Live data from Hacker News

Rep. Mike Rogers Calls CISPA Opponents "14 Year Old Tweeters in Their Basement"

cms.fightforthefuture.org

81–88 of 88 posts

Re: Rep. Mike Rogers Calls CISPA Opponents "14 Year Old Tweeters in Their Basement"

#81
post #79
post #78

Earlier quoted context omitted.

CISPA not only works for sharing of information with the government, but also with security companies. Your second sentence is a rather weak counterargument. (1) would be fine on its own, it is in the context of (2) and (3) that it is not; the incentives make (2) and (3) extra bad.

We are a SOURCE of threat information. We are not a consumer of threat information.

Wouldn't CISPA also protect the companies providing information to you by giving you permission to test and/or access to their systems, and hence be beneficial to your business? Why aren't you a consumer of threat information that way?

Re: Rep. Mike Rogers Calls CISPA Opponents "14 Year Old Tweeters in Their Basement"

#82
post #81
post #79

Earlier quoted context omitted.

We are a SOURCE of threat information. We are not a consumer of threat information.

Wouldn't CISPA also protect the companies providing information to you by giving you permission to test and/or access to their systems, and hence be beneficial to your business? Why aren't you a consumer of threat information that way?

I think you have absolutely no idea what it is we do.

Re: Rep. Mike Rogers Calls CISPA Opponents "14 Year Old Tweeters in Their Basement"

#83
post #82
post #81

Earlier quoted context omitted.

Wouldn't CISPA also protect the companies providing information to you by giving you permission to test and/or access to their systems, and hence be beneficial to your business? Why aren't you a consumer of threat information that way?

I think you have absolutely no idea what it is we do.

Why are you so defensive and rude? I think I have an idea what you do. You check applications for security vulnerabilities. While doing this, you may access information that usually would be considered information that the company you are investigating would not be allowed to give you. But with CISPA, they would be allowed to give you.

FYI, you have a dead link: http://www.matasano.com/services/shipsafe/

Re: Rep. Mike Rogers Calls CISPA Opponents "14 Year Old Tweeters in Their Basement"

#84
post #83
post #82

Earlier quoted context omitted.

I think you have absolutely no idea what it is we do.

Why are you so defensive and rude? I think I have an idea what you do. You check applications for security vulnerabilities. While doing this, you may access information that usually would be considered information that the company you are investigating would not be allowed to give you. But with CISPA, they would be allowed to give you. FYI, you have a dead link: http://www.matasano.com/services/shipsafe/

I like the guy who asks why I'm being rude after suggesting that I arrived at my public policy positions out of a concealed financial interest.

You have a weird and broken understanding of how engineering firms are contacted to test for vulnerabilities. CISPA has absolutely no bearing on my firm whatsoever.

Re: Rep. Mike Rogers Calls CISPA Opponents "14 Year Old Tweeters in Their Basement"

#85
post #84
post #83

Earlier quoted context omitted.

Why are you so defensive and rude? I think I have an idea what you do. You check applications for security vulnerabilities. While doing this, you may access information that usually would be considered information that the company you are investigating would not be allowed to give you. But with CISPA, they would be allowed to give you. FYI, you have a dead link: http://www.matasano.com/services/shipsafe/

I like the guy who asks why I'm being rude after suggesting that I arrived at my public policy positions out of a concealed financial interest. You have a weird and broken understanding of how engineering firms are contacted to test for vulnerabilities. CISPA has absolutely no bearing on my firm whatsoever.

Can you explain how the way engineering firms are contracted means that CISPA has absolutely no bearing on your firm? As far as I can see, the bill doesn't say that if a company is contracted in a certain way, then its protections don't apply.

Surely it's not rude to ask if you have a personal interest, given that (1) CISPA has explicit provisions for security companies (2) it's not clear why this would not apply to your company and (3) you defend CISPA on almost every CISPA post on hacker news.

Re: Rep. Mike Rogers Calls CISPA Opponents "14 Year Old Tweeters in Their Basement"

#86
post #85
post #84

Earlier quoted context omitted.

I like the guy who asks why I'm being rude after suggesting that I arrived at my public policy positions out of a concealed financial interest. You have a weird and broken understanding of how engineering firms are contacted to test for vulnerabilities. CISPA has absolutely no bearing on my firm whatsoever.

Can you explain how the way engineering firms are contracted means that CISPA has absolutely no bearing on your firm? As far as I can see, the bill doesn't say that if a company is contracted in a certain way, then its protections don't apply. Surely it's not rude to ask if you have a personal interest, given that (1) CISPA has explicit provisions for security companies (2) it's not clear why this would not apply to…

If from this point on you would like to tell yourself that my non-responsive comment here, and my future lack of responsiveness to any of your other comments, implied that you Perry Mason'd some kind of acknowledgement of my corrupt CISPA dealings out of me on Hacker News, you have my blessing.

Re: Rep. Mike Rogers Calls CISPA Opponents "14 Year Old Tweeters in Their Basement"

#87
post #86
post #85

Earlier quoted context omitted.

Can you explain how the way engineering firms are contracted means that CISPA has absolutely no bearing on your firm? As far as I can see, the bill doesn't say that if a company is contracted in a certain way, then its protections don't apply. Surely it's not rude to ask if you have a personal interest, given that (1) CISPA has explicit provisions for security companies (2) it's not clear why this would not apply to…

If from this point on you would like to tell yourself that my non-responsive comment here, and my future lack of responsiveness to any of your other comments, implied that you Perry Mason'd some kind of acknowledgement of my corrupt CISPA dealings out of me on Hacker News, you have my blessing.

It is indeed unfortunate that in you reply to the substance at little as possible, since this way neither I nor other readers can benefit from your knowledge. The bill is not very large, so it would not be hard for you to show that it does not apply to your company, if indeed it does not. I don't think this has anything to do with corruption, but it does have something to do with bias. However, since you clearly genuinely believe that this bill does not pertain to your company, this possibility for bias has already been eliminated whether or not the bill actually does apply to your company. Still, I think that's an interesting question.

As far as I can tell, these sections of the bill indicate that it does apply to your company:

    ‘‘(A) CYBERSECURITY PROVIDERS.— Not-
    5 withstanding any other provision of law, a cy-
    6 bersecurity provider, with the express consent 
    7 of a protected entity for which such cybersecu-
    8 rity provider is providing goods or services for 
    9 cybersecurity purposes, may, for cybersecurity 
    10 purposes— 
    11 ‘‘(i) use cybersecurity systems to iden-
    12 tify and obtain cyber threat information to 
    13 protect the rights and property of such 
    14 protected entity; and [...]
So, if the company your are investigating gives you consent, you may obtain cyber threat information. Note that this says nothing about the way the company is contracted.

What is cyber threat information?

    1 ‘‘(2) CYBER THREAT INFORMATION.—The term 
    2 ‘cyber threat information’ means information di-
    3 rectly pertaining to a vulnerability of, or threat to, 
    4 a system or network of a government or private enti-
    5 ty, including [...]
So this means that you can get all information pertaining to a vulnerability, and CISPA will protect the company you're getting that information from. This is so vague that it could be virtually any data. But it gets better:

    ‘‘(4) EXEMPTION FROM LIABILITY.—No civil or 
    12 criminal cause of action shall lie or be maintained in 
    13 Federal or State court against a protected entity, 
    14 self-protected entity, cybersecurity provider, or an 
    15 officer, employee, or agent of a protected entity, self- 
    16 protected entity, or cybersecurity provider, acting in 
    17 good faith— 
    18 ‘‘(A) for using cybersecurity systems or 
    19 sharing information in accordance with this sec-
    20 tion; or 
    21 ‘‘(B) for decisions made based on cyber 
    22 threat information identified, obtained, or 
    23 shared under this section
So even if a company managed to share data that would not be allowed, as long as it's acting "in good faith" everything is A-OK. Given this I fail to see how your company is not a consumer of cyber threat information as defined in this bill.

If you are so easily offended, you may wish to review your own writing style, since your comments are far from the least argumentative on HN (and I do not just mean this thread).

Thanks for your blessing, you have mine as well.

Re: Rep. Mike Rogers Calls CISPA Opponents "14 Year Old Tweeters in Their Basement"

#88
post #41

Earlier quoted context omitted.

Anything can be roped into "actual attack." Remember the actual language of the bill, since you read it: "theft of intellectual property." What the hell does that mean? Of course there is no oversight aside from the people who are making requests, so the idea that a company would actually be penalized for releasing info "unreleated to cyberthreats" is laughable at best.

Like I said upthread, CISPA goes further in trying to actually define what a "cyberattack" is than any other bill I've read. How would you modify the definitions in the bill?

You and I have discussed DHS related things before, and I think we simply have differing views on this entire thing. I simply don't want any more power going to the most demonstrably incompetent branch of government in the history of the US (including, of course, everything historically that came out of the 1947 act that this is a rider to).

I do agree with you that the definitions of cybercrime and attacks in CISPA would be a start for the framework for coherent legislation. I just don't think that DHS should continue to be added onto piecemeal until they control 100% of all law enforcement activities as well, since let's face it, that's the eventual goal.

Post reply on HN