Should the U.S. Bomb Countries Harboring Hackers?

slfisher 1 Tallied Votes 309 Views Share

Nations such as Russia and China who have malicious hackers should be held accountable for the actions of those criminals, according to a report from the Council on Foreign Relations, an independent, nonpartisan membership organization.

"Though the United States cannot expect countries to prevent all malicious behavior, it can expect them to secure their networks to a reasonable standard, pass laws outlawing international cyber crime, and have mechanisms in place to act on requests for assistance in shutting down attacks, and investigating and prosecuting them," wrote author Robert Knake. He is the coauthor, with Richard Clarke, of the book Cyber War.

In addition, the U.S. needs to lead by example, Knake said. "It should take steps to clean up its national network, work to stop its systems from being used in international cyberattacks, prioritize criminal investigation of cyberattacks with foreign victims, and make clear that the primary goal of its military efforts in cyberspace is to defend the United States and preserve international connectivity."

Steps the U.S. should take include developing a stronger set of international regimes to fight crime in cyberspace, moving beyond the current Council of Europe Convention to draw in non-Western states, and developing realtime mechanisms for collaborating to stop cyberattacks in progress and investigate attacks across borders; developing new norms and pursuing treaties to protect the core functions of the Internet and ban distributed denial-of-service attacks; and updating the Internet's underlying technologies to be more secure, such as adding more authentication to IP, BGP, and DNS, Knake said. He also recommends a U.S. bureau on cyber affairs within the State Department.

The problem is that much of the world economy is dependent on the Internet today, meaning attacks can be much more devastating, but that overreactions to such attacks can also cause problems, Knake said.

Knake also criticized the U.S. broadband plan for making the U.S. more dependent on the Internet. "Given the current cyber threat environment, extending U.S. dependence is at best naive and at worst could create a situation in which America’s homeland is vulnerable to both state and nonstate actors that will seek to skip the battlefield and do harm to U.S. society in cyberspace."

Raising the spectre that harboring a geek version of Osama bin Laden could result in war, Knake said, "Countries that do not cooperate in criminal investigations should understand that failure to cooperate will be treated as a sign of complicity. Responses can include both traditional diplomatic protest, sanctions, and military action as well as network actions, including higher-level scrutiny for Internet traffic leaving states that do not cooperate and ultimately blockading access to U.S. and allied networks from states that continue to be outliers."

Opinions on the likelihood of a cyberwar vary, with some people saying it is imminent and others saying concerns are overblown. The U.S. is also looking at a controversial bill intended to give the federal government more control over the Internet in the event of such an attack.

Dani AI

Generated

The quick takeaway: using kinetic force (bombing) to punish a state for hackers sheltered inside its territory is legally fraught, operationally risky, and usually counterproductive. ’s post rightly frames state responsibility as an issue, but international law sets a high bar for the use of force—only actions that amount to an “armed attack” (or Security Council authorization) can justify military reprisals, and most cyber incidents fall below that threshold. UN Charter (full text). The Tallinn Manual 2.0 is the best practical guide lawyers and policymakers use to map how those legal rules apply in cyberspace. (It finds that only cyber operations with effects comparable to kinetic damage cross into “use of force.”) Tallinn Manual (CCDCOE).

Attribution is the other hard constraint. As ’s point implies, proving who ordered or directed an intrusion usually requires technical indicators plus independent intelligence and time; attackers can and do plant false flags. Academic work on the “attribution problem” shows why hasty kinetic reprisals risk striking the wrong party and prompting dangerous escalation. Jon R. Lindsay, “Tipping the scales: the attribution problem…” (Journal of Cybersecurity).

Practical, legally defensible tools exist and are used routinely: criminal indictments, public attribution, targeted sanctions, cooperative takedowns, and measured network operations. Recent DOJ indictments and Treasury/OFAC designations show how law enforcement plus economic measures can impose costs without resorting to war. DOJ press release (Mabna indictment). Treasury/OFAC sanctions on cyber actors.

In short: ’s and ’s instincts toward targeted, proportionate action are the more realistic path. The durable approach is better attribution, multilateral cooperation, law‑enforcement pressure, sanctions, and calibrated cyber operations — not bombing, which is legally risky and likely to make the problem worse.

roblimo 0 Newbie Poster

What about all the U.S.-based hackers? Are we going to bomb Maryland, California, Washington, Oregon, and New Jersey? These are all well-known hacker hotbeds, plus New Jersey is home to that awful Jersey Shore TV show and those horrid Real Housewives. Even so, is bombing a country over the sins of a few of its citizens morally justified?

slfisher 0 Posting Whiz

Yeah, that would be interesting, if Russia or China were to bomb *us* for what it perceived as hacking coming from the U.S.

setherith 0 Newbie Poster

Military action is at the far end of the spectrum, I think identifying the culprit and disconnecting them as a warning is probably as far as anyone needs to go. It's certainly what happens here already in the UK. If you get caught pirating/hacking or using your connection in a less than saintly way your disconnected from your ISP.

Agilemind 0 Posting Whiz in Training

History is very clear state vs individuals always results in individuals winning because the state doesn't know how to play on their terms. If you want to stop hackers hack them back, set up infected hacker-tools sites etc...

It the same as insurgency and terrorism you have to fight at their scale, otherwise you always end up creating more of them than you get rid of. Imposing restrictions on some countries harbouring hackers will punish all the non-hackers in that country and feeling they are unfairly treated they will become hackers to get around the restrictions.

It is individuals and intelligence organizations that have to take the lead here to pinpoint the culprits so you can target them and only them.

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.