Earlier quoted context omitted.
CISPA not only works for sharing of information with the government, but also with security companies. Your second sentence is a rather weak counterargument. (1) would be fine on its own, it is in the context of (2) and (3) that it is not; the incentives make (2) and (3) extra bad.
We are a SOURCE of threat information. We are not a consumer of threat information.
Rep. Mike Rogers Calls CISPA Opponents "14 Year Old Tweeters in Their Basement"
81–88 of 88 posts
Re: Rep. Mike Rogers Calls CISPA Opponents "14 Year Old Tweeters in Their Basement"
#82Earlier quoted context omitted.
We are a SOURCE of threat information. We are not a consumer of threat information.
Wouldn't CISPA also protect the companies providing information to you by giving you permission to test and/or access to their systems, and hence be beneficial to your business? Why aren't you a consumer of threat information that way?
Re: Rep. Mike Rogers Calls CISPA Opponents "14 Year Old Tweeters in Their Basement"
#83Earlier quoted context omitted.
Wouldn't CISPA also protect the companies providing information to you by giving you permission to test and/or access to their systems, and hence be beneficial to your business? Why aren't you a consumer of threat information that way?
I think you have absolutely no idea what it is we do.
FYI, you have a dead link: http://www.matasano.com/services/shipsafe/
Re: Rep. Mike Rogers Calls CISPA Opponents "14 Year Old Tweeters in Their Basement"
#84Earlier quoted context omitted.
I think you have absolutely no idea what it is we do.
Why are you so defensive and rude? I think I have an idea what you do. You check applications for security vulnerabilities. While doing this, you may access information that usually would be considered information that the company you are investigating would not be allowed to give you. But with CISPA, they would be allowed to give you. FYI, you have a dead link: http://www.matasano.com/services/shipsafe/
You have a weird and broken understanding of how engineering firms are contacted to test for vulnerabilities. CISPA has absolutely no bearing on my firm whatsoever.
Re: Rep. Mike Rogers Calls CISPA Opponents "14 Year Old Tweeters in Their Basement"
#85Earlier quoted context omitted.
Why are you so defensive and rude? I think I have an idea what you do. You check applications for security vulnerabilities. While doing this, you may access information that usually would be considered information that the company you are investigating would not be allowed to give you. But with CISPA, they would be allowed to give you. FYI, you have a dead link: http://www.matasano.com/services/shipsafe/
I like the guy who asks why I'm being rude after suggesting that I arrived at my public policy positions out of a concealed financial interest. You have a weird and broken understanding of how engineering firms are contacted to test for vulnerabilities. CISPA has absolutely no bearing on my firm whatsoever.
Surely it's not rude to ask if you have a personal interest, given that (1) CISPA has explicit provisions for security companies (2) it's not clear why this would not apply to your company and (3) you defend CISPA on almost every CISPA post on hacker news.
Re: Rep. Mike Rogers Calls CISPA Opponents "14 Year Old Tweeters in Their Basement"
#86Earlier quoted context omitted.
I like the guy who asks why I'm being rude after suggesting that I arrived at my public policy positions out of a concealed financial interest. You have a weird and broken understanding of how engineering firms are contacted to test for vulnerabilities. CISPA has absolutely no bearing on my firm whatsoever.
Can you explain how the way engineering firms are contracted means that CISPA has absolutely no bearing on your firm? As far as I can see, the bill doesn't say that if a company is contracted in a certain way, then its protections don't apply. Surely it's not rude to ask if you have a personal interest, given that (1) CISPA has explicit provisions for security companies (2) it's not clear why this would not apply to…
Re: Rep. Mike Rogers Calls CISPA Opponents "14 Year Old Tweeters in Their Basement"
#87Earlier quoted context omitted.
Can you explain how the way engineering firms are contracted means that CISPA has absolutely no bearing on your firm? As far as I can see, the bill doesn't say that if a company is contracted in a certain way, then its protections don't apply. Surely it's not rude to ask if you have a personal interest, given that (1) CISPA has explicit provisions for security companies (2) it's not clear why this would not apply to…
If from this point on you would like to tell yourself that my non-responsive comment here, and my future lack of responsiveness to any of your other comments, implied that you Perry Mason'd some kind of acknowledgement of my corrupt CISPA dealings out of me on Hacker News, you have my blessing.
As far as I can tell, these sections of the bill indicate that it does apply to your company:
‘‘(A) CYBERSECURITY PROVIDERS.— Not-
5 withstanding any other provision of law, a cy-
6 bersecurity provider, with the express consent
7 of a protected entity for which such cybersecu-
8 rity provider is providing goods or services for
9 cybersecurity purposes, may, for cybersecurity
10 purposes—
11 ‘‘(i) use cybersecurity systems to iden-
12 tify and obtain cyber threat information to
13 protect the rights and property of such
14 protected entity; and [...]
So, if the company your are investigating gives you consent, you may obtain cyber threat information. Note that this says nothing about the way the company is contracted.What is cyber threat information?
1 ‘‘(2) CYBER THREAT INFORMATION.—The term
2 ‘cyber threat information’ means information di-
3 rectly pertaining to a vulnerability of, or threat to,
4 a system or network of a government or private enti-
5 ty, including [...]
So this means that you can get all information pertaining to a vulnerability, and CISPA will protect the company you're getting that information from. This is so vague that it could be virtually any data. But it gets better: ‘‘(4) EXEMPTION FROM LIABILITY.—No civil or
12 criminal cause of action shall lie or be maintained in
13 Federal or State court against a protected entity,
14 self-protected entity, cybersecurity provider, or an
15 officer, employee, or agent of a protected entity, self-
16 protected entity, or cybersecurity provider, acting in
17 good faith—
18 ‘‘(A) for using cybersecurity systems or
19 sharing information in accordance with this sec-
20 tion; or
21 ‘‘(B) for decisions made based on cyber
22 threat information identified, obtained, or
23 shared under this section
So even if a company managed to share data that would not be allowed, as long as it's acting "in good faith" everything is A-OK. Given this I fail to see how your company is not a consumer of cyber threat information as defined in this bill.If you are so easily offended, you may wish to review your own writing style, since your comments are far from the least argumentative on HN (and I do not just mean this thread).
Thanks for your blessing, you have mine as well.
Re: Rep. Mike Rogers Calls CISPA Opponents "14 Year Old Tweeters in Their Basement"
#88Earlier quoted context omitted.
Anything can be roped into "actual attack." Remember the actual language of the bill, since you read it: "theft of intellectual property." What the hell does that mean? Of course there is no oversight aside from the people who are making requests, so the idea that a company would actually be penalized for releasing info "unreleated to cyberthreats" is laughable at best.
Like I said upthread, CISPA goes further in trying to actually define what a "cyberattack" is than any other bill I've read. How would you modify the definitions in the bill?
I do agree with you that the definitions of cybercrime and attacks in CISPA would be a start for the framework for coherent legislation. I just don't think that DHS should continue to be added onto piecemeal until they control 100% of all law enforcement activities as well, since let's face it, that's the eventual goal.