Live data from Hacker News

CISPA 'dead' in Senate, privacy concerns cited

zdnet.com

41–50 of 95 posts

Re: CISPA 'dead' in Senate, privacy concerns cited

#41
post #17

Earlier quoted context omitted.

Some people oppose CISPA because of fixable issues regarding privacy or overly broad scope, some oppose it because they they think that it'll let the government spy on every URL they visit or allow the MPAA to take down all of Facebook for copyright infringement. According to the latter, CISPA isn't just a bad idea, it's pure malicious evil - the people supporting it need to be defeated so soundly that they never eve…

You make it sound as though those are the only two kind of people on this issue: Those who are reasonable and think CISPA can be fixed, and those who think CISPA is a bill to make spying on every American citizen the legal obligation of every ISP and internet company. You leave no room for the vast majority of us who believe that the US government already has more than enough authority to spy on people; the governmen…

Do you remember the Ecomom story yesterday, where the VP of Sales had no responsibility for ensuring profits were realized, only for ensuring that revenue was high?

That's the kind of problem that CISPA proponents are trying to solve with regard to "cyberspace security". It's not supposed to be another way for the government to obtain information on people or threat groups, for the exact reasons you listed. It's supposed to be a way for the private sector and government to cooperate on network defense, sharing information as necessary to provide a coordinated defense in response, investigate attackers, etc.

Government can't do it alone as the private sector controls the networks and has a lot of the needed expertise. The private sector can't do it alone as they have no legal authority, which is quite deliberately retained with the government (especially in light of what happened to Sunil Tripathi).

There are actually similar arrangements already in place in other areas. For example disaster relief/emergency management has a lot of tie-in between Federal, state, and local governments, DoD, and NGOs such as the Red Cross, all of which have pre-planned responses to various disaster scenarios. But these can be done without changes to the law, which is at least somewhat unclear in the case of coordinated network security.

Now CISPA as it currently stands is dangerous because it still doesn't provide enough privacy protection (especially on the commercial -> government direction), but please don't act like it's just another feeder source for the FBI, as if that were the only possible motive, especially given existing issues such as the Aurora attack on Google.

Re: CISPA 'dead' in Senate, privacy concerns cited

#42
post #37
post #32

Earlier quoted context omitted.

How is that "quartering soldiers?" Or do words just mean whatever we want them to mean?

Well, if what you do virtually on line can be considered on a par with what you do physically, so inciting terrorism on facebook for example, there has to be some sort of parallel with virtual soldiers, which we could refer to as spy service spybots, spying on out computers in our homes, or on our mobile devices. Im not sure the government can on one had work that logic to prosecute citizens, while not applying the s…

[deleted]

Re: CISPA 'dead' in Senate, privacy concerns cited

#43
post #17

Earlier quoted context omitted.

Some people oppose CISPA because of fixable issues regarding privacy or overly broad scope, some oppose it because they they think that it'll let the government spy on every URL they visit or allow the MPAA to take down all of Facebook for copyright infringement. According to the latter, CISPA isn't just a bad idea, it's pure malicious evil - the people supporting it need to be defeated so soundly that they never eve…

You make it sound as though those are the only two kind of people on this issue: Those who are reasonable and think CISPA can be fixed, and those who think CISPA is a bill to make spying on every American citizen the legal obligation of every ISP and internet company. You leave no room for the vast majority of us who believe that the US government already has more than enough authority to spy on people; the governmen…

Actually, I was talking about the difference between rational, principled opposition and irrational, apocalyptic doomsaying. The groups I gave were meant to be examples, not comprehensive enumerations of every possible belief. Based on your reply, I'd consider you part of the first group - you've articulated a reasonable position that's based on your own beliefs and principles, and I can respect that even if I don't agree with it.

It wasn't my intention to offend by excluding or ignoring anyone, and I'm sorry if my post came off that way.

Re: CISPA 'dead' in Senate, privacy concerns cited

#44

For those not familiar with the legislative process in the U.S., the Senate does not have to pass CISPA. They just need to pass some cybersecurity bill, which can then be conferenced together with CISPA. Some will take this as proof that the system is broken, but the truth is that we really do need some improvements and clarifications of certain laws to help companies improve their security. If the Senate passes a bi…

> but the truth is that we really do need some improvements and clarifications of certain laws to help companies improve their security.

Oh, well, since you put together such a persuasive argument.

Re: CISPA 'dead' in Senate, privacy concerns cited

#45

Earlier quoted context omitted.

The 4th amendment protects against unreasonable searches and seizures, not all of them.

Except the ones that aren't unreasonable are carried out with a judge's signature or have very narrow latitude (plain sight, hot pursuit).

And is not part of the problem here trying to determine the "cyber equivalent" of such things as plain sight and hot pursuit? A lot of what goes on online is the equivalent of high noon in the public square, even if people don't quite understand that.

Re: CISPA 'dead' in Senate, privacy concerns cited

#46
post #9
post #2

"Undead" is more like. This thing will keep coming back under different names until it passes.

No joke- Obama threatened a veto on privacy concerns and the senate punted on it- and yet: The government is dead serious about turning every sizable company on the internet into a part of a gross-national cybersecurity infrastrucutre maintainer, and they are not going to quit until the internet has been adequately leashed by the legislative hand. If corporations are people, this is definitely a violation of the 3rd…

I don't think you understand who's asking the government to do this.

Re: CISPA 'dead' in Senate, privacy concerns cited

#47
post #15

Earlier quoted context omitted.

Isn't that how it is supposed to work? There is pretty widespread agreement even among opponents of CISPA in its current form that the problems it is trying to address are real, serious, and need to be addressed, and I believe that there is even wide agreement that CISPA addresses them. The objections are that it needs some tweaking to prevent abuse (e.g., tighten up some definitions). Why should it not come back aft…

If it were coming back "tweaked" to address the flaws of the bill, then sure, that'd be how the system is supposed to work. Except that's not what's happening and things aren't working. The issue is that CISPA is fundamentally flawed; I have no doubt that there are well-meaning people who believe we need something to address the problems CISPA allegedly addresses. But any solution which consists of "first, we stop ca…

A passable CISPA is one that wouldn't allow companies to share information specific to its users (except it's not that simple, if I'm a hacker do I get some kind of special immunity if I register on the website I hacked? What if part of the hack required me to register, is that information suddenly invalid because I have a username and a password?).

I should be able to share the md5s of malware I found on my system with my direct competitor without being hit in the face by the Sherman Antitrust Act. I should also be able to disclose to my users/the public that I was hacked in the first place, without fear of being sued.

Are you seriously saying these aren't problems?

Re: CISPA 'dead' in Senate, privacy concerns cited

#48
post #30
post #20

Earlier quoted context omitted.

Explain the third amendment bit: "No Soldier shall, in time of peace be quartered in any house, without the consent of the Owner, nor in time of war, but in a manner to be prescribed by law." Who exactly is suggesting we house soldiers in peoples' houses?

If I understand the GP correctly, the claim is that we are now perpetually at cyberwar and CISPA would invite cyberwarriors into everyone's home.

More like the farmers who grow the food we eat would be begging the cyberwarriors to look at the footprints the bandits left behind.

But hey, what's accuracy when you've got passion!

Re: CISPA 'dead' in Senate, privacy concerns cited

#49

Earlier quoted context omitted.

The 4th amendment protects against unreasonable searches and seizures, not all of them.

Would you find it unreasonable to have a search warrant on every single American's internet activity? As far as I understand it, that is, in effect, what CISPA proposes.

> a search warrant on every single American's internet activity? As far as I understand it, that is, in effect, what CISPA proposes.

no.

no.

not at all. please read the bill. it says nothing of the sort.

Re: CISPA 'dead' in Senate, privacy concerns cited

#50

For those not familiar with the legislative process in the U.S., the Senate does not have to pass CISPA. They just need to pass some cybersecurity bill, which can then be conferenced together with CISPA. Some will take this as proof that the system is broken, but the truth is that we really do need some improvements and clarifications of certain laws to help companies improve their security. If the Senate passes a bi…

> but the truth is that we really do need some improvements and clarifications of certain laws to help companies improve their security. Oh, well, since you put together such a persuasive argument.

The only people who disagree with this statement are people who are simply not informed.

What you see from groups like the ACLU, EFF, Demand Progress, etc. is opposition to the specific language in CISPA, not opposition to the concept of a cybersecurity bill in general. They did not oppose the Senate bill last year for instance.

Post reply on HN