Saxby Chambliss (R-GA), was passed out of the Senate Intelligence on a 12-3 vote, and is expected to be put to a vote in the full Senate.[135] The bill is designed to enhance and provide liability protections for information sharing between private corporate entities, between private corporate entities and the Government, and between Government agencies.<\/p>\n<p>[30]\u00a0\u00a0\u00a0\u00a0\u00a0 Yet another promising option is the partnership that critical infrastructure institutions have formed, or should investigate forming, with ISPs. For example, ISPs currently provide DDoS mitigation services that, although not particularly effective in application vulnerability (OSI model layer 7) attacks, are very capable in responding to volume-based attacks.[136] One senior ISP executive proposed to this author, under the Chatham House Rule,[137] the possibility that ISPs may be able to provide aggregated threat intelligence information, including attribution, based upon monitoring of the entirety of its networks (not merely the network traffic to and from an individual corporate client).<\/p>\n<p>[31]\u00a0\u00a0\u00a0\u00a0\u00a0 ISPs\u2019 capabilities are, however, subject both to statutory and regulatory limitations, including, for example, the Cable Act,[138] and proposed rules that would restrict the blocking of \u201clawful content, applications, services, or non-harmful devices,\u201d that may appear to implicate liability-incurring discretion.[139]<\/p>\n<p>[32]\u00a0\u00a0\u00a0\u00a0\u00a0 Nevertheless, several researchers urge that ISPs should assume a \u201clarger security role,\u201d and are in a good position \u201cto cost-effectively prevent certain types of malicious cyber behavior, such as the operation of botnets on home users\u2019 and small businesses\u2019 computers.\u201d[140] Likewise, the Federal Communications Commission has defined \u201clegitimate network management\u201d as including \u201censuring network security and integrity\u201d and managing traffic unwanted by end users:<\/p>\n<p style=\"padding-left: 30px\">In the context of broadband Internet access services, techniques to ensure network security and integrity are designed to protect the access network and the Internet against actions by malicious or compromised end systems. Examples include spam, botnets, and distributed denial of service attacks. Unwanted traffic includes worms, malware, and virus that exploit end-user system vulnerabilities; denial of service attacks; and spam.[141]<\/p>\n<p><em>N.B.,<\/em> a 2010 study found that just ten ISPs accounted for 30 percent of IP addresses sending out spam worldwide.[142] And, in 2011, it was reported that over 80% of infected machines were located within networks of ISPs, and that fifty ISPs control about 50% of all botnet infected machines worldwide.[143]<\/p>\n<p>[33]\u00a0\u00a0\u00a0\u00a0\u00a0 Other options that some companies have pursued as alternatives to the pitfalls of inherently risky threat counter-intelligence gathering discussed above include risk transfer or automated monitoring, both of which rely on outside vendors or subscription services.<\/p>\n<p>[34]\u00a0\u00a0\u00a0\u00a0\u00a0 Under the risk transfer approach, a corporate entity may choose to rely on the findings of a private contractor or company without undue concern for how the contractor or firm acquired the information. U.S. companies already outsource threat intelligence gathering to firms who employ operatives in Israel, such as IBM-Trusteer and RSA,[144] ostensibly because these operatives are able to effectively obtain information without running afoul of U.S. law. For legal scholars, perhaps a case to help justify this approach might be that of the famous Pentagon Papers (<em>New York Times v. United States<\/em>), in which the Supreme Court held that the public\u2019s right to know was superior to the Government\u2019s need to maintain secrecy of the information, notwithstanding that the leaked documents were obtained unlawfully (<em>i.e.<\/em>,in alleged violation of \u00a7 793 of the Espionage Act).[145] Yet, a corporate entity that knowingly\u2014or with blissful ignorance\u2014retains the services resulting from unethical conduct or conduct that would be criminal if undertaken in the U.S. may nevertheless suffer injury to the brand resulting from revelations of the vendor\u2019s actions.<\/p>\n<p>[35]\u00a0\u00a0\u00a0\u00a0\u00a0 Under the automated monitoring approach, corporate entities rely on vendor subscription services, such as Internet Identity (IID&#x2122;), that use automated software to monitor various fora or social media sites for the occurrence of keywords, concepts, or sentiment, and then alert the customer. Variations of these technologies are in use for high frequency stock trading and e-Discovery. An example might be detecting the offering for sale on a site of primary account numbers and related information by a cyberthief, and providing real-time notification to the merchant so that the accounts can be disabled.<\/p>\n<p>[36]\u00a0\u00a0\u00a0\u00a0\u00a0 Other promising options include \u201cbig data\u201d approach, which is to employ data scientists and software and hardware automation in-house to draw more meaningful inferences from the data and evidence already legally within the company\u2019s custody and control. For example, David Bianco, a \u201cnetwork hunter\u201d for security firm FireEye, suggests allocating resources for detecting, evaluating, and treating threat indicators according to their value <em>to the attacker<\/em>, which he represents in his so-called \u201cPyramid of Pain.\u201d[146] Under this model, remediation efforts are directed toward those indicators that are costly (in time or resources) to the attacker, requiring the attacker to change strategy or incur more costs.[147] Bianco proposed this model after concluding that organizations seem to blindly collect and aggregate indicators, without making the best use of them.[148] Vendors, such as Guardian Analytics,[149] FireEye\u2019s Threat Analytics Program,[150] CrowdStrike\u2019s Falcon platform,[151] and HP\u2019s Autonomy IDOL[152] (intelligent data operating layer) are endeavoring to bring real-time threat intelligence parsing or information sharing tools and services to the marketplace<\/p>\n<p>&nbsp;<\/p>\n<h2 style=\"text-align: center\"><strong>III. Conclusion<\/strong><\/h2>\n<p>[37]\u00a0\u00a0\u00a0\u00a0\u00a0 Hack back or active defense, depending on how one defines each\u2014and everything in between\u2014consists of activities that are both lawful and unlawful, and which carry all the business and professional risks associated with deceptive practices, misattribution, and escalation. To urge a risk-based approach to using even lawful active defense tactics would be to state the obvious, and the use of certain types of active defense where misattribution is possible, may be to entirely abandon the risk-based approach to problem solving. Moreover, at the time of this writing, a qualified privilege to hack back through legislative reform seems unlikely, and would be difficult because the holder of such a privilege would not only have to establish proper intent, but also attribution. However, the tools, technologies, partnerships, and information sharing between corporations, governments, vendors, and trade associations are promising; they have already proven effective, and are steadily improving.<\/p>\n<p>&nbsp;<\/p>\n<hr \/>\n<p>&nbsp;<\/p>\n<p>* The author is a cyber-security policy analyst in the banking industry and a digital forensics examiner in private practice. Mr. Harrington is a graduate with honors from Taft Law School, and holds the CCFP, MCSE, CISSP, CHFI, and CSOXP certifications. He has served on the board of the Minnesota Chapter of the High Technology Crime Investigation Association, is a current member of Infragard, the Financial Services Roundtable\u2019s legislative and regulatory working groups, FS-ISAC, the U.S. Chamber of Commerce \u201cCyber Working Group,\u201d the Fourth District Ethics Committee in Minnesota, and is a council member of the Minnesota State Bar Association\u2019s Computer &amp; Technology Law Section. Mr. Harrington teaches computer forensics for Century College in Minnesota, and recently contributed a chapter on the Code of Ethics for the forthcoming Official (ISC)\u00b2\u00ae Guide to the Cyber Forensics Certified Professional CBK\u00ae. He is also an instructor for the CCFP certification.<\/p>\n<p>&nbsp;<\/p>\n<div>\n<div>\n<p>[1] Rush, <em>The Body Electric<\/em>,<em> on <\/em>Grace under Pressure (Mercury Records 1984).<\/p>\n<p>[2] Sean Sposito,<em> Banks Remain the Top Target for Hackers, Report Says<\/em>, Am. Banker (April 23, 2013, 10:04 AM), http:\/\/www.americanbanker.com\/issues\/178_78\/banks-remain-the-top-target-for-hackers-report-says-1058543-1.html.<\/p>\n<p>[3] Eric A. Fisher, Cong. Research Serv., R 42114, Federal Laws Relating to Cybersecurity: Overview and Discussion of Proposed Revisions 3 (2013), <em>available at<\/em> http:\/\/fas.org\/sgp\/crs\/natsec\/R42114.pdf (discussing, for example, the Federal Information Security Management Act).<\/p>\n<p>[4] <em>See <\/em>Yonatan Lupu, <em>The Wiretap Act and Web Monitoring: A Breakthrough for Privacy Rights?<\/em>, 9 Va. J.L. &amp; Tech. 3, \u00b6\u00b6 7, 9 (2004) (discussing the use of the ECPA and the lack of words such as \u201cInternet,\u201d \u201cWorld Wide Web,\u201d and \u201ce-commerce\u201d in the text or legislative history); <em>see also <\/em>Eric C. Bosset et al., <em>Private Actions Challenging Online Data Collection Practices Are Increasing: Assessing the Legal Landscape<\/em>, Intell. Prop. &amp; Tech. L.J., Feb. 2011, at 3 (\u201c[F]ederal statutes such as the Electronic Communications Privacy Act (ECPA) and the Computer Fraud and Abuse Act (CFAA) . . . were drafted long before today\u2019s online environment could be envisioned . . . .\u201d); Miguel Helft &amp; Claire Cain Miller, <em>1986 Privacy Law Is Outrun by the Web<\/em>,N.Y. TIMES (Jan. 9, 2011), http:\/\/www.nytimes.com\/2011\/01\/10\/technology\/10privacy.html?pagewanted=all&amp;_r=1&amp; (noting that Congress enacted the ECPA before the World Wide Web or widespread use of e-mail); Orin S. Kerr, <em>The Future of Internet Surveillance Law: A User&#8217;s Guide to the Stored Communications Act, and a Legislator&#8217;s Guide to Amending It<\/em>, 72 Geo. Wash. L. Rev. 1208, 1208, 1213-14, 1229-30 (2004); <em>see generally The Electronic Communications Privacy Act: Government Perspectives on Privacy in the Digital Age: Hearing Before the S. Comm. on the Judiciary<\/em>, 112th Cong. 1-2(2011) (statement of Sen. Patrick Leahy, Chairman, S. Comm. on the Judiciary), <em>available at<\/em> http:\/\/fas.org\/irp\/congress\/2011_hr\/ecpa.pdf (\u201c[D]etermining how best to bring this privacy law into the Digital Age will be one of Congress&#8217;s greatest challenges. . . . [The] ECPA is a law that is hampered by conflicting standards that cause confusion for law enforcement, the business community, and American consumers alike.\u201d).<\/p>\n<p>[5] <em>See<\/em> <em>generally <\/em>Nat\u2019l Inst. of Standards &amp; Tech., Framework for Improving Critical Infrastructure Cybersecurity 4 (Version 1.0, 2014) <em>available at <\/em>http:\/\/www.nist.gov\/cyberframework\/upload\/cybersecurity-framework-021214-final.pdf (describing The Framework as \u201ca risk-based approach to managing cybersecurity risk\u201d).<\/p>\n<p>[6] <em>See,<\/em> Eric Griffith, <em>What is Cloud Computing?<\/em>, PC Magazine (May 13, 2013) http:\/\/www.pcmag.com\/article2\/0,2817,2372163,00.asp.<\/p>\n<p>[7] <em>See, e.g.<\/em>, Ken Dilanian, <em>A New Brand of Cyber Security: Hacking the Hackers<\/em>, L.A. Times (Dec. 4, 2012), http:\/\/articles.latimes.com\/2012\/dec\/04\/business\/la-fi-cyber-defense-20121204\/2 (proposing that \u201ccompanies should be able to \u2018hack back\u2019 by, for example, disabling servers that host cyber attacks\u201d).<\/p>\n<p>[8] <em>See, e.g.<\/em>, Scott Carle, <em>Crossing the Line: Ethics for the Security Professional<\/em>,SANS Inst. (2003), http:\/\/www.sans.org\/reading-room\/whitepapers\/hackers\/crossing-line-ethics-security-professional-890. Readers, doubtless, will know of earlier references.<\/p>\n<p>[9] Techopedia, http:\/\/www.techopedia.com\/definition\/23172\/back-hack (last visited June 28, 2014); <em>see also<\/em> NetLingo, http:\/\/www.netlingo.com\/word\/back-hack.php (last visited June 28, 2014)(\u201c[Back-hack is t]he reverse process of finding out who is hacking into a system. Attacks can usually be traced back to a computer or pieced together from \u2018electronic bread crumbs\u2019 unknowingly left behind by a cracker.\u201d).<\/p>\n<p>[10] Melissa Riofrio, <em>Hacking Back: Digital Revenge Is Sweet but Risky<\/em>, PCWorld (May 9, 2013, 3:00 AM), http:\/\/www.pcworld.com\/article\/2038226\/hacking-back-digital-revenge-is-sweet-but-risky.html.<\/p>\n<p>[11] Dmitri Alperovitch, <em>Active Defense: Time for a New Security Strategy<\/em>, Crowdstrike (Feb. 25, 2013),http:\/\/www.crowdstrike.com\/blog\/active-defense-time-new-security-strategy\/.<\/p>\n<p>[12] Comm\u2019n on the Theft of Am. Intellectual Prop., The IP Commission Report 81 (2013) [hereinafter The IP Commission Report], <em>available at <\/em>http:\/\/ipcommission.org\/report\/IP_Commission_Report_052213.pdf; s<em>ee also <\/em>Sam Cook, <em>Georgia<\/em><em> Outs Russian Hacker, Takes Photo with His Own Webcam<\/em>, Geek (Oct. 31, 2012, 4:28 PM), http:\/\/www.geek.com\/news\/georgia-outs-russian-hacker-takes-photo-with-his-own-webcam-1525485\/. <em>See <\/em>Jay P. Kesan &amp; Carol M. Hayes, <em>Thinking Through Active Defense in Cyberspace,<\/em> in Proceedings of a Workshop on Deterring Cyberattacks: Informing Strategies and Developing Options for U.S. Policy<\/p>\n<p>327, 328 (The National Academies Press ed., 2010) (\u201cCounterstrikes of this nature have already been occurring on the Internet over the last decade, by both government and private actors, and full software packages designed to enable counterstriking have also been made commercially available, even though such counterstrikes are of questionable legality\u201d).<\/p>\n<p>[13] <em>See <\/em>The IP Commission Report, <em>supra <\/em>note 12.<\/p>\n<p>[14] Tom Fields, <em>To \u2018Hack Back\u2019 or Not?<\/em>, BankInfoSecurity(Feb. 27, 2013), http:\/\/www.bankinfosecurity.com\/to-hack-back-or-not-a-5545.<\/p>\n<p>[15] <em>Id.<\/em><\/p>\n<p>[16] <em>Id.<\/em><\/p>\n<p>[17] <em>Hackback? Claptrap!\u2014An Active Defense Continuum for the Private Sector<\/em>, RSA Conf. (Feb. 27, 2014, 9:20 AM), http:\/\/www.rsaconference.com\/events\/us14\/agenda\/sessions\/1146\/hackback-claptrap-an-active-defense-continuum-for.<\/p>\n<p>[18] Shane McGee, Randy V. Sabett, &amp; Anand Shah, <em>Adequate Attribution: A Framework for Developing a National Policy for Private Sector Use of Active Defense,<\/em> 8 J. Bus. &amp; Tech. L. 1 (2013) Available at: http:\/\/digitalcommons.law.umaryland.edu\/jbtl\/vol8\/iss1\/3<\/p>\n<p>[19] <em>See, e.g.<\/em>, Rafal Los, <em>Another Reason Hacking Back Is Probably a Bad Idea<\/em>, InfosecIsland (June 20, 2013), http:\/\/www.infosecisland.com\/blogview\/23228-Another-Reason-Hacking-Back-is-Probably-a-Bad-Idea.html; Riofrio, <em>supra<\/em> note 10.<\/p>\n<p>[20] Dilanian, <em>supra <\/em>note 7;<em>see also <\/em>William Jackson, <em>The Hack-Back vs. The Rule of Law: Who Wins?<\/em>, Cybereye, (May 31, 2013, 9:39 AM) http:\/\/gcn.com\/blogs\/cybereye\/2013\/00\/hacking-back-vs-the-rule-of-law.aspx (stating \u201c[i]n the face of increasing cyber threats there is an understandable pent-up desire for an active response, but this response should not cross legal thresholds. In the end, we either have the rule of law or we don\u2019t. That others do not respect this rule does not excuse us from observing it. Admittedly this puts public- and private-sector organizations and individuals at a short-term disadvantage while correcting the situation, but it\u2019s a pill we will have to swallow.\u201d).<\/p>\n<p>[21] James Andrew Lewis, <em>Private Retaliation in Cyberspace<\/em>,Center for Strategic &amp; Int\u2019l Studies (May 22, 2013), http:\/\/csis.org\/publication\/private-retaliation-cyberspace.<\/p>\n<p>[22] <em>See <\/em>Cyber Intelligence Sharing and Protection Act, H.R. 624, 113th Cong. (2013).<\/p>\n<p>[23] Christopher M. Matthews, <em>Support Grows to Let Cybertheft Victims &#8216;Hack Back&#8217;<\/em>, Wall St. J. (June 2, 2013, 9:33 PM), http:\/\/online.wsj.com\/news\/articles\/SB10001424127887324682204578517374103394466.<\/p>\n<p>[24] <em>See <\/em>Alperovitch, <em>supra <\/em>note 11. The firm\u2019s online marketing literature includes the following: \u201cActive Defense is NOT about \u2018hack-back,\u2019 retaliation, or vigilantism . . . we are fundamentally against these tactics and believe they can be counterproductive, as well as potentially illegal.\u201d <em>Id.<\/em>; <em>see also <\/em>Paul Roberts,<em> Don\u2019t Call It a Hack Back: Crowdstrike Unveils Falcon Platform<\/em>, Security Ledger (June 19, 2013, 11:47 AM), https:\/\/securityledger.com\/2013\/06\/dont-call-it-a-hack-back-crowdstrike-unveils-falcon-platform\/.<\/p>\n<p>[25] Charlie Mitchell, <em>Senate Judiciary Panel Will Examine Stronger Penalties for Cyber Crimes and Espionage, <\/em>Inside Cybersecurity (May 9, 2014) http:\/\/insidecybersecurity.com\/Cyber-Daily-News\/Daily-News\/senate-judiciary-panel-will-examine-stronger-penalties-for-cyber-crimes-and-espionage\/menu-id-1075.html (stating \u201c[a]uthorization for so-called countermeasures is included in the draft cyber information-sharing and liability protection bill . . . White House and Department of Homeland Security officials . . . declined to discuss the administration&#8217;s view of deterrence issues such as active defense.\u201d). To be distinguished from OCM, \u201ccountermeasure\u201d is defined in the draft Cybersecurity Information-Sharing Act of 2014 as \u201can action, device, procedure, technique, or other measure applied to an information system or information that is stored on, processed by, or transiting an information system that prevents or mitigates a known or suspected cybersecurity threat or security vulnerability.\u201d <em>See <\/em>H.R. 624.<\/p>\n<p>[26] <em>See, e.g.<\/em>,Marcus Tullius Cicero, The Speech of M.T. Cicero in Defence of Titus Annius Milo, <em>in <\/em>The Orations of Marcus Tullius Cicero 390, 392-393 (C.D. Yonge trans., 1913).<\/p>\n<p>[27] Sheng Li, Note, <em>When Does Internet Denial Trigger the Right of Armed Self-Defense?<\/em>, 38 Yale J. Int&#8217;l L. 179, 182 (2013).<\/p>\n<p>[28] <em>See, e.g.<\/em>, Walter Gary Sharp Sr., Cyberspace and the Use of Force 129-31 (1999).<\/p>\n<p>[29] <em>See <\/em>U.S. Dep\u2019t. of Def., Conduct of the Persian Gulf War: Final Report to Congress Pursuant to Title V of the Persian Gulf Conflict Supplemental Authorization and Personnel Benefits Act of 1991 (Public Law 102-25) N-1 (1992) (\u201cCivilian employees, despite seemingly insurmountable logistical problems, unrelenting pressure, and severe time constraints, successfully accomplished what this nation asked of them in a manner consistent with the highest standards of excellence and professionalism.\u201d).<\/p>\n<p>[30] <em>See <\/em>CyCon, http:\/\/ccdcoe.org\/cycon\/index.html (last visited July 16, 2014).<\/p>\n<p>[31] <em>See<\/em> NATO Coop. Cyber Defence Ctr. of Excellence, Tallinn Manual on the International Law Applicable to Cyber Warfare 4 (Michael N. Schmitt ed., 2013); <em>see also <\/em>U.N. Charter art. 2, para. 4 &amp; art. 51 (governing the modern law of self-defense)<em>.<\/em><\/p>\n<p>[32] <em>See, e.g.<\/em>, Keiko Kono, <em>Briefing Memo: Cyber Security and the Tallinn Manual<\/em>, Nat\u2019l Inst. For Def. Studies News, Oct. 2013, at 2, <em>available at <\/em>www.nids.go.jp\/english\/publication\/briefing\/pdf\/2013\/briefing_e180.pdf.<\/p>\n<p>[33] <em>See, e.g.<\/em>,Siobhan Gorman &amp; Danny Yadron, <em>Banks Seek U.S. Help on Iran Cyberattacks, <\/em>Wall St. J. (June 16, 2013, 12:01 AM), http:\/\/online.wsj.com\/news\/articles\/SB10001424127887324734904578244302923178548; Christopher J. Castelli, <em>DOJ Official Urges Public-Private Cybersecurity Partnership Amid Legal Questions<\/em>,Inside Cybersecurity (April 1, 2014), http:\/\/insidecybersecurity.com\/Cyber-Daily-News\/Daily-News\/doj-official-urges-public-private-cybersecurity-partnership-amid-legal-questions\/menu-id-1075.html.<\/p>\n<p>[34] One such example is the \u201cComputer Trespasser\u201d exception added by Congress to the Wiretap Act, which allows law enforcement officials to monitor the activities of hackers when (1) the owner or operator of the network authorizes the interception; (2) law enforcement is engaged in a lawful investigation; (3) law enforcement has reasonable grounds to believe the contents of the communications will be relevant to that investigation; and (4) such interception does not acquire communications other than those transmitted to or from the hacker. <em>See <\/em>18 U.S.C. \u00a7 2511(2)(i)(I)-(IV) (2012);<em> see also<\/em> Bradley J. Schaufenbuel, <em>The Legality of Honeypots<\/em>, ISSA J., April 2008, at 16, 19, <em>available at <\/em>http:\/\/www.jdsupra.com\/legalnews\/the-legality-of-honeypots-50070\/.<\/p>\n<p>[35] <em>See, e.g., <\/em>David E. Sanger, <em>White House Details Thinking on Cybersecurity Flaws,<\/em> New York Times, (April 28, 2014) (discussing the Government\u2019s admission that it refrains from disclosing major computer sercurity vulnerabilities that could be useful to \u201cthwart a terrorist attack, stop the theft of our nation\u2019s intellectual property, or even discover more dangerous vulnerabilities that are being used by hackers or other adversaries to exploit our networks.\u201d)<\/p>\n<p>[36] <em>See <\/em>Sameer Hinduja, <em>Computer Crime Investigations in the United States: Leveraging Knowledge from the Past to Address the Future<\/em>, 1 Int\u2019l J. Cyber Criminology 1, 16 (2007) (citation omitted).<\/p>\n<p>[37] <em>Id.<\/em> at 19. <em>But see <\/em>Kesan &amp; Hayes, <em>supra, <\/em>note 12 at 33 (\u201cthere is a more significant downside of entrusting active defense to private firms. Our model addressing the optimal use of active defense emphasizes that there are threshold points where permitting counterstrikes would be the socially optimal solution. However, it does not define these thresholds, and determining these thresholds requires some sort of standardization. It would be unwise to allow individual companies to make these decisions on a case by case basis.\u201d)<\/p>\n<p>&nbsp;<\/p>\n<p>[38] The IP Commission Report, <em>supra <\/em>note 12, at 81. <em>See also<\/em> Joseph Menn, <em>Hacked Companies Fight Back With Controversial Steps, <\/em>Reuters, June 18, 2012, available at http:\/\/www.reuters.com\/article\/2012\/06\/18\/us-media-tech-summit-cyber-strikeback-idUSBRE85G07S20120618<\/p>\n<p>[39] <em>See <\/em>Stephanie Olsen, <em>Nearly Undetectable Tracking Device Raises Concerns<\/em>, CNET(July 12, 2000), http:\/\/news.cnet.com\/2100-1017-243077.html.<\/p>\n<p>[40] <em>See id. See also<\/em> John Gilroy, <em>Ask The Computer Guy,<\/em> Wash. Post, Jan. 27, 2002, at H07 (describing web bugs in lay parlance).<\/p>\n<p>[41] Sean L. Harrington, <em>Collaborating with a Digital Forensics Expert: Ultimate Tag Team or Disastrous Duo?<\/em>, 38 Wm. Mitchell L. Rev. 353, 363 (2011), <em>available at <\/em>http:\/\/www.wmitchell.edu\/lawreview\/Volume38\/documents\/7.Harrington.pdf.<\/p>\n<p>[42] <em>Id.<\/em><\/p>\n<p>[43] <em>S<\/em><em>ee generally<\/em>Brian M. Bowen et al., <em>Baiting Inside Attackers Using Decoy Documents<\/em>, Colum. Univ. Dep\u2019t of Computer Sci. (2009), <em>available at <\/em>http:\/\/www.cs.columbia.edu\/~angelos\/Papers\/2009\/DecoyDocumentsSECCOM09.pdf (last visited May 13, 2014) (introducing and discussing properties of decoys as a guide to design \u201ctrap-based defenses\u201d to better detect the likelihood of insider attacks).<\/p>\n<p>[44] <em>See <\/em>Matthews, <em>supra <\/em>note 23.<\/p>\n<p>[45] <em>Id. <\/em><\/p>\n<p>[46] <em>Id.<\/em><\/p>\n<p>[47] <em>Id.<\/em><\/p>\n<p>[48] <em>See <\/em>Harrington, <em>supra <\/em>note 41, at 362-64.<\/p>\n<p>[49]The Supreme Court has tacitly approved deception as a valid law enforcement technique in investigations and interrogations. <em>See <\/em>Illinois v. Perkins,496 U.S. 292, 297 (1990) (\u201c<em>Miranda<\/em> forbids coercion, not mere strategic deception . . .\u201d); United States v. Russell, 411 U.S. 423, 434 (1973) (\u201cCriminal activity is such that stealth and strategy are necessary weapons in the arsenal of the police officer.\u201d); Allan Lengel, <em>Fed Agents Going Undercover on Social Networks Like Facebook<\/em>, AOLNews (Mar. 28, 2010, 5:55 PM), http:\/\/www.ticklethewire.com\/2010\/03\/28\/fed-agents-going-undercover-on-social-networks-like-facebook\/.<\/p>\n<p>[50] <em>See <\/em>Model Rules of Prof\u2019l Conduct R. 5.3 (2013).<\/p>\n<p>[51] Model Rules of Prof\u2019l Conduct r. 8.4(c);<em> see, e.g.<\/em>,<em> In re <\/em>Disciplinary Action Against Carlson<em>, <\/em>No. A13-1091 (Minn. July 11, 2013)(public reprimand for \u201cfalsely posing as a former client of opposing counsel and posting a negative review about opposing counsel on a website, in violation of Minn. R. Prof. Conduct 4.4(a) and 8.4(c)\u201d); <em>In re <\/em>Pautler<em>,<\/em> 47 P.3d 1175, 1176 (Colo. 2002) (disciplining a prosecutor, who impersonated a public defender in an attempt to induce the surrender of a murder suspect, for an act of deception that violated the Rules of Professional Conduct).<\/p>\n<p>[52] <em>See <\/em>Sharon D. Nelson &amp; John W. Simek, <em>Muddy Waters: Spyware\u2019s Legal and Ethical Implications<\/em>, GPSolo Mag., Jan.-Feb. 2006, http:\/\/www.americanbar.org\/newsletter\/publications\/gp_solo_magazine_home\/gp_solo_magazine_index\/spywarelegalethicalimplications.html (\u201cThe legality of spyware is murky, at best. The courts have spoken of it only infrequently, so there is precious little guidance.\u201d).<\/p>\n<p>[53]<em> In re <\/em>Disciplinary Action Against Zotaley, 546 N.W.2d 16, 19 (Minn. 1996) (quoting Minn. R. Prof\u2019l Conduct 3.3 cmt. 3 (2005)).<\/p>\n<p>[54]<em>See<\/em> Phila. Bar Ass\u2019n Prof\u2019l Guidance Comm., Op. 2009-02, at 1-2<em>\u00a0<\/em>(2009), <em>available at<\/em> http:\/\/www.philadelphiabar.org\/WebObjects\/PBAReadOnly.woa\/Contents\/WebServerResources\/CMSResources\/Opinion_2009-2.pdf.<\/p>\n<p>[55] <em>See <\/em>N.Y.C. Bar Ass\u2019n Prof\u2019l &amp; Judicial Ethics Comm., Formal Op. 2010-2 (2010), <em>available at<\/em> http:\/\/www2.nycbar.org\/Publications\/reports\/show_html.php?rid=1134; <em>cf. <\/em>Justin P. Murphy &amp; Adrian Fontecilla, <em>Social Media Evidence in Government Investigations and Criminal Proceedings: A Frontier of New Legal Issues<\/em>, 19 Rich. J.L. &amp; Tech. 11, \u00b6 21 n.76 (2013) (citing similar ethics opinions rendered by bar committees in New York State and San Diego County).<\/p>\n<p>[56] David Bianco, <em>Use of the Term \u201cIntelligence\u201d in the RSA 2014 Expo<\/em>, Enterprise Detection &amp; Response (Feb. 28, 2014) http:\/\/detect-respond.blogspot.com\/#!\/2014\/03\/use-of-term-intelligence-at-rsa.html.<\/p>\n<p>[57] <em>See <\/em>Sameer, <em>supra <\/em>note 36, at 15 (citing A. Meehan, G. Manes, L. Davis, J. Hale &amp; S. Shenoi, <em>Packet Sniffing for Automated Chat Room Monitoring and Evidence Preservation<\/em>, <em>in<\/em> Proceedings of the 2001 IEEE Workshop on Information Assurance and Security 285, 285 (2001))(\u201c[T]he monitoring of bulletin-boards and chat-rooms by investigators has led to the detection and apprehension of those who participate in sex crimes against children.\u201d), <em>available at <\/em>http:\/\/index-of.es\/Sniffers\/Sniffers_pdf\/52463601-packet-sniffing-for-automated-chat-room-74909.pdf; <em>see, e.g.<\/em>, Kimberly J. Mitchell, Janis Wolak &amp; David Finkelhor, <em>Police Posing as Juveniles Online to Catch Sex Offenders: Is It Working?<\/em>, 17 Sexual Abuse: J. Res. &amp; Treatment 241 (2005); Lyta Penna, Andrew Clark &amp; George Mohay, <em>Challenges of Automating the Detection of Paedophile Activity on the Internet,<\/em> <em>in<\/em> <em>Proceedings of the First International Workshop on Systematic Approaches to Digital Forensic Engineering<\/em> (2005), <em>available at <\/em>http:\/\/eprints.qut.edu.au\/20860\/1\/penna2005sadfe.pdf.<\/p>\n<p>[58] Martin Moylan, <em>Target\u2019s Data Breach Link to \u2018the Amazon of Stolen Credit Card Information\u2019<\/em>,MPRnews (February 3, 2014), http:\/\/www.mprnews.org\/story\/2014\/02\/02\/stolen-credit-and-debit-card-numbers-are-just-a-few-clicks-away.<\/p>\n<p>[59] <em>See <\/em>\u201cInvestigating the Dark Web \u2014 The Challenges of Online Anonymity for Digital Forensics Examiners,\u201d Forensic Focus (July 28, 2014) (\u201cIt is certainly easier to access indecent images of children and similar content on the dark net.\u201d) Available at http:\/\/articles.forensicfocus.com\/2014\/07\/28\/investigating-the-dark-web-the-challenges-of-online-anonymity-for-digital-forensics-examiners\/. <em>And see, e.g.<\/em>, Minn. Stat. \u00a7 617.247 subd. 4(a) (2013) (criminalizing possession of \u201ca pornographic work [involving minors] or a computer disk or computer or other electronic, magnetic, or optical storage system or a storage system of any other type, containing a pornographic work, knowing or with reason to know its content and character\u201d).<\/p>\n<p>[60] <em>See <\/em>Rainer Link &amp; David Sancho, <em>Lessons Learned While Sinkholing Botnets\u2014Not As Easy As It Looks!<\/em>, <em>in <\/em>Proceedings of the Virus Bulletin Conference 106, 106 (2011), <em>available at <\/em>http:\/\/www.trendmicro.com\/media\/misc\/lessons-learned-virusbulletin-conf-en.pdf.<\/p>\n<p>[61] <em>Id.<\/em><\/p>\n<p>[62] <em>Id.<\/em>at 107.<\/p>\n<p>[63] \u201c[C]onsent may be demonstrated through evidence of appropriate notice to users through service terms, privacy policies or similar disclosures that inform users of the potential for monitoring.\u201d Bosset et.al, <em>supra<\/em> note 4 (citing Mortensen v. Bresnan Commc\u2019ns, LLC<em>,<\/em> No. CV 10-13-BLG-RFC, 2010 WL 5140454, at *3-5 (D. Mont. Dec. 13, 2010)).<\/p>\n<p>[64] <em>See <\/em>Craigslist Inc. v. 3Taps Inc., 964 F. Supp. 2d 1178, 1182-83 (N.D. Cal. 2013).<\/p>\n<p>[65] <em>See <\/em>Link &amp; Sancho, <em>supra<\/em> note 60, at 107-08<em>.<\/em><\/p>\n<p>[66] <em>Honeypot<\/em>, SearchSecurity, http:\/\/searchsecurity.techtarget.com\/definition\/honey-pot (last visited June 29, 2014).<\/p>\n<p>[67] Eric Cole &amp; Stephen Northcutt, <em>Honeypots: A Security Manager&#8217;s Guide to Honeypots<\/em>, SANS Inst., http:\/\/www.sans.edu\/research\/security-laboratory\/article\/honeypots-guide (last visited May 13, 2014).<\/p>\n<p>[68] <em>See, e.g.<\/em>, Jerome Radcliffe, CyberLaw 101: A Primer on US Laws Related to Honeypot Deployments 6-9 (2007), <em>available at<\/em> http:\/\/www.sans.org\/reading-room\/whitepapers\/legal\/cyberlaw-101-primer-laws-related-honeypot-deployments-1746.<\/p>\n<p>[69] <em>See id. <\/em>at 14-17.<\/p>\n<p>[70] <em>See <\/em>Schaufenbuel, <em>supra <\/em>note 34, at 16-17 (\u201cBecause a hacker finds a honeypot by actively searching the Internet for vulnerable hosts, and then attacks it without active encouragement by law enforcement officials, the defense of entrapment is not likely to be helpful to a hacker.\u201d).<\/p>\n<p>[71] <em>See <\/em>Cole &amp; Northcutt, <em>supra<\/em> note 67<em>.<\/em><\/p>\n<p>[72] Schaufenbuel, <em>supra<\/em> note 34, at 19.<\/p>\n<p>[73] <em>See generally id.<\/em> (stating that the best way for a honeypot owner to avoid downstream liability is to configure the honeypot to prohibit or limit outbound connections to third parties).<\/p>\n<p>[74] Scott L. Vernick, <em>To Catch a Hacker, Companies Start to Think Like One<\/em>, Fox Rothschild, LLP (Feb. 15, 2013), http:\/\/www.foxrothschild.com\/print\/convertToPDF.aspx?path=\/newspubs\/newspubsprint.aspx&amp;parms=id|15032388757.<\/p>\n<p>[75] <em>See <\/em>Kevin Parrish, <em>Copyright Troll Busted for Seeding on The Pirate Bay<\/em>,tom\u2019s GUIDE (Aug. 19, 2013, 2:00 PM), http:\/\/www.tomsguide.com\/us\/torrent-pirate-bay-copyright-troll-prenda-law-honeypot,news-17391.html#torrent-pirate-bay-copyright-troll-prenda-law-honeypot%2Cnews-17391.html?&amp;_suid=1396370990577022740795081848747.<\/p>\n<p>[76] <em>Id.<\/em><\/p>\n<p>[77] <em>See id.<\/em><\/p>\n<p>[78] <em>See, e.g.<\/em>, Sean L. Harrington, <em>Rule 11, Barratry, Champerty, and \u201cInline Links<\/em>\u201d, Minn. St. Bar Ass\u2019n Computer &amp; Tech. L. Sec. (Jan. 27, 2011, 11:42 PM), http:\/\/mntech.typepad.com\/msba\/2011\/01\/rule-11-barratry-champerty-and-inline-links.html (discussing the vexatious litigation tactics of Righthaven, LLC).<\/p>\n<p>[79] <em>See <\/em>Scott Cohn, <em>Companies Battle Cyberattacks Using \u2018Hack Back\u2019<\/em>, CNBC (June 04, 2013, 1:00 PM), http:\/\/www.cnbc.com\/id\/100788881 (\u201c[L]aw enforcement is unlikely to detect or prosecute a hack back. \u2018If the only organization that gets harmed is a number of criminals\u2019 computers, I don&#8217;t think it would be of great interest to law enforcement.\u201d); Aarti Shahani, <em>Tech Debate: Can Companies Hack Back?<\/em>, Al Jazeera Am. (Sept. 18, 2013, 5:57 PM), http:\/\/america.aljazeera.com\/articles\/2013\/9\/18\/tech-debate-can-companieshackback.html (\u201cThe Justice Department has not prosecuted any firm for hacking back and, as a matter of policy, will not say if any criminal investigations are pending\u201d).<\/p>\n<p>[80] <em>See <\/em>Cohn, <em>supra <\/em>note 79 (statement of Professor Joel Reidenberg) (\u201c\u2018Reverse hacking is a felony in the United States, just as the initial hacking was. It&#8217;s sort of like, if someone steals your phone, it doesn&#8217;t mean you&#8217;re allowed to break into their house and take it back.\u2019\u201d); Shahani, <em>supra<\/em> note 79 (statement of David Wilson) (\u201c\u2018No, it\u2019s not legal, not unless the blackmailer gave permission. . . . But who\u2019s going to report it? Not the bad guy.\u2019\u201d).<\/p>\n<p>[81] <em>See, e.g.<\/em>,Nathan Thornburgh, <em>The Invasion of the Chinese Cyberspies (and the Man Who Tried to Stop Them),<\/em>TIME (Sept. 5, 2005), http:\/\/courses.cs.washington.edu\/courses\/csep590\/05au\/readings\/titan.rain.htm (discussing the \u201crogue\u201d counter-hacking activities of Shawn Carpenter, who was working with the FBI and for whose activities Carpenter claimed the FBI considered prosecuting him).<\/p>\n<p>[82] <em>See <\/em>Dilanian, <em>supra<\/em> note 7 (\u201cOthers, including Stewart Baker, former NSA general counsel, said the law does allow hacking back in self-defense. A company that saw its stolen data on a foreign server was allowed to retrieve it, Baker argued.\u201d) (In preparation for this comment, the author asked Mr. Baker about the interview, and he replied, \u201c[T]he<em> LA Times<\/em> interview didn\u2019t involve me talking about a particular case where retrieving data was legal. I was arguing that it should be legal.\u201d).<\/p>\n<p>[83] John Strand et al., Offensive Countermeasures: The Art of Active Defense 207 (2013).<\/p>\n<p>[84] David Willson, <em>Hacking Back in Self Defense: Is It Legal; Should It Be?<\/em>, Global Knowledge (Jan. 6, 2012), http:\/\/blog.globalknowledge.com\/technology\/security\/hacking-cybercrime\/hacking-back-in-self-defense-is-it-legal-should-it-be\/.<\/p>\n<p>[85]<em> See id.<\/em><\/p>\n<p>[86] Stewart Baker, <em>The Hack Back Debate <\/em>(Nov. 02, 2012) http:\/\/www.steptoecyberblog.com\/2012\/11\/02\/the-hackback-debate\/.<\/p>\n<p>[87] <em>See<\/em> W. Page Keeton et al., Prosser &amp; Keeton on the Law of Torts \u00a7 22 (5th ed. 1984).<\/p>\n<p>[88]<em> See id.<\/em><\/p>\n<p>[89]<em> See id. <\/em>at\u00a7 24.<\/p>\n<p>[90]<em> See id. <\/em>at\u00a7 21. <em>And see <\/em>McGee, Sabett, &amp; Shah, <em>supra, <\/em>note 18 (\u201cReaching consensus on applying the concepts of self-defense to the cyber domain has proven to be a difficult task, though not for the lack of trying\u201d).<\/p>\n<p>[91] <em>See <\/em>Jassandra Nanini, <em>China<\/em><em>, Google, and Private Security: Can Hack-Backs Provide the Missing Defense in Cybersecurity<\/em>, (forthcoming 2015) (manuscript at 14-15) (on file with author).<\/p>\n<p>[92] <em>See id. <\/em>(manuscript at 14).<\/p>\n<p>[93] <em>Id.<\/em> (manuscript at 15-16).<\/p>\n<p>[94] <em>See <\/em>Sean Harrington, <em>Why Divorce Lawyers Should Get Up to Speed on CyberCrime Law<\/em>, Minn. St. B. Ass\u2019n Computer &amp; Tech. L. Sec. (Mar. 24, 2010, 9:40 PM), http:\/\/mntech.typepad.com\/msba\/2010\/03\/why-divorce-lawyers-should-get-up-to-speed-on-cybercrime-law.html (collecting cases regarding unauthorized computer access).<\/p>\n<p>[95] 18 U.S.C. \u00a7 1030 (2012); <em>see <\/em>Clements-Jeffrey v. Springfield, 810 F. Supp. 2d 857, 874 (S.D. Ohio 2011) (\u201cIt is one thing to cause a stolen computer to report its IP address or its geographical location in an effort to track it down. It is something entirely different to violate federal wiretapping laws by intercepting the electronic communications of the person using the stolen laptop.\u201d).<\/p>\n<p>[96]<em> See<\/em> <em>generally<\/em> Orin S. Kerr, <em>Cybercrime\u2019s Scope: Interpreting \u201cAccess\u201d and \u201cAuthorization\u201d in Computer Misuse Statutes<\/em>, 78 N.Y.U. L. Rev. 1596, 1624\u201342 (2003) (showing how and why courts have construed unauthorized access statutes in an overly broad manner that threatens to criminalize a surprising range of innocuous conduct involving computers).<\/p>\n<p>[97] In re DoubleClick Privacy Litig., 154 F. Supp. 2d 497, 526 (S.D.N.Y. 2001) (emphasis added).<\/p>\n<p>[98] <em>See <\/em>In re Pharmatrak, Inc. Privacy Litig.<em>,<\/em> 329 F.3d 9, 13 &amp; 21-22 (1st Cir. 2003) (holding use of tracking cookies to intercept electronic communications was within the meaning of the ECPA, because the acquisition occurred simultaneously with the communication).<\/p>\n<p>[99] <em>See <\/em>Peter J. Toren, <em>Amending the Computer Fraud and Abuse Act<\/em>,BNA (Apr. 9, 2013), http:\/\/about.bloomberglaw.com\/practitioner-contributions\/amending-the-computer-fraud-and-abuse-act\/.<\/p>\n<p>[100] <em>See, e.g.<\/em>, Holly R. Rogers &amp; Katharine V. Hartman, <em>The Computer Fraud and Abuse Act: A Weapon Against Employees Who Steal Trade Secrets<\/em>,BNA (June 21, 2011) (\u201c[E]mployers are increasingly using this cause of action to go after former employees who steal trade secrets from their company-issued computers.\u201d).<\/p>\n<p>[101] <em>A Byte for a Byte<\/em>,Economist (Aug. 10, 2013), <em>available at <\/em>http:\/\/www.economist.com\/node\/21583268\/; <em>see also <\/em>Lewis<em>, supra<\/em> note 21 (\u201cThere is also considerable risk that amateur cyber warriors will lack the skills or the judgment to avoid collateral damage. A careless attack could put more than the intended target at risk. A nation has sovereign privileges in the use of force. Companies do not.\u201d); John Reed, <em>The Cyber Security Recommendations of Blair and Huntsman&#8217;s Report on Chinese IP Theft<\/em>, Complex Foreign Pol\u2019y (May 22, 2012), http:\/\/complex.foreignpolicy.com\/posts\/2013\/05\/22\/the_cyber_security_recomendations_of_blair_and huntsman_report_on_chinese_ip_theft (\u201cWhile it may be nice to punch back at a hacker and take down his or her networks or even computers, there&#8217;s a big potential for collateral damage, especially if the hackers are using hijacked computers belonging to innocent bystanders.\u201d).<\/p>\n<p>[102] John Reed, <em>Mike Rogers: Cool It with Offensive Cyber Ops<\/em>, Complex Foreign Pol\u2019y (Dec. 14, 2012, 5:07 PM), http:\/complex.foreignpolicy.com\/posts\/2012\/12\/14\/mike_rogers_cool_it_with_offensive_cyber_ops (audio recording of full speech <em>available at<\/em> http:\/\/www.c-span.org\/video?314114-1\/rep-rogers-rmi-addresses-cyber-threats-economy). <em>But see See <\/em>McGee, Sabett, &amp; Shah, <em>supra, <\/em>note 18 (urging the adoption of a \u201cFramework for \u2018good enough\u2019 attribution\u201d).<\/p>\n<p>[103] For definitions and discussion of these terms, seeEric A. Fischer et al., Cong. Research Serv., R42984, The 2013 Cybersecurity Executive Order: Overview and Considerations for Congress2-4,(2013), <em>available at<\/em> http:\/\/www.fas.org\/sgp\/crs\/misc\/R42984.pdf.<\/p>\n<p>[104] Max Fisher, <em>Should the U.S. Allow Companies to \u2018Hack Back\u2019 Against Foreign Cyber Spies?<\/em>, Wash. Post (May 23, 2013, 10:43 AM), http:\/\/www.washingtonpost.com\/blogs\/worldviews\/wp\/2013\/05\/23\/should-the-u-s-allow-companies-to-hack-back-against-foreign-cyber-spies\/ (quoting Lewis, <em>supra, <\/em>note 21).<\/p>\n<p>[105] Los, <em>supra<\/em> note 19.<\/p>\n<p>[106] <em>See <\/em>Fahmida Y. Rashid, <em>Layered Security Essential Tactic of Latest FFIEC Banking Guidelines<\/em>,eWeek (June 30, 2011), http:\/\/www.eweek.com\/c\/a\/IT-Infrastructure\/Layered-Security-Essential-Tactic-of-Latest-FFIEC-Banking-Guidelines-557743\/ (\u201cBanks must adopt a layered approach to security in order to combat highly sophisticated cyber-attacks, the Federal Financial Institutions Examination Council said in a supplement released June 28. The new rules update the 2005 \u2018Authentication in an Internet Banking Environment\u2019 guidance to reflect new security measures banks need to fend off increasingly sophisticated attacks. . . . The guidance . . . emphasized a risk-based approach in which controls are strengthened as risks increase.\u201d).<\/p>\n<p>[107] <em>See PCI 2.0 Encourages Risk-Based Process: Three Things You Need to Know<\/em>, ITGRC (Aug. 23, 2010), http:\/\/itgrcblog.com\/2010\/08\/23\/pci-2-0-encourages-risk-based-process-three-things-you-need-to-know\/.<\/p>\n<p>[108] <em>See <\/em>Lee Vorthman, <em>IT Security: NIST&#8217;s Cybersecurity Framework<\/em>, NetApp (July 16, 2013, 6:01 AM), https:\/\/communities.netapp.com\/community\/netapp-blogs\/government-gurus\/blog\/2013\/07\/16\/it-security-nists-cybersecurity-framework) (\u201cIt is widely anticipated that the Cybersecurity Framework will improve upon the current shortcomings of FISMA by adopting several controls for continuous monitoring and by allowing agencies to move away from compliance-based assessments towards a real-time risk-based approach.\u201d).<\/p>\n<p>[109] Reed, <em>supra <\/em>note 102.<\/p>\n<p>[110] Geoffrey C. Hazard, Jr., <em>Law, Morals, and Ethics<\/em>, 19 S. Ill. U. L.J. 447, 453 (1995), <em>available at <\/em>http:\/\/repository.uchastings.edu\/faculty_scholarship\/252.<\/p>\n<p>[111]<em> Id.<\/em><\/p>\n<p>[112]<em> See generally<\/em> Heinz C. Luegenbiehl &amp; Michael Davis, Engineering Codes of Ethics: Analysis and Applications 10 (1986) (referring to the \u201cContract with society\u201d theory on the relation between professions and codes of ethics).<\/p>\n<p style=\"padding-left: 30px\">According to this approach, a code of ethics is one of those things a group must have before society will recognize it as a profession. The contents of the code are settled by considering what society would accept in exchange for such benefits of professionalism as high income and high prestige. A code is a way to win the advantages society grants only to those imposing certain restraints on themselves.<\/p>\n<p>[113]<em> See, e.g.<\/em>, Official (ISC)<sup>2<\/sup> Guide to the CISSP CBK 1214 (Steven Hernandez ed., 3d ed. 2013) (\u201cThe code helps to protect professionals from certain stresses and pressures (such as the pressure to cut corners with information security to save money) by making it reasonably likely that most other members of the profession will not take advantage of the resulting conduct of such pressures. An ethics code also protects members of a profession from certain consequences of competition, and encourages cooperation and support among the professionals.\u201d).<\/p>\n<p>[114]<em> See id.<\/em><\/p>\n<p>[115] (ISC)<sup>2<\/sup>, (ISC)<sup>2<\/sup> Overview: Evolving in Today\u2019s Complex Security Landscape 4 (2013), <em>available at <\/em>www.infosec.co.uk\/_novadocuments\/47180?v=635294483175930000.<\/p>\n<p>[116] <em>See id.<\/em><\/p>\n<p>[117] David E. Sanger &amp; John Markoff, <em>After Google\u2019s Stand on China, U.S. Treads Lightly<\/em>,N.Y. Times (Jan. 15, 2010), http:\/\/www.nytimes.com\/2010\/01\/15\/world\/asia\/15diplo.html?_r=0.<\/p>\n<p>[118] <em>See, e.g.<\/em>,Skipper Eye, <em>Google Gives Chinese Hackers a Tit for Tat<\/em>, Redmond Pie (Jan. 16, 2010), <em>available at <\/em>http:\/\/www.redmondpie.com\/google-gives-chinese-hackers-a-tit-for-tat-9140352\/.<\/p>\n<p>[119] <em>See<\/em> Shelley Boose, <em>Black Hat Survey: 36% of Information Security Professionals Have Engaged in Retaliatory Hacking<\/em>, BusinessWire(June 26, 2012, 11:00 AM), http:\/\/www.businesswire.com\/news\/home\/20120726006045\/en\/Black-Hat-Survey-36-Information-Security-Professionals (\u201cWhen asked \u2018Have you ever engaged in retaliatory hacking?\u2019 64% said \u2018never,\u2019 23% said \u2018once,\u2019 and 13% said \u2018frequently\u201d. . . . [W]e should take these survey results with a grain of salt . . . . It\u2019s safe to assume some respondents don\u2019t want to admit they use retaliatory tactics.\u201d).<\/p>\n<p>[120] Lewis, <em>supra<\/em> note 21 (\u201cAnother argument is that governments are not taking action, and therefore private actors must step in.\u201d).<\/p>\n<p>[121] Reed, <em>supra<\/em> note 102.<\/p>\n<p>[122] <em>See About FS-ISAC<\/em>, Fin. Serv.: Info. Sharing &amp; Analysis Center, https:\/\/www.fsisac.com\/about (last visited June 9, 2014). Launched in 1999, FS-ISAC was established by the financial services sector in response to 1998&#8217;s Presidential Directive 63. That directive \u2015 later updated by 2003&#8217;s Homeland Security Presidential Directive 7 \u2015 mandated that the public and private sectors share information about physical and cyber security threats and vulnerabilities to help protect the U.S. critical infrastructure. <em>See id<\/em>.<\/p>\n<p>[123] <em>See id.<\/em><\/p>\n<p>[124] <em>FS-ISAC Security Automation Working Group Continues to Mature Automated Threat Intelligence Strategy, Deliver on Multi-Year Roadmap<\/em>, Fin. Serv.: Info. Sharing &amp; Analysis Center (Feb. 26, 2014), https:\/\/www.fsisac.com\/sites\/default\/files\/news\/FSISAC_PR_SAWG_Feb19-2014v1AH%20-%20DHE-ALL-EDITS-FINAL2%20EG.pdf.<\/p>\n<p>[125] <em>See id.<\/em><\/p>\n<p>[126] Sean Sposito, <em>In Cyber Security Fight, Collaboration Is Key: Guardian Analytics<\/em>, Am. Banker (Oct. 08. 2013, 2:01 PM), http:\/\/www.americanbanker.com\/issues\/178_195\/in-cyber-security-fight-collaboration-is-key-guardian-analytics-1062688-1.html.<\/p>\n<p>[127] <em>See generally, Taking Down Botnets: Public and Private Efforts to Disrupt and Dismantle Cybercriminal Networks: Hearing Before the S. Comm. on the Judiciary<\/em>, 113th Cong. (July 15, 2014) http:\/\/www.judiciary.senate.gov\/meetings\/taking-down-botnets_public-and-private-efforts-to-disrupt-and-dismantle-cybercriminal-networks (providing access to testimony from the hearing).<\/p>\n<p>[128] <em>See <\/em>Tracy Kitten, <em>Microsoft, FBI Take Down Citadel Botnets<\/em>, Bank Info Security (June 6, 2013), http:\/\/www.bankinfosecurity.com\/microsoft-fbi-takedown-citadel-botnets-a-5819\/op-1.<\/p>\n<p>[129] <em>See id.<\/em><\/p>\n<p>[130] <em>See id. <\/em><\/p>\n<p>[131] <em>See NCA Leads Global Shylock Malware Takedown<\/em>, infosecurity (July 12, 2014) http:\/\/www.infosecurity-magazine.com\/view\/39289\/nca-leads-global-shylock-malware-takedown\/.<\/p>\n<p>[132] <em>See <\/em>Gregg Keizer, <em>Massive Botnet Takedown Stops Spread of Cryptolocker Ransomware<\/em>,ComputerWorld (June 5, 2014 02:15 PM), http:\/\/www.computerworld.com\/s\/article\/9248872\/Massive_botnet_takedown_stops_spread_of_Cryptolocker_ransomware.<\/p>\n<p>[133] John E. Dunn, <em>Worried US Retailers Battle Cyber-attacks Through New Intelligence-Sharing Body,<\/em> TechWorld (May 16, 2014, 6:29 PM), http:\/\/news.techworld.com\/security\/3517094\/worried-us-retailers-battle-cyber-attacks-through-new-inte\/.<\/p>\n<p>[134] <em>See, e.g.<\/em>,Dan Dupont Retail, <em>Financial Sectors Form Cybersecurity Partnership in Wake of Data Breaches<\/em> (March 13, 2014), http:\/\/insidecybersecurity.com\/Cyber-Daily-News\/Daily-News\/retail-financial-sectors-form-cybersecurity-partnership-in-wake-of-data-breaches\/menu-id-1075.html.<\/p>\n<p>[135] <em>See <\/em>Press Release, Dianne Feinstein, <em>Senate Intelligence Committee Approves Cyber Security Bill <\/em>(July 8, 2014) <em>available at <\/em>http:\/\/www.feinstein.senate.gov\/public\/index.cfm\/2014\/7\/senate-intelligence-committee-approves-cybersecurity-bill.<\/p>\n<p>[136]<em>See <\/em>Brent Rowe et al., The Role of Internet Service Providers in Cyber Security 7 (2011), <em>available at <\/em>http:\/\/sites.duke.edu\/ihss\/files\/2011\/12\/ISP-Provided_Security-Research-Brief_Rowe.pdf.<\/p>\n<p>[137] <em>See, generally, Chatham House Rule<\/em>, Chatham House; The Royal Institute of International Affairs http:\/\/www.chathamhouse.org\/about\/chatham-house-rule (explaining the Chatham House Rule).<\/p>\n<p>[138] Section 631 of the Cable Communications Policy Act of 1984, 47 U.S.C. \u00a7\u00a7 521, <em>et seq. <\/em> The Cable Act prohibits cable systems\u2019 disclosure of personally identifiable subscriber information without the subscriber\u2019s prior consent; requires the operator to destroy information that is no longer necessary for the purpose it was collected, to notify subscribers of system data collection, retention and disclosure practices and to afford subscribers access to information pertaining to them; provides certain exceptions to the disclosure restrictions, such as permission for the cable operator to disclose \u201cif necessary to conduct a legitimate business activity related to a cable service or other service\u201d provided to the subscriber, and disclosure of subscriber names and addresses (but not phone numbers), subject to an \u201copt out\u201d right for the subscriber. Congress expanded, as part of the Cable Television Consumer Protection and Competition Act of 1992, the privacy provision of the Communications Act to cover interactive services provided by cable operators. <em>Id. <\/em><\/p>\n<p>[139] <em>Protecting and Promoting the Open Internet<\/em>, GN Docket No. 14-28, at App\u2019x A, \u00a7\u00a7 8.5, 8.11 (May 15, 2015).<\/p>\n<p>[140] <em>Id. <\/em>at 1-2.<\/p>\n<p>[141] Preserving the Open Internet, 76 Fed. Reg. 59192, 59209 n.102 (Sept. 23, 2011).<\/p>\n<p>[142] Michel Van Eeten et al., The Role of Internet Service Providers in Botnet Mitigation: An Empirical Analysis Based on Spam Data 1 (2010), <em>available at <\/em>http:\/\/weis2010.econinfosec.org\/papers\/session4\/weis2010_vaneeten.pdf.<\/p>\n<p>[143] Rowe et al., <em>supra <\/em>note 136.<\/p>\n<p>[144] <em>See, e.g.<\/em>, Meir Orbach, <em>Israeli Cyber Tech Companies on Rise in US Market<\/em>, Al Monitor (Jan. 23, 2014) http:\/\/www.al-monitor.com\/pulse\/business\/2014\/01\/us-cyber-security-market-israeli-companies.html.<\/p>\n<p>[145] <em>See <\/em>New York Times Co. v. United States, 403 U.S. 713, 714 (1971).<\/p>\n<p>[146] <em>See <\/em>David Bianco, <em>The Pyramid of Pain<\/em>, Enterprise detection &amp; Response Blog(Mar. 1, 2014), http:\/\/detect-respond.blogspot.com\/#!\/2013\/03\/the-pyramid-of-pain.html.<\/p>\n<p>[147] <em>See id. <\/em><\/p>\n<p>[148] <em>See id. <\/em><\/p>\n<p>[149]<em> See <\/em>Sposito, <em>supra<\/em> note 126<em>.<\/em><\/p>\n<p>[150] <em>See FireEye Threat Analytics Platform<\/em>, FireEye,http:\/\/www.fireeye.com\/products-and-solutions\/threat-analytics-platform.htm (last visited June 9, 2014).<\/p>\n<p>[151] <em>See <\/em>Tim Wilson, <em>CrowdStrike Turns Security Fight Toward Attacker<\/em>, Dark Reading (June 25, 2013, 9:18 AM), http:\/\/www.darkreading.com\/analytics\/threat-intelligence\/crowdstrike-turns-security-fight-toward-attacker\/d\/d-id\/1139998?.<\/p>\n<p>[152] <em>See HP IDOL<\/em>,HP Autonomy,www.autonomy.com\/products\/idol (last visited June 9, 2014).<\/p>\n<p>&nbsp;<\/p>\n<\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>DownloadPDF Cite as: Sean L. Harrington, Cyber Security Active Defense: Playing with Fire or Sound Risk Management?, 20 Rich. J.L. &amp; Tech. 12 (2014), http:\/\/jolt.richmond.edu\/v20i4\/article12.pdf. \u00a0Sean L. Harrington* Trying to change its program Trying to change the mode . . . crack the code Images conflicting into data overload[1] \u00a0I. Introduction [1]\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 \u201cBanks Remain the [&hellip;]<\/p>\n","protected":false},"author":4287,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"jetpack_post_was_ever_published":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":false,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2}},"categories":[1228],"tags":[],"class_list":["post-2264","post","type-post","status-publish","format-standard","hentry","category-articles"],"jetpack_publicize_connections":[],"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/paMHOZ-Aw","jetpack-related-posts":[],"_links":{"self":[{"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/posts\/2264","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/users\/4287"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/comments?post=2264"}],"version-history":[{"count":0,"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/posts\/2264\/revisions"}],"wp:attachment":[{"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/media?parent=2264"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/categories?post=2264"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/tags?post=2264"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}