ABRACADABRA Labs Resource directory

Topic · 48 links

Deception Law

The law that decides when deceiving an adversary is lawful: in armed conflict, in peacetime between states, and at home when defenders run honeypots and police run stings.

The law of armed conflict has tolerated deception for as long as it has existed. Ruses such as camouflage, decoys and misinformation are lawful; perfidy, feigning a protected status such as surrender or a Red Cross emblem in order to kill or capture, is not. Most of the writing collected here asks where that old line falls in cyberspace. Does a spoofed ICRC domain count as misusing a protected emblem? Is a deepfake surrender message a ruse or perfidy? Can an autonomous system be deceived perfidiously at all, when the rule assumes a human who trusts? The ICRC's digital emblem project brings the question from theory into engineering.

Outside war the questions change. Between states, the debate is whether covert influence, disinformation and concealed election interference amount to a breach of sovereignty or prohibited intervention. At home, defenders who deploy deception meet ordinary law: wiretap statutes that may treat honeypot monitoring as interception, computer-crime law that limits beacons and hack-back, data-protection rules on what a decoy may record, and, for law enforcement, the entrapment and admissibility fights that followed the FBI's covert ANOM platform. The entries flag which pieces are dated and which were judged from an abstract or summary rather than the full text.

Start here

Six readings, best read in order. You'll start with the wartime rule that separates a lawful ruse from forbidden perfidy, see it applied to protective emblems online and to deceiving civilians, move to peacetime international law, come home to the legal exposure of running a honeypot, and finish with the ethics the law leaves open. The first four are also on the home page; the full set of paths is on Paths.

  1. Emerging Technology and Perfidy in Armed Conflict

    Start with the line everything else argues about: ruses are lawful, perfidy is not, and here is how that rule carries over to cyber operations.

    Applies perfidy rules to emerging technologies including cyber, endorsing Tallinn Manual Rules 60–61 (perfidy prohibited, ruses permitted). Gives examples of cyber perfidy such as falsely claiming to be the ICRC or sending fake surrender messages, while unmarked military networks remain lawful.

  2. The Misuse of Protected Indicators in Cyberspace: Defending a Core Aspect of International Humanitarian Law

    Then the most concrete case of perfidy online: protective emblems and enemy indicators, and the gaps an adversary could exploit.

    Argues IHL bans on misusing protective emblems and enemy indicators extend to domain names, email addresses and graphical symbols in cyberspace. Flags gaps (e.g., IP addresses lack recognized protected status) that adversaries could exploit to erode trust in humanitarian actors.

  3. The Legal Boundaries of (Digital) Information or Psychological Operations Under International Humanitarian Law

    From deceiving soldiers to reaching civilians: what IHL forbids in information operations whatever deceptive method is used.

    Misinformation aimed at enemy forces is a lawful ruse if non-perfidious, but IHL bars digital IO that encourage violations, spread terror, cause displacement or harm protected persons and facilities, whatever deceptive method is used.

  4. 'Virtual' Disenfranchisement: Cyber Election Meddling in the Grey Zones of International Law

    Outside armed conflict the rules change. Concealing who is speaking can itself breach sovereignty.

    Distinguishes lawful overt propaganda from covert troll operations that disguise their source; argues concealing origin can breach sovereignty and may be coercive because voters cannot evaluate the information.

  5. Avoiding the Pitfalls of Operating a Honeypot

    Back to domestic law and to practice: what operating a honeypot can expose its operator to.

    Lawyer's guide: phone-home tech on attackers' systems 'almost certainly' violates CFAA/state laws; honeypot domains risk trademark claims; GDPR/ECPA limit data collection; entrapment concerns may deter prosecution.

  6. Exploring the Ethics of Cyber Deception Technologies for Defensive Cyber Deception

    Finish where the law runs out: consent, entrapment and harm to attackers, weighed as ethics rather than statute.

    Identifies six issues (consent, entrapment, cyber perfidy, responsibility, attacker harm, internet safety) and engages the UK Computer Misuse Act in weighing attacker data collection; proposes ethical frameworks.

Everything in this topic

Grouped by subtopic, then by source type within each subtopic.

Perfidy and ruses 16

Where the law of armed conflict draws the line between a lawful ruse and prohibited perfidy, including misuse of protective emblems online.

Information operations and civilians 5

What the law of armed conflict allows when deception, disinformation or deepfakes reach a civilian population.

Peacetime international law 5

Sovereignty, non-intervention, countermeasures and state responsibility for deception below the threshold of armed conflict.

Authorities for influence operations 4

The domestic legal authorities under which governments run, and counter, deceptive cyber and influence operations.

Active defense and computer-crime law 6

Hacking back, beacons and honeypots under computer-crime statutes such as the CFAA, and proposals to change them.

Privacy and wiretap law 3

Whether watching intruders in a honeypot is interception, and who is liable for what they do there.

  • Deploying Honeypots and Honeynets: Issues of Liability

    Examines civil and criminal liability of honeypot/honeynet administrators and the liability of attackers caught by them. Full text not reviewed.

    paywalled
  • Liability and Ethics of Honeypots

    Downstream liability if a honeypot is used to attack others is unresolved and set by state law; operators may face copyright liability if attackers distribute contraband, so outbound filtering is essential.

    dated
  • Use a Honeypot, Go to Prison?

    Reports DOJ attorney Richard Salgado's view that honeypot monitoring can be interception under the Wiretap Act; banners, the computer-trespasser exception and provider exception may help, but a honeypot built to be attacked may not qualify.

    dated

Data protection 4

GDPR and other data-protection rules applied to honeypots, decoys and botnet defense.

  • Botnet Defense under EU Data Protection Law

    Analyzes GDPR and ePrivacy constraints on botnet defense, including a dedicated scenario on honeypot use by an ISP and DNS sinkholing by a public authority.

    paywalled
  • Deploying Honeypots and Honeynets: Issue of Privacy

    Analyzes what data EU-based honeypot operators may lawfully collect and retain, distinguishing low- vs high-interaction and research vs production honeypots. Full text not reviewed.

    paywalled
  • Legal Issues of Honeynet's Generations

    Maps legal issues (privacy, liability, compliance) across honeynet data control, capture, collection and analysis functions under EU law. Full text not reviewed.

    paywalled
  • Proactive Detection of Security Incidents: Honeypots

    EU agency study of honeypot tools with a short legal section flagging liability if a honeypot is used in attacks and advising CERTs to obtain jurisdiction-specific legal advice.

    dated

Stings and entrapment 4

Covert law-enforcement platforms and online stings, and the entrapment and admissibility challenges they draw.

Ethics of defensive deception 1

What defensive deception owes attackers and bystanders where the law is silent: consent, harm and responsibility.