Proposed Info Sharing Legislation Could Worsen NSA Surveillance
cdt.org
cdt.org
Watch in the coming weeks as lawmakers point to the OPM hacks as justification for spying on everyone's Gmail activity.
They have already used so-called terrorism legislation to put away people involved with the drug trade. How long before they start spying on people downloading copyrighted material or in the UK people watching unsavory porn.
We can't stop leaking your personal information to the enemy, so we obviously need to collect and store more comprehensive and personal information.
Section 4(d)(2) requires removal of personal information before sharing unless that personal information is directly related to a cybersecurity threat.
A cybersecurity threat is defined as "an action, not protected by the First Amendment to the Constitution of the United States, on or through an information system that may result in an unauthorized effort to adversely impact the security, availability, confidentiality, or integrity of an information system or information that is stored on, processed by, or transiting an information system" and "does not include any action that solely involves a violation of a consumer term of service or a consumer licensing agreement".
There is no mass surveillance implied in this.
> Because this surveillance would be done in secret, people would have no legal basis to challenge what amounts to an end-run around the U.S. Constitution.
The Constitution restricts government from forcing companies to give up information against their will. Nothing in the Constitution prohibits companies from voluntarily giving up information, and so nothing you have cited is in any way an end-run around the Constitution.
Section 4(d)(2) of _what?_ These minimization requirements have been removed or weakened in the various iterations of CIS(P)A that have appeared and been defeated year after year. There is currently no bill in front of Congress, so your citing of a specific provision is questionable. Congress is expected to take a new version of CISA up in the next few weeks.
> The Constitution restricts government from forcing companies to give up information against their will.
Except under Section 702, companies are compelled to hand the information via secret orders with gag provisions. Fighting these orders is expensive and the gag orders prevent the companies from openly opposing them.
It _is_ an end-run around the Constitution if the data a company provides belongs to an individual and is disclosed without a proper warrant, unless you agree with the statement that "people have no right to privacy in any data held by third party service providers." Such an attitude ignores the reality that cloud services have become integrated into peoples' lives, and ubiquitous enough that the end-customer should have legal interest and Constitutional protection in data held by third parties.
Section 4(d)(2) of the bill that the article you are commenting on is writing about, S.754, the "Cybersecurity Information Sharing Act of 2015".
Anyway, I would appreciate if you could address the other point I raised because I'm very curious to hear your philosophical thoughts on this subject.
On the Constitutional issue:
> It _is_ an end-run around the Constitution if the data a company provides belongs to an individual and is disclosed without a proper warrant, unless you agree with the statement that "people have no right to privacy in any data held by third party service providers."
People have multiple rights to privacy related to such data. Some come from state law. Some come from federal agencies. Some come from federal legislation. Some come from the Constitution.
The ones from the Constitution protect against government compelling release of the data. They don't protect against the providers deciding on their own to disclose the information to the government (or to the public, or to private parties). If, for instance, PG&E decided to publish a list of its customers along with contact information and energy use records, it would not be violating a Constitutional right to privacy. If the government demanded that PG&E make and turn over such a list, then we've got a Constitutional issue to talk about.
In that hypothetical, PG&E would be violating some of those other rights to privacy that come from state legislation, federal legislation, and agency rules, and would run into a ton of trouble.
So, why does the Senate keep trying to crank up this sort of thing? They need to be a little answerable to their constituency, they need to exhibit a little leadership in terms of not just blindly following party leadership and lobbyists.
Is this whole category of law a place where the DoJ has intercepted enough sketchy conversations that they've got leverage against key Senators and Reps? That's the only thing I can think of, other than the "intelligence community" is flat out lying in the secure sessions. Since the "intelligence community" has a long history of lying, with a lot of recent scandalous reveals, you'd think that oversight committees would be a lot less willing to just believe.
So, I'm torn. Why does this keep popping up?
Constituents may vote, but lobbyists pay the bills.
Remember when EFF sued AT&T for [letting the NSA wiretap their Internet backbone facilities][1]? Congress killed the lawsuit by retroactively granting immunity under the FISA Amendments Act.
CISA is just the same thing, but for newer programs like PRISM, and tech companies want the immunity because they're otherwise being exposed to major liability.
Personally, I think a better idea would be to reform Section 702 of FISA to ban programs like PRISM. The government should be required to get a warrant when they want to look at private data.
We need security that my mother can understand. dad had a top secret clearance so mom understands why she needs to shred paper documents.
ive had no such luck explaining to her how to maintain her privacy with her imac.
That's all I can think of too after reading Daniel Suarez' "Influx." With the resources and information at their disposal I would not put it past them to take this approach.
That raises the question of how we can change the system if we have to assume some sort of blackmail like that might be taking place. Is there a workaround?
I was amazed that this story had such short legs. It seems like a big deal to me, a really big deal.
http://www.thedailybeast.com/articles/2015/06/24/hackers-sto...
Unfortunately many sites do not permit connections from exit nodes. cloudflare always requires one solve a captcha.
duckduckgo by contradt provides a hidden service.
Im planning on providing one too; I wouldnt want the FBI to know who is reading my articles about c++ memory management.
There was no mention of spying on their own citizens.