Should the government hack companies?
In my op-ed in The National Interest (attached), I propose that federal regulators should hack into the companies holding our most sensitive data to force companies to get their acts together. Full piece: https://nationalinterest.org/blog/techland/why-we-should-hack-ourselves-before-someone-else-does Highlights: 1/ The current incentive structure is wrong. An uploaded copyrighted movie is taken down from YouTube in seconds because of financial penalties. But companies stall on taking down terrorist infrastructure or comprehensively fixing cybersecurity vulnerabilities, because the penalties for inaction are negligible or non-existent. 2/ AI has changed cybersecurity for attackers and defenders. The same speed and scale that makes attacks cheaper can make defense just as fast. 3/ Every other regulator gets to show up unannounced. The USDA doesn't wait for an outbreak to inspect a slaughterhouse. The Fed doesn't ask a bank's permission before stress-testing it. Cybersecurity is the one place still running on the honor system, penetration tests by invitation, on a schedule the company sets, with no penalty for failing. Companies won’t get their act together until getting breached costs more than fixing the flaw. Right now it usually doesn't, and Equifax, stolen F-35 blueprints, and a dozen state water utilities (likely hacked by Iran) are the result. None of this requires new technology. It requires pointing the capability we already have at ourselves, before China, Iran, or a model with no country at all finds the next vulnerability for us. Much more detail in the piece. What do you think? Should the government be allowed to hack private enterprises?
Read original source ↗