Obama Signs CISA Bill into Law
npr.org
npr.org
PCNA, the House's (worse) version of CISA, passed with similar margins in April.
Obama has publicly supported the bill all year.
As much as HN and Twitter wants to believe CISA was enacted in some shady backroom deal, the process that actually occurred, including publicly available amendments and months-long review, is pretty close to "Schoolhouse Rocks".
The debate on CISA was over. Thankfully. The only debate left was how close CISA would come to PCNA, with its broader law enforcement ties and vaguer language (EFF claims PCNA would have in some cases authorized large private companies to "hack back" computers they believed had been trying to hack them). Instead, Senate's CISA is the law of land almost verbatim to what they passed --- in a drawn out, public process --- in October.
Later:
Someone downthread asked for a summary of the bill. I did my best to strip the legalese out of it:
Baldwin (D-WI)
Booker (D-NJ)
Brown (D-OH)
Coons (D-DE)
Franken (D-MN)
Leahy (D-VT)
Markey (D-MA)
Menendez (D-NJ)
Merkley (D-OR)
Paul (R-KY)
Sanders (I-VT)
Udall (D-NM)
Warren (D-MA)
Wyden (D-OR)
https://www.techdirt.com/articles/20151022/10133932597/cisa-...If anything he is being undermined by the DNC, not the media. The DNC should be ashamed of themselves for thier blatant support of one candidate over the other(s) .
The thing with Sanders, I think, is that he has been around for so long and he has been so consistent, that you can know what he think about most issues:
https://votesmart.org/candidate/key-votes/27110/bernie-sande...
i don't recall obama being an actual socialist or talking about breaking up the banks. i do recall obama being a dem and giving the banks bailout money though.
> he is being undermined by the DNC
agreed.
His ideological framework hasn't changed in the entire time I've been following him (I'm from Vermont) and that includes going from mayor of Burlington up through US Senator.
He's also not saying things to get elected. He'd have a much better chance if he dropped some of his more socialist rhetoric, but he genuinely believes it.
Yeah, this whole thing about electing the right president who will somehow magically change all the wrongs of the world overnight is a fairy tale. If someone like Ron Paul or Bernie Sanders got into office, a little would be different, especially with regards to foreign policy, but without a pliable or cooperative congress, literally nothing would get done. It would be a waste of 4 years. People overestimate just how much power the president has. Even with executive orders, there's only so much a president can do within the law. If you want universal health care, or MJ legalized, or CISA repealed, a president can't do that by himself, that requires congress.
Presidential elections are a red herring I'm afraid, and that's no exaggeration. If you want true and real governmental change, it requires you to vote the right congressmen and senators into the government.
I'm not sure who you guys think you're arguing against.
I understand why you feel like you're correct in naysaying and feeling like you're adding something to the conversation by being contrary. Unfortunately you're setting up a bit of a strawman, as if people who support Bernie feel like somehow he's going to magically change everything by himself. Bernie himself said that will not be the case, and you're mostly just arguing people who have little understanding of government, who honestly aren't even taking part in this conversation.
Bernie is probably the most likely candidate to promote the idea in your comment anyway, as he's the only candidate who I feel truly wants to change the system. So even in regards to your opinion your only real candidate is Bernie. He's the only one talking about political revolution, which is what would be necessary for real change.
Sometimes I forget that hackernews has a slightly more intelligent user-base. Unfortunately, I participate on reddit as well, and there, political supporters have a slightly naive view of how politics and the government works (that's putting it nicely). Sometimes I confuse the two websites.
> So even in regards to your opinion your only real candidate is Bernie. He's the only one talking about political revolution, which is what would be necessary for real change.
Well, real change means electing the right congressmen. To up-end our current republic, the first-past-the-post system, and to reform campaign finance requires electing senators who would do just that.
If Bernie wins the nomination, he's definitely getting my vote. Unfortunately, that's a near impossibility. And he also said he wouldn't run against Hillary if she wins the nomination. Bernie recognizes the fact that he would damage the party and take votes away from Hillary if he runs as an independent. He's a pragmatic & logical man and understands that a Clinton presidency is orders of magnitude better for our country than a Bush or Trump presidency. It's simply the lesser of all the evils.
And unless you run for office yourself, it's always, always going to be choosing between the "least evil" because no candidate will represent your views 100% unless, again, you run yourself.
Read that, not so crazy.
Unfortunately, I read the same exact thing about Ron Paul in 2008 & 2012. :)
http://www.csmonitor.com/USA/Elections/President/2011/1106/R...
and
http://www.forbes.com/sites/kenrapoza/2012/01/09/cbs-poll-in...
[1] http://www.senate.gov/legislative/LIS/roll_call_lists/roll_c...
[2] http://www.baldwin.senate.gov/press-releases/us-senator-tamm... & http://www.markey.senate.gov/news/press-releases/to-protect-...
How would net neutrality work without that regulatory power? The FCC needs teeth to do its job. Net neutrality without anyone to actively enforce it is the same as no net neutrality at all.
Rand Paul (or his supporters) are just using semantics to try and wave away this pretty important issue.
I'd argue that, to some extent, we're already seeing this many of T-Mobile's more pro-competition moves in the wireless telecom space, though it's also easy to argue that the FCC is more necessary there as wireless spectrum is a much more finite, common resource than fiber in the ground (theoretically, you could run an unlimited amount of it).
As an aside, of course, many see T-Mobile's moves as bad for net neutrality based on principle, despite the fact that they're actually good for the consumer today.[1] I might argue that those people are making the same argument you are about Rand Paul: that they're " just using semantics to try and wave away this pretty important issue".
[1] http://www.theverge.com/2014/6/18/5822996/t-mobile-music-fre...
For most potential players, it simply costs too much to even think about entering the market. Truly unregulated free markets are great in theory, but are instantly distorted when you take things like reality into account.
Part of what the recent net neutrality rules did is ensure that power utilities must lease pole/conduit access to internet utilities at the same rates they lease to cable tv and telephone utilities. This helps reduce cost to enter the market.
Government research and subsidies brought us these. The market only sold them.
You do realize that the government pays (with private company tax dollars) other private companies to do things for them, don't you?
http://www.wired.com/2013/07/we-need-to-stop-focusing-on-jus...
Except, all the evidence throughout history has shown this never to be the case. It never, ever works. It's what the big companies want you to believe to you'll buy into whatever ideology they're selling. It's libertarian nonsense with no basis in reality. It's a Koch brothers talking point - they literally live by that mantra.
The solution to the problem is to support organizations and institutions that have real substantive incentives to protect net neutrality -- not merely an inherently co-optable political mandate -- and to work in parallel to diminish the actual capacity of ISPs to actually abridge e.g. by promoting widespread end-to-end encryption of everything, etc.
The mindset of "we've got to address this potential problem by giving monopolistic coercive power to this single centralized institution" has just got to go away.
http://time.com/4154635/rand-paul-paul-ryan-omnibus-spending...
http://www.theregister.co.uk/2007/01/18/kahn_net_neutrality_...
The same with abortion laws. I'd be way more into supporting him if he would concede he doesn't agree personally, but that people shouldn't be forced by the government to live according to his religious beliefs.
The states-as-testing-grounds concept has always felt pretty reasonable. Some will make objectively bad choices, but the right choices will eventually will themselves out.
The folks fighting for gay rights had to go state-to-state because there was no traction in federal legislature to get changes made.
Follow up: http://www.politico.com/story/2015/06/rand-paul-comments-gay...
"I believe marriage is between a man and a woman. I am not in favor of gay marriage."
is exactly what Obama "believed" in 2008.
Paul is a libertarian and believes that Government should not be involved in the private space, including marriage. I think that's a very reasonable position to have - and I don't think I have seen him saying anything against gays, but please provide a source if you have any.
So in extensional terms, such "libertarians" are often indistinguishable from theocrats on key social issues (i.e., regardless of what different set of inner philosophical principles they might claim to be following, the outward result in terms of lawmaking is identical). Which in turn means they're not going to get my vote.
How many self-professed libertarians are there in the Congress? Paul's not even self-professed libertarian. The only one I know is Justin Amash, and he couldn't introduce any of type of bills you reference because under Boehner's regime only bills blessed by his team could ever make it to the floor.
https://en.m.wikipedia.org/wiki/Common-law_marriage_in_the_U...
I can't see myself voting in 2016. I find the views of all the Republican and Democratic candidates to be morally repugnant, just for different reasons.
As an LGBT person myself, I refuse to vote for Paul or any other candidate who opposes LGBT rights (including the entire Republican field), and as a Jew, I refuse to vote for any candidate that opposes refugees. However, I also won't vote for the Democrats because their views on other subjects are just as repugnant, including gun control and minimum wage.
Not a joke. I would vote for it.
This is not the case in an across-the-aisle Presidency. There are lots of Paul supporters who would like to see Sanders dead, and a whole bunch of them have guns and are fond of out-of-the-box thinking about their liberty. I spent a few months participating in online communities associated with Ron Paul back in 2007; It was enlightening, though it left me feeling a little soiled.
The interesting thing is if the Democrats nominate Sanders and the Republicans nominate Paul.
Interesting, if only due to its impossibility.
Like, not one the president and the other one the vice president. If they were just, dual presidents. Both the singular president. ( if either died, it would be counted as the president dieing, and the vp would take the place)
Nay - Sen. Michael Crapo [R]
Nay - Sen. Michael Enzi [R]
Nay - Sen. Charles “Chuck” Grassley [R]
Nay - Sen. John McCain [R]
Nay - Sen. Jefferson “Jeff” Sessions [R]
Nay - Sen. Richard Shelby [R]
Nay - Sen. John Boozman [R]
Nay - Sen. Richard Burr [R]
Nay - Sen. Jeff Flake [R]
Nay - Sen. Jerry Moran [R]
Nay - Sen. Robert “Rob” Portman [R]
Nay - Sen. Patrick “Pat” Toomey [R]
Nay - Sen. David Vitter [R]
Nay - Sen. John Thune [R]
Nay - Sen. Bill Cassidy [R]
Nay - Sen. James Risch [R]
Nay - Sen. Tim Scott [R]
Not Voting - Sen. Marco Rubio [R]
Nay - Sen. Rand Paul [R]
Nay - Sen. Mike Lee [R]
Nay - Sen. Tom Cotton [R]
Nay - Sen. Steve Daines [R]
Nay - Sen. Deb Fischer [R]
Nay - Sen. Ted Cruz [R]
Nay - Sen. Dan Sullivan [R]
Nay - Sen. Joni Ernst [R]
Nay - Sen. Benjamin Sasse [R]
Nay - Sen. Jeff Merkley [D]
Nay - Sen. Joe Manchin III [D]
Nay - Sen. Jon Tester [D]
Nay - Sen. Claire McCaskill [D]
Not Voting - Sen. Barbara Boxer [D]
Nay - Sen. Ron Wyden [D]
Nay - Sen. Edward “Ed” Markey [D]
Nay - Sen. Bernard “Bernie” Sanders [I]
Source: https://www.govtrack.us/congress/votes/114-2015/s339Cowards.
Schoolhouse rocks, last I checked, had one bill moving from one house to the other. Citizens could lobby at any point, including the conference committee.
Each of these were passed in isolation, then stuck together, then stuck into a budget bill. Then the only question was whether you wanted the entire bill to pass or not.
It's a fair interpretation to say that some reasonable public feedback -- if nothing else than what kinds of compromises needed to occur between both bills -- was missing from the mash-up we got this past week. Yes, majorities approved of similar bills in both houses. But there was no point in time where the public was informed "Hey, this is your last chance if you want to change what's going to go into the law"
Another way of looking at this is asking this question: if we're going to use the rules for budget bills on everything else that might be controversial, why have conference committees at all? Just pass kinda the same thing in each house and then look for the right political moment and the right combination of things to lump together so that you can do whatever you want to.
This is just leadership writing laws. If they want to do things like that, fine. I believe the logical conclusion is that we should start having direct election of house and senate leadership.
There was extended public debate and a prolonged amendment process for CISA and PCNA in both houses of Congress. There was intense media coverage and, once CISA passed in October, the consensus was that CISA was going to be the law of the land.
The one uncertainty about it was the extent to which the House would drag CISA towards PCNA's broader law enforcement language. Thankfully, that drama, with its attendant opportunity for "public commentary", didn't happen.
For you to make a strong case for how important a prolonged conference committee would have been to the process, I think you should start by pointing out another bill that died in a conference committee due to public outcry. Has that ever happened?
For those who are interested, this type of application is fairly recent. The Reconciliation Act was passed in 74. It hadn't even been out a year before it was being used in ways not anticipated by the sponsors, and the stretching has continued year-after-year. Relevant wiki: https://en.wikipedia.org/wiki/Reconciliation_(United_States_...
IIRC, CORBA was the first big "win", providing continuing insurance privileges to folks when they left their job. A great idea, no doubt, but not a damned thing to do with the budget.
Also more information: https://www.votetocracy.com/blog/what-is-reconciliation
Interesting historical quote from the second article. President Clinton attempted to use reconciliation to pass his 1993 health care plan, but Senator Byrd, according to Wikipedia, “insisted that the health care plan was out of bounds for a process that is theoretically about budgets,”
Times have changed. Each year these things get easier and easier.
I am sad.
In message board land, the fact that the bill was finalized in the middle of the night is evidence that The Man is trying to sneak CISA past us. In reality, nobody in Congress cares about CISA; that's a done deal. It's the budget they're being sneaky about.
I wouldn't be surprised to learn that CISA (and a bunch of other random stuff in the budget bill) had been scheduled to go through on the budget bill for weeks.
Thankfully? In the sense that at least it wasn't close to PCNA or that you think this bill will do anything to actually benefit "cybersecurity"? Because if it doesn't serve its purpose, then it doesn't really matter how close was or wasn't to the PCNA, does it?
Also, you're not worried at all about the legal protections companies get for cooperating with the NSA? If they "aren't doing anything wrong", why should they need legal immunity?
It is not the way conference committees work that there's a whole new open public process. By the time a bill has passed both houses of Congress, the incentive is declare victory and get the thing over with. The only reason there even is a conference committee is to get the House and Senate to agree on language.
I've explained repeatedly why the legal immunity language in CISA is not only reasonable, but in fact most of the impetus for the entire bill.
I'm a little annoyed at how you're asking me to explain it again, because that once again puts me in the position of being perceived as a supporter of CISA, which I am not. I'm very tired of people --- like, respectfully, you --- equating "effort taken to understand a complicated issue" with "partisan support for one side of that issue".
The "tell" that that's what's happening here is the language you chose to use: "you're not worried at all that...?". In sales, language like that is referred to as "an assumptive close". It is literally a mind control technique. Here, you're trying to deploy it on me to put me on the wrong side of an issue being discussed on HN.
PLEASE STOP DOING THAT.
In a late-night session of Congress, House Speaker Paul Ryan announced a new version of the “omnibus” bill, a massive piece of legislation that deals with much of the federal government’s funding. It now includes a version of CISA as well. Lumping CISA in with the omnibus bill further reduces any chance for debate over its surveillance-friendly provisions, or a White House veto. And the latest version actually chips away even further at the remaining personal information protections that privacy advocates had fought for in the version of the bill that passed the Senate.
Snowden's comment on this:
Shameful: @Facebook secretly backing Senate's zombie #CISA surveillance bill while publicly pretending to oppose it. https://t.co/du7RK7V1WJ — Edward Snowden (@Snowden) October 25, 2015
[1] http://www.wired.com/2015/12/congress-slips-cisa-into-omnibu...
The US really needs to break away from its 2-party system, and the only way to do that is to kill the FPTP voting system. Otherwise, Americans will never have real choices for stuff that really matters.
Maybe this is just the generation of internet users who are willing to trade other people's freedom for their own security, given the chance?
(Of course it's possible to repeal it later, as is true for all laws; they didn't pass a constitutional amendment.)
The public-choice situation as I understand it is that CISA was a bill that concentrated interests (large tech companies) liked but which the public as a whole did not like (insofar as they bothered to know about it). The key to passing such a bill is to minimize publicity and bundle it with a distraction.
--
Washington Times: "ISA cyber bill squeezed into omnibus spending plan | Lawmakers have contentious cybersecurity legislation into an omnibus spending plan..."
http://www.washingtontimes.com/news/2015/dec/16/cisa-cyber-b...
Huffington Post: "Congress Ties Controversial Cybersecurity Bill To Key Spending Package | And critics are not happy about it."
http://www.huffingtonpost.com/entry/cisa-omnibus-spending-bi...
The Guardian: "Congress just revived the surveillance state in the name of 'cybersecurity'"
http://www.theguardian.com/commentisfree/2015/dec/16/congres...
CNN: "Congress, don't be fooled by cybersurveillance bill"
http://www.cnn.com/2015/12/18/opinions/polis-cybersecurity-l...
International Business Times: "Controversial Cybersecurity Bill CISA Passes House, Takes One Step Closer To Becoming Law"
http://www.ibtimes.com/controversial-cybersecurity-bill-cisa...
Washington Times: "Lawmakers line up to complain about last-minute inclusion of cyber bill CISA in omnibus"
http://www.washingtontimes.com/news/2015/dec/17/lawmakers-li...
There's nothing at all wrong with that.
Certainly, even when I disagree with them, I'd rather read Wyden and Amash talking points than hearing about why we should kill the families of ISIS members. And I mostly agree with Wyden!
But it's just worth remembering that no matter what had happened with CISA and PCNA, there were always going to be these stories. You take press hits when you can get them, and these were lay-up press hits.
The House and Senate bills passed with overwhelming support and significant media coverage, and Obama backed the bill. Nobody is hiding.
Anyways, sorry to drag this out. I don't have anything more productive to add. I appreciate your insight here.
So his very first act as speaker is to break every single promise he made to become speaker.
He did? I thought he got the job (after much cajoling) because he was the only candidate the moderate and right wings of the GOP could agree on.
The idea that Ryan got the speakership through backroom deals is false. The House majority was in disarray following the sudden departure of Boehner and the failure of McCarthy's bid; the political media at the time was discussing how long the House could run without a speaker and what kind of rift the debacle would create in the GOP. Ryan was more or less drafted into the position.
McCarthy killed his bid with one interview on Hannity where he implied that he had helped orchestrate the Benghazi committee as a means to take down Hillary. That was the slip-up that gave the Freedom Caucus the necessary leverage they needed.
Other than that, I agree with your understanding of how Ryan became Speaker.
The shell shocked attitude that's followed by complacency is exactly, "We're all megafucked," possibly in other words.
It's exactly that attitude that we need to steer away from, no matter how grim the landscape looks. That's step 1 to change.
If our local community can become strong enough, we may have a chance to survive to see what the next attempt at national/federal(/world?) government might look like.
It's one of the few ways I can think of to do something positive and legal. And non-violent.
As for not seeing the end of it, it's the same as TOS and software updates we receive on iOS, et al. Not many people look at the details, rather they just press OK. Attrition as an agent of change is much more effective than a full-frontal assault. https://en.wikipedia.org/wiki/Fabian_strategy
Their landing page has this quote "If CISA passes, all your photos, posts, relationships, and likes will have a path to government databases." Which, from what very little I understand, is not quite true. At a minimum, "government databases" already have such a path via subpoenas, NSLs and such right?
I want to believe FB is worse, yes. I'd just like a more convincing source to give people.
People are not going to distrust a [free] service they use daily, they'll give FB benefit of the doubt, time and time again. It doesn't matter how good the source, today's users are addicts.
The secret is Baseline Budgeting[1].
If your agency got $100 this year, you ask for $110 next year and that becomes the "baseline." Now when the actual budget negotiations happen, you may only get $105. Most people would call this a 5% increase but instead they consider it a (roughly) 5% cut from the baseline.
This is how the government can claim they're "cutting the budget" while still spending more than last year.
For a bonus, imagine the above agency is sympathetic - like the food stamp program - and requests $200 next year. When some Congressperson says "No wait, you only need $110," they're accused of "cutting food stamps in half" and "wanting people to starve!" It's effective for tearing apart the other person, not effective for actually getting things done.
Baseline budgeting uses current spending levels as the "baseline" for establishing future funding requirements and assumes future budgets will equal the current budget times the inflation rate times the population growth rate.
Sounds reasonable to me.
There are one-time projects, ongoing programs, an ever-changing list of agency priorities, and - like any negotiation - groups start higher than they need so they have wiggle room. And yes, many of those things are out of thin air or completely arbitrary.
That's quite a claim.
EDIT: Now that I think about it, you're clearing confusing budget requests with baseline budgets. Everything you've said applies to budget requests.. none of it applies to baseline budgeting.
CBO assumes the government continues current operations and applies the effects of new laws to create their baseline.
Agencies include discretionary spending to create their baseline.
All of this is noted on the Wikipedia page.
Baseline is defined by law. There's no made up definition or arbitrary budget.
Budget requests are not baseline budgets. These are two completely different things.
Agencies request more than they need so they can say their budget is being cut. That's like negotiations 101.
Other than your words, you're basically correct.
Sure, but that means the companies now face minimal incentive to protect user data but doubtless will experience pressure from the government to give it up even without a warrant.
The EFF's criticism is basically that the bill is overly broad and can be used nefariously, even if it's not an all purpose FB message vacuum:
> The bill's broad immunity clauses, vague definitions, and aggressive spying powers combine to make the bill a surveillance bill in disguise. Further, the bill does not address problems from the recent highly publicized computer data breaches that were caused by unencrypted files, poor computer architecture, un-updated servers, and employees (or contractors) clicking malware links.
https://www.eff.org/deeplinks/2015/10/eff-strongly-oppose-ci...
That seems consistent with my aforementioned worry.
1. They can establish and run a process that ensures that data doesn't have personally identifying information in it. For instance, they can have a process by which they sign off on the types of things they're willing to share, and share only the stuff that never has PII in it.
2. They can instead run software that tries to spot PII and zaps it before sharing it.
I don't know how people can take EFF seriously when they say things like "aggressive spying powers". Whatever "spying powers" are in this bill are subtle; I don't think they're there at all. EFF does this a lot: they know their readers aren't going to read the bill, and further that their readers want to believe that the bill is horrifying, and they play that to the hilt.
Agreed that the EFF risks its reputation when it freely uses hyperbolic language. But I think some of this is due to (mostly philosophical) difference about how much we should worry about granting vague powers to the government which are mostly not abused. People similarly differ in how fiercely they fight free speech restrictions, etc.
But my interest is in making sure we know the truth as precisely as we can, and I believe nobody is well-served by the propagation of falsehoods, even when the falsehoods support a valid narrative.
As such, it strikes me as a try-hard and forced attempt to implement private-to-governmental-entity data sharing with little assurance, and cloaked as a seemingly routine bill. It thus makes perfect tactical sense to bundle it with an omnibus, since it blends in well.
They even inherited the CISPA amendment that established that terms of service violations weren't cybersecurity threats.
"Cybersecurity purpose" is itself mostly a pointer contingent to the meaning of "cybersecurity threat":
Except as provided in subparagraph (B), the term
cybersecurity threat means an action, not protected by
the First Amendment to the Constitution of the United
States, on or through an information system that may
result in an unauthorized effort to adversely impact the
security, availability, confidentiality, or integrity of
an information system or information that is stored on,
processed by, or transiting an information system.
(6) Cyber threat indicator is rather loose with F, G and H. B drops the term "security control". A seems to be legitimately trying to address automated scanning, but might seem to let through legitimate scraping since it doesn't further qualify.If this is, as you say, one of the least egregious definitions, then I'm not sure whether this is a cause for concern or hope.
The possibility that Facebook could be attacked makes the lawyers unhappy: their job includes minimising risks, and this is a big one given the PR around it. The ability to oppose abusive requests makes the (very many) privacy-concerned employees happy: they really don’t like spending their career helping ideas they strongly oppose. That’s why you can have contradictory statements.
The real issue here is the existence of secret courts, and administrative processes that exclude judges and the basic legal protection (guaranteed by the Fourth amendment in the US). Facebook can’t really oppose that without exposing itself to spin around being pro-terrorists (which is mind-boggling when you think about how loudly the same people talk about “Freedom”). Allowing an appeal and maintaining needed discretion in certain matters is a delicate problem, but hardly a new one in law.
It sounds to me (not a legal expert) that what would be preferable is to have a Public defender for privacy, fluent in legal and technical matter, who be made privy to secret decision, and not allowed to contact the people being targeted before they know about the surveillance. The ACLU sounds like they could recommend good candidates. A judge should be able to do that, and Congress at a higher level — but whomever was in charge lately has dropped the ball quite dramatically, being both lied to and far too lenient in what they knew.
Specific details of how to do this must be decided in the next 90 (or was it 180)days and compliance oversight reports are required regularly.
I'm a little embarrassed, but I must have missed the part where this makes things worse. I'm being honest here: If I should be upset about this I need to know why, please.
Unlike CISPA, CISA allows shared information to be used for law enforcement purposes. Ideally, threat information shared with the government should be used solely to improve defenses and prevent breaches; instead, anyone who shares data now needs to be cognizant of the other uses to which it will be put.
(PCNA had broader language that enabled prosecutions of a variety of crimes with indicator data).
Again, CISPA, the bill FFTF takes credit for killing, had none of this language.
Where does it state that private cos get access to this data?
103(a)(3) also requires them to share, when possible, with the general public.
In the Senate CISA draft, the language about "entities" is a little confusing. "Entities", unqualified, are private companies; government agencies are "Federal entities".
One the few changes in the budget bill CISA is to have the law now refer to "Federal entities" and "Non-federal entities".
I'm sure Techdirt found a way to spin that into a conspiracy to chopper away the Open Whisper System developers in black helicopters.
Is there a digestible explanation of what this CISA entails?
The full text is only about 30 pages, and can be found here: https://www.govtrack.us/congress/bills/114/hr2029/text/eah#l...
This is embedded in the "H.R. 2029: Military Construction and Veterans Affairs and Related Agencies Appropriations Act, 2016", which is the vehicle for the Omnibus bill as passed by the Senate yesterday: https://www.govtrack.us/congress/bills/114/hr2029
CISA defines "cybersecurity threats" and "threat indicators", which are now legalese versions of the stuff Intrusion Detection Systems track: exploit code, vulnerability information, and wire traces of attacks.
Everyone already collects this stuff; that's most of what network security teams are paid to do. The government has several huge network security teams (they operate the largest IT system in the world), and, of course, the whole Fortune 500 does as well. All these organizations are collecting information about attacks and siloing it.
CISA requires the government to establish a process to share indicators with private companies. So when analysts or IPS systems or anomaly detection schemes running inside FedGov networks generate a signature for an attack, there will now be federal rules requiring them to submit that data to a process that will disseminate it to the private sector.
CISA allows the private sector to do the same thing in reverse, sharing their data with the government, which will in turn share a facsimile of that data back out to the rest of the private sector. The bill requires companies to have a process to ensure they aren't knowingly sharing any personally identifying information, and they are only allowed to share information that pertains to the types of attacks defined as "cybersecurity threats". Those attacks specifically exclude terms of service violations.
Unlike CISPA, which was a more benign bill, CISA explicitly allows local, state, and federal law enforcement to use threat indicators to prosecute crimes. CISA has a very short list of crimes whose prosecution can be assisted with shared indicators --- identity theft, espionage, and trade secret theft. PCNA, the (now dead) House version of CISA, had a broader list.
Unlike the law of the land before CISPA/CISA/PCNA was proposed, there is now a path for private companies to share data with the USG regardless of the other regulatory regimes they're under. This is good if you think sharing attack information is very important and bad if you think companies that work with regulated information (driving records, credit scores, medical data, student records, &c) should operate under different, stricter rules than other companies. Much of the impetus for these bills was to overcome objections from legal at BigCos that would never allow any information sharing out of fear that such sharing could get them sued. They are now immunized from those suits, so long as they're in good faith sharing only information about actual cybersecurity threats.
That's pretty much it, at a high level. It's a very short bill, just 30 pages, and most of the interesting stuff is in the definitions at the top of the bill. It's worth skimming.
Here's what the bill says you can share, lightly edited:
Data about malicious reconnaissance and recon anomalies, vulnerabilities and exploit code, anomaly events that describe exploit attempts, privilege escalation attempts that bypass security features for post-auth users, malware C&C, documentation of the data exfiltrated by attackers in breaches, and, finally, anything at all related to cyber attacks iff you were already lawfully allowed to share it.
That's it.
The deeper problem is that any piece or amount of information can, in the right circumstances, become personally-identifiable, and so the only guaranteed-safe system would be to forbid collecting or sharing anything. Which would necessarily result in literally turning off the internet.
At the very least, this allows one to quantify the tradeoff of security and specificity in what is released.
Encrypted pub/sub social will be the only way to ensure privacy, long-term. (Other than purely anonymous networks, which have other use cases.)
By "we", I mean those of us with the technological know-how to protect our own privacy if desired.
I bring this up because laws like CISA are meant to deal with large-scale collection of data for ostensibly well-meaning reasons from the vast majority of internet users. Those vast majorities that aren't lurking on HN, who don't know or care about the technical details of privacy beyond maybe vaguely wanting it, who want the internet to work, fast, free, and easily.
It seems to me that with the vast law enforcement and intelligence agencies on the one side and the even larger internet economy on the other, there is no serious getting in the way of whatever flow of information those two groups agree on. It doesn't matter what you, me, the EFF, or Edward Snowden think. There is far too much money at stake. And the "privacy" threat, as we discuss it here, is irrelevant to just about everyone.
Beyond implementing strong crypto with trusted software, for those who care to, I don't see that there is anything to be done here. As Schneier pointed out a few years ago, this ship sailed a long time ago: https://www.schneier.com/blog/archives/2013/03/our_internet_...
Original: https://www.techdirt.com/articles/20151022/10133932597/cisa-...
Votes against the bill that was signed into law: https://www.govtrack.us/congress/votes/114-2015/s339
Is there a standard or format for how the government will expect this threat data to be packaged? STIX / TAXII?
Startups; assemble!
Even if the US government would attempt to force companies to do this, they wouldn't. And as far as I can tell, this bill doesn't force companies to comply, it just holds them harmless should they choose to comply.
This means that the precedent is already set. If the company operates in the US and is served a warrant, the US Govt wants ALL of the data WHEREVER it's held.
I'm rooting for MS on this one and hope their appeal is upheld.
[1] http://www.theguardian.com/technology/2014/apr/29/us-court-m...
[2] http://www.zdnet.com/article/microsoft-refuses-to-hand-over-...
[3] http://www.techweekeurope.co.uk/e-regulation/microsoft-resis...
The US and EU obviously have two completely imcompatible rulings in play now.
So apparently corporate media has no problem with CISA for some reason.
Since congress rarely write their own laws and let the industry write it for them - who actually wrote CISA ? There's no way congress would know what to ask for. Did the NSA write CISA?
In some sense that would put us closer to agreement, but from my perspective that viewpoint clings to a prescriptive model that is clearly irrelevant at this time. Democracy has become our national religion, and the mechanics of how the celebrities obtain office isn't so important as the idea that no action is off limits to the court of public opinion, adjudicated by the media.
They're not covering it now because this is boring procedural stuff. There's no story this week. Obama has been on record all year saying he'd sign it. The one dramatic thing that could have happened --- a showdown between the House and Senate over whether the language would be closer to the (bad) PCNA bill --- didn't happen.
All you're noticing is that CNN isn't covering a nonstory.
"(e) Prohibited conduct -- Nothing in this title shall be construed to permit price-fixing, allocating a market between competitors, monopolizing or attempting to monopolize a market, boycotting, or exchanges of price or cost information, customer lists, or information regarding future competitive planning."
Does this imply it could have been construed that way without this clause?
How can public fight government for years and lose?
How is it possible to pass a law in US that is clearly against everyone's will? I mean for all I know, most of the people are strongly against it, except for a few polititians, nobody wants this to happen, so how is that even a discussion?
because democracy only works when people actually care. most us citizens are more concerned about the superbowl than government.
> How is it possible to pass a law in US that is clearly against everyone's will?
Who is everyone? Again - most people don't give a shit.
The day of reckoning is coming.
> It strengthens cybersecurity programs