UPDATED 19:47 EST / MARCH 27 2023

SECURITY

Biden administration bans government use of commercial spyware that may pose a security risk

President Joe Biden signed an executive order today banning government agencies from using commercial spyware deemed to present a national security risk to the United States.

The order imposes a ban on agencies using such commercial tools “when they determine, based on credible information, that such use poses significant counterintelligence or security risks to the United States government or that the commercial spyware poses significant risks of improper use by a foreign government or foreign person.”

For the purposes of the executive order, the definition of risk includes commercial spyware that may pose counterintelligence or security risks when a foreign government or person has used the software to gain or attempt to gain access to U.S. government computers.

Also banned is software from vendors that maintain, transfer or use data from spyware without authorization from the end-user or the U.S. government, has disclosed or intends to disclose nonpublic government information, is under the direct control of a foreign government or person engaging in intelligence activities against the U.S government, or may pose a risk of improper use by a foreign government or person.

Upon signing the statement, administration officials told the media that the ban was imposed partly because about 50 U.S. government personnel in at least 10 countries were infected or targeted by such spyware, although no further details were provided.

The Wall Street Journal reported that senior administration officials also said the order is intended to grapple with the rapidly growing international marketplace of cyber intrusion tools that can break into someone’s phone — often with malware that doesn’t require a victim to click on a malicious link or attachment.

There are likely multiple companies that provide such services, but there’s one very well-known company infamous for being able to hack phones with no user input: Israel’s NSO Group. The mention of government personnel being hacked also points to NSO, whose Pegasus software was allegedly used to hack State Department employees based in Uganda in 2021.

The fact that officials didn’t name NSO is surprising, given that parts of the U.S. government haven’t been shy in targeting the company before. The Department of Commerce announced sanctions against NSO in November 2021, saying that the company provides spyware used by foreign governments to target government officials, journalists, businesspeople, activists, academics and embassy workers maliciously.

Although the executive order bans the general use of spyware tools such as those from NSO, commercial spyware can still be purchased with approval on a case-by-case basis. Vendors that find themselves banned through relationships with foreign governments can be considered again if they cancel licensing agreements with governments known to violate human rights.

Photo: Gage Skidmore/Flickr

A message from John Furrier, co-founder of SiliconANGLE:

Support our mission to keep content open and free by engaging with theCUBE community. Join theCUBE’s Alumni Trust Network, where technology leaders connect, share intelligence and create opportunities.

  • 15M+ viewers of theCUBE videos, powering conversations across AI, cloud, cybersecurity and more
  • 11.4k+ theCUBE alumni — Connect with more than 11,400 tech and business leaders shaping the future through a unique trusted-based network.
About SiliconANGLE Media
SiliconANGLE Media is a recognized leader in digital media innovation, uniting breakthrough technology, strategic insights and real-time audience engagement. As the parent company of SiliconANGLE, theCUBE Network, theCUBE Research, CUBE365, theCUBE AI and theCUBE SuperStudios — with flagship locations in Silicon Valley and the New York Stock Exchange — SiliconANGLE Media operates at the intersection of media, technology and AI.

Founded by tech visionaries John Furrier and Dave Vellante, SiliconANGLE Media has built a dynamic ecosystem of industry-leading digital media brands that reach 15+ million elite tech professionals. Our new proprietary theCUBE AI Video Cloud is breaking ground in audience interaction, leveraging theCUBEai.com neural network to help technology companies make data-driven decisions and stay at the forefront of industry conversations.