Edit: It looks like the NSA/Law Enforcement wouldn't even need due process since the companies are just giving away the private data. https://www.faxbigbrother.com/#whatiscisa
Edit: It looks like the NSA/Law Enforcement wouldn't even need due process since the companies are just giving away the private data. https://www.faxbigbrother.com/#whatiscisa
If government forced me to hand over data on users, I wouldn't want to be held liable for that. So, I'm not sure why people are complaining to companies about it? Do they expect companies to break laws?
People forget that government is always the highest power of the land. You are forced to do what government decides it wants to do.
Take your issues up with government, not me.
Some companies already have legal contracts with you to protect your private data. Are you implying they can break those contracts?
I need actual scenarios written out, preferably based on an actual example EULA being violated. Not "maybe something scary might possibly happen in the future."
I see an exemption for anti-trust, and I see an immunity to other laws requiring disclosure (say, FOIA), but I do not see any immunity to violate previously established EULAs.
Do you?
https://www.congress.gov/bill/114th-congress/senate-bill/754...
(i) No Liability For Non-Participation.—Nothing in this Act shall be construed to subject any entity to liability for choosing not to engage in the voluntary activities authorized in this Act.
Reading through the bill, it seems like this is a well-intentioned attempt to promote data sharing between corporations and security agencies in the event of a widespread cyberattack. There are definite use cases for a law like this. For example, if both Lockheed Martin and Boeing are hit by a cyberattack, under this bill they are allowed to coordinate and mitigate the attack using data from both parties. But the enormous flaw in this bill is that there are only vague restrictions on the type of data allowed to be shared. These restrictions are so vague that an unscrupulous company could send all their customers' private data to the government under the context of this law.
The US needs reform on its cybersecurity defense and this bill is a step towards change. But with the potential for abuse this bill is a huge step backwards. Hopefully there are other ways to improve US cybersecurity defense without compromising civil liberties.
You can find a copy of the bill, including a short summary of each section, at the link below:
https://www.congress.gov/bill/114th-congress/senate-bill/754
Doesn't this just mean companies don't have to hand-off private data to government?
Isn't that the exact opposite thing people are complaining about?
Did you even read the original link, or anything anyone posted in the thread so far?
Microsoft already "needs" to win multiple contracts with the government, and Apple is supposed to "win" Apple Pay integration with federal services.
If all the data requests would be legal then they shouldn't need immunity, should they? This is 90% of the way the encryption backdoor the government has been requesting. That's why it's "backing down" on that.
Much like what Microsoft has already been doing years before this [1], the NSA will get Apple, Microsoft, Adobe, Oracle and others' zero-days ~3-12 months before they are patched, as part of the "cyber-threat sharing" program. That's as good as having dozens of backdoors in tech companies' software that billions of people are using.
Michael Hayden, who formerly directed the National Security Agency and the CIA, described the attention paid to important company partners: “If I were the director and had a relationship with a company who was doing things that were not just directed by law but were also valuable to the defense of the Republic, I would go out of my way to thank them and give them a sense as to why this is necessary and useful.”
This is how they are thanking them, by giving them immunity.
[1] http://www.bloomberg.com/news/articles/2013-06-14/u-s-agenci...
Government couldn't have gotten it if you didn't collect it. Why should you be held responsible for storing data in an insecure fashion (which given the long arm of the government, translates to storing the data at all). This is especially true of data the average user isn't considering as being captured/stored, such as Microsoft's grabbing everything you do and storing it.
It is? Please explain why other people should be prepared to go to gaol or businesses should pay heavy fines to protect my personal information from legal(1) government requests? Particularly when I apparently don't care enough about the privacy of said information to the point that I allow it to be stored in the US, where apparently these sorts of shenanigans go on?
Edit: (because I'm being downvoted to death, which I don't think the comment deserves)
These companies agree that our data should be private and protected. They are not prepared to take heavy penalties to protect those rights. Anger should not be directed at these companies, but rather at the completely fucked up US government approach to privacy. At the end of the day, whether these companies fight and get fined out of existence, or comply, the government will still end up getting your data. That's the problem, and it's the US government that has betrayed people, not the companies listed by this stupid site.
1. I'm personally dubious as to the legality of these orders, but for now the US judiciary don't seem to be opposing the executive on this one, at least for the time being, so hey, I guess it's legal...