Opens in a new tab
vmblog logo 2024 wht (updated)

3 Major Problems With the Proposed Hack Back Law

Share: 

David Marshall | Published: June 20, 2017

Recently, Tom Graves, a Republican representative from Georgia proposed an update to the Active Cyber Defense Certainty Act (ACDC). If it becomes a law, victims of hacking could respond to the perpetrators in kind without prosecution.

On its face, this law might seem like an effective way to make hacked organizations feel empowered when their networks are compromised. However, analysts argue there are many issues to contend with.

1. Third-Party Hosting Providers May Suffer Damages, Too

The ACDC would make it legal for hacking victims to identify the responsible parties, stop the attacks and seize the stolen files. However, a large percentage of companies are woefully ill-prepared against hacking attempts, so it’s a big stretch to assume their representatives would hire people who can hack back if called upon, without causing unnecessary damages.

Being able to respond with hacking in a way that does not cause harm due to carelessness is especially important when third-party hosting providers are involved. The stipulation that allows for victims to retrieve stolen files would be valid as long as the victims notify the Federal Bureau of Investigation first.

But, what if those files in question are hosted on a third-party site like Amazon and the person or team retaliating against the initial hacking attempt hurts Amazon’s infrastructure in the process? If the ACDC update becomes a reality, there will also have to be measures put in place that spell out what happens if hosting providers get caught in the crossfire, so to speak.

2. It Might Cause Business Leaders to Become Less Vigilant About Security

Getting a security certification for your business is an excellent way to increase customer confidence, learn to adjust your company’s existing security measures so they fit within an established framework and enjoy more peace of mind during day-to-day operations.

However, if business leaders don’t understand how complicated hacking can be, they might stop being so concerned about all types of security-related precautions.

Many naïve business executives casually assume hacking won’t happen at their companies. Some even take such lackadaisical thinking a step further and think, “If it does, I’ll just hire a hacker who is able to respond defiantly and quickly.” That’s not a realistic option though, considering that hackers’ attacks are often extremely well planned and more complicated than they seem.  

3. Revealing Hackers and Preserving Evidence for Court Proceedings Will Be Difficult

Some cybercrime movies make it seem like unveiling a hacker is a relatively straightforward process. However, people who are experts in internet-related crimes say that’s not the case at all, especially since the most skilled and experienced cybercriminals use what’s known as false flagging to mislead the people who are trying to figure out what’s going on.

False flagging is not a new concept. It originated with the Navy warships used in World War I. Spy organizations often participate in false flagging to frame their targets, and, if things are done well, those framers are never found out about.

The reality of false flagging is often brought up when people talk about what could go wrong if the ACDC is passed. Hacking victims informing law enforcement officials that they’re going to hack back is one thing, but preserving evidence so it’ll be valid in a court of law is a much trickier matter, especially if false flagging comes into play and makes it more time-consuming than expected to reveal the real culprits.

Experts warn if companies want to exercise their rights within the ACDC, they need to first hire legal representatives who are well versed in gathering evidence that would not likely be deemed invalid. Otherwise, even seemingly high-profile cases could quickly get thrown out.

It’ll be interesting to see what happens when the ACDC progresses further through the legislative process. For now though, it should be clear why people in the know assert the measure is not as worthy as it seems after a merely superficial examination.

##

About the Author

Kayla Matthews is a tech-loving blogger who writes and edits ProductivityBytes.com. Follow her on Twitter to read all of her latest posts!