How does the Cybersecurity Act of 2015 change the Internet surveillance laws?
washingtonpost.com
washingtonpost.com
To get there, it is going to take a complete shift in how we build internet software. These problems cannot be fixed using the current status quo. I highly encourage you to start looking into projects like Ethereum, IPFS, Whisper and Swarm. The offer a way to build web applications that are completely immune to censorship, monitoring, and large scale data breaches while giving user's control over their data.
This isn't to say that there aren't battles to be fought in the legislation arena. There are and kudos to entities like the EFF for leading the charge. What I'm trying to say is that as long as it's possible to do pervasive surveillance, we're going to keep seeing the powers that be continue in that direction. If it is possible, they will try and do it.
Sources:
* https://github.com/ethereum/go-ethereum/wiki/Swarm---distrib...
I find it a bit disingenuous that this is not being disclosed, considering that there are numerous Ethereum competitors (primary, Bitcoin with SegWit, coming 2016, and Storj, Maidsafe).
I thought about adding the disclaimer and chose against it. Maybe I chose wrong. I sort of see your point about conflict of interest, but that line of thinking also disqualifies almost all of the people who are most intimately familiar with the technology.
If you're skeptical, lets have a conversation about it. I regularly describe my position as skeptically optimistic about Ethereum's future success.
Yes, when one is advocating for and recommending a product, it is pretty standard (and, in my opinion, an ethical requirement) for one to also disclose that he/she is heavily involved with that product. It is even more important when one stands to benefit -- especially financially! -- from the product's success.
One's credibility quickly goes right out the window when one fails to disclose these basic facts.
Last year, I was driving across the country and needed a place to crash. I randomly looked for someone from a PyCon list and found Piper. He was happy to let myself and a friend sleep at his home; he introduced us to his family and greeted us warmly.
So, take his words with whichever grains of salt you find most relevant.
Furthermore, I find your comment extremely suspect, considering you also have a top-level comment [1] in this thread that basically amounts to "guys, guys... there's no reason to worry about this bill!"
If anyone's motives should be questioned, it's you.
In order to make sure we don't spill private data I think we need a privacy active monitoring browser. For example, it should have a list of all the identifying attributes such as name, email, facebook page, reddit nickname and make sure they are not passed outside. The privacy browser could also identify dangerous topics and pages and send warnings before searching/posting/loading anything. It would actually enforce good data hygiene to make this process much easier for people.
Privacy is hard to maintain, requires a lot of care and a single mistake could be enough to reveal your real identity. That's why we need to create safe environments where privacy is a given.
Isn't the point of the whole privacy thing to not be forced in to avoiding discussion of certain topics for fear of being labeled a dissident?
[0] "Alibi Routing" [pdf] suggests a way to avoid routing packets through certain locations (e.g. to counter dragnet surveillance) http://conferences.sigcomm.org/sigcomm/2015/pdf/papers/p611....
We're too late. It already passed.
FTA (first sentence):
> "... President Obama signed into law last week ..."
We saw this coming a long way off. The best solution I can think of is requiring politicians to take comprehensive classes on whatever topic they're grying to legislate, but that in itself is a nightmare to implement.
Well, first, they wouldn't be the same advisors -- even same-party administrations don't tend to carry over very many of of the President's direct advisors.
Second, even with the same advisors, Sanders, while he might agree with Obama on some things, is likely to have different priorities and values, which will shape actual policy, even if he had the same advisors presenting the same facts and similar interpretations of the facts.
They might be persuasive. But there is little evidence from outcomes in Iraq, Syria, etc. that they are right in any way that matters.
The Occam's razor explanation is that this is just politicians acting in their interests, not that there is some blockbuster intel that, if only we knew...
It's not that there's a great threat, it's that the public is just particularly stupid about this issue.
http://www.huffingtonpost.com/evan-greer/bernie-sanders-woul...
> "I think Snowden played a very important role in educating the American public ... he did break the law, and I think there should be a penalty to that," Sanders said. He went on to say that the role Snowden played in educating the public about violations of their civil liberties should be considered before he is sentenced, and that as president he would "absolutely" end the NSA spying programs in question.
Basically it seems to me he wants Snowden to get a fair trial, which would require some new legislation first or for him to be charged with a different crime. And aside from Rand Paul, I don't think any other candidate is as strong on Internet freedom as Sanders.
What is concerning is what the law may be twisted to "authorize" (see patriotic act and mass metadata), but on the surface of it I really don't see concern about CISA.
>What is concerning is what the law may be twisted to "authorize"
It's the only way to keep government and politicians honest.
Of course they are working on inventing reasons to make that illegal too.
No, not in a practical sense. Securing data in transit and at rest drgrades the value of breaking endpoint security, and it degrades the value of massive internet snooping.
Breaking endpoint security, one machine at a time, and exfiltrating data, is vastly riskier than hoovering it up from the backbone. It is more likely to be noticed, and the exfiltration traced. It doesn't scale well.
Endpoint security sucks now, but if people, governments, and enterprises find out data being exfiltrated from their machines, the demand for secure hardware will increase.
Whether that's good or bad can be debated, but we're talking about endpoints giving up data, not necessarily ISPs snooping and reporting badness.