The Trump admin will start letting private firms launch international cyberattacks

The Trump admin will start letting private firms launch international cyberattacks

特朗普政府将允许私营企业发起国际网络攻击

The Trump administration is launching a new program that will allow private firms to perform cyberattacks against foreign criminals, as reported earlier by Bloomberg. The private firms would operate “under the control and oversight” of the federal government, giving them permission to surveil and disrupt criminal networks, according to a presidential memorandum published on Wednesday.

据彭博社早前报道,特朗普政府正在启动一项新计划,允许私营企业对外国犯罪分子进行网络攻击。根据周三发布的一份总统备忘录,这些私营企业将在联邦政府的“控制和监督”下运作,并获得监视和破坏犯罪网络的许可。

The Department of Justice and Department of Homeland Security will oversee the private firms, which must meet requirements in “technical proficiency, proven performance of cyber operations, facility security,” and more. Companies in the program must hold a bond or escrow of at least $1 million that they’ll forfeit if they don’t comply with their contractual agreement. The memorandum also says private firms will only hack groups that are “not an institutional part of a foreign government or wholly operated under a foreign government’s direction.”

美国司法部和国土安全部将负责监管这些私营企业,企业必须满足“技术熟练度、网络行动的过往表现、设施安全”等方面的要求。参与该计划的公司必须持有至少 100 万美元的保证金或托管资金,如果未能遵守合同协议,这些资金将被没收。备忘录还指出,私营企业只能攻击那些“非外国政府机构组成部分,或非完全在外国政府指挥下运作”的组织。

The memo describes private businesses as “underutilized” forces for fighting criminal networks. “It is the policy of the United States to use all instruments of national power, including the innovative capabilities of the private sector, to combat cybercrime,” it says.

该备忘录将私营企业描述为打击犯罪网络中“未被充分利用”的力量。备忘录称:“美国的政策是利用一切国家力量工具,包括私营部门的创新能力,来打击网络犯罪。”

But as pointed out by Cybersecurity Dive, it can be difficult to identify which criminal groups are affiliated with foreign governments, which could put cybersecurity firms at risk of stoking geopolitical or legal conflicts. Jason Healey, a senior cyber conflict researcher at Columbia University, tells Cybersecurity Dive that “Anyone conducting these operations is doing so at substantial personal legal risk.” Jake Williams, the vice president of research and development at Hunter Strategy, similarly tells TechCrunch that “Americans participating in these operations could easily be classified as non-uniformed combatants while traveling overseas.”

但正如《Cybersecurity Dive》所指出的,很难识别哪些犯罪集团与外国政府有关联,这可能会使网络安全公司面临引发地缘政治或法律冲突的风险。哥伦比亚大学高级网络冲突研究员杰森·希利(Jason Healey)告诉《Cybersecurity Dive》:“任何进行此类行动的人都面临着巨大的个人法律风险。”Hunter Strategy 的研发副总裁杰克·威廉姆斯(Jake Williams)也向 TechCrunch 表示:“参与这些行动的美国人在海外旅行时,很容易被归类为非武装战斗人员。”

Ben Bernstein, a manager for the cybersecurity advisers team at Huntress, also raises concerns about how this program will play out. “Threat actors don’t launch attacks from labeled servers in Moscow; they route traffic through compromised, innocent infrastructure, like a vulnerable router at an Ohio dental office or a hospital network,” Bernstein says. “That makes it practically impossible to ‘strike back’ without taking out innocent bystanders.”

Huntress 网络安全顾问团队经理本·伯恩斯坦(Ben Bernstein)也对该计划的实施方式提出了担忧。伯恩斯坦说:“威胁行为者不会从莫斯科带有标签的服务器发起攻击;他们通过受损的无辜基础设施路由流量,比如俄亥俄州牙科诊所的易受攻击路由器或医院网络。这使得在不伤害无辜旁观者的情况下进行‘反击’几乎是不可能的。”

The US government previously carried out its own cyber operations, rather than relying on third parties. President Donald Trump began making plans to get private cybersecurity companies involved last year, Bloomberg reported.

此前,美国政府通常自行开展网络行动,而非依赖第三方。据彭博社报道,唐纳德·特朗普总统去年就开始计划让私营网络安全公司参与其中。