Showing posts with label cybersecurity. Show all posts
Showing posts with label cybersecurity. Show all posts

Tuesday, February 19, 2013

Meet the New CISPA. Same as the Old CISPA.

Monday, February 18, 2013 by Save the Internet
by Josh Levy

Last year, thanks to a public outcry, the effort to pass overreaching cybersecurity legislation stalled in the Senate. Now supporters have reintroduced the House version of that legislation — the Cyber Intelligence Sharing and Protection Act (CISPA).

The “new” version is in fact identical to the original CISPA — and poses the same threat to our digital civil liberties and our freedom to connect online.

Here’s what we had to say about CISPA last April:
CISPA would allow companies and the government to bypass privacy protections and share all sorts of information about what Americans do online. The legislation makes it far easier for authorities and private companies to spy on your email traffic, comb through your mobile texts, filter your online content and even block access to popular websites.

The new CISPA — just like the old CISPA — would protect companies like Facebook and Microsoft from legal liability when they hand over your sensitive online data to the federal government, without any regard for your privacy. The bill would permit the government — including the National Security Agency and the Department of Homeland Security — to use that information for matters that have nothing to do with cybersecurity. The whole process would, of course, take place behind closed doors, with no accountability to the public.

Last year’s activism succeeded in improving a similar bill in the Senate, before that bill ultimately failed to move forward. At the time, President Obama vowed to veto any destructive CISPA-like bill that reached his desk.

This time around, for a number of reasons — including changes in Obama’s staff and shifting political dynamics — it’s unclear if the president would once again commit to vetoing CISPA. So if this “new” bill goes farther than it did last time around, we simply don’t know what will happen.

If CISPA becomes law, it will be a major blow to our online privacy. But more than that, CISPA’s passage would have a chilling effect on our freedom to connect online. We won’t feel as free to state unpopular opinions, or to speak truth to power, if we know that Big Brother is getting a feed of everything we say and do.

This is not what the free and open Internet is about. We need to bury this bill for good.

Monday, February 4, 2013

Congress Will Battle Over Internet Privacy in 2013

Saturday, February 2, 2013 by Deeplinks Blog / EFF  
by Mark M. Jaycox

Last year, we saw more battles in Congress over Internet freedom than we have in many years as user protests stopped two dangerous bills, the censorship-oriented SOPA, and the privacy-invasive Cybersecurity Act of 2012. But Congress ended the year by ramming through a domestic spying bill and weakening the Video Privacy Protection Act.

In 2013, Congress will tackle several bills—both good and bad—that could shape Internet privacy for the next decade. Some were introduced last year, and some will be completely new. For now, here's what's ahead in the upcoming Congress:

Reforming Draconian Computer Crime Law

The Computer Fraud and Abust Act (CFAA), was one of the key laws the government used in its relentless and unjust prosecution of Aaron Swartz. Zoe Lofgren has proposed "Aaron's Law," which ensures that breaking a terms of service or other contractual obligation does not amount to a CFAA violation. Lofgren's reforms are a terrific start and will be introduced in Congress over the coming weeks. EFF has also proposed revisions to Lofgren's language and overall reform to the CFAA that reduces the draconian penalties and clarifies key definitions in the statute. The proposed reforms will go a long way in preventing a similar situation from happening to a freedom fighter like Aaron again. It's unclear where the language stands in the Senate, but Senators like Ron Wyden have voiced support for Lofgren's bill and should take up CFAA reform. You can take action and email your members of Congress to tell them to support reform of the Computer Fraud and Abuse Act here.

Update to the Electronic Communications Privacy Act (ECPA)

Once again, the 113th Congress will try to update the archaic Electronic Communications Privacy Act. The law, which was passed in 1986, lays out procedures for when the government can obtain your private electronic messages, like email or Facebook messages, from service providers. ECPA states that the government doesn’t need a warrant for emails when they are older than 180 days—even though the Sixth Circuit held that this “180-day rule” violates the Fourth Amendment. Despite the ruling, the Justice Department continues to argue that the DOJ does not have to obtain a warrant.

Last Congress Senator Leahy successfully moved the Senate Judiciary Committee to approve an ECPA amendment mandating warrants for all private electronic communications, but the bill didn’t get to the full Senate. This year, both Senator Leahy and House Reps. Goodlatte and Lofgren will introduce similar legislation to ensure that the same protections that apply to physical private messages also apply to virtual private messages.

Congress should take the lead from the courts and move the legislation forward.

Restricting Government and Corporate Use of your Cell Phone GPS Info

Updating ECPA is also about protecting users geolocation information, especially after the Supreme Court’s decision in the GPS case, United States v. Jones. Senator Wyden and Rep. Chaffetz's GPS Act mandates that the government obtain a warrant before it seeks a user's geolocation information. Currently, the government can obtain such information without a warrant or probable cause, which is something the government has done at a staggering rate.

But the government isn't the only entity spying on cell phone users. Over and over, users are learning the hard way that private companies surreptitiously collect information from users' mobile devices and often share that data with unknown third parties. That's why Congressmen like Rep. Markey and Senator Franken introduced legislation last Congress that requires clear notification and disclosures when a company collects and shares user information with third parties. Both Congressmen plan to reintroduce and move the legislation forward in the 113th Congress.

Cybersecurity Legislation

Congressmen are also girding for another fight on Cybersecurity. Along with more warnings of an upcoming "cyber-Pearl Harbor," Congressmen named cybersecurity a priority in 2013 and are planning to reintroduce a new version of an “information sharing” cybersecurity bill called CISPA, which as EFF described at the time, carved a giant and vague “cybersecurity” loophole into all US privacy laws, while alsogranting new powers and legal immunity to companies.

The Internet community helped defeat the Cybersecurity legislation and Congress needs to craft any new bill with the utmost concern for privacy.

FBI Silent About Wanting To “Back Door" the Web

Lastly, there are rumors that the Obama Administration will propose a new Internet surveillance law, which will expand the Communications Assistance to Law Enforcement Act (CALEA), which forces telephone companies to build wiretap-friendly backdoors into all their technology—but not social networks and other web-based communications services.In 2005, the FBI pushed the FCC to rule that VOIP and "facilities-based internet access providers" had to abide by CALEA requirements. Now they want even more power. This expansion is in spite of the fact that the FBI has yet to respond adequately to EFF's FOIA lawsuit seeking records that would justify the need to expand federal surveillance laws, given they have a myriad of ways to get such data already (Google’s transparency report shows the government requests for user data is skyrocketing).

The White House and the FBI have not released what is in the proposed legislation, but one report states the FBI wants to require Internet companies, like Google, Facebook, and Twitter to build the same type of backdoors for real-time government surveillance. This would not only create a huge Internet security problem, making the Internet less safe just as Congress pushes for a cybersecurity bill, but threatens basic privacy on the web.

The potential for the 113th Congress to introduce backwards bills like CISPA and CALEA is great. But Congress, and especially new members, should take note of the Internet community's strong—and successful—opposition to bills like SOPA.

It's time to curry favor with everyday constituents, and not with giant corporations or overreaching law enforcement.

Thursday, June 21, 2012

CISPA sponsor says Obama will sign cybersecurity bill

21 June, 2012 - RT


The White House has gone on the record to say that US President Barack Obama will veto the controversial cybersecurity bill known as CISPA, but the author of the act has his doubts that the commander-in-chief will keep that promise.

Congressman Mike Rogers (R-Michigan), one of two US Representatives responsible for introducing the heated Cyber Intelligence Security Protection Act to Congress, has opened up once more on the subject of CISPA. According to the lawmaker — who also sits as chairman of the House Permanent Select Committee on Intelligence — President Obama is likely to loosen his stance on the cybersecurity bill and sign it into law if given the change.

“[I]f we can get a bill on information-sharing to the president’s desk, he’ll sign it. I do believe that,” Rep. Rogers said this week during a panel discussion on the bill, reports Daily Dot. 

Since being introduced earlier this year, CISPA has attracted criticism from across the country thanks to activists rallying against the attempt to involve Washington in the inner workings of the Web. If passed, the government would be given the go-ahead to peer into personal information stored online by Internet users and would be invited to put their eyes on sensitive data provided to third-party companies and other private sector corporations that operate on the Web — all while excusing those businesses from any liability — under the guise of national security.

The legislation has already cleared the US House of Representatives and is awaiting a vote in the Senate. As lawmakers on that side of the aisle prepare to ponder the bill, however, Rep. Rogers says he’s confident that, once the “dust settles,” Obama will authorize the act.
Earlier this year, the White House responded to the attention CISPA was accumulating by releasing a statement expressing the administration's attitude against the bill.
“The sharing of information must be conducted in a manner that preserves Americans' privacy, data confidentiality and civil liberties and recognizes the civilian nature of cyberspace,” the memo reads. “Cybersecurity and privacy are not mutually exclusive. Moreover, information sharing, while an essential component of comprehensive legislation, is not alone enough to protect the nation's core critical infrastructure from cyber threats. Accordingly, the administration strongly opposes H.R. 3523, the Cyber Intelligence Sharing and Protection Act, in its current form.”

Comparisons have been made, of course, with another controversial legislation authorized by Obama in recent months that was done after a similar statement was offered to the public. Last year the administration insisted that the president would veto the National Defense Authorization Act for Fiscal Year 2012, but Obama eventually inked his name to the bill on December 31, providing a signing statement acknowledging that he had reservations about the legislation. Nonetheless, the attention-grabbing provisions of the NDAA that include rules about indefinitely detaining American citizens were included in the final bill, despite the president’s alleged opposition. Several state have since considered legislation on their own that would free them from complying with those federal provisions.

Last month, Howard A. Schmidt, a leading White House official who publically condemned CISPA on behalf of the administration, suddenly stepped down as Obama’s cybersecurity coordinator. In turn, skeptics were quick to suggest that the president may in the future be less persistent in the White House’s fight against CISPA than it had been with Schmidt on board.

That is not to say, however, that CISPA will be inevitably authorized. It has garnered the attention of several leading lawmakers in Washington who are opposed to the bill, including Rep. Ron Paul (R-Texas) and Sen. Ron Wyden (D-Oregon). Last month Sen. Wyden told members of Congress that passing CISPA would create “a Cyber Industrial Complex” that would allow the federal government and its Big Business cohorts to profit off of the personal info of any American with an Internet connection.

Monday, May 7, 2012

CISPA: An Alternate Future Where Your Personal Privacy No Longer Exists

By Adam Dachis ~ May 7, 2012 ~ LifeHacker

Last week the House of Representatives passed the Cyber Intelligence Sharing and Protection Act (CISPA), a follow-up bill to SOPA that wants to erode your personal privacy. The bill, itself, is palatable enough that Facebook and Microsoft gave it their seal of approval, and it's already got a kick start towards passing into law. So what would life be like if CISPA were part of our reality?




I Am Not Who You Think I Am
I am not a child pornographer, but you've probably heard otherwise. Everyone tells the story a little differently. Sometimes my classmates say I chose to drop out of the private college I'd wanted to attend since the day I understood ambition, and others believe my departure was the result of an expulsion. I'm not sure whose choice it was anymore, but ultimately it doesn't matter. You don't actually have to be a bad guy—you just have to be painted like one.

Back in early March 2013, a 12-year-old girl uploaded a copy of Toy Story to share with a friend she met online who lived overseas. That friend shared the movie with others, and suddenly it was heavily downloaded across the globe. The girl who shared it had no idea, but when the Motion Picture Association of America (MPAA) caught wind of her actions, they pressured the government for information. Just a year earlier you'd see internet service providers, web apps, social media services, and most corporations act cautiously before turning over private information about their clients—12 years old or otherwise. Then CISPA passed, and safest thing for any corporation was to provide the government with what they asked. Because cyber security was never clearly defined in the law, the possibility of intellectual property theft was a justifiable cause for investigation. The government took the girl's information and provided it to the MPAA. Days later, a lawsuit was in place. At first I didn't believe this because it sounded so ridiculous, but then I remembered that a similar suit was filed against a 12-year-old girl for downloading music in 2003. And then something impossible happened to me.

I Drew the Wrong Card
I never had aspirations of becoming a writer, but my parents were both hard workers and always insisted that I'd be best served in any profession if I spent my time on writing and math. Being the geek that I am, math came easy but I wasn't so fortunate with words. It's one of the reasons I chose my college. It was known for its communications school, and every major was required to study several dimensions of writing. Incoming Freshmen were required to take two essay-writing courses during their first year. Most students were averse. I was excited.

The course options varied from the dull to the dramatic, so I wasted no time registering for an essay class simply labeled "Controversy." Each month we wrote a short argument about subversive topics selected at random. Every student drew a small card from a brown paper bag. Most of my classmates wanted the card that read "legalize marijuana." I wanted more of a challenge, and I got one. My card read, "reform child pornography law."

At first I was a little concerned. It seemed incredibly wrong to even argue against any laws that served to prosecute child pornographers, illustrators, or anything that sought to sexualize children. But after a little research, I discovered that many of the laws were vague and too broadly applied. They were written in a way that allowed the government to prosecute and convict alleged deviants based on flimsy evidence. It wasn't much different from CISPA, which was signed into law highly due to its broad language.



Full size


As I continued my research I found more and more instances of laws with vaguely-defined terms that were designed to be tough on crime. No one bothered to oppose them in fear of being painted weak, or as a lover of terrorism and sexual deviancy. As a result, innocent people ended up in jail as collateral damage. The law had chosen to try and assuage our fears by sacrificing our freedoms as payment. But even worse, it didn't seem to be working. When you cast a wide net, you not only catch too many fish but so many that you can't find the fish you're actually looking for. People who broke the law weren't getting caught because the resources previously utilized to catch them were diverted to finding offenders before they actually offended. It's a nice thought to think we can preemptively prevent a crime, but it just doesn't work.

Nonetheless, you can't write an argument against child pornography laws without feeling at least a little gross. Just the act of Googling "information about child pornography" is enough to unsettle most stomachs, mine included. I made myself feel better by making off-color jokes about the subject in online chats and emails. I even posted a few of them to Facebook. I'd always been very careful about what I shared online, but we have a tendency to only try to protect ourselves when the threat is obvious. I didn't conceal my subversive sense of humor because I didn't believe that anyone would care. I did request for my search history to be tossed out, but it turned out that choice only applied to my account. My history was still being tracked "anonymously" with my IP address.

Perhaps none of this would've mattered if my school's servers hadn't been hacked. You wouldn't think there was much to hack, but the college had a system that allowed students to use their identification cards to make purchases at the bookstore, in the cafeteria, and at any other retailer partner around the city. The college charged all of our purchases to a stored credit card number at the end of each month, and the hacker seemed to be after that data.

Many private colleges—especially the older institutions—are a bit behind on security so this database was an easy target. They never caught the hacker, but s/he sold the data and it became one of the larger identity theft investigations that year. As a result, the federal government took an interest and started an investigation. While the interviews were tense (for those of us who had them) and watching the FBI roam the campus made everyone uncomfortable, the real problem came when they acquired our private data.

Student email, chat logs, search histories, social media posts, and more were handed over to the feds. Google, Facebook, Microsoft, Mint, Twitter, AOL, and Yahoo were all in compliance. CISPA made it practical for companies to ignore our privacy and offer up our data because they were shielded from any legal action on our part. It was during the many months that the FBI combed through our stupid conversations and useless posts that they found no hacker in the student body. But they found supposed evidence of drug sales and a few media pirates. They also found a common thread in my data: child pornography.

My Reputation Was Collateral Damage
The first chat began with the school, who chose to inform me of the allegations before I spoke with the authorities. It didn't take long for the other students to hear about my alleged sexual deviancy. They'd heard about the drug dealers and the downloaders, too, but those crimes assumed a certain "bad ass" quality that did little to ruin a reputation. When people believe you might be a sex offender, it doesn't really matter if you are. The damage has already been done. It's the sort of accusation that follows you for life.

Eventually my name was cleared, but not before the school asked me to take a leave of absence until the investigation was complete. I didn't argue. My roommate requested a transfer that was quickly granted. I received looks and threatening notes. My friends had my back, but I could tell that defending me took a toll on them, too. It was best for everyone if I just left.
I didn't think much of CISPA when it passed into law. It seemed like the sort of thing that would only reach people who put themselves in bad situations. I'd never expected that going to college would fall into that category.

It was a bill that never should have passed in the first place. At the time, President Obama had promised to veto CISPA if it ever reached his desk, but even the best-intentioned politicians make compromises. He did the same thing with the National Defense Authorization Act, after all. Perhaps CISPA passed because the internet had just put up a valiant fight against SOPA and PIPA and didn't have the energy to take on yet another piece of frightening legislation. What worries me the most is the ability humans have to adapt. Many were outraged when CISPA was signed into law, but we felt that way about the Patriot Act, too. We adapted. We started ignoring the stories about victims until news organizations saw no reason to provide them anymore. The CISPA stories still manage to get a little press, but nothing has changed. We now have a government that works hand-in-hand with business.

We let this happen. CISPA may not directly affect everyone, but it leaves the possibility of everything we share online becoming an accusation. When we all live in glass houses, anyone can look guilty. It's easy to think you'll never be targeted, but I made that mistake. Hopefully now you'll know better.

This Is Not Yet Our Reality
Currently, CISPA has only passed the House of Representatives. Before it can reach the desk of the president, it must pass the Senate as well. If you oppose CISPA, contact your state senators and let them know how you feel. The web site SOPA Track now provides information about the position of each senator so you can find out where they stand as well as contact them if you disagree. The vote is coming soon. Now is the time to act.

Note: This is a fictional narrative based on what we believe the U.S. might be like if CISPA is passed into law, based on an in-depth discussion with Derek Bambauer, Associate Professor of Law at Brooklyn Law School. This story hasn't happened, but we've created it to illustrate one probable future.

Sunday, April 29, 2012

Insanity: CISPA Got Way Worse, And Then Passed in the House On Rushed Vote

from the this-is-crazy dept
by Leigh Beadon - TechDirt
Thu, Apr 26th 2012

Update: Some have asserted that Quayle's amendment actually made CISPA better, not worse. Thoughts on that.

Until Thursday afternoon, the final vote on CISPA was supposed to be Friday. Then, abruptly, it was moved up to last Thursday—and the House voted in favor of its passage with a vote of 248-168. But that's not even the worst part.

The vote followed the debate on amendments, several of which were passed. Among them was an absolutely terrible change (pdf and embedded below—scroll to amendment #6) to the definition of what the government can do with shared information, put forth by Rep. Quayle. Astonishingly, it was described as limiting the government's power, even though it in fact expands it by adding more items to the list of acceptable purposes for which shared information can be used. Even more astonishingly, it passed with a near-unanimous vote. The CISPA that was just approved by the House is much worse than the CISPA being discussed as recently as Wednesday.

Previously, CISPA allowed the government to use information for "cybersecurity" or "national security" purposes. Those purposes have not been limited or removed. Instead, three more "valid" uses have been added: investigation and prosecution of cybersecurity crime, protection of individuals, and protection of children.
Cybersecurity crime is now defined as any crime involving network disruption or hacking, plus any violation of the CFAA.

Illegally downloading a single MP3 means you have violated CISPA. Basically this means CISPA can no longer be called a cybersecurity bill at all. The government would be able to search information it collects under CISPA for the purposes of investigating American citizens with complete immunity from all privacy protections as long as they can claim someone committed a "cybersecurity crime". Basically it says the 4th Amendment does not apply online, at all. Moreover, the government could do whatever it wants with the data as long as it can claim that someone was in danger of bodily harm, or that children were somehow threatened—again, notwithstanding absolutely any other law that would normally limit the government's power.

CISPA is now a completely unsupportable bill that rewrites (and effectively eliminates) all privacy laws for any situation that involves a computer. Far from the defense against malevolent foreign entities that the bill was described as by its authors, it is now an explicit attack on the freedoms of every American.

HRPT-112-HR3523HR4628


Can CISPA Be Fixed?
from the perhaps-not dept


For quite some time now it has been argued that the government should present the actual evidence for why a "cybersecurity" bill is needed. We've heard fearmongering and warnings of planes falling from the skies, but no evidence that there's a real problem here -- or, if there is a problem, that it needs a legislative solution. And CISPA moves forward, passing  the House on Thursday.

Larry Downes has taken on the question of whether or not CISPA can be fixed and has decided that it cannot be, and that it represents a real threat to some key elements of the internet ecosystem. He lists out some key rules for policy makers (and goes into great detail on each, so click through):

  1. Don’t legislate technology using definitions that are either too specific or too general. 
  2. Don’t legislate technology until you can articulate concrete and calculable harms
  3. Don’t encourage or require information sharing with the government unless it’s unavoidableAll of this seems quite reasonable... which is why it's an uphill battle to get people to follow through on it.

Friday, April 27, 2012

Facebook Lobbies Washington to “Like” Spying on Users

Friday, April 27, 2012 by CorpWatchby Pratap Chatterjee


Facebook, the social network behemoth that is about to become a multi-billion dollar company, has been lobbying for a proposed new U.S. law called the Cyber Intelligence Sharing and Protection Act (CISPA) that would allow companies to share information with government agencies. Zaid Jilani at the Republic Report has been digging up details on the Washington lobbyists who are helping Facebook.

“Under CISPA, private companies may spy on user communications, whether stored or in transit, and freely pass personal information to the government as long as they claim a vague "cybersecurity" exception,” write Mark M. Jaycox and Lee Tien at the Electronic Frontier Foundation. “The bill also creates expansive legal immunity that makes companies and the government largely unaccountable to users. Companies ‘acting in good faith’ are also excused from all liability for engaging in potential countermeasures, even if they hurt innocent parties.”

This is not the first time that the U.S. Congress has tried to pass a dubious law on computer security in the name of stopping piracy. Last year, the Stop Online Piracy Act and the Protect IP Act – backed by Hollywood and opposed by Facebook, Google and Wikipedia – was defeated after a huge backlash. Opponents noted that the law – as drafted - would threaten freedom of speech and support Internet censorship.

Mike Rogers, a Republican from Michigan, and Dutch Ruppersberger, a Democrat from Maryland, are the sponsors of the new bill. Unusually for Washington, the two men work together well, according to the Washington Post. Rogers is a former Federal Bureau of Investigations agent who has been promoting the drone war, notes the Post, and the two men have the backing of people like Michael Hayden, former director of the Central Intelligence Agency and the National Security Agency. So it is small wonder that CISPA will help out the intelligence agencies by expanding their powers of surveillance.

Not surprisingly, activists like Avaaz are campaigning against CISPA and so is (surprisingly) the Obama White House, which has threatened to veto the bill if it makes it to the president’s desk.

But Facebook – which opposed the cyber-security bills last year – has decided to support CISPA. The proposed law “would make it easier for Facebook and other companies to receive critical threat data from the U.S. government,” Facebook’s Washington DC office posted on its blog. It would “impose no new obligations on us to share data with anyone –- and ensures that if we do share data about specific cyber threats, we are able to continue to safeguard our users’ private information, just as we do today.”

Well, many Facebook users would testify that the company actually does a very poor job of protecting user’s private information.

Zaid Jilani at the Republic Report points out that Facebook is actively paying a Washington lobby firm to lobby for CISPA. In his article titled “Dislike: Meet The Lobbyists Facebook Hired To Help The Government Spy On You” he reports on the people at Fierce, Isakowitz & Blalock that are working the halls of Congress to get the bill passed.

“What’s particularly interesting about all of these individuals is that every single one previously worked somewhere in the executive or legislative branches of the Federal government. They were paid by taxpayers to get the training and connections that now allow them to have high-paid lobbying jobs representing corporations,” writes Jilani.

After all, Facebook has a lot to gain from this such as the ability to “freely pass personal information to the government” and to be “excused from all liability even if they hurt innocent parties.”

On Friday, when Congress gets to vote, we will find out which members “like” Facebooks plans.

Thursday, April 19, 2012

SOPA Redux: Groups Push Back Against Cyber Spying Act


Wednesday, April 18, 2012 by Common Dreams
CISPA would allow government, private companies to surveil massive amounts of Internet users' data

Civil society groups are pushing back this week against CISPA, the Cyber Intelligence Sharing and Protection Act, which privacy advocates believe would give broad powers and immunity to private companies and the government to spy on Internet users.

While CISPA is purportedly meant to protect the government and companies from cyber attacks, Tim Karr of the media reform group Free Press says that "CISPA goes far beyond its stated purposes, sacrificing almost all of our online privacy rights without any safeguards against abuse." And it "could lead all too easily to governmental and corporate attacks on our digital freedoms."

Karr writes that "CISPA contains sweeping language that could be used as a blunt weapon to silence whistleblower websites like WikiLeaks and the news organizations that publish their revelations."

Digital rights group Electronic Frontier Foundation (EFF) notes that the act, written by Rep. Mike Rogers (R-MI) and Dutch Ruppersberger (D-MD), "will grant Internet companies immunity from civil or criminal liability for any monitoring or sharing of user activity—as long as it is done in ‘good faith.’"

The current pushback against CISPA called ‘Stop Cyber Spying Week’ has the suppot of groups including EFF, Avaaz.org, Free Press Action Fund, ACLU, Access, CDT and the American Library Association.

* * *
What is “CISPA”?
CISPA stands for The Cyber Intelligence Sharing and Protection Act, a cybersecurity bill written by Rep. Mike Rogers (R-MI) and Dutch Ruppersberger (D-MD) (H.R. 3523). The bill purports to allow companies and the federal government to share information to prevent or defend from cyberattacks. However, the bill expressly authorizes monitoring of our private communications, and is written so broadly that it allows companies to hand over large swaths of personal information to the government with no judicial oversight—effectively creating a “cybersecurity” loophole in all existing privacy laws. Because the bill is so hotly debated now,unofficial proposed amendments are also being circulated and the actual bill language is in flux. 
Under CISPA, can a private company read my emails? 
Yes. Under CISPA, any company can “use cybersecurity systems to identify and obtain cyber threat information to protect the rights and property” of the company. This phrase is being interpreted to mean monitoring your communications—including the contents of email or private messages on Facebook. 
Right now, well-established laws, like the Wiretap Act and the Electronic Communications Privacy Act, prevent companies from routinely monitoring your private communications. 
Communications service providers may only engage in reasonable monitoring that balances the providers' needs to protect their rights and property with their subscribers' right to privacy in their communications. And these laws expressly allow lawsuits against companies that go too far. CISPA destroys these protections by declaring that any provision in CISPA is effective “notwithstanding any other law” and by creating a broad immunity for companies against both civil and criminal liability. This means companies can bypass all existing laws, as long as they claim a vague “cybersecurity” purpose. 
What would allow a company to read my emails? 
CISPA has such an expansive definition of "cybersecurity threat information" that many ordinary activities could qualify. CISPA is not specific, but similar definitions in two Senate bills provide clues as to what these activities could be. Basic privacy practices that EFF recommends—like using an anonymizing service like Tor or even encrypting your emails—could be considered an indicator of a “threat” under the Senate bills. As we have stated previously, the bills’ definitions “implicate far more than what security experts would reasonably consider to be cybersecurity threat indicators—things like port scans, DDoS traffic, and the like.” 
A more detailed explanation about what could constitute a “cybersecurity purpose” or “cyber security threat indicator” in the various cybersecurity bills can be read here. 
Under CISPA, can a company hand my communications over to the government without a warrant? 
Yes. After collecting your communications, companies can then voluntarily hand them over to the government with no warrant or judicial oversight whatsoever as long is the communications have what the companies interpret to be “cyber threat information” in them. Once the government has your communications, they can read them too. 
Under CISPA, what can I do if a company improperly hands over private information to the government? 
Almost nothing. CISPA would affirmatively prevent users from suing a company if they hand over their private information to the government in virtually all cases. A broad immunity provision in the proposed amendments gives companies complete protection from user lawsuits unless information was given to the government: 
(I) intentionally to achieve a wrongful purpose; 
(II) knowingly without legal or factual justification; and
(III) in disregard of a known or obvious risk that is so great as to make it highly probably that the harm of the act or omission will outweigh the benefit. 
As Techdirt concluded, “no matter how you slice it, this is an insanely onerous definition of willful misconduct that makes it essentially impossible to ever sue a company for wrongly sharing data under CISPA.” This proposed immunity provision is actually worse than the prior version of the bill, under which companies could be sued if they acted in “bad faith.”

* * *

The Guardian: Cispa will give US unprecedented access, internet privacy advocates warn
With echoes of Sopa, critics charge that bill will overturn US privacy protections in government attempts to track hackers 
Washington looks set to wave through new cybersecurity legislation next week that opponents fear will wipe out decades of privacy protections at a stroke. 
The Cyber Intelligence Sharing and Protection Act (Cispa) will be discussed in the House of Representatives next week and already has the support of 100 House members. [...] 
In one section, the bill defines "efforts to degrade, disrupt or destroy" a network as an area that would trigger a Cispa investigation. Opponents argue something as simple as downloading a large file – a movie for example – could potentially be defined as an effort to "degrade" a network. 
The bill also exempts companies from any liability for handing over private information.
"As it stands the bill allows companies to turn over private information to the government and for them to use it for any purpose that they see fit, all without a warrant," said Michelle Richardson, with the American Civil Liberties Union (ACLU). "For 40 years we have had legislation about wiretapping that protects people. This would overturn that and make a cyber exception." 
Privacy advocates are especially concerned about what they see as the overly broad language of the bill. As people increasingly use services like Skype and other internet telephony services, Twitter and Facebook to communicate, advocates fear the bill is a land grab that would give US authorities unprecedented access to private information while removing a citizen's legal protection. 
It will be the first such bill to go to a vote since the collapse of the Stop Online Piracy Act (Sopa) in January after global protests and a concerted campaign by internet giants such as Google, Wikipedia and Twitter.

* * *

Timm Karr: Big Brother Is Not Your 'Friend'

Promoted to protect our national interests against a loosely defined horde of cyber-terrorists, CISPA goes far beyond its stated purposes, sacrificing almost all of our online privacy rights without any safeguards against abuse. It’s the type of misguided Internet legislation that we have seen in the past, where government and corporations craft restrictive new laws without giving Internet users a seat at the table. Will they never learn?

Groups including EFF, Avaaz.org, Free Press Action Fund, ACLU, Access, CDT and the American Library Association have just launched “Stop Cyber Spying Week” so that Washington understands that the online rights of millions of Americans are not negotiable. In addition to helping Americans contact Congress, these groups have unleashed the power of Twitter against any legislator weighing a vote for this bad bill.

The folks behind CISPA claim that national security interests make this surveillance necessary, but the bill's language is so vague and overreaching that it opens the door for rampant abuse. Here’s what’s wrong:
  • CISPA would allow companies and the government to bypass privacy protections and spy on your email traffic, comb through your text messages, filter your online content and even block access to popular websites.
  • CISPA would permit companies to give the government your Facebook data, Twitter history and cellphone contacts. It would also allow the government to search your email using the vaguest of justifications — and without any real legal oversight.
  • CISPA contains sweeping language that could be used as a blunt weapon to silence whistleblower websites like WikiLeaks and the news organizations that publish their revelations.
  • CISPA would have a chilling effect on our ability to speak freely online by stoking fears that the National Security Agency — the same agency that has conducted "warrantless wiretapping" online for years — could come knocking.
  • CISPA could lead all too easily to governmental and corporate attacks on our digital freedoms. And while there is a real need to protect vital national interests from cyber attacks, we can’t do it at the expense of our rights.

* * *


Katitza Rodriguez: EFF: The Impending Cybersecurity Power Grab – It’s not just for the United States

Using the guise of ‘cybersecurity’, CISPA aims to mobilize Internet intermediaries to institute a sweeping, privacy-invasive, voluntary information-sharing regime with few safeguards. The U.S. cybersecurity strategy, embodied in CISPA and other legislative proposals, also seeks to empower Internet companies to deploy ill-defined ‘countermeasures’ in order to combat these threats. Use of these powers is purportedly limited to situations addressing ‘cybersecurity’ threats, yet this term is so loosely defined that it can encompass almost anything – even,potentially, to investigate potential breaches of intellectual property rights! 
The cornerstone of the privacy-invasive CISPA component is the establishment of private-public partnerships for information sharing. This creates a two-tiered regime that, on the one hand, facilitates the collection of personal Internet data by private Internet companies as well as the sharing of that information with the government and, on the other, allows government agencies to share information with private companies. 
To enable information flows from Internet companies to government agencies, CISPA will grant Internet companies immunity from civil or criminal liability for any monitoring or sharing of user activity—as long as it is done in ‘good faith.’ Specifically, CISPA authorizes companies to “use cybersecurity systems to identify and obtain cyber threat information.” Aggrieved users who sue Internet companies for wrongfully handing over their data to the government will have to meet the incredibly high bar of proving the decision comprised ‘willful misconduct.’ 
The U.S. cybersecurity strategy will also permit Internet companies to employ dubiously defined ‘countermeasures,’ provided they are justified with equally vague and undefined ‘defensive intent.’ Internet companies will be permitted to deploy ‘cybersecurity systems’ – products designed to ‘safeguard...a network from efforts to degrade, disrupt, or destroy’. While it is unclear exactly what this would permit an Internet company to do, it could allow blocking of specific websites or individuals or even a much broader range of filtering. 
Given the potentially all-encompassing and inclusive definition of ‘cybersecurity’, it would not be surprising if these ‘countermeasures’ were ultimately used to block online entities such as Wikileaks or sites accused of copyright infringement. The inclusion of ‘degrade’ in the definition of permissible ‘cybersecurity systems’ could even raise net neutrality concerns, as ISPs have, in the past, claimed ‘network degradation’ as justification for the throttling of downstream services such as peer-to-peer applications. Indeed, U.S. cybersecurity laws have a history of being employed by private Internet companies to stifle downstream competition. 
In sum, the U.S. cybersecurity strategy envisions a voluntary cooperative regime where Internet companies are given broad-ranging immunities to surveil Internet users and downstream online services. This amounts to an erosion of personal privacy safeguards currently in place. Under this regime, an online company need only to assert a vague ‘cybersecurity objective’ and it will have carte blanche to bypass domestic laws and protections against privacy invasion.

Monday, April 16, 2012

The NSA Wants Even More Power


DownsizeDC.org
April 16, 2012
by James Wilson

 "The NSA has been lobbying for a bigger role in the cybersecurity operations of private networks for some time, including more access to private communications." - Leslie Harris, Center for Democracy & Technology  

Two competing "cybersecurity" bills will be considered in the House the week of April 23.
Is Congress about to authorize private companies to share your personal information to the National Security Agency (NSA)?  

As this highly-recommended article by James Bamford shows, the NSA is already spending billions on supercomputers in order to unconstitutionally collect and permanently store your personal data. 

Should the NSA be further empowered? Or should it be stopped?

I sent the following letter to STOP the NSA using DownsizeDC.org's Hands Off the Internet Campaign, and I urge you to do the same

The hard-wired message says...
As a constituent, I insist that you oppose any attempts to undermine Internet freedom.
You may borrow from or copy these additional comments...
That is why I'm opposed to the Rogers bill (HR 3523) and the Lungren bill (HR 3674).
"Cybersecurity" is the new "terrorism." It's a made-up scare-word. It benefits those who seek federal power. It favors crony contractors. It does so at the expense of my privacy. It pretends I'll be safer if the internet is less free. 
  • Jim Dempsey, of the Center for Democracy and Technology, calls these bills a "classic case of overreach."... (http://bit.ly/I31te2)
  • Victims of cyber-attacks are already permitted to share information with The State, just as they are permitted to report crimes in the real world. 
  • We may need a tweak in current law that allows service providers to share information about _attacks_ with one another. But both bills go farther than a tweak. And the Rogers bill is FAR worse than the Lungren bill. Lungren has limits on the sharing of cybersecurity information. But the Rogers bill... (http://abcn.ws/HyRizc)
  • Contains vague language that could hand sweeping powers to agencies like the National Security Agency (NSA). For example, they could create "backdoor wiretaps." 
  • Creates a sweeping "cybersecurity exception" to every single federal and state law, including key privacy laws. 
  • Offers a very broad, almost unlimited definition of the information that can be shared with government agencies. 
  • Allows private companies to share your private communications with each other and with all other agencies of the federal government. In a cyber-crisis, warrants and prior disclosure to customers would be unnecessary.  
  • Gives blanket immunity to companies for cooperating with The State, thereby increasing the INCENTIVE to do so.   
  • Authorizes any collected personal data to be used to prosecute ANY crime, not just cybersecurity crimes. Be careful what you write in email!. As James Bamford has reported, the NSA already has too much power. This agency is creating a Big Brother system of surveillance, called Stellar Wind. (http://www.wired.com/threatlevel/2012/03/ff_nsadatacenter/all/1) 
  • The NSA is currently constructing a $2 billion "data collection" facility in Utah. 
  • In its "near-bottomless databases will be all forms of communication, including the complete contents of private emails, cell phone calls, and Google searches." 
  • It will have the most powerful hacking system in the world for financial information, stock transactions, business deals, foreign military and diplomatic secrets, legal documents, and confidential personal communications, including ALL of my emails and phone calls. Do you seriously want to give the NSA even GREATER ability to collect our data?

Wednesday, April 4, 2012

Even worse than SOPA: New CISPA cybersecurity bill will censor the Web

Published: 04 April, 2012 - RT
An onrush of condemnation and criticism kept the SOPA and PIPA acts from passing earlier this year, but US lawmakers have already authored another authoritarian bill that could give them free reign to creep the Web in the name of cybersecurity.

As congressmen in Washington consider how to handle the ongoing issue of cyberattacks, some legislators have lent their support to a new act that, if passed, would let the government pry into the personal correspondence of anyone of their choosing.

H.R. 3523, a piece of legislation dubbed the Cyber Intelligence Sharing and Protection Act (or CISPA for short), has been created under the guise of being a necessary implement in America’s war against cyberattacks. But the vague verbiage contained within the pages of the paper could allow Congress to circumvent existing exemptions to online privacy laws and essentially monitor, censor and stop any online communication that it considers disruptive to the government or private parties. Critics have already come after CISPA for the capabilities that it will give to seemingly any federal entity that claims it is threatened by online interactions, but unlike the Stop Online Privacy Act and the Protect IP Acts that were discarded on the Capitol Building floor after incredibly successful online campaigns to crush them, widespread recognition of what the latest would-be law will do has yet to surface to the same degree.

Kendall Burman of the Center for Democracy and Technology tells RT that Congress is currently considering a number of cybersecurity bills that could eventually be voted into law, but for the group that largely advocates an open Internet, she warns that provisions within CISPA are reason to worry over what the realities could be if it ends up on the desk of President Barack Obama. So far CISPA has been introduced, referred and reported by the House Permanent Select Committee on Intelligence and expects to go before a vote in the first half of Congress within the coming weeks.

“We have a number of concerns with something like this bill that creates sort of a vast hole in the privacy law to allow government to receive these kinds of information,” explains Burman, who acknowledges that the bill, as written, allows the US government to involve itself into any online correspondence, current exemptions notwithstanding, if it believes there is reason to suspect cyber crime. As with other authoritarian attempts at censorship that have come through Congress in recent times, of course, the wording within the CISPA allows for the government to interpret the law in such a number of degrees that any online communication or interaction could be suspect and thus unknowingly monitored.

In a press release penned last month by the CDT, the group warned then that CISPA allows Internet Service Providers to “funnel private communications and related information back to the government without adequate privacy protections and controls.

The bill does not specify which agencies ISPs could disclose customer data to, but the structure and incentives in the bill raise a very real possibility that the National Security Agency or the DOD’s Cybercommand would be the primary recipient,” reads the warning.

The Electronic Frontier Foundation, another online advocacy group, has also sharply condemned CISPA for what it means for the future of the Internet. “It effectively creates a ‘cybersecurity'’ exemption to all existing laws,” explains the EFF, who add in a statement of their own that “There are almost no restrictions on what can be collected and how it can be used, provided a company can claim it was motivated by ‘cybersecurity purposes.’”

What does that mean? Both the EFF and CDT say an awfully lot. Some of the biggest corporations in the country, including service providers such as Google, Facebook, Twitter or AT&T, could copy confidential information and send them off to the Pentagon if pressured, as long as the government believes they have reason to suspect wrongdoing. In a summation of their own, the Congressional Research Service, a nonpartisan arm of the Library of Congress, explains that “efforts to degrade, disrupt or destroy” either “a system or network of a government or private entity” is reason enough for Washington to reach in and read any online communiqué of their choice.

The authors of CISPA say the bill has been made “To provide for the sharing of certain cyber threat intelligence and cyber threat information between the intelligence community and cybersecurity entities,” but not before noting that the legislation could be used “and for other purposes,” as well — which, of course, are not defined.

“Cyber security, when done right and done narrowly, could benefit everyone,” Burman tells RT. “But it needs to be done in an incremental way with an arrow approach, and the heavy hand that lawmakers are taking with these current bills . . . it brings real serious concerns.”

So far CISPA has garnered support from over 100 representatives in the House who are favoring this cybersecurity legislation without taking into considerations what it could do to the everyday user of the Internet. And while the backlash created by opponents of SOPA and PIPA has not materialized to the same degree yet, Burman warns Congress that it could be only a matter of time before concerned Americans step up to have their say.

“One of the lessons we learned in the reaction to SOPA and PIPA is that when Congress tries to legislate on things that are going to affect Internet users’ experience, the Internet users are going to pay attention,” says Burman. H.R. 3523, she cautions, “Definitely could affect in a very serious way the internet experience.” Luckily, adds Burman, “People are starting to notice.” Given the speed that the latest censorship bill could sneak through Congress, however, anyone concerned over the future of the Internet should be on the lookout for CISPA as it continues to be considered on Capitol Hill.

Sunday, March 11, 2012

Bill would create partnership between NSA and U.S. corporations

By Stephen C. Webster - RAW Story
Wednesday, March 7, 2012

Speaking at a policy debate Wednesday at The Heritage Foundation, a representative of the American Civil Liberties Union (ACLU) warned that a bill currently being considered by the House Select Committee on Intelligence would intertwine the National Security Agency (NSA) with corporate America, exposing vast amounts of private civilian data to unprecedented levels of monitoring, all in the name of “cybersecurity.”

H.R. 3523, introduced last year by Rep. Mike Rogers (R-MI), purports to help safeguard American corporations from espionage and cyber crime by allowing the NSA and other federal spy agencies to work directly with large corporate players, funneling them classified information on threat assessments to enable companies to defend themselves.

While the bill is openly supported by companies like AT&T, Lockheed Martin, Microsoft, Facebook, Boeing and Intel, ACLU legislative counsel Michelle Richardson cautioned Wednesday that it is not something to be taken up lightly.

“[The Rogers bill] will encourage companies to share personal and private data with the government,” she said. “And then with very little oversight, allow the information to be used in a number of different ways.”

“If you put the government int he middle of an information sharing scheme, it is absolutely critical that you clarify that it must be run by a civilian agency,” Richardson added. “One of our biggest criticisms of the Rogers bill is that they either explicitly say information should go to the National Security Agency and Cyber Command, or they’re otherwise silent and allow companies to choose where they want to send information, including to these different military facilities.”

Rogers contended that the NSA is full of “brilliant” people who “spend their day trying to figure out what the bad guys are doing to people, and what potential bad things are out there that we ought to be looking for.”

“Imagine how much stronger [U.S. corporations] would be if we let them know what the enemies are up to, and allowed them to see it in a very classified way, so that they can apply that knowledge to their networks and protect that network,” he added.

While it may sound good to some, Richardson countered that Rogers’ plan breaks with American tradition by explicitly using a military organization for domestic purposes.

“It’s a longstanding American value that the military does not operate on U.S. soil, and that’s what we’re really talking about here with these cyber security programs: domestic, civilian Internet use,” she said. “It is wholly inappropriate to have the military at the center of receiving, processing and distributing that information.”

Richardson also stressed that should Congress commit to using the government as an information sharing apparatus for corporate America, it must very narrowly define how information is shared and limit exceptions to privacy laws to extraordinary circumstances only.

The ACLU also recommended in a letter published in December that Congress take special care to require that all personally identifiable information be removed from information shared with its cyber command, to protect against the potential for abuse. They also asked for an oversight structure that produces regular public reports on the program.

“We’re very happy to see that the Obama Administration agrees, and they’ve spent the last several years making sure that these sorts of civilian domestic cyber security operations are going through [the Department of Homeland Security] and not the NSA,” Richardson said.

Saturday, February 19, 2011

Internet 'kill switch' bill gets a makeover

February 18, 2011 by Declan McCullagh, CNET

A Senate proposal that has become known as the Internet "kill switch" bill was reintroduced this week, with a tweak its backers say eliminates the possibility of an Egypt-style disconnection happening in the United States.

As CNET reported last month, the 221-page bill hands Homeland Security the power to issue decrees to certain privately owned computer systems after the president declares a "national cyberemergency." A section in the new bill notes that does not include "the authority to shut down the Internet," and the name of the bill has been changed to include the phrase "Internet freedom."

"The emergency measures in our bill apply in a precise and targeted way only to our most critical infrastructure," Sen. Susan Collins (R-Maine) said yesterday about the legislation she is sponsoring with Sen. Joe Lieberman (I-Conn). "We cannot afford to wait for a cyber 9/11 before our government finally realizes the importance of protecting our digital resources."

But the revised wording (PDF) continues to alarm civil liberties groups and other critics of the bill, who say the language would allow the government to shut down portions of the Internet or restrict access to certain Web sites or types of content. Even former Egyptian President Hosni Mubarak didn't actually "shut down" the Internet: at least at first, a trickle of connections continued.

"It still gives the president incredible authority to interfere with Internet communications," ACLU legislative counsel Michelle Richardson said today. If the Department of Homeland Security wants to pull the plug on Web sites or networks, she said, "the government needs to go to court and get a court order."

That concern was punctuated by a report yesterday that Homeland Security erroneously seized 84,000 Web domains and took them offline. Former congressman Bob Barr, now an NRA board member and newspaper columnist, wrote that the mistake shows that "no government--no matter how benign or well-meaning--should be empowered to control the Internet."

The Electronic Frontier Foundation said today that it continues to have concerns about the Lieberman-Collins bill. "The president would have essentially unchecked power to determine what services can be connected to the Internet or even what content can pass over the Internet in a cybersecurity emergency," said EFF Senior Staff Attorney Kevin Bankston. "Our concerns have not changed."

Some of the companies and industry groups listed as supporting last June's version of the bill, before the protests in Egypt, the FBI's push on Internet wiretapping, and the Justice Department's campaign for Internet data retention, stopped short of endorsing the revised version.

Larry Clinton, president of the Internet Security Alliance, pointed to his letter to the Senate committee last year saying the legislation "is in need of additional refinement." Clinton said in an e-mail today that "much more needed to be done before we could support enactment."
Microsoft said it did not have a position on the legislation. "The bill language just came out, and so we really need to review it before we can provide further comment," a representative said today.

From "Protecting Cyberspace" to "Internet Freedom"

Many portions of the revised bill, also sponsored by Sen. Tom Carper (D-Del.), are generally uncontroversial, dealing with topics such as boosting the federal government's information security, recruiting federal "cybersecurity personnel," and funding research into secure versions of Internet protocols. (The bill previously was called the Protecting Cyberspace as a National Asset Act; as part of its makeover it's been renamed the "Cybersecurity and Internet Freedom Act.")

But all of the recent attention has been focused on the sections handing the president emergency powers. The new version follows the same process as the old one: President Obama would be given the power to "issue a declaration of a national cyberemergency." Once that happens, Homeland Security would receive sweeping new authorities, including the power to require that so-called critical companies "shall immediately comply with any emergency measure or action" decreed.

No "notice" needs to be given "before mandating any emergency measure or actions." That means a company could be added to the "critical" infrastructure list one moment, and ordered by Homeland Security to "immediately comply" with its directives the next.

The U.S. Senate's Homeland Security and Governmental Affairs Committee, which Lieberman chairs, appears to believe that it's not necessary to include explicit judicial review of the president's emergency authority once exercised, believing it's implicit. Any such lawsuit filed by a targeted company would likely focus on language saying the emergency decrees should be "the least disruptive means feasible."

The president may declare a "cyberemergency" for 30 days, and extend it for one 30-day period, unless Congress votes to approve further extensions.

Homeland Security will "establish and maintain a list of systems or assets that constitute covered critical infrastructure" and that will be subject to those emergency decrees.

Homeland Security is only supposed to place a computer system (which could include a server, Web site, router, and so on) on the list if certain requirements are met. First, the disruption of the system could cause "severe economic consequences" or worse. Second, the system is "a component of the national information infrastructure," such as the Internet, or relies on that infrastructure. Third, it can't be placed on the list "based solely" on any First Amendment-protected activities.

A committee report from December says that senators hope that Homeland Security will interpret that language to include a "combination" of factors, including mass casualties or evacuations, over $25 billion in damages, or "severe degradation" of national security. The suggestion, however, appears to be nonbinding and doesn't actually appear in the legislation.
One big change: Earlier versions of the bill barred companies from filing a lawsuit objecting to being placed on that list. The revised version explicitly permits judicial review as long as the lawsuit is filed in the District of Columbia.

"A state of public peril"

A 1934 law (PDF) creating the Federal Communications Commission says that in wartime, or if a "state of public peril or disaster or other national emergency" exists, the president may "authorize the use or control of any...station or device." That could sweep in the Internet, but it's not entirely clear it does. (The revised bill says that existing authority may not be used to "shut down the Internet," but does not otherwise limit it.)

In congressional testimony (PDF) last year, the Obama administration stopped short of endorsing the Lieberman-Collins bill. The 1934 law already addresses "presidential emergency authorities, and Congress and the administration should work together to identify any needed adjustments to the act," DHS Deputy Undersecretary Philip Reitinger said, "as opposed to developing overlapping legislation."

A draft Senate proposal that CNET obtained in August 2009 authorized the White House to "declare a cybersecurity emergency," and another from Sens. Jay Rockefeller (D-W.Va.) and Olympia Snowe (R-Maine) would have explicitly given the government the power to "order the disconnection" of certain networks or Web sites. House Democrats have taken a similar approach.

In a statement, Lieberman said there's no "kill switch" in this bill.

"It is impossible to turn off the Internet in this country," he said. "This legislation applies to the most critical infrastructures that Americans rely on in their daily lives--energy transmission, water supply, financial services, for example--to ensure that those assets are protected in case of a potentially crippling cyberattack."

The ACLU's Richardson believes the problem was never a "kill switch." She said: "The question is bigger than that. It's generally, can the government interfere with communications...The question is: Are there significant protections in there?"

Jim Harper, director of information policy studies at the free-market Cato Institute and a member of a Homeland Security advisory panel, says that supporters of the bill have yet to make the argument that such governmental emergency powers will do more good than harm.

"They recognize that a total Internet kill switch is totally unacceptable," Harper said today. "A smaller Internet kill switch, or a series of kill switches, is also unacceptable...How does this make cybersecurity better? They have no answer."

Monday, January 10, 2011

Unique internet ID for all Americans coming--Big Brother will be watching you and know who you are

(The Obama Administration--to whom many bad bad ideas have already been attached--has come up with another incredibly bad idea and way to violate our rights to anonymity. This is another thing Bush would have loved to do that the fake liberal Obama will do. Hope and change feel just as bad as the despair and angst we've felt since 2000. Obama is the antithesis of everything he "stood" for during his campaign, making those who voted for him feel like suckers. Thanks to Matt S. for the share.--jef)


***

Obama administration moves forward with unique internet ID for all Americans, Commerce Department to head system up
By Laura June posted Jan 9th 2011

President Obama has signaled that he will give the United States Commerce Department the authority over a proposed national cybersecurity measure that would involve giving each American a unique online identity. Other candidates mentioned previously to head up the new system have included the NSA and the Department of Homeland Security, but the announcement that the Commerce Department will take the job should please groups that have raised concerns over security agencies doing double duty in police and intelligence work. So anyway, what about this unique ID we'll all be getting? Well, though details are still pretty scant, U.S. Commerce Secretary Gary Locke, speaking at an event at the Stanford Institute, stressed that the new system would not be akin to a national ID card, or a government controlled system, but that it would enhance security and reduce the need for people to memorize dozens of passwords online. Sorry, Locke, sounds like a national ID system to us. Anyway, the Obama administration is currently drafting what it's dubbed the National Strategy for Trusted Identities in Cyberspace, which is expected at the Department of Commerce in a few months. We'll keep you posted if anything terrifying or cool happens.--CBS News

Tuesday, June 29, 2010

White House cybersecurity policy to require web users to use identity tokens

US outlines online security strategy
By Joseph Menn in San Francisco
June 26 2010 00:39

The White House set out a sweeping strategy to make online transactions more secure on Friday. The move is the most ambitious initiative to emerge from a cybersecurity policy intended to blunt the growing menace of online crime.

Howard Schmidt, president Barack Obama’s cybersecurity co-ordinator, who took up his duties in early 2010, released the strategy paper after 12 months of discussions led by the National Security Council and involving scores of private sector groups, critical infrastructure owners and privacy advocates.

The strategy seeks the creation of a system for identity management that would allow citizens to use additional authentication techniques, such as physical tokens or modules on mobile phones, to verify who they are before buying things online or accessing such sensitive information as health or banking records.

A set of standards would let multiple vendors offer authentication services, while people whose identities have been verified would be able to move from website to website without resubmitting information.

Privacy protections would require companies involved to limit their collection and dissemination of personal data, for example confirming that a consumer is over 21 without passing along the person’s birth date.

The government would take the lead by establishing the standards and subscribing to authentication services.

Internet companies and government agencies have long supported the idea of multipurpose identification systems, but adoption has foundered in part because of limited incentives for participation. As a result, a bank will have one set of protocols for establishing a client’s identity, while a state agency and hospital have others.

The matter has taken on increased urgency as more valuable data pours online and malicious software grows more sophisticated. Industry estimates for the theft of intellectual property and online fraud run as high as $1,000bn annually.

Congressional and private sector support will be critical for the new effort.

“This is a vision and you need that, but they’re going to need to work with Congress and get government agencies to test out different pieces of this,” said Aris Schwartz, vice-president of the Center for Democracy and Technology. Congress would need to fund test programmes and, perhaps, approve tax incentives.

It has been hard to formulate legislation because internet security issues intrude into so many political areas. But Harry Reid, Senate majority leader, recently urged committee chairmen to harmonise pending bills for cybersecurity overhauls, making it likely new laws will emerge from Congress this year.

Thursday, March 4, 2010

Cyber Security Act

Feds weigh expansion of Internet monitoring
by Declan McCullagh

SAN FRANCISCO--Homeland Security and the National Security Agency may be taking a closer look at Internet communications in the future.

The Department of Homeland Security's top cybersecurity official told CNET on Wednesday that the department may eventually extend its Einstein technology, which is designed to detect and prevent electronic attacks, to networks operated by the private sector. The technology was created for federal networks.

Greg Schaffer, assistant secretary for cybersecurity and communications, said in an interview that the department is evaluating whether Einstein "makes sense for expansion to critical infrastructure spaces" over time.

Not much is known about how Einstein works, and the House Intelligence Committee once charged that descriptions were overly "vague" because of "excessive classification." The White House did confirm this week that the latest version, called Einstein 3, involves attempting to thwart in-progress cyberattacks by sharing information with the National Security Agency.

Greater federal involvement in privately operated networks may spark privacy or surveillance concerns, not least because of the NSA's central involvement in the Bush administration's warrantless wiretapping scandal. Earlier reports have said that Einstein 3 has the ability to read the content of emails and other messages, and that AT&T has been asked to test the system.

(The Obama administration says the "contents" of communications are not shared with the NSA.)

"I don't think you have to be Big Brother in order to provide a level of protection either for federal government systems or otherwise," Schaffer said. "As a practical matter, you're looking at data that's relevant to malicious activity, and that's the data that you're focused on. It's not necessary to go into a space where someone will say you're acting like Big Brother. It can be done without crossing over into a space that's problematic from a privacy perspective."

If Einstein 3 does perform as well as Homeland Security hopes, it could help less-prepared companies fend off cyberattacks, including worms sent through e-mail, phishing attempts, and even denial of service attacks.

On the other hand, civil libertarians are sure to raise questions about privacy, access, and how Einstein could be used in the future. If it can perform deep packet inspection to prevent botnets from accessing certain Web pages, for instance, could it also be used to prevent a human from accessing illegal pornography, copyright-infringing music, or offshore gambling sites?

"It's one thing for the government to monitor its own systems for malicious code and intrusions," said Greg Nojeim, senior counsel at the Center for Democracy and Technology. "It's quite another for the government to monitor private networks for those intrusions. We'd be concerned about any notion that a governmental monitoring system like Einstein would be extended to private networks."

AT&T did not respond to a request for comment on Wednesday.

Cooperation, or a loss of control?

At the RSA Conference here on Wednesday, Homeland Security Secretary Janet Napolitano stressed the need for more cooperation between the government and the private sector on cybersecurity, saying that "we need to have a system that works together."

During a House appropriations hearing on February 26, Napolitano refused to discuss Einstein 3 unless the hearing were closed to the public. "I don't want to comment publicly on Einstein 3, per se, here in an unclassified setting," she said. "What I would suggest, perhaps, is a classified briefing for members of the subcommittee who are interested."

Some privacy concerns about Einstein have popped up before. An American Bar Association panel said this about Einstein 3 in a September 2009 report: "Because government communications are commingled with the private communications of non-governmental actors who use the same system, great caution will be necessary to insure that privacy and civil liberties concerns are adequately considered."

Jacob Appelbaum, a security researcher and programmer for the Tor anonymity project, said that expanding Einstein 3 to the private sector would amount to a partial outsourcing of security. "It's clearly a win for people without the security know-how to protect their own networks," Appelbaum said. "It's also a clear loss of control. And anyone with access to that monitoring system, legitimate or otherwise, would be able to monitor amazing amounts of traffic."
Einstein grew out of a still-classified executive order, called National Security Presidential Directive 54, that President Bush signed in 2008.

While little information is available, former Homeland Security Secretary Michael Chertoff once likened it to a new "Manhattan Project," and the Washington Post reported that the accompanying cybersecurity initiative represented the "single largest request for funds" in last year's classified intelligence budget. The Electronic Privacy Information Center has filed a lawsuit (PDF) to obtain the text of the order.

Homeland Security has published (PDF) a privacy impact assessment for a less capable system called Einstein 2--which aimed to do intrusion detection and not prevention--but has not done so for Einstein 3.

The department did, however, prepare a general set of guidelines (PDF) for privacy and civil liberties in June 2009. In addition, the Bush Justice Department wrote a memo (PDF) saying Einstein 2 "complies with" the U.S. Constitution and federal wiretap laws.
That justification for Einstein 2 "turned on the consent of employees in the government that are being communicated with, and on the notion that a person who communicates with the government can't then complain that the government read the communication," said CDT's Nojeim. "How does that legal justification work should Einstein be extended to the private sector?"

********

A New Age for US Cybersecurity
By Richard Adhikari
TechNewsWorld
03/03/10 9:53 AM PT

U.S. cybersecurity efforts must be multifaceted, emphasized White House Cybersecurity Coordinator Howard Schmidt in a speech at RSA 2010 on Tuesday. "In order to be successful against today's cybersecurity threats, we need to seek out new and innovative partnerships -- not only between business and government, but also academia."

In the wake of repeated warnings by former top-level government cybersecurity experts that the United States is ill-prepared for a cyberwar, White House Cybersecurity Coordinator Howard Schmidt disclosed Tuesday the Obama administration's plans to prepare for the cybersecurity needs of the future.

The administration is taking a multifaceted approach to cybersecurity, Schmidt said at the RSA Conference 2010 in San Francisco.

"Security is not a binary thing we do -- our cybersecurity policies have to be well aligned, so we're looking at digital networks to make sure they're resilient and robust," he said. "We also need to reach out; we don't want to do things that hamper innovation."

Part of reaching out is working with the National Economic Council, Schmidt said. Another part is having the national security staff, which consists of representatives from various government agencies and departments, pull together a holistic picture of how the economy and cybersecurity are intertwined.

A 360-Degree View

Schmidt also spoke about the Cybersecurity Policy Review commissioned by President Obama, which calls for changes in the United States' approach to cybersecurity.

The U.S. needs to have a handle on the ever-changing state of cybersecurity, he said. It also needs to look at its cybersecurity policies in terms of current requirements and make sure they are updated as needed.

In order to achieve these goals, the national security staff keeps President Obama and his key advisers informed about the comprehensive picture it puts together of cybersecurity and the economy, Schmidt said.

That support at the highest levels is critical.

"One of the key issues of governance is you have to have leadership from the top," Schmidt said. "Many of us have spent our careers pushing upwards from the bottom, and market prices and other factors have been an impediment in the past. They're no longer an impediment."

The Cybersecurity Policy Review also calls for addressing international cooperation in the cybersecurity field, developing an instant response plan for cyberemergencies, and transparency in government.

Our Overseas Friends

One of the worst problems cybersecurity professionals face is that they're restricted by regional, local and national boundaries, while cybercriminals are not.

Local, state and federal law enforcement agencies in the U.S. don't cooperate much, and cooperation with international law enforcement is even worse. Meanwhile, cybercriminals operate in gangs that cross national borders, making it difficult to arrest and prosecute them.

In some countries, well-connected cybercriminals are protected by their national governments.

The National Cybersecurity Policy seeks to address these problems.

"We'll start looking at international cybersecurity policy," Schmidt said. "We need to make sure our policy and framework are addressing the international field."

Who're You Gonna Call?

The Cybersecurity Policy Review also calls for the establishment of an instant response plan.

"There should never be a question as to where the private sector needs to go during an incident," Schmidt explained. "There should never be a question about whether the private sector needs to coordinate what needs to be done. The Department of Homeland Security is doing a great job of pulling this together."

An instant response plan is critical. The U.S. is the most vulnerable country in a cyberwar because it's the most connected, Mitch McConnell, former director of national intelligence, has testified before the Senate.

Both McConnell and current Director of National Intelligence Dennis Blair are among the cybersecurity experts who have testified before Congress about the need for stronger cooperation between the private and public sectors on security.

Peekaboo! I See You!

Private-public sector cooperation alone is not enough; the American people also have to be involved, Schmidt said.

"In order to be successful against today's cybersecurity threats, we need to seek out new and innovative partnerships -- not only between business and government, but also academia," he explained.

In order for that to happen, government needs greater transparency.

"Transparency and partnerships are concepts that have to go hand in hand," said Schmidt. "We can't ask industry to help government, or government to step in, unless we have transparency."

In line with that policy of transparency, the government on Tuesday declassified part of its Comprehensive National Cybersecurity Initiative (CNCI), publishing details of the US$40 billion cybersecurity plan on the Internet Tuesday, Schmidt announced.

Transparency has been a key requirement of the Obama administration all along, Schmidt said. "The foundation aspects of the government's cybersecurity policy are transparency and accountability."

******

Sens. Push for Government Cybersecurity Authority
By Kenneth Corbin
February 24, 2010

WASHINGTON -- The senators backing sweeping and controversial legislation to overhaul U.S. cybersecurity policy pressed their cause Tuesday, signaling in a hearing that they have no intention of backing down from a dramatic expansion of executive authority to respond to an attack on the nation's digital infrastructure.

"This hearing is a next step in examining the important action we should be taking, right now -- as a government and as a national economy -- to harden our defenses and safeguard critical infrastructure against a major cyber attack," said Commerce Committee Chairman John Rockefeller (D-WV).

Rockefeller, along with Olympia Snowe (R-ME), jointly introduced the Cybersecurity Act of 2009 last April, legislation that drew immediate protests from groups that warned against provisions in the bill that could supersede privacy laws in the event of a cyber attack and give the president authority to take temporary control over private networks.

But Rockefeller and Snowe Tuesday indicated that they remain committed to the executive authority provisions in the bill, which they hope to push through the senate this year.

"We've got to give the president the right to intervene," Rockefeller said. "That's controversial. That'll always be controversial."

The senators said that they and their staffers had held more than a hundred meetings with members of the private sector and other stakeholders and that the bill has been substantially revised at least four times.

Cyber security warnings
At Tuesday's hearing, the witnesses offered dire warnings about the vulnerabilities of U.S. digital networks, which are largely owned and operated by firms in the private sector.

"If the nation went to war today in a cyber war, we would lose," said retired Adm. Michael McConnell, the former director of the National Security Agency who currently serves as executive vice president of Booz Allen Hamilton's National Security Business. "We're the most vulnerable. We're the most connected. We've got the most to lose."

McConnell praised the Rockefeller-Snowe bill as a good first step, but in his dark view, policymakers won't be spurred to take the dramatic action he sees necessary until the nation is hit with a crippling attack.

"We will not mitigate this risk," he said. "As a consequence of not mitigating this risk, we're going to have a catastrophic event."

Cyber attack response
The expanded government role in cybersecurity is at the heart of the Rockefeller-Snowe bill, which would elevate the cyber coordinator position President Obama created last year to Cabinet-level status, reporting directly to the president and requiring confirmation by the senate.

Snowe also suggested that the government could take steps toward establishing more rigid standards, such as shielding companies that adhered to baseline security standards from liability in the event of an attack.

She also called for government agencies to make security a higher priority when making procurement decisions, using the considerable federal purchasing power to move the market toward more secure systems.

But the bill comes out of a concern that the stakes are too high to allow market forces to set the standard for cybersecurity.

"Since this is a network and everything is interconnected, if 10 percent don't do the right thing then 100 percent would be vulnerable," said James Lewis, director of the Technology and Public Policy Program at the Center for Strategic and International Studies, the group that delivered a cybersecurity report to then-President-elect Obama in December 2008. The Rockefeller-Snowe bill draws extensively from the CSIS report.

Considerable opposition
Not surprisingly, the prospect of increased government role in private networks has stoked considerable opposition to the proposed legislation.

"Companies tended to resist the idea of the government sort of getting in the way of what they were already doing, which they felt to be adequate," Rockefeller said of his meetings with industry representatives.

Some of that opposition was on display today, with Mary Ann Davidson, Oracle's chief security officer, telling the panel that the real shortfall is in the university system, where security is given short shrift in computer science programs.

"We have to train all computer science graduates in how to write secure code because they weren't taught this in universities," Davidson said.

She suggested that the government slow the push to move critical systems like the electrical grid to IP-enabled networks before implementing standards to secure the millions of devices that would be operating as clients.

In the area of standards, she suggested that a government agency, such as the National Institute of Standards and Technology could take the lead. Similarly, she urged the senators to focus their attention on the transparency of software development, noting that organizations commonly purchase and deploy software today with little -- if any -- insight into the development process, including the ability to withstand an attack.

In addition to setting standards, she suggested that the government's role would properly be limited to using its purchasing power to nudge the market toward higher security and transparency standards.

*********

The ‘war on cyber terrorism’
February 27, 2010 at 11:04 pm


Until now, the Internet has been a mostly unregulated, user-created technology; giving rise to an unprecedented expansion of free speech. However, that may soon be changing.

According to a Washington Post article on Wednesday, the federal government is looking for ways to regulate both federal and private industry in an effort to increase cyber security.

Senators Jay Rockefeller (D-W.Va.) and Olympia Snowe (R-Maine) are drafting legislation to protect the nation from a massive cyber security attack. Rockefeller described such an attack as an “enormous threat” and justified the controversial legislation.

“Too much is at stake for us to pretend that today’s outdated cybersecurity policies are up to the task of protecting our nation and economic infrastructure,” Rockefeller said. “We have to do better and that means it will take a level of coordination and sophistication to outmatch our adversaries.”

According to an article in The Hill, the power to regulate and, if need be, control the Internet would be vested in one man, the President of the United States:

“The president would then have the ability to initiate those network contingency plans to ensure key federal or private services did not go offline during a cyberattack of unprecedented scope”

The threat posed by cyber attacks is real. Google recently fell victim to an attack it claims originated in China. Even the Joplin Globe blogs, including Redheaded Politics, were shut down in January 2009 by hackers opposed to U.S. and Israeli policy in Gaza.

But the threat of giving the executive branch sweeping powers of regulation and “protection” in case of a national emergency are far more unsettling. If the federal government wishes to increase the security of its own networks let it do so. The ramifications of it controlling and monitoring the private sector, aka me and you, could be dreadful.