ameliaquining
9 hours ago
If you (like me) found this hard to read, Reuters wrote up a decent summary: https://www.reuters.com/world/trump-signed-memo-allow-use-cy...
On a related note, https://mentalwires.tumblr.com/post/622219187310542848/black...
9 hours ago
If you (like me) found this hard to read, Reuters wrote up a decent summary: https://www.reuters.com/world/trump-signed-memo-allow-use-cy...
On a related note, https://mentalwires.tumblr.com/post/622219187310542848/black...
an hour ago
I am less preoccupied about private companies or government contractors able to carry out cyberattacks on foreign targets and more worried about what constitutes a "foreign target" according to the current US administration.
9 hours ago
Zero-day hunters and the exploit broker market have been a thing for some time now. The US is one buyer on a world market of exploits. Maybe that's what this is trying to address. Many Nation states already stockpile zero days to use against one another when necessary or useful. I skimmed over the whole thing, and I'm guessing the US government wants to carve out a niche in the international zero-day market by creating a privatized, government-backed body that will collectively share hacking tools and exploits among one another. Membership being contingent on NOT participating in any other zero-day markets nor bargaining with any known exploit brokers.
4 hours ago
What laws made this legal? How as the money appropriated by Congress? What oversight does Congress have?
I'm particularly concerned here because the Republican leadership has already begun insisting they can grant companies total immunity from the all state laws, simply by hiring them with a contract! [0]
With that in mind, how likely are these technical contractors to get tasked with, say, surveilling and hacking supposedly "foreign Antifa"? Perhaps with an extrajudicial slur of "waging psychological warfare" with something that inconveniences the administration, like documenting and sharing videos of Americans getting shot by ICE.
> the NCC shall conduct all Program activities in accordance with the Constitution and all other applicable laws and international obligations of the United States, including section 1030 of title 18, United States Code
Huh? That section [1] is basically the Computer Fraud and Abuse Act. Yes, it's extremely relevant, but how precisely will they subcontract civilian companies to run "sustained cyber campaigns" and also claim those contractors will scrupulously obey the CFAA and never make any kind of unauthorized access or fraud?
Either there's some trick that reconciles the conflict, or the companies can't do very much except get nice big taxpayer checks, or else they're going to break the law...
[0] https://www.wired.com/story/ices-new-detention-contracts-dec...
8 hours ago
This sounds similar to letters of marque and reprisal, which is something I haven't thought of since middle school constitution class until now.
3 hours ago
It appears like they're trying to make an industry that works outside of conventional bounds. Just like with private military contractors. Not quite privateers like in the 1630s.
7 hours ago
Erik Prince and similar have been trying to get that going again (for actual commercial cargo shipping related activities) for some time now.
9 hours ago
Vigilantes worked out so well during Reconstruction. But now these are nominally profit-motivated vigilantes. What could possibly go wrong?
11 hours ago
Those who engage in this better have good insurance. Ruin people's stuff, they're going to sue
3 hours ago
Hmm, the fancy interoffice memo plan says that participants will be required to put at least $1m in escrow... but it doesn't say those funds are for paying liability or damages to people they hurt!
Instead, it's money to be simply forfeited to the US treasury [0] if the contractor breaks some to-be-determined conditions in not-yet-existing contracts. In other words, its a money-hostage for obedience.
[0] At least, that would be the legal default, but I'd watch carefully to make sure it doesn't somehow get stolen into an Executive Branch slush-fund.
10 hours ago
With some of these cybercrime groups, being sued is probably the least of their worries..
10 hours ago
This seems like the kind of thing you wouldn't want to announce publicly? But I guess the little man always needs to project power.