A bold new strategy or a dangerous precedent? Experts are divided on Trumpâs memo.
A bold new strategy or a dangerous precedent? Experts are divided on Trumpâs memo.
A newly-signed presidential memorandum enlisting private sector companies in federal law enforcement hacking operations against criminal organizations could present a number of legal, practical and moral pitfalls, cyber experts told CyberScoop a day after the order was released.
While some have celebrated the memo as an overdue maneuver to more aggressively combat cybercriminals, others view it as risky at best and potentially destructive at worst. Supporters, critics and everyone in between also said that how it plays out could be decided in the 60-day timeframe the memo sets to establish the program.
But ultimately, âitâs a massive shift in the cyber policy community,â said Michael Garcia, a former top official at the Cybersecurity and Infrastructure Agency. âThis is a philosophical shift.â
The Concerns
On the most critical end of the spectrum is security consultant Davi Ottenheimer, who has been a proponent of concepts like âhack backâ or âactive defenseâ that envision a bigger role for the private sector. But he was unsparing in his criticism of the Trump memo.
âItâs an embarrassment to America,â he told CyberScoop. âItâs like seeing somebody strapped onto a horse backwards, looking at the wrong end of a rifle.â
The Trump memoâs approach has been likened to the âletters of marqueâ concept used in early U.S. history, when it authorized sea privateers to attack and capture enemy ships and goods on behalf of the country. But Ottenheimer, founder of Ottenheimer GmbH, noted that the practice fell out of favor for good reason in the 1800s because of the violence it unleashed and how it contributed to mercenarism.
Additionally, the memo raises a number of targeting-related issues, he said. Ottenheimer is concerned about Trumpâs intentions. The memo specifically pertains to the use of participating companies against transnational criminal organizations.
âLeft-wing opposition, liberals, anti-fascists âtheyâre all criminals to him,â Ottenheimer said. âSo to authorize attacking criminals under this means private organizations can go hack people that he designates as criminals.â
Under the memo, the program must establish legal and constitutional procedures for the prior approval of the targeting of U.S. citizens, as well as develop procedures to halt any unintentional targeting of U.S. people or systems.
However, the limitation on targeting criminals only creates a perverse incentive for attackers and a peculiar defense for anyone whoâs attacked, Ottenheimer said.
He envisioned a scenario for a company participating in the program where âyouâre hacking [a target], and they go, âHey, weâre the state.â And then [private companies] are like, âOh, I canât hack you anymore.â Boom. They decided when you can and canât hack.â
Furthermore, âyou incentivize people to know as little as possible so [operations] can be authorized,â he said.
The memo raises ethical concerns for him as well: âYou canât attack somebody and then say itâs your fault that you didnât notify them you didnât want to be attacked.â
âThereâs no notice for you being designated. Thereâs no prevention of you being designated. Thereâs no way for you to know youâre being designated,â Ottenheimer said. âThatâs like a person sitting down next to you and smoking a cigarette and blowing smoke in your face and saying, âHey, you got to say you donât like cancer if you donât want me to do this to you right now.ââ
Garcia, now vice president of the cybersecurity practice at Monument Advocacy, said he supports some of the ideas of the memo, but worries about how it will be executed.
âIt comes down to attribution, and if you make a risky bet on who weâre attributing [attacks] to, thatâs where things can get dicey,â Garcia told CyberScoop.
There could be pressure to attribute faster, which could perhaps lead to lower certainty about whoâs being targeted, and that in turn could lead to a private sector company accidentally attacking a foreign government, he said.
That raises legal questions: âItâs in the Constitution âthe federal government has the ability to wage war. And there are laws by which private citizens canât take up arms,â Garcia said.
He wanted the memo to include court oversight of the program, similar to whatâs been required for private sector takedown operations. .
Garcia also isnât sure whether there will be a big enough pool of companies willing to jump into offensive cyber operations.
âFrom the lawyer perspective, itâs, âAre you okay with engaging in this kind of legal risk? And who knows what protections the government will provide?ââ he said. âIâd be very curious to see what the foreign governmentsâ reactions are â âWeâre going to cut ties with any participating company that engages in this.ââ
Errata Security CEO Robert Graham wrote that under the program, companies âare not willy-nilly hacking back,â given the federal supervision elements. âThough, I wonder if it doesnât eventually morph into law enforcement saying âStop bothering us, just do what you think is best.âââ
The Case For
The Trump administration and the memoâs supporters have touted it as a means to put the United States on stronger ground in cyberspace.
Amanda Naylor, the director of cyber policy at the National Security Council who worked on the memo, said on LinkedIn that it was designed âto bring the capabilities, speed, and innovation of the American private sector into the fight against transnational cybercrime and fraud.â
Former Trump White House cybersecurity official Joshua Steinman said he views the memo as a step toward âparity,â given how U.S. adversaries operate in cyberspace.
âThe Chinese and the Russians do this at scale, and I guarantee you they have very few limiting tools when they do it,â said Steinman, now founder of the security firm Gavalnick. âIt opens up an entire workforce that allows us to go out and achieve strategic objectives.â
The restrictions in the memo are important, he told CyberScoop.
âThe most sensitive things are going to continue to be done by the uniformed and authorized civilian workforces, but thereâs a lot of low-hanging fruit,â i.e., criminal organizations, Steinman said. He doesnât have any fear of the program overstepping as a result.
âWe operate like a Boy Scout in cyberspace,â he said. âItâs measured and reasoned.â He compared it to the Right to Try Act for medications.
He also said he expects to see a lot of interest in participating in the private sector.
Ari Redbord, global head of policy at TRM Labs, praised the memo too, calling it âa huge step toward empowering the private sector at a critical momentâ that âhas a real opportunity to be truly transformative.â
âScammers are using AI to move with unprecedented speed and scale, stealing billions in life savings from average Americans and small businesses,â he said. âThe private sector holds the data. The public sector holds the authorities. This [memo] puts them together.â
Whatâs Next
The coordination center charged with establishing the program under the memo has 60 days to complete its work. That process could determine a lot. Graham noted that the memo has a classified annex, too.
The memo as written is quiet about what becomes of any seized assets, Graham noted. Redbord raised the same topic as one of his questions about execution of the memo.
âWhat government direction and control looks like in the middle of a live operation,â he said in listing his questions. âHow disruption turns into actual dollars back in victimsâ pockets, and whether we can build a true victim compensation fund as part of this program. What happens when an operation touches a third country with its own laws and its own interests. And how success gets measured, in money recovered and networks dismantled.â
Will Barker, cybersecurity adviser at Huntress, said whatâs next could be key.
âThe 60-day implementing guidance is where the real substance lives,â he said in a written quote. âMinimum standards, operational procedures, the adjudicatory framework for target selection.â
How it works
Once you click Generate, Ollama reads this article and crafts 5 comprehension questions. Your answers are graded against the article content â general knowledge won't be enough. Score 70+ to count toward your certificate.
Questions are cached â you'll always get the same 5 for this article.