Calling it "revenge hacking" is a pretty major misrepresentation. The proposed legislation basically makes a company exempt from hacking laws if they are doing it to protect their data from someone else who has broken those laws, or assist in forensics.


This is pretty important and could have a big positive impact on the field of infosec. Without legislation like this, if your organization had a data breach, and you had a way to get that data out of the hands of the intruder, you wouldn't be legally able to act upon it, as you'd be illegally accessing someone's system yourself.

This basically says "if you had a data breach, you can try to identify the intruder or neutralize the data".


