8 ms·
> So getting an internet connection from a company that has opted in means I have no protection against searches and seizures (almost arbitrarily based on an in
by andylei 13y ago
> So getting an internet connection from a company that has opted in means I have no protection against searches and seizures (almost arbitrarily based on an individual's web habbits)
no, that's not anywhere in the bill. did you read the bill?
- lawnchair_larry 13y agoI'd argue that it is. He's on "Hacker News". It would be perfectly reasonable for an automated system that is designed to look for security-related activity to report that fact. The bill, as it is written, says any action his ISP now takes, or anyone that they share his information with (which would then be allowed to do, with anyone in the poorly defined "cybersecurity club"), is fully acceptable as long as it was "in good faith." And who could argue that? Hacker News is benign, but it's an honest mistake.
- tptacek 13y agoHow does the bill's definition of an attack include sites with "hacker" in the name?
- lawnchair_larry 13y agoCISPA contains no definition of "attack", nor does it limit itself to "actual attacks", or anything resembling that language. Furthermore, if it did, it doesn't matter. Bad actors are allowed to be wrong, with impunity, if they promise that it was "in good faith".
- tptacek 13y ago4) CYBER THREAT INFORMATION.— ‘‘(A) IN GENERAL.—The term ‘cyber threat information’ means information directly pertaining to— ‘‘(i) a vulnerability of a system or net- work of a government or private entity; ‘‘(ii) a threat to the integrity, con- fidentiality, or availability of a system or network of a government or private entity or any information stored on, processed on, or transiting such a system or network; ‘‘(iii) efforts to deny access to or de- grade, disrupt, or destroy a system or net- work of a government or private entity; or ‘‘(iv) efforts to gain unauthorized ac- cess to a system or network of a govern- ment or private entity, including to gain such unauthorized access for the purpose of exfiltrating information stored on, proc- essed on, or transiting a system or network of a government or private entity You're right that I phrased this more casually than the bill does, which harms my point but I believe still leaves it standing.
- lawnchair_larry 13y ago> You're right that I phrased this more casually Did you think that I was suggesting you were merely phrasing it casually, or is that a subtle argument technique? ;)
- tptacek 13y agoNo, I was owning up to the fact that by saying CISPA only pertained to "attacks", I was making it easier to accept my premise. You were right to point out that the language in the bill is more subtle than that.