Obama Administration Threatens To Veto CISPA
techdirt.com
techdirt.com
I'm glad to hear this veto threat, but I hope our President has the sense this time to realize that signed laws can be used or abused by any future President.
We cannot predict how laws will be used. Software patents are a classic example.
These are disjunctive. The President threatened a veto of the NDAA over very specific provisions that he disagreed with, which _were_ removed eventually. In addition, the NDAA did not authorize anything habeas corpus related that the Supreme Court hadn't already ruled AUMF did. (See Hamdi v. Rumsfeld)
I would rather see a more pointed example of blatant disregard of a veto threat before I cast judgement on the credibility of this one.
A veto threat is not a veto promise. Just because most Americans oppose a certain provision doesn't mean the veto threat is conditioned on removing that same provision. The proof is in the handling of the NDAA bill text.
Though I'm not familiar enough with the bill to know if everything objectionable in CISPA is in fact objected to in the memo, it's definitely a substantial and positive step.
In addition, H.R. 3523 would inappropriately shield
companies from any suits where a company's actions are
based on cyber threat information identified, obtained, or
shared under this bill, regardless of whether that action
otherwise violated Federal criminal law or results in
damage or loss of life. This broad liability protection
not only removes a strong incentive to improving
cybersecurity, it also potentially undermines our Nation's
economic, national security, and public safety interests.
I don't need to know everything about the bill to know that liability protection that broad is a Bad Thing, and that attempts to strip it out are both substantial and positive.Hint: the Federal law that attempts to establish that email stored at a provider is even "private" to begin with carves out a broad exception for exactly this kind of sharing, with no limitations on how that information is stored or relayed.
It's also worth noting that HIPAA is a notoriously toothless regulation; if you talk to practice managers that focus on health care, you'll hear stories about companies simply setting aside funds to pay the (comparatively minor) fines they're unlikely to be assessed.
I don't mean to excuse or justify any acts on behalf of the president, just to point out that the surrounding circumstances are a lot different.
There is way too much political gamesmanship around packaging bills together in our system today.
I would personally support a Constitutional amendment putting an upper limit on the amount of attachments placed in any bill passed by Congress.
Obviously what you really want to complain about is "bad" spending in general, for which both branch are guilty. But the problem with that is that there isn't that much "bad" spending. Cutting anyone hurts someone somewhere, and those people vote. So instead political wonks like to complain about process issues as a proxy, so they flip out about "earmarks" instead of actual policy. Yawn.
The check-and-balance situation at play here is why the notion of a "line item veto" is so controversial. The legislative branch of the government likes that the executive really has to mean it if it wants to shoot down a provision the legislature voted in favor of.
In this case, no part of the NDAA was interesting enough to not pay soldiers over. A previous comment on this thread is correct: the authority Internet people were freaking out about came not from the NDAA, but from the AUMF.
It is no accident that the US government is trying to control and throttle the internet. As dictatorships around the world have discovered, its the internet and freedom OR dictatorship. Our homegrown power lusters, such as Obama, are paying lip service to our rights while doing everything in their power to abrogate them. The internet has destroyed the traditional means (primarily via the NYT and the MSM) of controlling the political discourse and agenda . Like it or not, we are in the middle of the greatest social revolution since the invention of the printing press destroyed the power of the Catholic Church. See Clay Shirky's article on this topic; http://www.shirky.com/weblog/2009/03/newspapers-and-thinking...
Nobody really knows how this will turn out.
The congressmen are concerned by the next election, and the primary concern that currently drives american voters is the economy. So they're working to protect the intellectual property since it's pretty much the only thing we produce. That's a tiny assault on the constitution. The president is terrified of another terrorist attack because it will probably mean the end of his administration. So he has massive incentives to expand the rights of security organizations. That's a tiny assault on the constitution. The mayors are concerned with looking tough on crime, so they incentivize the police officers to stretch the concept of probably cause to clean up the streets. That's a tiny assault on the constitution from the other side, the municipalities.
This goes on, and on. If we had a person or an organization to take a stand against, things would have been much easier. But how do you take a stand against a massive system that includes every commercial organization, individual, municipality, and state and federal agency in the country?
Ultimately, a small group citizens concerned about individual freedoms cannot fight a massive system head on. There isn't enough energy or resources for dealing with millions of little issues one by one. The only way to make a difference is change the minds of the electorate in a scalable way. We haven't figured out a way to do that yet, because the right idea, the right meme that resonates with the majority of the populace hasn't been feed. This is why things may seem hopeless. But as we've grown to appreciate, this can change in a matter of days.
TL;DR: freedom needs a viral YouTube video.
Unfortunately for the thread, what I just described is an economic and engineering problem, not the narrative arc of a Cory Doctorow novel; in other words, my comment is boring, and so surely scores lower than its parents on HN.
1) Corporations will not share cybersecurity vulnerability data for fear of attracting lawsuits. As a result, known, relatively simple attacks succeed at company after company after company. CISPA seeks to solve this problem by limiting liability for voluntary data sharing. In theory this will help improve everyone's security by improving the dissemination of knowledge.
2) Federal cybersecurity intelligence is classified and therefore not available to private companies, who by the way run the vast majority of the U.S. data infrastructure. CISPA commands federal intelligence services to create a way to share their classified data with companies. Again: better dissemination of knowledge.
Both of these would help improve security.
1. Protect user privacy, separate intra-government sharing from government/private sharing (troubling because data shared with DHS could possible be shared with NSA or FBI then, even if the company doesn't intend for that data to go to those agencies) 2. More oversight/liability for inappropriate use of these proposed powers; data sharing should not be used to help incumbents crush startups 3. Liability waivers to encourage information sharing go way too far, protects bad behavior 4. Internet is civilian, but bill treats it as military re: intelligence, which is bad
CISPA is the GOP's "let the industry regulate itself" response to the Obama Administration's concern about Chinese state sponsored hacking. The privacy issue here is a fig leaf; CISPA is entirely voluntary (unlike previous "cybersecurity" bills supported by the administration), and private industry already has the legal tools to feed private information to the government under the ECPA.
ECPA, though, that's another thing to research, thanks. I just want to focus on getting founders the visas they need to build great companies; I don't know anything about this open internet stuff, but I keep getting dragged into it.
CISPA is certainly not going to be #3.
Grade sitting Presidents participating in a reelection campaign on their actions, not their words.
Much like the threat of a filibuster is basically as powerful as a filibuster, the threat of a veto is almost as powerful as a veto.
You're being vague. The truth is, once the president says he's going to veto a bill, it never makes it to his desk in its present state. In fact, all of the veto threats outline the parts he has a problem with and those parts usually go away.
But some laws can't be fixed. They can't be fixed because they're based on a false premise.
Enough with these threats of fix this or fix that! Garbage shall not pass. As simple as that.
If he didn't follow through, all his future veto threats would ring hollow and he'd have lost an important executive tool. Even if he didn't want to veto CISPA on principle, at this point he has too.
Granted I'm sure a lot of them already log data like that already.
https://www.eff.org/deeplinks/2007/10/qwest-ceo-nsa-punished...
Note that there are already 112 co-sponsors of the bill with folks from both parties. If there isn't some huge groundswell of public opinion (and a few nerd-oriented trade articles don't qualify) this could get a fairly big vote in the House. Perhaps veto-proof, more probably loaded up with lots more stuff anybody in their right mind would support (Orphan-Feeding Act of 2012?). It has certainly been set up to succeed. (Political wonk note: big difference between a bill with 100+ supporters from both parties coming to a committee vote and something like Chuck Schumer's yesterday one-of threats for better immigration law. They both might be reported in the same way, but there's a huge difference in the underlying reality.)