A new executive order would let private US companies hack back against cybercriminals.
Under the order, a business that opts in could manipulate, disrupt, degrade, or even destroy the IT systems of suspected cybercriminals in order to stop an attack. The apparent goal is letting companies act in real time instead of waiting on law enforcement to respond. That marks a sharp break from the industry's usual defensive playbook of patching, monitoring, and reporting incidents after the fact. What's been reported so far does not detail who approves an operation, how a company confirms its target, or what liability it takes on.
This reopens a long-running argument in cybersecurity circles: does letting victims strike back make the internet safer, or does it just add more attackers to it? Backers of hacking back say it could take down criminal infrastructure faster than courts and subpoenas ever could. Skeptics point to the attribution problem: proving who is actually behind an attack is hard, and going after the wrong system risks real collateral damage.
Until the fine print on oversight and accountability surfaces, this reads more like a policy signal than a workable rulebook.