Despite privacy concerns, CISA bill poised for passage
america.aljazeera.com
Despite privacy concerns, CISA bill poised for passage
1–10 of 95 posts
Re: Despite privacy concerns, CISA bill poised for passage
#2Re: Despite privacy concerns, CISA bill poised for passage
#3Once again we can thank Dianne Feinstein for this. How did she get re-elected again? Was it gerrymandering or did her NSA buddies, which she keeps propping up, hack the poorly secured voting machines?
Re: Despite privacy concerns, CISA bill poised for passage
#4Is the concern that Google is going to hand over your browser history under the guise of CISA?
Re: Despite privacy concerns, CISA bill poised for passage
#5Once again we can thank Dianne Feinstein for this. How did she get re-elected again? Was it gerrymandering or did her NSA buddies, which she keeps propping up, hack the poorly secured voting machines?
I really really dislike her, but it totally makes sense that she is basically invulnerable within her senate seat.
Re: Despite privacy concerns, CISA bill poised for passage
#6Once again we can thank Dianne Feinstein for this. How did she get re-elected again? Was it gerrymandering or did her NSA buddies, which she keeps propping up, hack the poorly secured voting machines?
Feinstein is a senator. How could gerrymandering have anything to do with her election?
Re: Despite privacy concerns, CISA bill poised for passage
#7Earlier quoted context omitted.
Feinstein is a senator. How could gerrymandering have anything to do with her election?
(the answer, of course, is that it can't)
The OP is hinting through his username that somehow the Mt. Gox bitcoin exchange was involved.
Re: Despite privacy concerns, CISA bill poised for passage
#8Setting aside any hatred for the government and mistrust, how does Company A share information with Company B (or the FBI) about how a hacker got into their networks? Is the concern that Google is going to hand over your browser history under the guise of CISA?
This is pretty typical for bills in US Federal Law: Congress enacts a relatively broad statute that establishes principles relied upon in a later "rulemaking" process; the statute will delegate to specific agencies the privilege of making those rules.
Re: Despite privacy concerns, CISA bill poised for passage
#9https://www.govtrack.us/congress/bills/114/s754/text
There are no amendments to CISA that I can find (CISPA collected quite a few amendments, some of which were very relevant to HN, before the bill eventually died).
I read CISA so you don't have to! (You still should). Here's a summary:
There are three particularly important defined concepts:
>, which means "unauthorized activity" that might plausibly compromise confidentiality, integrity, or availability, but that isn't either protected speech or a mere ToS violation.
>, the most important concept in the bill, which is, roughly: logs of recon activity, exploit techniques, vulnerability data, account hijack techniques (I think this bill actually tries to capture the notion of an XSS), bot C&Cs, damage reports on attacks, and anything else related to security and not already prohibited by law.
>, roughly, things that stop or monitor attacks.
"Defensive measures" is a confusing concept in the bill. For awhile, it was thought that CISA would authorize something akin to hack-back privilege for private entities; it does not. Meanwhile, defensive measures are probably already lawfully shareable. Anyways, the bill allows you to share both indicators and defenses.
The bill allows the USG to share indicators and defensive measures with private entities, and vice versa.
So then:
Section 3 of the bill authorizes the USG to share stuff with private entities. This isn't the part of the bill that concerns people (we all probably want more sharing from USG to private entities; for instance, that's what we're saying every time we demand NSA fork over its zero-days).
Section 4 authorizes private entities to share with the USG. Here's what it allows:
(a) You can monitor your own systems, or those of people who give you written authorization, for any security purpose, notwithstanding any previous limitation on monitoring. Even if ECPA or student records law says you shouldn't monitor, if you're doing it to deal with security threats, you're now allowed to.
(b) You can run your own defensive measures, or defensive measures on people who give you written authorization. Ok then.
(c) You can share indicators and defenses with the USG, and receive them from the USG so long as you comply with their sharing restrictions.
(d) You have to keep the data secure, you can't share it willy-nilly, and before you share anything, you have to (1) review it for PII and (2) anonymize any PII you find.
Sec 4 (d) (4) has problematic language that allows, say, Facebook to provide written authorization to the USG to prosecute based on shared indicators; in theory, they can do this even if the prosecution they're going to launch isn't related to a computer crime, but just happens to be illuminated by the indicator Facebook shared. (But remember: Facebook can't share under CISA unless they have a bona fide cybersecurity purpose for doing so).
Section 5 has a bunch of rulemaking authority in it, but buried in it is Sec 5 (d) (5) (a), which gives all the purposes FedGov is allowed to use indicators for:
* any security purpose * attributing threats * determining whether threats are foreign * preventing immediate disaster/harm (iv) * stopping child sex trafficking (v) * stopping major felonies, espionage, trade secret theft (vi)
(iv), (v), and (vi) are major problems; these aren't cybersecurity purposes at all, but rather a sort of "these crimes are so bad that we're allowed to repurpose indicators to deal with them", which, maybe fair enough (except for trade secret theft), but still, not OK that new investigative capabilities are buried in the middle of a cybersecurity bill.
And that's it.
Re: Despite privacy concerns, CISA bill poised for passage
#10Earlier quoted context omitted.
(the answer, of course, is that it can't)
Passive gerrymandering. California's state lines were intentionally not redrawn before the last election, so as to not absorb Republican voters from Nevada, which would have diluted the democratic majority in California and made things tough for Feinstein. The OP is hinting through his username that somehow the Mt. Gox bitcoin exchange was involved.