
Expanding Capabilities to Combat Transnational Cyber-Enabled Crime
On one hand, what a niche issue that is unlikely to be noticed by almost anyone outside of a small sliver of a specific industry.
On the other hand... Cyber Pirates.
In short this directs DHS and DOJ to create a framework for private companies to hack and disrupt foreign hacker groups. Based on my reading the primary source of income for these appears to be sort of "protection" contracts with companies, local, or federal government where the pirates do hack-backs to respond to incidents.
Interestingly, it excludes attacking foreign government agencies, but I wonder where we'll draw the line. We know Russia/China/Iran/N Korea have extensive hacking groups, but they do not actually claim credit. There's some reason to believe those governments even do financially motivated cyber crime. I wonder if we will take an approach of "well if Russia/China/Iran/N Korea says it isn't them, then it is fair game" or if it will be more like "well we all know it was actually China, so you can't go there"
Do you think this is a good idea? Do you think it will be something future administrations continue? Do you think it will actually make a difference in the number of cyber attacks targeting US infrastructure?