Live data from Hacker News

Despite privacy concerns, CISA bill poised for passage

america.aljazeera.com

21–30 of 95 posts

Re: Despite privacy concerns, CISA bill poised for passage

#21
post #17
post #13

There's an AMA on reddit right now with the EFF, Access, Fight for the Future, FFTF, and Demand Progress about this. https://www.reddit.com/r/IAmA/comments/3qban2/oh_look_its_th... Looks like it just started a few minutes ago, so no idea if it'll be useful, or not.

I'm never super happy with EFF's advocacy (I think they do good and important legal and technical work but I'm almost always unhappy with how they represent policy to the public). I've been uniformly discouraged by FFTF's advocacy, which I find goes way past "misleading" into "straight up dishonest", such as their recent piece that strongly suggested Facebook supported CISA (a fact not in evidence, for whatever that'…

they're referring to Sec 4 (d) (4) (b)

Also 5 (d) (3) (a) and (b) which exempts "Cyber threat indicators and defensive measures provided to the Federal Government under this Act".

Re: Despite privacy concerns, CISA bill poised for passage

#22
post #21
post #17

Earlier quoted context omitted.

I'm never super happy with EFF's advocacy (I think they do good and important legal and technical work but I'm almost always unhappy with how they represent policy to the public). I've been uniformly discouraged by FFTF's advocacy, which I find goes way past "misleading" into "straight up dishonest", such as their recent piece that strongly suggested Facebook supported CISA (a fact not in evidence, for whatever that'…

they're referring to Sec 4 (d) (4) (b) Also 5 (d) (3) (a) and (b) which exempts "Cyber threat indicators and defensive measures provided to the Federal Government under this Act".

Right. Same deal, right? They're simply saying that raw indicators are exempt from FOIA, and, of course, they'd have to be.

Re: Despite privacy concerns, CISA bill poised for passage

#23
post #3
post #2

Once again we can thank Dianne Feinstein for this. How did she get re-elected again? Was it gerrymandering or did her NSA buddies, which she keeps propping up, hack the poorly secured voting machines?

Feinstein is a senator. How could gerrymandering have anything to do with her election?

Have you seen the shape of California? I mean, it's implausible at best. :-)

But seriously, it's kind of fun to imagine what life would be like if U.S. states were shaped like House districts. Maryland is probably the closest, geometrically.

Re: Despite privacy concerns, CISA bill poised for passage

#24
post #22
post #21

Earlier quoted context omitted.

they're referring to Sec 4 (d) (4) (b) Also 5 (d) (3) (a) and (b) which exempts "Cyber threat indicators and defensive measures provided to the Federal Government under this Act".

Right. Same deal, right? They're simply saying that raw indicators are exempt from FOIA, and, of course, they'd have to be.

So I guess the serious (and it is serious) question is this. If I can't FOIA for security indicators, or defensive measures, then how could I ever know that they included illegal or illegitimate information about me?

Re: Despite privacy concerns, CISA bill poised for passage

#25
post #24
post #22

Earlier quoted context omitted.

Right. Same deal, right? They're simply saying that raw indicators are exempt from FOIA, and, of course, they'd have to be.

So I guess the serious (and it is serious) question is this. If I can't FOIA for security indicators, or defensive measures, then how could I ever know that they included illegal or illegitimate information about me?

I think a U.S. citizen can file a request for records about themself via the Privacy Act. As I understand it, FOIA allows anyone to ask for anything; Privacy Act allows one person to ask for information about themselves.

I don't know if CISA also prevents Privacy Act requests, or if it only applies to FOIA.

Theoretically, companies using CISA would anonymize personally identifiable information before sharing to the government. An IP address, for example, is probably not PII (as millions of people have pointed out in the context of digital piracy lawsuits). I doubt one could file a Privacy Act request just based on an IP address.

Re: Despite privacy concerns, CISA bill poised for passage

#26
I can't believe the number of times this bill has been voted down, only to come back up for a vote again under a different bill or different name.

It is like they keep submitting bills until it gets passed. This not only is a waste of time, it seems to be how the lobbyists get their bills passed. Eventually one will get passed and then our privacy will no longer exist. If you want our data, get a judge to order a search warrant. Otherwise it is Unconstitutional.

Re: Despite privacy concerns, CISA bill poised for passage

#27
post #17
post #13

There's an AMA on reddit right now with the EFF, Access, Fight for the Future, FFTF, and Demand Progress about this. https://www.reddit.com/r/IAmA/comments/3qban2/oh_look_its_th... Looks like it just started a few minutes ago, so no idea if it'll be useful, or not.

I'm never super happy with EFF's advocacy (I think they do good and important legal and technical work but I'm almost always unhappy with how they represent policy to the public). I've been uniformly discouraged by FFTF's advocacy, which I find goes way past "misleading" into "straight up dishonest", such as their recent piece that strongly suggested Facebook supported CISA (a fact not in evidence, for whatever that'…

It is uncontroversial to state that corporations and special interest groups frequently lobby in public for a position and in private against a position. Frequently you know this only through un-attributable information passed to you.

Advocacy organizations are not journalists. They don't need to cite their sourcing before making claims they believe are true. The purpose of calling out Facebook is an attempt force them to align their public and private positions if they differ.

As usual, Marcy does excellent analysis about what information NSA will be able to collect, analyze and disseminate under CISA.[1]

[1] https://www.emptywheel.net/2015/10/26/two-intended-consequen...

Re: Despite privacy concerns, CISA bill poised for passage

#28
post #27
post #17

Earlier quoted context omitted.

I'm never super happy with EFF's advocacy (I think they do good and important legal and technical work but I'm almost always unhappy with how they represent policy to the public). I've been uniformly discouraged by FFTF's advocacy, which I find goes way past "misleading" into "straight up dishonest", such as their recent piece that strongly suggested Facebook supported CISA (a fact not in evidence, for whatever that'…

It is uncontroversial to state that corporations and special interest groups frequently lobby in public for a position and in private against a position. Frequently you know this only through un-attributable information passed to you. Advocacy organizations are not journalists. They don't need to cite their sourcing before making claims they believe are true. The purpose of calling out Facebook is an attempt force th…

This is a blog post that makes two very broad claims:

1. That Chrysler can exploit CISA to avoid liability for vulnerabilities in their cars simply by sharing the flaws with the USG as an "indicator".

2. That the USG can use CISA to collude with private companies to avoid warrant requirements and spy on their customers.

Both of these points are, I think, false. I've linked upthread to the text of the bill and provided a summary. In particular, I don't think the "Chrysler reading" of the bill finds any support at all in the text; Chrysler is immunized from suits stemming from their own sharing, and even in the sharing, they are explicitly on the hook for negligence and misconduct.

If it's helpful, here's the entire limitation of liability in CISA. Notice: companies are exempt from liability for monitoring, sharing, and receipt of indicators. They aren't exempt from liability for having vulnerabilities in the first place!

    6.Protection from liability
     
    (a) Monitoring of information systems 
     
    No cause of action shall lie or be maintained in any court against
    any private entity, and such action shall be promptly dismissed,
    for the monitoring of information systems and information under
    section 4(a) that is conducted in accordance with this Act.
     
    (b) Sharing or receipt of cyber threat
    indicators 
     
    No cause of action shall lie or be maintained in any court against
    any entity, and such action shall be promptly dismissed, for the
    sharing or receipt of cyber threat indicators or defensive
    measures under section 4(c) if—
     
    (1) such sharing or receipt is conducted in accordance with this
    Act; and
     
    (2) in a case in which a cyber threat indicator or defensive
    measure is shared with the Federal Government, the cyber threat
    indicator or defensive measure is shared in a manner that is
    consistent with section 5(c)(1)(B) and the sharing or receipt, as
    the case may be, occurs after the earlier of—
     
    (A) the date on which the interim policies and procedures are
    submitted to Congress under section 5(a)(1); or
     
    (B) the date that is 60 days after the date of the enactment of
    this Act.
     
    (c) Construction
     
    Nothing in this section shall be
    construed—
     
    (1)to require dismissal of a cause of action against an entity
    that has engaged in gross negligence or willful misconduct in the
    course of conducting activities authorized by this Act; or
     
    (2)to undermine or limit the availability of otherwise applicable
    common law or statutory defenses.

Re: Despite privacy concerns, CISA bill poised for passage

#29
post #24
post #22

Earlier quoted context omitted.

Right. Same deal, right? They're simply saying that raw indicators are exempt from FOIA, and, of course, they'd have to be.

So I guess the serious (and it is serious) question is this. If I can't FOIA for security indicators, or defensive measures, then how could I ever know that they included illegal or illegitimate information about me?

You can FOIA for records the government keeps in the management of indicators from different companies; the only thing excluded is the indicators themselves. Again: how could it be otherwise?

Re: Despite privacy concerns, CISA bill poised for passage

#30
post #9

The actual text of CISA: https://www.govtrack.us/congress/bills/114/s754/text There are no amendments to CISA that I can find (CISPA collected quite a few amendments, some of which were very relevant to HN, before the bill eventually died). I read CISA so you don't have to! (You still should). Here's a summary: There are three particularly important defined concepts: >, which means "unauthorized activity" that might…

I could be missing a further limitation, but doesn't Section 4(a) de facto amount to a repeal of all other laws that limit monitoring? Yes, the exception is limited to monitoring for a "security purpose", but a pretty broad range of things can be justified as a "security purpose". I'm also skeptical that courts will seriously second-guess companies' representations on that point.
Post reply on HN