Live data from Hacker News

Obama Signs CISA Bill into Law

npr.org

41–50 of 230 posts

Re: Obama Signs CISA Bill into Law

#42
post #14

I believe that CISA is mostly about changes within the government itself about sharing data between agencies. It seems to interface with the non-government world insofar as it lets companies share their data with government agencies without getting sued. I do NOT believe it contains any further provisions requiring private companies to share their data without a warrant. Can someone tell me if I’m reading it correctl…

It also says that non-related personal information will be removed from the shared data, and (surprise!) that if someone's personal data were accidentally (I presume) shared then the feds must notify that person of the breach. That's actually a positive in this bill.

Re: Obama Signs CISA Bill into Law

#43

How this happened [1]: In a late-night session of Congress, House Speaker Paul Ryan announced a new version of the “omnibus” bill, a massive piece of legislation that deals with much of the federal government’s funding. It now includes a version of CISA as well. Lumping CISA in with the omnibus bill further reduces any chance for debate over its surveillance-friendly provisions, or a White House veto. And the latest…

It's useful to note that Paul Ryan gained his position by saying shady backroom deals like this, plus giving Congress almost no time to read and think about the bill themselves, were the exact things he promised to stop. So his very first act as speaker is to break every single promise he made to become speaker.

I am Jack's complete lack of surprise

Re: Obama Signs CISA Bill into Law

#44
post #42
post #14

I believe that CISA is mostly about changes within the government itself about sharing data between agencies. It seems to interface with the non-government world insofar as it lets companies share their data with government agencies without getting sued. I do NOT believe it contains any further provisions requiring private companies to share their data without a warrant. Can someone tell me if I’m reading it correctl…

It also says that non-related personal information will be removed from the shared data, and (surprise!) that if someone's personal data were accidentally (I presume) shared then the feds must notify that person of the breach . That's actually a positive in this bill.

https://www.govtrack.us/congress/bills/114/hr2029/text/eah#l...

Re: Obama Signs CISA Bill into Law

#45
CISA passed the Senate with almost 3:1 bipartisan support in October.

PCNA, the House's (worse) version of CISA, passed with similar margins in April.

Obama has publicly supported the bill all year.

As much as HN and Twitter wants to believe CISA was enacted in some shady backroom deal, the process that actually occurred, including publicly available amendments and months-long review, is pretty close to "Schoolhouse Rocks".

The debate on CISA was over. Thankfully. The only debate left was how close CISA would come to PCNA, with its broader law enforcement ties and vaguer language (EFF claims PCNA would have in some cases authorized large private companies to "hack back" computers they believed had been trying to hack them). Instead, Senate's CISA is the law of land almost verbatim to what they passed --- in a drawn out, public process --- in October.

Later:

Someone downthread asked for a summary of the bill. I did my best to strip the legalese out of it:

https://news.ycombinator.com/item?id=10763827

Re: Obama Signs CISA Bill into Law

#46

Earlier quoted context omitted.

Can someone explain why/how the CISA portion of the bill can or can't be removed later?

What are you asking exactly? In order to be attached to the bill, the amendment must be approved by a majority of the chamber. So that means it's already garnered support from congress, and congress is unlikely to take it off again before voting on the bill as a whole. Once it passes congress, the only way for it to be defeated would be for the president to veto the enormous budget bill based only on the amendment, w…

He has in fact publicly campaigned in favor of CISA.

Re: Obama Signs CISA Bill into Law

#47
post #27

Earlier quoted context omitted.

What are you asking exactly? In order to be attached to the bill, the amendment must be approved by a majority of the chamber. So that means it's already garnered support from congress, and congress is unlikely to take it off again before voting on the bill as a whole. Once it passes congress, the only way for it to be defeated would be for the president to veto the enormous budget bill based only on the amendment, w…

I think he means, while they approved the bill, warts and all, that doesn't mean everybody likes all the warts. (Although it is congress, so we have to assume they DO like warts... but let's put that aside). He's asking if they can come back and remove some of the warts, essentially, in a separate action at a later time.

But a majority of congress did like the wart. That's why the amendment adding the CISA text to the omnibus bill passed, and that's while it's very unlikely to be repealed later.

(Of course it's possible to repeal it later, as is true for all laws; they didn't pass a constitutional amendment.)

The public-choice situation as I understand it is that CISA was a bill that concentrated interests (large tech companies) liked but which the public as a whole did not like (insofar as they bothered to know about it). The key to passing such a bill is to minimize publicity and bundle it with a distraction.

Re: Obama Signs CISA Bill into Law

#48
post #14

I believe that CISA is mostly about changes within the government itself about sharing data between agencies. It seems to interface with the non-government world insofar as it lets companies share their data with government agencies without getting sued. I do NOT believe it contains any further provisions requiring private companies to share their data without a warrant. Can someone tell me if I’m reading it correctl…

You are reading it correctly. CISA explicitly establishes by statute that private entities are never required to share data, but that the government is required to share with private entities.

Re: Obama Signs CISA Bill into Law

#49

Earlier quoted context omitted.

It's useful to note that Paul Ryan gained his position by saying shady backroom deals like this, plus giving Congress almost no time to read and think about the bill themselves, were the exact things he promised to stop. So his very first act as speaker is to break every single promise he made to become speaker.

I am Jack's complete lack of surprise

Indeed.

Re: Obama Signs CISA Bill into Law

#50
post #14

I believe that CISA is mostly about changes within the government itself about sharing data between agencies. It seems to interface with the non-government world insofar as it lets companies share their data with government agencies without getting sued. I do NOT believe it contains any further provisions requiring private companies to share their data without a warrant. Can someone tell me if I’m reading it correctl…

The bill itself reads mostly mundane, which I think is part of the intention. The main issues are the liberal definitions of "cybersecurity purpose," "cybersecurity threat" and "cyber threat indicator," along with the really half-assed integrity requirements ("Make sure you scrub out personally identifiable information, but only if you're aware of it, so no big deal.") and a repeated insistence on the data being "sha…

Could you be more specific about the "liberal definitions" of "cybersecurity purpose, threat, and indicator"? I've read all the computer security legislation that's been proposed in the last 8 years or so, and CISA had the least egregious definitions I'd read.

They even inherited the CISPA amendment that established that terms of service violations weren't cybersecurity threats.

Post reply on HN