Live data from Hacker News

Civil Liberties Groups Speak Out Against CISPA in Lead Up to Hearings

eff.org

101–110 of 113 posts

Re: Civil Liberties Groups Speak Out Against CISPA in Lead Up to Hearings

#101
post #97
post #89

Earlier quoted context omitted.

Or that you asked at 1:00AM. Two responses, briefly: 1. FISMA spells out in positive terms that incident data collected by agencie is to be reported out to LEOs and the national security services unless otherwise designated by the President, and 2. much of the data we're discussing is classified, so, 18 U.S.C. § 798 is a starting point. Do you dispute that, say, botnet identification data collected by DoD is classifi…

Now we're getting somewhere! You're right, of course, that federal agencies have the power to classify data. But I think saying that overclassification happens all the time is not a controversial statement; President Obama in 2010 signed the Reducing Over-Classification Act and the DOD IG announced last November that it reviewing DOD classification procedures. One of the 9/11 Commission members concluded: "Much more…

I don't understand how your last graf connects to your first.

Start here: packet captures and netflow traces from operational military networks are a textbook definition of something that reasonably should default to "classified".

So then the fact that CISPA preempts classification is the mechanism by which it crafts the exception allowing that stuff to be published. The law says "you can keep classifying secops data on military networks, but when you come across material that would be valuable to the public if sent to a clearinghouse, CISPA preempts classification".

How is that not a sensible measure? And in context, isn't it clear that preempting things like classified disclosure laws is just a pragmatic measure, since reforming all of classification is a huge can of worms, and not some sinister attempt to create a backdoor wiretapping mechanism?

Re: Civil Liberties Groups Speak Out Against CISPA in Lead Up to Hearings

#102
post #96
post #90

Earlier quoted context omitted.

The bill supersedes privacy and communication laws, but is (a) opt-in and (b) severely limited in scope. Specifically: CISPA provides a positive authority for sharing only "cyber threat information", which is defined in the bill: (i) information about a vulnerability, (ii) information about a confidentiality/integrity/availability threat, (iii) information about denial of service or destructive attacks, and (iv) effo…

Thanks for your polite response. Two thoughts: First, I'm not interested in what politicians say in defense of their bill -- I'm interested in what the actual text of the bill says. Second, asking what specific privacy law is overruled is a bit odd because -all- of them are. ECPA, SCA, Wiretap Act, FCRA, DPPA, FERPA, PPA, RFPA, TCPA, VPPA are among them, and that's not even counting state privacy laws. Remember, CISP…

I'm not interested in what politicians say either, except to the extent that in a court challenge, when judges look to interpret the intent behind the statute, they have a clear signal by the authors of the bill that the statute was designed to prevent the collection of personal information by ISPs. Which was why I brought that up.

Your second graf begs my question. Obviously we're both aware of the ECPA and SCA. My question was, in what way do the preemptions on those acts materially harm the public interest? Put it this way: if you think that CISPA is in direct conflict with SCA, then clearly you can imagine situations in which e.g. Facebook could collect Netflow data from a DDOS attack and then worry that they'd somehow contravene SCA by sharing the information. Doesn't that "conflict" explain the need for an act like CISPA?

I'd also note that the first three acts you cited --- obviously the three most important, because they cover the integrity of online communications in general and not with respect to any particular application domain --- already contain exemptions similar in spirit to the ones in CISPA:

* ECPA permits providers to collect and in some limited cases share information that is related to the maintenance of their own infastructure

* SCA permits collection and monitoring of stored communication by the operators of stored communication services

* The Wiretap Act allows operators to intercept and monitor signals causing disruption to networks

CISPA harmonizes collection and sharing of data in cases of direct adversarial attacks. Compared to the exceptions in (for instance) ECPA, CISPA is narrowly tailored and very specific.

Furthermore, when you point out all the laws encumbering sharing of attack information, you start to make the preemption point for me. It may already be possible to share attack information, so long as it doesn't involve raw emails, and the attack information is shared by telecom providers under the ECPA maintenance exemption. UNLESS YOU'RE AN AUTO INSURANCE COMPANY, in which case Congress helpfully (and reasonably!) enacted a specific privacy regime under DPPA, which means now simply to have Progressive push netflow records to Verizon they might have to incur $50,000 in legal review which by the time it's done the attack will be over.

Instead of repeating my original question --- how exactly does CISPA conflict with existing privacy laws in ways that harm the public interest? --- why don't I ask the question in a different framing. If we stipulate that the problem we're talking about here does exist --- that Advocate Health Care in Illinois would incur significant and unnecessary legal risk in pushing netflow DDOS information to a public clearinghouse --- what is the privacy-protecting language YOU would like to see in a bill that aimed to address that problem?

Incidentally: can you do better than thanking me for a polite response? I'm not actually sure I'm being that polite anyways; I feel like I'm being blunt and direct. But on the other hand, you wrote a comment with a complicated technical question last night at 1:00AM, and when you didn't get a prompt response, you accused me of "handwaving". Can I argue now that it it's pretty obvious that neither you nor I is "handwaving", and that we've both done our homework, or at least way more homework than most CISPA commenters have done? Instead of thanking me for polite responses, could you instead just not impugn my motives or intellectual honesty again? We can then just chalk our initial static up to "message boards and politics".

PS: The worst, most crazymaking thing about CISPA debates online is that they invariably put me in the position of "CISPA advocate". I have a position in the CISPA debate: "CISPA is not evil". I think if you believe like I do that CISPA is facially benign, the way organizations like EFF are choosing to message against it starts to get disquieting. But my position does not carry into "CISPA is a great idea". A sane argument against CISPA is that it forestalls a needed reform across all online privacy bills to enable network security to function sanely. CISPA might be a bad idea. I am not a CISPA advocate. I just don't think it's overtly contrary to the public interest.

Re: Civil Liberties Groups Speak Out Against CISPA in Lead Up to Hearings

#103
post #92
post #72

Earlier quoted context omitted.

I disagree, but I don't think this subthread is important enough to litigate. If he wants to chime in and say "I absolutely am not saying CISPA is part of a scheme that will increase the powers of rightsholders", I'll apologize for mischaracterizing him.

I absolutely am not saying CISPA is part of a scheme that will increase the powers of "rightsholders." I don't see that in there. I was referring to the "spying" claim of the parent post of my first response. My concern is with limiting of my right to civil suit against a corporation, and my fear that the bartering of these rights for information bypasses legal constraints on information collecting by government and…

Do you think it is reasonable that an auto insurance company that operates under DPPA, or a classroom management service that operates under FERPA, or credit agency operating under FCRA, or nationwide bank under RFPA, or for that matter any online service managing information that could be considered stored communications --- do you think it is reasonable that these organizations should incur either the risk of a class action lawsuit or the expense of tens of thousands of dollars of legal review simply in order to push a worm signature or botnet identification or DDOS netflow information to a public clearinghouse? In other words, do you think it is in the public interest for you to retain the right to sue these kinds of companies to vindicate your theoretical privacy interest in network security data shared in good faith?

Thanks to Declan Mccullagh downthread for making my arguments about CISPA more vivid by citing all the privacy regs CISPA interacts with. :)

Oh: by the way: if I understand you correctly, you're not at all concerned that CISPA is a backdoor attempt to enable copyright enforcement, and by rebutting that idea earlier, I mischaracterized your point. I apologize for doing that. CISPA makes me jumpy.

Re: Civil Liberties Groups Speak Out Against CISPA in Lead Up to Hearings

#104
post #62

Earlier quoted context omitted.

CISPA allows exactly that to happen! Any "Cyber security provider" can collect and share information (on a voluntary, opt-in basis ) under the act. Moreover, the largest repository of threat information --- netflow traces, botnet identification, &c --- is housed inside the USG, which is prevented from sharing that information. That's the other problem CISPA solves. Did you read the bill? I'm not asking in an accusato…

>Did you read the bill? Reading bills is usually a headache because they keep changing. Cue Pelosi's idiotic comment about having to pass the law so we can know what's in it. This one seems to be no exception: The original bill is talking about intellectual property, people complained about it, they removed that in later versions. EFF is complaining about how it doesn't put limits on what the federal government can d…

Wow. Ok. Let me take a shot at this.

* Bills start as draft language. The draft is circulated so that organizations like ACLU can point out things like "this bill gives too much deference to content rightsholders". The bill's authors then say, "that's not at all the intent of the bill" and then fix the language. It is very weird to complain about this, since it's the system actually working in the public interest. So, sorry, you're going to have to keep reading the bill. Also: CISPA is tiny. You can read it inside of 5 minutes. It isn't PPACA, the bill Pelosi commented on.

* I don't think software vulnerabilities are the best or most likely example of information that will be shared from the USG to the private sector under CISPA, but to the extent it is, you can simply assume that a (say) OpenSSH bug disclosed under CISPA to (say) Facebook is going to be patched immediately. I am a vulnerability researcher; that's my profession. It is a near-consensus among vulnerability researchers that the sooner vulnerability data is published, the safer we all are. I find it difficult to be concerned that CISPA might get OpenSSL flaws published faster. If that happens, great.

* If organizations don't want to share vulnerability information with the USG, they don't have to. CISPA is entirely opt-in. Moreover: vulnerabilities are a bad example of information CISPA enables sharing for. Companies can already lawfully share vulnerabilities with the USG. There is a whole cottage industry of small companies that sell vulnerabilities to the intelligence services. To the extent that your concerns about CISPA involve trafficking in privacy-harming exploit code (a very legitimate concern in general), you are (respectfully) ill informed about the current state of cybersecurity regulation.

* The reason CISPA preempts existing privacy laws and provides protection from liability is because there are lots of different privacy regulations on the books that make it difficult for companies operating in certain verticals to share any data without expensive legal review. If you deal with classroom data, you've got FERPA. If you have driver records, you have DPPA. CISPA does not repeal DPPA or HIPAA or FERPA; instead, it simply says that as long as companies are dealing in good faith with attack data --- "cyber threat information", a term the bill goes to some lengths to define --- they can reasonably assume they won't get sued for violating HIPAA by sharing that attack data.

* Individuals are exempted as private entities to protect individual privacy. The intent of that definition as stated by the bill's authors was to prevent CISPA from being interpreted as a mechanism for ISPs and the USG to enter into agreements to track individual customers. See "Myths and Facts About CISPA" at the House Intelligence Committee page. So: you have that concern exactly backwards.

* I don't have any response to your concern that the USG should not be liable for negligence in publishing sensitive data. I see it as a good thing that the bill creates accountability for the handling of the data, and wish there was more accountability in the bill, not less.

There are other questions in your comment that I didn't address because I didn't understand them, sorry.

Re: Civil Liberties Groups Speak Out Against CISPA in Lead Up to Hearings

#105
post #96

Earlier quoted context omitted.

Thanks for your polite response. Two thoughts: First, I'm not interested in what politicians say in defense of their bill -- I'm interested in what the actual text of the bill says. Second, asking what specific privacy law is overruled is a bit odd because -all- of them are. ECPA, SCA, Wiretap Act, FCRA, DPPA, FERPA, PPA, RFPA, TCPA, VPPA are among them, and that's not even counting state privacy laws. Remember, CISP…

I'm not interested in what politicians say either, except to the extent that in a court challenge, when judges look to interpret the intent behind the statute, they have a clear signal by the authors of the bill that the statute was designed to prevent the collection of personal information by ISPs. Which was why I brought that up. Your second graf begs my question. Obviously we're both aware of the ECPA and SCA. My…

So, I didn't really answer because I knew you were kind of baiting me with that question. Whatever I wrote, you probably knew that you were going to be able to reply with "they can already do that under ECPA" (HN has had that discussion previously and I was paying attention). So let's just fast forward all of that.

Last time around, I believe you said CISPA is one giant legislative NOP. I think you have probably revised your position on that. Someone is trying very hard to pass this, and they don't do that for no reason. There is something very important in CISPA to someone.

It sounds like at least part of the reason for it, in your interpretation, is related to legal assurances. Since you have studied both, can you provide an effective 'diff' between CISPA and ECPA, within the scope of 'cyber'?

For what it's worth, after doing some basic searching on who is backing it and what their business objectives are, I feel like it is more probable that there is not evil intent behind CISPA at this time.

The problem, as I said, and as described by EFF, is that it is vague in many key areas (I'm not going to enumerate them, it's too tedious and not relevant enough to go into specifics). Look at the CFAA. The intent there was not to nail a MAC address spoofing wget loop or a fake email submitted to a captive portal to the wall for 35 years. The intent behind the PATRIOT act, at least as far as some supporters were concerned (even though they were probably duped) was actually to fight terrorism. Both have since become wildcards for bad actors to do things that the original supporters didn't intend. We have to expect this when we write laws.

It's the same as auditing C. You know those conversations you have with those "special" clients who respond to your bug report by saying "yeah, but that is only meant to hold a username, no one is REALLY going to try and have a 2GB username"? This is the legal equivalent.

> what is the privacy-protecting language YOU would like to see in a bill that aimed to address that problem?

This is an unreasonable rebuttal. "It's not perfect, but you don't have anything better" is not how we make laws. Obviously, a journalist or a security consultant discussing something as important as this is not going to just spit out a bill that solves every problem in an HN comment.

Re: Civil Liberties Groups Speak Out Against CISPA in Lead Up to Hearings

#106

Earlier quoted context omitted.

I'm not interested in what politicians say either, except to the extent that in a court challenge, when judges look to interpret the intent behind the statute, they have a clear signal by the authors of the bill that the statute was designed to prevent the collection of personal information by ISPs. Which was why I brought that up. Your second graf begs my question. Obviously we're both aware of the ECPA and SCA. My…

So, I didn't really answer because I knew you were kind of baiting me with that question. Whatever I wrote, you probably knew that you were going to be able to reply with "they can already do that under ECPA" (HN has had that discussion previously and I was paying attention). So let's just fast forward all of that. Last time around, I believe you said CISPA is one giant legislative NOP. I think you have probably revi…

I still don't think CISPA is vital or that it will make much of a difference in online security. Part of the reason I think that is that I have (from previous companies) some professional familiarity with how attack data is already shared. It's cumbersome and not very effective but I don't think CISPA fixes it.

The comparison to CFAA is interesting. Long before the drama with Aaron Swartz (drama you and I are probably on the same page about), CISPA was revised to blunt that concern: TOS violations are explicitly exempted from the sharing provisions of the app. So if you're on online music store and someone starts mass-exploiting a vulnerability to take music without paying for it but doesn't threaten the integrity of your actual computers, you can't share that attack information under CISPA. To me, that is a level of specificity and care that is unique to CISPA. Even the Wiretap Act, which exists almost entirely to suppress monitoring of communications, leaves much larger holes for service operators to monitor traffic.

So my response to you on this --- and I recognize that you want to avoid the nitty-gritty details, and that's fine --- is that CISPA is substantially more detailed than other online regulations. It is written more carefully to cover operational security issues than HIPAA is; it's far more specific than Sarbox was; it actually (IMO) narrows what could already be shared under ECPA, and it does this by spelling out in detail what an actual online security attack is.

I am specifically not making the argument that you have to propose a better bill to justify not passing this one! I agree, that is an infuriating objection. I'm saying, your proposed privacy-protecting language would help clarify the concerns you have with CISPA, so that we could be more sure we're debating each other and not past each other.

Finally, we disagree more than we agree about online policy, across the board. So any time this stuff comes up, any time I ask you to clarify something, you can reasonably expect me to follow up with some kind of rebuttal. I appreciate how that feels like being baited, but I'm not doing it in bad faith. Agreement for the sake of decorum is boring, isn't it? Let's just say what we think.

Re: Civil Liberties Groups Speak Out Against CISPA in Lead Up to Hearings

#107

Earlier quoted context omitted.

So, I didn't really answer because I knew you were kind of baiting me with that question. Whatever I wrote, you probably knew that you were going to be able to reply with "they can already do that under ECPA" (HN has had that discussion previously and I was paying attention). So let's just fast forward all of that. Last time around, I believe you said CISPA is one giant legislative NOP. I think you have probably revi…

I still don't think CISPA is vital or that it will make much of a difference in online security. Part of the reason I think that is that I have (from previous companies) some professional familiarity with how attack data is already shared. It's cumbersome and not very effective but I don't think CISPA fixes it. The comparison to CFAA is interesting. Long before the drama with Aaron Swartz (drama you and I are probabl…

To clarify on the baiting comment, I didn't intend to accuse bad faith or mean that was generally applicable to debates. For this particular issue, we have already advanced beyond that point in the conversation last time this was on HN, and I just wanted to expedite that. "Debate fatigue" or something :)

So my eventual reply is, if I list off my concerns and you point out that it's already possible to do those things, what is CISPA adding? Let's start the conversation there.

I'm not sure if it's a fallacy to appeal to common sense, but I don't buy that someone is pushing this through so hard to narrow what can already be shared. Even though you are certainly more familiar with previous relevant legislation, I feel pretty safe in saying that if that is your interpretation, it has to be incorrect.

Nobody spends money trying to take permissions away from themselves, and nobody versed in this area of law isn't already aware of their capabilities under ECPA.

Re: Civil Liberties Groups Speak Out Against CISPA in Lead Up to Hearings

#108
post #78
post #77

Earlier quoted context omitted.

He isn't saying CISPA should be opposed, but rather, additional specific legislation to protect individual's data from being retrieved by the government without due process.

But that is already unlawful.

I was pointing out a misunderstanding of what he was saying.

Re: Civil Liberties Groups Speak Out Against CISPA in Lead Up to Hearings

#109

Earlier quoted context omitted.

I still don't think CISPA is vital or that it will make much of a difference in online security. Part of the reason I think that is that I have (from previous companies) some professional familiarity with how attack data is already shared. It's cumbersome and not very effective but I don't think CISPA fixes it. The comparison to CFAA is interesting. Long before the drama with Aaron Swartz (drama you and I are probabl…

To clarify on the baiting comment, I didn't intend to accuse bad faith or mean that was generally applicable to debates. For this particular issue, we have already advanced beyond that point in the conversation last time this was on HN, and I just wanted to expedite that. "Debate fatigue" or something :) So my eventual reply is, if I list off my concerns and you point out that it's already possible to do those things…

I guess, if I was going to put my CISPA-advocate hat on, which I don't like because it is an ugly hat that I think my cat peed on, I would say this:

It is already possible for service providers to do the things CISPA enables them to do. However, under current regulations, it is legally risky for them to do it. Some of what they do incurs legal risk. Some of the legal risks mean that whole companies in some verticals won't entertain any conversation about information sharing because they're encumbered by specific privacy rules which, while important, were never intended to hamstring network security. As a result, there is much less information sharing now than there could be.

If I was going to put my political analyst hat on, which is ugly but at least doesn't smell like cat piss, I would point out the following:

CISPA came into being less an urgent fix to an immediate problem than as a response to another, more interventionist approach to regulating cybersecurity. That other approach would essentially have the USG "pick winners" in the information assurance market and, down the road, would allow the USG to designate certain private companies as "critical infrastructure" that would require the commercial ministrations of those companies. The winners in that scenario would have been Raytheon, Lockheed, and SAIC. Nobody in private industry wanted that, and it was antithetical to the Republican House, so they came up with an industry-friendly counterproposal.

Re: Civil Liberties Groups Speak Out Against CISPA in Lead Up to Hearings

#110

Earlier quoted context omitted.

To clarify on the baiting comment, I didn't intend to accuse bad faith or mean that was generally applicable to debates. For this particular issue, we have already advanced beyond that point in the conversation last time this was on HN, and I just wanted to expedite that. "Debate fatigue" or something :) So my eventual reply is, if I list off my concerns and you point out that it's already possible to do those things…

I guess, if I was going to put my CISPA-advocate hat on, which I don't like because it is an ugly hat that I think my cat peed on, I would say this: It is already possible for service providers to do the things CISPA enables them to do. However, under current regulations, it is legally risky for them to do it. Some of what they do incurs legal risk. Some of the legal risks mean that whole companies in some verticals…

Do you think that EFF vs AT&T would have been easier to dismiss, post-CISPA?
Post reply on HN