CISPA 'dead' in Senate, privacy concerns cited
81–90 of 95 posts
Re: CISPA 'dead' in Senate, privacy concerns cited
#82Earlier quoted context omitted.
A passable CISPA is one that wouldn't allow companies to share information specific to its users (except it's not that simple, if I'm a hacker do I get some kind of special immunity if I register on the website I hacked? What if part of the hack required me to register, is that information suddenly invalid because I have a username and a password?). I should be able to share the md5s of malware I found on my system w…
Correct, those are not problems. You can do both of those things already, and they're done every day.
Re: CISPA 'dead' in Senate, privacy concerns cited
#83Earlier quoted context omitted.
A passable CISPA is one that wouldn't allow companies to share information specific to its users (except it's not that simple, if I'm a hacker do I get some kind of special immunity if I register on the website I hacked? What if part of the hack required me to register, is that information suddenly invalid because I have a username and a password?). I should be able to share the md5s of malware I found on my system w…
As far as I can tell, I argued that the "solution" CISPA offers is one that is not compatible with the Constitution of the United States. Again, that makes it a bit of a non-starter, regardless of what problem it's attempting to solve.
Re: CISPA 'dead' in Senate, privacy concerns cited
#84Earlier quoted context omitted.
Correct, those are not problems. You can do both of those things already, and they're done every day.
Incorrect. Facebook can't legally aid its direct competitors, and Facebook can currently be sued by its stock holders if it discloses that it was breached and as a result of that disclosure the stock drops.
What they can't do, is give someone like me private info from user accounts. And they don't need to. And that's the way it should be. Do you really want me reading your private messages with impunity because I'm investigating a security incident? And do you want me to then share it with all of the other companies involved in the breach? Do you care if I leave dirty messages between you and your wife on an unencrypted hard drive somewhere, and people read it? Under current laws, I'd be liable for that (if I actually needed it in the first place).
You shouldn't.
Under CISPA, I can't be charged or sued for any action taken in good faith. I'll just say "oops, sorry, it was an honest mistake while investigating a security incident".
(Not that this use case has anything to do with what is actually motivating CISPA anyway, but I will refrain from repeating myself)
Also, for what it's worth, I've worked with AV industry groups and they all share not only hashes, but actual samples as well. Every single one of them. I'm not talking passing around an interesting sample or two, but full, multi-gigabyte feeds. I don't know where people get the idea that they can get sued for this; it's silly and it's not true.
Re: CISPA 'dead' in Senate, privacy concerns cited
#85Earlier quoted context omitted.
Incorrect. Facebook can't legally aid its direct competitors, and Facebook can currently be sued by its stock holders if it discloses that it was breached and as a result of that disclosure the stock drops.
Incorrect, Facebook can and does do this, and I've personally worked with them on it while being at other companies. Furthermore, the opposite is even true - they have a legal obligation to disclose most breaches. There is no basis for any part of your claim and it's not consistent with how Facebook is actually doing security today. Without CISPA. What they can't do, is give someone like me private info from user acc…
And Facebook has no obligation to disclose breaches, not legally, anyway. Where did you get that information? And even if they somehow do have a special obligation, most companies do not, so it's not really relevant. The example is apocryphal.
And AV isn't who this is about, it's about the people who make a living off of having indicators you don't have. I shouldn't have to hire a company who's been hired by everyone else to get the collective knowledge of what hackers look like. They're criminals, and the government takes care of criminals.
Re: CISPA 'dead' in Senate, privacy concerns cited
#86Earlier quoted context omitted.
The only people who disagree with this statement are people who are simply not informed. What you see from groups like the ACLU, EFF, Demand Progress, etc. is opposition to the specific language in CISPA, not opposition to the concept of a cybersecurity bill in general. They did not oppose the Senate bill last year for instance.
> The only people who disagree with this statement are people who are simply not informed. So I take it that you don't realize this is a logical error called Argumentum ad populum ? http://en.wikipedia.org/wiki/Argumentum_ad_populum
(Ah, recursion...)
Re: CISPA 'dead' in Senate, privacy concerns cited
#87Earlier quoted context omitted.
The only people who disagree with this statement are people who are simply not informed. What you see from groups like the ACLU, EFF, Demand Progress, etc. is opposition to the specific language in CISPA, not opposition to the concept of a cybersecurity bill in general. They did not oppose the Senate bill last year for instance.
> The only people who disagree with this statement are people who are simply not informed. Please try to be less obvious about your lack of arguments.
Re: CISPA 'dead' in Senate, privacy concerns cited
#88Earlier quoted context omitted.
> The only people who disagree with this statement are people who are simply not informed. So I take it that you don't realize this is a logical error called Argumentum ad populum ? http://en.wikipedia.org/wiki/Argumentum_ad_populum
Actually, that's not only a fairly weakly implied argumentum ad populum , as it doesn't actually argue that the number of ignorant people are small or the number of non-ignorant people are large (though the use of "only" might imply that.) "The only people who disagree with this statement are people who are simply not informed" is more directly argumentum ad hominem , and, particularly, abusive ad hominem . http://co…
It is harder to make a substantive case against the need for a cybersecurity bill because to do that, one would have to actually know what one is talking about.
Here is an example of the sort of distortion that the current legal environment is causing:
http://online.wsj.com/article/SB1000142412788732488360457839...
I hope you will consider the idea that if companies feel forced into going to lawyers for network security advice, the system might benefit from a bit of tweaking.
Re: CISPA 'dead' in Senate, privacy concerns cited
#89Earlier quoted context omitted.
Would you find it unreasonable to have a search warrant on every single American's internet activity? As far as I understand it, that is, in effect, what CISPA proposes.
This is not what CISPA proposes. It really isn't. There are a lot of advocacy organizations (EPIC, etc) that like to bluster about what it does. Right now EPIC is blustering that it's part of authorizing a secret program. What they didn't tell you is that this is their real goal is to gain possible congressional support for the FOIA request they filed, they are just trying to tie it all together so they can gain supp…
Re: CISPA 'dead' in Senate, privacy concerns cited
#90Earlier quoted context omitted.
Incorrect, Facebook can and does do this, and I've personally worked with them on it while being at other companies. Furthermore, the opposite is even true - they have a legal obligation to disclose most breaches. There is no basis for any part of your claim and it's not consistent with how Facebook is actually doing security today. Without CISPA. What they can't do, is give someone like me private info from user acc…
CISPA wouldn't stop a hired security analyst from reading your Facebook messages, it'd stop Facebook from sharing them with the government. Under a passable CISPA, anyway. And furthermore, the whole point of CISPA is to explicitly codify some very grey area. It is possible they do indeed share threat intel with their direct competitors, but there is no legal precedent for doing so. The whole point of CISPA was to low…
Really?
http://en.wikipedia.org/wiki/Security_breach_notification_la...
For someone repeatedly making demonstrably false assertions, you are oddly sure of yourself. You're not even challenging a viewpoint here, you're just straight up talking out of your ass. You should stop doing that.