MIT Technology Review Subscribe

Why Trump’s last-minute cyber order could have limited impact

One of the outgoing president’s last acts was to ask for more regulation and security for cloud computing companies.

The news: Hours before leaving the presidency, Donald Trump issued an executive order that requires American cloud computing companies to do more to verify the identities of their foreign customers. The stated aim is to help prevent hacking operations against the United States, although the timing and scope of the order mean it is surrounded by uncertainty.

What it says: The order instructs the Commerce Department to write new customer vetting regulations within six months for “infrastructure as a service” products offered by American tech giants such as Google, Microsoft, and Amazon. The new rules would set minimum customer identity verification standards and record-keeping requirements for cloud companies that sell to foreign customers. It includes sales made through resellers, which hackers have used in order to hide their identity before committing abuse. 

Advertisement

Late in the day: The timing of the executive order—which was announced on the evening of January 19, the end of Trump’s last full day in office—is exceptional. Not only did it arrive just as the curtains close on his presidency, but it comes in the wake of an extraordinary hacking campaign against American government agencies and major companies. US intelligence agencies say the Russian government is “likely” behind the espionage campaign, a charge Moscow denies. The full impact of the operation is still being calculated.

This story is only available to subscribers.

Don’t settle for half the story.
Get paywall-free access to technology news for the here and now.

Subscribe now Already a subscriber? Sign in
You’ve read all your free stories.

MIT Technology Review provides an intelligent and independent filter for the flood of information about technology.

Subscribe now Already a subscriber? Sign in

Uncertain impact: In a statement released last night, National Security Advisor Robert C. O’Brien said attacks of this nature “played a role in every cyber incident during the last four years, including the actions resulting in the penetrations of United States firms FireEye and SolarWinds.” But whether rules like this would actually stop foreign hackers in practice is a source of debate. And since the order was signed so late and will take months to have any impact, the question of whether it lasts in its current form falls to Joe Biden’s incoming administration. Any of Trump’s executive orders could be revoked or tweaked by the new president, who is expected to sign a wave of such orders quickly as he comes into office.

This is your last free story.
Sign in Subscribe now

Your daily newsletter about what’s up in emerging technology from MIT Technology Review.

Please, enter a valid email.
Privacy Policy
Submitting...
There was an error submitting the request.
Thanks for signing up!

Our most popular stories

Advertisement