Story image

Expert says Germany’s ‘hack back’ proposal is a slippery slope

09 Oct 2017

Late last week German intelligence officials urged lawmakers to grant them more legal authority to ‘hack back’ in the event of international cyberattacks.

This comes in the wake of various attacks, including the May 2015 hacking of the German lower house of parliament, the Bundestag, which German officials blamed on APT28, a Russian hacker group that is said to have ties to Moscow.

Head of the BfV domestic intelligence agency, Hans-Georg Massen proclaimed to the parliamentary oversight committee that they should be legally equipped to destroy data that is stolen from German servers and moved to foreign servers – thus preventing cybercriminals and foreign powers from misusing it.

In a similar way to which human agents are used for counter-espionage, Massen argued it would be logical to ‘infect’ foreign servers with software that would then provide for improved visibility and surveillance of any malicious operations targeted against German cyber targets.

“In the real world, it would be like turning a foreign intelligence agent and getting them to work for us ... Something like this should be possible in the cyber world too,” Maassen told the committee in its first public hearing.

“These are ‘hack back’ instruments, but they are below the threshold of destroying or incapacitating a foreign server,” Maassen said.

CEO of web security company High-Tech Bridge, Ilia Kolochenko says while at first glance a hack back concept sounds fair and reasonable, he believes it may be a slippery slope as in the digital world the counterattack principle may be very different from its common notion.

“On the Dark Web, one can easily purchase access to hacked systems of governments, law enforcement agencies and police. Cybercriminals and nation-state actors may just buy compromised systems of their rivals andup them,” says Kolochenko.

“Afterwards, genuine attackers will use an alleged breach as an excuse for well-prepared attacks on their victims. Legal questions intertwined with the hack back are much less complicated compared to practical problems we may face.”

Kolochenko asserts the solution needs to be approached with care.

“Therefore, we should rigorously conceptualise and analyse the hack back principle with the game theory in mind. Otherwise, we will unavoidably create a parade of horrors detrimental for all civilized states."

Germany’s BND chief, Bruno Kahl told the committee that its foreign intelligence agency already has the expertise to destroy foreign servers, but lacks the legal authority.

However, Kahl says at the end of the day, such decisions have to be made by politicians.

Secureworks Magic Quadrant Leader for Security Services
This is the 11th time Secureworks has been positioned as a Leader in the Gartner Magic Quadrant for Managed Security Services, Worldwide.
Google puts Huawei on the Android naughty list
Google has apparently suspended Huawei’s licence to use the full Android platform, according to media reports.
Using data science to improve threat prevention
With a large amount of good quality data and strong algorithms, companies can develop highly effective protective measures.
General staff don’t get tech jargon - expert says time to ditch it
There's a serious gap between IT pros and general staff, and this expert says it's on the people in IT to bridge it.
ZombieLoad: Another batch of flaws affect Intel chips
“This flaw can be weaponised in highly targeted attacks that would normally require system-wide privileges or a complete subversion of the operating system."
Forget endpoints—it’s time to secure people instead
Security used to be much simpler: employees would log in to their PC at the beginning of the working day and log off at the end. That PC wasn’t going anywhere, as it was way too heavy to lug around.
DimData: Fear finally setting in amongst vulnerable orgs
New data ranking the ‘cybermaturity’ of organisations reveals the most commonly targeted sectors are also the most prepared to deal with the ever-evolving threat landscape.
ExtraHop’s new partner program for enterprise security
New accreditations and partner portal enable channel partners to fast-track their expertise and build their security businesses.