Live data from Hacker News

Rep. Mike Rogers Calls CISPA Opponents "14 Year Old Tweeters in Their Basement"

cms.fightforthefuture.org

71–80 of 88 posts

Re: Rep. Mike Rogers Calls CISPA Opponents "14 Year Old Tweeters in Their Basement"

#71
post #63

Earlier quoted context omitted.

Yes, they do quite a bit of lobbying.

This makes me happy to continuing donating to the EFF every year.

The EFF and the ACLU defend personal freedom by lobby and direct litigation in court. They both been earning my money, someone who trades in information, for years.

Re: Rep. Mike Rogers Calls CISPA Opponents "14 Year Old Tweeters in Their Basement"

#72
post #62

Earlier quoted context omitted.

How does the bill's definition of an attack include sites with "hacker" in the name?

CISPA contains no definition of "attack", nor does it limit itself to "actual attacks", or anything resembling that language. Furthermore, if it did, it doesn't matter. Bad actors are allowed to be wrong, with impunity, if they promise that it was "in good faith".

     4) CYBER THREAT INFORMATION.— 
      ‘‘(A) IN GENERAL.—The term ‘cyber 
      threat information’ means information directly 
      pertaining to— 
      ‘‘(i) a vulnerability of a system or net-
      work of a government or private entity; 
      ‘‘(ii) a threat to the integrity, con-
      fidentiality, or availability of a system or 
      network of a government or private entity 
      or any information stored on, processed on, 
      or transiting such a system or network; 
      ‘‘(iii) efforts to deny access to or de-
      grade, disrupt, or destroy a system or net-
      work of a government or private entity; or 
      ‘‘(iv) efforts to gain unauthorized ac-
      cess to a system or network of a govern-
      ment or private entity, including to gain 
      such unauthorized access for the purpose 
      of exfiltrating information stored on, proc-
      essed on, or transiting a system or network 
      of a government or private entity	
You're right that I phrased this more casually than the bill does, which harms my point but I believe still leaves it standing.

Re: Rep. Mike Rogers Calls CISPA Opponents "14 Year Old Tweeters in Their Basement"

#73
post #33

Earlier quoted context omitted.

The liability shield is practically the whole point of the bill; there are something like 10 federal laws that restrict what information can be shared in any circumstance, intentionally or not, which precludes a bunch of different forms of cooperation during attack. A simple use case for this law: you are under a concerted DDOS attack. Your network deals with, say, drivers records. Drivers records are protected under…

Why on earth would you need to send the actual drivers records? Of course we don't want to share that. Nothing in the DPPA prevents sharing netflows. And that is kind of a poor justification because we know that society doesn't currently have an epidemic of people DDoSing the DMV. Someone else wants this passed, and they really want it passed. It ain't the DMV.

You don't. You only need to reveal information that could with analysis be used to derive information protected under some piece of privacy legislation.

Incidentally, the DPPA wasn't written to lock down the DMV.

I use the DPPA as an example of surprising limitations on the ability of private companies to share operational data that could conceivably due to operator error or time constraints potentially include protected information. Another example: FERPA.

Re: Rep. Mike Rogers Calls CISPA Opponents "14 Year Old Tweeters in Their Basement"

#74
post #10

Mike Rogers is making it very hard to defend CISPA by saying things like this, but I'll point out that what Mike Rogers thinks about CISPA opponents is probably the least important thing to know about the bill. Something you might want to know is that "Fight For The Future" feels comfortable riling you up without telling you the full story about the bill. CISPA, according to FFTF, "lets the government spy on you with…

Given that you are running a security company, in that respect you have personal interest in this bill getting passed, right?

The problems with the bill are mainly this:

1. The immunity gives companies an incentive to share more data.

2. There is neither oversight nor transparency for the sharing of information and other measures companies are allowed to take based on this bill, and what the government and third parties are allowed to do with the information.

3. Even if there were oversight, the conditions under which the companies would get immunity are so broad and ill defined that there is practically no restriction on that.

I would like to add that there are people who make hysterical arguments against the bill, but that doesn't mean that the bill isn't bad.

Re: Rep. Mike Rogers Calls CISPA Opponents "14 Year Old Tweeters in Their Basement"

#75
post #72

Earlier quoted context omitted.

CISPA contains no definition of "attack", nor does it limit itself to "actual attacks", or anything resembling that language. Furthermore, if it did, it doesn't matter. Bad actors are allowed to be wrong, with impunity, if they promise that it was "in good faith".

4) CYBER THREAT INFORMATION.— ‘‘(A) IN GENERAL.—The term ‘cyber threat information’ means information directly pertaining to— ‘‘(i) a vulnerability of a system or net- work of a government or private entity; ‘‘(ii) a threat to the integrity, con- fidentiality, or availability of a system or network of a government or private entity or any information stored on, processed on, or transiting such a system or network; ‘‘…

> You're right that I phrased this more casually

Did you think that I was suggesting you were merely phrasing it casually, or is that a subtle argument technique? ;)

Re: Rep. Mike Rogers Calls CISPA Opponents "14 Year Old Tweeters in Their Basement"

#76
post #74
post #10

Mike Rogers is making it very hard to defend CISPA by saying things like this, but I'll point out that what Mike Rogers thinks about CISPA opponents is probably the least important thing to know about the bill. Something you might want to know is that "Fight For The Future" feels comfortable riling you up without telling you the full story about the bill. CISPA, according to FFTF, "lets the government spy on you with…

Given that you are running a security company, in that respect you have personal interest in this bill getting passed, right? The problems with the bill are mainly this: 1. The immunity gives companies an incentive to share more data. 2. There is neither oversight nor transparency for the sharing of information and other measures companies are allowed to take based on this bill, and what the government and third part…

We run a software security engineering firm, we don't do FedGov work, and in no way benefit from CISPA.

The whole point of the bill is to get companies to share more data.

Re: Rep. Mike Rogers Calls CISPA Opponents "14 Year Old Tweeters in Their Basement"

#77
post #72

Earlier quoted context omitted.

4) CYBER THREAT INFORMATION.— ‘‘(A) IN GENERAL.—The term ‘cyber threat information’ means information directly pertaining to— ‘‘(i) a vulnerability of a system or net- work of a government or private entity; ‘‘(ii) a threat to the integrity, con- fidentiality, or availability of a system or network of a government or private entity or any information stored on, processed on, or transiting such a system or network; ‘‘…

> You're right that I phrased this more casually Did you think that I was suggesting you were merely phrasing it casually, or is that a subtle argument technique? ;)

No, I was owning up to the fact that by saying CISPA only pertained to "attacks", I was making it easier to accept my premise. You were right to point out that the language in the bill is more subtle than that.

Re: Rep. Mike Rogers Calls CISPA Opponents "14 Year Old Tweeters in Their Basement"

#78
post #76
post #74

Earlier quoted context omitted.

Given that you are running a security company, in that respect you have personal interest in this bill getting passed, right? The problems with the bill are mainly this: 1. The immunity gives companies an incentive to share more data. 2. There is neither oversight nor transparency for the sharing of information and other measures companies are allowed to take based on this bill, and what the government and third part…

We run a software security engineering firm, we don't do FedGov work, and in no way benefit from CISPA. The whole point of the bill is to get companies to share more data.

CISPA not only works for sharing of information with the government, but also with security companies.

Your second sentence is a rather weak counterargument. (1) would be fine on its own, it is in the context of (2) and (3) that it is not; the incentives make (2) and (3) extra bad.

Re: Rep. Mike Rogers Calls CISPA Opponents "14 Year Old Tweeters in Their Basement"

#79
post #78
post #76

Earlier quoted context omitted.

We run a software security engineering firm, we don't do FedGov work, and in no way benefit from CISPA. The whole point of the bill is to get companies to share more data.

CISPA not only works for sharing of information with the government, but also with security companies. Your second sentence is a rather weak counterargument. (1) would be fine on its own, it is in the context of (2) and (3) that it is not; the incentives make (2) and (3) extra bad.

We are a SOURCE of threat information. We are not a consumer of threat information.
Post reply on HN