Live data from Hacker News

Obama Signs CISA Bill into Law

npr.org

121–130 of 230 posts

Re: Obama Signs CISA Bill into Law

#122

Earlier quoted context omitted.

Does that roughly mean that FB must (to be shielded from lawsuits) anonymize the data before passing it to the government? This isn't particularly comforting, since it could still be used to prosecute individuals if identity can be inferred from other context. The EFF's criticism is basically that the bill is overly broad and can be used nefariously, even if it's not an all purpose FB message vacuum: > The bill's bro…

They have to do one of two things: 1. They can establish and run a process that ensures that data doesn't have personally identifying information in it. For instance, they can have a process by which they sign off on the types of things they're willing to share, and share only the stuff that never has PII in it. 2. They can instead run software that tries to spot PII and zaps it before sharing it. I don't know how pe…

Thanks very much for info. Much appreciated.

Agreed that the EFF risks its reputation when it freely uses hyperbolic language. But I think some of this is due to (mostly philosophical) difference about how much we should worry about granting vague powers to the government which are mostly not abused. People similarly differ in how fiercely they fight free speech restrictions, etc.

Re: Obama Signs CISA Bill into Law

#123
My favorite clause...

"(e) Prohibited conduct -- Nothing in this title shall be construed to permit price-fixing, allocating a market between competitors, monopolizing or attempting to monopolize a market, boycotting, or exchanges of price or cost information, customer lists, or information regarding future competitive planning."

Does this imply it could have been construed that way without this clause?

Re: Obama Signs CISA Bill into Law

#124

Earlier quoted context omitted.

They have to do one of two things: 1. They can establish and run a process that ensures that data doesn't have personally identifying information in it. For instance, they can have a process by which they sign off on the types of things they're willing to share, and share only the stuff that never has PII in it. 2. They can instead run software that tries to spot PII and zaps it before sharing it. I don't know how pe…

Thanks very much for info. Much appreciated. Agreed that the EFF risks its reputation when it freely uses hyperbolic language. But I think some of this is due to (mostly philosophical) difference about how much we should worry about granting vague powers to the government which are mostly not abused. People similarly differ in how fiercely they fight free speech restrictions, etc.

I think the underlying worry here is very legitimate.

But my interest is in making sure we know the truth as precisely as we can, and I believe nobody is well-served by the propagation of falsehoods, even when the falsehoods support a valid narrative.

Re: Obama Signs CISA Bill into Law

#125
post #10

Earlier quoted context omitted.

https://en.wikipedia.org/wiki/Cybersecurity_Information_Shar... The core problem is it lets major industry players like MS / Google / Apple give the fed access to all the personal info they record without investigators needing a warrant and with no liability on the companies part (ie, you cannot sue them for state disclosure of your personal info that then resulted in harm against you). It basically means do not be s…

Search without a warrant though sounds unconstitutional. Legislative arbitrage. Passed low key in Congress, Removed at high cost in the courts

Facebook or Google searching their own data isn't a search under the 4th amendment. All that data analysis they run on you is their data not yours.

Them searching your private messages/emails are (probably) a search but since they aren't government the 4th amendment doesn't apply. If government specifically coordinates that brings it under the 4th amendment.

But--here is the problem. Google (and I assume facebook) are already reading your email. They run algorithms and text searches on it. If I were DOJ I'd argue 1) that none of those messages are private since the companies are allowed to read the data whenever they want. 2) if not, then the indexing and analysis is definitely not private.

People should step back and realize this CISA only occurs when you already let companies violate your privacy.

Re: Obama Signs CISA Bill into Law

#126
post #53
post #15

Earlier quoted context omitted.

What's the alternative?

Not sure if something like this exist but what if you could use a system where people could subscribe to you (a bit like RSS) and get all your content (a bit like newsgroups, so that a third party would have a harder time to figure out at least some of the metadata) but the recipients could only decrypt what is addressed to them personally or to a group that they are part of...

SpiderOak's experimental Kloak provides such a system.

Encrypted pub/sub social will be the only way to ensure privacy, long-term. (Other than purely anonymous networks, which have other use cases.)

Re: Obama Signs CISA Bill into Law

#127
I think the "big deal" about CISA is that it essentially gives the heads of state the ability to say "cybersecurity threat indicator" and by so doing collect any information or spy on any system they wish without warrant or any other form of informed oversight.

Re: Obama Signs CISA Bill into Law

#128

Earlier quoted context omitted.

It's the end of the year and they're trying to get shit wrapped up. CISA and PCNA weren't controversial except on message boards. They passed with overwhelming support, positive media coverage, and the overt support of the President.

Although I'm happy to admit that there was no major public pushback against CISA because no one in the public cared, I'm not convinced that it had public support or positive media coverage. I typed "CISA" into Google news, and these were first articles and opinion pieces that came up on the mainstream (not tech-related) news sites. (I couldn't find any positive publicity at all.) -- Washington Times: "ISA cyber bill…

Replying to tptacek: OK, but I think everything you said is consistent with no one in public having any idea or caring. This was "out in the open" in the same way that essentially all regulations that benefit a concentrated interest with diffuse costs do (like most pork). It's just ignored by the public.

Anyways, sorry to drag this out. I don't have anything more productive to add. I appreciate your insight here.

Re: Obama Signs CISA Bill into Law

#129
post #84

Earlier quoted context omitted.

Don't forget Rand Paul

Rand Paul is actually fighting against net neutrality http://www.reuters.com/article/us-usa-internet-neutrality-id...

Net neutrality, as it's currently being implemented, grants the FCC significant amounts of regulatory power over private companies. This regulatory power has the potential to be abused. So, Rand Paul being against it is consistent with his general philosophy of less government intervention.

Re: Obama Signs CISA Bill into Law

#130
post #45

CISA passed the Senate with almost 3:1 bipartisan support in October. PCNA, the House's (worse) version of CISA, passed with similar margins in April. Obama has publicly supported the bill all year. As much as HN and Twitter wants to believe CISA was enacted in some shady backroom deal, the process that actually occurred, including publicly available amendments and months-long review, is pretty close to "Schoolhouse…

> The debate on CISA was over. Thankfully

Thankfully? In the sense that at least it wasn't close to PCNA or that you think this bill will do anything to actually benefit "cybersecurity"? Because if it doesn't serve its purpose, then it doesn't really matter how close was or wasn't to the PCNA, does it?

Also, you're not worried at all about the legal protections companies get for cooperating with the NSA? If they "aren't doing anything wrong", why should they need legal immunity?

Post reply on HN