Showing posts with label internet kill switch. Show all posts
Showing posts with label internet kill switch. Show all posts

Saturday, July 14, 2012

White House gives Homeland Security control of all communication systems

RT - Published: 13 July, 2012

The White House has finally responded to criticism over US President Barack Obama’s hushed signing last week of an Executive Order that allows the government to command privately-owned communication systems and acknowledges its implications.

When President Obama inked his name to the Assignment of National Security and Emergency Preparedness Communications Functions Executive Order on July 6, he authorized the US Department of Homeland Security to take control of the country’s wired and wireless communications — including the Internet — in instances of emergency. The signing was accompanied with little to no acknowledgment outside of the White House, but initial reports on the order quickly caused the public to speak out over what some equated to creating an Oval Office kill switch for the Web. Now the Obama administration is addressing those complaints by calling the Executive Order a necessary implement for America’s national security.

“The [order] recognizes the creation of DHS and provides the Secretary the flexibility to organize the communications systems and functions that reside within the department as [Homeland Security Secretary Janet A. Napolitano] believes will be most effective,” White House spokeswoman Caitlin Hayden tells the Washington Post. 

Hayden insists that “The [order] does not transfer authorities between or among departments,” but the order does indeed allow the DHS to establish and implement control over even the privately owned communication systems in the country, including Internet Service Providers such as Time Warner, Verizon and Comcast, if the administration agrees that it is warranted for security’s sake.

Immediately after last week’s signing, the Electronic Privacy Information Center (EPIC) said the order allowed the DHS "the authority to seize private facilities when necessary, effectively shutting down or limiting civilian communications." 

Following up with the Post this week, EPIC attorney Amie Stephanovich stands by that initial explanation, agreeing that the DHS can now “seize control of telecommunications facilities, including telephone, cellular and wireless networks, in order to prioritize government communications over private ones in an emergency.”

“The previous orders did not give DHS those authorities over private and commercial networks,” adds. Stepanovich. “That’s a new authority.”

According to the order, the DHS can take charge of “commercial, government, and privately owned communications resources” to satisfy what is described as “priority communication requirements.” With little insight from outside the White House, though, what constitutes such an emergency may very well be decided on by Washington, where the country’s elected leaders are still split on all things involving the Internet.

Even still, Stepanovich says that approaching Capitol Hill for comment before rushing through an Executive Order could have caused things to come out differently, but would have also arguably brought forth a firestorm such as the one that accompanied an attempt to pass the Stop Online Piracy Act. When Congress tried to pass SOPA this year — which included provisions that were argued to grossly regulate the Internet — protests nationwide played a massive part in killing the legislation.

“This should have been done by Congress, so there could have been proper debate about it,” Stepanovich tells the Post of last week’s signing. “This is not authority that should be granted by executive order.”

White House spokesperson Hayden adds to the Post, “Mobile phones, the Internet, and social media are all now integral to the communications landscape,” concreting still the allegations that this order could be used as a kill switch to any of the millions upon millions of handheld and desktop devices across the country.

Saturday, February 19, 2011

Internet 'kill switch' bill gets a makeover

February 18, 2011 by Declan McCullagh, CNET

A Senate proposal that has become known as the Internet "kill switch" bill was reintroduced this week, with a tweak its backers say eliminates the possibility of an Egypt-style disconnection happening in the United States.

As CNET reported last month, the 221-page bill hands Homeland Security the power to issue decrees to certain privately owned computer systems after the president declares a "national cyberemergency." A section in the new bill notes that does not include "the authority to shut down the Internet," and the name of the bill has been changed to include the phrase "Internet freedom."

"The emergency measures in our bill apply in a precise and targeted way only to our most critical infrastructure," Sen. Susan Collins (R-Maine) said yesterday about the legislation she is sponsoring with Sen. Joe Lieberman (I-Conn). "We cannot afford to wait for a cyber 9/11 before our government finally realizes the importance of protecting our digital resources."

But the revised wording (PDF) continues to alarm civil liberties groups and other critics of the bill, who say the language would allow the government to shut down portions of the Internet or restrict access to certain Web sites or types of content. Even former Egyptian President Hosni Mubarak didn't actually "shut down" the Internet: at least at first, a trickle of connections continued.

"It still gives the president incredible authority to interfere with Internet communications," ACLU legislative counsel Michelle Richardson said today. If the Department of Homeland Security wants to pull the plug on Web sites or networks, she said, "the government needs to go to court and get a court order."

That concern was punctuated by a report yesterday that Homeland Security erroneously seized 84,000 Web domains and took them offline. Former congressman Bob Barr, now an NRA board member and newspaper columnist, wrote that the mistake shows that "no government--no matter how benign or well-meaning--should be empowered to control the Internet."

The Electronic Frontier Foundation said today that it continues to have concerns about the Lieberman-Collins bill. "The president would have essentially unchecked power to determine what services can be connected to the Internet or even what content can pass over the Internet in a cybersecurity emergency," said EFF Senior Staff Attorney Kevin Bankston. "Our concerns have not changed."

Some of the companies and industry groups listed as supporting last June's version of the bill, before the protests in Egypt, the FBI's push on Internet wiretapping, and the Justice Department's campaign for Internet data retention, stopped short of endorsing the revised version.

Larry Clinton, president of the Internet Security Alliance, pointed to his letter to the Senate committee last year saying the legislation "is in need of additional refinement." Clinton said in an e-mail today that "much more needed to be done before we could support enactment."
Microsoft said it did not have a position on the legislation. "The bill language just came out, and so we really need to review it before we can provide further comment," a representative said today.

From "Protecting Cyberspace" to "Internet Freedom"

Many portions of the revised bill, also sponsored by Sen. Tom Carper (D-Del.), are generally uncontroversial, dealing with topics such as boosting the federal government's information security, recruiting federal "cybersecurity personnel," and funding research into secure versions of Internet protocols. (The bill previously was called the Protecting Cyberspace as a National Asset Act; as part of its makeover it's been renamed the "Cybersecurity and Internet Freedom Act.")

But all of the recent attention has been focused on the sections handing the president emergency powers. The new version follows the same process as the old one: President Obama would be given the power to "issue a declaration of a national cyberemergency." Once that happens, Homeland Security would receive sweeping new authorities, including the power to require that so-called critical companies "shall immediately comply with any emergency measure or action" decreed.

No "notice" needs to be given "before mandating any emergency measure or actions." That means a company could be added to the "critical" infrastructure list one moment, and ordered by Homeland Security to "immediately comply" with its directives the next.

The U.S. Senate's Homeland Security and Governmental Affairs Committee, which Lieberman chairs, appears to believe that it's not necessary to include explicit judicial review of the president's emergency authority once exercised, believing it's implicit. Any such lawsuit filed by a targeted company would likely focus on language saying the emergency decrees should be "the least disruptive means feasible."

The president may declare a "cyberemergency" for 30 days, and extend it for one 30-day period, unless Congress votes to approve further extensions.

Homeland Security will "establish and maintain a list of systems or assets that constitute covered critical infrastructure" and that will be subject to those emergency decrees.

Homeland Security is only supposed to place a computer system (which could include a server, Web site, router, and so on) on the list if certain requirements are met. First, the disruption of the system could cause "severe economic consequences" or worse. Second, the system is "a component of the national information infrastructure," such as the Internet, or relies on that infrastructure. Third, it can't be placed on the list "based solely" on any First Amendment-protected activities.

A committee report from December says that senators hope that Homeland Security will interpret that language to include a "combination" of factors, including mass casualties or evacuations, over $25 billion in damages, or "severe degradation" of national security. The suggestion, however, appears to be nonbinding and doesn't actually appear in the legislation.
One big change: Earlier versions of the bill barred companies from filing a lawsuit objecting to being placed on that list. The revised version explicitly permits judicial review as long as the lawsuit is filed in the District of Columbia.

"A state of public peril"

A 1934 law (PDF) creating the Federal Communications Commission says that in wartime, or if a "state of public peril or disaster or other national emergency" exists, the president may "authorize the use or control of any...station or device." That could sweep in the Internet, but it's not entirely clear it does. (The revised bill says that existing authority may not be used to "shut down the Internet," but does not otherwise limit it.)

In congressional testimony (PDF) last year, the Obama administration stopped short of endorsing the Lieberman-Collins bill. The 1934 law already addresses "presidential emergency authorities, and Congress and the administration should work together to identify any needed adjustments to the act," DHS Deputy Undersecretary Philip Reitinger said, "as opposed to developing overlapping legislation."

A draft Senate proposal that CNET obtained in August 2009 authorized the White House to "declare a cybersecurity emergency," and another from Sens. Jay Rockefeller (D-W.Va.) and Olympia Snowe (R-Maine) would have explicitly given the government the power to "order the disconnection" of certain networks or Web sites. House Democrats have taken a similar approach.

In a statement, Lieberman said there's no "kill switch" in this bill.

"It is impossible to turn off the Internet in this country," he said. "This legislation applies to the most critical infrastructures that Americans rely on in their daily lives--energy transmission, water supply, financial services, for example--to ensure that those assets are protected in case of a potentially crippling cyberattack."

The ACLU's Richardson believes the problem was never a "kill switch." She said: "The question is bigger than that. It's generally, can the government interfere with communications...The question is: Are there significant protections in there?"

Jim Harper, director of information policy studies at the free-market Cato Institute and a member of a Homeland Security advisory panel, says that supporters of the bill have yet to make the argument that such governmental emergency powers will do more good than harm.

"They recognize that a total Internet kill switch is totally unacceptable," Harper said today. "A smaller Internet kill switch, or a series of kill switches, is also unacceptable...How does this make cybersecurity better? They have no answer."

Saturday, January 29, 2011

How to Foil a Nationwide Internet Shutdown

How to Foil a Nationwide Internet Shutdown
By Adam Dachis Jan 28, 2011

The Egyptian government cut internet connections across their country to silence protests, leaving nearly all of its citizens without online access. But they weren't entirely successful. When governments shut down broadband and mobile connections, here's what to do.

What's Going on Now?

If you haven't been keeping up with the story, here's the gist. Citizens across Egypt are protesting their government in unprecedented numbers, and its believed that the internet played a major role in the protests. So what did the Egyptian government do? First, they started blocking domain name servers (DNS)—the phone book of the internet—but citizens circumvented this limitation by using proxy servers. In reaction, the government cut broadband connections to the web and forced mobile providers to do the same. For more details, read Gizmodo's take on how Egypt turned off the internet. The result: a nationwide internet blackout that's preventing Egyptian citizens from communicating online. To put it bluntly, this sucks. But it's still not good enough. We're going to look at how Egyptian citizens can (and are) circumventing the problem.

Old School Internet

Unless the Egyptian government kills all of the phone lines as well, you might remember one means of getting online that broadband has since relegated to obsolescence: dial-up. While there's no Egyptian ISP that will allow internet access to Egyptian citizens, other countries will, meaning any Egyptian citizen with long-distance calling capabilities can break out their old school 56k modem and dial-up an ISP in another country. (Sure it's going to be a slow connection, but you can survive.)

Several ISPs—such as Budget DialUp—offer dial-up numbers all over the globe. Some ISPs in other countries are offering free access to Egyptians specifically in response to the Egyptian government's actions. According to twitter user @ioerror, French ISP FDN is one of them:

Egypt can use this number for dial up: +33172890150 (login 'toto' password 'toto') - thanks to a French ISP (FDN)#egypt #jan25

Others report that even DSL is still a possibility:

@SultanAlQassemi DIAL-UP ISP IS WORKING. DSL still working#Egypt,Try their Dial up numbers (0777 7770),(0777 7000) SPREAD THE WORD #jan25

While dial-up isn't an ideal means of getting online for most of us, it's still a perfectly effective means of connecting when your government shuts down the internet. And until the Egyptian government shuts down all landline access—another huge step up the censorship ladder—there's not much they can do to completely shut down the internet.

Sunday, June 20, 2010

Lieberman, Collins, Carper introduce bill allowing President to Kill Internet

Senators introduce bill that would allow US to disconnect the Internet
By John Byrne
Friday, June 18th, 2010

Sen. Joe Lieberman (I-CT), along with one Republican and Democratic senator, introduced a bill late last week that would allow the President to effectively disconnect the internet by emergency decree.

The Protecting Cyberspace as a National Asset Act would allow the President to disconnect Internet networks and force private websites to comply with broad cybersecurity measures.

Future US presidents would have their Internet "kill switch" powers renewed indefinitely.

The bill was introduced by Lieberman, Sen. Susan Collins (R-ME) and Sen. Tom Carper (D-DE). A parallel bill was drafted last year by Sen. Jay Rockefeller (D-WV) and Sen. Olympia Snowe (R-ME) which would allow the federal government to unilaterally "order the disconnection" of certain websites.

“For all of its ‘user-friendly’ allure, the Internet can also be a dangerous place with electronic pipelines that run directly into everything from our personal bank accounts to key infrastructure to government and industrial secrets," Lieberman said in a release announcing his bill. "Our economic security, national security and public safety are now all at risk from new kinds of enemies -- cyber-warriors, cyber-spies, cyber-terrorists and cyber-criminals.

“The need for this legislation is obvious and urgent,” the Connecticut senator added.

"We cannot afford to wait for a cyber 9/11 before our government realises the importance of protecting our cyber resources," Sen. Collins said.

The bill would give a newly-formed National Center for Cybersecurity and Communications the authority to monitor the "security status" of private websites, ISPs and other net-related business within the U.S. as well as critical internet components in other countries. Companies would be required to take part in "information sharing" with the government and certify to the NCCC that they have implemented approved security measures. Furthermore, any company that "relies on" the internet, telephone system or any other part of the U.S. "information infrastructure" would also be "subject to command" by the NCCC under the proposed new law.
Lieberman's bill would also create a cadre of cybersecurity agencies and order strategy planning with private firms. The legislation is supported by anti-virus giant Symantec.

“The Internet may have started out as a communications oddity some 40 years ago but it is now a necessity of modern life, and sadly one that is under constant attack,” Lieberman added in his release. “It must be secured... The Protecting Cyberspace as a National Asset Act of 2010 is designed to bring together the disjointed efforts of multiple federal agencies and departments to prevent cyber theft, intrusions, and attacks across the federal government and the private sector. The bill would establish a clear organizational structure to lead federal efforts in safeguarding cyber networks. And it would build a public/private partnership to increase the preparedness and resiliency of those private critical infrastructure cyber networks upon which our way of life depends."