
When companies can hack back.
Dave Bittner: Hello, everyone, and welcome to "Caveat," N2K CyberWire's privacy, surveillance, law, and policy podcast. I'm Dave Bittner, and joining me is my co-host, Ben Yelin from the University of Maryland Center for Cyber, Health, and Hazard Strategies. Hey, there, Ben.
Ben Yelin: Hello, Dave.
Dave Bittner: On today's show, Ben discusses the new White House executive order on hacking back. I've got consideration over the notion of AI constitutions. While this show covers legal topics, and Ben is a lawyer, the views expressed do not constitute legal advice. For official legal advice on any of the topics we cover, please contact your attorney. [ Music ] All right. Ben, we've got a lot to cover here this week. First of all, it's good to be back.
Ben Yelin: Great to have you, Dave. You guys let the kids run the asylum while you were gone, but we're glad to have you back and hope you enjoyed your travels.
Dave Bittner: I did, and I very much appreciate you and Ethan stepping up while I was away, so thank you very much. All right. Let's dig into some stories here. What do you got for us, Ben?
Ben Yelin: This one is really an important story. I am taking it from an NPR article. This is about the Trump administration enacting an executive order allowing private companies to hack foreign criminals, to "hack back," if you will. This is a new initiative. It would allow private U.S. companies, who come to some sort of an agreement with federal agencies, to conduct government-authorized cyber operations against foreign criminal groups involved in cybercrime. The foreign criminal groups' part is kind of critical because we don't want to be hacking nation states, having private companies hack nation states, because that could cause all types of diplomatic problems.
Dave Bittner: Yeah.
Ben Yelin: Oftentimes, there's a gray area, right? There could be a foreign criminal organization that has some ties to the state. Usually, it's in an adversarial state, like Russia or China. So that really, kind of, blurs the line here, but this executive order is a memorandum. It directs the government to create this program where it can authorize vetted private companies -- so you have to go through kind of an application process -- to pursue foreign cybercriminal organizations. You're doing it on behalf of the U.S. government. Generally, of course, it's better for legal purposes for the government to do this themselves, but the government's capacity is limited, and I think the administration wants to leverage the expertise of the private sector to go after our cybercriminal enemies. There are a couple of interesting complications here. For one, we have anti-hacking laws in this country, most notably, the Computer Fraud and Abuse Act. That generally prohibits us from having private actors conduct offensive cyber operations. The memo doesn't disclaim any federal statute. It just, basically, says that you are operating as a private company at the behest of the federal government because you're essentially, like, a federal contractor, which I think is -- I don't know. I'd love your viewpoint on this, but I don't know if that's entirely a correct way of characterizing it because, yes, you're being supervised by the government, but you are bringing your own expertise and your own strategies, right? Certainly, there is government oversight, but it's certainly a private action in any way that you could possibly understand the term. One of the rationales for this that was, kind of, whispered about by administration officials is this idea of cyber-privateers.
Dave Bittner: There's a mark, yar!
Ben Yelin: Yeah. [ Laughter ] So, yeah, I mean, this goes back into naval history that I'm certainly not an expert -- but the situation was eerily, kind of, similar. Like, you have private actors who are out on the waters, right, and they were authorized to attack enemy targets on behalf of the state. This is sort of like that, except you have to have -- you don't have any independent authority as a private company to hack back. You have to be in some sort of official agreement with the federal government. A lot of details are unclear here -- how extensive the capabilities are going to be -- but I think it's, especially for smaller firms, it could be a great business opportunity. Get buy-in from the government and secure government work. Maybe you can leverage that to get future government contracts, raise your profile, and be a cyber-privateer on behalf of the United States of America. This is really something that's novel and interesting, and I'm very curious to see how this is received and how it's carried out.
Dave Bittner: How do you suppose something like this could work? I mean, would this be a situation where the government would say to the organizations that have been vetted here, contracted with, I suppose, say, hey, we have a target here. We want you to do X, Y, and Z, and then off they go?
Ben Yelin: It's sort of like that. Basically, they envision, kind of, two different types of activity on the part of the private company. There are cyber-surveillance operations and then cyber-effects operations. Surveillance is just getting yourself onto these adversarial foreign networks and passing along intelligence information, and then the cyber-effects would be trying to, like, actually damage their infrastructure. Both of those are permitted under this executive order, as long as it's sanctioned by the supervising government agency. So, you know, it's -- there aren't inherent limitations in the executive order that say this is only going to be used for cyber-surveillance and not for operations. A faithful read of this, if you take it literally, is that you could use this to damage the networks and online infrastructure of cyber-enabled transnational criminal organizations, which is a very significant power.
Dave Bittner: So privatizing something like Stuxnet?
Ben Yelin: Exactly. I mean, that's essentially what this is doing. What the administration would argue is that in all different types of contexts in our legal system, when private companies act on behalf of the federal government and under its supervision, then their actions are essentially the actions of law enforcement. That matters for something like the Computer Fraud and Abuse Act because that's a general anti-hacking statute, but it has an exception for legitimate law enforcement or government-authorized exceptions. In the administration's mind, because these private companies are going to be working at the behest of the administration, this would count as a government-authorized exception. There's a really interesting piece on The Reason blog by a friend of the pod, Professor Orin Kerr -- second straight mention of him on the podcast. He brings up a lot of potential questions that come up as a result of this program and its interplay with the Computer Fraud and Abuse Act, such as whether this level of supervision is sufficient to take private actors outside the prohibitions of the CFAA; whether contractors can legally perform cyber operations that would otherwise be criminal if conducted independently; is the administration advancing such a novel interpretation of federal law that it hasn't been interpreted by the courts? That might cause some private companies to be like, yeah, I don't know if we should get involved in this.
Dave Bittner: Right.
Ben Yelin: The administration is telling us it's legal, but that's a theory that's untested. You know, I don't think even Professor Kerr, who's skeptical, I don't think he thinks that this is clearly illegal, but this brings up really difficult and unexplored questions, and we kind of have to figure out where the boundaries are.
Dave Bittner: Yeah, so suppose that I'm the CEO of -- I don't know -- Palo Alto Networks or Accenture or some of these organizations who are the usual suspects when it comes to contracting with the federal government.
Ben Yelin: First, can I have some of your money if we're doing that role playing?
Dave Bittner: Exactly. If I'm the CEO of one of those companies, could this put me in a position where, potentially, I would have to worry about where I travel? In the same way that the U.S. scoops up foreign hackers when they vacation to places that have extradition agreements with the U.S., if I'm a private citizen taking part in these sorts of things, would that be something that would need to be on my radar, the international fallout of something like this?
Ben Yelin: It would certainly be on my radar. I don't know exactly where the risk vectors are. If you're in a country within the European Union, I would not anticipate it being a problem, but I also -- we just don't know the full details of how this program is going to work in practice.
Dave Bittner: Do we expect we ever will?
Ben Yelin: No, absolutely not.
Dave Bittner: Okay. [Laughter]
Ben Yelin: I mean, that would kind of defeat the purpose of the program, if it was, like, "Here are our 10 cyber-criminal adversaries, and we are going to attack them at 0100 hours on August" whatever. It certainly exposes private actors to that type of international apprehension. I would not travel to any countries where we know there are cyber-criminal organizations acting against us if I was in that position. If I were in Russia and/or China and I had participated in one of these agreements, I'd be pretty concerned about it. I'd probably want to use encrypted communications. When I was -- end-to-end encrypted communications when I was speaking with government agents. Make sure the room at whatever government facility these meetings are held at doesn't have any hidden listening devices.
Dave Bittner: All your standard espionage stuff.
Ben Yelin: Exactly, but you can see why a company would want to be involved in this.
Dave Bittner: Right.
Ben Yelin: It's -- for one, there is an element of patriotism in it. I mean, you are helping the government go after people who are trying to bring down our critical infrastructure.
Dave Bittner: Yeah, absolutely.
Ben Yelin: We've seen all of these attacks against water systems recently. That's really bad, so to the extent that we want somebody fighting back, I can understand the patriotic impulse behind it, and it's a great business opportunity. If you succeed in partnership with the government, then you're definitely going to move to the front of the line on all of these federal contract opportunities.
Dave Bittner: I wonder how the folks at Cyber Command, you know, or those types of organizations, part of the NSA, you know, the people in the government who are tasked with these sorts of things -- I wonder how they feel about this. Do they feel like this is great? We're going to have more help. We're going to be able to do more, or do they feel, like, hey, we've had this? Why are we going after the private sector instead of funding our operations inside the government itself?
Ben Yelin: Yeah, there's certainly a lot to be said for something like that, especially because if you work for Cyber Command. You've been vetted. You've gone through the most rigorous security clearance process. I would assume they're going to do the same thing when it comes to these agreements with private firms, but yeah, I mean, I'd certainly have some of those concerns. I think it's a recognition that these agencies might be understaffed, and that even if they're doing an excellent job fulfilling their mission, we can always add more expertise, more speed, more innovation when it comes to hacking foreign cybercriminal networks. I mean, basically, we've seen how effective the private sector can be getting ahead of the government when it comes to all things cyber, and so you want to, kind of, grab that entrepreneurial spirit and use it to our advantage. I'm sure it's not going to make people who are part of U.S. Cyber Command feel great, but they probably at least appreciate having this level of support if it's done well and if it complements their efforts and doesn't interfere with their efforts.
Dave Bittner: Why announce this at all? If this is work that is going to be behind-the-scenes, presumably classified, why is it advantageous for the Trump administration to publicly make this statement?
Ben Yelin: That's a really interesting question. I mean, I think there is enough left out of this presidential memorandum that it's not giving away any operational information. In that sense, it's putting our adversaries on notice that, like, hey, you've seen all that American innovation, right? You've seen what OpenAI has done. You've seen what Anthropic has done. We're going to put that to use against our enemies and these cybercriminal international organizations. We're not going to tell you how we're going to do it. We're not going to tell you the extent of it, but this is something that we can and will do. If you're sitting there as one of our adversaries and think, "I can defeat the bureaucrats within the U.S. government," you might think twice about hacking us, knowing that we have this privateer army waiting in the wings to attack your networks. I, obviously, have no inside information on this, but that would be my instinct as to why they'd want to announce something like this. It's a way of warning our enemies that what they see as potential U.S. responses to cyber incidents doesn't capture the full universe of what we're capable of as a country.
Dave Bittner: Is there any legal peril here for the administration, for the companies who would participate in this? Say we got a new administration in a few years, you know? Might they take a different view of this?
Ben Yelin: Well, I'll say a couple of things about that. For one, I think there are going to be a lot of blanket pardons at the end of this administration. I also think if a company is acting in good faith in what they see as a presidential memorandum, an executive order that's been duly authorized, and they are complying with all the regulations set forth in that memorandum, I think any court would be reluctant to hold these companies accountable. But then again, if they're in violation of the Computer Fraud and Abuse Act, even if they're not criminally charged, if they commit some type of tort or legal wrong against a U.S. party or an international party, then they can be sued under the Computer Fraud and Abuse Act in a civil action. That could have major consequences.
Dave Bittner: It reminds me of, you know, we've seen these stories about the major AI models that have broken out of their sandboxes and hacked other companies. You know, I saw someone writing about that saying, oh, it was so nice of these companies to lay out all of the crimes that they've committed, right, as part of the Computer Fraud and Abuse Act -- to illustrate and step-by-step take us through the crimes that they've committed, which of course is, you know, some snark in there, but I think to your point that most -- I guess, law enforcement at this point of enthusiasm about AI would say, this is what you get being on the bleeding edge. No crimes were intended to be committed here, so we're just going to hang back and not pursue anything.
Ben Yelin: Right. I mean, there have been a lot of cases stemming from the Bush era where, like, private contractors were being sued, sometimes by foreign entities. There are levels of immunity that you can get by saying that you were complying with a good-faith interpretation of a government directive. That's not always going to get you out of -- not literally -- out of jail. That's not always going to be your get-out-of-jail-free card, but it certainly would help. Then the broader issue here is -- you know, is hacking back -- you know, this gets beyond the purview of the legal issues and even this podcast. Like, is hacking back, itself, the most effective strategy for countering some of these large-scale attacks? I mean, I think there's a view out there that you can't really offense your way to cybersecurity. There are always going to be additional threat actors, and sometimes when you hack back, and it affects another nation state, especially if it affects their critical infrastructure, you're just creating a new generation of enemies, so it's not really solving the problem. That, I think, depends on your perspective about cyber warfare and, frankly, warfare in general, but it's important enough of an issue that I think it's worth bringing up here.
Dave Bittner: It's illegal to booby-trap your property, right?
Ben Yelin: Oh, great question.
Dave Bittner: No, it is.
Ben Yelin: I mean, it is illegal to booby trap your property.
Dave Bittner: My understanding is that it is. You know -- yeah, yeah. It's not completely dissimilar to what we're talking about here.
Ben Yelin: Exactly. Yeah, you can't set up a secret cage that falls on a trespasser when they cross over --
Dave Bittner: Right, a pit full of spikes that they fall into, you know?
Ben Yelin: So let's just say, Kevin in Home Alone, you are extremely vulnerable to civil and criminal penalties.
Dave Bittner: Right, that's right. All right. Well, interesting stuff. We will have a link to that story in our show notes. Let's take a quick break here to hear from our show sponsors. We will be right back after these messages. [ Music ] All right. We are back, and Ben, once again, I am leaning on the good folks over at Lawfare who wrote up a pretty interesting article. This was an area that I had not read about or really considered, and that's this notion of AI constitutions. Has this been on your radar at all?
Ben Yelin: It has been recently. It's something that a lot of the big companies have started to put out as, kind of, a statement of principles --
Dave Bittner: Yeah.
Ben Yelin: -- which is good. They're not always complying by their own guardrails, but I think as a good-faith effort to set the boundaries around these frontier models, I do think it's promising. The issue raised in this article is fascinating to me.
Dave Bittner: Yeah, so just sort of a quick review. As you said, Ben, these are documents that are supposed to define the values and behaviors that these AI models should follow. They also directly influence how the models are trained and how they behave, so what the companies put into their models and what they expect to get out of them. You know, governments are showing increased interest in these sorts of things, and so will lawmakers take notice and try to regulate how the AI models behave -- what they can and cannot do and the types of things that they're allowed to be trained on? But as this article points out, it veers into issues of protected speech, protected corporate speech, so help me understand what that means, Ben.
Ben Yelin: Yeah, so the Supreme Court looks very disfavorably upon compelled speech, where you are forcing a person or an entity to say something that they otherwise would not say. That runs counter to the values of our First Amendment, which protects the freedom of speech. The idea here is that if we are setting forth such specific regulations that we are compelling these companies to put government-sanctioned language in their constitution, that runs afoul of First Amendment jurisprudence. I completely agree with that. I think constitutions are expressions of values, and that's something that the government really can't and shouldn't get involved with at all. I think the government can regulate these AI models in a variety of ways. You can set up safety guardrails. Certainly, there have been federal proposals to do so. We haven't seen a comprehensive AI safety statute enacted, and states have tried to put in various guardrails as well. I think you should be attacking the actions of these models. You should be outlining the things that would lead to legal liability, you know, whether we're using a negligence theory of the case or a product liability theory of the case. When it comes to these AI constitution documents, I mean, I think that would be the wrong place to target regulation. I think let them elucidate their principles. They can have whatever principles they want. They just have to abide by the laws, as duly enacted by our representatives.
Dave Bittner: So is the broad notion here that any AI constitution should not run afoul of the Constitution of the United States?
Ben Yelin: I don't think that's necessarily true either. I mean, these constitutions are not binding documents. So let's say -- I'll give you an example.
Dave Bittner: Yeah.
Ben Yelin: Let's say one of the AI companies said, like, our AI constitution prioritizes innovation at all costs. We are willing to sacrifice the safety of a certain number of Americans to achieve algorithmic supremacy over our geopolitical foes. I would disagree with that as a principle, but, like, that is a perfectly legitimate principle to elucidate. For Congress to try and regulate an AI company's Statement of Values through its constitution in any way, or, like, hold that such constitution is null and void as a result of a government intervention, that's a major affront to the First Amendment.
Dave Bittner: Right.
Ben Yelin: What you could be preventing are actions that the company takes in pursuit of those values, so if they aren't putting proper safeguards, if they aren't complying with government regulations, if they're putting consumers at risk in a way that the FTC determines to be against the spirit of our federal regulations, then you can go after them for those actions. But you're not -- the constitutions themselves are just statements of values. I think even if you find the ethics of these companies to be wanting, they still have a right, as private entities, to have these ethics. Companies can have any ethics. I mean, you could have a mission statement from a company that's so wholly offensive, the idea of our free market would be that we would not purchase such a product. Now, that's not really applicable to this case, because there are only several frontier AI models, and if they all have the same types of principles that we think threaten our safety, then, you know, we can't just go out and find a rogue company on the market, or we can't just go out and start our own AI model company as competition. Again, this is just a statement of principle. One of the arguments in this Lawfare article is that you could see AI constitutions being seen as software instructions more than protected expression. You know, just I don't -- I don't think that's what an AI constitution is. You can have something like a model card that outlines the purpose of the model. You can have all different types of documents for transparency purposes, but an AI constitution is something categorically different because it's a statement of values. I think any statement of values is just not something that should or can be subject to government regulation.
Dave Bittner: So to be clear here, what we're talking about is, it is within the AI company's right to say, "Our model will not discuss matters of Holocaust denial," something controversial. We're just -- we're not going there. As an organization, we have decided that we're putting guardrails around that. Nothing good can come of it in our -- from the opinion of our company." That's different from the government saying, "Your AI models -- or no one's AI models -- can discuss Holocaust denial.".
Ben Yelin: Exactly, so the first case would be a completely legitimate action on the part of the company, and the company is protected from the government coming in and saying, "Hey, we don't believe in censorship. You have to enable Holocaust-related content on your platforms. It's a government mandate." That would be the prototypical example of compelled speech, which the Constitution disfavors. Yeah, the government going in and saying, this certain category of speech is prohibited to be used on these AI models, is also an inhibition on speech and can only be justified with some type of exceedingly persuasive justification, or a compelling state interest, and the means would have to be narrowly tailored to achieving that interest. So that's a test that 999 times out of 1,000 is going to fail, so the government just, really, doesn't have much of a role in regulating what these models can and can't say. They can regulate -- again, you can regulate some of the actions that result from those values, but you have to limit your potential regulation to those actions, and not to the values underlying those actions. Even if you see the constitution as sort of software instructions because it informs the AI algorithm, it's still just a statement of principles. It's still -- even if it is a technical blueprint, and it's a binding rulebook on the company, it's still just the company's own view of how their models should exist. That's something that's fully constitutionally protected.
Dave Bittner: I'm reminded of, you know, years ago, when Microsoft initially released their Tay model. Do you remember Tay?
Ben Yelin: Oh yeah, I remember that.
Dave Bittner: Yeah, and so Tay --
Ben Yelin: It's been a while.
Dave Bittner: It's been a while, but, you know, Tay was not around for very long, because it turns out Tay was extremely abrasive and racist [laughter] in many of the things that Tay had to say about this world. One of my takeaways from that experience was that these AI models that ingest everything, and average them out, and calculate them and spit them back out, they're a reflection of who we actually are, rather than who we aspire to be -- warts and all.
Ben Yelin: Yeah, I mean, that's kind of been the overall AI experience, is that AI is a reflection on our own foibles, also our own ingenuity. It just does things faster, and at a greater scale than we are capable of doing as human beings.
Dave Bittner: So that leads me to this question, which is, does the government have a part to play when it comes to things like bias in these AI engines and ideological neutrality? We've seen recent administrations going after people or organizations for what they claim is some sort of political bias. Whether that's true or not, they pursue it.
Ben Yelin: Yeah, I mean, my general view of it is that you can't -- as a private company, unless they are violating an existing federal statute, you can't hold them accountable for whatever decisions they make vis-a-vis bias. I mean, that's one of the -- kind of the spirit behind Section 230, is to allow companies themselves to make these decisions and have that shield of liability. I think that's kind of the way the market works in this country. There are, obviously, pitfalls to this because companies might see it in their competitive advantage to allow all different types of what we would determine to be offensive material to come out of these algorithms. I think that's the price we pay for not having government dictates to these companies that force them to say one thing or another. I think what the Trump administration has tried to do in other contexts is they recognize that they can't directly force Harvard University to make a particular statement or to have a particular policy related to diversity, equity, and inclusion. They will instead use their leverage as, kind of, a defunding organization. They're the ones who give grants to these universities. So they'll say, "You're not eligible for government grants or research grants unless you change your DEI policies." That's an area where the government might actually have a little bit more leverage, but even that -- the ability to condition federal dollars on taking a certain stance or expressing a certain idea -- that's run into all different types of difficulties as it's reached federal courts. That's not going to be the be-all and end-all, even that tactic of trying to leverage the use of federal dollars.
Dave Bittner: We're seeing that with Anthropic, right? Where the Department of Defense has said, we want to use these tools for this, that, and the other, and Anthropic has said, no, no. We're putting guardrails around that. The response from the administration has been, okay, well, then nobody in the federal government gets to use your tools.
Ben Yelin: Yeah, and that's -- first of all, that's subject to litigation.
Dave Bittner: Right, which is happening, right?
Ben Yelin: Which is happening, so it's not like they're just completely getting away with it, and there isn't a question of fact or law here
Dave Bittner: Right.
Ben Yelin: But notice what the government is not doing. They even recognize in these circumstances that they can't go and criminally arrest the CEO of Anthropic for not complying with the Department of War's preferred specifications, right?
Dave Bittner: Yeah, yeah.
Ben Yelin: They have not sued this company from refusing to take a certain stance. They're using the leverage that they have as a purchaser of this product, and I think that's much more legitimate leverage than using the force of the government to weigh in on somebody's business decisions or business values. It is kind of like a -- it's a little bit of a libertarian perspective, but I kind of -- I think it's critically important because I think it's important for companies to have this vector of independence, to have all different types of values and allow consumers to make choices. I'll reiterate that sometimes those choices aren't meaningful choices when there are only several models that are capable of interacting with the Department of War, right?
Dave Bittner: Yeah, yeah.
Ben Yelin: But I still think it's a value worth protecting.
Dave Bittner: Is there an element here where we have to take into account the degree to which the AI models have a legal standing as an entity? We've, you know, famously, you can't copyright an AI-created work, so the output from an AI, does it somehow automatically have less value or less standing than other sources?
Ben Yelin: I think that's an open question, but I'll note what this article is talking about does not relate, necessarily, to the output of the AI. I think there might be a cause of action, potentially, if there were some type of harmful output, and we've seen that in a lot of different contexts. Like, models that have encouraged suicidal ideation are facing lawsuits and criminal investigations across various states in this country. What this article is talking about are these AI constitutions, which -- that's fully the voice of the companies themselves, and I think it's indisputable that's the voice of the companies themselves. Unless the CEO of Anthropic was, like, hey, I'm going to open up Claude and ask it to draft our company some values that we can put in our constitution.
Dave Bittner: Right, right.
Ben Yelin: Maybe then it's a gray area.
Dave Bittner: The snake eating its own tail.
Ben Yelin: But presuming that they've put some actual thought into this and that this is the reasoned expression of the leadership of these companies, it's not the same as the kind of murky legal situation related to outputs of these AI models, if that makes sense.
Dave Bittner: Yeah, no, it does. All right. Well, we will have a link to that article in the show notes, and I think it's a pretty interesting one, one well worth your time. Something -- like I said -- it was new to me, so I've spent a good amount of time thinking on that one. [ Music ] And that is "Caveat" brought to you by N2K CyberWire. We'd love to know what you think of this podcast. Your feedback ensures we deliver the insights that keep you a step ahead in the rapidly changing world of cybersecurity. If you like our show, please share a rating and review in your favorite podcast app. Please also fill out the survey in the show notes or send an email to caveat@n2k.com. This episode is produced by Liz Stokes. Our Executive Producer is Jennifer Eiben. The show is mixed by Tré Hester. Peter Kilpe is our Publisher. I'm Dave Bittner.
Ben Yelin: I'm Ben Yelin.
Dave Bittner: Thanks for listening.

