Live data from Hacker News

Should hack-back be legal?

speculumx.at

1–10 of 17 posts

Re: Should hack-back be legal?

#2
There’s a case for allowing digital privateering against countries that routinely allow fraud. For example fraud is 68% of Laos’s GDP.

If Laos wants to be taken off the list of permitted targets then it can crack down on fraud. They have effectively allowed digital privateering against us by failing to crack down on fraud.

https://www.theguardian.com/technology/2025/dec/02/scam-stat...

Re: Should hack-back be legal?

#4
All vigilantism has issues. For example, if I was ever to do something horrific online I’d probably hack someone unrelated to me first and tunnel through their computer and online presence to make sure if I got caught it would not blowback onto me so easily. Not that I’ve thought about it or anything :-/

Re: Should hack-back be legal?

#5
post #2

There’s a case for allowing digital privateering against countries that routinely allow fraud. For example fraud is 68% of Laos’s GDP. If Laos wants to be taken off the list of permitted targets then it can crack down on fraud. They have effectively allowed digital privateering against us by failing to crack down on fraud. https://www.theguardian.com/technology/2025/dec/02/scam-stat...

The issue is those jurisdictions that have allowed such rot to take hold truly don't care.

Both Cambodia and Laos have governments where leadership is directly tied to organized crime, but the PRC has continued to expand their relationships with both because of their strategic position and because their governments directly cooperate with Chinese law enforcement.

Similarly, in the threat hunting space, it's been common to find Russian originated malware that would shut itself off if it identified an indicator or signature that implied that the workload was within the CIS.

In the same manner, if I were to conduct illicit cyberoperations in a jurisdiction like the UAE but not target the US, India, China, and a couple other jurisdictions with strong ties with the UAE I could operate with impunity.

It's the same reason Neville Singham is in Shanghai and Guo Wengui is in New York. It's also the same reason Ecuador handed Assange after the government changed from being hard-left and aligned with Russia and Venezuela to center-right and aligned with the US.

Edit: can't reply

> the case that fraudsters can already target Loas and Cambodia with impunity from certain jurisdictions

Not legally or morally, but this is de facto the case.

That said, the countries most annoyed at Laos and Cambodia (eg. Thailand, Vietnam, and the auS) would much rather use regime change, or use pressure points like financial crimes prosecution which dramatically reduces your freedom and dramatically increases your risk of being used as a pawn to trade, and offer the carrot of negotiated immunity deals in return for flipping.

These kinds of organizations don't exist with impunity - they are pawns that are discarded the moment their value can no longer justify their liabilities.

Re: Should hack-back be legal?

#7
post #3

I think you’re fine, which hacker is going to go to the police about it?

"If I sprain my ankle

While I'm robbing your place;

If I hurt my knuckles

When I punch you in the face...

I'm gonna sue! Sue! Yeah, that's what I'm gonna do!

Sue! Sue! I might even sue you!"

—Weird Al Yankovic, "I'll Sue Ya"

Re: Should hack-back be legal?

#8
I mean it sounds ok, assuming that you are evenly matched. But assuming this was legal and someone like google has automated hack back triggered by some automated rule.

Its a bit trigger happy and I do something like change VPN, with my session, and it looks like I'm trying to probe with multiple IPs.

Boom, my devices all fall apart and my internet is offline until they stop DOS'ing me

Re: Should hack-back be legal?

#9
post #2

There’s a case for allowing digital privateering against countries that routinely allow fraud. For example fraud is 68% of Laos’s GDP. If Laos wants to be taken off the list of permitted targets then it can crack down on fraud. They have effectively allowed digital privateering against us by failing to crack down on fraud. https://www.theguardian.com/technology/2025/dec/02/scam-stat...

The issue is those jurisdictions that have allowed such rot to take hold truly don't care. Both Cambodia and Laos have governments where leadership is directly tied to organized crime, but the PRC has continued to expand their relationships with both because of their strategic position and because their governments directly cooperate with Chinese law enforcement. Similarly, in the threat hunting space, it's been comm…

Are you making the case that fraudsters can already target Loas and Cambodia with impunity from certain jurisdictions?

If you are then I would point out that being legitimate allows you to attract better talent. See America’s private military contracting sector. Yes you can go and be a mercenary abroad and operate in a legal grey area, but if you’re a Private Military Contractor working for a major US company then you won’t go to jail in the US when you come back, and you can put it on your CV.

Post reply on HN