Biden signs an EO limiting US agencies' use of hacking tools from companies that are linked to human rights abuses or are deemed to pose national security risks
The new restriction adds the provenance and conduct of offensive-tool suppliers to that arc. It matters because agencies' use of hacking capabilities now faces a screen beyond technical utility alone.
First-order effects
U.S. agencies must avoid hacking tools supplied by companies connected to human-rights abuses or judged to create national-security risk, narrowing the eligible vendor pool.
Affected tool makers face a direct loss of access to agency customers unless they can satisfy the government's risk assessment.
Second-order effects
Procurement teams and security buyers will need stronger supplier due diligence, pushing vendors to document ownership, customers, and compliance practices alongside tool performance.
Competitors with cleaner risk profiles can gain an advantage in federal sales, while agencies may need to reassess tool availability and sourcing options.
Third-order effects
If applied consistently, the policy would make human-rights and national-security exposure a durable qualification criterion in the market for dual-use cyber capabilities.
It points toward a federal cyber strategy in which procurement, network protection, and controls on sensitive technologies are increasingly treated as connected security levers.
The trend: Governments are turning access to dual-use cyber technology into a procurement-controlled security boundary, not merely a technical buying decision.
BREAKING: Biden White House issues executive order on commercial spyware. Also confirms over 50+ USG personnel suspected targeted w/#Pegasus Huge deal, let me break the new #SpywareEO down. 1/ https://twitter.com/...
2/ Investment fuels spyware proliferation. A lot of that is predicated on the juicy dream of the USG as the ultimate customer. The new #SpywareEO says to mercenary spyware vendors & backers: decision time. Either stop contributing to proliferation right now, or lose our number.
this #spyware order is result of @citizenlab @AmnestyTech forensic human rights work, major advocacy from @accessnow & others, attention from @UN_SPExperts, groundbreaking reporting from @FbdnStories & @skirchy. kudos to @POTUS for this, esp the call for global norms. #Pegasus ht…
19/ Remarkable to see @POTUS and the White House leaning this hard into the issue. This is what global leadership looks like. It also would not have happened without tremendous work from civil society and many brave #spyware victims coming forward year. after. year.
As commercial spyware becomes increasingly widespread, the US needs to take additional security measures to safeguard Americans. I'm encouraged by @POTUS's Executive Order to safeguard national security & protect our most sensitive information from nefarious foreign actors. https…
12/ Takeaway: The #SpywareEO is the first comprehensive action by any government on #spyware. It was clearly drafted to pump the breaks on proliferation & is written with a good understanding the slippery nature of the industry. It closes many loopholes.
We strongly support the @whitehouse effort to curb the abuse of out of control spyware. The targeting of journalists, human rights activists, and government personnel needs to stop. We'll continue to do our part to hold NSO accountable for their abuses. https://www.whitehouse.gov…
What's missing: more action from @whitehouse to end the misuse & abuse of surveillance tech domestically in the USA. How will the USA lead at home so we can lead by “the power of our example” abroad, @POTUS? Will you propose or support a data protection act? cc @AmbRice46 @whcos …
Never thought I'd see the day. Of everything I covered/outed at the @nytimes the proliferation of spyware is what I am most proud of. This is a huge deal and should put a freeze on US investment in surveillance technology like NSO Group/Pegasus. #thisishowtheytellmetheworldends h…
NEW: The Biden administration today issued a new executive order banning federal agencies from using commercial spyware (think NSO, Candiru, etc). The devil is in the details but this is a start. Although I see it as a bit of cyber protectionism. https://techcrunch.com/...
Glad to see the US government moving to ban commercial spyware entities responsible for egregious human rights violations and US-citizen targeting such as Predator-maker Cytrox. #Predator #υποκλ οπες https://www.whitehouse.gov/...
US confirming widespread #spyware targeting. ✔️50+ US Gov personnel ✔️10+ countries ✔️Multiple continents Takeaway: Spyware proliferation= critical national security problem for the US. Also, cases are probably tip of the hackberg. By @kevincollier https://www.nbcnews.com/... htt…
18/ I expect the #SpywareEO to immediately chill investor comfort with reckless spyware vendors... Some prospectuses are probably hitting the shredder right now. But also need to see other direct disincentives for US-based investors that fuel harmful spyware proliferation.
I don't think there's one single way to “solve” the threat of commercial spyware, such as Pegasus and Predator. The “solution” will require both technology and policy, and today's EO from @POTUS tells me we're moving in the right direction. https://www.whitehouse.gov/...
Officials declined to identify the hacked victims but said some were senior-ranking and that they were located in at least 10 countries on multiple continents. The tally is expected to increase—perhaps dramatically—as the admin continues to investigate. https://www.wsj.com/...
NEWS: Commercial hacking tools have compromised at least 50 U.S. personnel stationed overseas, officials say, far more than previously known. The revelation comes as Biden signs new executive order limiting the use of spyware across the federal government. https://www.wsj.com/...