Live data from Hacker News

Despite privacy concerns, CISA bill poised for passage

america.aljazeera.com

51–60 of 95 posts

Re: Despite privacy concerns, CISA bill poised for passage

#51
post #44
post #39

Earlier quoted context omitted.

Again: they can't be prosecuted for sharing , for monitoring , or for receipt of information. This is statutory language and the words matter. If there's an authority under which Chrysler can be prosecuted for having vulnerabilities (spoiler: I don't believe there is), CISA doesn't change any of that. Certainly, there's no clear linkage between CISA sharing and a private actor's ability to sue Chrysler for torts emer…

It is probably impossible for a lay person to understand how a court is likely to interpret statutory language. I prefer my analysis from folks who devote a substantial amount of time to it. Marcy compares the CISA liability protections to the very similar Section 314(b) of the Patriot Act financial information sharing liability safe harbor. It seems at least plausible that they will operate in a similar fashion if C…

But that statute has also never been used to shield vendors from lawsuit or prosecution for vulnerabilities!

Re: Despite privacy concerns, CISA bill poised for passage

#52
post #43
post #28

Earlier quoted context omitted.

This is a blog post that makes two very broad claims: 1. That Chrysler can exploit CISA to avoid liability for vulnerabilities in their cars simply by sharing the flaws with the USG as an "indicator". 2. That the USG can use CISA to collude with private companies to avoid warrant requirements and spy on their customers. Both of these points are, I think, false. I've linked upthread to the text of the bill and provide…

I'm not sure why you were downvoted for a reasonable post citing original sources (I upvoted you to try to correct that). I expect I will disagree with you about the desirability of CISA, just as we disagreed years ago about CISPA, but enjoy your posts on the topic nevertheless. They make thoughtful and reasonable points. Even if you end up on the wrong side. :)

Just to be clear: CISA is bad. I oppose it.

Re: Despite privacy concerns, CISA bill poised for passage

#53
post #39
post #35

Earlier quoted context omitted.

I could bug Marcy for an answer. I will do totally inadequate job of defending her analysis compared to her. It seems relatively simple to read this passage in the following way: Let's say a major car company decided to leave open a port with a remote code execution vulnerability on their cars. Let's say this car company discovered this port was being exploited and informs the NSA of affected vehicles IMEI numbers, I…

Again: they can't be prosecuted for sharing , for monitoring , or for receipt of information. This is statutory language and the words matter. If there's an authority under which Chrysler can be prosecuted for having vulnerabilities (spoiler: I don't believe there is), CISA doesn't change any of that. Certainly, there's no clear linkage between CISA sharing and a private actor's ability to sue Chrysler for torts emer…

Because the government has NEVER demonstrated any behavior in deliberate (expanded) interpretation of the law to further their interests.

The lengths taken to interpret "torture" for instance. It used to be that we have a fairly logical, common sense interpretation of things but I think those days are gone. I mean, unlimited data should really mean unlimited data not subject to some arbritary cap or throttling .

Re: Despite privacy concerns, CISA bill poised for passage

#54
One of the things that concerns me about this debacle is that ongoing CISA controversy will eliminate the possibility of legislative support for information sharing for good. I appreciate that there are privacy concerns in CISA, however, it is very important to the security field that sharing of intelligence indicators become more plainly safe from a legal perspective.

'Indicators' usually consist of information about external actors and organizations that are relevant to intrusion detection, for example, the most common types of indicators are domains used for C&C and hashes of malicious files. It is difficult to construe a privacy violation from these types of indicators. There are concerns about certain providers who may have indicators relevant to their users - for example, some providers might share the names of otherwise legitimate user accounts which have been compromised as these are often used to send spam that ought to be blocked. However, in general, cyber intel indicators do not involve sensitive information about users.

Right now a great deal of organizations are not participating in public or private threat information sharing because of concerns over liability and compliance, and this significantly impedes defense by letting threat actors get away with infrastructure and tool reuse that ideally should reveal them. These acts originated as an attempt to correct that. It looks alarmingly like many advocacy organizations want to keep it this way for good.

I don't want to be painted as anti-privacy and I would say that I'm not, but the principal goal of this legislation is not to send your data to the NSA, it's to help me do my job. I hope that the internet community will have the foresight to try to resolve the specific problems with current legislation, and not to entirely prevent information sharing.

Re: Despite privacy concerns, CISA bill poised for passage

#55
post #41
post #17

Earlier quoted context omitted.

I'm never super happy with EFF's advocacy (I think they do good and important legal and technical work but I'm almost always unhappy with how they represent policy to the public). I've been uniformly discouraged by FFTF's advocacy, which I find goes way past "misleading" into "straight up dishonest", such as their recent piece that strongly suggested Facebook supported CISA (a fact not in evidence, for whatever that'…

If you think they do important work why do you consider it your duty to go on every advocacy thread and say how you disagree with their tactics ? How does your tactic of constantly discouraging people from advocating for these issues serve your stated shared goals better than EFF's?

Probably for the same reason that you clearly feel it's your duty to repeat this same comment on all those threads. I'm guessing it's a shared feeling of someone being wrong on the Internet.

I'm really not sure what's so complicated about this.

I have a hard time thinking of legal support EFF has provided that I don't support. If EFF was just legal support, I'd be a donor.

I think their technical work is mostly good; it would be entirely good but for the egregiously terrible Secure Messaging Scorecard --- but hey, that scorecard won me a $1000 bet against Matt Green, so some good came out of it.

Virtually all of EFF's policy advocacy, I find untrustworthy. I don't even believe they take it seriously. I think they play to the crowds, in the hope that the retweets and upvotes will generate more donations.

Is it really that hard for you to see that as a plausible narrative? I'm not asking you to agree with it.

Re: Despite privacy concerns, CISA bill poised for passage

#56
post #17

Earlier quoted context omitted.

I'm never super happy with EFF's advocacy (I think they do good and important legal and technical work but I'm almost always unhappy with how they represent policy to the public). I've been uniformly discouraged by FFTF's advocacy, which I find goes way past "misleading" into "straight up dishonest", such as their recent piece that strongly suggested Facebook supported CISA (a fact not in evidence, for whatever that'…

> Example from today's AMA is FFTF's claim that CISA "exempts itself from FOIA", making it impossible to challenge in court: they're referring to Sec 4 (d) (4) (b), which exempts from FOIA individual shared indicators, which of course must be the case, because indicators are things like compromised account names and passwords. That's all the law exempts from disclosure. Nope. The bill clearly defines "cyber threat in…

I'm not sure who you're arguing with. Are there people advocating for CISA by saying it's only about metadata? I'm not one of those people.

Re: Despite privacy concerns, CISA bill poised for passage

#57

Dianne Feinstein again? Wasn't she Really angry some time ago when it was revealed the NSA spied on Congress? Does privacy apply only to Congress and not to ordinary citizens? Ms. Feinstein peaked before the computer was invented. It is time this 82-year-old was retired and we get in charge someone who understands technology. How does this woman keep getting elected?

But this industry isn't ageist at all, no...

Re: Despite privacy concerns, CISA bill poised for passage

#58
post #39

Earlier quoted context omitted.

Again: they can't be prosecuted for sharing , for monitoring , or for receipt of information. This is statutory language and the words matter. If there's an authority under which Chrysler can be prosecuted for having vulnerabilities (spoiler: I don't believe there is), CISA doesn't change any of that. Certainly, there's no clear linkage between CISA sharing and a private actor's ability to sue Chrysler for torts emer…

Because the government has NEVER demonstrated any behavior in deliberate (expanded) interpretation of the law to further their interests. The lengths taken to interpret "torture" for instance. It used to be that we have a fairly logical, common sense interpretation of things but I think those days are gone. I mean, unlimited data should really mean unlimited data not subject to some arbritary cap or throttling .

Non-falsifiable argument is non-falsifiable.

Re: Despite privacy concerns, CISA bill poised for passage

#59
post #3

Earlier quoted context omitted.

Feinstein is a senator. How could gerrymandering have anything to do with her election?

Have you seen the shape of California? I mean, it's implausible at best. :-) But seriously, it's kind of fun to imagine what life would be like if U.S. states were shaped like House districts. Maryland is probably the closest, geometrically.

Have you seen the shape of California?

Did you know that Reno has been gerrymandered so far it's now west of Los Angeles? That has to be some kind of conspiracy. Otherwise it would just be impossible.

Re: Despite privacy concerns, CISA bill poised for passage

#60
post #3

Earlier quoted context omitted.

Feinstein is a senator. How could gerrymandering have anything to do with her election?

Have you seen the shape of California? I mean, it's implausible at best. :-) But seriously, it's kind of fun to imagine what life would be like if U.S. states were shaped like House districts. Maryland is probably the closest, geometrically.

[deleted]
Post reply on HN