5 ms·
I live in the Netherlands, can anyone tell me what this law is about and why it is damaging to the internet?
by st0p 13y ago
I live in the Netherlands, can anyone tell me what this law is about and why it is damaging to the internet?
- wavefunction 13y agoDo you use any sites in America? Do you access any sites hosted outside of America but accessed via any network infrastructure owned by an American company? If so, any of this information can be easily shared with the US Government free of charge to you!
- tptacek 13y agoCan you tell a short story about how some specific piece of information this person shares with a US site winds up shared with the USG?
- samstave 13y agoI am no expert on the matter, but I believe what this does is pave the pre-approval for something that has long been in place; echelon. Basically the government had previously stated that capturing of any electronic information and storing it is not the same as wire-tapping/reviewing the information. They can capture and record whatever they want and should they at a later date want to look at anything you did, they can get the warrant and look at this historical info. With CISPA -- the legal process for doing any of this is now far easier for them. (please correct me if this is not true)
- tptacek 13y agoCISPA doesn't revoke ECPA or SCA. It overrides it, purportedly for the sole purpose of enabling the sharing of operational network security information, in roughly two scenarios: discovery/dissemination of new vulnerabilities, and ongoing incidents.
- lawnchair_larry 13y agoHehe, "purportedly"
- tptacek 13y agoI literally write this way because of you. You should feel free to fill in my blanks.
- samstave 13y agoCan you do an explain like I'm five on this thing? (Plus echelon)?
- tptacek 13y agoYeah but it may take me a bit because I'm commenting in between Ansible runs. You may find a good way to get me to write a canonical summary is to make a bunch of egregiously false statements about the bill. :)
- jules 13y agoWhy do you continue to say that "operational network information", when (A) that clearly isn't the case and (B) the whole bill doesn't even mention the word "operational" once? (nor does it mention "network information" for that matter) Why not simply say what the bill says: "The term ‘cyber threat information’ means information directly pertaining to a vulnerability of, or threat to, a system or network of a government or private entity." This way people can decide for themselves what could be the possible interpretations of that which a lawyer could successfully defend to be "in good faith" -- which is all that the bill requires. I would be surprised if anybody would come to the conclusion that the only defensible interpretation of that is "operational network information".
- tptacek 13y agoWhat version of this bill are you quoting from where that is the definition given of "cyber threat information"? URL? I'm looking at the current version on the House Subcommittee site, and that is not the definition, or even the language for that one clause of the definition.
- mscarborough 13y agoCan you tell a short story about how the legally-binding privacy protections in this bill work, that would prevent sharing with the government without a warrant? The onus is not on the opposition to this bill to explain how privacy will go wrong, it is on the supporters since it is a new law with vague language and far-reaching potential consequences. Also, having privacy amendments shot down or not brought to vote doesn't make CISPA seem very democratic.
- tptacek 13y agoThe whole point of the bill is to facilitate the sharing of a limited set of operational network security data without warrants or court orders, so it is very difficult to respond to your question.
- lawnchair_larry 13y agoNothing about the bill suggests it will be limited to operational network security data, so you should stop spreading this untruth. In fact, it's pretty obvious that it won't be just netflows. (For those following and don't know what a netflow is, it doesn't contain payload data. It's more or less headers and statistics. Nothing about CISPA attempts to limit information to netflows only.)
- diminoten 13y agoSo the whole "directly related to a cyber threat" thing doesn't limit the data that can be shared in any way? I wish this bill were more focused on network security events and didn't have any language in it to deal with stuff like cyberbullying, but I'm glad it's moving forward. Worst case scenario we find it in the Supreme Court where it gets narrowed to be more like what it should have been written as. Happens all the time, we're not going to wake up to a dystopian future with silent arrests and "we have always been at (cyber) war with Eastasia!" the day this passes.
- tptacek 13y agoI don't think it's very honest of you to suggest that I'm claiming CISPA only covers Netflow information. I use Netflow as an example of the kind of benign information that is difficult to share today, and would be easier to share under CISPA. I've explicitly described scenarios that could include message payloads on these threads, and I know you've read those messages because you've replied to them.