One Thing Maine, Virginia and Arizona Have in Common: Opposition to the NDAA
By Allie Bohm | ACLU | April 27, 2012
This week, the House Armed Services Committee has turned its attention back to the National Defense Authorization Act and began working on this year’s bill. You remember last year’s perversion that, for the first time in American history, codified indefinite military detention without charge or trial far from any battlefield? State legislators and activists and concerned citizens on the right and the left — and everyone in between — haven’t forgotten.
On Wednesday, Arizona’s state legislature sent a bill opposing the detention provisions in the NDAA to their governor. And, last week, a similar bill became law in Virginia, about a month after Maine passed a joint resolution to the same effect. Add to that list the cities and counties that have passed resolutions urging Congress to repeal the problematic provisions in the NDAA — Fairfax, Calif.; Santa Cruz, Calif.; El Paso County, Colo.; Fremont County, Colo.; Moffat County, Colo.; Weld County, Colo.; Cherokee County, Kan.; Northampton, Mass.; Alleghany County, N.C.; Macomb, N.Y.; Elk County, Pa.; and New Shoreham, R.I. — and the map starts looking awfully full. This is not a red state issue or a blue state issue or a purple state issue. A few of the resolutions are under-inclusive, but their message is still clear: across social and political lines, no one likes the idea of indefinite detention or mandatory military detention far from any battlefield. (Okay, except maybe Sen. Lindsey Graham (R-S.C.) and a few other misguided members of Congress.)
Will your town, city, county, or state be the next to speak up? You can make that happen. Check out our model legislation and activist toolkit for legislative language, talking points, and tips to help you get started. Our bill sends a message from your local legislative body to Congress that the indefinite military detention provisions of the NDAA should be repealed. The model legislation prohibits state and local employees from aiding the federal armed forces in the investigation, arrest, detention, or trial of any person within the United States under the NDAA. It also sends a message from your legislative body to Congress that the 2001 Authorization for Use of Military Force should expire at the end of the war in Afghanistan so that the government cannot continue to use the AUMF as justification for its claims that war is everywhere and anywhere and that the president can order the American military to imprison without charge or trial people picked up far from any battlefield.
And while you’re at it, head over to our Action Center and urge your member of Congress to fix the NDAA. The time is now. This year’s NDAA provides the perfect opportunity for Congress to fix last year’s debacle. And, we need you — and your state legislators and city council members — to speak up if we’re going to get Congress to finally do the right thing.
Related articles
- A Slick Trick on the NDAA and Indefinite Detention; Don’t Be Fooled! (alethonews.wordpress.com)
- Virginia lawmakers agree to reject NDAA (EndtheLie.com)
- Arizona Legislature Passes Anti-NDAA Bill (destructionist.wordpress.com)
CISPA passes House in unexpected last-minute vote
RT | 27 April, 2012
The House of Representatives has approved Cyber Intelligence Sharing and Protection Act with a vote count of 248-168. The bill is now headed for the Senate. President Barack Obama will be able to sign or cancel it pending Senate approval.
Initially slated to vote on the bill Friday, the House of Representatives decided to pass Cyber Intelligence Sharing and Protection Act (CISPA) Thursday after approving a number of amendments.
Apart from cyber and national security purposes, the bill would now allow the government to use private information obtained through CISPA for the investigation and prosecution of “cybersecurity crime,” protection of individuals and the protection of children. The new clauses define “cybersecurity crime” as any crime involving network disruption or hacking.
“Basically this means CISPA can no longer be called a cyber security bill at all. The government would be able to search information it collects under CISPA for the purposes of investigating American citizens with complete immunity from all privacy protections as long as they can claim someone committed a ‘cybersecurity crime.’ Basically it says the Fourth Amendment does not apply online, at all,” Techdirt’s Leigh Beadon said.
Declan McCullagh, correspondent from CNET News, says CISPA will cause more trouble than is immediately apparent.
“The most controversial section of CISPA is the language – that notwithstanding any other portion the of law, companies can share what they want as long as it’s for what they call a ‘cyber security purpose,'” he told RT.
CISPA was introduced in the House last November. Critics chided the bill, saying its broad wording could allow the government to spy on individual Internet users and block websites that publish vaguely defined ‘sensitive’ data.
“[CISPA] doesn’t really have any protections against cyber threats, all it does is make people share their information. But that’s not going to solve the problem. What’s going to solve the problem is actual security measures, protecting the service in the first place, not spying on people after the fact,” Internet activist Aaron Swartz told RT.
The White House issued a statement Wednesday saying President Barack Obama would be advised to veto the bill if he receives it. The Obama administration denounces the proposed law for potentially giving the government cyber-sleuthing powers that would allow both federal authorities and private businesses to sneak into inboxes and online activities in the name of combating Internet terrorism tactics.
Earlier, the House of Representatives and Senate also considered adopting the Stop Online Piracy Act (SOPA) and Protect IP Act (PIPA). These bills sought to entitle the US government to curb access to “rogue websites” that illegally hosted intellectual property. The bills could effectively force search engines to remove these websites from search results, an action many private companies considered intrusive.
PIPA and SOPA were opposed by many Internet giants including Google, Mozilla, Facebook, Yahoo!, Wikipedia and Reddit. Google organized a petition against the legislation, while Wikipedia held a 24-hour blackout to protest the bill in January. As a result, SOPA was recalled while PIPA was postponed indefinitely.
However, CISPA was actually backed by Facebook, despite its opposition to SOPA and PIPA. In a blog post on April 13, Joel Kaplan, Vice President of US Public Policy at Facebook, argued that if enacted into law, the bill would “give companies like ours the tools we need to protect our systems and the security of our users’ information, while also providing those users confidence that adequate privacy safeguards are in place.”
A number of big companies, including AT&T, Microsoft, Boeing, Verizon and Oracle have also supported CISPA.
Security for the 99%
By Dan Auerbach | EFF | April 25, 2012
The House of Representatives kicked off their “cybersecurity week” yesterday with a hearing titled “America Is Under Cyber Attack: Why Urgent Action is Needed.” Needless to say, the rhetoric of fear was in full force. A lot of topics were raised by members of Congress and panelists, but perhaps the most troublesome theme came from panelist and Former Executive Assistant Director of the FBI Shawn Henry, who repeatedly urged that good cybersecurity means going on the offensive:
“the problem with existing […] tactics is that they are too focused on adversary tools (malware and exploits) and not on who the adversary is and how they operate. Ultimately, until we focus on the enemy and take the fight to them […], we will fail.”
This offensively-minded approach has major pitfalls, as it could lead to more government monitoring and control over our communications. While we think an increased focus on catching criminals using existing tools is a fine tactic that could be used by law enforcement, we fear the temptation for law enforcement to increase their surveillance capabilities in order to successfully go on the offensive in the context of computer crimes. This could mean things like breaking into people’s computers without warrants, or disrupting privacy-enhancing tools like Tor. Needless to say, we think it would be a very bad idea to link our safety to the ability for law enforcement to effectively monitor people, and that is a danger of focusing solely on an offensive strategy. Instead, we would like to offer an alternative, defensively-oriented point of view regarding security, an important view that we think was not adequately represented in yesterday’s panel.
Securing U.S. critical infrastructure networks, corporate networks, and the Internet at large depends upon securing our computers and networked devices. Fundamentally, it’s very simple: fewer software vulnerabilities means more security. Once a vulnerability is patched and an upgraded version of software is available and in use, that increases safety for all of us. Ensuring that the right mechanisms are in place to maximize this baseline security should be a major focus area of any organized effort to secure our critical and other Internet infrastructure. This means encouraging the disclosure of vulnerabilities when they are found so that they can be fixed, and no longer exploited. This is what we mean when we talk about security for everyone. This defensive strategy also takes a view of vulnerabilities that includes engineering with security in mind: if software doesn’t force good security on administrators and other humans who have a role to play to keep things secure, then that should be considered a security vulnerability in that software.
In order to understand why vulnerabilities are the foundation of insecurity and ought to be the focus of defensive efforts, let’s take a bit of time for those new to the computer security world to define bugs, vulnerabilities, exploits, and a particularly nasty class of exploits called “zero-day” exploits.
What are bugs, vulnerabilities, exploits and “zero-day” exploits?
A software bug is a general term referring to an unintentional problem with a piece of software that causes the software to work in an unexpected or unintended way. Bugs can refer to low-level issues (“we started counting from 0 over here, but from 1 over there, and now this array is messed up”), or to high-level issues (“we didn’t implement a feature allowing people to see their open orders on this website”).
Security vulnerabilities are a class of bugs in software; these are the bugs that allow an attacker to gain unauthorized access to do something that she couldn’t before. This could mean gaining access to a remote computer, or to a private network, or to other private information. Once again, these range from low-level vulnerabilities (“We weren’t expecting the user to give a name that was 4 gigabytes long; our oversight allowed the user to crash the program and execute her malicious code on the victim’s system”) to high-level (“Since we didn’t force a user to use a strong passphrase, his account could be compromised”).
Exploits are pieces of software that actually take advantage of the security vulnerability and give the user running the software unauthorized access. A security vulnerability could lead to an exploit, although not all vulnerabilities lead to exploits.
Zero-day exploits are exploits that take advantage of an undisclosed vulnerability. Suppose there is a publicly known vulnerability in the browser Internet Explorer 6. Then any exploit based on that vulnerability is NOT considered a zero-day, and you can (often, theoretically) protect yourself from such a vulnerability. In this case, for example, you could do so by downloading Internet Explorer 9. However, if there is a “zero-day” in Internet Explorer 9, there’s nothing you can knowingly do as a user to protect yourself. This makes this type of vulnerability especially scary, since it could be used not just against unwitting users who haven’t upgraded their software, but against anyone.
Ok, got it. To make us safer, we need to patch vulnerabilities and prevent exploits, especially zero-day exploits. Does CISPA encourage this?
Unfortunately, the “cybersecurity” bill CISPA and other legislation under debate does NOT focus on this baseline security. Instead of encouraging the patching of vulnerabilities as quickly as possible, or offering solutions to improve the general security of networked computers, the bill encourages broad surveillance of personal data by companies and the government. This type of information sharing is largely unrelated to the core issue of vulnerabilities that need to be patched at the software level. It’s certainly possible that by mining that data one could come across an exploit or an unknown vulnerability and share it with the vendor, but the bill is NOT about sharing vulnerabilities so that they can be patched – it’s about sharing raw data in a way that could legitimize a public-private surveillance partnership. And this data sharing between companies and the government in no way encourages security vulnerabilities themselves to be shared with the relevant software vendors and developers so that they can be patched. In other words, it just doesn’t attack the root of the problem.
Why is fixing vulnerabilities at odds with taking an offensive approach to security?
If we take an offensive approach as Mr. Henry suggests, a “security for the 1%” situation seems likely to arise, in which vulnerabilities are sometimes kept secret, and mitigations or fixes for these vulnerabilities are selectively doled out by the government or other private security firms only to critical infrastructure or paying clients (the “1%” deemed worthy of protection). The government might even deploy black box systems to companies and infrastructure designed to mitigate exploits based on secret vulnerabilities while giving as little information as possible about those underlying vulnerabilities, even to the companies they are protecting. Either way, the vendor would not be told about the vulnerability and so anyone who wasn’t a recipient of the “privileged” information would be hung out to dry.
What is a better approach to security?
Changing the incentives and culture to encourage the right sort of information sharing concerning vulnerabilities is a complex problem, and we do not purport to have a complete solution. There are many pieces to the puzzle: what should be done about vendors who don’t care about security? What about users who don’t upgrade software, or go out of their way to be vulnerable? What about security researchers who discover vulnerabilities, and choose to sell this knowledge to the highest bidder, instead of ensuring that the vendor knows about the vulnerability and it gets fixed?
There are some common sense tactics that the government can take to help solve these problems. For starters, the government can itself commit to disclosing any known vulnerabilities to vendors so that they are promptly patched. Next, incentives could be put in place to encourage research that has broad beneficial effects for everyone’s security. For example, suppose a researcher invents a new testing technique that reduces how many exploitable vulnerabilities there are in software in general. This is a win for everyone, and we think the government should strongly encourage such research.1
But beyond these common sense suggestions, the main point we want to raise in this post is not to offer a solution to these problems, but rather suggest that anyone interested in security at the national and international level should be thinking hard about them. Taking an offensive approach has the potential to put our civil liberties in danger, and could create a situation in which our safety ebbs and flows with how well the intelligence community can spy on us. This precarious and undesirable situation can be avoided if instead we take a defensive approach to stop the problem at its core, working to ensure that everyone is maximally protected. Mr. Henry suggests that “offense outpaces the defense.” That seems like an oversimplification, but even if one accepts it to be true, we should not take this to be an immutable property of the world. Instead, we should work to change it by increasing our defensive efforts. Unfortunately, the “cybersecurity” debate does not seem to be addressing this point of view, but we hope that somebody brings it up during “cybersecurity week”.
In the mean time, please speak out against the misguided cybersecurity legislation by taking action against CISPA.
Related articles
FAA approves spy drones to fly US skies
Press TV – April 23, 2012
US law enforcement agencies have received the approval of the Federal Aviation Administration (FAA) to use unmanned aircraft known as drones for mass surveillance.
More than 50 non-military organizations within the United States have received approval to fly drones, according to documents obtained via the Freedom of Information Act requests by the advocacy group, Electronic Frontier Foundation.
Major agencies like the FBI, the US Department of Homeland Security and the US Department of Justice had been cleared to launch drones, US President Barack Obama administration’s favorite weapon of war which is being used in countries such as Pakistan, Afghanistan and Yemen.
The Electronic Frontier Foundation civil liberty group warned that the use of drones poses a serious threat to personal privacy.
The documents revealed that individual city police forces are also drawing up plans to use the reconnaissance aircraft.
In February, the US Congress passed a bill which approved the government’s deployment of up to 30,000 spy drones in American airspace by 2020.
The Federal Aviation Administration Reauthorization Act, which President Obama is expected to sign, also ordered the FAA to develop regulations for the testing and licensing of drones by 2015.
According to some estimates, the commercial drone market in the United States will be worth hundreds of millions of dollars. Currently almost 50 companies are developing some 150 different drone systems.
The US has been using the unmanned vehicles for its spy operations and assassination missions worldwide and the strikes have intensified since Obama took office three years ago.
Proposed Amendments to #CISPA Don’t Protect Privacy
By Michelle Richardson | ACLU | April 19, 2012
Yesterday, the House Intelligence Committee released proposed changes to the Cyber Intelligence Sharing and Protection Act of 2011, also known as CISPA that, according to its sponsors, represent “huge progress” towards addressing the privacy and internet freedom community’s concerns.
But, many privacy advocates, including the ACLU, and groups including the Center for Democracy and Technology, Free Press, the Electronic Frontier Foundation and the Constitution Project still maintain their opposition. The changes are so underwhelming that even the Obama administration issued a statement yesterday that their privacy concerns persist.
Here are some of the main problems with CISPA:
1. CISPA still allows companies to share lots of sensitive and private information about our internet use with the government. The proposal amended the definition of what could be shared by taking out its explicit reference to stealing “intellectual property.” But it still allows the sharing of Internet use records or the content of emails for “cybersecurity purposes” and unlike proposals drafted by Sens. Joe Lieberman and Dianne Feinstein or the Obama administration, CISPA does not require companies to even make an effort to remove information that could be tied to a specific individual.
2. CISPA still lets military agencies such as the National Security Agency directly collect the Internet records of American citizens who use the public, domestic, civilian Internet. The proposed changes state that the Department of Homeland Security should be cc’d when companies share our private details with the military and others, but this is no substitute for ensuring that a civilian agency is put in charge of collecting Americans’ information.
3. CISPA still lets the government use the private information it collects about us for any purpose it deems fit outside of regulation. For four months, the draft bill has remained the same: the government can use information collected under this broad new program for “any lawful purpose” so long as a “significant purpose” of its use is a cybersecurity or national security one. But as former federal and FISA court judge James Robertson said at a congressional briefing this week, this “significant purpose” limitation is meaningless. The Patriot Act inserted this language into our foreign intelligence surveillance laws, and since then, in Judge Robertson’s words, they’ve had a “hole you could drive a truck through.”
Hard to see the progress here.
CISPA is still expected to hit the House floor for “Cybersecurity Week” next week. You can find out more about the bills in this memo, and more importantly, help us spread the word on Twitter and write to your Member of Congress today. Let Congress know that in spite of the minor changes floated by the House Intelligence Committee, you still oppose CISPA.
Related articles
- The Disturbing Privacy Dangers in CISPA (alethonews.wordpress.com)
- Worse than SOPA? CISPA to censor Web in name of cybersecurity (alethonews.wordpress.com)
- 5 Reasons the CISPA Cybersecurity Bill Should Be Tossed (techland.time.com)
- CISPA Lacks Protections for Individual Rights (usnews.com)
- Week of Action Against CISPA Begins, But Don’t Expect Web Blackouts (mashable.com)
Israeli Authorities or Cyber Police? Ola Haniyeh Arrested with no Charges
By Dylan Collins | Palestine Monitor | April 17, 2012
In the early morning hours of Monday March 26th, a large force of Israeli soldiers surrounded the Haniyeh house in Al-Bireh, located in the heart of the West Bank’s capital city of Ramallah. After setting up a perimeter around the house, 12 well-armed soldiers kicked down the Haniyeh’s door and entered the home.
“They broke the door. They didn’t knock. They didn’t ring. They broke the door and we found them in the middle of our bedroom,” says 26 year-old Dima Haniyeh.
After confining Dima’s parents to their bedroom, the soldiers proceeded on to the next bedroom shared by Dima and her 22 year-old sister, Ola.
Right off the bat, Dima recalls, it was clear the soldiers had an apparent interest in her young sister. “They wanted to search us both and they wanted Ola’s mobile phone and laptop.”
A female soldier was brought in to search them both.
Coincidentally, Ola’s phone had been lost several days before but the soldiers didn’t believe her.
“If you don’t give us your phone we are going to destroy the room. We will destroy every room until we find it,” Dima remembers one of the soldiers having said.
They did just that—, emptying every drawer onto the floor, flipping the beds, and clearing the shelves. Eventually, they told Ola to get dressed. They wanted to take her with them for questioning.
Ola remembers her father saying, “Why don’t you ask her here?! You’ve been here an hour and a half and haven’t asked a single question!”
Brushing aside her father’s supplications, and in violation of Fourth Geneva Convention, the soldiers took Ola with them and brought her directly to Israel’s Askalan prison in the Naqab Desert.
Another Detainee Without Charges
Ola has been held in Askalan ever since. Although no charges have been officially filed against her, a review trial held at the Askalan military court on Thursday April 5th ruled in favor of a 7-day extension of Ola’s detention. Ola was given another trial on Wednesday April 4th which resulted in yet another detention extension for the second time, as the prosecutors and Israeli judge did not carry out an investigation as they were on a vacation. Ola’s third court extension date was given this week, with her due to appear in court on Thursday, April 19.
“She is being interrogated daily regarding internet activity. The suspicion is that the internet pages are connected to ‘security activities’”, says Amal Husein of Addameer.
Ola’s detention was up for review on Tuesday April 17th. Her family and friends are confident that she will be released, as she hasn’t been accused or charged of anything as of yet. However, given the Israeli authorities’ administrative detention track record, anything is possible.
“People have said that the Israeli authorities have taken many people because of Facebook,” says Dima. “But everyone has a Facebook. Everyone puts his or her opinion on Facebook. There is nothing serious about it… it is freedom of speech.”
Ola recently graduated with a degree in Media and Political Science from Birzeit University last Fall. “She might go to protests sometimes, as all of us do, to speak out against the occupation and to support people- nothing extraordinary,” says Dima. “All of us participate—its part of being in Palestine and living under occupation.”
“She’s a quiet girl,” continues Dima. “She is a genuine and passionate person. She has friends and is lively, but she is much more the quiet type.”
Ola’s sister Dima says that Ola had perhaps had made comments on Facebook in support of Palestinian prisoners in general and against Israel’s policy of administrative detention but had done nothing out of the ordinary. “She is a journalist. This is her job. She should be able to do that,” argues Dima.
Ola’s sister and friends are quite confident that she was arrested simply because she voiced her opinions—a scary thought in the Facebook age.
“When you don’t have charges against someone—why… how can you keep them detained?” asks Dima. “When you don’t have any serious charges, how can you break down someone’s door in the middle of the night and take them? What happens when they have a serious case? What will they do then? Its scary.”
Related articles
- 1,600 Palestinian prisoners begin open-ended hunger strike in Israeli jails (alethonews.wordpress.com)
- Israeli forces shut down media launch in Jerusalem (alethonews.wordpress.com)
- Israel – Israeli troops force two Palestinian TV stations to close (en.rsf.org)
- Report: 201 Palestinians Died in Israeli Jails (and more…) (occupiedpalestine.wordpress.com)
France refuses to give Press TV team visas; no explanation offered
Press TV – April 16, 2012
The French Embassy in Tehran has refused to issue visas for a Press TV team that wanted to participate in the annual MIPTV and MIPDOC film festivals in Cannes, France, Press TV reports.
The Press TV team completed the application procedure on February 15 and was told by the visa section of French Embassy in Tehran that the initial response would come on March 7, 2012.
The embassy, however, gave no clear answer to the application until April 9 when a French Embassy employee contacted Press TV to announce that visa requests for the team had been rejected. No clear explanation was given for the rejection.
Press TV officials also wrote a letter to French Ambassador to Tehran Bruno Foucher asking him to provide them with a proper explanation. The French embassy, however, gave no answer to the letter.
MIPDOC and MIPTV festivals are purely cultural events which were held in the southern French port city of Cannes from March 30 to April 4, 2012.
Press TV has been regularly participating in both festivals since 2008.
In addition to Press TV crews, eyewitnesses said, it has become a habit for the French embassy to refrain from issuing visas to Iranian university professors and even physicians who want to participate in scientific events in France.
Experts believe that the measure is a clear sign that the incumbent French government is not willing to continue cultural and media cooperation with Iran.
This is not the first time that a major member of the European Union has taken hostile positions on Press TV and its staff.
In late January, the British Office of Communications (Ofcom) took a questionable measure and without offering a valid response to the Press TV CEO’s letters, revoked the channel’s broadcasting license and finally removed it from the Sky platform. Before revoking Press TV license, Ofcom had hit Press TV with a fine of 100 thousand pounds.
The British media regulator stepped up pressure on Press TV after the news channel covered British police crackdowns on anti-austerity protesters in London and other British cities.
Also, on April 3, under pressure from the German government, Munich media regulatory office (BLM) made an illegal decision to remove Press TV from the SES Astra satellite platform.
Vice President of the SES Platforms Services Stephane Goebel wrote in an e-mail to the Islamic Republic of Iran Broadcasting officials that the BLM had asked Press TV be immediately removed from the platform claiming that the channel did not have a license for broadcast in Europe.
Experts believe that such moves are clearly part of a scheme orchestrated by the West to silence the voice of the Iranian English-language channel.
Related articles
- US, Israeli cyber attack on Press TV fails (disclose.tv)
- UK threatens to confiscate Press TV property in London (1oneday.wordpress.com)
The Disturbing Privacy Dangers in CISPA
By Trevor Timm | EFF | April 15, 2012
This week, EFF – along with a host of other civil liberties groups – are protesting the dangerous new cybersecurity bill known as CISPA that will be voted on in the House on April 23. Here is everything you need to know about the bill and why we are protesting:
What is “CISPA”?
CISPA stands for The Cyber Intelligence Sharing and Protection Act, a cybersecurity bill written by Rep. Mike Rogers (R-MI) and Dutch Ruppersberger (D-MD) (H.R. 3523). The bill purports to allow companies and the federal government to share information to prevent or defend from cyberattacks. However, the bill expressly authorizes monitoring of our private communications, and is written so broadly that it allows companies to hand over large swaths of personal information to the government with no judicial oversight—effectively creating a “cybersecurity” loophole in all existing privacy laws. Because the bill is so hotly debated now, unofficial proposed amendments are also being circulated [link] and the actual bill language is in flux.
Under CISPA, can a private company read my emails?
Yes. Under CISPA, any company can “use cybersecurity systems to identify and obtain cyber threat information to protect the rights and property” of the company. This phrase is being interpreted to mean monitoring your communications—including the contents of email or private messages on Facebook.
Right now, well-established laws, like the Wiretap Act and the Electronic Communications Privacy Act, prevent companies from routinely monitoring your private communications. Communications service providers may only engage in reasonable monitoring that balances the providers’ needs to protect their rights and property with their subscribers’ right to privacy in their communications. And these laws expressly allow lawsuits against companies that go too far. CISPA destroys these protections by declaring that any provision in CISPA is effective “notwithstanding any other law” and by creating a broad immunity for companies against both civil and criminal liability. This means companies can bypass all existing laws, as long as they claim a vague “cybersecurity” purpose.
What would allow a company to read my emails?
CISPA has such an expansive definition of “cybersecurity threat information” that many ordinary activities could qualify. CISPA is not specific, but similar definitions in two Senate bills provide clues as to what these activities could be. Basic privacy practices that EFF recommends—like using an anonymizing service like Tor or even encrypting your emails—could be considered an indicator of a “threat” under the Senate bills. As we have stated previously, the bills’ definitions “implicate far more than what security experts would reasonably consider to be cybersecurity threat indicators—things like port scans, DDoS traffic, and the like.”
A more detailed explanation about what could constitute a “cybersecurity purpose” or “cyber security threat indicator” in the various cybersecurity bills can be read here.
Under CISPA, can a company hand my communications over to the government without a warrant?
Yes. After collecting your communications, companies can then voluntarily hand them over to the government with no warrant or judicial oversight whatsoever as long is the communications have what the companies interpret to be “cyber threat information” in them. Once the government has your communications, they can read them too.
Under CISPA, what can I do if a company improperly hands over private information to the government?
Almost nothing. CISPA would affirmatively prevent users from suing a company if they hand over their private information to the government in virtually all cases. A broad immunity provision in the proposed amendments gives companies complete protection from user lawsuits unless information was given to the government:
(I) intentionally to achieve a wrongful purpose;
(II) knowingly without legal or factual justification; and
(III) in disregard of a known or obvious risk that is so great as to make it highly probably that the harm of the act or omission will outweigh the benefit.
As Techdirt concluded, “no matter how you slice it, this is an insanely onerous definition of willful misconduct that makes it essentially impossible to ever sue a company for wrongly sharing data under CISPA.” This proposed immunity provision is actually worse than the prior version of the bill, under which companies could be sued if they acted in “bad faith.”
What government agencies can look at my private information?
Under CISPA, companies are directed to hand “cyber threat information” to the Department of Homeland Security (DHS). Once it’s in DHS’s hands, the bill says that DHS can then hand the information to other intelligence agencies, including the National Security Agency, at its discretion.
Can the government use my private information for other purposes besides “cybersecurity” once they have it?
Yes. When the bill was originally drafted, information could be used for all other law enforcement purposes besides “regulatory purposes.” A new amendment narrows this slightly. Now—even though the information was passed along to the government for only cybersecurity purposes—the government can use your personal information for either cybersecurity or national security investigations. And as long as it can be used for one of those purposes, it can be used for any other purpose as well.
Can the government use my private information to go after alleged copyright infringers and whistleblower websites?
Up until last Friday the answer was yes, and now it’s changed to maybe. In response to the overwhelming protest from the Internet community that this bill would become a backdoor for SOPA 2, the bill authors have proposed an amendment that rids the bill of any reference to “intellectual property.”
The bill previously defined “cyber threat intelligence” and “cybersecurity purpose” to include “theft or misappropriation of private or government information, intellectual property, or personally identifiable information.” Now the text reads:
(B) efforts to gain unauthorized access to a system or network, including efforts to gain such unauthorized access to steal or misappropriate private or government information
But it is important to remember that this proposed amendment is just that: proposed. The House has not voted it into the bill yet, so they still must follow through and remove it completely.
A more detailed explanation of how this provision could be used for copyright enforcement and censoring whistleblower sites like WikiLeaks can be read here.
What can I do to stop the government from misusing my private information?
CISPA does allow users to sue the government if they intentionally or willfully use their information for purposes other than what is described above. But any such lawsuit will be difficult to bring. For instance, the statute of limitations for such a lawsuit is two years from the date of the actual violation. It’s not at all clear how an individual would know of such misuse if it were kept inside the government.
Moreover, suing the government where classified information or the “state secrets privilege” is involved is difficult, expensive, and time consuming. EFF has been involved for years in a lawsuit over Fourth Amendment and statutory violations stemming from the warrantless wiretapping program run by the NSA—a likely recipient of “cyber threat information.” Despite six years of litigation, the government continues to maintain that the “state secrets” privilege prevents the lawsuit from being heard.
Given that DHS is notorious for classifying everything—even including their budget and number of employees—they may attempt to prevent users from finding out exactly how this information was ever used. And if the information is in the hands of the NSA and they claim “national security,” then it would get even harder.
In addition, while CISPA does mandate an Inspector General should issue a report to Congress over the government’s use of this information, its recommendations or remedies do not have to be followed.
Why are Facebook and other companies supporting this legislation?
Facebook and other companies have endorsed this legislation because they want to be able to receive information about network security threats from the government. This is a fine goal, but unfortunately CISPA would do far more than that—it would eviscerate existing privacy laws by allowing companies to voluntarily share users’ private information with the government.
Facebook released a statement Friday saying that they are concerned about users’ privacy rights and that the provision allowing them to hand user information to the government “is unrelated to the things we liked about HR 3523 in the first place.” As we explained in our analysis of Facebook’s response: the “stated goal of Facebook—namely, for companies to receive data about cybersecurity threats from the government—does not necessitate any of the CISPA provisions that allow companies to routinely monitor private communications and share personal user data gleaned from those communications with the government.” Read more about why Facebook should withdraw support from CISPA until privacy safeguards are in place here.
What can I do to stop this bill?
It’s vital that concerned Internet users tell Congress to stop this bill. Use EFF’s action center to send an email to your Congress member urging them to oppose this bill.
Related articles
- Worse than SOPA? CISPA to censor Web in name of cybersecurity (alethonews.wordpress.com)
- Facebook defends CISPA support, completely misses the point (digitaltrends.com)
- What You Need to Know About CISPA (readwriteweb.com)
- What Facebook Wants in Cybersecurity Doesn’t Require Trampling On Our Privacy Rights (eff.org)
- Say ‘hello’ to CISPA, it will remind you of SOPA (news.cnet.com)

