Showing posts with label CISA. Show all posts
Showing posts with label CISA. Show all posts

Thursday, April 23, 2015

CISPA Redux: New Cybersurveillance Bill Passes House

On Wednesday the House passed the Protecting Cyber Networks Act (PCNA) by a vote of 307-116. The PCNA is the new version of CISPA and had been floundering in Congress due to privacy concerns before the high profile hacks of Target and Sony Entertainment provided sufficient momentum to push the bill through. PCNA and its Senate counterpart known as CISA will remove legal barriers stopping the sharing of information between private corporations and the federal government.

If enacted the law would allow customer information from private companies to be shared with the government with minor to nonexistent restraints. Another bill making its way through the House - the National Cybersecurity Protection Advancement Act (NCPA) - will setup the Department of Homeland Security as the federal agency coordinating the information sharing.

Not surprisingly, privacy and cybersecurity advocates are calling the bill a disaster and warning that it will do more harm than good. Before the passage of the bill a letter signed by 55 civil society organizations, security experts and academics, called on House members to vote no on PCNA citing major concerns that the bill would:
· Authorize companies to significantly expand monitoring of their users’ online activities, and permit sharing of vaguely defined “cyber threat indicators” without adequate privacy protections prior to sharing: This could result in the unnecessary scrutiny of innocent Internet users online activities, and sharing of their personal information, and information about that Internet use, including content of their online communications. 
· Require federal entities to automatically disseminate to the NSA all cyber threat indicators they receive, including personal information about individuals: This requirement fails to effectively cement civilian control of domestic cybersecurity information sharing and could vastly and unnecessarily increase the NSA’s access to innocent users’ information. 
· Authorize overbroad law enforcement uses that go far outside the scope of cybersecurity: Law enforcement would be allowed to use cyber threat indicators to investigate crimes and activities that have nothing to do with cybersecurity, such as robbery, arson, carjacking, or any threat of serious bodily injury or death, regardless of whether the harm is imminent. The use authorizations included in this bill undermine traditional due process protections, and turn PCNA into a cyber-surveillance bill rather than a cybersecurity bill; and 
· Authorize companies to deploy invasive countermeasures, euphemistically called “defensive measures”: The authorization for deploying defensive measures is narrower than in other bills, however PCNA still authorizes an entity to deploy a defensive measure that gains unauthorized access to computer systems of innocent third parties who did not perpetrate the threat, an action that would otherwise violate the Computer Fraud and Abuse Act. It may also authorize defensive measures that unintentionally harm innocent third parties.
Much like the retroactive immunity for the telcom companies participating in President Bush's unconstitutional domestic spying program, this bill will legalize some activity that is likely already happened. But with the legal barriers/liability gone it will be open season on internet users' private information.

In one sense this bill deregulates the data market, now everyone is for sale.

Monday, April 13, 2015

CISPA Is Back With A Vengeance

First introduced in the House of Representatives in 2011, the Cyber Intelligence Sharing and Protection Act (CISPA) is once again back in play and is being considered for legislative action this month. Much of the same concerns that accompanied its introduction in 2011 remain specifically that it is a blank check for cybersurveillance dressed up as a bill to promote cybersecurity.

The earlier version of both SOPA and CISPA were defeated due in part to staunch opposition from numerous corners of the internet. CISPA initially contained language that included intellectual property issues as falling under the act making it essentially SOPA-light.

CISPA and its Senate equivalent the Cybersecurity Information Sharing Act (CISA) are being reintroduced in hopes of capitalizing on public anxiety related to recent high profile hacks such as those of Target and Sony. The bills claim to only promote information sharing between companies and the government but in reality will expand government and private surveillance power over the public.

The Open Technology Institute notes six problems with the current CISA bill now under consideration:
  1. CISA would authorize excessive information sharing, including unnecessary sharing of personal information.
  2. CISA Would Require DHS to automatically and indiscriminately disseminate to the NSA all indicators it receives.
  3. Law enforcement agencies are authorized to use CISA-derived information to investigate a wide array of garden-variety crimes.
  4. CISA authorizes companies to monitor all of their users’ activities and communications.
  5. CISA’s liability protections leave customers no recourse if they are wrongly harmed by information sharing and monitoring.
  6. CISA authorizes companies to deploy potentially dangerous defensive measures that could harm the computers of innocent people, and contains worrisome language regarding military cyber operations.
As often happens with abuses of power and corruption in America, Congress wants to legalize the behavior. If the bill passes domestic spying will not be a scandal but a codified status quo.

And as for defensive measures, well don't worry, the US military is already gearing up for "offensive operations in cyberspace." The world is a battlefield and now so is in the internet. Are you the enemy?