Topic · 48 links
Deception Law
The law that decides when deceiving an adversary is lawful: in armed conflict, in peacetime between states, and at home when defenders run honeypots and police run stings.
The law of armed conflict has tolerated deception for as long as it has existed. Ruses such as camouflage, decoys and misinformation are lawful; perfidy, feigning a protected status such as surrender or a Red Cross emblem in order to kill or capture, is not. Most of the writing collected here asks where that old line falls in cyberspace. Does a spoofed ICRC domain count as misusing a protected emblem? Is a deepfake surrender message a ruse or perfidy? Can an autonomous system be deceived perfidiously at all, when the rule assumes a human who trusts? The ICRC's digital emblem project brings the question from theory into engineering.
Outside war the questions change. Between states, the debate is whether covert influence, disinformation and concealed election interference amount to a breach of sovereignty or prohibited intervention. At home, defenders who deploy deception meet ordinary law: wiretap statutes that may treat honeypot monitoring as interception, computer-crime law that limits beacons and hack-back, data-protection rules on what a decoy may record, and, for law enforcement, the entrapment and admissibility fights that followed the FBI's covert ANOM platform. The entries flag which pieces are dated and which were judged from an abstract or summary rather than the full text.
Start here
Six readings, best read in order. You'll start with the wartime rule that separates a lawful ruse from forbidden perfidy, see it applied to protective emblems online and to deceiving civilians, move to peacetime international law, come home to the legal exposure of running a honeypot, and finish with the ethics the law leaves open. The first four are also on the home page; the full set of paths is on Paths.
-
Emerging Technology and Perfidy in Armed Conflict
Start with the line everything else argues about: ruses are lawful, perfidy is not, and here is how that rule carries over to cyber operations.
Applies perfidy rules to emerging technologies including cyber, endorsing Tallinn Manual Rules 60–61 (perfidy prohibited, ruses permitted). Gives examples of cyber perfidy such as falsely claiming to be the ICRC or sending fake surrender messages, while unmarked military networks remain lawful.
-
Then the most concrete case of perfidy online: protective emblems and enemy indicators, and the gaps an adversary could exploit.
Argues IHL bans on misusing protective emblems and enemy indicators extend to domain names, email addresses and graphical symbols in cyberspace. Flags gaps (e.g., IP addresses lack recognized protected status) that adversaries could exploit to erode trust in humanitarian actors.
-
From deceiving soldiers to reaching civilians: what IHL forbids in information operations whatever deceptive method is used.
Misinformation aimed at enemy forces is a lawful ruse if non-perfidious, but IHL bars digital IO that encourage violations, spread terror, cause displacement or harm protected persons and facilities, whatever deceptive method is used.
-
'Virtual' Disenfranchisement: Cyber Election Meddling in the Grey Zones of International Law
Outside armed conflict the rules change. Concealing who is speaking can itself breach sovereignty.
Distinguishes lawful overt propaganda from covert troll operations that disguise their source; argues concealing origin can breach sovereignty and may be coercive because voters cannot evaluate the information.
-
Avoiding the Pitfalls of Operating a Honeypot
Back to domestic law and to practice: what operating a honeypot can expose its operator to.
Lawyer's guide: phone-home tech on attackers' systems 'almost certainly' violates CFAA/state laws; honeypot domains risk trademark claims; GDPR/ECPA limit data collection; entrapment concerns may deter prosecution.
-
Exploring the Ethics of Cyber Deception Technologies for Defensive Cyber Deception
Finish where the law runs out: consent, entrapment and harm to attackers, weighed as ethics rather than statute.
Identifies six issues (consent, entrapment, cyber perfidy, responsibility, attacker harm, internet safety) and engages the UK Computer Misuse Act in weighing attacker data collection; proposes ethical frameworks.
Everything in this topic
Grouped by subtopic, then by source type within each subtopic.
Nothing matches those filters. Try clearing one of them.
Perfidy and ruses 16
Where the law of armed conflict draws the line between a lawful ruse and prohibited perfidy, including misuse of protective emblems online.
-
Finds deepfakes may be perfidy under AP I art. 37 when they exploit protected status, but the ruse/perfidy line is ambiguous and IHL was not built for synthetic media; reform is needed but unlikely.
-
Deepfake Fight: AI-Powered Disinformation and Perfidy Under the Geneva Conventions
Analyzes how Geneva Conventions/AP I perfidy rules apply to AI-generated deception in armed conflict and recommends ways to strengthen governance of military deepfakes. Full text not reviewed.
-
Argues IHL bans on misusing protective emblems and enemy indicators extend to domain names, email addresses and graphical symbols in cyberspace. Flags gaps (e.g., IP addresses lack recognized protected status) that adversaries could exploit to erode trust in humanitarian actors.
-
Cyber Law Development and the United States Law of War Manual
Reviews the cyber chapter of the DoD Law of War Manual, noting its treatment of improper use of signs and its example that cyber attacks exploiting communications that open non-hostile relations (ceasefires, prisoner exchanges) are prohibited.
-
Cyber Perfidy, Ruse, and Deception
Examines how LOAC distinguishes permitted ruses from prohibited perfidy when applied to cyber operations and where the analogy breaks down. Full text not reviewed.
paywalled# -
Emerging Technology and Perfidy in Armed Conflict
Applies perfidy rules to emerging technologies including cyber, endorsing Tallinn Manual Rules 60–61 (perfidy prohibited, ruses permitted). Gives examples of cyber perfidy such as falsely claiming to be the ICRC or sending fake surrender messages, while unmarked military networks remain lawful.
-
Argues malware that masquerades as legitimate civilian software is a form of perfidy that should be prohibited, and proposes international agreements on detection cooperation, attribution and non-perfidious attack methods.
-
Argues tactical PSYOP and military deception must respect the perfidy ban, distinction and proportionality, but deserve liberal legal interpretation because they aim to influence rather than kill.
-
IHL's Lighthouse: Navigating Towards a Digital Emblem
Update on the digital emblem project (IETF/ITU standardization; decentralized, covertly verifiable). Stresses it is a signaling mechanism to be integrated into IHL, including existing misuse prohibitions.
-
Argues AI systems cannot form the 'belief,' 'confidence' or 'trust' that perfidy requires, so deceiving an autonomous system (e.g., abusing a white-flag signal it reads) falls outside the rule, leaving a legal gap.
-
Towards a 'Digital Emblem'? Five Questions on Law, Tech, and Policy
Proposes a digital emblem for medical/humanitarian assets and acknowledges the risk of falsely marking military infrastructure; says misuse is already prohibited and perfidious misuse may be a war crime (Rome Statute art. 8(2)(b)).
-
Identifying Protected Missions in the Digital Domain
Compares technical designs for a digital emblem and warns that the scale of potential misuse is far greater than for physical emblems, with weaker enforcement.
-
"Deepfakes" and the Law of Armed Conflict: Are They Legal?
Concludes deepfakes are lawful as ruses but unlawful when perfidious (e.g., fake surrender used to attack) or when they spread terror among civilians or breach protective obligations.
-
The New Era of Disinformation Wars: Does IHL Sufficiently Regulate the Use of Deepfakes?
Deepfakes can be lawful ruses or prohibited perfidy, but panic-inducing deepfakes aimed at civilians escape regulation because they are not 'attacks' causing physical harm.
-
Cyber Operations and the New Defense Department Law of War Manual: Initial Impressions
Notes the Manual permits certain deceptions, such as falsely using journalist credentials to feign civilian status for espionage or sabotage, and that such deceptions could readily be done by cyber means, with risks for journalists.
-
A Digital Emblem for Cyber Conflicts: Making Humanitarian Protection Machine-Readable
Addresses spoofing of a machine-readable emblem (attackers faking marks to shield offensive infrastructure) and proposes PKI-anchored authentication; cites Tallinn Manual 2.0 that perfidy and emblem abuse are prohibited online.
Information operations and civilians 5
What the law of armed conflict allows when deception, disinformation or deepfakes reach a civilian population.
-
Addressing the Gray Zone Between the Law of War and Information Operations
Information operations usually fall below the 'attack' threshold and are permitted; proposes prohibiting civilian-directed IO that threatens survival and is excessive relative to military advantage.
-
Emerging Need to Regulate Deepfakes in International Law: The Russo–Ukrainian War as an Example
Deepfakes can be lawful ruses under the Geneva Conventions, but IHL is insufficient; proposes protecting 'cognitive liberty' at national and regional level for wartime and peacetime.
-
Misinformation aimed at enemy forces is a lawful ruse if non-perfidious, but IHL bars digital IO that encourage violations, spread terror, cause displacement or harm protected persons and facilities, whatever deceptive method is used.
-
Upholding IHL in the Use of ICTs During Armed Conflicts – Workstream 6 Background Paper
State-consultation paper noting IO spreading terror are prohibited and that false information deliberately obstructing medical or humanitarian activities violates IHL; links to digital-emblem work.
-
Disinformation and Deepfakes in Conflict: The Neglected Opportunity of the UN OEWG Report
Criticizes the 2025 UN OEWG report for not clarifying how international law (perfidy/ruse, non-intervention, human rights) applies to state disinformation and deepfakes; few states have addressed it.
Peacetime international law 5
Sovereignty, non-intervention, countermeasures and state responsibility for deception below the threshold of armed conflict.
-
Argues fake-news and disinformation operations designed to make an electorate vote differently are coercive and therefore prohibited intervention.
-
'Virtual' Disenfranchisement: Cyber Election Meddling in the Grey Zones of International Law
Distinguishes lawful overt propaganda from covert troll operations that disguise their source; argues concealing origin can breach sovereignty and may be coercive because voters cannot evaluate the information.
-
Black Holes and Open Secrets: The Impact of Covert Action on International Law
Argues covert, unacknowledged state conduct distorts the evidence other states use to form legal judgments and weakens the development of international law. Linked to a Lawfare summary; full text not reviewed.
-
Hacking Back and International Law: An Irreconcilable Pair?
Active responses beyond one's network are hard to justify as countermeasures or self-defense because they require timely state attribution; necessity is ill-suited as a legislative basis.
-
Cyber Weapon Reviews under International Humanitarian Law: A Critical Analysis
Uses weaponized honeypots to illustrate the blurry offensive/defensive line and asks whether adding harmful payloads to decoys makes them weapons requiring legal review.
Authorities for influence operations 4
The domestic legal authorities under which governments run, and counter, deceptive cyber and influence operations.
-
Examines Title 10/Title 50 lines after Congress defined clandestine cyber activities as 'traditional military activities,' including Pentagon concerns over strategic deception and peacetime psychological operations.
-
Describes DOJ's use of trademark/counterfeiting law to seize 32 Doppelgänger domains impersonating news sites, plus AML statutes, FARA and sanctions, as legal tools against deceptive influence operations.
-
Argues LOAC-derived frameworks fit poorly with gray-zone cyber and influence operations; authorities and targeting approaches must differ for influence vs disruption objectives.
-
New Authorities for Military Cyber Operations and Surveillance, Including TMA
Reviews FY2019 NDAA cyber provisions, including language treating military deception and psychological operations as authorized activities and targeting Russian actors planting narratives.
Active defense and computer-crime law 6
Hacking back, beacons and honeypots under computer-crime statutes such as the CFAA, and proposals to change them.
-
Surveys 20 countries' laws on private active defense; analyzes honeypots and beacons, noting honeypots may implicate trap-and-trace prohibitions in many jurisdictions.
-
Spoiling for a Fight: Hacking Back with the Active Cyber Defense Certainty Act
Assesses ACDC's benefits and risks; dedicates a section to honeypots and discusses the Act's 'attributional technology' (beacon) carve-out and collateral-damage concerns.
-
Treats honeypots/tarpits as low-risk in-network measures and discusses ACDC's beacon carve-out, but argues CLOUD Act-style data access is a better route to attribution than hack-back.
-
Cyber Security Active Defense: Playing with Fire or Sound Risk Management?
Beaconing legality is a gray area; honeypots risk ECPA violations and downstream liability; deception by agents can breach attorney ethics rules (Model Rules 5.3, 8.4).
-
Avoiding the Pitfalls of Operating a Honeypot
Lawyer's guide: phone-home tech on attackers' systems 'almost certainly' violates CFAA/state laws; honeypot domains risk trademark claims; GDPR/ECPA limit data collection; entrapment concerns may deter prosecution.
-
Hackback Back: Assessing the Active Cyber Defense Certainty Act
Analyzes the ACDC Act's proposed CFAA defense, including its treatment of 'beacon' code in decoy files that phones home with forensic data when stolen.
Privacy and wiretap law 3
Whether watching intruders in a honeypot is interception, and who is liable for what they do there.
-
Deploying Honeypots and Honeynets: Issues of Liability
Examines civil and criminal liability of honeypot/honeynet administrators and the liability of attackers caught by them. Full text not reviewed.
paywalled# -
Liability and Ethics of Honeypots
Downstream liability if a honeypot is used to attack others is unresolved and set by state law; operators may face copyright liability if attackers distribute contraband, so outbound filtering is essential.
dated# -
Reports DOJ attorney Richard Salgado's view that honeypot monitoring can be interception under the Wiretap Act; banners, the computer-trespasser exception and provider exception may help, but a honeypot built to be attacked may not qualify.
dated#
Data protection 4
GDPR and other data-protection rules applied to honeypots, decoys and botnet defense.
-
Botnet Defense under EU Data Protection Law
Analyzes GDPR and ePrivacy constraints on botnet defense, including a dedicated scenario on honeypot use by an ISP and DNS sinkholing by a public authority.
paywalled# -
Deploying Honeypots and Honeynets: Issue of Privacy
Analyzes what data EU-based honeypot operators may lawfully collect and retain, distinguishing low- vs high-interaction and research vs production honeypots. Full text not reviewed.
paywalled# -
Legal Issues of Honeynet's Generations
Maps legal issues (privacy, liability, compliance) across honeynet data control, capture, collection and analysis functions under EU law. Full text not reviewed.
paywalled# -
Proactive Detection of Security Incidents: Honeypots
EU agency study of honeypot tools with a short legal section flagging liability if a honeypot is used in attacks and advising CERTs to obtain jurisdiction-specific legal advice.
dated#
Stings and entrapment 4
Covert law-enforcement platforms and online stings, and the entrapment and admissibility challenges they draw.
-
Discusses Germany's Federal Constitutional Court upholding use of ANOM evidence and criticizes its limited scrutiny of foreign law-enforcement deception and data-location findings.
preprint# -
Entrapped on the Web? Applying the Entrapment Defense to Cases Involving Online Sting Operations
Identifies factors courts use for online-sting entrapment claims: persistence of officer contact, length of relationship, and suspect reluctance. Based on the abstract; full text not reviewed.
paywalled# -
AN0M in the High Court – CD v Commonwealth [2025] HCA 37
Explains the High Court's unanimous upholding of legislation retrospectively validating ANOM evidence as an evidentiary provision, not a usurpation of judicial power.
-
Operation Trojan Shield May Be Clever, but Is It Outrageous?
Asks whether the FBI's creation and control of the ANOM encrypted app crosses into 'outrageous government conduct' barring convictions under Ninth Circuit due-process precedent. Based on a summary; full text not reviewed.
paywalled#
Ethics of defensive deception 1
What defensive deception owes attackers and bystanders where the law is silent: consent, harm and responsibility.
-
Exploring the Ethics of Cyber Deception Technologies for Defensive Cyber Deception
Identifies six issues (consent, entrapment, cyber perfidy, responsibility, attacker harm, internet safety) and engages the UK Computer Misuse Act in weighing attacker data collection; proposes ethical frameworks.