Live data from Hacker News

Proposed Info Sharing Legislation Could Worsen NSA Surveillance

cdt.org

11–20 of 24 posts

Re: Proposed Info Sharing Legislation Could Worsen NSA Surveillance

#11
this is why I use tor.

Unfortunately many sites do not permit connections from exit nodes. cloudflare always requires one solve a captcha.

duckduckgo by contradt provides a hidden service.

Im planning on providing one too; I wouldnt want the FBI to know who is reading my articles about c++ memory management.

Re: Proposed Info Sharing Legislation Could Worsen NSA Surveillance

#12
Just now i read in The Columbian that obama has committed not to spy on the prime minister of france, after france called for an intelligence code of ethics in which the allies agree not to spy on each other.

There was no mention of spying on their own citizens.

Re: Proposed Info Sharing Legislation Could Worsen NSA Surveillance

#13

CISA is the government's way of writing into law that people have no right to privacy in any data held by third party service providers. By granting legal immunity for service providers to share so-called "threat" data—potentially containing unminimized private customer data—law enforcement agencies are opening a huge backdoor for uncontrolled warrantless mass surveillance. Because this surveillance would be done in…

> Watch in the coming weeks as lawmakers point to the OPM hacks as justification for spying on everyone's Gmail activity. We can't stop leaking your personal information to the enemy, so we obviously need to collect and store more comprehensive and personal information.

this suggests a market opportunity.

Re: Proposed Info Sharing Legislation Could Worsen NSA Surveillance

#14
post #5

NSA/FBI surveillance is pretty unpopular - I'm pretty sure that Senator and Representative offices got a ton of calls about it, otherwise the PATRIOT Act section 215 wouldn't have sunsetted, it would have gotten a big sloppy wet rubber stamp. SOPA touched off a big campaign a couple of years ago, CISA gets nearly unanimous bad reviews. So, why does the Senate keep trying to crank up this sort of thing? They need to b…

> So, I'm torn. Why does this keep popping up? Constituents may vote, but lobbyists pay the bills.

government contractors pay the lobbyists. consider that the very first cray was purchased by the nsa.

Re: Proposed Info Sharing Legislation Could Worsen NSA Surveillance

#15

Just now i read in The Columbian that obama has committed not to spy on the prime minister of france, after france called for an intelligence code of ethics in which the allies agree not to spy on each other. There was no mention of spying on their own citizens.

And if someone else spies on the PM of France, and the US happens to get their hands on that data, then I'll bet they'd argue the US did not spy on them.

Re: Proposed Info Sharing Legislation Could Worsen NSA Surveillance

#16

NSA/FBI surveillance is pretty unpopular - I'm pretty sure that Senator and Representative offices got a ton of calls about it, otherwise the PATRIOT Act section 215 wouldn't have sunsetted, it would have gotten a big sloppy wet rubber stamp. SOPA touched off a big campaign a couple of years ago, CISA gets nearly unanimous bad reviews. So, why does the Senate keep trying to crank up this sort of thing? They need to b…

>Is this whole category of law a place where the DoJ has intercepted enough sketchy conversations that they've got leverage against key Senators and Reps?

That's all I can think of too after reading Daniel Suarez' "Influx." With the resources and information at their disposal I would not put it past them to take this approach.

That raises the question of how we can change the system if we have to assume some sort of blackmail like that might be taking place. Is there a workaround?

Re: Proposed Info Sharing Legislation Could Worsen NSA Surveillance

#17

CISA is the government's way of writing into law that people have no right to privacy in any data held by third party service providers. By granting legal immunity for service providers to share so-called "threat" data—potentially containing unminimized private customer data—law enforcement agencies are opening a huge backdoor for uncontrolled warrantless mass surveillance. Because this surveillance would be done in…

> By granting legal immunity for service providers to share so-called "threat" data—potentially containing unminimized private customer data—law enforcement agencies are opening a huge backdoor for uncontrolled warrantless mass surveillance

Section 4(d)(2) requires removal of personal information before sharing unless that personal information is directly related to a cybersecurity threat.

A cybersecurity threat is defined as "an action, not protected by the First Amendment to the Constitution of the United States, on or through an information system that may result in an unauthorized effort to adversely impact the security, availability, confidentiality, or integrity of an information system or information that is stored on, processed by, or transiting an information system" and "does not include any action that solely involves a violation of a consumer term of service or a consumer licensing agreement".

There is no mass surveillance implied in this.

> Because this surveillance would be done in secret, people would have no legal basis to challenge what amounts to an end-run around the U.S. Constitution.

The Constitution restricts government from forcing companies to give up information against their will. Nothing in the Constitution prohibits companies from voluntarily giving up information, and so nothing you have cited is in any way an end-run around the Constitution.

Re: Proposed Info Sharing Legislation Could Worsen NSA Surveillance

#18
post #17

CISA is the government's way of writing into law that people have no right to privacy in any data held by third party service providers. By granting legal immunity for service providers to share so-called "threat" data—potentially containing unminimized private customer data—law enforcement agencies are opening a huge backdoor for uncontrolled warrantless mass surveillance. Because this surveillance would be done in…

> By granting legal immunity for service providers to share so-called "threat" data—potentially containing unminimized private customer data—law enforcement agencies are opening a huge backdoor for uncontrolled warrantless mass surveillance Section 4(d)(2) requires removal of personal information before sharing unless that personal information is directly related to a cybersecurity threat. A cybersecurity threat is d…

> Section 4(d)(2) requires removal of personal information

Section 4(d)(2) of _what?_ These minimization requirements have been removed or weakened in the various iterations of CIS(P)A that have appeared and been defeated year after year. There is currently no bill in front of Congress, so your citing of a specific provision is questionable. Congress is expected to take a new version of CISA up in the next few weeks.

> The Constitution restricts government from forcing companies to give up information against their will.

Except under Section 702, companies are compelled to hand the information via secret orders with gag provisions. Fighting these orders is expensive and the gag orders prevent the companies from openly opposing them.

It _is_ an end-run around the Constitution if the data a company provides belongs to an individual and is disclosed without a proper warrant, unless you agree with the statement that "people have no right to privacy in any data held by third party service providers." Such an attitude ignores the reality that cloud services have become integrated into peoples' lives, and ubiquitous enough that the end-customer should have legal interest and Constitutional protection in data held by third parties.

Re: Proposed Info Sharing Legislation Could Worsen NSA Surveillance

#19
post #17

Earlier quoted context omitted.

> By granting legal immunity for service providers to share so-called "threat" data—potentially containing unminimized private customer data—law enforcement agencies are opening a huge backdoor for uncontrolled warrantless mass surveillance Section 4(d)(2) requires removal of personal information before sharing unless that personal information is directly related to a cybersecurity threat. A cybersecurity threat is d…

> Section 4(d)(2) requires removal of personal information Section 4(d)(2) of _what?_ These minimization requirements have been removed or weakened in the various iterations of CIS(P)A that have appeared and been defeated year after year. There is currently no bill in front of Congress, so your citing of a specific provision is questionable. Congress is expected to take a new version of CISA up in the next few weeks.…

> Section 4(d)(2) of _what?_

Section 4(d)(2) of the bill that the article you are commenting on is writing about, S.754, the "Cybersecurity Information Sharing Act of 2015".

Re: Proposed Info Sharing Legislation Could Worsen NSA Surveillance

#20
post #19

Earlier quoted context omitted.

> Section 4(d)(2) requires removal of personal information Section 4(d)(2) of _what?_ These minimization requirements have been removed or weakened in the various iterations of CIS(P)A that have appeared and been defeated year after year. There is currently no bill in front of Congress, so your citing of a specific provision is questionable. Congress is expected to take a new version of CISA up in the next few weeks.…

> Section 4(d)(2) of _what?_ Section 4(d)(2) of the bill that the article you are commenting on is writing about, S.754, the "Cybersecurity Information Sharing Act of 2015".

Section 4(d)(2) requires removal of information that a company "knows at the time of sharing" to be private personal information. That's complete weak sauce. There is tons of leeway here for the government to demand threat indicators that could "accidentally" vacuum up private info without anyone "knowing" about it. And the bill hasn't even gone through committee. If the past is any indication, the GOP will try to strike it completely.

Anyway, I would appreciate if you could address the other point I raised because I'm very curious to hear your philosophical thoughts on this subject.

Post reply on HN