效仿中国?特朗普授权美国企业参与黑客行动

Wait 5 sec.

DUSTIN VOLZ2026年8月14日一位研究中国黑客生态的专家表示,从历史上看,北京曾效仿美国的各项网络安全政策,但特朗普政府的新政策却逆转了这种局面。 Vincent Thian/Associated PressThe Trump administration is encouraging American companies to conduct their own cyberattacks against criminal hackers, a move that White House officials say will help address digital scourges like ransomware but that some former officials and security experts warn could lead to chaos.特朗普政府正鼓励美国企业参与对犯罪黑客发起的网络攻击行动,白宫官员表示,此举将有助于应对勒索软件等数字祸害,但一些前官员和安全专家警告称,这可能会引发混乱。Under a national security memorandum that President Trump signed late Wednesday, select companies would work with the Justice and Homeland Security Departments to strike foreign cybercriminal groups with hacks under certain conditions. The attacks would allow both surveillance of the criminal networks and specific types of hacking operations that could lead to disruption, manipulation or destruction of information systems and networks, including virtual and physical infrastructure.根据特朗普总统周三深夜签署的一份国家安全备忘录,符合条件的企业将在特定情况下与司法部和国土安全部合作,对外国网络犯罪团伙发动黑客攻击。这些攻击既可用于监控犯罪网络,也可以开展特定类型的黑客行动,对包括虚拟和实体基础设施在内的信息系统和网络实施干扰、操纵甚至摧毁。It was not clear which companies, if any, would sign up, but the move is a sharp pivot from decades of cybersecurity policy across Republican and Democratic administrations that generally prioritized improving corporate defenses and confined offensive cyberoperations to the U.S. military and intelligence agencies. It adds detail to a shift that Trump officials had teased in general terms for months.目前还不清楚究竟会有哪些企业(如果有的话)参与这一计划,但此举明显偏离了共和党和民主党政府数十年来的网络安全政策。过去的政策通常优先加强企业自身的网络防御,并将进攻性网络行动限制在美国军方和情报机构的范围内。这一做法进一步明确了特朗普官员数月来一直以笼统措辞预告的政策转向。The concept of giving the private sector a more direct role in offensive cyberactions has been around for years. But it has never before been publicly endorsed by a presidential administration, in part because of concerns that doing so could provoke more cyberconflict, raise novel questions of liability and international legal exposure for U.S. firms, and have unforeseen — and potentially escalatory — consequences. The new memorandum does not directly address many of those concerns, though it states that the policy is meant to tap into the “ingenuity of the private sector” to stem the ever rising costs of cyberattacks.让私营部门在网络攻击中发挥更直接作用的构想已存在多年。但此前从未有任何一届政府公开支持过这一做法,部分原因是担心这样做可能引发更多网络冲突,给美国企业带来新的责任和国际法律风险,并可能产生不可预见的、甚至可能导致局势升级的后果。新的备忘录没有直接解决其中许多担忧,尽管它指出该政策旨在利用“私营部门的创造力”来遏制不断上升的网络攻击成本。Rather than permit a free-for-all on the digital battlefield, however, the conduct that U.S. companies can engage in is intended to be relatively circumscribed. Participating companies must first be vetted to be included in the program, sign a contract with the government that includes $1 million fines for violations, and receive written approval from officials at the Justice and Homeland Security Departments before proceeding with an attack. The policy will not authorize attacks that are likely to lead to loss of life, serious injury or “rise to the level of use of force or armed attack under international law,” though former officials and experts said precisely calibrating offensive cyberoperations is sometimes as much an art as a science.不过,这并不是要允许企业在数字战场上各自为战。美国企业可以采取的行动范围实际上受到相当严格的限制。参与企业必须首先接受审查才能加入计划,然后与政府签署协议;违反规定将面临最高100万美元的罚款。此外,在发动攻击之前,还必须获得司法部和国土安全部官员的书面批准。这项政策不授权实施那些可能导致人员死亡、严重伤害,或“根据国际法构成使用武力或武装攻击”程度的行动。不过,一些前政府官员和专家表示,要精确控制进攻性网络行动有时既是一门艺术,也是一门科学。The White House did not respond to questions about the memorandum other than to say operations would be “based on intelligence.” The Trump administration did not brief reporters on the order ahead of its release late Wednesday.白宫没有回应该备忘录的相关问题,只表示相关行动将“以情报为依据”。特朗普政府也没有在备忘录周三深夜公布之前向记者介绍这项命令。Amanda Naylor, director of cyberpolicy at the National Security Council, which helped draft the memo along with the Office of the National Cyber Director, said in a LinkedIn post that the memo would “give the United States new tools to protect Americans from cybercrime and fraud.”国家安全委员会网络政策主任阿曼达·内勒在领英上发帖称,该备忘录将为美国提供“保护美国人民免受网络犯罪和欺诈的新工具”。这份备忘录由国家安全委员会与国家网络总监办公室共同起草。But many former officials and some security executives expressed worry that the new approach could be difficult to enact and risked complicating the already unpredictable world of modern cyberwarfare. Among other issues, it appeared that the approved companies could potentially take actions that exceed the authorities granted to the government’s own security agencies, a former senior U.S. intelligence official said.但许多前政府官员以及一些网络安全高管对此表示担忧,认为这种新做法可能难以实施,而且还可能让本就变幻莫测的现代网络战局势变得更加复杂。其中一名美国前高级情报官员表示,按照目前的安排,获准参与该计划的企业在某些情况下可能采取超出美国政府的安全机构法定权限的行动。Mr. Trump’s executive action contains a classified annex laying out a process to deconflict private-sector hacking with the federal government’s own operations. The memo also specifies that attacks will be limited to transnational criminal organizations that are considered separate from a foreign government “unless clear intelligence exists establishing such connection.”特朗普的行政令包含一份机密附件,规定了如何协调私营部门的黑客行动与联邦政府的网络行动,避免双方相互干扰。备忘录还规定,攻击对象将限于被视为与外国政府无关的跨国犯罪组织——“除非有明确情报证明二者存在关联”。Nick Carr, the threat intelligence lead at Microsoft and a former cybersecurity official, said in a social media post that his biggest concern was “just how difficult attribution in criminal operations is, and how few organizations can repeatably do it right,” including government agencies. He added, however, that the order could improve those efforts.微软威胁情报部门负责人、前网络安全官员尼克·卡尔在社交媒体上发帖称,他最大的担忧是“在犯罪行动中进行归因非常困难,而且很少有组织能持续正确地做到这一点”,即使是政府机构也不例外。不过,他同时表示,这项命令也可能有助于改善相关工作。Still, it is often murky whether a criminal hacking group, such as a Russian-speaking gang of cyberthieves, has ties to a foreign power or at times does work for a spy agency on the side. Michael Garcia, who served as the associate chief of policy at the Cybersecurity and Infrastructure Security Agency until departing in June, said that while attribution had improved over the years, it still was not perfect and that “obfuscation is still a hell of a tactic.”然而,很多时候,一个犯罪黑客团伙——例如一个讲俄语的网络盗窃团伙——究竟是否与某个外国势力存在联系,或者是否偶尔会替某个间谍机构秘密执行任务,往往难以判断。迈克尔·加西亚说,尽管近年来网络攻击的归因能力有所提高,但仍然无法做到百分之百准确,“混淆和隐藏身份依然是一种极其有效的策略”。他曾担任网络安全与基础设施安全局政策部门副主管,直至今年6月离职。Some former officials said the order sought to address a growing and unsustainable problem that was probably only going to become worse in the short term with artificial intelligence.一些前官员表示,此项政令意在应对一项日益加剧且不可持续的困局,而随着人工智能的发展,这一问题在短期内很可能还会进一步恶化。“The current pace of cyberoperations is unsustainable for just the military,” said Mieke Eoyang, a former Pentagon official who oversaw military cyberweapon use during the Biden administration.“仅靠军方维持当前网络行动的速度是不可持续的,”曾在拜登政府时期负责监督军事网络武器使用的五角大楼前官员米克·约扬说。Ms. Eoyang, now a visiting professor at Carnegie Mellon University, said the memo’s success would hinge on the classified procedures for vetting firms and approving targets. She added that the existing process for approving military cyberoperations, developed during the first Trump administration, was “onerous, but it took into consideration collateral consequences and deconfliction.”约扬现在卡内基梅隆大学担任客座教授,她表示,这份备忘录能否成功,关键将取决于其中规定的企业资质审查和打击目标批准程序的保密细节。她还指出,特朗普第一任期建立的军方网络行动审批流程“很繁琐,但会考虑附带后果以及行动协调问题”。To some extent, the new order would align the United States more with some of its chief cyberantagonists, including China and Russia, where spy agencies have long relied on contract hackers working in the private sector to further their national security missions, in part to afford the state plausible deniability. U.S. defense technology companies also support the National Security Agency and U.S. Cyber Command, but that relationship usually involves supplying hacking tools, cyberintelligence and tradecraft to the U.S. intelligence community and military, rather than engaging directly in cyberoperations.从某种程度上说,这项新命令会让美国的做法更加接近中国和俄罗斯等主要网络对手。在这些国家,情报机构长期以来一直依靠私营部门的受雇黑客来执行国家安全任务,其中一个原因就是为政府提供合理否认的余地。美国的国防科技公司同样为国家安全局和美国网络司令部提供支持,但这种关系通常包括向美国情报界和军方提供黑客工具、网络情报和相关技术,而不是直接参与网络行动。Dakota Cary, an expert on China’s hacking ecosystem, said that historically Beijing had copied various cybersecurity policies from the United States, but that the new Trump policy was a reversal of that arrangement.中国黑客生态系统专家达科塔·凯里表示,北京曾效仿美国的各种网络安全政策,但特朗普的新政策是对这一模式的逆转。“In many ways, China’s hacking prowess now stems from the fact that they copied our education system,” said Mr. Cary, an adviser at the U.S. cybersecurity company SentinelOne. “Now it seems the U.S. is interested in copying China’s system for deputizing private-sector hackers.”“在很多方面,中国如今的黑客能力源于他们复制了我们的教育体系,”在美国网络安全公司SentinelOne担任顾问的凯里说。“现在看来,,美国似乎有意复制中国授权私营部门黑客参与行动的做法。”Given all its complexities, it was not clear what companies might participate in the program, which some lawyers said appeared to contain substantial risk.考虑到其中涉及的种种复杂问题,目前还不清楚哪些企业会参加这一计划。一些律师认为,这项政策似乎包含相当大的风险。“This approach from the government presents novel questions for publicly traded companies in the sector: Even if they engage in ‘hack back’ activities under U.S. government cover or direction, how will they manage the increased operational risk to their business and customers, and how and when will they disclose it?” said Vanessa Le, a partner at Latham & Watkins who advises companies on geopolitical risk.“政府的这种做法给该行业的上市公司带来了新的问题:即使他们在美国政府的掩护或指示下进行‘反黑客’活动,他们将如何管理由此增加的对其业务和客户带来的运营风险,又将在什么情况下、何时披露这些行动?”瑞生国际律师事务所合伙人、为企业提供地缘政治风险咨询的瓦内萨·勒表示。Dustin Volz为时报撰写网络安全和情报方面的文章,他常驻华盛顿。翻译:纽约时报中文网点击查看本文英文版。获取更多RSS:https://feedx.net https://feedx.site