16 ms·
Tech group representing Google, Yahoo backs CISPA
- msandford 13y agoSure, why not? Why would you NOT want to avoid all kinds of lawsuits? From our point of view it's disgusting but for upper management it's a no-brainer.
- tptacek 13y agoWhy is it "disgusting"?
- msandford 13y agoLike all new laws this one will be sold one way and used another -- likely very expansionary -- way. For example the Patriot Act was sold as a thing that would only be used to catch terrorists. It's total terrorist-catching prosecutions to date is trivial, zero to a few. But it's still getting used quite a bit. http://www.nytimes.com/2003/09/28/us/us-uses-terror-law-to-pursue-crimes-from-drugs-to-swindling.html?pagewanted=all&src=pm http://www.nytimes.com/2003/09/28/us/us-uses-terror-law-to-p... http://www.cbsnews.com/2100-201_162-573155.html http://www.cbsnews.com/2100-201_162-573155.html I'm not saying that the people who got caught in many of those cases didn't do something wrong, nor am I saying that they should get away with no consequences. But I don't see how you can charge people with "terrorism" for doing decidedly non-terrorist things.
- tptacek 13y agoIf the text of the bill doesn't matter, the text of every other privacy-related bill doesn't matter either, and we can skip all these pointless arguments and let them pass SOPA. After all, they're just going to use milk safety regulations to combat piracy.
- msandford 13y agoIt's not that the text of the bill is COMPLETELY irrelevant. It's that the big companies will use their newfound powers in ways that fall into a gray area in the bill and of course the government will choose not to prosecute them for doing so, or judges will allow it because it's a gray area and not EXPLICITLY disallowed.
- rpedroso 13y agoBecause CISPA's definition of a "cybersecurity" threat is too broad. One of the vague terms it employs is "unauthorized access" -- a term we have seen abused recently in the cases of Aaron Swartz and Weev. My fear is that, like the PATRIOT act, CISPA will grant overly-broad powers to intelligence agencies that will be employed for general surveillance. My view is that any law that curtails liberty should do so minimally. I don't oppose fighting cybersecurity threats, but the bill needs work still. For anyone curious, the ACLU has several blog posts breaking down the problems with CISPA: http://www.aclu.org/search/cispa?show_aff=1 http://www.aclu.org/search/cispa?show_aff=1
- tptacek 13y agoYou just made an argument that is directly contradicted by the text of the bill. ‘(B) EXCLUSION.— Such term does not 23 include information pertaining to efforts to gain 24 unauthorized access to a system or network of 25 a government or private entity that solely in 1 volve violations of consumer terms of service or 2 consumer licensing agreements and do not oth- 3 erwise constitute unauthorized access.
- declan 13y agoExcept that Aaron Swartz was not charged with unauthorized access "solely" because of his violation of a TOU or EULA. Mind you, I'm not saying the previous poster's claim is the best argument against CISPA, but that your claim of "directly contradicted" is false.
- tptacek 13y agoNo, I was responding to the "unauthorized access" point in the parent comment. Since you can't be charged with a crime under CISPA at all, I'm not sure how your comment isn't a non sequitur.
- trhtrsh 13y agoYou can be charged with a crime under existing law, and CISPA can be used to collect evidence for that charge.
- mtgx 13y agoGoDaddy supported SOPA basically for the same reason - because it offered hosting providers immunity if they were taking down the sites themselves.
- benmarks 13y agoBased on the post title, my brain read the link name as thehell.com.
- mratzloff 13y agoI wouldn't be surprised if this bill simply protected what they're already doing in secret. I'm sure all of these companies already have agreements with the NSA of one kind or another.
- jauer 13y agoReally it just streamlines things and eliminates paperwork shuffles. If you have something they should see and they know you aren't a crank you just say hey, I have this event. If you are interested, send me admin subpoena. If they care, they do. The entity handling this stuff seems to be DHS or FBI, not NSA, but they are all part of IC so the info should, in theory, be shared around. My wild speculation is they are trying to gather logs to make a sort of national IDS to be more proactive in detecting APT.
- abdophoto 13y agoDon't be evil.
- enraged_camel 13y agoAt this point I'm convinced that they never meant this. It was simply a recruiting slogan to attract all the liberal/libertarian/anti-coporation comp sci students who went to Stanford and Berkeley.
- rdl 13y agoI'm pretty sure that early on (when pb coined the phrase), it was meant like "don't be like the other evil companies we've seen on the Internet in the past") (which presumably at the time meant Microsoft, maybe USG, maybe ITU, etc.) Which Google probably broadly believed internally. (this was in the early 2000s).
- trhtrsh 13y agoA recruiting slogan, and an intstruction to new hires. What does it mean to "not mean" something that your employees believe and live by?
- rdl 13y agoThis is the part where tptacek says CISPA doesn't do anything particularly bad vs. the state of law now, other people express fairly emotional vs. fact based arguments about what bad it could do, and no one (in industry or government or watchdog groups) really knows for sure what CISPA would, in practice, mean, right?
- deepblueocean 13y agoNah. It's bad. Here's a simple argument that covers just one part of the bill. CISPA would give a safe harbor from other privacy rules to companies that share information with the government as long as that information is about "cyber threats". Now, let's say someone breaks into your database server and you're at a company with not-too-skilled IT people. The government shows up and says "hey, what can you tell us about the attack you experienced? PS - we'd be happy to analyze your data for you." What do your IT people do? They say "screw it, we'll just send in all the logs we have and let the feds figure it out." And so they do that. What if the law protects the information in those logs? What if the information is sensitive (like health or financial information) and is protected under a special privacy regime like HIPAA? Or what if the information is protected from disclosure by contract (like in a TOS/TOU document)? CISPA says that the disclosure is exempt from whatever sanctions/punishments would happen under those protection regimes because Cyber Threats Are Important (tm). Disclosure: I am not a lawyer. Even after it's passed into law, only a court can decide exactly what the safe harbor in CISPA means.
- tptacek 13y agoThat is in fact more or less what the law allows firms to do: when their database is compromised, they are allowed to cooperate with other service providers and with law enforcement to track down what actually happened to their systems without spending $50,000 to ensure that they aren't violating, say, DPPA.
- anoncow 13y agoSo that means, if the database contained emails, call records, or sms, The feds could read all of it. That sounds like a security risk waiting to happen at your cell phone carrier and email service provider.
- 6thSigma 13y agoDidn't Google recently file a lawsuit claiming that NSLs which are used to uncover private user information are unconstitutional? Edit: They did [1]. [1] http://www.bloomberg.com/news/2013-04-04/google-fights-u-s-national-security-probe-data-demand.html http://www.bloomberg.com/news/2013-04-04/google-fights-u-s-n...
- tptacek 13y agoThere is no intersection between the NSL controversy and CISPA. CISPA is entirely opt-in. Google has to volunteer the information; it can't be coerced into doing so by the government. Even if Google wanted to share emails, voluntarily, it would not find authority to do so in CISPA, because CISPA scopes the kinds of information that can be shared to data incident to actual cyber attacks.
- declan 13y agoI halfway agree. Google and some other left-coast companies are the least likely to take advantage of CISPA's wildcard override-all-existing-privacy-laws loophole. Google has fought the DOJ in court before to protect the privacy of their users; they're fighting the FBI now. Facebook, Amazon, and Twitter have done the same. But other companies, including AT&T, are far more likely to exploit this loophole (in fact they persuaded Congress to immunize them for illegal activity, post-facto): http://news.cnet.com/8301-13578_3-9986716-38.html http://news.cnet.com/8301-13578_3-9986716-38.html Your claim that a company could "not find authority" to share emails under CISPA is close to the mark but not quite there. First, the House Intelligence committee rejected an amendment by a 4-16 vote that would have required companies to "make reasonable efforts" to delete "information that can be used to identify" individual Americans. Second, data that can be freely shared with FedGov including NSA encompasses broad categories of information relating to security vulnerabilities, network uptime, intrusion attempts, and denial-of-service attacks, with no limit on sharing emails or personal data. See: http://news.cnet.com/8301-13578_3-57579012-38/privacy-protections-booted-from-cispa-data-sharing-bill/ http://news.cnet.com/8301-13578_3-57579012-38/privacy-protec...
- 13y ago
- deepblueocean 13y agoSo who is TechNet? It's not really fair to cherry-pick from their members when writing a story like this. So let's take a look: http://www.technet.org/leaders/member-companies/ http://www.technet.org/leaders/member-companies/ A headline "Tech group representing AT&T, Palantir backs CISPA" isn't good copy. But that could have been the headline. The "Executive Council" (which seems to be the part of the organization that draws the focus on Google and Yahoo) also contains people from Oracle, Microsoft, and VeriSign. And one thing that council doesn't do is sign off on every letter the group sends out (or, probably, every point in the policy platform it espouses). I doubt without knowing exactly that Google's official position is anti-CISPA and that this group doesn't speak for them because they don't actually control what it says. But I've been surprised in the past. Perhaps, though, people should read this and think "hey, Google ought to put some pressure on the lobbying groups they participate in not to be stupid/evil/whatever." And perhaps if a few Google executives express that they're upset that their names were used in conjunction with something they don't support, they can rein in groups that want to claim the mantle of "the tech industry".
- npsimons 13y agoThe difference is, we expect this sort of Evil behavior from AT&T, Palantir, Oracle, VeriSign and definitely Microsoft. But when a company with the supposed motto of "Don't be evil" backs it, it's news. Yahoo, though, I'm only a little surprised. I'm also not surprised Apple is a member, nor that you (and the headline) didn't mention them. Sure, sure, you can't keep track of the political positions of every group you're a member of. But if a group holds opinions that are evil, that might just be a good reason to not maintain membership. I could easily Godwin this thread by mentioning certain groups I am not a member of for exactly that reason. The company you keep and all that.
- declan 13y agoGoogle has never "backed" CIPSA. Facebook and Microsoft previously backed CISPA but then distanced themselves. See: http://news.cnet.com/8301-13578_3-57579012-38/privacy-protections-booted-from-cispa-data-sharing-bill/ http://news.cnet.com/8301-13578_3-57579012-38/privacy-protec... Trade associations tend to remain silent when a good portion of their members oppose legislation. But Google/Facebook/Microsoft aren't opposing CISPA, last I checked. It's more like they're just remaining neutral.
- ebbv 13y agoAnd the erosion of privacy protection in the name of "security" continues unabated. The problem with CISPA is we don't need it. I'm not a libertarian (I want single payer universal health care, for example), but I am fully against the PATRIOT Act, FISA abuse and the numerous other things done in the name of security since 9/11. The reason 9/11 happened was not a lack of security or intelligence; we had those. It was failure to act on the information we had. We shouldn't be putting more power in the hands of intelligence agencies which have no public oversight. I understand the need for those agencies, but I think they should be as small as possible. Things like CISPA seem to be based on an opposite view; giving them as much power as possible. EDIT: Also the notion that you can learn everything you need to know about these bills by reading the bill itself is so myopic as to be comical.
- tptacek 13y agoYou could say exactly this set of things about any bill ever. Not one phrase in this comment binds in any way onto CISPA. You literally could have written it 8 years ago, saved it in a tfile in your home directory, and just copy/pasted it into this thread no matter what the bill said. If you think the real meaning of the bill has nothing to do with the text of the bill, that the text of the bill doesn't matter, just give up. CISPA is tiny compared to ECPA; if you think CISPA has holes a truck could drive through, give a close read to SCA. If you believe the government is going to use milk safety regulations to prosecute movie pirates, just let them pass whatever, and skip the arguments.
- ebbv 13y ago> You could say exactly this set of things about any bill ever. No, I couldn't. There are unfortunately a lot of bills I could have said that about (and I mentioned some of them), but not literally any bill ever. In fact, most bills are not about granting more power to intelligence agencies at the cost of privacy protections. But thanks for sticking to your role as mindless CISPA defender. You play it well. EDIT: > If you think the real meaning of the bill has nothing to do with the text of the bill, that the text of the bill doesn't matter, just give up. I didn't say that and obviously didn't mean that. I also couldn't give a shit about movie pirates. I buy my entertainment. That's the bonus of being a full grown adult with a career. But I do care about the erosion of privacy law for no benefit whatsoever, and in fact, what I see as a detriment; continuing to grow the intelligence industry which has no public oversight. That's a Bad Idea(tm).