Live data from Hacker News

Tech group representing Google, Yahoo backs CISPA

thehill.com

51–60 of 77 posts

Re: Tech group representing Google, Yahoo backs CISPA

#51

So who is TechNet? It's not really fair to cherry-pick from their members when writing a story like this. So let's take a look: http://www.technet.org/leaders/member-companies/ A headline "Tech group representing AT&T, Palantir backs CISPA" isn't good copy. But that could have been the headline. The "Executive Council" (which seems to be the part of the organization that draws the focus on Google and Yahoo) also cont…

The difference is, we expect this sort of Evil behavior from AT&T, Palantir, Oracle, VeriSign and definitely Microsoft. But when a company with the supposed motto of "Don't be evil" backs it, it's news. Yahoo, though, I'm only a little surprised. I'm also not surprised Apple is a member, nor that you (and the headline) didn't mention them. Sure, sure, you can't keep track of the political positions of every group you…

Google has never "backed" CIPSA. Facebook and Microsoft previously backed CISPA but then distanced themselves. See: http://news.cnet.com/8301-13578_3-57579012-38/privacy-protec...

Trade associations tend to remain silent when a good portion of their members oppose legislation. But Google/Facebook/Microsoft aren't opposing CISPA, last I checked. It's more like they're just remaining neutral.

Re: Tech group representing Google, Yahoo backs CISPA

#52
post #39

Earlier quoted context omitted.

You probably don't care if you can convince tptacek, but to random people following along (who you might be able to convince), calling tptacek mindless undermines your goal.

tptacek has a dog in this hunt. I'd say his comments here are quite mindful of that.

That is news to me.

Re: Tech group representing Google, Yahoo backs CISPA

#53
post #50
post #24

Earlier quoted context omitted.

You just made an argument that is directly contradicted by the text of the bill. ‘(B) EXCLUSION.— Such term does not 23 include information pertaining to efforts to gain 24 unauthorized access to a system or network of 25 a government or private entity that solely in 1 volve violations of consumer terms of service or 2 consumer licensing agreements and do not oth- 3 erwise constitute unauthorized access.

Except that Aaron Swartz was not charged with unauthorized access "solely" because of his violation of a TOU or EULA. Mind you, I'm not saying the previous poster's claim is the best argument against CISPA, but that your claim of "directly contradicted" is false.

No, I was responding to the "unauthorized access" point in the parent comment. Since you can't be charged with a crime under CISPA at all, I'm not sure how your comment isn't a non sequitur.

Re: Tech group representing Google, Yahoo backs CISPA

#54
post #29
post #27

Earlier quoted context omitted.

I feel like I'm being charitable by discussing CISPA as if it was somehow similar to SOPA or PIPA, because CISPA has nothing whatsoever to do with SOPA or PIPA. I do not have a problem with people who generally oppose Internet regulation of all sorts (I don't agree, but I don't make fun of them either). I do have a problem with "Internet Hate Machines" of all sorts. You are not entitled to invoke principles to deploy…

The connection between SOPA/PIPA and CISPA goes the other way; anti-SOPA/PIPA entities are using CISPA to fundraise and influenceraise, independent of the reality of CISPA. The only amendments I've read about in 2013 are PII removal and removing the "national security" terms, both of which are civil liberties enhancements. (although I don't know where to find the actual text of the amendments). The 2012 amendments we…

>(although I don't know where to find the actual text of the amendments).

This¹ site lists the amendments and has a PDF for each. I'm not sure if it's all of them or contains the ones you mention. The PDFs are dated and some are Feb-April 2013. This PDF² seems to be the current bill with the amendments accounted for in the text ("H.R. 624 as Amended").

edit: I just noticed that ² has a date of Feb. 2013 while some of the amendments have April 2013 dates, so I don't think it's the most current version.

¹ http://intelligence.house.gov/hr-624-bill-and-amendments

² http://intelligence.house.gov/sites/intelligence.house.gov/f...

Re: Tech group representing Google, Yahoo backs CISPA

#55
post #43

Didn't Google recently file a lawsuit claiming that NSLs which are used to uncover private user information are unconstitutional? Edit: They did [1]. [1] http://www.bloomberg.com/news/2013-04-04/google-fights-u-s-n...

There is no intersection between the NSL controversy and CISPA. CISPA is entirely opt-in . Google has to volunteer the information; it can't be coerced into doing so by the government. Even if Google wanted to share emails, voluntarily, it would not find authority to do so in CISPA, because CISPA scopes the kinds of information that can be shared to data incident to actual cyber attacks.

I halfway agree. Google and some other left-coast companies are the least likely to take advantage of CISPA's wildcard override-all-existing-privacy-laws loophole. Google has fought the DOJ in court before to protect the privacy of their users; they're fighting the FBI now. Facebook, Amazon, and Twitter have done the same.

But other companies, including AT&T, are far more likely to exploit this loophole (in fact they persuaded Congress to immunize them for illegal activity, post-facto): http://news.cnet.com/8301-13578_3-9986716-38.html

Your claim that a company could "not find authority" to share emails under CISPA is close to the mark but not quite there. First, the House Intelligence committee rejected an amendment by a 4-16 vote that would have required companies to "make reasonable efforts" to delete "information that can be used to identify" individual Americans.

Second, data that can be freely shared with FedGov including NSA encompasses broad categories of information relating to security vulnerabilities, network uptime, intrusion attempts, and denial-of-service attacks, with no limit on sharing emails or personal data. See: http://news.cnet.com/8301-13578_3-57579012-38/privacy-protec...

Re: Tech group representing Google, Yahoo backs CISPA

#56
post #46
post #27

Earlier quoted context omitted.

I feel like I'm being charitable by discussing CISPA as if it was somehow similar to SOPA or PIPA, because CISPA has nothing whatsoever to do with SOPA or PIPA. I do not have a problem with people who generally oppose Internet regulation of all sorts (I don't agree, but I don't make fun of them either). I do have a problem with "Internet Hate Machines" of all sorts. You are not entitled to invoke principles to deploy…

I have read the 2013 House CISPA amendments and wrote about them here: http://news.cnet.com/8301-13578_3-57579012-38/privacy-protec... I'd be interested to hear defenders of the legislation explain why CISPA remains such a lovely bill after the House Intelligence committee rejected these four amendments that were aimed at protecting privacy: * Limiting the sharing of private sector data to civilian agencies, and spec…

I kind of hate those amendments (without having read them). I'm not really defending CISPA (I would like better security, but I generally distrust the government both for competence and for goals/morality/ethics).

1) NSA and USAF are specifically the only parts of the USG I want to have access to this data. I trust NSA and DOD way more than I trist FBI, DEA, etc. to not fuck me personally if my data is somehow included in a dump given to them for anti-terrorism purposes.

2) Useless bureaucrat. I don't believe in oversight of government by government; mandatory reporting requirements to the public, with independent watchdogs like EFF/ACLU, are the only thing which would really work for me.

3) Vague thing is vague.

4) I don't really want companies to have to do PII filtering; I'd rather they be able to dump bulk data if under attack, since J. Random big dumb company or non-security startup is in no position to do forensics, filter, etc.

Re: Tech group representing Google, Yahoo backs CISPA

#57
post #55
post #43

Earlier quoted context omitted.

There is no intersection between the NSL controversy and CISPA. CISPA is entirely opt-in . Google has to volunteer the information; it can't be coerced into doing so by the government. Even if Google wanted to share emails, voluntarily, it would not find authority to do so in CISPA, because CISPA scopes the kinds of information that can be shared to data incident to actual cyber attacks.

I halfway agree. Google and some other left-coast companies are the least likely to take advantage of CISPA's wildcard override-all-existing-privacy-laws loophole. Google has fought the DOJ in court before to protect the privacy of their users; they're fighting the FBI now. Facebook, Amazon, and Twitter have done the same. But other companies, including AT&T, are far more likely to exploit this loophole (in fact they…

You wrote a lengthier comment that enumerated the failed CISPA amendments that I need to take some time to respond to, but in the meantime:

Regarding PII in threat data, we're talking about orthogonal concerns. The amendment you're talking about would require all threat data to use (presumably commercially reasonable methods) to scrub PII. The concern there is accidental inclusion of PII; it's that disclosure of, say, IP addresses in NetFlow information might uniquely identify customers. But providers today aren't required to fully anonymize NetFlow when they cooperate with investigations. The amendment was a sensible measure and I wish it had passed, but its failure does not break new ground for privacy nor does it change the original scope of the bill. When we last discussed CISPA on HN, that amendment didn't exist, and I still didn't think the bill was scary.

The PII concerns I'm referring to involve the idea that CISPA could be used to frame individual citizens as cyber threat protected entities so that raw information about them could be shared by AT&T incident to some supposed attack. That is an interpretation of CISPA that was explicitly rejected by the bill's sponsors; they cite specific language they added to the bill to counter that interpretation.

(I didn't downvote you and don't understand why anyone would downvote you, but I could get downvoted here for saying "water is wet", so oh well.)

Re: Tech group representing Google, Yahoo backs CISPA

#58
post #45
post #19

Earlier quoted context omitted.

I don't understand why you think CISPA is hard to parse. The 2013 draft bill is public. The bill is extraordinarily short. And much of the objections --- which you rightly call out as emotional --- are contradicted by the text of the bill. I don't so much care whether CISPA passes. What I do care about is people trying to fundraise by convincing willfully ignorant nerds that CISPA is a backdoor SOPA bill; why, just l…

I agree with tptacek (hi there!) that CISPA is not that difficult to parse, and that people might as well read it for themselves. More: http://news.cnet.com/8301-13578_3-57579012-38/privacy-protec... But I disagree with his "Michigan Militia" analogy, which is a bit silly. Another way to look at it is that starting with Clipper, CDA, CALEA, crypto export controls (plus mandatory domestic key escrow approved by a Hous…

Wait, what? We don't have Clipper or key escrow of any sort. You seem to be arguing that every measure ever introduced into Congress has to be judged against the dumbest ideas ever introduced into Congress.

Re: Tech group representing Google, Yahoo backs CISPA

#59
post #56
post #46

Earlier quoted context omitted.

I have read the 2013 House CISPA amendments and wrote about them here: http://news.cnet.com/8301-13578_3-57579012-38/privacy-protec... I'd be interested to hear defenders of the legislation explain why CISPA remains such a lovely bill after the House Intelligence committee rejected these four amendments that were aimed at protecting privacy: * Limiting the sharing of private sector data to civilian agencies, and spec…

I kind of hate those amendments (without having read them). I'm not really defending CISPA (I would like better security, but I generally distrust the government both for competence and for goals/morality/ethics). 1) NSA and USAF are specifically the only parts of the USG I want to have access to this data. I trust NSA and DOD way more than I trist FBI, DEA, etc. to not fuck me personally if my data is somehow includ…

It would have taken me 19 paragraphs to make the same points. I agree with all of them.

Ryan, your head seems to be screwed on properly, so what are the things you would like to see done to CISPA to make it commercially feasible to share bulk data when banks or ISPs come under sustained attack?

Re: Tech group representing Google, Yahoo backs CISPA

#60
post #45
post #19

Earlier quoted context omitted.

I don't understand why you think CISPA is hard to parse. The 2013 draft bill is public. The bill is extraordinarily short. And much of the objections --- which you rightly call out as emotional --- are contradicted by the text of the bill. I don't so much care whether CISPA passes. What I do care about is people trying to fundraise by convincing willfully ignorant nerds that CISPA is a backdoor SOPA bill; why, just l…

I agree with tptacek (hi there!) that CISPA is not that difficult to parse, and that people might as well read it for themselves. More: http://news.cnet.com/8301-13578_3-57579012-38/privacy-protec... But I disagree with his "Michigan Militia" analogy, which is a bit silly. Another way to look at it is that starting with Clipper, CDA, CALEA, crypto export controls (plus mandatory domestic key escrow approved by a Hous…

tptacek: You're quite right that neither are with us today. The reason: Clipper and key escrow were defeated by the same advocacy groups you claim, without any evidence, are trying to "fundraise by convincing willfully ignorant nerds" CISPA is bad.

I can imagine FBI director Louis Freeh saying the same thing when he was defending bans on non-escrowed encryption in the late 1990s: "Nothing wrong with mandatory key escrow! Silly ACLU EFF EPIC etc. are just trying to fundraise off of fear and emotion."

Post reply on HN