Live data from Hacker News

CISPA 'dead' in Senate, privacy concerns cited

zdnet.com

51–60 of 95 posts

Re: CISPA 'dead' in Senate, privacy concerns cited

#53
post #15
post #2

"Undead" is more like. This thing will keep coming back under different names until it passes.

Isn't that how it is supposed to work? There is pretty widespread agreement even among opponents of CISPA in its current form that the problems it is trying to address are real, serious, and need to be addressed, and I believe that there is even wide agreement that CISPA addresses them. The objections are that it needs some tweaking to prevent abuse (e.g., tighten up some definitions). Why should it not come back aft…

I have not heard a clear case made for where current laws fall short. The existing Computer Fraud and Abuse Act (CFAA) has massive teeth that can be sunk into nearly anyone, and it's but one of many laws that can be used against someone.

For example, the only reason adservers & their cookie tracking escape is because they fall short of the $5000 minimum damages established in law.

One of the main CISPA focuses seems to be upon data-sharing initiatives. Yet I've heard very few examples of where cyber-law hasn't been effective & would have benefited from such federal oversight. The case has been poorly made, so I'm not sure why you're on about objections- objections are a thing that get made once someone has a case, and CISPA seems far more like something the government just wants to do than anything it's tried to justify.

Re: CISPA 'dead' in Senate, privacy concerns cited

#54

Earlier quoted context omitted.

If it were coming back "tweaked" to address the flaws of the bill, then sure, that'd be how the system is supposed to work. Except that's not what's happening and things aren't working. The issue is that CISPA is fundamentally flawed; I have no doubt that there are well-meaning people who believe we need something to address the problems CISPA allegedly addresses. But any solution which consists of "first, we stop ca…

A passable CISPA is one that wouldn't allow companies to share information specific to its users (except it's not that simple, if I'm a hacker do I get some kind of special immunity if I register on the website I hacked? What if part of the hack required me to register, is that information suddenly invalid because I have a username and a password?). I should be able to share the md5s of malware I found on my system w…

As far as I can tell, I argued that the "solution" CISPA offers is one that is not compatible with the Constitution of the United States.

Again, that makes it a bit of a non-starter, regardless of what problem it's attempting to solve.

Re: CISPA 'dead' in Senate, privacy concerns cited

#55
post #30
post #20

Earlier quoted context omitted.

Explain the third amendment bit: "No Soldier shall, in time of peace be quartered in any house, without the consent of the Owner, nor in time of war, but in a manner to be prescribed by law." Who exactly is suggesting we house soldiers in peoples' houses?

If I understand the GP correctly, the claim is that we are now perpetually at cyberwar and CISPA would invite cyberwarriors into everyone's home.

That is quite a stretch.

Re: CISPA 'dead' in Senate, privacy concerns cited

#56
post #13

Expect it to be introduced on a Friday night and quickly, quietly passed with no notice.

Why wouldn't they have just passed it now? I mean, it might be re-introduced, but surely the idea is to deal with these concerns before doing so, or it'll just be dropped again?

Not usually. Usually the idea is to wait until all the publicity dies down and then quietly slip it through when nobody's looking.

Re: CISPA 'dead' in Senate, privacy concerns cited

#57
post #6

Earlier quoted context omitted.

I will predict that this does not happen within the next 5 years, 85% confidence.

Questionable confidence ratings aside, what you're betting against is a very narrow example of the many things that could happen that would push this through. It died once and is back; it got farther this time, and whether it's because of a hacking scare, because even fewer people are paying attention, or for any of myriad other reasons, it will eventually go through.

It's the price I'd put on it if Intrade were still around.

Re: CISPA 'dead' in Senate, privacy concerns cited

#58
I've complied with a number of US federal requests made to a corporation that sells internet access and hosting. The requests started out as federal subpoenas detailing exact information to retrieve. Then they started to slide to unofficial requests for "everything you have" on the target and finally settled on, "please observe this account and search for anything we can use to get a subpoena." That was 10 years ago. What exactly is the victory here?

Re: CISPA 'dead' in Senate, privacy concerns cited

#60
post #49

Earlier quoted context omitted.

Would you find it unreasonable to have a search warrant on every single American's internet activity? As far as I understand it, that is, in effect, what CISPA proposes.

> a search warrant on every single American's internet activity? As far as I understand it, that is, in effect, what CISPA proposes. no. no. not at all. please read the bill. it says nothing of the sort.

Except that it does, and that's why it's being pushed. See new details uncovered by EPIC:

http://news.cnet.com/8301-13578_3-57581161-38/u.s-gives-big-...

CISPA's true motivation is becoming very clear. It's needed to expand a pilot program for dragnet surveillance by the NSA and defense contractors. You know, the same thing they've been doing for ages and getting sued over by the EFF. If you read the letters in support of CISPA by the defense contractors who are lobbying for it and funding Mike Rogers who authored it, they even acknowledge this program by name (it's called the DIB cyber pilot).

That's why the bill is so vague, and why they refuse amendments to narrow the scope. It's a get out of jail free card for complicit companies and they can claim virtually anything is related to "security". They can also be wrong, as long as they claim it was "in good faith". It's more or less the "state secrets privilege" equivalent, but for companies cooperating with the "data sharing".

It solves nothing, because it's already legal to share threat data. You just have to scrub it of private or protected information. If its protected, it's because we passed a law for something we felt was worth protecting. For CISPA to just undo all of those laws wholesale is outrageous.

Post reply on HN