Earlier quoted context omitted.
You can certainly enjoy your life a lot more if you take your ball, go home, and play with your computer. Who knows, computers may even turn out to be popular in a decade's time.
I've come to the conclusion that mainstreaming a technology results in the technology conforming to the mainstream, rather than the mainstream adopting the interests of the early adopters of the technology.
Civil Liberties Groups Speak Out Against CISPA in Lead Up to Hearings
81–90 of 113 posts
Re: Civil Liberties Groups Speak Out Against CISPA in Lead Up to Hearings
#82Earlier quoted context omitted.
Pushing their agenda: "You wouldn't download a car"? Not covering other agendas: basically any news agency ever that only covers one side of a story (e.g. anti-gun-control news stations only reporting positive gun news, pro-gun-control stations only reporting negative gun news, no news stations reporting on anything outside the viewer-driving manufactured hot button issues). Another example, though this is an isolate…
> Pushing their agenda: "You wouldn't download a car"? I'm not sure I've ever seen one of these in a movie or DVD. I sure as hell saw the "kill SOPA" stuff Wikipedia, Google, etc, put up while I was trying to user their service for something else.
Re: Civil Liberties Groups Speak Out Against CISPA in Lead Up to Hearings
#83One of the biggest (and most frustrating) problems with the legislative process is that the people who really want this to go through KNOW that we - "the masses" - eventually start to suffer from "protest exhaustion". They can propose a bill - we can rally our troops and get on TV and black out Wikipedia and do 100 interviews and maybe - just maybe - we can kill it. The first time. And maybe the second time. And mayb…
You are especially likely to become numb to calls to arms when they are in fact cries of "wolf". SOPA was a genuinely invasive bill and a clear power grab by the content industry. It created a new special second-class "tainted" designation for content sites that refused to play ball with rightsholders and gave rightsholders new means to prosecute their rights outside of civil courts. It was understandable and --- eve…
I have yet to hear a good argument for why we need CISPA to override all federal and state privacy laws, including laws restricting what companies can turn over to the government in the absence of legal process. In programmerese, CISPA is a wildcard approach -- an "rm -rf *" -- when you haven't done an "ls" to see what's in the directory first. Perhaps one or two need to be overriden for good reason, but why not specify them instead of using a wildcard?
Here are some details: http://news.cnet.com/8301-31921_3-57422693-281/ What sparked significant privacy worries is the section of CISPA that says "notwithstanding any other provision of law," companies may share information "with any other entity, including the federal government." It doesn't, however, require them to do so. By including the word "notwithstanding," House Intelligence Committee Chairman Mike Rogers (R-Mich.) and ranking member Dutch Ruppersberger (D-Md.) intended to make CISPA trump all existing federal and state civil and criminal laws. (It's so broad that the non-partisan Congressional Research Service once warned (PDF) that using the term in legislation may "have unforeseen consequences for both existing and future laws.") "Notwithstanding" would trump wiretap laws, Web companies' privacy policies, gun laws, educational record laws, census data, medical records, and other statutes that protect information, warns the ACLU's Richardson: "For cybersecurity purposes, all of those entities can turn over that information to the federal government."
Re: Civil Liberties Groups Speak Out Against CISPA in Lead Up to Hearings
#84Earlier quoted context omitted.
If you truly don't understand why many are opposed to it, you should read the EFF FAQ page. It doesn't matter what the objectives are, or whether or not the intention is to protect rights holders. It matters what the law actually allows as written. That's what we take issue with. And yes, I have read the entire thing.
We've both read the law! We can actually have an interesting discussion! Even if we both know we're not going to convince each other. What does the law as written allow to have happen that you object to?
Re: Civil Liberties Groups Speak Out Against CISPA in Lead Up to Hearings
#85One of the biggest (and most frustrating) problems with the legislative process is that the people who really want this to go through KNOW that we - "the masses" - eventually start to suffer from "protest exhaustion". They can propose a bill - we can rally our troops and get on TV and black out Wikipedia and do 100 interviews and maybe - just maybe - we can kill it. The first time. And maybe the second time. And mayb…
I worry that most of the opposition to this bill is based on FUD that EFF is spreading. Having experience actually working in the security industry and knowing the limitations that this bill is trying to address, the ability of the government and private sector to work together to keep malicious groups out of their networks, I recognize the necessity and intentions of this bill. This isn't about spying on Americans.…
I'm not sure why you think the very smart lawyers and legislative counsel at the ACLU, the ALA, etc. are incapable of reaching their own conclusions about the relative merits of legislation.
I hope you're right that CISPA isn't about spying on Americans. The problem is that, as written, it allows precisely that, with the cooperation of the same companies that have opened their networks to the FedGov in the past. If the wildcard language trumping all state and federal privacy laws were deleted, I think a lot of the (informed) opposition would vanish.
BTW, there were "lots of lawyers involved in the process" of creating SOPA. Look how that turned out. I'd be far more comforted if there we had fewer lawyers and more technologists involved. :)
More: http://news.cnet.com/8301-31921_3-57422693-281/ and http://news.cnet.com/8301-13578_3-57574196-38/
Re: Civil Liberties Groups Speak Out Against CISPA in Lead Up to Hearings
#86Earlier quoted context omitted.
It's not necessarily the letter of the law that people are worried about, it's the overreach that would result once it's on the books.
The USG is actively prevented by current regulations from setting up a clearinghouse that would collect netflow signatures, botnet identification, and traffic captures of exploit code and then sharing that information with companies like Google and Facebook. Private companies can and do share (heavily scrubbed) electronic signature information, but must go through contortions to do so, and incur huge legal costs to d…
Re: Civil Liberties Groups Speak Out Against CISPA in Lead Up to Hearings
#87Earlier quoted context omitted.
The USG is actively prevented by current regulations from setting up a clearinghouse that would collect netflow signatures, botnet identification, and traffic captures of exploit code and then sharing that information with companies like Google and Facebook. Private companies can and do share (heavily scrubbed) electronic signature information, but must go through contortions to do so, and incur huge legal costs to d…
What "regulations" are those that weren't addressed by the president's executive order last month? Can you provide a cite to an actual federal law that says this?
Re: Civil Liberties Groups Speak Out Against CISPA in Lead Up to Hearings
#88Earlier quoted context omitted.
What "regulations" are those that weren't addressed by the president's executive order last month? Can you provide a cite to an actual federal law that says this?
Are you suggesting that the President's EO gave the federal government a blanket authority to publish threat information to the private sector?
That you failed to provide any, even though I think my request was fairly clear, provides strong evidence that you're unable to do so and your pro-CISPA argument was hand-waving, not based on facts or the law.
Re: Civil Liberties Groups Speak Out Against CISPA in Lead Up to Hearings
#89Earlier quoted context omitted.
Are you suggesting that the President's EO gave the federal government a blanket authority to publish threat information to the private sector?
No, what I'm asking you for is an actual citation to federal law or the U.S. Code of Federal Regulations that backs up your claim ("USG is actively prevented by current regulations from setting up...") That you failed to provide any, even though I think my request was fairly clear, provides strong evidence that you're unable to do so and your pro-CISPA argument was hand-waving, not based on facts or the law.
Two responses, briefly:
1. FISMA spells out in positive terms that incident data collected by agencie is to be reported out to LEOs and the national security services unless otherwise designated by the President, and
2. much of the data we're discussing is classified, so, 18 U.S.C. § 798 is a starting point.
Do you dispute that, say, botnet identification data collected by DoD is classified? Do you have a source to suggest otherwise? I did network security product work at Pentagon with Arbor Networks and they were bananas about classification, operating an entire clone of their enterprise network to account for classification.
I find it interesting that you can publish an article that suggests CISPA is a backdoor attempt at warrantless wiretapping but accuse other people of handwaving.
Re: Civil Liberties Groups Speak Out Against CISPA in Lead Up to Hearings
#90Earlier quoted context omitted.
We've both read the law! We can actually have an interesting discussion! Even if we both know we're not going to convince each other. What does the law as written allow to have happen that you object to?
Your comment wasn't directed at me, but see the fourth Q&A pair here, and my response above: http://news.cnet.com/8301-31921_3-57422693-281/
Specifically: CISPA provides a positive authority for sharing only "cyber threat information", which is defined in the bill: (i) information about a vulnerability, (ii) information about a confidentiality/integrity/availability threat, (iii) information about denial of service or destructive attacks, and (iv) efforts to hack into systems and exfiltrate data.
The bill incudes language that explicitly exempts the kind of stuff Aaron Swartz got caught up into: it exempts attacks that "solely involve violations of consumer terms of service or consumer licensing agreements and do not otherwise constitute unauthorized access.". That exclusion is repeated multiple times in the definitions section of the bill.
The bill explicitly does not cover individuals, in a fashion that the bill's authors say affirmatively prevents it from being used to allow ISPs to share individual customer records.
So: back to you. What specific state or Federal privacy measure is compromised by CISPA, and how?