Obama's proposed laws against hacking will negatively impact cybersecurity professionals, create a cyber police state
Obama's War on Hackers … In next week's State of the Union address, President Obama will propose new laws against hacking that could make either retweeting or clicking on the above link illegal.
Context & Ripple Effects
This piece is a counterpoint landing mid-salvo: two days earlier the administration had floated legislation shielding firms that share cyberthreat data with the government and criminalizing botnet and stolen-financial-info sales, alongside parallel proposals on student privacy and mandatory breach disclosure. Errata Security's argument is that broad statutory definitions of hacking turn ordinary researcher behavior — linking to, or reposting, exploit material — into prosecutable acts.
A week later the president would make the bipartisan State of the Union pitch for that agenda, so this critique arrives at the moment of maximum legislative attention, framing what security professionals stand to lose before any text becomes law.
First-order effects
- Cybersecurity researchers face immediate legal exposure under the proposed language: per Errata Security, even retweeting or clicking a flagged link could be criminalized, chilling vulnerability research and public disclosure.
- Firms weighing participation in the threat-data-sharing program must weigh liability risk against the promised legal protection — the incentive structure depends on how narrowly 'hacking' gets defined.
Second-order effects
- If researchers self-censor, the market loses the informal discovery layer that surfaces breaches early, pushing firms toward more breach-disclosure incidents under the separate disclosure mandate and raising compliance costs.
- Congress drafting the bills must choose between industry demands for information sharing and the civil-liberties objections this critique amplifies, shaping which version can clear a bipartisan vote.
Third-order effects
- The pattern points toward codified federal control over hacking terminology and threat classification — later visible in the Cyber Incident Severity Schema — where government definitions of attack severity become the reference standard for liability across the private sector.
- Sustained expansion of executive cybersecurity authority establishes a template successors build on, as seen when [[a:881418|Biden planned a sweeping cybersecurity EO covering monitoring, software procurement, AI use, and punishment of foreign hackers]] a decade later.
The trend: U.S. cybersecurity policy is consolidating around expanding federal legal authority over hacking activity, with each administration layering new statutes, schemas, and orders onto the last.