Live data from Hacker News

Rep. Mike Rogers Calls CISPA Opponents "14 Year Old Tweeters in Their Basement"

cms.fightforthefuture.org

51–60 of 88 posts

Re: Rep. Mike Rogers Calls CISPA Opponents "14 Year Old Tweeters in Their Basement"

#51
post #3

As Senator Mark Hanna said in 1895 (118 years ago!): "There are two things that are important in politics. The first is money, and I can't remember what the second one is."[1] If you want to understand why Representative Mike Rogers is mocking CISPA opponents as "14 Year Old Tweeters in Their Basement," just ask, who finances his political campaigns? I hate to be cynical, but calling your Representative may not be en…

http://www.opensecrets.org/politicians/contrib.php?cycle=201...

What's scary is how cheap it is to buy politicians.

Re: Rep. Mike Rogers Calls CISPA Opponents "14 Year Old Tweeters in Their Basement"

#52
post #44

Earlier quoted context omitted.

And how are the affected people to know that such information has been shared, if you can't even make a FOIA request?

Any bill that ever allows private companies to share information with the USG is going to include a FOIA exemption, because the alternative is that no private company's management team would ever allow information to be shared under any circumstance, as it could allow the public access to trade secrets, contractually confidential information, and market intelligence.

Ok, but you haven't answered my question.

Re: Rep. Mike Rogers Calls CISPA Opponents "14 Year Old Tweeters in Their Basement"

#53
And I call Mike Rogers a 54(?) year old political hack without a actual argumentative leg to stand on. This would be just another trite case of legislators wearing their donation sources on their sleeve, but the truth is that these kinds of people are dangerous to not only the tech industry in general, but really more foundational elements (I hate to sound like a CATO-monkey, because that gets irksome, but guys like Rogers and Feinstein really do trammel on "freedoms" pretty rampantly).

I've read through CISPA. It's got some very elegant wording, but its contemptible all the way around in what its going after.

Re: Rep. Mike Rogers Calls CISPA Opponents "14 Year Old Tweeters in Their Basement"

#54
post #46

Earlier quoted context omitted.

And here is the main problem with the bill. "Not incident to an actual attack" is not reflective of the language used. It's so vauge that you could drive a truck through it. Or, a $2+ billion Utah datacenter, for instance.

The statutory "good faith" language is a problem, in that "good faith" isn't well defined anywhere. But what are the additional changes you'd make to the liability exemption to tighten it up?

The wildcards (such as "good faith", but there are others) are non-starters. You don't even need to reason about the finer points of the bill with that in there.

But ideally? I don't want anybody to share any information of mine to any third party, without my consent, at any time. I'm having trouble thinking of why that would be necessary.

I'm willing to entertain reasonable arguments as to why it might be necessary, and may make some compromises (without wildcard language) in light of a compelling argument, but nobody sponsoring CISPA has even made an attempt to do that.

Re: Rep. Mike Rogers Calls CISPA Opponents "14 Year Old Tweeters in Their Basement"

#55
post #44

Earlier quoted context omitted.

Any bill that ever allows private companies to share information with the USG is going to include a FOIA exemption, because the alternative is that no private company's management team would ever allow information to be shared under any circumstance, as it could allow the public access to trade secrets, contractually confidential information, and market intelligence.

Ok, but you haven't answered my question.

I think my answer is they probably won't know. The purpose of the bill is to allow sharing of operational data about network security attacks. The bill isn't intended to allow private companies to share your Facebook profile or email.

I guess you could argue that malware often uses mail to spread, and that a social media provider might dragnet a whole bunch of email spools to collect malware samples and then forklift it to LEOs for investigation. That would be bad.

The bill takes some small steps to keep that from happening, but probably not enough.

Re: Rep. Mike Rogers Calls CISPA Opponents "14 Year Old Tweeters in Their Basement"

#56
post #27
post #25

Earlier quoted context omitted.

That is a dishonest attack against a short marketing website. Your comment defends CISPA without telling the full story of the bill, just like this website did. You used a short description of what you think are relevant points that support your case, just like this website. Except that the website includes links to analysis by EFF, ACLU, Sunshine Foundation and others to support their arguments.

Maybe FFTF can tell us how many people hit their signup sheet, versus the number of people who click through to the background information. Maybe you could point out the call to action I must have missed on this site, urging readers to learn more about the bill before signing up with FFTF.

How does the number of people who hit the signup sheet and didn't read the details matter to their argument or how they have backed up their position?

Re: Rep. Mike Rogers Calls CISPA Opponents "14 Year Old Tweeters in Their Basement"

#57
post #46

Earlier quoted context omitted.

The statutory "good faith" language is a problem, in that "good faith" isn't well defined anywhere. But what are the additional changes you'd make to the liability exemption to tighten it up?

The wildcards (such as "good faith", but there are others) are non-starters. You don't even need to reason about the finer points of the bill with that in there. But ideally? I don't want anybody to share any information of mine to any third party, without my consent, at any time. I'm having trouble thinking of why that would be necessary. I'm willing to entertain reasonable arguments as to why it might be necessary,…

Sure. Here are two examples.

1. You're a web app company that routinely comes under DDOS attacks. A private security company would like you to subscribe and push Netflow traces to them during attacks, so they can derive minimal ACLs and relay them to ISPs so the attack could be filtered upstream. That Netflow data could in theory contain some of your traffic, and further could be statistically de-anonymized to reveal your personal usage of that service. Currently, you need authorization from your counsel every time you share that Netflow data; post-CISPA, you could get a one-time authorization and automatically push Netflow to the anti-DDOS provider.

2. You're working with several social networking companies to track down a browser malware attack that transmit itself through online messages. You'd like to collect a large volume of samples programmatically to share with other providers and LEOs, but you're extremely concerned that in doing so you might reveal details about private messages, perhaps even by sharing which users have messaging relationships with other users. Pre-CISPA, your counsel might refuse that sharing outright; post-CISPA, you'd have statutory protections for sharing that operational data in the course of responding to malware.

Re: Rep. Mike Rogers Calls CISPA Opponents "14 Year Old Tweeters in Their Basement"

#58
post #27

Earlier quoted context omitted.

Maybe FFTF can tell us how many people hit their signup sheet, versus the number of people who click through to the background information. Maybe you could point out the call to action I must have missed on this site, urging readers to learn more about the bill before signing up with FFTF.

How does the number of people who hit the signup sheet and didn't read the details matter to their argument or how they have backed up their position?

The site is not designed to get people to learn about CISPA, it's designed to elicit an immediate reaction. The fact that it somehow links to additional background information (we'll stipulate that the background information is accurate) is not a meaningful response to my complaint.

Re: Rep. Mike Rogers Calls CISPA Opponents "14 Year Old Tweeters in Their Basement"

#59

I find the choice of "14 year olds" quite fascinating, because 14 year olds don't have voting rights. If 14 is replaced with 18, then suddenly the phrase takes a completely different tone, since then it'd be disenfranchising a block of the population that has legitimate voting rights. I feel that 14 was chosen deliberately to give teh additional implication that CISPA opponents "don't have the right to oppose it" or…

It's also bizarrely tone-deaf metaphor-mixing.

the pejorative "basement" refers to an adult who doesn't have their own residence, and so lives in extra space in (but near the edge of) their parent's home, while pretending it is a separate residence. It doesn't make any sense to call a 14-year old a "basement"-dweller, they would have a regular bedroom.

Re: Rep. Mike Rogers Calls CISPA Opponents "14 Year Old Tweeters in Their Basement"

#60
post #35

Earlier quoted context omitted.

So getting an internet connection from a company that has opted in means I have no protection against searches and seizures (almost arbitrarily based on an individual's web habbits). So what if it's written specifically? People often don't have much of a choice when it comes to their ISPs, and wouldn't be able to just choose another one that doesn't opt in. In the modern world, where people use the internet for every…

> So getting an internet connection from a company that has opted in means I have no protection against searches and seizures (almost arbitrarily based on an individual's web habbits) no, that's not anywhere in the bill. did you read the bill?

I'd argue that it is.

He's on "Hacker News". It would be perfectly reasonable for an automated system that is designed to look for security-related activity to report that fact. The bill, as it is written, says any action his ISP now takes, or anyone that they share his information with (which would then be allowed to do, with anyone in the poorly defined "cybersecurity club"), is fully acceptable as long as it was "in good faith." And who could argue that? Hacker News is benign, but it's an honest mistake.

Post reply on HN