Live data from Hacker News

Civil Liberties Groups Speak Out Against CISPA in Lead Up to Hearings

eff.org

51–60 of 113 posts

Re: Civil Liberties Groups Speak Out Against CISPA in Lead Up to Hearings

#51

As a wise man pointed out on HN the last time around, we haven't won when this law fails to pass. We've only won a law explicitly stating the opposite passes.

So what you're saying is, the best possible thing to happen would be a law specifically preventing any American company from relaying threat information --- packet captures of exploits, netflow traffic profiles of botnets, &c --- to the US government, and, further, preventing any agency in the USG from providing traffic capture information, packet filter information, or botnet identification information to private companies.

Re: Civil Liberties Groups Speak Out Against CISPA in Lead Up to Hearings

#52

I am never more reminded of how smart people can succumb to groupthink than I am when I read HN posts about CISPA. There are a lot of misconceptions about the law, including what kind of data gets shared (only relevant threat data, this isn't your bank account info, and the RIAA can't sue you if shared data reveals you to be torrenting movies - can elaborate more on this if there's interest), who does the sharing (or…

It's not necessarily the letter of the law that people are worried about, it's the overreach that would result once it's on the books.

Re: Civil Liberties Groups Speak Out Against CISPA in Lead Up to Hearings

#53
post #5

One of the biggest (and most frustrating) problems with the legislative process is that the people who really want this to go through KNOW that we - "the masses" - eventually start to suffer from "protest exhaustion". They can propose a bill - we can rally our troops and get on TV and black out Wikipedia and do 100 interviews and maybe - just maybe - we can kill it. The first time. And maybe the second time. And mayb…

You are especially likely to become numb to calls to arms when they are in fact cries of "wolf".

SOPA was a genuinely invasive bill and a clear power grab by the content industry. It created a new special second-class "tainted" designation for content sites that refused to play ball with rightsholders and gave rightsholders new means to prosecute their rights outside of civil courts. It was understandable and --- even though I'm a supporter of copyright in general --- commendable that organized opposition to SOPA killed that bill outright.

CISPA is nothing like SOPA.

To begin with, CISPA has none of the same objectives of SOPA. It isn't about the content industry at all. In fact, when early opposition to CISPA by organizations like EFF started catching on, its sponsors scrubbed the bill of language that could have been read (in a stretch) as protecting rightsholders. CISPA is about online security attacks, not about piracy.

Next, CISPA isn't invasive. SOPA threatened to create a kangaroo court system of copyright-noncompliant sites that the content industry could starve by banning commercial transactions with them. CISPA is an opt-i bill; the USG cannot compel any organization to cooperate with any USG agency, but instead creates a facility that companies can use if they need to share attack information but don't want to spend $100,000 in ECPA-interpreting legal review each time they do it.

In fact, CISPA in practice probably has more to do with information moving FROM the USG TO private companies. The USG spends hundreds of millions of dollars a year monitoring its networks (which together constitute the largest IT organization in the world). It is true that the largest IT org in the world happens to be a shitty IT shop, but it has nevertheless built up about a decade of experience tracking malware and botnets and DOS attack information; when Blaster broke out, the experience of the Naval Marine Corp Intranet getting overrun by it was some of the first shared among ISPs. All sorts of random rules prevent USG IT shops from running any kind of central clearinghouse of attack information, and still more rules prevent any of that information from being published.

I don't particularly like CISPA. It obviously sounds like I do, but that's because the uninformed paranoia about CISPA is so virulent that any measured take on the bill sounds like cheerleading. I don't care whether CISPA passes or doesn't pass. But it drives me a little bananas to see how easily the ostensibly curious and well-informed people on HN are bamboozled by identity politics on issues like this.

It's a tiny bill, as bills go. Just go read it.

Re: Civil Liberties Groups Speak Out Against CISPA in Lead Up to Hearings

#54

I am never more reminded of how smart people can succumb to groupthink than I am when I read HN posts about CISPA. There are a lot of misconceptions about the law, including what kind of data gets shared (only relevant threat data, this isn't your bank account info, and the RIAA can't sue you if shared data reveals you to be torrenting movies - can elaborate more on this if there's interest), who does the sharing (or…

It's not necessarily the letter of the law that people are worried about, it's the overreach that would result once it's on the books.

Having read the criticism the EFF's been pointing at CISPA, I fail to see how they're interpreting the bill to mean that such overreaching is even possible. I want to see what sort of changes the EFF would make to the current bill which would satisfy the privacy concerns they're claiming exist.

I think everyone agrees that companies should be able to describe to the cops what the guy who robbed them looked like, and those companies should be able to tell their customers they've been robbed without getting sued by their shareholders because the ensuing PR fallout tanks the stocks.

Re: Civil Liberties Groups Speak Out Against CISPA in Lead Up to Hearings

#55
post #42

Earlier quoted context omitted.

Political maneuvering has nothing to do with what CISPA actually says (as many others in this thread have pointed out).

The bill is too short to lie about what's in it. Anyone with about 5 minutes and a 4th grade reading level can at least muddle through.

For anyone wants to read it you can find the full text here: http://www.govtrack.us/congress/bills/112/hr3523/text

Re: Civil Liberties Groups Speak Out Against CISPA in Lead Up to Hearings

#56

I am never more reminded of how smart people can succumb to groupthink than I am when I read HN posts about CISPA. There are a lot of misconceptions about the law, including what kind of data gets shared (only relevant threat data, this isn't your bank account info, and the RIAA can't sue you if shared data reveals you to be torrenting movies - can elaborate more on this if there's interest), who does the sharing (or…

It's not necessarily the letter of the law that people are worried about, it's the overreach that would result once it's on the books.

The USG is actively prevented by current regulations from setting up a clearinghouse that would collect netflow signatures, botnet identification, and traffic captures of exploit code and then sharing that information with companies like Google and Facebook.

Private companies can and do share (heavily scrubbed) electronic signature information, but must go through contortions to do so, and incur huge legal costs to do it. As a result, only the largest companies participate in these efforts.

Because the USG is more or less enjoined from participating in clearinghouses with private companies, information sharing networks are handshake affairs that are often unknown to anyone outside tier-3 network engineering. Other private IT security product companies run de facto clearinghouses, but only for their customers.

As a result, when your startup gets DDoS'd and you call your ISP for help, they generally can't do shit to help you. It may annoy you to know that if your connectivity provider is large, there is a group in there that could offramp your traffic to internal "scrubbing centers" to peel off DDOS traffic. But because high-end DDoS protection at ISPs is done sub rosa, startups have a very hard time finding these people.

There is an actual problem with online security attacks right now, and hysteria over any USG intervention with the Internet at all is helping perpetuate it. And all it appears to take to fuel that hysteria is statements like "think of the overreach that will happen once a law hits the books".

Re: Civil Liberties Groups Speak Out Against CISPA in Lead Up to Hearings

#57
post #26
post #12

Earlier quoted context omitted.

I worry that most of the opposition to this bill is based on FUD that EFF is spreading. Having experience actually working in the security industry and knowing the limitations that this bill is trying to address, the ability of the government and private sector to work together to keep malicious groups out of their networks, I recognize the necessity and intentions of this bill. This isn't about spying on Americans.…

I understand what you're saying, but when legislation is proposed I look at what it very easily could enable, not just what it's written to be for. When I look at what's being proposed I see that the government is using its sovereign power to trade away my right to civil suit against a company in event of a data loss, in exchange to that company for it handing over private information (that very well can include cust…

You are not allowed to make arguments that are directly rebutted by the facts. There were drafts of CISPA that were published in which the assets protected by the bill (which defines attacks in terms of the familiar C.I.A. triad) included "IP", which would have included things like the source code to operating system drivers. But the bill that got voted on included a series of amendments, all published, that neutered that language because of exactly that concern.

CISPA is simply not about the interests of rightsholders.

Re: Civil Liberties Groups Speak Out Against CISPA in Lead Up to Hearings

#58
post #51

As a wise man pointed out on HN the last time around, we haven't won when this law fails to pass. We've only won a law explicitly stating the opposite passes.

So what you're saying is, the best possible thing to happen would be a law specifically preventing any American company from relaying threat information --- packet captures of exploits, netflow traffic profiles of botnets, &c --- to the US government, and, further, preventing any agency in the USG from providing traffic capture information, packet filter information, or botnet identification information to private co…

No. In my mind, the best possible thing to happen would be a law specifically preventing any American government agency from requiring any company to hand over such information without due process. Sadly, you would think this was already clear enough from the constitution, but there are already enough loop holes that it happens anyway. Another good thing would be for American internet companies to voluntarily adopt and adhere to privacy policies along the same lines.

Re: Civil Liberties Groups Speak Out Against CISPA in Lead Up to Hearings

#59
post #34
post #28

Earlier quoted context omitted.

> If you want to talk about confusing, I watch C-SPAN constantly (it's an illness) and whenever anybody in the legislative or executive branch talks about "cyber security" they always talk about IP protection and "preventing a cyber pearl harbor" in the same breath. The trouble is that the effective, worthwhile and highly damaging cyberattacks all involve IP, in some way or another. There's not much value in taking d…

No they don't. I think it is extremely confusing to talk about theft of data at the same time as talking about someone hacking a nuclear power plant to go into meltdown or something. When people say things like "cyber pearl harbor" at that time they could be talking about a DDOS that makes it impossible to do online banking or they could be talking about an attack on SCADA systems at a power plant that takes out powe…

I have no idea what this comment is even trying to articulate. You suggest two kinds of "cyber attacks", one which cause power plants to malfunction and the other that attacks online banking. I am not sure what you think this distinction demonstrates about online security.

On the one hand, the attacks on power plants that you allude to are possible. Utilities have been networked and electronically controlled since the 1970s. Nobody builds networks on telephony or X.25 anymore; it's all IP. IP connectivity to insanely sensitive systems leaks routinely; moreover, application-level data sharing between Internet-connected systems and supposedly air-gapped backend systems is extremely common.

On the other hand, the "less serious" attacks you allude to are very very bad. Google and Hotmail aren't national utilities. But they are attacked by state actors because dissident organizations use them to communicate. For that matter, the Internet backbone is a collection of computers sharing information using a decades-old routing protocol for which policy is controlled by regular expressions.

Finally, if you run a startup and happen to say something I disagree with, such as "I think CISPA is a power grab by the content industry", I could today very easily push you off the Internet with a trivial DDoS attack. The people who extorted online casinos with DDoS botnets were not rocket surgeons. When I attack you for disagreeing me online, and you call your ISP, guess what you're going to hear? "You're on your own". It is always very weird for me to see people on Hacker News, a hub for online startup news, downplaying the severity of DOS attacks. I've spent a decent chunk of my career in DOS mitigation and it is not remotely a solved problem.

Re: Civil Liberties Groups Speak Out Against CISPA in Lead Up to Hearings

#60
post #51

Earlier quoted context omitted.

So what you're saying is, the best possible thing to happen would be a law specifically preventing any American company from relaying threat information --- packet captures of exploits, netflow traffic profiles of botnets, &c --- to the US government, and, further, preventing any agency in the USG from providing traffic capture information, packet filter information, or botnet identification information to private co…

No. In my mind, the best possible thing to happen would be a law specifically preventing any American government agency from requiring any company to hand over such information without due process. Sadly, you would think this was already clear enough from the constitution, but there are already enough loop holes that it happens anyway. Another good thing would be for American internet companies to voluntarily adopt a…

CISPA does not require any company to hand over any information to the USG without due process!
Post reply on HN