House Session on CISPA, ongoing now [video]
c-span.org
c-span.org
Unfortunately, if you read the bill with an optimistic view of government, most of the items in the bill are written to seem like common sense and good ideas. If the bill is read with a skeptical eye, one can see how vast the breaches of privacy and abuses of CISPA could reach.
It's been hard for me to get clarification on what some of the vagueries and broad language of the bill could actually mean legally due to most articles I read having a strong bias one way or the other.
I'm supportive of information sharing in order to combat and better protect against cyber threats, but if that information sharing is covered by a liability shield (which it almost certainly has to be), it seems like even a benevolent company may err on the side of sharing more information than needed with the government.
As the bill details little about oversight of who gets access to the data and how it will be used, a skeptical and cynical look at this information being in the hands of the government could suggest that this information would be used for profiling or information gathering on US citizens.
I think the broader argument could be "what expectation of privacy do we have on the internet?". I'm not sure where I fall on that issue, but I do wish it was clearer, not necessarily for me, but moreso for folks like my parents that don't truly understand what it means to send information across the internet (encrypted or unencrypted).
http://www.gpo.gov/fdsys/pkg/CRPT-113hrpt41/pdf/CRPT-113hrpt...
The first of them has passed.
The second, limiting the use of CLASSIFIED information to cyber-security activities, has passed.
The third, allowing independent contractors to handle cyber-threat information sourced from the USG, has passed.
I am predicting the fourth, which is so unbelievably boring that I refuse to summarize it, is about to pass.
http://www.gpo.gov/fdsys/pkg/BILLS-113hr624rh/pdf/BILLS-113h...
http://intelligence.house.gov/bill/cyber-intelligence-sharin...
This landing page includes links to the amendments.
Edit: I guess 'independent' contractors means individuals, I just meant independent of the government. Anyway, that's still my bet. It doesn't have anything to do with small companies needing to share netflows without asking their lawyers every time.
I just called my Representative and hope for the best, but I fear these assholes are going to win this round. I will be throwing the EFF some more money next payday though.
So I believe this is a done deal -- unless something dramatically changes.
(Shameless plug: I've summarized some of this on the blog: http://freedom-or-safety.com/blog/aclu-cispa-far-from-fixed/)
Q: Can a company hack a perceived threat under CISPA ("hack back")?
A: CISPA provides companies with immunity "for decisions made based on cyber threat information" as long as they are acting in good faith. But CISPA doesn’t define “decisions made.” Aggressive companies could interpret this immunity to cover "defensive"—and what some would consider offensive—countermeasures like DDOSing suspected intruders, third parties, or even innocent users. Private defense contractors have already advocated for this power. These actions should not be allowed by such expansive wording. It leaves the bill ripe for abuse.
So, corporations can effectively DDoS other servers now, without legal repercussion, as long as it was in 'good faith'. How does one evaluate 'good faith' in a court room? If I'm a small company with a website, and some major corporation attacks me and knocks my site offline because the attacker who attacked them spoofed the IP address with my website's address, are they off the hook because their attack was in 'good faith'?
To me, I get the feeling that CISPA is about more than violating privacy (although it does that in spades), but also legitimatizing the militarization of the Internet.
On the one hand, the idea that there could ever be federal authorization for "hacking back" at any target is preposterous. The result would be chaos. Attackers would almost certainly invest effort in tricking the service providers dumb enough to do it into striking innocent networks, or, better yet, into striking out at other providers who themselves would launch "hack-back" efforts --- you know, this is starting to sound awesome --- and in reality no company with a lawyer on staff, retainer, or in the phone book would ever allow their team to do such a thing, CISPA or no CISPA.
On the other hand, if just one company is dumb enough to misread the law as providing authorization and tort immunity from running attack code on their imagined attackers, that's probably a very good reason to amend the bill.
No one likes to see adults or minors injured, but this inclusion is at odds with proponents' claim that it CISPA is only "for cybersecurity purposes". Even the House Committee on Intelligence's own FAQ seems to contradict the bill's text in its first entry:
http://intelligence.house.gov/sites/intelligence.house.gov/f...
"Serious bodily harm" isn't a term which just covers terrorist acts; it covers things like automobile accidents. One wonders if data collected under CISPA could be used to find and prosecute drunk drivers in a National Park -- hey, it prevents serious bodily harm and it's on Federal property, right?
Other claims that the bill's language is too broad and needs more work:
http://www.legislationandpolicy.com/747/cispa-and-the-need-t...
http://www.whitehouse.gov/sites/default/files/omb/legislativ...
Noticed that there are only letters of support provided here, though. See https://www.eff.org/cybersecurity-bill-faq for EFF's take.
"However, the Administration is concerned about the broad scope of liability limitations in H.R. 624. Specifically, even if there is no clear intent to do harm, the law should not immunize a failure to take reasonable measures, such as the sharing of information, to prevent harm when and if the entity knows that such inaction will cause damage or otherwise injure or endanger other entities or individuals." [http://news.cnet.com/8301-13578_3-57579905-38/obama-threaten...]
In other words, that corporations should be punished for not providing information.