There are ideas that sound terrible because they are terrible.
Then there are ideas that sound terrific for about thirty seconds, right up until you ask the most basic question in international relations:
What happens when everyone else does it too?
President Donald Trump has just signed a National Security Presidential Memorandum establishing a program under which vetted American private companies can participate in offensive cyber operations against foreign transnational criminal organizations.
That description sounds almost reassuring.
We’re going after ransomware gangs. Scammers. Cybercriminals. People stealing billions of dollars from Americans.
Good.
Hit them where it hurts.
Except that isn’t all the memorandum says.
The government is contemplating something considerably more consequential. Participating private companies may conduct what the memorandum calls “cyber surveillance operations” and “cyber effects operations.” Those operations can include manipulating, disrupting, degrading or destroying information systems and infrastructure.
In other words, private American companies may receive authorization from the United States government to break into computers in other countries and potentially destroy things inside them.
That is not my characterization of the policy. Those capabilities are contained in the memorandum itself.
And apparently we have decided this is a good idea.
I think it is a spectacularly bad one.
We Are Writing a Rule for Everyone
The easiest way to evaluate any new American foreign-policy power is to perform what I call the Putin Test.
Take whatever authority we’re claiming for ourselves and replace the words United States with Russia.
Would we still consider it reasonable?
Suppose Vladimir Putin announced tomorrow:
“The Russian Federation will authorize vetted Russian corporations to penetrate, manipulate, disrupt and destroy computer systems in foreign countries belonging to organizations that victimize Russian citizens.”
Would anyone in Washington respond:
“That seems perfectly reasonable. As long as they’re vetted.”
Of course not.
We would call them state-sponsored hackers.
If China authorized private Chinese technology companies to attack computers in California, we’d call it Chinese aggression.
If Iran created a corps of government-approved private hackers and one of those companies disabled an American server, we’d demand consequences.
If North Korea did it, we’d probably impose another dozen sanctions before lunch.
But somehow when we create government-authorized private hacking companies, we’re supposed to call it innovative public-private cooperation.
That’s the problem with precedent.
You don’t get to write international rules that contain the phrase “only when America does it.”
Welcome Back, Privateers
There is an almost wonderfully archaic quality to this.
Centuries ago governments used privateers.
Instead of relying entirely upon their navies, governments authorized privately owned ships to attack designated enemies. Private individuals could effectively conduct state-sanctioned warfare.
It was useful.
It was also messy, difficult to control and wonderfully prone to abuse.
Eventually the great trading powers developed a rather obvious insight:
Maybe allowing private actors to conduct international violence isn’t such a terrific idea.
Now we appear determined to reinvent privateering because the ships are computers.
The Financial Times is already describing the concept as “cyber privateering.”
The analogy isn’t exact. These aren’t pirates receiving permission to loot merchant ships and keep the treasure.
But the underlying concept should make us uncomfortable:
The state is delegating offensive international power to private actors.
We’ve spent generations trying to make governments responsible for what governments do.
Now we’re deliberately muddying that distinction.
Don’t Worry. There Are Guardrails.
Naturally, there are safeguards.
Companies have to be vetted.
Operations require approval.
The Justice Department and Department of Homeland Security are supposed to review proposed operations.
Targets are supposed to be foreign criminal organizations rather than foreign governments.
Companies must put up at least a $1 million bond or escrow that can be forfeited if they violate the rules. Operations expected to kill or seriously injure people or rise to the level of an armed attack aren’t supposed to be authorized.
Wonderful.
I’m sure the Internet will respect those boundaries.
The fundamental problem is that computers don’t come with little flags telling you who actually owns them.
Cybercriminals routinely operate through other people’s infrastructure.
They compromise servers.
They hijack computers.
They rent cloud services.
They route operations through innocent systems.
They hide behind intermediaries.
And sometimes the criminals themselves have complicated relationships with governments.
That last part should terrify us.
The distinction between a Russian criminal hacker and a Russian intelligence asset isn’t necessarily a nice clean line.
A hacker can be a criminal on Monday, useful to an intelligence service on Tuesday and back to stealing cryptocurrency on Wednesday.
Cybersecurity experts are already pointing to precisely this problem: determining whether apparently independent criminal groups are actually connected to foreign governments can be extraordinarily difficult.
Eventually somebody is going to get it wrong.
Not because Americans are stupid.
Because attribution in cyberspace is extraordinarily difficult.
And Then We Hit the Wrong Computer
Imagine the inevitable incident.
An American cyber contractor receives authorization to destroy infrastructure belonging to a ransomware organization.
The intelligence looks solid.
The operation succeeds beautifully.
Servers disappear.
Data is destroyed.
Everyone congratulates themselves.
Except six hours later we discover that one of those machines didn’t actually belong to the ransomware organization.
It belonged to a German company.
Or a Canadian hospital.
Or a Singaporean bank.
Or a French telecommunications provider.
Or, considerably worse, an intelligence service belonging to a nuclear-armed country.
Now what?
The American company says:
“We were operating under authorization from the United States government.”
Which is exactly the problem.
This isn’t some teenager in a basement.
It’s us.
One expert quoted by Cybersecurity Dive argues that under international law the United States could be accountable for cyberattacks conducted by participating companies—even when a company violates the program’s rules.
That ought to get everyone’s attention.
We may have privatized the keyboard.
We haven’t necessarily privatized the consequences.
Then Comes Reciprocity
This is where the policy goes from questionable to potentially disastrous.
Russia doesn’t even have to retaliate directly.
It can simply copy us.
So can China.
So can Iran.
Create a certification program.
Vet some companies.
Establish government oversight.
Require authorization.
Give them approved targets.
Then unleash them.
And here’s the really fun part:
Who defines “criminal”?
We do?
Apparently not.
Every country does.
China considers activities criminal that Americans consider protected political speech.
Russia considers some organizations criminal or extremist that Western governments do not.
Iran has its own definitions.
Saudi Arabia has its own definitions.
Suddenly the question isn’t whether private companies should be allowed to attack foreign criminal organizations.
We’ve already answered that.
The question becomes:
Whose definition of criminal organization counts?
Imagine a Chinese-approved cyber company attacking the computers of a Chinese dissident organization operating in California.
Beijing announces that the organization was engaged in criminal activities threatening Chinese citizens.
Washington screams that China has attacked Americans.
And Beijing calmly replies:
“We are conducting carefully supervised cyber-effects operations against a transnational criminal organization. We adopted safeguards modeled on the American system.”
That wouldn’t make China’s attack lawful.
It wouldn’t eliminate America’s right to respond.
But we would have surrendered one extremely useful argument:
Private corporations should not be conducting government-authorized offensive cyber operations inside other countries.
Because apparently we don’t believe that anymore.
The World’s Biggest Glass House Just Started Handing Out Rocks
There is another reason America should be particularly cautious about establishing this norm.
Look at what we have to lose.
The United States is one of the most digitally dependent societies in human history.
Our banking system runs on computers.
Our hospitals run on computers.
Our communications run on computers.
Our airlines run on computers.
Our logistics networks run on computers.
Our water systems run on computers.
Our electrical grid runs on computers.
Our businesses run on cloud computing.
Our government runs on enormous interconnected information systems.
We have built an astonishing civilization on top of silicon, fiber optics, radio links and software.
And now the world’s biggest glass house has decided throwing rocks is an exciting new strategy.
That doesn’t mean America shouldn’t conduct offensive cyber operations.
Sometimes it absolutely should.
But that’s why we have intelligence agencies, law enforcement agencies, the military and U.S. Cyber Command.
Those organizations exist inside elaborate systems of governmental authority precisely because the consequences of getting this wrong can be enormous.
The question isn’t whether America should fight ransomware gangs.
Of course it should.
The question is why we suddenly think delegating destructive international cyber capabilities to private corporations makes us safer.
And What Happens to the Employees?
Here’s another little detail that ought to bother every employee of one of these companies.
American authorization is not international diplomatic immunity.
Suppose an employee of an American cybersecurity company participates in an authorized operation against computers physically located in Russia.
Six months later she travels to Thailand for vacation.
Russia has issued a warrant accusing her of violating Russian computer-crime laws.
Now she’s sitting in an airport detention room explaining that President Trump said it was okay.
TechCrunch reported cybersecurity veteran Jake Williams raising essentially this danger: Americans participating in these operations could face foreign criminal accusations or detention while traveling overseas.
And foreign governments don’t even have to tell the truth.
Once America publicly establishes that private American cybersecurity employees participate in offensive operations, adversaries gain plausible cover for accusing almost any American cybersecurity professional of participating.
Congratulations.
We may have just made American computer-security engineers geopolitical bargaining chips.
Then Follow the Money
And because this is America, eventually somebody is going to make money from all of this.
That may be entirely legitimate.
But creating an industry whose revenue depends upon conducting offensive cyber operations creates an incentive worth watching very carefully.
Companies will develop capabilities.
They’ll hire specialists.
They’ll build teams.
They’ll invest in tools.
They’ll acquire intelligence.
And eventually those companies will need customers.
The federal government will be the customer.
At that point we will have created something that should sound extremely familiar:
A private industry whose profitability depends partly upon the government’s willingness to authorize operations against foreign targets.
Maybe everything works perfectly.
Maybe oversight is magnificent.
Maybe nobody ever exaggerates a threat.
Maybe contractors never lobby for expanded authorities.
Maybe politicians never discover that looking “tough on cybercrime” wins votes.
Maybe corporations never discover that fear is good for business.
Maybe the revolving door between government and contractors never spins.
Maybe.
We’ve certainly never seen that movie before.
And Apparently a Million Dollars Makes Everything Okay
Participating companies must maintain at least a $1 million bond or escrow.
I almost admire the optimism.
A million dollars sounds impressive until you compare it with the potential damage caused by a serious cyber incident.
Accidentally disrupt a multinational company’s operations?
Million dollars.
Knock part of a telecommunications network offline?
Million dollars.
Cause financial-market disruption?
Million dollars.
Trigger an international confrontation?
Well, presumably the check clears.
The safeguard has the comforting feel of installing a smoke detector in a fireworks factory.
Yes, technically it’s better than not having one.
I’m just not convinced we’ve addressed the principal risk.
The Worst Outcome May Be Success
Here’s the part that worries me most.
Suppose I’m completely wrong.
Suppose the program works spectacularly.
American cyber contractors obliterate ransomware networks.
Fraud operations disappear.
Americans save billions of dollars.
The participating companies behave impeccably.
Nobody attacks an innocent server.
Nobody triggers an international incident.
Congress looks at the results and says:
MORE.
Expand the targets.
Expand the companies.
Expand the authorities.
Other countries notice.
They create their own programs.
Within ten years perhaps dozens of governments have licensed private organizations to conduct offensive cyber operations outside their borders.
Now we have created an entirely new international industry:
government-sanctioned private cyberwarfare.
And eventually somebody won’t be careful.
Somebody won’t have American safeguards.
Somebody will deliberately blur criminal and political targets.
Somebody will hire the equivalent of cyber mercenaries.
Some government will conveniently “lose control” of its private operators.
Another will maintain plausible deniability.
And every one of them will be able to point backward and say:
America helped normalize this.
That may ultimately be the greatest danger of Trump’s decision.
Not that an American contractor accidentally starts World War III next Tuesday.
Not that ransomware criminals don’t deserve to have their infrastructure destroyed.
Not even that the first operations will necessarily go badly.
It’s that successful policies become precedents.
And precedents become norms.
We Used to Understand This
America benefits enormously from a world governed by rules.
That isn’t idealism.
It’s self-interest.
The wealthiest trading nation, with enormous overseas interests and extraordinarily valuable infrastructure, benefits disproportionately when everyone agrees that certain things simply aren’t done.
Ships don’t attack merchant vessels because they feel like it.
Diplomats aren’t ordinarily arrested.
Borders matter.
Governments are responsible for their military forces.
And private corporations don’t get to conduct international warfare.
Those rules are imperfect.
Countries violate them.
Governments cheat.
But norms still matter.
Every time America tears down one of those fences because climbing over it would be convenient today, we should ask why somebody built the fence in the first place.
Maybe there was a reason.
Fight Cybercrime. Don’t Privatize Cyber Conflict.
None of this means America should sit helplessly while foreign criminals steal billions from its citizens.
Quite the opposite.
Hunt them.
Indict them.
Sanction them.
Seize their money.
Work with foreign governments.
Destroy their infrastructure when American law and international law permit it.
Use the FBI.
Use the intelligence community.
Use U.S. Cyber Command where appropriate.
Make America the most dangerous country on Earth for ransomware organizations to attack.
But if the United States government decides that an offensive cyber operation is important enough to penetrate and destroy computer systems in another country, then perhaps the United States government should have the courage to conduct that operation as the United States government and accept responsibility for it.
Don’t outsource sovereign power and pretend the subcontractor changes the nature of the act.
It doesn’t.
President Trump’s memorandum doesn’t simply create another cybersecurity program.
It crosses a boundary.
For the first time, the United States is explicitly establishing a framework in which vetted private companies can conduct offensive cyber operations abroad under federal authorization and supervision. Reuters describes the operations as potentially involving manipulation, disruption or destruction of information systems.
Perhaps the administration will implement it cautiously.
Perhaps the safeguards will work.
Perhaps it will destroy criminal networks and save Americans billions.
I sincerely hope so.
Because the alternative is that we have just rediscovered one of humanity’s oldest bad ideas:
Give private actors governmental authority to attack things beyond your borders and assume you’ll always be able to control what happens next.
We used to call them privateers.
Now they have laptops.
And if this becomes the international norm, America—with more wealth, infrastructure and digital dependency to attack than almost anyone else—may eventually discover something painfully obvious:
The rules we abandon when they inconvenience us are the same rules we desperately wish existed when someone else comes after us.
Leave a comment