5 ms·
There have been very many versions of laws similar to CISA that have been proposed, modified, and changed/passed/failed/delayed. When I try to understand exactl
by mixedmath 11y ago
There have been very many versions of laws similar to CISA that have been proposed, modified, and changed/passed/failed/delayed. When I try to understand exactly what this CISA version includes, most rhetoric I read is alarmist and not conducive to actually knowing what can and cannot be done under CISA.
Is there a digestible explanation of what this CISA entails?
- zanny 11y agohttps://en.wikipedia.org/wiki/Cybersecurity_Information_Sharing_Act https://en.wikipedia.org/wiki/Cybersecurity_Information_Shar... The core problem is it lets major industry players like MS / Google / Apple give the fed access to all the personal info they record without investigators needing a warrant and with no liability on the companies part (ie, you cannot sue them for state disclosure of your personal info that then resulted in harm against you). It basically means do not be surprised when you are charged with crimes for "private" communications over facetime, hangouts, skype, or with email over hotmail / yahoo / gmail. If you want slightly more editorialized takes on the terms, while the EFF and ACLU are obviously opinionated in this, I've never heard of them lying: https://www.eff.org/deeplinks/2014/06/zombie-bill-comes-back-look-senates-cybersecurity-information-sharing-act-2014 https://www.eff.org/deeplinks/2014/06/zombie-bill-comes-back... https://www.aclu.org/blog/beware-dangers-congress-latest-cybersecurity-bill?redirect=blog/national-security-technology-and-liberty/beware-dangers-congress-latest-cybersecurity-bill https://www.aclu.org/blog/beware-dangers-congress-latest-cyb...
- pinkrooftop 11y agoSearch without a warrant though sounds unconstitutional. Legislative arbitrage. Passed low key in Congress, Removed at high cost in the courts
- egwynn 11y agoI believe CISA is more about what the feds MUST do and what private companies MAY do. It’s incentivising the private companies to rat you out, not requiring that they do so.
- knughit 11y agoAnd Room 419A shows us how that plays out in practice. Private companies get paid to break the law wih immunity.
- rhino369 11y agoFacebook or Google searching their own data isn't a search under the 4th amendment. All that data analysis they run on you is their data not yours. Them searching your private messages/emails are (probably) a search but since they aren't government the 4th amendment doesn't apply. If government specifically coordinates that brings it under the 4th amendment. But--here is the problem. Google (and I assume facebook) are already reading your email. They run algorithms and text searches on it. If I were DOJ I'd argue 1) that none of those messages are private since the companies are allowed to read the data whenever they want. 2) if not, then the indexing and analysis is definitely not private. People should step back and realize this CISA only occurs when you already let companies violate your privacy.
- walterbell 11y ago> charged with crimes for "private" communication TPP/TISA will create new "crimes" to be discovered. Would CISA cause data breaches to supplement legal fishing expeditions? That could incentivize rather than deter the market for mercenary data breaches.
- Amezarak 11y ago> The core problem is it lets major industry players like MS / Google / Apple give the fed access to all the personal info they record without investigators needing a warrant and with no liability on the companies part (ie, you cannot sue them for state disclosure of your personal info that then resulted in harm against you). As far as I know, they can already do that. And a lot of tech companies did. What CISA does is explicitly formalize a voluntary arrangement for sharing 'cybersecurity indicators' and 'defensive measures' among government agencies and private companies. There are, actually, explicit provisions for removing personal information and making sure that any indicators that do contain personal information anyway are deleted in a timely manner. It's hard to gauge the accuracy of those links, because both of those are from 2014 and the bill has changed since then. I think the strongest argument against the law is the potential for abuse, not anything actually in the law. Actually if you removed provisions 3, 4, and 5 on page 1766 I think it'd be a good idea, other than the fact it creates a system that potentially government agencies and corporations could abuse (in violation of the law, but who is going to call them on it?)
- tptacek 11y agoThere is no way to have actually read the short text of CISA and come away with the conclusion that it "lets major industry players like MS / Google / Apple give the fed access to all the personal info they record without investigators needing a warrant and with no liability on the companies part". No part of this summary squares with the text of the bill: not the kinds of information shared, nor the methods by which it's shared. Just for absolute ground-floor starters, CISA private->government sharing is PUSH, not PULL, and there is no mechanism whatsoever for the government to request (even by asking nicely) any indicator data. Wherever you got this summary from, they just fucking made it up.
- propogandist 11y agothey just need something extremely vague in place as law to support operations that would otherwise be illegal. Obama is actively abusing the Authorization of Military Force Against Terrorists who conducted Sept 11 attacks [0] to go out and police the world. The media is told to frequently link ISIS back to AlQueda in all the fear mongering, so no one questions the president's authority to put "boots on the ground." Sounds like you're way to trusting of the government and forgot about NSA Director lying to the American people about warrantless spying of citizens and govt. spying overall. [1] [0] https://en.wikipedia.org/wiki/Authorization_for_Use_of_Military_Force_Against_Terrorists https://en.wikipedia.org/wiki/Authorization_for_Use_of_Milit... [1]https://theintercept.com/2015/12/17/a-secret-catalogue-of-government-gear-for-spying-on-your-cellphone/ https://theintercept.com/2015/12/17/a-secret-catalogue-of-go...
- tptacek 11y agoI don't know what message board you spend most of your time on where you have to expend energy to sneak the string "Obama" past the filters they've set up to keep posts like this off, but HN isn't that board.
- propogandist 11y agocompletely ignore O and 0 being right next to each other and attack the typo. well played.
- lhl 11y agoI don't know if there's a how you'd tell what's a good summary vs alarmist rhetoric so the best way to tell what's in the bill is probably to read it. The full text is only about 30 pages, and can be found here: https://www.govtrack.us/congress/bills/114/hr2029/text/eah#link=N_I&nearest=HBE35C3E75E4C47EDA12269B2095A05E9 https://www.govtrack.us/congress/bills/114/hr2029/text/eah#l... This is embedded in the "H.R. 2029: Military Construction and Veterans Affairs and Related Agencies Appropriations Act, 2016", which is the vehicle for the Omnibus bill as passed by the Senate yesterday: https://www.govtrack.us/congress/bills/114/hr2029 https://www.govtrack.us/congress/bills/114/hr2029
- tptacek 11y agoSure. CISA defines "cybersecurity threats" and "threat indicators", which are now legalese versions of the stuff Intrusion Detection Systems track: exploit code, vulnerability information, and wire traces of attacks. Everyone already collects this stuff; that's most of what network security teams are paid to do. The government has several huge network security teams (they operate the largest IT system in the world), and, of course, the whole Fortune 500 does as well. All these organizations are collecting information about attacks and siloing it. CISA requires the government to establish a process to share indicators with private companies. So when analysts or IPS systems or anomaly detection schemes running inside FedGov networks generate a signature for an attack, there will now be federal rules requiring them to submit that data to a process that will disseminate it to the private sector. CISA allows the private sector to do the same thing in reverse, sharing their data with the government, which will in turn share a facsimile of that data back out to the rest of the private sector. The bill requires companies to have a process to ensure they aren't knowingly sharing any personally identifying information, and they are only allowed to share information that pertains to the types of attacks defined as "cybersecurity threats". Those attacks specifically exclude terms of service violations. Unlike CISPA, which was a more benign bill, CISA explicitly allows local, state, and federal law enforcement to use threat indicators to prosecute crimes. CISA has a very short list of crimes whose prosecution can be assisted with shared indicators --- identity theft, espionage, and trade secret theft. PCNA, the (now dead) House version of CISA, had a broader list. Unlike the law of the land before CISPA/CISA/PCNA was proposed, there is now a path for private companies to share data with the USG regardless of the other regulatory regimes they're under. This is good if you think sharing attack information is very important and bad if you think companies that work with regulated information (driving records, credit scores, medical data, student records, &c) should operate under different, stricter rules than other companies. Much of the impetus for these bills was to overcome objections from legal at BigCos that would never allow any information sharing out of fear that such sharing could get them sued. They are now immunized from those suits, so long as they're in good faith sharing only information about actual cybersecurity threats. That's pretty much it, at a high level. It's a very short bill, just 30 pages, and most of the interesting stuff is in the definitions at the top of the bill. It's worth skimming. https://www.govtrack.us/congress/bills/114/s754/text https://www.govtrack.us/congress/bills/114/s754/text