Rep. Mike Rogers Calls CISPA Opponents "14 Year Old Tweeters in Their Basement"
cms.fightforthefuture.org
cms.fightforthefuture.org
Something you might want to know is that "Fight For The Future" feels comfortable riling you up without telling you the full story about the bill. CISPA, according to FFTF, "lets the government spy on you without a warrant". In actual fact, CISPA is an opt-in measure that allows a company like Yahoo to share information about ongoing attacks --- which find a specific definition in the bill, more specific than any other cyber bill proposed --- with security providers and with law enforcement.
It's been my experience that most people who oppose CISPA are not familiar with what the bill actually says, even though CISPA is a very short bill. There are principled opponents of CISPA with very strong arguments, but sites like FFTF are unprincipled in their opposition to the bill.
I have far fewer karma than you, and have been on HN far fewer days, but I'm not stupid. And I know that your hypocrisy on every single HN post regarding CISPA is reaching an intolerable level.
Your rhetoric is flawed at a very basic level -- you claim that the EFF and other institutions are not telling you the complete truth about the bill and advocate it with such ferocity, yet, even you fail to present valid arguments.
You use smoke-and-mirrors tactics to distract readers from the real point -- which is not whether anti-CISPA institutions are telling you "the whole truth" -- but whether CISPA infringes on the Fourth Amendment. The bill has loopholes, and the traditional unclear and tangled legalese that is all too prevalent in bills such as these only ensures there will be more to come.
Sometimes a vocal majority can be wrong. But that doesn't mean you should discredit their rhetoric, because it's valuable. If we all did what you said, we would be likely still be living in monarchical England.
Basically, it's open season on surveillance because now companies aren't liable if requests are followed in "good faith," which essentially means "we did whatever the government wanted."
Of course there is no oversight aside from the people who are making requests, so the idea that a company would actually be penalized for releasing info "unreleated to cyberthreats" is laughable at best.
I do agree with you that the definitions of cybercrime and attacks in CISPA would be a start for the framework for coherent legislation. I just don't think that DHS should continue to be added onto piecemeal until they control 100% of all law enforcement activities as well, since let's face it, that's the eventual goal.
But ideally? I don't want anybody to share any information of mine to any third party, without my consent, at any time. I'm having trouble thinking of why that would be necessary.
I'm willing to entertain reasonable arguments as to why it might be necessary, and may make some compromises (without wildcard language) in light of a compelling argument, but nobody sponsoring CISPA has even made an attempt to do that.
1. You're a web app company that routinely comes under DDOS attacks. A private security company would like you to subscribe and push Netflow traces to them during attacks, so they can derive minimal ACLs and relay them to ISPs so the attack could be filtered upstream. That Netflow data could in theory contain some of your traffic, and further could be statistically de-anonymized to reveal your personal usage of that service. Currently, you need authorization from your counsel every time you share that Netflow data; post-CISPA, you could get a one-time authorization and automatically push Netflow to the anti-DDOS provider.
2. You're working with several social networking companies to track down a browser malware attack that transmit itself through online messages. You'd like to collect a large volume of samples programmatically to share with other providers and LEOs, but you're extremely concerned that in doing so you might reveal details about private messages, perhaps even by sharing which users have messaging relationships with other users. Pre-CISPA, your counsel might refuse that sharing outright; post-CISPA, you'd have statutory protections for sharing that operational data in the course of responding to malware.
I guess you could argue that malware often uses mail to spread, and that a social media provider might dragnet a whole bunch of email spools to collect malware samples and then forklift it to LEOs for investigation. That would be bad.
The bill takes some small steps to keep that from happening, but probably not enough.
Maybe you could point out the call to action I must have missed on this site, urging readers to learn more about the bill before signing up with FFTF.
So what if it's written specifically? People often don't have much of a choice when it comes to their ISPs, and wouldn't be able to just choose another one that doesn't opt in. In the modern world, where people use the internet for every facet of their life, this essentially means law enforcement gets to know every detail about you, without the need for any reasonable suspicion.
I really don't understand how this isn't a violation of the 4th Amendment. Our rights as citizens and as people are being removed by bills like this, and by law enforcement and large service platform based businesses redefining what personal information is ours to control and own.
no, that's not anywhere in the bill. did you read the bill?
He's on "Hacker News". It would be perfectly reasonable for an automated system that is designed to look for security-related activity to report that fact. The bill, as it is written, says any action his ISP now takes, or anyone that they share his information with (which would then be allowed to do, with anyone in the poorly defined "cybersecurity club"), is fully acceptable as long as it was "in good faith." And who could argue that? Hacker News is benign, but it's an honest mistake.
Furthermore, if it did, it doesn't matter. Bad actors are allowed to be wrong, with impunity, if they promise that it was "in good faith".
4) CYBER THREAT INFORMATION.—
‘‘(A) IN GENERAL.—The term ‘cyber
threat information’ means information directly
pertaining to—
‘‘(i) a vulnerability of a system or net-
work of a government or private entity;
‘‘(ii) a threat to the integrity, con-
fidentiality, or availability of a system or
network of a government or private entity
or any information stored on, processed on,
or transiting such a system or network;
‘‘(iii) efforts to deny access to or de-
grade, disrupt, or destroy a system or net-
work of a government or private entity; or
‘‘(iv) efforts to gain unauthorized ac-
cess to a system or network of a govern-
ment or private entity, including to gain
such unauthorized access for the purpose
of exfiltrating information stored on, proc-
essed on, or transiting a system or network
of a government or private entity
You're right that I phrased this more casually than the bill does, which harms my point but I believe still leaves it standing.Did you think that I was suggesting you were merely phrasing it casually, or is that a subtle argument technique? ;)
"EXEMPTION FROM LIABILITY.—No civil or criminal cause of action shall lie or be maintained in Federal or State court against a protected entity, self-protected entity, cybersecurity provider, or an officer, employee, or agent of a protected entity, self- protected entity, or cybersecurity provider, acting in good faith"
A simple use case for this law: you are under a concerted DDOS attack. Your network deals with, say, drivers records. Drivers records are protected under the DPPA. You want to share NetFlow information with a 3rd party DDOS tracking service. Today, your general counsel needs to authorize any such sharing explicitly. Post-CISPA, you could make arrangements to share that information automatically.
Taking the opposing position, I might argue:
(a) Our total ineffectiveness at responding to current network security attacks is such a pressing issue that a legislative "patch" makes sense, rather than spending time litigating fiddly changes to tens of existing statutes.
(b) It might not be to our benefit to relitigate the protections of those existing privacy bills; the result might be a weakening of existing privacy protections. Creating a common-sense exception that says "you can share malware or DDOS netflow traces no matter what kind of company you are" might leave our civil liberties safer in the long run.
And that is kind of a poor justification because we know that society doesn't currently have an epidemic of people DDoSing the DMV.
Someone else wants this passed, and they really want it passed. It ain't the DMV.
Incidentally, the DPPA wasn't written to lock down the DMV.
I use the DPPA as an example of surprising limitations on the ability of private companies to share operational data that could conceivably due to operator error or time constraints potentially include protected information. Another example: FERPA.
Care to give a few more examples of what makes it more complicated?
The problems with the bill are mainly this:
1. The immunity gives companies an incentive to share more data.
2. There is neither oversight nor transparency for the sharing of information and other measures companies are allowed to take based on this bill, and what the government and third parties are allowed to do with the information.
3. Even if there were oversight, the conditions under which the companies would get immunity are so broad and ill defined that there is practically no restriction on that.
I would like to add that there are people who make hysterical arguments against the bill, but that doesn't mean that the bill isn't bad.
The whole point of the bill is to get companies to share more data.
Your second sentence is a rather weak counterargument. (1) would be fine on its own, it is in the context of (2) and (3) that it is not; the incentives make (2) and (3) extra bad.
FYI, you have a dead link: http://www.matasano.com/services/shipsafe/
You have a weird and broken understanding of how engineering firms are contacted to test for vulnerabilities. CISPA has absolutely no bearing on my firm whatsoever.
Surely it's not rude to ask if you have a personal interest, given that (1) CISPA has explicit provisions for security companies (2) it's not clear why this would not apply to your company and (3) you defend CISPA on almost every CISPA post on hacker news.
As far as I can tell, these sections of the bill indicate that it does apply to your company:
‘‘(A) CYBERSECURITY PROVIDERS.— Not-
5 withstanding any other provision of law, a cy-
6 bersecurity provider, with the express consent
7 of a protected entity for which such cybersecu-
8 rity provider is providing goods or services for
9 cybersecurity purposes, may, for cybersecurity
10 purposes—
11 ‘‘(i) use cybersecurity systems to iden-
12 tify and obtain cyber threat information to
13 protect the rights and property of such
14 protected entity; and [...]
So, if the company your are investigating gives you consent, you may obtain cyber threat information. Note that this says nothing about the way the company is contracted.What is cyber threat information?
1 ‘‘(2) CYBER THREAT INFORMATION.—The term
2 ‘cyber threat information’ means information di-
3 rectly pertaining to a vulnerability of, or threat to,
4 a system or network of a government or private enti-
5 ty, including [...]
So this means that you can get all information pertaining to a vulnerability, and CISPA will protect the company you're getting that information from. This is so vague that it could be virtually any data. But it gets better: ‘‘(4) EXEMPTION FROM LIABILITY.—No civil or
12 criminal cause of action shall lie or be maintained in
13 Federal or State court against a protected entity,
14 self-protected entity, cybersecurity provider, or an
15 officer, employee, or agent of a protected entity, self-
16 protected entity, or cybersecurity provider, acting in
17 good faith—
18 ‘‘(A) for using cybersecurity systems or
19 sharing information in accordance with this sec-
20 tion; or
21 ‘‘(B) for decisions made based on cyber
22 threat information identified, obtained, or
23 shared under this section
So even if a company managed to share data that would not be allowed, as long as it's acting "in good faith" everything is A-OK. Given this I fail to see how your company is not a consumer of cyber threat information as defined in this bill.If you are so easily offended, you may wish to review your own writing style, since your comments are far from the least argumentative on HN (and I do not just mean this thread).
Thanks for your blessing, you have mine as well.
I hate to be cynical, but calling your Representative may not be enough. Judging by Hanna's 118-year-old quote, it's never been enough. In the long run the solution might be campaign finance reform, but in the short run we may also want organizations like the EFF to raise money so they can finance political campaigns aligned with their values, gaining more influence over the political process.
--
[1] http://www.goodreads.com/quotes/405598-there-are-two-things-...
At least when it's pay-for-favors the public can follow the money. Not to mention the fact that under this system, any ordinary citizen has a much better chance of affecting outcomes by encouraging others to pool resources than he would have under systems that afford people power mainly, or solely, through kinship or affiliation.
But most importantly, take 2 minutes and call your House Rep and tell them what you think about CISPA: https://eff.org/r.5bPw
I found it quite cathartic.
I feel that 14 was chosen deliberately to give teh additional implication that CISPA opponents "don't have the right to oppose it" or something along those lines.
the pejorative "basement" refers to an adult who doesn't have their own residence, and so lives in extra space in (but near the edge of) their parent's home, while pretending it is a separate residence. It doesn't make any sense to call a 14-year old a "basement"-dweller, they would have a regular bedroom.
I've read through CISPA. It's got some very elegant wording, but its contemptible all the way around in what its going after.
The tech industry is so much bigger and more important to USA economy than the content industry that allowing them to dominate the lobbying discussion is just a 'tail wagging the dog' situation.
Yes -- a bunch of people who are four years away from being able to vote Rogers out of office.