Despite privacy concerns, CISA bill poised for passage
america.aljazeera.com
america.aljazeera.com
https://www.reddit.com/r/IAmA/comments/3qban2/oh_look_its_th...
Looks like it just started a few minutes ago, so no idea if it'll be useful, or not.
I've been uniformly discouraged by FFTF's advocacy, which I find goes way past "misleading" into "straight up dishonest", such as their recent piece that strongly suggested Facebook supported CISA (a fact not in evidence, for whatever that's worth) because doing so would immunize them from privacy suits for user data so long as they dumped all that user data to the USG. No reading of CISA gets you to that.
Example from today's AMA is FFTF's claim that CISA "exempts itself from FOIA", making it impossible to challenge in court: they're referring to Sec 4 (d) (4) (b), which exempts from FOIA individual shared indicators, which of course must be the case, because indicators are things like compromised account names and passwords. That's all the law exempts from disclosure.
Also 5 (d) (3) (a) and (b) which exempts "Cyber threat indicators and defensive measures provided to the Federal Government under this Act".
I don't know if CISA also prevents Privacy Act requests, or if it only applies to FOIA.
Theoretically, companies using CISA would anonymize personally identifiable information before sharing to the government. An IP address, for example, is probably not PII (as millions of people have pointed out in the context of digital piracy lawsuits). I doubt one could file a Privacy Act request just based on an IP address.
how could it be otherwise?
Allow FOIA, and use the existing exemptions for classified material if the information is actually classified. This would mean that breaches of privacy could be found when non-classified information is present.
There seems to be concentration on "indicators" being username/passwords, etc. However, Sec 2 (6) (G) is "any other attribute of a cybersecurity threat, if disclosure of such attribute is not otherwise prohibited by law;". That's basically anything since cybersecurity threat is defined as "means _an action_ ... on or through an information system that _may_ result in an unauthorized effort ...". That seems to be a rather large hole.
So there'd need to be some other regime in place that ensures that no harm is done by publishing information that companies are voluntarily sharing with the USG.
What would that regime look like?
I'm also not really convinced that there's a problem with the catch-all at the end of Sec.2(6) --- that's enabling companies to share things they were already allowed to share, and just bringing it under the same set of controls as the new sensitive stuff they can share. How is that a loophole the USG can exploit? What does that loophole look like in practice, in actual use?
Advocacy organizations are not journalists. They don't need to cite their sourcing before making claims they believe are true. The purpose of calling out Facebook is an attempt force them to align their public and private positions if they differ.
As usual, Marcy does excellent analysis about what information NSA will be able to collect, analyze and disseminate under CISA.[1]
[1] https://www.emptywheel.net/2015/10/26/two-intended-consequen...
1. That Chrysler can exploit CISA to avoid liability for vulnerabilities in their cars simply by sharing the flaws with the USG as an "indicator".
2. That the USG can use CISA to collude with private companies to avoid warrant requirements and spy on their customers.
Both of these points are, I think, false. I've linked upthread to the text of the bill and provided a summary. In particular, I don't think the "Chrysler reading" of the bill finds any support at all in the text; Chrysler is immunized from suits stemming from their own sharing, and even in the sharing, they are explicitly on the hook for negligence and misconduct.
If it's helpful, here's the entire limitation of liability in CISA. Notice: companies are exempt from liability for monitoring, sharing, and receipt of indicators. They aren't exempt from liability for having vulnerabilities in the first place!
6.Protection from liability
(a) Monitoring of information systems
No cause of action shall lie or be maintained in any court against
any private entity, and such action shall be promptly dismissed,
for the monitoring of information systems and information under
section 4(a) that is conducted in accordance with this Act.
(b) Sharing or receipt of cyber threat
indicators
No cause of action shall lie or be maintained in any court against
any entity, and such action shall be promptly dismissed, for the
sharing or receipt of cyber threat indicators or defensive
measures under section 4(c) if—
(1) such sharing or receipt is conducted in accordance with this
Act; and
(2) in a case in which a cyber threat indicator or defensive
measure is shared with the Federal Government, the cyber threat
indicator or defensive measure is shared in a manner that is
consistent with section 5(c)(1)(B) and the sharing or receipt, as
the case may be, occurs after the earlier of—
(A) the date on which the interim policies and procedures are
submitted to Congress under section 5(a)(1); or
(B) the date that is 60 days after the date of the enactment of
this Act.
(c) Construction
Nothing in this section shall be
construed—
(1)to require dismissal of a cause of action against an entity
that has engaged in gross negligence or willful misconduct in the
course of conducting activities authorized by this Act; or
(2)to undermine or limit the availability of otherwise applicable
common law or statutory defenses.It seems relatively simple to read this passage in the following way:
Let's say a major car company decided to leave open a port with a remote code execution vulnerability on their cars.
Let's say this car company discovered this port was being exploited and informs the NSA of affected vehicles IMEI numbers, IP addresses etc.
Now let's say FTC/NTSB wanted to put together a case for punishing the car manufacturer for their poor security operations.
It seems perfectly reasonable for a lawyer to read the passage from CISA and claim the court couldn't use any disclosure to the government under like the number of affected vehicles(easily calculated from the threat information previously shared) in any determination of liability.
If there's an authority under which Chrysler can be prosecuted for having vulnerabilities (spoiler: I don't believe there is), CISA doesn't change any of that. Certainly, there's no clear linkage between CISA sharing and a private actor's ability to sue Chrysler for torts emerging from vulnerabilities.
I don't even think there's a stretch reading of the statute that gets you where this blog post lands.
Marcy compares the CISA liability protections to the very similar Section 314(b) of the Patriot Act financial information sharing liability safe harbor.
It seems at least plausible that they will operate in a similar fashion if CISA becomes law.
https://www.emptywheel.net/2015/10/14/time-to-get-very-conce...
The lengths taken to interpret "torture" for instance. It used to be that we have a fairly logical, common sense interpretation of things but I think those days are gone. I mean, unlimited data should really mean unlimited data not subject to some arbritary cap or throttling .
I expect I will disagree with you about the desirability of CISA, just as we disagreed years ago about CISPA, but enjoy your posts on the topic nevertheless. They make thoughtful and reasonable points. Even if you end up on the wrong side. :)
Tell me where you find these journalists today.
So in other words, as long as they are "advocacy organizations" and say that they believe in some view, they get a free pass to lie, spread bullshit and FUD? I thought we should have a higher standard.
Personally, I am for severely punishing liars as a top priority, no matter what side they're on. Then we may get a constructive discussion.
I'm really not sure what's so complicated about this.
I have a hard time thinking of legal support EFF has provided that I don't support. If EFF was just legal support, I'd be a donor.
I think their technical work is mostly good; it would be entirely good but for the egregiously terrible Secure Messaging Scorecard --- but hey, that scorecard won me a $1000 bet against Matt Green, so some good came out of it.
Virtually all of EFF's policy advocacy, I find untrustworthy. I don't even believe they take it seriously. I think they play to the crowds, in the hope that the retweets and upvotes will generate more donations.
Is it really that hard for you to see that as a plausible narrative? I'm not asking you to agree with it.
This is an interesting conspiracy theory.
> Is it really that hard for you to see that as a plausible narrative?
My theory is that they really believe in what they're doing. They are based in SF, so they are surrounded by well-funded startups offering high salaries. Employees of EFF could be making small fortunes, and instead they choose to fight to secure civil rights. Why? Because some people value freedom over currency. This narrative seems more plausible.
I'm sure they're all good people who believe in what they're doing. It does not follow that they believe in every individual position they advocate for; they're a nonprofit, so fundraising is a huge part of their job.
Nope. The bill clearly defines "cyber threat indicators" to include the entire content of whatever these companies disclose to the government. The things that make up "cyber threat indicators" go on for an entire page, and it's an "or" list rather than an "and" list. For Facebook, it would probably be something like a particular Facebook post that tripped their "threat" trigger, plus all the info that Facebook has about that user account (maybe every post that account ever made), including IP addresses that posted to that account and everything else.
And yes, every single thing "shared" with the government (I'm reminded of "the sharing economy" with this usage) is entirely exempt from FOIA disclosure, as the CISA bill clearly says. And of course no cause of action shall lie in any court, so there's no help there either. So no, there will never be any way to review the scope or magnitude of this "sharing", apart from whatever information (truthful or not) the government deigns to share.
Your description of CISA is the one that is straight up dishonest.
I even took the time, elsewhere on the thread, to summarize all the different classes of data that CISA deems "indicators":
American: Home of the safe and the surveilled.
It is like they keep submitting bills until it gets passed. This not only is a waste of time, it seems to be how the lobbyists get their bills passed. Eventually one will get passed and then our privacy will no longer exist. If you want our data, get a judge to order a search warrant. Otherwise it is Unconstitutional.
This is my position and nothing will move me from it because it is the principled position. Moreover, the advocates of mass surveillance fail to realize that even if their motives are as pure as the driven snow nevertheless a mass surveillance system will attract sociopaths and psychopaths who survive by preying on other human beings instead of creating value and trade. This is exactly why we have a Constitution to limit the powers of government.
'Indicators' usually consist of information about external actors and organizations that are relevant to intrusion detection, for example, the most common types of indicators are domains used for C&C and hashes of malicious files. It is difficult to construe a privacy violation from these types of indicators. There are concerns about certain providers who may have indicators relevant to their users - for example, some providers might share the names of otherwise legitimate user accounts which have been compromised as these are often used to send spam that ought to be blocked. However, in general, cyber intel indicators do not involve sensitive information about users.
Right now a great deal of organizations are not participating in public or private threat information sharing because of concerns over liability and compliance, and this significantly impedes defense by letting threat actors get away with infrastructure and tool reuse that ideally should reveal them. These acts originated as an attempt to correct that. It looks alarmingly like many advocacy organizations want to keep it this way for good.
I don't want to be painted as anti-privacy and I would say that I'm not, but the principal goal of this legislation is not to send your data to the NSA, it's to help me do my job. I hope that the internet community will have the foresight to try to resolve the specific problems with current legislation, and not to entirely prevent information sharing.
These have seen widespread adoption by medium and large sized companies, and are doing good work. Or at least the one I participate in is; I can't speak for the other ISACs.
They have policies that facilitate information sharing without privacy or liability issues.
There are definitely still a very large portion of organizations that are not a member of any ISAC or similar information sharing group, though. I don't know how much CISA may help with that.
Much of the benefit of CISA is specifically in the area of information sharing with the gov't, which has various initiatives like NCCIC that are falling flat in a lot of ways. Of course the ISACs would like to be involved in this. CISA is also seen as a way to get a lot more organizations to contribute to ISACs, as well.
This is what folks with this argument are missing - it doesn't matter one bit what the goal of legislation is, especially when it involves immunity for very vague things. Just because you will use it for that, does not prevent someone else from abusing it now or in the future. The point of legislation should be to protect the people.
Just like the author of the Patriot Act never intended for it to be abused the way it was. And these things are extraordinarily difficult to curtail after the fact.
"Sensenbrenner supported the Amash Amendment, a plan to defund the NSA's telephone surveillance program. "Never, he said, did he intend to allow the wholesale vacuuming up of domestic phone records, nor did his legislation envision that data dragnets would go beyond specific targets of terrorism investigations." The Amendment fell seven votes short of the number it needed to pass."
Also, I don't really buy that businesses are limited by their inability to share threat information, because they have been doing this for years.
Is the concern that Google is going to hand over your browser history under the guise of CISA?
This is pretty typical for bills in US Federal Law: Congress enacts a relatively broad statute that establishes principles relied upon in a later "rulemaking" process; the statute will delegate to specific agencies the privilege of making those rules.
Is this necessary to slow down the rate and severity of breaches? If so, what should this law look like?
But I still don't think it's a big deal either way. Like, don't donate money to prevent it from passing if this is the only donation you can make this year.
https://www.govtrack.us/congress/bills/114/s754/text
There are no amendments to CISA that I can find (CISPA collected quite a few amendments, some of which were very relevant to HN, before the bill eventually died).
I read CISA so you don't have to! (You still should). Here's a summary:
There are three particularly important defined concepts:
<<Sec. 2 (5) (A) "Threats">>, which means "unauthorized activity" that might plausibly compromise confidentiality, integrity, or availability, but that isn't either protected speech or a mere ToS violation.
<<Sec 2 (6) "Indicators">>, the most important concept in the bill, which is, roughly: logs of recon activity, exploit techniques, vulnerability data, account hijack techniques (I think this bill actually tries to capture the notion of an XSS), bot C&Cs, damage reports on attacks, and anything else related to security and not already prohibited by law.
<<Sec 2 (7) "Defensive measures">>, roughly, things that stop or monitor attacks.
"Defensive measures" is a confusing concept in the bill. For awhile, it was thought that CISA would authorize something akin to hack-back privilege for private entities; it does not. Meanwhile, defensive measures are probably already lawfully shareable. Anyways, the bill allows you to share both indicators and defenses.
The bill allows the USG to share indicators and defensive measures with private entities, and vice versa.
So then:
Section 3 of the bill authorizes the USG to share stuff with private entities. This isn't the part of the bill that concerns people (we all probably want more sharing from USG to private entities; for instance, that's what we're saying every time we demand NSA fork over its zero-days).
Section 4 authorizes private entities to share with the USG. Here's what it allows:
(a) You can monitor your own systems, or those of people who give you written authorization, for any security purpose, notwithstanding any previous limitation on monitoring. Even if ECPA or student records law says you shouldn't monitor, if you're doing it to deal with security threats, you're now allowed to.
(b) You can run your own defensive measures, or defensive measures on people who give you written authorization. Ok then.
(c) You can share indicators and defenses with the USG, and receive them from the USG so long as you comply with their sharing restrictions.
(d) You have to keep the data secure, you can't share it willy-nilly, and before you share anything, you have to (1) review it for PII and (2) anonymize any PII you find.
Sec 4 (d) (4) has problematic language that allows, say, Facebook to provide written authorization to the USG to prosecute based on shared indicators; in theory, they can do this even if the prosecution they're going to launch isn't related to a computer crime, but just happens to be illuminated by the indicator Facebook shared. (But remember: Facebook can't share under CISA unless they have a bona fide cybersecurity purpose for doing so).
Section 5 has a bunch of rulemaking authority in it, but buried in it is Sec 5 (d) (5) (a), which gives all the purposes FedGov is allowed to use indicators for:
* any security purpose * attributing threats * determining whether threats are foreign * preventing immediate disaster/harm (iv) * stopping child sex trafficking (v) * stopping major felonies, espionage, trade secret theft (vi)
(iv), (v), and (vi) are major problems; these aren't cybersecurity purposes at all, but rather a sort of "these crimes are so bad that we're allowed to repurpose indicators to deal with them", which, maybe fair enough (except for trade secret theft), but still, not OK that new investigative capabilities are buried in the middle of a cybersecurity bill.
And that's it.
Companies aren't allowed to just make up "security purpose", though; under CISA, they have to be monitoring for threats as construed in CISA, which means, for instance, they can't find exemption for liability for monitoring for mere ToS violations.
Of course, our terms of use on most sites already say they can collect + monetize such things, so maybe this is moot.
> I do see lots of places in the bill that allow sharing to other private entities or to the USG for cybersecurity purposes.
It's a short bill. Read it again! These terms are defined, reasonably well.
Politics in the US cannot change until people simply say no. That means at least voting for someone not from the big two or voting against your own party to show them the lesson they need.
After all, how can your vote be wasted doing so when so many are convinced their vote already doesn't matter?
₋ The net is a-central and not dependent on a single facist org to run it
₋ Pirate utopias will crop up to subvert any such control mechanisms.
⸗ 4 letter acronyms by virtue of being over⁻arching make the net stronger by way of streisand effect
The OP is hinting through his username that somehow the Mt. Gox bitcoin exchange was involved.
Feinstein won 49.5 to 12.7; a landslide victory.
Gerrymandering had nothing to do with CISA.
But seriously, it's kind of fun to imagine what life would be like if U.S. states were shaped like House districts. Maryland is probably the closest, geometrically.
Interestingly, some of the motivations for the proposals did involve something like gerrymandering, in terms of arguments about how many Mormons who had emigrated to the west would end up being included in California's territory.
Another interesting thing about the California-Nevada border that ended up getting adopted is where the northwest line turns north (where the bend is): it's inside of Lake Tahoe. That makes it a lot easier to remember!
Did you know that Reno has been gerrymandered so far it's now west of Los Angeles? That has to be some kind of conspiracy. Otherwise it would just be impossible.
It was also shaped so that it encompassed the driest point in the U.S.--Death Valley--and one of the wettest: 100 feet underwater below the Golden Gate Bridge.
Also, if the state of California were its own country, it would be referred to as the nation of California. True story.
I really really dislike her, but it totally makes sense that she is basically invulnerable within her senate seat.
All I see with her about this is the hypocrisy of it all. She is totally fine with the NSA intervening in our lives, but threw a huge fit when the CIA was found to be spying on members of Congress. Yes, spying on the people is OK, but spying on Congress by the CIA is a "violation of separation of powers" and shouldn't be tolerated?
People elect Feinstein because they think she is doing a good job. They might even agree with you that she's wrong on your pet issue but that issue just isn't as important to them as it is to you.