Live data from Hacker News

Civil Liberties Groups Speak Out Against CISPA in Lead Up to Hearings

eff.org

91–100 of 113 posts

Re: Civil Liberties Groups Speak Out Against CISPA in Lead Up to Hearings

#91
post #83
post #53

Earlier quoted context omitted.

You are especially likely to become numb to calls to arms when they are in fact cries of "wolf". SOPA was a genuinely invasive bill and a clear power grab by the content industry. It created a new special second-class "tainted" designation for content sites that refused to play ball with rightsholders and gave rightsholders new means to prosecute their rights outside of civil courts. It was understandable and --- eve…

It is true that some of the criticism of CISPA is off the mark. So was some of the criticism of SOPA. It does not necessarily follow that _all_ of the criticism of CISPA is uninformed, and in fact much of it is perfectly accurate. Rebutting uninformed criticism may be an entertaining hobby, but it leaves the informed criticism unrebutted. I have yet to hear a good argument for why we need CISPA to override all federa…

I answered your last paragraph upthread.

Since otherwise reputable sources are running articles suggesting that CISPA is "the worst bill since SOPA" and "a power grab by the content industry" and "a backdoor warrantless wiretap" and "a mechanism by which the feds will read our email", I respectfully disagree with you about the utility of refuting uninformed criticism of the bill. Most of the criticism of the bill is uninformed.

Re: Civil Liberties Groups Speak Out Against CISPA in Lead Up to Hearings

#92
post #72

Earlier quoted context omitted.

The sentence you quote is referring to the confusion about the bill, not the bill itself. Again, the OP didn't claim that CISPA was about IP.

I disagree, but I don't think this subthread is important enough to litigate. If he wants to chime in and say "I absolutely am not saying CISPA is part of a scheme that will increase the powers of rightsholders", I'll apologize for mischaracterizing him.

I absolutely am not saying CISPA is part of a scheme that will increase the powers of "rightsholders." I don't see that in there. I was referring to the "spying" claim of the parent post of my first response.

My concern is with limiting of my right to civil suit against a corporation, and my fear that the bartering of these rights for information bypasses legal constraints on information collecting by government and law enforcement.

Re: Civil Liberties Groups Speak Out Against CISPA in Lead Up to Hearings

#93
post #81

Earlier quoted context omitted.

I've come to the conclusion that mainstreaming a technology results in the technology conforming to the mainstream, rather than the mainstream adopting the interests of the early adopters of the technology.

Which is precisely how it should be. Technology is for the use and convenience of the masses--it's not a vector for political minorities to spread their ideological viewpoints. My mom doesn't need to listen to Vint Cerf's politics to use the TCP/IP to trade pictures of my kid with my wife's mom.

Yes, clearly the capabilities of technology shouldn't inform people's philosophies. They should continue to receive their views via mass media social pressure instead.

Re: Civil Liberties Groups Speak Out Against CISPA in Lead Up to Hearings

#94
post #59
post #34

Earlier quoted context omitted.

No they don't. I think it is extremely confusing to talk about theft of data at the same time as talking about someone hacking a nuclear power plant to go into meltdown or something. When people say things like "cyber pearl harbor" at that time they could be talking about a DDOS that makes it impossible to do online banking or they could be talking about an attack on SCADA systems at a power plant that takes out powe…

I have no idea what this comment is even trying to articulate. You suggest two kinds of "cyber attacks", one which cause power plants to malfunction and the other that attacks online banking. I am not sure what you think this distinction demonstrates about online security. On the one hand, the attacks on power plants that you allude to are possible . Utilities have been networked and electronically controlled since t…

I think the government has a legitimate interest in protecting against computer attacks on public infrastructure that could result in death, and I see a place in there for government involvement. To a lesser degree there is a legitimate interest for government regarding IP theft. But I think how the government is involved and what powers they have, are different for these two scenarios. I understand that they overlap. CISPA is going to give government a much expanded jurisdiction and I don't think the restrictions are fine-grained enough.

Re: Civil Liberties Groups Speak Out Against CISPA in Lead Up to Hearings

#95
post #81

Earlier quoted context omitted.

Which is precisely how it should be. Technology is for the use and convenience of the masses--it's not a vector for political minorities to spread their ideological viewpoints. My mom doesn't need to listen to Vint Cerf's politics to use the TCP/IP to trade pictures of my kid with my wife's mom.

Yes, clearly the capabilities of technology shouldn't inform people's philosophies. They should continue to receive their views via mass media social pressure instead.

The capability of technology should inform people's philosophies, not the personal beliefs of the creators.

Re: Civil Liberties Groups Speak Out Against CISPA in Lead Up to Hearings

#96
post #90
post #84

Earlier quoted context omitted.

Your comment wasn't directed at me, but see the fourth Q&A pair here, and my response above: http://news.cnet.com/8301-31921_3-57422693-281/

The bill supersedes privacy and communication laws, but is (a) opt-in and (b) severely limited in scope. Specifically: CISPA provides a positive authority for sharing only "cyber threat information", which is defined in the bill: (i) information about a vulnerability, (ii) information about a confidentiality/integrity/availability threat, (iii) information about denial of service or destructive attacks, and (iv) effo…

Thanks for your polite response. Two thoughts: First, I'm not interested in what politicians say in defense of their bill -- I'm interested in what the actual text of the bill says.

Second, asking what specific privacy law is overruled is a bit odd because -all- of them are. ECPA, SCA, Wiretap Act, FCRA, DPPA, FERPA, PPA, RFPA, TCPA, VPPA are among them, and that's not even counting state privacy laws. Remember, CISPA is a legal wildcard. Asking your question is like asking "what specific file does rm -rf * delete?"

Re: Civil Liberties Groups Speak Out Against CISPA in Lead Up to Hearings

#97
post #89
post #88

Earlier quoted context omitted.

No, what I'm asking you for is an actual citation to federal law or the U.S. Code of Federal Regulations that backs up your claim ("USG is actively prevented by current regulations from setting up...") That you failed to provide any, even though I think my request was fairly clear, provides strong evidence that you're unable to do so and your pro-CISPA argument was hand-waving, not based on facts or the law.

Or that you asked at 1:00AM. Two responses, briefly: 1. FISMA spells out in positive terms that incident data collected by agencie is to be reported out to LEOs and the national security services unless otherwise designated by the President, and 2. much of the data we're discussing is classified, so, 18 U.S.C. § 798 is a starting point. Do you dispute that, say, botnet identification data collected by DoD is classifi…

Now we're getting somewhere!

You're right, of course, that federal agencies have the power to classify data. But I think saying that overclassification happens all the time is not a controversial statement; President Obama in 2010 signed the Reducing Over-Classification Act and the DOD IG announced last November that it reviewing DOD classification procedures. One of the 9/11 Commission members concluded: "Much more information needs to be declassified. A great deal of information should never be classified at all."

So if the only reason we need CISPA is that DOD is inadvisedly classifying botnet data as SECRET, then a sensible fix is for DOD to declassify it. Or, that failing, Congress could amend 18 USC 798 to allow that to happen. Laws, like computer security, should follow the principle of least privilege, and enacting a broad wildcard law that overrides all federal and state laws to fix a narrow botnet-classification problem violates that principle.

Also: the primary criticism of CISPA is that it overrides all other state and federal laws in allowing the transfer of customer data from private companies to .gov, .mil and other organizations. You're defending .gov->.com data transfer, which is hand-wavingly orthogonal to an explanation of why a wildcard override for .com->.gov data transfer is necessary.

Re: Civil Liberties Groups Speak Out Against CISPA in Lead Up to Hearings

#98
post #91
post #83

Earlier quoted context omitted.

It is true that some of the criticism of CISPA is off the mark. So was some of the criticism of SOPA. It does not necessarily follow that _all_ of the criticism of CISPA is uninformed, and in fact much of it is perfectly accurate. Rebutting uninformed criticism may be an entertaining hobby, but it leaves the informed criticism unrebutted. I have yet to hear a good argument for why we need CISPA to override all federa…

I answered your last paragraph upthread. Since otherwise reputable sources are running articles suggesting that CISPA is "the worst bill since SOPA" and "a power grab by the content industry" and "a backdoor warrantless wiretap" and "a mechanism by which the feds will read our email", I respectfully disagree with you about the utility of refuting uninformed criticism of the bill. Most of the criticism of the bill is…

I've already stipulated that some articles are ill-informed or even wrong. Sadly not everyone who writes about legislation reads it first. But some of us do. :)

Re: Civil Liberties Groups Speak Out Against CISPA in Lead Up to Hearings

#99
post #62

Earlier quoted context omitted.

>In an ideal world you would have a virtuous cycle, where one company stops a threat, sends the critical threat info the government, which shares it with every other company--all basically in real time. But why does the government need the information at all? Why not have a private consortium of companies who share threat information under NDA (or, for that matter, just allow it to be published), and craft appropriat…

CISPA allows exactly that to happen! Any "Cyber security provider" can collect and share information (on a voluntary, opt-in basis ) under the act. Moreover, the largest repository of threat information --- netflow traces, botnet identification, &c --- is housed inside the USG, which is prevented from sharing that information. That's the other problem CISPA solves. Did you read the bill? I'm not asking in an accusato…

>Did you read the bill?

Reading bills is usually a headache because they keep changing. Cue Pelosi's idiotic comment about having to pass the law so we can know what's in it. This one seems to be no exception: The original bill is talking about intellectual property, people complained about it, they removed that in later versions. EFF is complaining about how it doesn't put limits on what the federal government can do with the information, so they added some limits, but they're overly broad. (What does "national security" even mean? Because it's pretty plausible it's going to be read as "whatever the National Security Agency or Department of Homeland Security does with it.") I mean it's good that they're taking criticism into account and making modifications, but it seems like a really weird bill, and I think it's a good thing that it's getting a lot of scrutiny.

If you want me to go through it and complain about it, I can do that…

>CISPA allows exactly that to happen!

Not exactly. First of all, publication seems very much not to be the idea. Half the the bill is talking about security clearances and the like, and how if you get "cyber threat information" from the feds (presumably even if they got it from other private sector entities) then it could still be classified and you can't publish it. And I don't see anything in the bill about the information becoming automatically declassified once a patch is available, so that's not going to be good for full disclosure. Plus, if I get this super secret threat information, now how do I e.g. submit a patch to the Linux kernel or OpenSSH to address it without impermissibly letting the cat out of the bag? Have they thought this one through?

But my original point was not that private entities could share information too, the point was, why should we want the federal government to have it? There is a real concern that they would use vulnerability information to advance their stupid "cyberwar" nonsense and then accidentally loose the network equivalent of the black plague, or use vulnerabilities to spy on people and expand their warrantless surveillance of the world population. I can see why they might be able to use the information to patch their own systems, but I would be a lot happier to see a specific restriction that disallows anyone from using any information received under these provisions for offensive or surveillance purposes.

>Moreover, the largest repository of threat information --- netflow traces, botnet identification, &c --- is housed inside the USG, which is prevented from sharing that information. That's the other problem CISPA solves

I don't think that's the part people have a problem with. It's not the information coming out of the government (assuming it really is technical information and not anything that identifies individuals or impinges on privacy), rather it's the information going back into it to feed proto-Skynet.

But let's talk about some of the other crazy things.

1) It seems like a major part of the legislation is the grant of immunity for entities that share information. Which is a really very strange thing. Why do these entities need to be exempted from all state and federal laws? Can we not identify the specific ones that are problematic and then fix them? Certainly at least identifying them would be useful. I'm not really comfortable with the idea of exempting companies from prosecution for, say, polluting the water supply or murdering bystanders when they're reporting or responding to cybersecurity vulnerabilities. And if we can't even identify the laws we're concerned about, that seems like a problem more in need of our attention than this.

2) Why are individuals explicitly excluded from qualifying as "protected entities" or "self-protected entities" that would otherwise qualify them for the immunity provision? Are Microsoft and its employees for some reason more deserving of immunity than e.g. Moxie Marlinspike, or any random schmuck who finds and wants to report a security vulnerability?

3) There is a whole list of things under "protection of sensitive personal documents" like library circulation records and medical records. First of all, how is any of that sort of thing the sort of thing that should qualify for this in the first place? But never mind that. If those things would otherwise qualify, shouldn't we then be concerned about a lot of other stuff that isn't on the list, like browsing history, search history, financial records, purchasing history, location data, etc.?

4) The section on liability for wrongful disclosure by the federal government is pretty extreme. I'm not happy with it as a taxpayer. So if the federal government screws up (it's been known to happen) and releases a vulnerability e.g. in some financial software that causes a trillion dollars in damages to other countries, the U.S. taxpayer is on the hook for that to any person adversely affected, not because they had any responsibility for the vulnerability but only because the government disclosed it? No thank you. How about instead we put some some personal liability on the government employee(s) who actually made the wrongful disclosure.

5) The bill does a lot of talking about the U.S. federal government and not a lot of talking about state governments or foreign governments. It looks like they may qualify as entities however, and if they don't then that's weird (because what if I want to share threat information with my city or state or Canada or something?). But then we're exempting state governments and foreign governments from all state and federal laws for "decisions made based on cyber threat information identified, obtained, or shared under this section"? What???

This is where I reiterate my concern that we're exempting them from laws against things like murder, kidnapping, wiretapping, espionage, terrorism, etc. Granted the exemption requires acting in "good faith" -- but that's putting a lot of work behind two fuzzy words.

The whole immunity thing seems like a huge kludge that doesn't address the underlying problem, which is really the Aaron Swartz problem. Some laws are unnecessarily complicated, overly broad or poorly drafted such that liability under them is arbitrary and unreasonable, but instead of carefully fixing the bad laws individually, we just throw them all away in this one specific case and let anyone else subjected to their continuing insanity fend for themselves.

Re: Civil Liberties Groups Speak Out Against CISPA in Lead Up to Hearings

#100
post #95

Earlier quoted context omitted.

Yes, clearly the capabilities of technology shouldn't inform people's philosophies. They should continue to receive their views via mass media social pressure instead.

The capability of technology should inform people's philosophies, not the personal beliefs of the creators.

However, the personal beliefs of the creators inform the design of the technology. And the resulting technology's capabilities can render this moment's squabbling moot.
Post reply on HN