> launch attacks on critical infrastructure from outside the country
First, "outside the the country" is a nebulous thing. For example, I suspect that a NSA and/or GCHQ trick is to simply route traffic[1] so it flows over an international fiber so it becomes "foreign" in origin. The bad BGP routes that redirected traffic through
More importantly, the executive order does not reference "critical infrastructure" (itself a vary vague term that includes "safety" and "security" (unqualified)). Instead, it references[2] "critical infrastructure sector".
(A) harming, or otherwise significantly compromising
the provision of services by, a computer or network
of computers that support one or more entities in a
critical infrastructure sector;
Which it defines as: (d) the term "critical infrastructure sector" means any
of the designated critical infrastructure sectors
identified in Presidential Policy Directive 21
PPD-21's list[3] of the "Designated Critical Infrastructure Sectors" includes: Commercial Facilities
Communications
Financial Services
Government Facilities
Information Technology
It would not take much imagination at all to construe various petty offenses, legitimate (but disliked) use cases, and simple accidents as "attacks" or "disruption" of some insignificant government service. Is screen scraping a business's website too fast count as "harming" a "commercial facility" that should allow accounts to be frozen without due process?The vagueness of this is terrifying.
--
[1] http://research.dyn.com/2013/11/mitm-internet-hijacking/
[2] https://www.whitehouse.gov/the-press-office/2015/04/01/execu...
[3] https://www.whitehouse.gov/the-press-office/2013/02/12/presi...