Live data from Hacker News

Tech group representing Google, Yahoo backs CISPA

thehill.com

41–50 of 77 posts

Re: Tech group representing Google, Yahoo backs CISPA

#41
post #38
post #22

Earlier quoted context omitted.

That is in fact more or less what the law allows firms to do: when their database is compromised, they are allowed to cooperate with other service providers and with law enforcement to track down what actually happened to their systems without spending $50,000 to ensure that they aren't violating, say, DPPA.

So that means, if the database contained emails, call records, or sms, The feds could read all of it. That sounds like a security risk waiting to happen at your cell phone carrier and email service provider.

Sure. What's the alternative? What did you think happened when law enforcement investigated serious computer crimes? If a financial institution has a key database popped and the Secret Service is called in to investigate, was it your expectation that the victim was required to carefully anonymize and blind all the data in that database? How could any criminal investigation work if that was the requirement? (Cliff's Notes: That's not the requirement).

The bill as written, even before the narrowing amendments, acknowledges the risk this subthread discusses. It does that by trying to define "cyber threat information", as information directly implicated in an attack. In the sponsor's notes on the bill on the House site, they explain that the definition of "protected entity" was changed specifically to prevent individual people from being considered as entities, so that person-specific data couldn't be handed over under CISPA authority.

The basic problem the bill addresses is this: large companies are under continuous attack. Let's stipulate that attacks come in two flavors: DDOS and targeted malware.

In both cases, there is clear utility in allowing companies to collaborate with other companies and with the government.

In the DDOS case, you want to share NetFlow information with your upstream ISPs and with DDOS trackers, because those are the organizations that generate black-hole and IP filtering rules, and they all work better if they have lots of different vantage points to work from. At the very least, you want to push sources back up to your immediate upstream providers so they can soak them up on their infrastructure rather than saturating your uplinks.

In the malware case, you want to share forensic information that would help identify (a) the vulnerability the malware exploits, (b) the C&C system the malware is using, (c) any evidence of the source of the malware, and (d) forensic information that would help investigators discern the intent of the malware.

In both cases, your company's general counsel is apt to inform you that the legal risk of sharing just that information is potentially unbounded, because nobody can predict exactly what claims could be made under ECPA, SCA, DPPA, HIPAA, FERPA, &c; nobody even knows what traces of information, overt or statistical, might be lurking in NetFlow.

So the situation we have today is that there is information sharing when attacks happen, but much of it is sub rosa, and you have to be in the right clubs to get access to the right sharing networks.

It does not make intuitive sense to me that electronic privacy should mean that basic low-level systems information incident to a real attack should incur unbounded legal risk when shared with other companies directly involved in mitigating those attacks.

You might disagree, and that's fine. But the notion that CISPA is actually intended to allow NSA to read your email is just not supported by the language of the bill, by any advocacy for the bill, or by any of the bill's amendments, and the problem the bill is addressing is a real problem (I have some limited professional exposure to it).

Re: Tech group representing Google, Yahoo backs CISPA

#42
post #23

Earlier quoted context omitted.

It's funny you should mention that. Random amendments were in fact added to CISPA 2012. They did things like, for instance, ensuring that terms of services violations wouldn't constitute cyberthreats, or making it clear that bill wasn't intended to stop piracy. The amendments are public too. You can actually read them. As you can see, I'm not very charitable about this. Nerds are to online regulation what the Michiga…

To be fair: THOMAS is usually very slow at putting up amendment text, sometimes taking weeks or months after a vote to put up floor amendments. (I have complained, and they said the should be there the next day, but then I pointed out about 25 cases where it wasn't, and they kinda stopped talking :P)

(THOMAS being the Library of Congress document management system).

Re: Tech group representing Google, Yahoo backs CISPA

#43

Didn't Google recently file a lawsuit claiming that NSLs which are used to uncover private user information are unconstitutional? Edit: They did [1]. [1] http://www.bloomberg.com/news/2013-04-04/google-fights-u-s-n...

There is no intersection between the NSL controversy and CISPA. CISPA is entirely opt-in. Google has to volunteer the information; it can't be coerced into doing so by the government. Even if Google wanted to share emails, voluntarily, it would not find authority to do so in CISPA, because CISPA scopes the kinds of information that can be shared to data incident to actual cyber attacks.

Re: Tech group representing Google, Yahoo backs CISPA

#44
post #39
post #34

Earlier quoted context omitted.

> You could say exactly this set of things about any bill ever. No, I couldn't. There are unfortunately a lot of bills I could have said that about (and I mentioned some of them), but not literally any bill ever. In fact, most bills are not about granting more power to intelligence agencies at the cost of privacy protections. But thanks for sticking to your role as mindless CISPA defender. You play it well. EDIT: > I…

You probably don't care if you can convince tptacek, but to random people following along (who you might be able to convince), calling tptacek mindless undermines your goal.

tptacek has a dog in this hunt. I'd say his comments here are quite mindful of that.

Re: Tech group representing Google, Yahoo backs CISPA

#45
post #19
post #8

This is the part where tptacek says CISPA doesn't do anything particularly bad vs. the state of law now, other people express fairly emotional vs. fact based arguments about what bad it could do, and no one (in industry or government or watchdog groups) really knows for sure what CISPA would, in practice, mean, right?

I don't understand why you think CISPA is hard to parse. The 2013 draft bill is public. The bill is extraordinarily short. And much of the objections --- which you rightly call out as emotional --- are contradicted by the text of the bill. I don't so much care whether CISPA passes. What I do care about is people trying to fundraise by convincing willfully ignorant nerds that CISPA is a backdoor SOPA bill; why, just l…

I agree with tptacek (hi there!) that CISPA is not that difficult to parse, and that people might as well read it for themselves. More: http://news.cnet.com/8301-13578_3-57579012-38/privacy-protec...

But I disagree with his "Michigan Militia" analogy, which is a bit silly. Another way to look at it is that starting with Clipper, CDA, CALEA, crypto export controls (plus mandatory domestic key escrow approved by a House committee), we've lived through 20 years of ill-advised regulation. So unless the merits of a new proposed law clearly outweigh the downsides, which is not the case in CISPA, a measure of skepticism is reasonable.

Re: Tech group representing Google, Yahoo backs CISPA

#46
post #27
post #26

Earlier quoted context omitted.

There's a legitimate reason for the Internet Hate Machine to try to preempt bad law -- it takes a long time to power it up, and sometimes bad law is forced through quickly. The forcing through bad laws with minimal public comment and debate (epitomized by PATRIOT) is the real problem, there, though. There is no possible argument that CISPA, SOPA, or PIPA issues are so pressing as to not allow a reasonable period for…

I feel like I'm being charitable by discussing CISPA as if it was somehow similar to SOPA or PIPA, because CISPA has nothing whatsoever to do with SOPA or PIPA. I do not have a problem with people who generally oppose Internet regulation of all sorts (I don't agree, but I don't make fun of them either). I do have a problem with "Internet Hate Machines" of all sorts. You are not entitled to invoke principles to deploy…

I have read the 2013 House CISPA amendments and wrote about them here: http://news.cnet.com/8301-13578_3-57579012-38/privacy-protec...

I'd be interested to hear defenders of the legislation explain why CISPA remains such a lovely bill after the House Intelligence committee rejected these four amendments that were aimed at protecting privacy:

* Limiting the sharing of private sector data to civilian agencies, and specifically excluding the NSA and the Defense Department. (Failed by a 4-14 vote.)

* Directing the president to create a high-level privacy post that would oversee "the retention, use, and disclosure of communications, records, system traffic, or other information" acquired by the federal government. It would also include "requirements to safeguard communications" with personal information about Americans. (Failed by a 3-16 vote.)

* Eliminating vague language that grants complete civil and criminal liability to companies that "obtain" information about vulnerabilities or security flaws and make "decisions" based on that information. (Failed by a 4-16 vote.)

* Requiring that companies sharing confidential data "make reasonable efforts" to delete "information that can be used to identify" individual Americans. (Failed by a 4-16 vote.)

Re: Tech group representing Google, Yahoo backs CISPA

#47
post #23

Earlier quoted context omitted.

It's funny you should mention that. Random amendments were in fact added to CISPA 2012. They did things like, for instance, ensuring that terms of services violations wouldn't constitute cyberthreats, or making it clear that bill wasn't intended to stop piracy. The amendments are public too. You can actually read them. As you can see, I'm not very charitable about this. Nerds are to online regulation what the Michiga…

To be fair: THOMAS is usually very slow at putting up amendment text, sometimes taking weeks or months after a vote to put up floor amendments. (I have complained, and they said the should be there the next day, but then I pointed out about 25 cases where it wasn't, and they kinda stopped talking :P)

In this case the amendments were online on a .gov site about six hours or so after the vote (thanks, I suspect, to my bugging the committee).

Re: Tech group representing Google, Yahoo backs CISPA

#48
post #17

Earlier quoted context omitted.

The basic issue around CISPA is that it puts the power to share info in the hands of the tech companies. They like it because the government cannot compel actions--unlike the Senate bill last year. Tech companies trust themselves to only share the critical info needed for better security, so they do not see a risk in CISPA. Citizen groups do not trust tech companies or the government, so they see risk in any legislat…

Right, a lot of the issue is that SOPA/PIPA (and before that, PATRIOT, NDAA, etc) have poisoned the water between ~the users of the Internet and ~the Government.

Yes. And this retroactive immunity for illegal (and in some cases criminal) activities, which Candidate Obama supported despite telling me ~six months earlier he would not: http://news.cnet.com/8301-13578_3-9986716-38.html

"...voting to derail lawsuits against telecommunications companies that unlawfully opened their networks to the National Security Agency. Senators voted 69 to 28 for the bill, which would rewrite federal wiretap laws by granting retroactive immunity to telecommunications companies..."

Re: Tech group representing Google, Yahoo backs CISPA

#49
post #41
post #38

Earlier quoted context omitted.

So that means, if the database contained emails, call records, or sms, The feds could read all of it. That sounds like a security risk waiting to happen at your cell phone carrier and email service provider.

Sure. What's the alternative? What did you think happened when law enforcement investigated serious computer crimes? If a financial institution has a key database popped and the Secret Service is called in to investigate, was it your expectation that the victim was required to carefully anonymize and blind all the data in that database? How could any criminal investigation work if that was the requirement? (Cliff's N…

One alternative is to limit CISPA to law enforcement receiving the information rather than the National Security Agency and other arms of the defense-intelligence apparatus. But that amendment failed by a 4-14 vote this week.

May I assume that you'll publicly oppose CISPA if it continues to advance without that amendment? :)

Also, regarding your claims that person-specific data can't be handed over, a separate amendment requiring that failed by a 4-16 vote. So it will be able to be shared with the NSA.

BTW, I'm not arguing that there are not real problems arising from attacks that large companies, and even smaller companies, face. The question is what to do about it, and whether CISPA remains the best vehicle.

Re: Tech group representing Google, Yahoo backs CISPA

#50
post #24
post #9

Earlier quoted context omitted.

Because CISPA's definition of a "cybersecurity" threat is too broad. One of the vague terms it employs is "unauthorized access" -- a term we have seen abused recently in the cases of Aaron Swartz and Weev. My fear is that, like the PATRIOT act, CISPA will grant overly-broad powers to intelligence agencies that will be employed for general surveillance. My view is that any law that curtails liberty should do so minima…

You just made an argument that is directly contradicted by the text of the bill. ‘(B) EXCLUSION.— Such term does not 23 include information pertaining to efforts to gain 24 unauthorized access to a system or network of 25 a government or private entity that solely in 1 volve violations of consumer terms of service or 2 consumer licensing agreements and do not oth- 3 erwise constitute unauthorized access.

Except that Aaron Swartz was not charged with unauthorized access "solely" because of his violation of a TOU or EULA.

Mind you, I'm not saying the previous poster's claim is the best argument against CISPA, but that your claim of "directly contradicted" is false.

Post reply on HN