Facebook secretly lobbying for CISA?
boingboing.net
boingboing.net
Whether or not Facebook is secretly lobbying for CISA, the article describes the way the incentives look.
The first thing this bill allows for is to have Facebook rat out whatever communication they deem "malicious" to the federal government and be shielded from the fallout.
Meanwhile, the clear implication of the article we're commenting on, and the idea FFTF is trying to spread, is that CISA allows Facebook to violate user privacy, and to build its business doing so, by leveraging CISA. That's a nonsensical argument, and a terribly dishonest one.
CISA is a bad law, much more so than CISPA, which preceded it. The reason we have CISA instead of CISPA? FFTF.
I'm not opposed in principle to new investigative tools, but I don't think debate about them should be avoided by sticking them into cybersecurity bills.
Still: virtually everything organizations like FFTF say about CISA seems to be false, and all you have to do to see how is to read the actual text of the bill.
They are basing that on this article [2].
[1] https://www.reddit.com/r/technology/comments/3q1kgl/facebook...
[2] https://www.emptywheel.net/2015/10/14/time-to-get-very-conce...
Aka, a Letter Of Marque[1]. Facebook wants to be a modern privateer. Selling plundered data and reputation is less violent than the cargo that was traditionally the target of privateering, but it's still government-backed piracy.
[1] https://en.wikipedia.org/wiki/Letter_of_marque
edit: Wow. +5 to -1. That's more than the usual number of people using down-votes as a substitute for rebuttal.
CISA is a vehicle for the distribution of Indications of Compromise and other standard infosec threat intelligence between Government entities as well as the public and large corporations. The liability protections are completely reasonable if private companies were going to participate at all. The privacy protections built in are also much more thorough than I was expecting in a bill of this nature.
Really the only thing that really worries me about is that the things that the Government is allowed to do with shared information includes "identifying the use of an information system by a foreign adversary or terrorist". Which seems a little too broad for my tastes.
In fact, I was on the CISA hate train but after reading it I feel that it's an entirely inoffensive law and my outrage has fizzled into indifference. I'm not going to lose sleep if this passed nor if it isn't but likening it to a Letter of Marque is not warranted.
Here's the text for anyone interested: https://www.congress.gov/bill/114th-congress/senate-bill/754
https://www.reddit.com/r/technology/comments/3q1kgl/facebook...
"This is Jeff from Fight for the Future. I wish we could disclose our sources for this, but unfortunately we agreed not to. Multiple sources on the hill have reported that Facebook is THE tech company lobbying in favor of CISA, several offices have heard from Facebook that they support CISA.
"Facebook themselves has declined to take up our offers to take a public position thus far. The nature of this lobbying game is that people leak information because they can't come out and reveal who they talk to and give information to. I know that sucks, but we decided it was better to put out the information we can than to just keep it to ourselves. And, what they are doing now matters to what ends up happening. So, that's why we're asking Facebook to tell us what their position is and to come clean.
"Facebook was probably the loudest supporter of early versions of CISA, until it became unpopular. Then they went silent. Unlike all the other big tech companies that have come out against CISA, Facebook is still silent. Their top Senate lobbyist comes straight from the office of CISA sponsor Sen. Richard Burr, and "cybersecurity issues" is listed on her lobbying disclosures. The publicly available information about Facebook's position on CISA just supports what we know -- Facebook is one of the major forces pushing for this bill to pass."
Luckily, humans will always be the weakest links in these systems and you can get as many auth tokens you want for checked in public repos.
Myriah seems to be quite connected and has worked for various departments including for Obama which makes her a good lobbyists. https://www.opensecrets.org/revolving/rev_summary.php?id=773...
And here's an article I wrote for CNET in 2013 about Facebook's earlier position(s): http://www.cnet.com/news/facebook-unfriends-cispa-cybersecur...
But before condemning Facebook, let's at least confirm that the allegations are true. As evidence, BoingBoing gives us a Fight for the Future webpage, which says: "We've gotten information that Facebook is secretly lobbying..." (https://www.youbetrayedus.org/facebook/) There are no details in this Reddit thread: https://www.reddit.com/r/technology/comments/3q1kgl/facebook...
On one hand, Facebook is one of dozens of tech companies that are members of CCIA, which has criticized CISA in its current form. (https://www.ccianet.org/2015/10/ccia-urges-senate-to-improve...) On the other hand, CCIA's positions do not necessarily reflect the views of every member company on every issue, and Facebook has endorsed an earlier version.
Unless there's more evidence than an advocacy group's "we've gotten information" claim, let's give Facebook a chance to reply before assuming the worst.
So the Government is using sock puppets to violate its own laws. Nice. Criminals of all continents, unite! The U.S. is your land of opportunity.
Really, why be a terrorist when you can fuck everyone over legally and even get rich and powerful with it. As an added bonus, you get to call yourself a patriot while you're at it.
The statement in the OP's title breaks the HN guidelines by being misleading (presenting an allegation as fact) and baity (by using sensational language like "betrayed"). Putting "Petition:" in front does mitigate that, but not enough in my view.
If anyone can suggest a better way of solving the problem in this case, we'd be happy to change the title again.
I perceive the question mark at the end of the headline to mean that A) the author believes this but doesn't want to be "on the record" for something that lacks evidence, or B) the author doesn't believe it and just wants clicks.
An imperfect solution used by newspapers is to put the source of the allegation at the beginning: "Montoya: You killed my father" or "Sources: US plans to invade Canada".
Either way, some damage will be done by false headlines. The question is just whether you can signal to HN users that the article is speculative.
I'd say your anecdotal evidence is very, very, very wrong. Facebook's behavior, in the long run, is extremely effective. Large companies willing to lobby for favorable laws have been a dominant force in all societies since there was a such thing as a "large company". I don't know what could happen to change that.
1. http://www.statista.com/statistics/264810/number-of-monthly-...
It's likely that nearly 100% of all internet users are tracked by Facebook (with varying degrees of anonymity) as they browse the web.
Everyone says "because mobile" but I'm not convinced. Mobile also means that people are searching less for everything else that might be competing with facebook. Then there is the weird jump in October 2012 that the authors of the "end of facebook" paper corrected for.
It's hard to tell what's really going on.
Maybe the last 500 million users are the ones who get free facebook (but not web) and think facebook isn't even part of the internet.
Not true. Each service accessible on the web or on an app is separate. People don't always switch wholesale. I still know people who use Pinterest exclusively the web, but have switched from Facebook web to Facebook the app.
It do feel that it's possible that Facebook usage is declining as its core audience gets older and young people use other things, but WhatsApp and Instagram are certainly compensating for that, so the company's total users across properties are still growing aggressively.