{"id":6716,"date":"2017-10-23T17:42:24","date_gmt":"2017-10-23T21:42:24","guid":{"rendered":"http:\/\/jolt.richmond.edu\/?p=6716"},"modified":"2019-03-08T19:52:06","modified_gmt":"2019-03-09T00:52:06","slug":"defensive-hacking-leads-legal-transition-in-cybersecurity","status":"publish","type":"post","link":"https:\/\/blog.richmond.edu\/jolt\/2017\/10\/23\/defensive-hacking-leads-legal-transition-in-cybersecurity\/","title":{"rendered":"Defensive Hacking Leads Legal Transition in Cybersecurity"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-6717\" src=\"https:\/\/blog.richmond.edu\/jolt\/files\/2017\/10\/unnamed.jpg\" alt=\"\" width=\"284\" height=\"177\" \/><\/p>\n<p>By: Jon Neri,<\/p>\n<p>In light of the recent Equifax data breach, I feel that now is an appropriate time to be talking about current legislative pushes for the public recognition and legalization of defensive hacking efforts. Defensive hacking, sometimes referred to as \u201chackback,\u201d is a method to prevent and counteract future data breaches that has been scarcely discussed within a political forum up until recently.<a href=\"#_ftn1\" name=\"_ftnref1\">[1]<\/a> There is no single process to successfully hack an eminent hacker, and companies have been imploring a wide range of counter-hacking methods for well over a decade.<a href=\"#_ftn2\" name=\"_ftnref2\">[2]<\/a> Despite varying avenues for accomplishing a preemptive attack, strategies commonly involve collecting intel on suspect hackers, breach the hackers\u2019 data infrastructures, and then proceeding to destroy any stolen data.<a href=\"#_ftn3\" name=\"_ftnref3\">[3]<\/a><\/p>\n<p>Large companies, banks, search engines, and other internet entities that store the private information of their users are known to contract private companies and individuals who specialize in this practice; the goal being to protect their own networks and data from further breach and prevent the release of confidential information.<a href=\"#_ftn4\" name=\"_ftnref4\">[4]<\/a> Despite the known fact that these employed hackers are breaking those same laws as threatening hackers, their methods have rarely gained large-scale public attention.<a href=\"#_ftn5\" name=\"_ftnref5\">[5]<\/a> Therefore, the debate on whether such practices should become deemed suitable and further condoned under federal law has never entirely culminated.<a href=\"#_ftn6\" name=\"_ftnref6\">[6]<\/a><\/p>\n<p>While defensive hacking remains unsupported by codified law, it has long been observed that governing policy appears to support such efforts in countervailing data breaches.<a href=\"#_ftn7\" name=\"_ftnref7\">[7]<\/a> In 2005, there was a highly-publicized case in which the plaintiff sued his former employer for wrongful termination after being let go following his independent investigation of a network breach.<a href=\"#_ftn8\" name=\"_ftnref8\">[8]<\/a> Shawn Carpenter had been employed at Sandia National Laboratories as a network security analyst when the company\u2019s network was hacked in 2003.<a href=\"#_ftn9\" name=\"_ftnref9\">[9]<\/a> Carpenter took it upon himself to launch an independent investigation, utilizing hacking techniques in order to track-down a cyberespionage group centralized in China.<a href=\"#_ftn10\" name=\"_ftnref10\">[10]<\/a> He eventually reported his discoveries to the FBI.<a href=\"#_ftn11\" name=\"_ftnref11\">[11]<\/a> Once Sandia officials learned of Carpenter\u2019s sharing of information with outside agencies, they terminated him for the inappropriate use of power and confidential information that he only had access to through his position as network security manager.<a href=\"#_ftn12\" name=\"_ftnref12\">[12]<\/a><\/p>\n<p>Carpenter sued and ultimately won his case, the District Court of New Mexico awarding him $4.3 million in punitive damages and over $387,000 in compensatory damages.<a href=\"#_ftn13\" name=\"_ftnref13\">[13]<\/a> Carpenter\u2019s attorney gave a statement indicating that the jury\u2019s verdict served as \u201cvindication of his decision to do the right thing and turn over the information he obtained to the proper federal authorities\u2026 protect[ing] the national interest.\u201d<a href=\"#_ftn14\" name=\"_ftnref14\">[14]<\/a> It\u2019s safe to say that over a decade later, the message sent in the <em>Carpenter<\/em> ruling stands true today: the law intends to protect those who hack on behalf of security interests, whether those interests stem from government or otherwise.<a href=\"#_ftn15\" name=\"_ftnref15\">[15]<\/a><\/p>\n<p>However, the hush around counter-hacking has steadily grown louder with every news heading boasting another large-scale cybersecurity breach. As a result, some legislatives appear ready to address hackback within the public forum. In March of this year, Representative Tom Graves presented a discussion draft bill which would amend the Computer Fraud and Abuse Act (CFAA).<a href=\"#_ftn16\" name=\"_ftnref16\">[16]<\/a> Representative Graves stated that the \u201cbill is about empowering individuals to defend themselves online\u2026 [amendment] will serve as a disincentive for criminal hacking because the risk of getting caught will likely go up.\u201d<a href=\"#_ftn17\" name=\"_ftnref17\">[17]<\/a> This is because private individuals and companies will now officially be protected under the proposed law, when implementing hacking techniques with the intent to track hackers immediately following a network breach.<a href=\"#_ftn18\" name=\"_ftnref18\">[18]<\/a><\/p>\n<p>The proposed bill essentially provides a \u201cdefense to a prosecution under the CFAA that the conduct constituting the offense was an active cyber defense measure.\u201d<a href=\"#_ftn19\" name=\"_ftnref19\">[19]<\/a> This means that it is simply to be applied as a justification for the immediate tracking of hackers after a cyberattack.<a href=\"#_ftn20\" name=\"_ftnref20\">[20]<\/a> It excludes the \u201cdestruction of data\u201d or the \u201cimpairment of the functionality of the attacker\u2019s computer system.\u201d<a href=\"#_ftn21\" name=\"_ftnref21\">[21]<\/a> Thus, the proposed amendment does not place justice in private hands, but allows victims to conduct an instantaneous defense against hackers and then report relevant information to government agencies responsible for cybersecurity.<a href=\"#_ftn22\" name=\"_ftnref22\">[22]<\/a><\/p>\n<p>While the bill has received praise from legal professionals such as University of Texas law professor Robert Chesney, who sees it as a necessity in our technological age, it is not lacking in critiques.<a href=\"#_ftn23\" name=\"_ftnref23\">[23]<\/a> In fact, its strongest opposition is from those who deal in cybersecurity as a profession. Brad Maryman, retired FBI agent and leader cybersecurity firm Maryman &amp; Associates, is not of the opinion that \u201cthe average citizen is capable of appropriately identifying the hacker.\u201d<a href=\"#_ftn24\" name=\"_ftnref24\">[24]<\/a> This is because cyberattacks are routed through other victims\u2019 network systems after they have been attacked themselves. <a href=\"#_ftn25\" name=\"_ftnref25\">[25]<\/a> This creates a string of computers, known in the field as \u201cbotnet\u201d networks.<a href=\"#_ftn26\" name=\"_ftnref26\">[26]<\/a> Botnets are often incredibly complicated, and the notion that millions of victims engage in searches, trying to navigate such a complex maze, delivering information to authorities along the way could easily turn into chaos for everyone involved.<a href=\"#_ftn27\" name=\"_ftnref27\">[27]<\/a><\/p>\n<p>Regardless of its initial feedback, Rep. Graves\u2019s bill represents a transition in legal discourse surrounding cybersecurity. As data breaches continue to plague our industries, we will undoubtedly see increased efforts to promote legislation concerning cyberattacks and the rights of victims involved. Based on recent events in our cyber community, such rights are likely to incite legal protections concerning defensive hacking techniques in the near future.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref1\" name=\"_ftn1\">[1]<\/a> <em>See <\/em>Joseph Cox, <em>Revenge Hacking Is Hitting the Big Time<\/em>, The Daily Beast (Sept. 19, 2017, 1:00 AM), https:\/\/www.thedailybeast.com\/inside-the-shadowy-world-of-revenge-hackers.<\/p>\n<p><a href=\"#_ftnref2\" name=\"_ftn2\">[2]<\/a> <em>See <\/em>Jaikumar Vijayan, <em>Reverse hacker wins $4.3M in suit against Sandia Labs<\/em>, Computerworld (Feb. 14, 2007, 12:00 AM), https:\/\/www.computerworld.com\/article\/2543470\/security0\/reverse-hacker-wins&#8211;4-3m-in-suit-against-sandia-labs.html.<\/p>\n<p><a href=\"#_ftnref3\" name=\"_ftn3\">[3]<\/a> Cox, <em>supra <\/em>note 1.<\/p>\n<p><a href=\"#_ftnref4\" name=\"_ftn4\">[4]<\/a> <em>Id.<\/em><\/p>\n<p><a href=\"#_ftnref5\" name=\"_ftn5\">[5]<\/a> <em>See id.<\/em><\/p>\n<p><a href=\"#_ftnref6\" name=\"_ftn6\">[6]<\/a> <em>See id.<\/em><\/p>\n<p><a href=\"#_ftnref7\" name=\"_ftn7\">[7]<\/a> Robert Chesney, <em>Legislative Hackback: Notes on the Active Cyber Defense Certainty Act discussion draft<\/em>, Lawfare Blog (Mar. 7, 2017, 10:30 AM), https:\/\/www.lawfareblog.com\/legislative-hackback-notes-active-cyber-defense-certainty-act-discussion-draft.<\/p>\n<p><a href=\"#_ftnref8\" name=\"_ftn8\">[8]<\/a> Vijayan, <em>supra <\/em>note 2.<\/p>\n<p><a href=\"#_ftnref9\" name=\"_ftn9\">[9]<\/a> <em>Id.<\/em><\/p>\n<p><a href=\"#_ftnref10\" name=\"_ftn10\">[10]<\/a> <em>Id.<\/em><\/p>\n<p><a href=\"#_ftnref11\" name=\"_ftn11\">[11]<\/a> <em>Id.<\/em><\/p>\n<p><a href=\"#_ftnref12\" name=\"_ftn12\">[12]<\/a> <em>See id<\/em>.<\/p>\n<p><a href=\"#_ftnref13\" name=\"_ftn13\">[13]<\/a> <em>Id.<\/em>; <em>see also <\/em>Carpegnter v. Sandia Corp., No. 05-06347, N.M. Dist. WL 1108465 (Feb. 21, 2007).<\/p>\n<p><a href=\"#_ftnref14\" name=\"_ftn14\">[14]<\/a> Vijayan, <em>supra <\/em>note 2.<\/p>\n<p><a href=\"#_ftnref15\" name=\"_ftn15\">[15]<\/a> Chesney, <em>supra<\/em> note 7.<\/p>\n<p><a href=\"#_ftnref16\" name=\"_ftn16\">[16]<\/a> <em>See <\/em>Steven Nelson, <em>\u2018Self-Defense\u2019 Bill Would Allow Victims to Hack Back<\/em>, U.S. News, Mar. 9, 2007, https:\/\/www.usnews.com\/news\/articles\/2017-03-09\/self-defense-bill-would-allow-victims-to-hack-back.<\/p>\n<p><a href=\"#_ftnref17\" name=\"_ftn17\">[17]<\/a> <em>Id.<\/em><\/p>\n<p><a href=\"#_ftnref18\" name=\"_ftn18\">[18]<\/a> Chesney, <em>supra<\/em> note 7.<\/p>\n<p><a href=\"#_ftnref19\" name=\"_ftn19\">[19]<\/a> <em>Id.<\/em><\/p>\n<p><a href=\"#_ftnref20\" name=\"_ftn20\">[20]<\/a> <em>See id.<\/em><\/p>\n<p><a href=\"#_ftnref21\" name=\"_ftn21\">[21]<\/a> Active Cyber Defense Certainty Act of 2017 (discussion draft), 115<sup>th<\/sup> Cong. \u00a7 2(1)(B) (2017).<\/p>\n<p><a href=\"#_ftnref22\" name=\"_ftn22\">[22]<\/a> <em>Id. <\/em>at \u00a7 3(2)(B).<\/p>\n<p><a href=\"#_ftnref23\" name=\"_ftn23\">[23]<\/a> Chesney, <em>supra<\/em> note 7.<\/p>\n<p><a href=\"#_ftnref24\" name=\"_ftn24\">[24]<\/a> Nelson, <em>supra <\/em>note 16.<\/p>\n<p><a href=\"#_ftnref25\" name=\"_ftn25\">[25]<\/a> <em>Id.<\/em><\/p>\n<p><a href=\"#_ftnref26\" name=\"_ftn26\">[26]<\/a> <em>See id.<\/em><\/p>\n<p><a href=\"#_ftnref27\" name=\"_ftn27\">[27]<\/a> <em>See id.<\/em><\/p>\n<p>Image Source:\u00a0https:\/\/thetempconnection.com\/2777-2\/.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>By: Jon Neri, In light of the recent Equifax data breach, I feel that now is an appropriate time to be talking about current legislative pushes for the public recognition and legalization of defensive hacking efforts. Defensive hacking, sometimes referred to as \u201chackback,\u201d is a method to prevent and counteract future data breaches that has [&hellip;]<\/p>\n","protected":false},"author":4287,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"jetpack_post_was_ever_published":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":false,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2}},"categories":[51366],"tags":[],"class_list":["post-6716","post","type-post","status-publish","format-standard","hentry","category-blog-post"],"jetpack_publicize_connections":[],"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/paMHOZ-1Kk","jetpack-related-posts":[],"_links":{"self":[{"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/posts\/6716","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/users\/4287"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/comments?post=6716"}],"version-history":[{"count":0,"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/posts\/6716\/revisions"}],"wp:attachment":[{"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/media?parent=6716"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/categories?post=6716"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/tags?post=6716"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}