Live data from Hacker News

Obama Signs CISA Bill into Law

npr.org

81–90 of 230 posts

Re: Obama Signs CISA Bill into Law

#81
post #45

CISA passed the Senate with almost 3:1 bipartisan support in October. PCNA, the House's (worse) version of CISA, passed with similar margins in April. Obama has publicly supported the bill all year. As much as HN and Twitter wants to believe CISA was enacted in some shady backroom deal, the process that actually occurred, including publicly available amendments and months-long review, is pretty close to "Schoolhouse…

I must disagree. I believe you are overstating things. Schoolhouse rocks, last I checked, had one bill moving from one house to the other. Citizens could lobby at any point, including the conference committee. Each of these were passed in isolation, then stuck together, then stuck into a budget bill. Then the only question was whether you wanted the entire bill to pass or not. It's a fair interpretation to say that s…

Bills get passed in omnibus spending bills all the time. For instance, as someone pointed out on the last thread about CISA: your COBRA health insurance? COBRA stands for "Consolidated Omnibus Budget Reconciliation Act".

There was extended public debate and a prolonged amendment process for CISA and PCNA in both houses of Congress. There was intense media coverage and, once CISA passed in October, the consensus was that CISA was going to be the law of the land.

The one uncertainty about it was the extent to which the House would drag CISA towards PCNA's broader law enforcement language. Thankfully, that drama, with its attendant opportunity for "public commentary", didn't happen.

For you to make a strong case for how important a prolonged conference committee would have been to the process, I think you should start by pointing out another bill that died in a conference committee due to public outcry. Has that ever happened?

Re: Obama Signs CISA Bill into Law

#82
post #61

There have been very many versions of laws similar to CISA that have been proposed, modified, and changed/passed/failed/delayed. When I try to understand exactly what this CISA version includes, most rhetoric I read is alarmist and not conducive to actually knowing what can and cannot be done under CISA. Is there a digestible explanation of what this CISA entails?

Sure. CISA defines "cybersecurity threats" and "threat indicators", which are now legalese versions of the stuff Intrusion Detection Systems track: exploit code, vulnerability information, and wire traces of attacks. Everyone already collects this stuff; that's most of what network security teams are paid to do. The government has several huge network security teams (they operate the largest IT system in the world),…

The good or bad of this delends critically on what kind of information is being shared.

Re: Obama Signs CISA Bill into Law

#83

How this happened [1]: In a late-night session of Congress, House Speaker Paul Ryan announced a new version of the “omnibus” bill, a massive piece of legislation that deals with much of the federal government’s funding. It now includes a version of CISA as well. Lumping CISA in with the omnibus bill further reduces any chance for debate over its surveillance-friendly provisions, or a White House veto. And the latest…

I feel like I'm living in a twilight zone episode. I don't think we're ever going to see an end to this and I think its going to get worse and worse and no one is going to notice until there really is no way out. I'm sick of seeing comments about voting bad / good lawmakers out / in. Clearly that doesn't work because most citizens don't give a shit because they're too stupid to understand what is happening. Even when…

A simplified way of looking at things is that politicans cannot simultaneously be "for the people" and above them. Perhaps way lower down on the totem pole but not in the big leagues.

As for not seeing the end of it, it's the same as TOS and software updates we receive on iOS, et al. Not many people look at the details, rather they just press OK. Attrition as an agent of change is much more effective than a full-frontal assault. https://en.wikipedia.org/wiki/Fabian_strategy

Re: Obama Signs CISA Bill into Law

#84

Earlier quoted context omitted.

The 14 votes against, FWIW: Baldwin (D-WI) Booker (D-NJ) Brown (D-OH) Coons (D-DE) Franken (D-MN) Leahy (D-VT) Markey (D-MA) Menendez (D-NJ) Merkley (D-OR) Paul (R-KY) Sanders (I-VT) Udall (D-NM) Warren (D-MA) Wyden (D-OR) https://www.techdirt.com/articles/20151022/10133932597/cisa-...

Bernie Sanders and Tammy Baldwin are pretty consistent when it comes to supporting privacy and the internet. They were actually the only two Senators who voted against the "Freedom" Act [1] who also supported net neutrality [2]. Both also voted against the "Patriot" Act in 2001, while they served in the House [3]. [1] http://www.senate.gov/legislative/LIS/roll_call_lists/roll_c... [2] http://www.baldwin.senate.gov/pr…

Don't forget Rand Paul

Re: Obama Signs CISA Bill into Law

#85
post #45

CISA passed the Senate with almost 3:1 bipartisan support in October. PCNA, the House's (worse) version of CISA, passed with similar margins in April. Obama has publicly supported the bill all year. As much as HN and Twitter wants to believe CISA was enacted in some shady backroom deal, the process that actually occurred, including publicly available amendments and months-long review, is pretty close to "Schoolhouse…

The 14 votes against, FWIW: Baldwin (D-WI) Booker (D-NJ) Brown (D-OH) Coons (D-DE) Franken (D-MN) Leahy (D-VT) Markey (D-MA) Menendez (D-NJ) Merkley (D-OR) Paul (R-KY) Sanders (I-VT) Udall (D-NM) Warren (D-MA) Wyden (D-OR) https://www.techdirt.com/articles/20151022/10133932597/cisa-...

I'm a very liberal persion, but I really like Rand Paul. I just wish he didn't think gays were going to burn in hell for all eternity, or at least would stick to libertarian principles on the issue and let people live how they want to live.

The same with abortion laws. I'd be way more into supporting him if he would concede he doesn't agree personally, but that people shouldn't be forced by the government to live according to his religious beliefs.

Re: Obama Signs CISA Bill into Law

#86
post #82
post #61

Earlier quoted context omitted.

Sure. CISA defines "cybersecurity threats" and "threat indicators", which are now legalese versions of the stuff Intrusion Detection Systems track: exploit code, vulnerability information, and wire traces of attacks. Everyone already collects this stuff; that's most of what network security teams are paid to do. The government has several huge network security teams (they operate the largest IT system in the world),…

The good or bad of this delends critically on what kind of information is being shared.

Of course, but then, the bill recognizes that up front too.

Here's what the bill says you can share, lightly edited:

Data about malicious reconnaissance and recon anomalies, vulnerabilities and exploit code, anomaly events that describe exploit attempts, privilege escalation attempts that bypass security features for post-auth users, malware C&C, documentation of the data exfiltrated by attackers in breaches, and, finally, anything at all related to cyber attacks iff you were already lawfully allowed to share it.

That's it.

https://www.govtrack.us/congress/bills/114/s754/text

Re: Obama Signs CISA Bill into Law

#87
post #50

Earlier quoted context omitted.

The bill itself reads mostly mundane, which I think is part of the intention. The main issues are the liberal definitions of "cybersecurity purpose," "cybersecurity threat" and "cyber threat indicator," along with the really half-assed integrity requirements ("Make sure you scrub out personally identifiable information, but only if you're aware of it, so no big deal.") and a repeated insistence on the data being "sha…

Could you be more specific about the "liberal definitions" of "cybersecurity purpose, threat, and indicator"? I've read all the computer security legislation that's been proposed in the last 8 years or so, and CISA had the least egregious definitions I'd read. They even inherited the CISPA amendment that established that terms of service violations weren't cybersecurity threats.

That it does, along with consumer licensing agreements (presumably EULAs).

"Cybersecurity purpose" is itself mostly a pointer contingent to the meaning of "cybersecurity threat":

   Except as provided in subparagraph (B), the term 
   cybersecurity threat means an action, not protected by
   the First Amendment to the Constitution of the United
   States, on or through an information system that may 
   result in an unauthorized effort to adversely impact the
   security, availability, confidentiality, or integrity of
   an information system or information that is stored on,
   processed by, or transiting an information system.
(6) Cyber threat indicator is rather loose with F, G and H. B drops the term "security control". A seems to be legitimately trying to address automated scanning, but might seem to let through legitimate scraping since it doesn't further qualify.

If this is, as you say, one of the least egregious definitions, then I'm not sure whether this is a cause for concern or hope.

Re: Obama Signs CISA Bill into Law

#88
post #18

Earlier quoted context omitted.

Search without a warrant though sounds unconstitutional. Legislative arbitrage. Passed low key in Congress, Removed at high cost in the courts

I believe CISA is more about what the feds MUST do and what private companies MAY do. It’s incentivising the private companies to rat you out, not requiring that they do so.

And Room 419A shows us how that plays out in practice. Private companies get paid to break the law wih immunity.

Re: Obama Signs CISA Bill into Law

#89
post #64

Earlier quoted context omitted.

I'm honestly starting to think sander's is our last hope -- I was on the fence until seeing this. Meanwhile he is getting undermined by the media.

Not so on social media, however, which makes this election really interesting: we'll be able to see to what extent the old guard (broadcast news networks) reigns supreme.

and to what extent the twittering classes does or does not really effect things.

Re: Obama Signs CISA Bill into Law

#90
post #77

Earlier quoted context omitted.

It's useful to note that Paul Ryan gained his position by saying shady backroom deals like this, plus giving Congress almost no time to read and think about the bill themselves, were the exact things he promised to stop. He did? I thought he got the job (after much cajoling) because he was the only candidate the moderate and right wings of the GOP could agree on.

Yes. He had to be courted; the House Freedom Caucus had to make concessions for him to accept the job. The modal HN user has either a DailyKos or RedState (mostly Kos) understanding of US politics.

What concessions did they make? It was the other way round, he made a list of demands and they said no and then proceeded to not-endorse him.
Post reply on HN