{"id":8410,"date":"2025-11-13T05:05:23","date_gmt":"2025-11-13T05:05:23","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/11\/13\/on-hacking-back-html\/"},"modified":"2025-11-13T05:05:23","modified_gmt":"2025-11-13T05:05:23","slug":"on-hacking-back-html","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/11\/13\/on-hacking-back-html\/","title":{"rendered":"On Hacking Back"},"content":{"rendered":"\n<div>On Hacking Back<\/div>\n<p> \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>Former DoJ attorney John Carlin <a href=\"https:\/\/www.aspendigital.org\/blog\/so-you-want-to-hack-back\/\">writes<\/a> about hackback, which he defines thus: \u201cA hack back is a type of cyber response that incorporates a counterattack designed to proactively engage with, disable, or collect evidence about an attacker. Although hack backs can take on various forms, they are\u2014\u00adby definition\u00ad\u2014not passive defensive measures.\u201d<\/p>\n<p>His conclusion:<\/p>\n<blockquote>\n<p>As the law currently stands, specific forms of purely defense measures are authorized so long as they affect only the victim\u2019s system or data.<\/p>\n<p>At the other end of the spectrum, offensive measures that involve accessing or otherwise causing damage or loss to the hacker\u2019s systems are likely prohibited, absent government oversight or authorization. And even then parties should proceed with caution in light of the heightened risks of misattribution, collateral damage, and retaliation.<\/p>\n<p>As for the broad range of other hack back tactics that fall in the middle of active defense and offensive measures, private parties should continue to engage in these tactics only with government oversight or authorization. These measures exist within a legal gray area and would likely benefit from amendments to the CFAA and CISA that clarify and carve out the parameters of authorization for specific self-defense measures. But in the absence of amendments or clarification on the scope of those laws, private actors can seek governmental authorization through an array of channels, whether they be partnering with law enforcement or seeking authorization to engage in more offensive tactics from the courts in connection with private litigation.<\/p>\n<\/blockquote>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Bruce Schneier<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/www.schneier.com\/blog\/archives\/2025\/11\/on-hacking-back.html\">Go to bruce schneier<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>On Hacking Back Former DoJ attorney John Carlin writes about hackback, which he defines thus: \u201cA hack back is a type of cyber response that incorporates a counterattack designed to proactively engage with, disable, or collect evidence about an attacker. Although hack backs can take on various forms, they are\u2014\u00adby definition\u00ad\u2014not passive defensive measures.\u201d His [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[57,2029,624,1],"tags":[87],"class_list":["post-8410","post","type-post","status-publish","format-standard","hentry","category-bruce-schneier","category-hackback","category-laws","category-uncategorized","tag-bruce-schneier"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/8410"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=8410"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/8410\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=8410"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=8410"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=8410"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}