5 ms·
Please read the actual text of CISPA before making any judgements. It's reasonably short and not all that hard to understand. It's also nowhere near as evil as
by Xuzz 15y ago
Please read the actual text of CISPA before making any judgements. It's reasonably short and not all that hard to understand. It's also nowhere near as evil as it is being made out to be.
For those interested, here's a link: http://www.opencongress.org/bill/112-h3523/text http://www.opencongress.org/bill/112-h3523/text
As far as I can tell, it appears to be essentially a data-sharing bill for network intrusions, to allow companies and government to get around existing barriers to investigate network intrusions. I'm certainly open to the possibility that it is somehow worse, but I am really having a hard time seeing how.
- tptacek 15y agoSOPA was a rageview bonanza for sites like Wired and Mashable. This bill could declare the sky to be periodically be blue; so long as it contained the word "cyber" or mentioned computers, a credulous mob will vote it up. In this particular case, venues like the EFF blog are counting on the idea that readers don't know what the ECPA is, and that they'll believe that it was somehow unlawful for companies like AT&T and Google to monitor their networks and, yes, your data for evidence of intrusions, or to share that data once it's uncovered. It is not unlawful. This bill does virtually nothing. It's probably just a ploy for attention.
- rdl 15y agoECPA primarily covers networks and attacks on networks, and incidentally protects certain forms of communication, including stored information. In general, ECPA seems to restrict government activity. I don't think it goes far enough (it protects certain types of communication more than others, and the way they were picked seems to be a historical accident.) CISPA, as I read it, both protects networks AND "information rights holders". Given the history with DMCA, COPA, (+ SOPA, PIPA), etc., it doesn't seem at all unreasonable to think the government (and those information rights holders) will use CISPA to use the tools provided for national security to address copyright violation. This is the same government using PATRIOT to go after local drug dealers. I could support CISPA if it focused solely on information sharing from government to private enterprise (and protection from liability) for network or infrastructure attacks. Most of the legitimate network-defense activities which would be permitted under CISPA are already allowed under existing laws. There might be a few corner cases around classified intelligence and uncleared entities, but this legislation is overly broad.
- tptacek 15y agoWhat action currently unlawful under the ECPA would be made lawful in a plain reading of CISPA?
- rdl 14y agoI'm not sure. (You probably know/care more about this than I do; I assume everything can be done under NSL already, or entirely internal to large companies or their existing business partners, or by criminal organizations, so the legal protections are largely irrelevant.) I assume by ECPA you mean "ECPA as modified by the Patriot Act", which is a substantial change in protections. Under ECPA as originally enacted, a great many things currently done would be illegal. However, there's at least one major area which is currently illegal but would become lawful under CISPA: Providing classified intelligence to private companies in violation of the NSA of 1947 (which I don't think is permitted by ECPA; ECPA just allows info to go from private company to government in ways which would otherwise be wiretap act violations without specific court orders). Couple this with the government enjoying overclassifying everything, and it's a problem. I don't really have a problem with this, except that the procedures and safeguards need to be built well to protect that information. I think they can do this. The other addition is that intellectual property is covered. If "theft of [...] private information, intellectual property ..." provides "exemption from all liability [...] acting in good faith", this would seem to allow private entities to do a lot of things. I don't think ECPA/Patriot gives those powers to private entities, so a provider could have one (badly written) legal contract with customers (violation of which might lead to civil liability), then invoke CISPA to violate it. Most contracts are written to permit information sharing for security issues, but adding copyright protection would greatly expand their scope. I think it would allow a copyright holder to request (with no legal basis) information from an ISP, including ECPA protected information like VOIP/email in transit/etc., and or the ISP to turn it over with no legal protections to the requestor. So, overall: The Lungren (http://www.govtrack.us/congress/bills/112/hr3674 http://www.govtrack.us/congress/bills/112/hr3674) HR 3674 does not have this feature/defect. I'd support Lungren as written.
- tptacek 14y ago
- Natsu 15y ago> In this particular case, venues like the EFF blog are counting on the idea that readers don't know what the ECPA is I assume you're talking about this post by the EFF? https://action.eff.org/o/9042/p/dia/action/public/?action_KEY=8444 https://action.eff.org/o/9042/p/dia/action/public/?action_KE... I read through the text of the bill, which someone else helpfully posted: http://www.opencongress.org/bill/112-h3523/text http://www.opencongress.org/bill/112-h3523/text All those information sharing clauses begin with "Notwithstanding any other provision of law." That leads me to wonder why you believe the provisions of the Electronic Communications Privacy Act are not overridden by that.
- tptacek 14y agoI don't think the ECPA is/needs to be overridden by this law. That's my point. There's nothing this law allows companies under network (er "cyber") attack to do that they couldn't already do. I have firsthand experience (and not in my current company) with what Internet service providers are already doing to share the kinds of information contemplated by this bill. CISPA is just a showpiece. But of course: people love- luv- LUV! this Your Rights Online stuff, so they'll mod up any half-assed attempt to twist any law into "the next SOPA". Like I said: SOPA was a bonanza for the TechCrunches and Panderdailies of the world. I just wish more people would notice that they're being duped into crying wolf, because someday soon one of these bills is going to have actual teeth.
- Natsu 14y ago> I don't think the ECPA is/needs to be overridden by this law. Well, the EFF seems to think it creates a giant exception to pretty much everything so long as you're dealing with network security and I've read those "notwithstanding" clauses for myself, so we'll have to disagree on that. It has a huge catch-all net and we both know that there's always some joker trying to exploit random machines on the internet and you'll catch plenty of automated attempts if you watch your IDS & firewall logs. Insofar as the law is unnecessary, that's all the more reason not to pass it in the first place. You may very well be right about it being a favor for whomever. But it is the burden of the proponents to make the case that it is necessary and I've not seen anyone do that. I haven't seen anyone running through the streets shouting that the end is near, here, but I didn't bother to read any Wired or TC pieces on it, either. There's no reason we can't calmly explain to our reps that we oppose this unnecessary bill. I have no interest in defending whatever hyperbolic articles you've read. I haven't even bothered to read much of anything except the bill itself and the EFF piece. Even so, I find it to be a poorly considered law and I see good reason to calmly explain to my reps that I oppose it, even if nothing comes of it in the end.
- JoshTriplett 15y agoTwo items worth highlighting for consideration: - Blanket exemption from 5 USC 552, AKA the Freedom of Information Act. While that seems potentially reasonable at first glance (since this information may represent active intelligence), this would also provide for more instances of the same kind of consequence-free "sharing" that telcos do for Internet traffic. - Blanket exemption from liability for sharing information. See above.
- Natsu 15y agoIt's a giant blank check. Broadly speaking, it lets companies do anything, shields them from liability and keeps the whole thing under wraps with the FOIA exemption so long as they're dealing with a cybersecurity threat. What's wrong with the existing laws? They didn't tell us. They just asked for a blank check. I've seen comments saying this does nothing. If that's true, it ought to make you even more nervous. If it doesn't, please send me a blank check. I promise that I won't do anything I wasn't already going to do. You trust me... right?
- tptacek 14y agoExactly what "liability" were you thinking of here? There are at least two (very different) kinds of liability people are expressing concern about with CISPA. Which is it for you?
- Natsu 14y ago> Exactly what "liability" were you thinking of here? (3) EXEMPTION FROM LIABILITY- No civil or criminal cause of action shall lie or be maintained in Federal or State court against a protected entity, self-protected entity, cybersecurity provider, or an officer, employee, or agent of a protected entity, self-protected entity, or cybersecurity provider, acting in good faith-- (A) for using cybersecurity systems or sharing information in accordance with this section; or ‘(B) for not acting on information obtained or shared in accordance with this section. =========== Part (B) is pretty troubling. Suppose they find out, due to information shared in accordance with that section, that they're compromised. In spite of this, they fail to protect your money or data. Are they covered by that?
- tptacek 14y agoThey're not liable simply by dint of receiving the information, meaning that there's no legal disincentive for them to accept information about compromises, such that an elaborate, expensive, and time consuming legal facade would be required for them to receive it. It's not a blanket shield of liability against breaches. It confers immunity from liability only for transmitting and receiving information. In the spectacularly unlikely event that Google received information that they were compromised through this channel and then did not act on it (!), they would still be liable for information that comes to them about the compromise through other channels.
- deleted 15y ago[deleted]