Live data from Hacker News

Despite privacy concerns, CISA bill poised for passage

america.aljazeera.com

31–40 of 95 posts

Re: Despite privacy concerns, CISA bill poised for passage

#31
post #24

Earlier quoted context omitted.

So I guess the serious (and it is serious) question is this. If I can't FOIA for security indicators, or defensive measures, then how could I ever know that they included illegal or illegitimate information about me?

I think a U.S. citizen can file a request for records about themself via the Privacy Act. As I understand it, FOIA allows anyone to ask for anything; Privacy Act allows one person to ask for information about themselves. I don't know if CISA also prevents Privacy Act requests, or if it only applies to FOIA. Theoretically, companies using CISA would anonymize personally identifiable information before sharing to the g…

It specifically mentions "552(b)(3)(B) of title 5" which is the FOIA statute. No mention of the privacy act.

Re: Despite privacy concerns, CISA bill poised for passage

#32
post #9

The actual text of CISA: https://www.govtrack.us/congress/bills/114/s754/text There are no amendments to CISA that I can find (CISPA collected quite a few amendments, some of which were very relevant to HN, before the bill eventually died). I read CISA so you don't have to! (You still should). Here's a summary: There are three particularly important defined concepts: >, which means "unauthorized activity" that might…

I could be missing a further limitation, but doesn't Section 4(a) de facto amount to a repeal of all other laws that limit monitoring? Yes, the exception is limited to monitoring for a "security purpose", but a pretty broad range of things can be justified as a "security purpose". I'm also skeptical that courts will seriously second-guess companies' representations on that point.

Yep, I called that section out for that reason. I'm not particularly worried about it (I think this part of CISA mostly just clarifies something that was already pretty much settled).

Companies aren't allowed to just make up "security purpose", though; under CISA, they have to be monitoring for threats as construed in CISA, which means, for instance, they can't find exemption for liability for monitoring for mere ToS violations.

Re: Despite privacy concerns, CISA bill poised for passage

#33
post #29
post #24

Earlier quoted context omitted.

So I guess the serious (and it is serious) question is this. If I can't FOIA for security indicators, or defensive measures, then how could I ever know that they included illegal or illegitimate information about me?

You can FOIA for records the government keeps in the management of indicators from different companies; the only thing excluded is the indicators themselves. Again: how could it be otherwise?

So, in reality, if I suspected that there was some privacy breach with regards to the transfer of information, I could not prove it. This means that I would have no standing in court (no proof of injury means no standing). This seems problematic, and worthy of examining the privacy implications (or at least discussing them)

how could it be otherwise?

Allow FOIA, and use the existing exemptions for classified material if the information is actually classified. This would mean that breaches of privacy could be found when non-classified information is present.

There seems to be concentration on "indicators" being username/passwords, etc. However, Sec 2 (6) (G) is "any other attribute of a cybersecurity threat, if disclosure of such attribute is not otherwise prohibited by law;". That's basically anything since cybersecurity threat is defined as "means _an action_ ... on or through an information system that _may_ result in an unauthorized effort ...". That seems to be a rather large hole.

Re: Despite privacy concerns, CISA bill poised for passage

#34
post #33
post #29

Earlier quoted context omitted.

You can FOIA for records the government keeps in the management of indicators from different companies; the only thing excluded is the indicators themselves. Again: how could it be otherwise?

So, in reality, if I suspected that there was some privacy breach with regards to the transfer of information, I could not prove it. This means that I would have no standing in court (no proof of injury means no standing). This seems problematic, and worthy of examining the privacy implications (or at least discussing them) how could it be otherwise? Allow FOIA, and use the existing exemptions for classified material…

The problem is that none of this information is "classified". PII isn't classified. Zero-day vulnerabilities aren't classified. Classified information is stuff that goes through USG classification process.

So there'd need to be some other regime in place that ensures that no harm is done by publishing information that companies are voluntarily sharing with the USG.

What would that regime look like?

I'm also not really convinced that there's a problem with the catch-all at the end of Sec.2(6) --- that's enabling companies to share things they were already allowed to share, and just bringing it under the same set of controls as the new sensitive stuff they can share. How is that a loophole the USG can exploit? What does that loophole look like in practice, in actual use?

Re: Despite privacy concerns, CISA bill poised for passage

#35
post #28
post #27

Earlier quoted context omitted.

It is uncontroversial to state that corporations and special interest groups frequently lobby in public for a position and in private against a position. Frequently you know this only through un-attributable information passed to you. Advocacy organizations are not journalists. They don't need to cite their sourcing before making claims they believe are true. The purpose of calling out Facebook is an attempt force th…

This is a blog post that makes two very broad claims: 1. That Chrysler can exploit CISA to avoid liability for vulnerabilities in their cars simply by sharing the flaws with the USG as an "indicator". 2. That the USG can use CISA to collude with private companies to avoid warrant requirements and spy on their customers. Both of these points are, I think, false. I've linked upthread to the text of the bill and provide…

I could bug Marcy for an answer. I will do totally inadequate job of defending her analysis compared to her.

It seems relatively simple to read this passage in the following way:

Let's say a major car company decided to leave open a port with a remote code execution vulnerability on their cars.

Let's say this car company discovered this port was being exploited and informs the NSA of affected vehicles IMEI numbers, IP addresses etc.

Now let's say FTC/NTSB wanted to put together a case for punishing the car manufacturer for their poor security operations.

It seems perfectly reasonable for a lawyer to read the passage from CISA and claim the court couldn't use any disclosure to the government under like the number of affected vehicles(easily calculated from the threat information previously shared) in any determination of liability.

Re: Despite privacy concerns, CISA bill poised for passage

#36
post #27
post #17

Earlier quoted context omitted.

I'm never super happy with EFF's advocacy (I think they do good and important legal and technical work but I'm almost always unhappy with how they represent policy to the public). I've been uniformly discouraged by FFTF's advocacy, which I find goes way past "misleading" into "straight up dishonest", such as their recent piece that strongly suggested Facebook supported CISA (a fact not in evidence, for whatever that'…

It is uncontroversial to state that corporations and special interest groups frequently lobby in public for a position and in private against a position. Frequently you know this only through un-attributable information passed to you. Advocacy organizations are not journalists. They don't need to cite their sourcing before making claims they believe are true. The purpose of calling out Facebook is an attempt force th…

| Advocacy organizations are not journalists. They don't need to cite their sourcing before making claims they believe are true.

Tell me where you find these journalists today.

Re: Despite privacy concerns, CISA bill poised for passage

#37
post #5
post #2

Once again we can thank Dianne Feinstein for this. How did she get re-elected again? Was it gerrymandering or did her NSA buddies, which she keeps propping up, hack the poorly secured voting machines?

Feinnstein is a very long running senator with a hugely entrenched power base. Because of that it's hard to remove her from office. She also despite being very authoritarian is fairly progressive in other respects so she is able to appeal to her base of older democrats in that respect. I really really dislike her, but it totally makes sense that she is basically invulnerable within her senate seat.

This is the reason why I don't fill in a ballot for her whenever her seat comes up. I know it's not going to do much, and I am not really sure I want a Republican in that seat (if that were even possible) since I doubt it would be any better than her positions.

All I see with her about this is the hypocrisy of it all. She is totally fine with the NSA intervening in our lives, but threw a huge fit when the CIA was found to be spying on members of Congress. Yes, spying on the people is OK, but spying on Congress by the CIA is a "violation of separation of powers" and shouldn't be tolerated?

Re: Despite privacy concerns, CISA bill poised for passage

#38
post #32

Earlier quoted context omitted.

I could be missing a further limitation, but doesn't Section 4(a) de facto amount to a repeal of all other laws that limit monitoring? Yes, the exception is limited to monitoring for a "security purpose", but a pretty broad range of things can be justified as a "security purpose". I'm also skeptical that courts will seriously second-guess companies' representations on that point.

Yep, I called that section out for that reason. I'm not particularly worried about it (I think this part of CISA mostly just clarifies something that was already pretty much settled). Companies aren't allowed to just make up "security purpose", though; under CISA, they have to be monitoring for threats as construed in CISA, which means, for instance, they can't find exemption for liability for monitoring for mere ToS…

Couldn't one collect logs of all things, under the auspices of collecting logs that (may) contain "recon activity" and "exploits"? It seems on a surface reading that one could collect all those under the umbrella of collecting Indicators, and then also use it also for things like selling-to-advertisers or other business-related things.

Of course, our terms of use on most sites already say they can collect + monetize such things, so maybe this is moot.

Re: Despite privacy concerns, CISA bill poised for passage

#39
post #35
post #28

Earlier quoted context omitted.

This is a blog post that makes two very broad claims: 1. That Chrysler can exploit CISA to avoid liability for vulnerabilities in their cars simply by sharing the flaws with the USG as an "indicator". 2. That the USG can use CISA to collude with private companies to avoid warrant requirements and spy on their customers. Both of these points are, I think, false. I've linked upthread to the text of the bill and provide…

I could bug Marcy for an answer. I will do totally inadequate job of defending her analysis compared to her. It seems relatively simple to read this passage in the following way: Let's say a major car company decided to leave open a port with a remote code execution vulnerability on their cars. Let's say this car company discovered this port was being exploited and informs the NSA of affected vehicles IMEI numbers, I…

Again: they can't be prosecuted for sharing, for monitoring, or for receipt of information. This is statutory language and the words matter.

If there's an authority under which Chrysler can be prosecuted for having vulnerabilities (spoiler: I don't believe there is), CISA doesn't change any of that. Certainly, there's no clear linkage between CISA sharing and a private actor's ability to sue Chrysler for torts emerging from vulnerabilities.

I don't even think there's a stretch reading of the statute that gets you where this blog post lands.

Re: Despite privacy concerns, CISA bill poised for passage

#40
post #38
post #32

Earlier quoted context omitted.

Yep, I called that section out for that reason. I'm not particularly worried about it (I think this part of CISA mostly just clarifies something that was already pretty much settled). Companies aren't allowed to just make up "security purpose", though; under CISA, they have to be monitoring for threats as construed in CISA, which means, for instance, they can't find exemption for liability for monitoring for mere ToS…

Couldn't one collect logs of all things, under the auspices of collecting logs that (may) contain "recon activity" and "exploits"? It seems on a surface reading that one could collect all those under the umbrella of collecting Indicators, and then also use it also for things like selling-to-advertisers or other business-related things. Of course, our terms of use on most sites already say they can collect + monetize…

I'm not sure I see the part of CISA that allows you to sell your logs to advertisers. I do see lots of places in the bill that allow sharing to other private entities or to the USG for cybersecurity purposes.
Post reply on HN