CISPA would give a safe harbor from other privacy rules to companies that share information with the government as long as that information is about "cyber threats". Now, let's say someone breaks into your database server and you're at a company with not-too-skilled IT people. The government shows up and says "hey, what can you tell us about the attack you experienced? PS - we'd be happy to analyze your data for you."
What do your IT people do? They say "screw it, we'll just send in all the logs we have and let the feds figure it out." And so they do that.
What if the law protects the information in those logs? What if the information is sensitive (like health or financial information) and is protected under a special privacy regime like HIPAA? Or what if the information is protected from disclosure by contract (like in a TOS/TOU document)? CISPA says that the disclosure is exempt from whatever sanctions/punishments would happen under those protection regimes because Cyber Threats Are Important (tm).
Disclosure: I am not a lawyer. Even after it's passed into law, only a court can decide exactly what the safe harbor in CISPA means.
That sounds like a security risk waiting to happen at your cell phone carrier and email service provider.
The bill as written, even before the narrowing amendments, acknowledges the risk this subthread discusses. It does that by trying to define "cyber threat information", as information directly implicated in an attack. In the sponsor's notes on the bill on the House site, they explain that the definition of "protected entity" was changed specifically to prevent individual people from being considered as entities, so that person-specific data couldn't be handed over under CISPA authority.
The basic problem the bill addresses is this: large companies are under continuous attack. Let's stipulate that attacks come in two flavors: DDOS and targeted malware.
In both cases, there is clear utility in allowing companies to collaborate with other companies and with the government.
In the DDOS case, you want to share NetFlow information with your upstream ISPs and with DDOS trackers, because those are the organizations that generate black-hole and IP filtering rules, and they all work better if they have lots of different vantage points to work from. At the very least, you want to push sources back up to your immediate upstream providers so they can soak them up on their infrastructure rather than saturating your uplinks.
In the malware case, you want to share forensic information that would help identify (a) the vulnerability the malware exploits, (b) the C&C system the malware is using, (c) any evidence of the source of the malware, and (d) forensic information that would help investigators discern the intent of the malware.
In both cases, your company's general counsel is apt to inform you that the legal risk of sharing just that information is potentially unbounded, because nobody can predict exactly what claims could be made under ECPA, SCA, DPPA, HIPAA, FERPA, &c; nobody even knows what traces of information, overt or statistical, might be lurking in NetFlow.
So the situation we have today is that there is information sharing when attacks happen, but much of it is sub rosa, and you have to be in the right clubs to get access to the right sharing networks.
It does not make intuitive sense to me that electronic privacy should mean that basic low-level systems information incident to a real attack should incur unbounded legal risk when shared with other companies directly involved in mitigating those attacks.
You might disagree, and that's fine. But the notion that CISPA is actually intended to allow NSA to read your email is just not supported by the language of the bill, by any advocacy for the bill, or by any of the bill's amendments, and the problem the bill is addressing is a real problem (I have some limited professional exposure to it).
May I assume that you'll publicly oppose CISPA if it continues to advance without that amendment? :)
Also, regarding your claims that person-specific data can't be handed over, a separate amendment requiring that failed by a 4-16 vote. So it will be able to be shared with the NSA.
BTW, I'm not arguing that there are not real problems arising from attacks that large companies, and even smaller companies, face. The question is what to do about it, and whether CISPA remains the best vehicle.
I don't so much care whether CISPA passes. What I do care about is people trying to fundraise by convincing willfully ignorant nerds that CISPA is a backdoor SOPA bill; why, just look, GoDaddy supports it, it must be bad!
The amendments are public too. You can actually read them.
As you can see, I'm not very charitable about this. Nerds are to online regulation what the Michigan Militia is to gun control. I respect and defer to fact-based objections to CISPA, but I have no patience for the (large set of) people who simply make things up about it to try to win arguments.
I do not have a problem with people who generally oppose Internet regulation of all sorts (I don't agree, but I don't make fun of them either).
I do have a problem with "Internet Hate Machines" of all sorts. You are not entitled to invoke principles to deploy bad facts.
Have you read the 2013 House CISPA amendments. I have. They're public. I'm guessing, no, right? Are you a gambling man? Would you like to bet me how agreeable they are relative to the text of the bill itself? The 2012 CISPA amendments tightened and restricted the act. What do you think the new 2013 amendments do?
The only amendments I've read about in 2013 are PII removal and removing the "national security" terms, both of which are civil liberties enhancements. (although I don't know where to find the actual text of the amendments). The 2012 amendments were improvements to baseline CISPA (especially the ToS vs. CTI clarification, which was my only real objection to CISPA originally). I do not think I'd take your bet; the probability of something bad being attached is low, but if something bad is attached, it's high severity, so moderate risk. You'd give odds based on probability and I'd want based on expected-harm.
Re: IHM. Reasonable people don't really win at politics. Look at how AARP/etc. essentially eviscerate anyone who thinks of touching Medicare or SS. Thus, horrible public policy (wealth transfers from the poor and young to the old and wealthy!) persists in the face of all logic. That it does shows how effective their lobbying/rabble-rousing strategy is.
Civil libertarians tend to err on the other side, for "what would be best for society", and end up with all kinds of bad stuff happening to them.
I'm ok with "ends justify means" in this case -- if "means" is "make everyone in Congress terrified of any cyber-laws which aren't explicitly and transparently improvements to individual privacy and freedom."
This¹ site lists the amendments and has a PDF for each. I'm not sure if it's all of them or contains the ones you mention. The PDFs are dated and some are Feb-April 2013. This PDF² seems to be the current bill with the amendments accounted for in the text ("H.R. 624 as Amended").
edit: I just noticed that ² has a date of Feb. 2013 while some of the amendments have April 2013 dates, so I don't think it's the most current version.
¹ http://intelligence.house.gov/hr-624-bill-and-amendments
² http://intelligence.house.gov/sites/intelligence.house.gov/f...
I'd be interested to hear defenders of the legislation explain why CISPA remains such a lovely bill after the House Intelligence committee rejected these four amendments that were aimed at protecting privacy:
* Limiting the sharing of private sector data to civilian agencies, and specifically excluding the NSA and the Defense Department. (Failed by a 4-14 vote.)
* Directing the president to create a high-level privacy post that would oversee "the retention, use, and disclosure of communications, records, system traffic, or other information" acquired by the federal government. It would also include "requirements to safeguard communications" with personal information about Americans. (Failed by a 3-16 vote.)
* Eliminating vague language that grants complete civil and criminal liability to companies that "obtain" information about vulnerabilities or security flaws and make "decisions" based on that information. (Failed by a 4-16 vote.)
* Requiring that companies sharing confidential data "make reasonable efforts" to delete "information that can be used to identify" individual Americans. (Failed by a 4-16 vote.)
1) NSA and USAF are specifically the only parts of the USG I want to have access to this data. I trust NSA and DOD way more than I trist FBI, DEA, etc. to not fuck me personally if my data is somehow included in a dump given to them for anti-terrorism purposes.
2) Useless bureaucrat. I don't believe in oversight of government by government; mandatory reporting requirements to the public, with independent watchdogs like EFF/ACLU, are the only thing which would really work for me.
3) Vague thing is vague.
4) I don't really want companies to have to do PII filtering; I'd rather they be able to dump bulk data if under attack, since J. Random big dumb company or non-security startup is in no position to do forensics, filter, etc.
Ryan, your head seems to be screwed on properly, so what are the things you would like to see done to CISPA to make it commercially feasible to share bulk data when banks or ISPs come under sustained attack?
I don't know if it's possible to limit CISPA, while keeping it useful, enough to keep civil libertarians happy. The best solution is probably to take a page from my much more seriously followed personal legislative issue: gun rights.
I'm actually in favor of universal licensing/background checks and such for firearms, if implemented correctly (not building a registry, using a technical solution to make it possible to trace ownership of a gun without enumerating all guns owned by a person, etc.)
But, the gun lobby/gun owners rightly fear any new regulations are just there to kick them down the slippery slope, so they dig in their heels and oppose everything.
The way around it, I think, is to have a good background check bill proposed which ALSO eliminates a bunch of ineffective existing regulations (allow import of 1968+ MGs, non-sporting-use weapons, no 922(r) parts count, sale of transferable new post 1986 MG under existing NFA rules, removal of SBS/SBR/suppressors from NFA, potentially CCW reciprocity). There's enough pro gun stuff in that to make up for the risk/fear of the new licensing regulation.
Maybe do the same thing with CISPA -- information sharing, but at the same time address the NSL issue, fix anti-circumvention in DMCA, potentially limit CALEA (I hate that it applies to anything but POTS telephony), etc. I'm not sure what specific concessions should be made, but the idea of trading some relaxing ineffective or bad existing law for new law seems like the best way forward.
(I have complained, and they said the should be there the next day, but then I pointed out about 25 cases where it wasn't, and they kinda stopped talking :P)
But I disagree with his "Michigan Militia" analogy, which is a bit silly. Another way to look at it is that starting with Clipper, CDA, CALEA, crypto export controls (plus mandatory domestic key escrow approved by a House committee), we've lived through 20 years of ill-advised regulation. So unless the merits of a new proposed law clearly outweigh the downsides, which is not the case in CISPA, a measure of skepticism is reasonable.
I can imagine FBI director Louis Freeh saying the same thing when he was defending bans on non-escrowed encryption in the late 1990s: "Nothing wrong with mandatory key escrow! Silly ACLU EFF EPIC etc. are just trying to fundraise off of fear and emotion."
You yourself have conceded on HN that advocacy groups have directly misstated details about CISPA. Now you're writing comments suggesting that I'm being misleading by pointing that track record out. That is not honest debate, Declan.
Second, I'm not aware that anything ACLU EFF EPIC said that's intentionally false re: CISPA. As you correctly say, other groups may not be as careful (although even then, you could have unintentional falsehoods, and I rarely like to speculate about motives).
Tech companies trust themselves to only share the critical info needed for better security, so they do not see a risk in CISPA.
Citizen groups do not trust tech companies or the government, so they see risk in any legislation that seems to reduce oversight of info sharing between them.
You're right that nobody should be making inaccurate claims about the bill (though I try to be charitable and say inaccurate claims in either direction are misunderstandings, not intentional distortions). I'm making a slightly different point, which is an argument for lower threshold to trigger scrutiny, and a higher threshold to legislate in the first place.
Also, is there any subject for which everyone can agree that Congress is good at proposing legislation? The whole point of the legislative process is to adjudicate between competing opinions; so whether any piece of legislation is "good" or "bad" will vary, to some extent, according to the observer.
Edit to add conclusion: Each bill should be judged on its merits, not on the fact that it comes out of Congress (since that is where they all come from).
"...voting to derail lawsuits against telecommunications companies that unlawfully opened their networks to the National Security Agency. Senators voted 69 to 28 for the bill, which would rewrite federal wiretap laws by granting retroactive immunity to telecommunications companies..."