12 ms·
Civil Liberties Groups Speak Out Against CISPA in Lead Up to Hearings
- deleted 14y ago[deleted]
- halviti 14y agoObligatory Maddox from SOPA 1 http://thebestpageintheuniverse.net/c.cgi?u=pass_sopa http://thebestpageintheuniverse.net/c.cgi?u=pass_sopa
- chc 14y agoThis "CISPA is the next SOPA" meme is about as fact-based as "Electronic Arts is literally Hitler." I'm not telling you it's good or bad, but it's not remotely SOPA. It isn't even addressing the same general topic as SOPA.
- diminoten 14y agoSOPA isn't really related to CISPA all that much, I don't know why people think they're similar.
- tptacek 14y agoBecause the EFF actively campaigned (dishonestly) against CISPA as a sort of second coming of the objectives of SOPA.
- mtgx 14y agoThe White House petition against it passed 100,000 signatures, too: https://www.techdirt.com/articles/20130311/16221022286/white-house-petition-against-cispa-gets-over-100000-signature-threshold.shtml https://www.techdirt.com/articles/20130311/16221022286/white...
- nlh 14y agoOne of the biggest (and most frustrating) problems with the legislative process is that the people who really want this to go through KNOW that we - "the masses" - eventually start to suffer from "protest exhaustion". They can propose a bill - we can rally our troops and get on TV and black out Wikipedia and do 100 interviews and maybe - just maybe - we can kill it. The first time. And maybe the second time. And maybe even the third time. But after a while we're going to start to get numb to the calls-to-arms. And eventually our sometimes-well-intentioned-but-pulled-in-30-directions representatives are going to stop getting those concerned phone calls and emails from constituents, and they're going to fall prey to the typical "think of the children" argument that often gets put forward on any security bill, and something ugly is going to get passed. I hate resigning myself to this, but it's the disappointing reality. What to do?
- ori_b 14y agoGo on the offensive. Instead of just fighting to kill legislation like CISPA, lobby for legislation that will guarantee the freedom of the internet. That will unequivocally protect people's liberties on (and off) the internet.
- sp332 14y agoGetting such a law passed does nothing to prevent a future law from saying the opposite.
- drcube 14y agoUnless you amend the Constitution. Good luck! EDIT: Another option is for the courts to decide that freedom was guaranteed in the Constitution all along. But courts are unpredictable so again, good luck!
- stonemetal 14y agoAmendment 21(repeal of prohibition), Nothing is forever.
- 14y ago
- TallGuyShort 14y agoAs a wise man pointed out on HN the last time around, we haven't won when this law fails to pass. We've only won a law explicitly stating the opposite passes.
- tptacek 14y agoSo what you're saying is, the best possible thing to happen would be a law specifically preventing any American company from relaying threat information --- packet captures of exploits, netflow traffic profiles of botnets, &c --- to the US government, and, further, preventing any agency in the USG from providing traffic capture information, packet filter information, or botnet identification information to private companies.
- TallGuyShort 14y agoNo. In my mind, the best possible thing to happen would be a law specifically preventing any American government agency from requiring any company to hand over such information without due process. Sadly, you would think this was already clear enough from the constitution, but there are already enough loop holes that it happens anyway. Another good thing would be for American internet companies to voluntarily adopt and adhere to privacy policies along the same lines.
- tptacek 14y agoCISPA does not require any company to hand over any information to the USG without due process!
- TallGuyShort 14y agoI think you're taking the "opposite" in my initial post more literally than I intended. My point was that if the law seeks to violate certain rights to privacy we believe we have, the law being struck down is not the final solution. The final solution if the rights to privacy we believe we have successfully being codified into law to prevent that bad parts from being practical options in the future. I did not mean to imply that each term in CISPA be logically negated and passed into law.
- tocomment 14y agoShould we use a the internet bat signal[1] on this issue? What do you guys think? Is it already under discussion? [1] http://internetdefenseleague.org/ http://internetdefenseleague.org/
- Cieplak 14y agoSupporters include companies like AT&T, Facebook, IBM, Intel, Oracle Corporation, Symantec, Verizon, and Microsoft. http://en.wikipedia.org/wiki/Cyber_Intelligence_Sharing_and_Protection_Act#Supporters http://en.wikipedia.org/wiki/Cyber_Intelligence_Sharing_and_... I'm envisioning a web dashboard that lets federal agents do fuzzy queries on individuals, to see all the sites visited, emails sent, web searches, browsing habits, etc, from all the IP addresses used by the given individual in the past several years. The system would aggregate information gathered from ISPs and web companies. The government can already get anything they want from an ISP or web company, but they have to do it on a case by case basis and it is probably annoying to correlate information across sources. In the future, I imagine that a federal agent can go to his big brother dashboard, type in a name, and have immediate access to all sorts of information gathered from credit card companies, search providers, ISPs, telecoms.
- gojomo 14y agoDon't forget an "add person to cyber threat watchlist" button! It should automatically advise internet services that a person/account may be trouble, thus granting those private companies the blanket "exemption from liability... for decisions made based on cyber threat information identified, obtained, or shared under this [law]." (That's one of the most concerning vague and elastic provisions in the current proposed bill text.) There should also be a 'redress number' subsystem, for when people on the watchlist start noticing their accounts being restricted or disabled, and want to make the case they're not the bad guy the agent who pressed the button thought they were.
- pdonis 14y agoAre you actually advocating for these, or just trying to point out how extreme the government's powers could be if CISPA were passed?
- SoftwareMaven 14y agoI would bet, at least for the NSA and probably the FBI, this already exists. It just isn't quite as real-time as they would like it to be. Instead of the instant fuzzy-search, it's a couple of quick letters, but the oversight seems to be about the same.
- ericjeepn 14y agoJust tell the gun lobby that if any of the Gun Shops keep an online database of their customers that's subject to the law. No need to worry about a national gun registry, the GOV gets it for free. Get the NRA involved and ALL OF CONGRESS will run screaming about how this goes against the 2nd Amendment.
- crisnoble 14y agoThis actually would work. I think the general public either (a) doesn't know about this law at all or (b) doesn't think it will interfere with their daily activities. Getting other big organizations who value privacy would help solve both problems. I think that anyone who begins to understand the law will be opposed to it.
- diminoten 14y agoThe Gun Shop would have to volunteer that information to the government according to CISPA, so that wouldn't work.
- wmf 14y agoPolitical maneuvering has nothing to do with what CISPA actually says (as many others in this thread have pointed out).
- diminoten 14y agoThe bill is too short to lie about what's in it. Anyone with about 5 minutes and a 4th grade reading level can at least muddle through.
- fision-e 14y agoFor anyone wants to read it you can find the full text here: http://www.govtrack.us/congress/bills/112/hr3523/text http://www.govtrack.us/congress/bills/112/hr3523/text
- snowwrestler 14y agoI supposed I would ask what privacy-protecting language would make the approach envisioned in CISPA (cyber threat data sharing) acceptable to privacy-oriented organizations like the ones listed. If the answer is "none," I would question their good faith in the process--or at least the public face they put on it.
- diminoten 14y agoI am never more reminded of how smart people can succumb to groupthink than I am when I read HN posts about CISPA. There are a lot of misconceptions about the law, including what kind of data gets shared (only relevant threat data, this isn't your bank account info, and the RIAA can't sue you if shared data reveals you to be torrenting movies - can elaborate more on this if there's interest), who does the sharing (orgs share to the government voluntarily), who has access to the sharing (government and people the government decide to share the data with), etc. I saw an infographic a little while back that I thought made a pretty good representation of what the bill actually proposes, I wonder if anyone has a link available to it.
- Wingman4l7 14y agoIt's not necessarily the letter of the law that people are worried about, it's the overreach that would result once it's on the books.
- diminoten 14y agoHaving read the criticism the EFF's been pointing at CISPA, I fail to see how they're interpreting the bill to mean that such overreaching is even possible. I want to see what sort of changes the EFF would make to the current bill which would satisfy the privacy concerns they're claiming exist. I think everyone agrees that companies should be able to describe to the cops what the guy who robbed them looked like, and those companies should be able to tell their customers they've been robbed without getting sued by their shareholders because the ensuing PR fallout tanks the stocks.
- tptacek 14y agoThe USG is actively prevented by current regulations from setting up a clearinghouse that would collect netflow signatures, botnet identification, and traffic captures of exploit code and then sharing that information with companies like Google and Facebook. Private companies can and do share (heavily scrubbed) electronic signature information, but must go through contortions to do so, and incur huge legal costs to do it. As a result, only the largest companies participate in these efforts. Because the USG is more or less enjoined from participating in clearinghouses with private companies, information sharing networks are handshake affairs that are often unknown to anyone outside tier-3 network engineering. Other private IT security product companies run de facto clearinghouses, but only for their customers. As a result, when your startup gets DDoS'd and you call your ISP for help, they generally can't do shit to help you. It may annoy you to know that if your connectivity provider is large, there is a group in there that could offramp your traffic to internal "scrubbing centers" to peel off DDOS traffic. But because high-end DDoS protection at ISPs is done sub rosa, startups have a very hard time finding these people. There is an actual problem with online security attacks right now, and hysteria over any USG intervention with the Internet at all is helping perpetuate it. And all it appears to take to fuel that hysteria is statements like "think of the overreach that will happen once a law hits the books".