Private sector warms to U.S. Cyber Command carrying out ‘hack backs’

The U.S. government should decide how to retaliate against the worst attacks on the country’s private sector, and when appropriate, the military’s hacking unit should hit back, three experts said Monday. The controversial idea entails taking the fight to nefarious actors by attacking their computer network in-kind, probing for exfiltrated data and employing measures to retrieve or destroy stolen information. The three individuals, with experience in the private sector, intelligence community and military, spoke at a panel organized by APCO. They concurred that if companies feel compelled to hack back, they should delegate any potential response to the government. If retaliation is warranted, U.S. Cyber Command should carry it out. “I think if it’s going to happen, it’s best in the hands of the government,” said Sean Weppner, chief strategy officer at NISOS Group and a former DOD cyber officer. No company has the intelligence, offensive tools and contextual understanding of the […]

The post Private sector warms to U.S. Cyber Command carrying out ‘hack backs’ appeared first on Cyberscoop.

Continue reading Private sector warms to U.S. Cyber Command carrying out ‘hack backs’

Hacked Password Service Leakbase Goes Dark

Leakbase, a Web site that indexed and sold access to billions of usernames and passwords stolen in some of the world largest data breaches, has closed up shop. A source close to the matter says the service was taken down in a law enforcement sting that may be tied to the Dutch police raid of the Hansa dark web market earlier this year. Continue reading Hacked Password Service Leakbase Goes Dark

How DJI fumbled its bug bounty program and created a PR nightmare

A software vulnerability disclosure program recently launched by popular drone maker DJI has turned into a messy public relations battle pitting several security researchers against the growing Chinese technology firm. After DJI recently launched a bug bounty program, two researchers — Sean Malia and Kevin Finisterre — publicly disclosed vulnerabilities in DJI products. The revelations resulted in the company challenging each researcher’s findings and seemingly threatening one with a lawsuit tied to the Computer Fraud and Abuse Act. For researchers who have been poking and prodding DJI’s digital properties and products for about three months, Malia and Finisterre stories strike a familiar tone. Several researchers who approached DJI with information about evident vulnerabilities say the outcome has been less than satisfactory. DJI disputes aspects of some of these accounts, but experts say the firm has gone too far. “Many companies mistake a bug bounty program for a penetration test, in which the […]

The post How DJI fumbled its bug bounty program and created a PR nightmare appeared first on Cyberscoop.

Continue reading How DJI fumbled its bug bounty program and created a PR nightmare

Rep. Graves: ‘Active defense’ bill will launch a new industry

One of the authors of a controversial “hack back” bill in Congress believes the legislation can launch a new industry around “active defense” that allows companies to strike back against hackers who steal data. Rep. Tom Graves, R-Ga., predicts the private sector will develop new tools that will add a new layer of deterrence. Graves, who strenuously objects to the “hack back” terminology for the bill, spoke with CyberScoop earlier this month about the legislation. “You currently have a 1.5 percent conviction rate in cyberattacks,” Graves said. “I think you’ll see that rate go up because attribution will go up, but also because I think you’ll see the number of attacks reduced. And then you’ll see information sharing occurring prior to successful attacks, which will protect additional systems and networks as information being shared about attacks taking place or attempted attacks and the process they’re going about.” Graves and Rep. Kyrsten Sinema, D-Ariz., […]

The post Rep. Graves: ‘Active defense’ bill will launch a new industry appeared first on Cyberscoop.

Continue reading Rep. Graves: ‘Active defense’ bill will launch a new industry