<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: H.R. 4036: Active Cyber Defense Certainty Act in Industry News</title>
    <link>https://community.isc2.org/t5/Industry-News/H-R-4036-Active-Cyber-Defense-Certainty-Act/m-p/11408#M1093</link>
    <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/129426011"&gt;@HTCPCP-TEA&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;Let us know where you do get to present.&lt;/P&gt;&amp;nbsp;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;Thanks, I'll try to remember to stick it in here.&amp;nbsp; (I've spent most of the morning reading my co-presenter's draft dissertation on "ACD" [during a boring vendor seminar] [for which I'll have to remember to submit CPEs] and making notes for him to address issues there.)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/129426011"&gt;@HTCPCP-TEA&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;It would be of high interest to many I'm sure! If I see any call for such things I will pass details on to you.&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;Thanks much.&amp;nbsp; I've done a number of presentations on ethics over the years, and this makes a really interesting case study.&amp;nbsp; I also think it is an area that a lot more people should be thinking about, with implications for a wide range, such as artificial intelligence, network design, forensics, etc.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;(The vendor this morning works in the network security space.&amp;nbsp; We had a VP giving us top secret information about future product lines.&amp;nbsp; I asked a question about active defence, and expected he wouldn't answer because it might be too political/controversial even for a closed group like this one.&amp;nbsp; I didn't get an answer--because he didn't understand the question ...)&lt;/P&gt;</description>
    <pubDate>Tue, 12 Jun 2018 21:43:28 GMT</pubDate>
    <dc:creator>rslade</dc:creator>
    <dc:date>2018-06-12T21:43:28Z</dc:date>
    <item>
      <title>H.R. 4036: Active Cyber Defense Certainty Act</title>
      <link>https://community.isc2.org/t5/Industry-News/H-R-4036-Active-Cyber-Defense-Certainty-Act/m-p/11338#M1073</link>
      <description>&lt;P&gt;OK, USians, possibly time to talk to your Congresscritters.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.govtrack.us/congress/bills/115/hr4036" target="_blank"&gt;Govtrack&lt;/A&gt; gives &lt;A href="https://www.govtrack.us/congress/bills/115/hr4036/text" target="_blank"&gt;H.R. 4036&lt;/A&gt;, aka the &lt;A href="https://www.gpo.gov/fdsys/pkg/BILLS-115hr4036ih/pdf/BILLS-115hr4036ih.pdf" target="_blank"&gt;Active Cyber Defense Certainty Act&lt;/A&gt;, only about a 12% chance of succeeding.&amp;nbsp; Which is probably a good thing.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;"Congress determines that the use of active cyber defense techniques, when properly applied, can also assist in improving defenses and deterring cybercrimes."&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;Oh, really?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The rest of the rationale seems to be that attackers are dangerous and fast, and waiting around for law enforcement to help you is just going to give the bad guys time to destroy your systems and get away.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;OK, I don't understand all of the wording in this bill.&amp;nbsp; (I rather suspect that the author isn't entirely certain of it, either.)&amp;nbsp; But the overall upshot seems to be that, yes, you can attack anyone who is attacking you (or who you &lt;STRONG&gt;think&lt;/STRONG&gt; is attacking you) if you tell the FBI you are going to do it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Come to think of it, good luck with finding, before the bad guys destroy your systems and get away, someone in the FBI who understands the situation and will give you official permission to mount an active defence attack.&lt;/P&gt;</description>
      <pubDate>Mon, 09 Oct 2023 08:48:49 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/H-R-4036-Active-Cyber-Defense-Certainty-Act/m-p/11338#M1073</guid>
      <dc:creator>rslade</dc:creator>
      <dc:date>2023-10-09T08:48:49Z</dc:date>
    </item>
    <item>
      <title>Re: H.R. 4036: Active Cyber Defense Certainty Act</title>
      <link>https://community.isc2.org/t5/Industry-News/H-R-4036-Active-Cyber-Defense-Certainty-Act/m-p/11350#M1074</link>
      <description>&lt;P align="left"&gt;(10) Congress holds that active cyber defense techniques should only be used by qualified defenders with a high degree of confidence in attribution, and that extreme caution should be taken to avoid impacting intermediary computers or resulting in an escalatory cycle of cyber activity.&lt;/P&gt;&lt;P align="left"&gt;&amp;nbsp;&lt;/P&gt;&lt;P align="left"&gt;Hmmm....&lt;/P&gt;&lt;P align="left"&gt;&amp;nbsp;&lt;/P&gt;&lt;P align="left"&gt;No chance of them being explicit with who they feel are qualified then? And attribution is always easy, isn't it?!&lt;/P&gt;</description>
      <pubDate>Mon, 11 Jun 2018 07:37:25 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/H-R-4036-Active-Cyber-Defense-Certainty-Act/m-p/11350#M1074</guid>
      <dc:creator>JayCee</dc:creator>
      <dc:date>2018-06-11T07:37:25Z</dc:date>
    </item>
    <item>
      <title>Re: H.R. 4036: Active Cyber Defense Certainty Act</title>
      <link>https://community.isc2.org/t5/Industry-News/H-R-4036-Active-Cyber-Defense-Certainty-Act/m-p/11356#M1075</link>
      <description>&lt;P&gt;Agreed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It's been a much discussed issue here too (UK) in terms of "Attacking the Attackers". While it seems to be a great idea at first, there are so many inherent issues to consider that it becomes problematic to even consider.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;While the merits and pitfalls of such activities could be argued for years to come, there will inevitably be more and more reasons to sanction such activities. However, careful consideration would be needed in terms of where lines of remit, boundaries of responsibility and where the law sits in regards to it all.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Reporting into someone prior to taking action is likely the bet course of action, if it was at all feasible... but as you rightly point out, there is no guarantee that the person you report into would have any idea what you were about to do anyway, let alone have the power to critique or monitor it....&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As you rightly point out, at this moment, it is unlikely that any such legislation will come to pass....but maybe one day..........&lt;/P&gt;</description>
      <pubDate>Mon, 11 Jun 2018 13:19:33 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/H-R-4036-Active-Cyber-Defense-Certainty-Act/m-p/11356#M1075</guid>
      <dc:creator>HTCPCP-TEA</dc:creator>
      <dc:date>2018-06-11T13:19:33Z</dc:date>
    </item>
    <item>
      <title>Re: H.R. 4036: Active Cyber Defense Certainty Act</title>
      <link>https://community.isc2.org/t5/Industry-News/H-R-4036-Active-Cyber-Defense-Certainty-Act/m-p/11360#M1078</link>
      <description>&lt;P&gt;Imagine the future history book describing the early beginnings of World War III being started by a well meaning intern attacking and hacking back an unknown adversary. Setting off a chain of continuing chain of events that quickly escalates to the government level with all parties reacting accordingly. Hack, counter-hack and attack. Rinse and repeat.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;All we need is an electronic version of Gavrilo Princip to assassinate the next Franz Ferdinand. This bill needs to die quietly and never see the light of day or committee - whichever comes first.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Jun 2018 14:20:02 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/H-R-4036-Active-Cyber-Defense-Certainty-Act/m-p/11360#M1078</guid>
      <dc:creator>Beads</dc:creator>
      <dc:date>2018-06-11T14:20:02Z</dc:date>
    </item>
    <item>
      <title>Re: H.R. 4036: Active Cyber Defense Certainty Act</title>
      <link>https://community.isc2.org/t5/Industry-News/H-R-4036-Active-Cyber-Defense-Certainty-Act/m-p/11364#M1079</link>
      <description>&lt;P&gt;It's the modern version of a shoot out in front of the saloon-whoever has the quicker draw (compute power), better aim (strategy), and ability to dodge the bullet (think Neo in Matrix), would win the battle.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Beyond a few nation states, and some large corporations, namely Apple, IBM, Dell, HP, etc. that does have the compute power to execute a counter attack, the little guy has no chance.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;I agree with&amp;nbsp;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/1214778195"&gt;@Beads&lt;/a&gt;&amp;nbsp;that this is silly at best and demonstrates a complete lack of understanding of the dark web. This bill is a waste of time.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Jun 2018 15:15:03 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/H-R-4036-Active-Cyber-Defense-Certainty-Act/m-p/11364#M1079</guid>
      <dc:creator>Flyslinger2</dc:creator>
      <dc:date>2018-06-11T15:15:03Z</dc:date>
    </item>
    <item>
      <title>Re: H.R. 4036: Active Cyber Defense Certainty Act</title>
      <link>https://community.isc2.org/t5/Industry-News/H-R-4036-Active-Cyber-Defense-Certainty-Act/m-p/11371#M1081</link>
      <description>&lt;P&gt;A friend (who is just finishing up his PhD on the topic) and I are working on a presentation on "Ethics of Active Defence," and looking for conferences to present it at.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Jun 2018 16:52:42 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/H-R-4036-Active-Cyber-Defense-Certainty-Act/m-p/11371#M1081</guid>
      <dc:creator>rslade</dc:creator>
      <dc:date>2018-06-11T16:52:42Z</dc:date>
    </item>
    <item>
      <title>Re: H.R. 4036: Active Cyber Defense Certainty Act</title>
      <link>https://community.isc2.org/t5/Industry-News/H-R-4036-Active-Cyber-Defense-Certainty-Act/m-p/11394#M1087</link>
      <description>&lt;P&gt;Let us know where you do get to present.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It would be of high interest to many I'm sure! If I see any call for such things I will pass details on to you.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Jun 2018 07:39:44 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/H-R-4036-Active-Cyber-Defense-Certainty-Act/m-p/11394#M1087</guid>
      <dc:creator>HTCPCP-TEA</dc:creator>
      <dc:date>2018-06-12T07:39:44Z</dc:date>
    </item>
    <item>
      <title>Re: H.R. 4036: Active Cyber Defense Certainty Act</title>
      <link>https://community.isc2.org/t5/Industry-News/H-R-4036-Active-Cyber-Defense-Certainty-Act/m-p/11408#M1093</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/129426011"&gt;@HTCPCP-TEA&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;Let us know where you do get to present.&lt;/P&gt;&amp;nbsp;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;Thanks, I'll try to remember to stick it in here.&amp;nbsp; (I've spent most of the morning reading my co-presenter's draft dissertation on "ACD" [during a boring vendor seminar] [for which I'll have to remember to submit CPEs] and making notes for him to address issues there.)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/129426011"&gt;@HTCPCP-TEA&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;It would be of high interest to many I'm sure! If I see any call for such things I will pass details on to you.&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;Thanks much.&amp;nbsp; I've done a number of presentations on ethics over the years, and this makes a really interesting case study.&amp;nbsp; I also think it is an area that a lot more people should be thinking about, with implications for a wide range, such as artificial intelligence, network design, forensics, etc.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;(The vendor this morning works in the network security space.&amp;nbsp; We had a VP giving us top secret information about future product lines.&amp;nbsp; I asked a question about active defence, and expected he wouldn't answer because it might be too political/controversial even for a closed group like this one.&amp;nbsp; I didn't get an answer--because he didn't understand the question ...)&lt;/P&gt;</description>
      <pubDate>Tue, 12 Jun 2018 21:43:28 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/H-R-4036-Active-Cyber-Defense-Certainty-Act/m-p/11408#M1093</guid>
      <dc:creator>rslade</dc:creator>
      <dc:date>2018-06-12T21:43:28Z</dc:date>
    </item>
    <item>
      <title>Re: H.R. 4036: Active Cyber Defense Certainty Act</title>
      <link>https://community.isc2.org/t5/Industry-News/H-R-4036-Active-Cyber-Defense-Certainty-Act/m-p/11410#M1094</link>
      <description>&lt;P&gt;Hey, admins and ISC2 HQ type people: you guys interested in a Webinar on the Ethics of Active Defence?&lt;/P&gt;</description>
      <pubDate>Wed, 13 Jun 2018 01:23:54 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/H-R-4036-Active-Cyber-Defense-Certainty-Act/m-p/11410#M1094</guid>
      <dc:creator>rslade</dc:creator>
      <dc:date>2018-06-13T01:23:54Z</dc:date>
    </item>
    <item>
      <title>Re: H.R. 4036: Active Cyber Defense Certainty Act</title>
      <link>https://community.isc2.org/t5/Industry-News/H-R-4036-Active-Cyber-Defense-Certainty-Act/m-p/16072#M1830</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/129426011"&gt;@HTCPCP-TEA&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;Let us know where you do get to present.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Well, we are doing it in about four hours at &lt;A href="https://infowarcon.com/" target="_blank"&gt;Infowarcon&lt;/A&gt;.&amp;nbsp; Not my favourite situation for a first time out, since Patrick is in Virginia and I'm about 3,000 miles away leading off the &lt;A href="https://infowarcon.com/sessions/ethics-social-aspects-and-factors-related-to-active-cyber-defence-acd/" target="_blank"&gt;pres&lt;/A&gt; via Skype.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;(We still haven't tested the connection to the conference venue ...)&lt;/P&gt;</description>
      <pubDate>Thu, 01 Nov 2018 13:59:25 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/H-R-4036-Active-Cyber-Defense-Certainty-Act/m-p/16072#M1830</guid>
      <dc:creator>rslade</dc:creator>
      <dc:date>2018-11-01T13:59:25Z</dc:date>
    </item>
    <item>
      <title>Re: H.R. 4036: Active Cyber Defense Certainty Act</title>
      <link>https://community.isc2.org/t5/Industry-News/H-R-4036-Active-Cyber-Defense-Certainty-Act/m-p/18597#M2190</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/129426011"&gt;@HTCPCP-TEA&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;Let us know where you do get to present.&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;OK, the Vancouver Chapter is doing it &lt;A href="http://www.infosecbc.org/events/new-calendar-event-2/" target="_blank" rel="noopener"&gt;next week, Feb. 8, 2-4 pm, PST&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For those of you who aren't in Vancouver (poor you), we will be broadcasting this meeting&lt;BR /&gt;and may post it later on YouTube. Please register by sending an email to van.secsig@gmail.com with the Subject line: February 8th, 2019 + Your Name. You will get an email with the YouTube URL &lt;STRONG&gt;just&lt;/STRONG&gt; before the meeting.&amp;nbsp; (It might start a little after 2 pm.)&amp;nbsp; While you are welcome to share your display with colleagues (but remind them to abide by the confidentiality rules set by the speaker for the meeting), please do not forward the URL to others (instead, ask them to join VanSecSIG and register directly for the video broadcast). Please also note that the (ISC)Â² Vancouver Chapter will only submit CPE credits for those who attend the meeting in person and sign the attendance sheet.&amp;nbsp; (You can still submit for your own CPEs, but we can't prove anything about your attendance.)&lt;/P&gt;</description>
      <pubDate>Fri, 01 Feb 2019 17:43:08 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/H-R-4036-Active-Cyber-Defense-Certainty-Act/m-p/18597#M2190</guid>
      <dc:creator>rslade</dc:creator>
      <dc:date>2019-02-01T17:43:08Z</dc:date>
    </item>
    <item>
      <title>Re: H.R. 4036: Active Cyber Defense Certainty Act</title>
      <link>https://community.isc2.org/t5/Industry-News/H-R-4036-Active-Cyber-Defense-Certainty-Act/m-p/18601#M2191</link>
      <description>&lt;P&gt;Here on the East Coast in DC that is Happy Hour and Mrs. Fly doesn't like her date night messed with. So, I will wait for the Youtube link so I can watch it at a later time.&amp;nbsp; Hope it goes well!&lt;/P&gt;</description>
      <pubDate>Fri, 01 Feb 2019 18:37:36 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/H-R-4036-Active-Cyber-Defense-Certainty-Act/m-p/18601#M2191</guid>
      <dc:creator>Flyslinger2</dc:creator>
      <dc:date>2019-02-01T18:37:36Z</dc:date>
    </item>
  </channel>
</rss>

