12 comments

  • ameliaquining 9 hours ago ago

    If you (like me) found this hard to read, Reuters wrote up a decent summary: https://www.reuters.com/world/trump-signed-memo-allow-use-cy...

    On a related note, https://mentalwires.tumblr.com/post/622219187310542848/black...

  • rbtms an hour ago ago

    I am less preoccupied about private companies or government contractors able to carry out cyberattacks on foreign targets and more worried about what constitutes a "foreign target" according to the current US administration.

  • angelofthe0dd 9 hours ago ago

    Zero-day hunters and the exploit broker market have been a thing for some time now. The US is one buyer on a world market of exploits. Maybe that's what this is trying to address. Many Nation states already stockpile zero days to use against one another when necessary or useful. I skimmed over the whole thing, and I'm guessing the US government wants to carve out a niche in the international zero-day market by creating a privatized, government-backed body that will collectively share hacking tools and exploits among one another. Membership being contingent on NOT participating in any other zero-day markets nor bargaining with any known exploit brokers.

  • Terr_ 4 hours ago ago

    What laws made this legal? How as the money appropriated by Congress? What oversight does Congress have?

    I'm particularly concerned here because the Republican leadership has already begun insisting they can grant companies total immunity from the all state laws, simply by hiring them with a contract! [0]

    With that in mind, how likely are these technical contractors to get tasked with, say, surveilling and hacking supposedly "foreign Antifa"? Perhaps with an extrajudicial slur of "waging psychological warfare" with something that inconveniences the administration, like documenting and sharing videos of Americans getting shot by ICE.

    > the NCC shall conduct all Program activities in accordance with the Constitution and all other applicable laws and international obligations of the United States, including section 1030 of title 18, United States Code

    Huh? That section [1] is basically the Computer Fraud and Abuse Act. Yes, it's extremely relevant, but how precisely will they subcontract civilian companies to run "sustained cyber campaigns" and also claim those contractors will scrupulously obey the CFAA and never make any kind of unauthorized access or fraud?

    Either there's some trick that reconciles the conflict, or the companies can't do very much except get nice big taxpayer checks, or else they're going to break the law...

    [0] https://www.wired.com/story/ices-new-detention-contracts-dec...

    [1] https://www.law.cornell.edu/uscode/text/18/1030

  • michaelfm1211 8 hours ago ago

    This sounds similar to letters of marque and reprisal, which is something I haven't thought of since middle school constitution class until now.

    • Tanoc 3 hours ago ago

      It appears like they're trying to make an industry that works outside of conventional bounds. Just like with private military contractors. Not quite privateers like in the 1630s.

    • walrus01 7 hours ago ago

      Erik Prince and similar have been trying to get that going again (for actual commercial cargo shipping related activities) for some time now.

  • burnt-resistor 9 hours ago ago

    Vigilantes worked out so well during Reconstruction. But now these are nominally profit-motivated vigilantes. What could possibly go wrong?

  • bediger4000 11 hours ago ago

    Those who engage in this better have good insurance. Ruin people's stuff, they're going to sue

    • Terr_ 3 hours ago ago

      Hmm, the fancy interoffice memo plan says that participants will be required to put at least $1m in escrow... but it doesn't say those funds are for paying liability or damages to people they hurt!

      Instead, it's money to be simply forfeited to the US treasury [0] if the contractor breaks some to-be-determined conditions in not-yet-existing contracts. In other words, its a money-hostage for obedience.

      [0] At least, that would be the legal default, but I'd watch carefully to make sure it doesn't somehow get stolen into an Executive Branch slush-fund.

    • VoidWhisperer 10 hours ago ago

      With some of these cybercrime groups, being sued is probably the least of their worries..

  • pogue 10 hours ago ago

    This seems like the kind of thing you wouldn't want to announce publicly? But I guess the little man always needs to project power.