❌

Normal view

There are new articles available, click to refresh the page.
Before yesterdayMain stream

A bold new strategy or a dangerous precedent? Experts are divided on Trump’s memo.

13 August 2026 at 18:19

A newly-signed presidential memorandum enlisting private sector companies in federal law enforcement hacking operations against criminal organizations could present a number of legal, practical and moral pitfalls, cyber experts told CyberScoop a day after the order was released.

While some have celebrated the memo as an overdue maneuver to more aggressively combat cybercriminals, others view it as risky at best and potentially destructive at worst. Supporters, critics and everyone in between also said that how it plays out could be decided in the 60-day timeframe the memo sets to establish the program.

But ultimately, “it’s a massive shift in the cyber policy community,” said Michael Garcia, a former top official at the Cybersecurity and Infrastructure Agency. “This is a philosophical shift.”

The Concerns

On the most critical end of the spectrum is security consultant Davi Ottenheimer, who has been a proponent of concepts like “hack back” or “active defense” that envision a bigger role for the private sector. But he was unsparing in his criticism of the Trump memo. 

“It’s an embarrassment to America,” he told CyberScoop. “It’s like seeing somebody strapped onto a horse backwards, looking at the wrong end of a rifle.”

The Trump memo’s approach has been likened to the “letters of marque” concept used in early U.S. history, when it authorized sea privateers to attack and capture enemy ships and goods on behalf of the country. But Ottenheimer, founder of Ottenheimer GmbH, noted that the practice fell out of favor for good reason in the 1800s because of the violence it unleashed and how it contributed to mercenarism.

Additionally, the memo raises a number of targeting-related issues, he said. Ottenheimer is concerned about Trump’s intentions. The memo specifically pertains to the use of participating companies against transnational criminal organizations.

“Left-wing opposition, liberals, anti-fascists —they’re all criminals to him,” Ottenheimer said. “So to authorize attacking criminals under this means private organizations can go hack people that he designates as criminals.”

Under the memo, the program must establish legal and constitutional procedures for the prior approval of the targeting of U.S. citizens, as well as develop procedures to halt any unintentional targeting of U.S. people or systems. 

However, the limitation on targeting criminals only creates a perverse incentive for attackers and a peculiar defense for anyone who’s attacked, Ottenheimer said.

He envisioned a scenario for a company participating in the program where “you’re hacking [a target], and they go, ‘Hey, we’re the state.’ And then [private companies] are like, ‘Oh, I can’t hack you anymore.’ Boom. They decided when you can and can’t hack.”

Furthermore, “you incentivize people to know as little as possible so [operations] can be authorized,” he said.

The memo raises ethical concerns for him as well: “You can’t attack somebody and then say it’s your fault that you didn’t notify them you didn’t want to be attacked.”

“There’s no notice for you being designated. There’s no prevention of you being designated. There’s no way for you to know you’re being designated,” Ottenheimer said. “That’s like a person sitting down next to you and smoking a cigarette and blowing smoke in your face and saying, ‘Hey, you got to say you don’t like cancer if you don’t want me to do this to you right now.’”

Garcia, now vice president of the cybersecurity practice at Monument Advocacy, said he supports some of the ideas of the memo, but worries about how it will be executed.

“It comes down to attribution, and if you make a risky bet on who we’re attributing [attacks] to, that’s where things can get dicey,” Garcia told CyberScoop.

There could be pressure to attribute faster, which could perhaps lead to lower certainty about who’s being targeted, and that in turn could lead to a private sector company accidentally attacking a foreign government, he said.

That raises legal questions: “It’s in the Constitution —the federal government has the ability to wage war. And there are laws by which private citizens can’t take up arms,” Garcia said.

He wanted the memo to include court oversight of the program, similar to what’s been required for private sector takedown operations. .

Garcia also isn’t sure whether there will be a big enough pool of companies willing to jump into offensive cyber operations.

“From the lawyer perspective, it’s, ‘Are you okay with engaging in this kind of legal risk? And who knows what protections the government will provide?’” he said. “I’d be very curious to see what the foreign governments’ reactions are — ‘We’re going to cut ties with any participating company that engages in this.’”

Errata Security CEO Robert Graham wrote that under the program, companies “are not willy-nilly hacking back,” given the federal supervision elements. “Though, I wonder if it doesn’t eventually morph into law enforcement saying ‘Stop bothering us, just do what you think is best.’’” 

The Case For

The Trump administration and the memo’s supporters  have touted it as a means to put the United States on stronger ground in cyberspace. 

Amanda Naylor, the director of cyber policy at the National Security Council who worked on the memo, said on LinkedIn that it was designed “to bring the capabilities, speed, and innovation of the American private sector into the fight against transnational cybercrime and fraud.”

Former Trump White House cybersecurity official Joshua Steinman said he views the memo as a step toward “parity,” given how U.S. adversaries operate in cyberspace.

“The Chinese and the Russians do this at scale, and I guarantee you they have very few limiting tools when they do it,” said Steinman, now founder of the security firm Gavalnick. “It opens up an entire workforce that allows us to go out and achieve strategic objectives.”

The restrictions in the memo are important, he told CyberScoop.

“The most sensitive things are going to continue to be done by the uniformed and authorized civilian workforces, but there’s a lot of low-hanging fruit,” i.e., criminal organizations, Steinman said. He doesn’t have any fear of the program overstepping as a result.

“We operate like a Boy Scout in cyberspace,” he said. “It’s measured and reasoned.” He compared it to the Right to Try Act for medications.

He also said he expects to see a lot of interest in participating in the private sector.

Ari Redbord, global head of policy at TRM Labs, praised the memo too, calling it “a huge step toward empowering the private sector at a critical moment” that “has a real opportunity to be truly transformative.”

“Scammers are using AI to move with unprecedented speed and scale, stealing billions in life savings from average Americans and small businesses,” he said. “The private sector holds the data. The public sector holds the authorities. This [memo] puts them together.”

What’s Next

The coordination center charged with establishing the program under the memo has 60 days to complete its work. That process could determine a lot. Graham noted that the memo has a classified annex, too.

The memo as written is quiet about what becomes of any seized assets, Graham noted. Redbord raised the same topic as one of his questions about execution of the memo. 

“What government direction and control looks like in the middle of a live operation,” he said in listing his questions. “How disruption turns into actual dollars back in victims’ pockets, and whether we can build a true victim compensation fund as part of this program. What happens when an operation touches a third country with its own laws and its own interests. And how success gets measured, in money recovered and networks dismantled.”

Will Barker, cybersecurity adviser at Huntress, said what’s next could be key.

“The 60-day implementing guidance is where the real substance lives,” he said in a written quote. “Minimum standards, operational procedures, the adjudicatory framework for target selection.”

The post A bold new strategy or a dangerous precedent? Experts are divided on Trump’s memo. appeared first on CyberScoop.

Trump turns to private sector in offensive hacking operations memo

By: Greg Otto
13 August 2026 at 07:47

President Donald Trump signed a national security memorandum Wednesday that lays the groundwork for private sector companies to take a larger role in helping law enforcement carry out offensive hacking operations against transnational criminal organizations.

The White House said sustained fraud and other cyber-enabled campaigns from transnational criminal organizations (TCOs) warranted the memo, and cited a fraud-focused executive order from March as only the first step.

”This memorandum expands the fight against TCO-perpetrated cybercrime by incorporating the ingenuity of the private sector,” it reads.

Under the memorandum, a federal coordination center “shall create, manage, and maintain a Program to authorize Participating Companies … to conduct Cyber Surveillance Operations and Cyber Effects Operations against foreign Cyber-Enabled Transnational Criminal Organizations (CE-TCOs), under the control and oversight of the Federal Government“ that would be “part of lawful investigatory, protective, or intelligence operations carried out by Federal law enforcement.”

Participating companies would have to sign contracts with the Justice Department or Department of Homeland Security to “undergo rigorous vetting.” It would also allow participating companies to sign commercial agreements with other private sector entities to receive threat information. And participating companies’ agreements with federal, state and local governments would be geared toward identifying threats, and proposing cyber operations to the coordination center to address those threats.

The program would have to adhere to existing laws, according to the memo. That includes the Computer Fraud and Abuse Act, the main federal anti-hacking statute that prior proposals to open private sector participation in hacking operations would have amended. The memo mandates oversight to evaluate companies’ technical proficiency, ensures both small and large companies can participate, and requires regular reporting to federal officials.

In recent years, there has been some sentiment in conservative circles to authorize “letters of marque” for private-sector cyber firms similar to those for early-U.S. sea privateers. Some have suggested the government could lean on more private sector cyber experts to conduct offensive operations.

But there also has been deep concern in cyber circles about giving the private sector too much leeway in offensive operations, from industry condemnation of “hack back” legislative proposals that would authorize steps that are currently illegal as a dangerous precedent that critics fear could open cyberspace to wider chaos.

One former Cyber Command official, Jason Kitka, criticized several elements of the memorandum, calling it “a perpetual motion machine for billable threats” in a social media post.

But a former top White House cyber official during Trump’s first term, Galvanick co-founder Josh Steinman, cheered the development. 

Cyber pioneer Chris Wysopal, now co-founder of Veracode, called it “a pretty big shift in US cyber policy” that nonetheless stopped short of going as far as other “hack back” proposals.

The post Trump turns to private sector in offensive hacking operations memo appeared first on CyberScoop.

Supply chain challenges loom large in quantum race, White House official says

29 July 2026 at 16:22

One of the most difficult obstacles to overcome in the quantum race will be the supply chain, given how diffuse it is, a top White House official said Wednesday.

“Supply chain is one of the biggest challenges in my mind, and really, the challenge with the quantum supply chain is that quantum is not defined by a single hardware platform,” said Brad Blakestad, director of the National Quantum Coordination Office within the White House Office of Science and Technology Policy.

“If you look at the quantum computing technologies, the quantum sensing technologies, the networking — those are all different,” he said in a webinar hosted by Inside Cybersecurity and USTelecom. “And even within computing, there’s seven different modalities that use completely different components. So we have this not just one monolithic supply chain, but just a bunch of different supply chains that are kind of intertwined in various ways.”

Blakestad made his remarks a little more than a month after President Donald Trump signed two executive orders on quantum computing. He referenced proposed ways to address the supply chain challenge in one of the orders.

“The other major issue or challenge that we face right now is that we’re on the cusp of quantum exploding from a commercialization perspective, but we’re not quite there yet,” he said. “So there’s not the funding, the revenue coming from large-scale quantum companies at this point to really make the supply chain as robust as you would want. So thinking about it from the government perspective, it’s just [that] there are too many places that I would want to bolster and not enough funding to do it.”

Blakestad touted steps to help that along such as the government buying widgets from a company that makes them to certain specifications, or prize challenges.

The quantum supply chain isn’t just diffuse in the United States, an International Institute for Strategic Studies policy paper noted Wednesday. It’s “inherently international: no single country dominates the supply chain, whether specialised materials, cryogenic equipment, hardware, software, fabrication or algorithms,” the authors, Dongyoun Cho and Maria Shagina, wrote.

And a March report from the Center for a New American Security identified strengthening the quantum supply chain as pivotal to the United States seizing the benefits of the technology, citing gaps in the U.S. supply chain and reliance on foreign suppliers such as China and Russia. 

Supply chain wasn’t the only obstacle Blakestad mentioned as looming large.

“The encryption challenge is a real challenge, and we want to make sure that we are aware of when quantum computers will ultimately get to a scale that they start having these sorts of implications and move as quickly as we can,” he said. “So, just by owning the technologies, by owning the workforce, by making the United States the place that people want to come to be on the cutting edge of this technology, I think that kind of addresses both of those issues, and that’s what makes it so critical.”

Another difficulty is measuring progress, Blakestad said: “It’s also very, very hard to benchmark, and to know that you’re actually doing what you’re supposed to, what you are intending to do.”

The post Supply chain challenges loom large in quantum race, White House official says appeared first on CyberScoop.

❌
❌