Proposed Amendments to #CISPA Don’t Protect Privacy
By Michelle Richardson | ACLU | April 19, 2012
Yesterday, the House Intelligence Committee released proposed changes to the Cyber Intelligence Sharing and Protection Act of 2011, also known as CISPA that, according to its sponsors, represent “huge progress” towards addressing the privacy and internet freedom community’s concerns.
But, many privacy advocates, including the ACLU, and groups including the Center for Democracy and Technology, Free Press, the Electronic Frontier Foundation and the Constitution Project still maintain their opposition. The changes are so underwhelming that even the Obama administration issued a statement yesterday that their privacy concerns persist.
Here are some of the main problems with CISPA:
1. CISPA still allows companies to share lots of sensitive and private information about our internet use with the government. The proposal amended the definition of what could be shared by taking out its explicit reference to stealing “intellectual property.” But it still allows the sharing of Internet use records or the content of emails for “cybersecurity purposes” and unlike proposals drafted by Sens. Joe Lieberman and Dianne Feinstein or the Obama administration, CISPA does not require companies to even make an effort to remove information that could be tied to a specific individual.
2. CISPA still lets military agencies such as the National Security Agency directly collect the Internet records of American citizens who use the public, domestic, civilian Internet. The proposed changes state that the Department of Homeland Security should be cc’d when companies share our private details with the military and others, but this is no substitute for ensuring that a civilian agency is put in charge of collecting Americans’ information.
3. CISPA still lets the government use the private information it collects about us for any purpose it deems fit outside of regulation. For four months, the draft bill has remained the same: the government can use information collected under this broad new program for “any lawful purpose” so long as a “significant purpose” of its use is a cybersecurity or national security one. But as former federal and FISA court judge James Robertson said at a congressional briefing this week, this “significant purpose” limitation is meaningless. The Patriot Act inserted this language into our foreign intelligence surveillance laws, and since then, in Judge Robertson’s words, they’ve had a “hole you could drive a truck through.”
Hard to see the progress here.
CISPA is still expected to hit the House floor for “Cybersecurity Week” next week. You can find out more about the bills in this memo, and more importantly, help us spread the word on Twitter and write to your Member of Congress today. Let Congress know that in spite of the minor changes floated by the House Intelligence Committee, you still oppose CISPA.
Related articles
- The Disturbing Privacy Dangers in CISPA (alethonews.wordpress.com)
- Worse than SOPA? CISPA to censor Web in name of cybersecurity (alethonews.wordpress.com)
- 5 Reasons the CISPA Cybersecurity Bill Should Be Tossed (techland.time.com)
- CISPA Lacks Protections for Individual Rights (usnews.com)
- Week of Action Against CISPA Begins, But Don’t Expect Web Blackouts (mashable.com)
Israeli Authorities or Cyber Police? Ola Haniyeh Arrested with no Charges
By Dylan Collins | Palestine Monitor | April 17, 2012
In the early morning hours of Monday March 26th, a large force of Israeli soldiers surrounded the Haniyeh house in Al-Bireh, located in the heart of the West Bank’s capital city of Ramallah. After setting up a perimeter around the house, 12 well-armed soldiers kicked down the Haniyeh’s door and entered the home.
“They broke the door. They didn’t knock. They didn’t ring. They broke the door and we found them in the middle of our bedroom,” says 26 year-old Dima Haniyeh.
After confining Dima’s parents to their bedroom, the soldiers proceeded on to the next bedroom shared by Dima and her 22 year-old sister, Ola.
Right off the bat, Dima recalls, it was clear the soldiers had an apparent interest in her young sister. “They wanted to search us both and they wanted Ola’s mobile phone and laptop.”
A female soldier was brought in to search them both.
Coincidentally, Ola’s phone had been lost several days before but the soldiers didn’t believe her.
“If you don’t give us your phone we are going to destroy the room. We will destroy every room until we find it,” Dima remembers one of the soldiers having said.
They did just that—, emptying every drawer onto the floor, flipping the beds, and clearing the shelves. Eventually, they told Ola to get dressed. They wanted to take her with them for questioning.
Ola remembers her father saying, “Why don’t you ask her here?! You’ve been here an hour and a half and haven’t asked a single question!”
Brushing aside her father’s supplications, and in violation of Fourth Geneva Convention, the soldiers took Ola with them and brought her directly to Israel’s Askalan prison in the Naqab Desert.
Another Detainee Without Charges
Ola has been held in Askalan ever since. Although no charges have been officially filed against her, a review trial held at the Askalan military court on Thursday April 5th ruled in favor of a 7-day extension of Ola’s detention. Ola was given another trial on Wednesday April 4th which resulted in yet another detention extension for the second time, as the prosecutors and Israeli judge did not carry out an investigation as they were on a vacation. Ola’s third court extension date was given this week, with her due to appear in court on Thursday, April 19.
“She is being interrogated daily regarding internet activity. The suspicion is that the internet pages are connected to ‘security activities’”, says Amal Husein of Addameer.
Ola’s detention was up for review on Tuesday April 17th. Her family and friends are confident that she will be released, as she hasn’t been accused or charged of anything as of yet. However, given the Israeli authorities’ administrative detention track record, anything is possible.
“People have said that the Israeli authorities have taken many people because of Facebook,” says Dima. “But everyone has a Facebook. Everyone puts his or her opinion on Facebook. There is nothing serious about it… it is freedom of speech.”
Ola recently graduated with a degree in Media and Political Science from Birzeit University last Fall. “She might go to protests sometimes, as all of us do, to speak out against the occupation and to support people- nothing extraordinary,” says Dima. “All of us participate—its part of being in Palestine and living under occupation.”
“She’s a quiet girl,” continues Dima. “She is a genuine and passionate person. She has friends and is lively, but she is much more the quiet type.”
Ola’s sister Dima says that Ola had perhaps had made comments on Facebook in support of Palestinian prisoners in general and against Israel’s policy of administrative detention but had done nothing out of the ordinary. “She is a journalist. This is her job. She should be able to do that,” argues Dima.
Ola’s sister and friends are quite confident that she was arrested simply because she voiced her opinions—a scary thought in the Facebook age.
“When you don’t have charges against someone—why… how can you keep them detained?” asks Dima. “When you don’t have any serious charges, how can you break down someone’s door in the middle of the night and take them? What happens when they have a serious case? What will they do then? Its scary.”
Related articles
- 1,600 Palestinian prisoners begin open-ended hunger strike in Israeli jails (alethonews.wordpress.com)
- Israeli forces shut down media launch in Jerusalem (alethonews.wordpress.com)
- Israel – Israeli troops force two Palestinian TV stations to close (en.rsf.org)
- Report: 201 Palestinians Died in Israeli Jails (and more…) (occupiedpalestine.wordpress.com)
France refuses to give Press TV team visas; no explanation offered
Press TV – April 16, 2012
The French Embassy in Tehran has refused to issue visas for a Press TV team that wanted to participate in the annual MIPTV and MIPDOC film festivals in Cannes, France, Press TV reports.
The Press TV team completed the application procedure on February 15 and was told by the visa section of French Embassy in Tehran that the initial response would come on March 7, 2012.
The embassy, however, gave no clear answer to the application until April 9 when a French Embassy employee contacted Press TV to announce that visa requests for the team had been rejected. No clear explanation was given for the rejection.
Press TV officials also wrote a letter to French Ambassador to Tehran Bruno Foucher asking him to provide them with a proper explanation. The French embassy, however, gave no answer to the letter.
MIPDOC and MIPTV festivals are purely cultural events which were held in the southern French port city of Cannes from March 30 to April 4, 2012.
Press TV has been regularly participating in both festivals since 2008.
In addition to Press TV crews, eyewitnesses said, it has become a habit for the French embassy to refrain from issuing visas to Iranian university professors and even physicians who want to participate in scientific events in France.
Experts believe that the measure is a clear sign that the incumbent French government is not willing to continue cultural and media cooperation with Iran.
This is not the first time that a major member of the European Union has taken hostile positions on Press TV and its staff.
In late January, the British Office of Communications (Ofcom) took a questionable measure and without offering a valid response to the Press TV CEO’s letters, revoked the channel’s broadcasting license and finally removed it from the Sky platform. Before revoking Press TV license, Ofcom had hit Press TV with a fine of 100 thousand pounds.
The British media regulator stepped up pressure on Press TV after the news channel covered British police crackdowns on anti-austerity protesters in London and other British cities.
Also, on April 3, under pressure from the German government, Munich media regulatory office (BLM) made an illegal decision to remove Press TV from the SES Astra satellite platform.
Vice President of the SES Platforms Services Stephane Goebel wrote in an e-mail to the Islamic Republic of Iran Broadcasting officials that the BLM had asked Press TV be immediately removed from the platform claiming that the channel did not have a license for broadcast in Europe.
Experts believe that such moves are clearly part of a scheme orchestrated by the West to silence the voice of the Iranian English-language channel.
Related articles
- US, Israeli cyber attack on Press TV fails (disclose.tv)
- UK threatens to confiscate Press TV property in London (1oneday.wordpress.com)
The Disturbing Privacy Dangers in CISPA
By Trevor Timm | EFF | April 15, 2012
This week, EFF – along with a host of other civil liberties groups – are protesting the dangerous new cybersecurity bill known as CISPA that will be voted on in the House on April 23. Here is everything you need to know about the bill and why we are protesting:
What is “CISPA”?
CISPA stands for The Cyber Intelligence Sharing and Protection Act, a cybersecurity bill written by Rep. Mike Rogers (R-MI) and Dutch Ruppersberger (D-MD) (H.R. 3523). The bill purports to allow companies and the federal government to share information to prevent or defend from cyberattacks. However, the bill expressly authorizes monitoring of our private communications, and is written so broadly that it allows companies to hand over large swaths of personal information to the government with no judicial oversight—effectively creating a “cybersecurity” loophole in all existing privacy laws. Because the bill is so hotly debated now, unofficial proposed amendments are also being circulated [link] and the actual bill language is in flux.
Under CISPA, can a private company read my emails?
Yes. Under CISPA, any company can “use cybersecurity systems to identify and obtain cyber threat information to protect the rights and property” of the company. This phrase is being interpreted to mean monitoring your communications—including the contents of email or private messages on Facebook.
Right now, well-established laws, like the Wiretap Act and the Electronic Communications Privacy Act, prevent companies from routinely monitoring your private communications. Communications service providers may only engage in reasonable monitoring that balances the providers’ needs to protect their rights and property with their subscribers’ right to privacy in their communications. And these laws expressly allow lawsuits against companies that go too far. CISPA destroys these protections by declaring that any provision in CISPA is effective “notwithstanding any other law” and by creating a broad immunity for companies against both civil and criminal liability. This means companies can bypass all existing laws, as long as they claim a vague “cybersecurity” purpose.
What would allow a company to read my emails?
CISPA has such an expansive definition of “cybersecurity threat information” that many ordinary activities could qualify. CISPA is not specific, but similar definitions in two Senate bills provide clues as to what these activities could be. Basic privacy practices that EFF recommends—like using an anonymizing service like Tor or even encrypting your emails—could be considered an indicator of a “threat” under the Senate bills. As we have stated previously, the bills’ definitions “implicate far more than what security experts would reasonably consider to be cybersecurity threat indicators—things like port scans, DDoS traffic, and the like.”
A more detailed explanation about what could constitute a “cybersecurity purpose” or “cyber security threat indicator” in the various cybersecurity bills can be read here.
Under CISPA, can a company hand my communications over to the government without a warrant?
Yes. After collecting your communications, companies can then voluntarily hand them over to the government with no warrant or judicial oversight whatsoever as long is the communications have what the companies interpret to be “cyber threat information” in them. Once the government has your communications, they can read them too.
Under CISPA, what can I do if a company improperly hands over private information to the government?
Almost nothing. CISPA would affirmatively prevent users from suing a company if they hand over their private information to the government in virtually all cases. A broad immunity provision in the proposed amendments gives companies complete protection from user lawsuits unless information was given to the government:
(I) intentionally to achieve a wrongful purpose;
(II) knowingly without legal or factual justification; and
(III) in disregard of a known or obvious risk that is so great as to make it highly probably that the harm of the act or omission will outweigh the benefit.
As Techdirt concluded, “no matter how you slice it, this is an insanely onerous definition of willful misconduct that makes it essentially impossible to ever sue a company for wrongly sharing data under CISPA.” This proposed immunity provision is actually worse than the prior version of the bill, under which companies could be sued if they acted in “bad faith.”
What government agencies can look at my private information?
Under CISPA, companies are directed to hand “cyber threat information” to the Department of Homeland Security (DHS). Once it’s in DHS’s hands, the bill says that DHS can then hand the information to other intelligence agencies, including the National Security Agency, at its discretion.
Can the government use my private information for other purposes besides “cybersecurity” once they have it?
Yes. When the bill was originally drafted, information could be used for all other law enforcement purposes besides “regulatory purposes.” A new amendment narrows this slightly. Now—even though the information was passed along to the government for only cybersecurity purposes—the government can use your personal information for either cybersecurity or national security investigations. And as long as it can be used for one of those purposes, it can be used for any other purpose as well.
Can the government use my private information to go after alleged copyright infringers and whistleblower websites?
Up until last Friday the answer was yes, and now it’s changed to maybe. In response to the overwhelming protest from the Internet community that this bill would become a backdoor for SOPA 2, the bill authors have proposed an amendment that rids the bill of any reference to “intellectual property.”
The bill previously defined “cyber threat intelligence” and “cybersecurity purpose” to include “theft or misappropriation of private or government information, intellectual property, or personally identifiable information.” Now the text reads:
(B) efforts to gain unauthorized access to a system or network, including efforts to gain such unauthorized access to steal or misappropriate private or government information
But it is important to remember that this proposed amendment is just that: proposed. The House has not voted it into the bill yet, so they still must follow through and remove it completely.
A more detailed explanation of how this provision could be used for copyright enforcement and censoring whistleblower sites like WikiLeaks can be read here.
What can I do to stop the government from misusing my private information?
CISPA does allow users to sue the government if they intentionally or willfully use their information for purposes other than what is described above. But any such lawsuit will be difficult to bring. For instance, the statute of limitations for such a lawsuit is two years from the date of the actual violation. It’s not at all clear how an individual would know of such misuse if it were kept inside the government.
Moreover, suing the government where classified information or the “state secrets privilege” is involved is difficult, expensive, and time consuming. EFF has been involved for years in a lawsuit over Fourth Amendment and statutory violations stemming from the warrantless wiretapping program run by the NSA—a likely recipient of “cyber threat information.” Despite six years of litigation, the government continues to maintain that the “state secrets” privilege prevents the lawsuit from being heard.
Given that DHS is notorious for classifying everything—even including their budget and number of employees—they may attempt to prevent users from finding out exactly how this information was ever used. And if the information is in the hands of the NSA and they claim “national security,” then it would get even harder.
In addition, while CISPA does mandate an Inspector General should issue a report to Congress over the government’s use of this information, its recommendations or remedies do not have to be followed.
Why are Facebook and other companies supporting this legislation?
Facebook and other companies have endorsed this legislation because they want to be able to receive information about network security threats from the government. This is a fine goal, but unfortunately CISPA would do far more than that—it would eviscerate existing privacy laws by allowing companies to voluntarily share users’ private information with the government.
Facebook released a statement Friday saying that they are concerned about users’ privacy rights and that the provision allowing them to hand user information to the government “is unrelated to the things we liked about HR 3523 in the first place.” As we explained in our analysis of Facebook’s response: the “stated goal of Facebook—namely, for companies to receive data about cybersecurity threats from the government—does not necessitate any of the CISPA provisions that allow companies to routinely monitor private communications and share personal user data gleaned from those communications with the government.” Read more about why Facebook should withdraw support from CISPA until privacy safeguards are in place here.
What can I do to stop this bill?
It’s vital that concerned Internet users tell Congress to stop this bill. Use EFF’s action center to send an email to your Congress member urging them to oppose this bill.
Related articles
- Worse than SOPA? CISPA to censor Web in name of cybersecurity (alethonews.wordpress.com)
- Facebook defends CISPA support, completely misses the point (digitaltrends.com)
- What You Need to Know About CISPA (readwriteweb.com)
- What Facebook Wants in Cybersecurity Doesn’t Require Trampling On Our Privacy Rights (eff.org)
- Say ‘hello’ to CISPA, it will remind you of SOPA (news.cnet.com)
Israeli military court sentences Palestinian journalist
Palestine Information Center – 16/04/2012
RAMALLAH — The Israeli military court in Ofer passed a four-month imprisonment term against Suhaib Al-Asa, 26, along with 3000 shekels fine.
Aziz, the father of Suhaib Asa, said that the sentence falls in line with the Israeli occupation authority’s constant attacks on the Palestinian people and journalists.
He said that the sentence also reflects the IOA fears of a free press that defends Palestinian rights.
Israeli occupation forces stormed the home of Asa, who works with Bethlehem 2000 radio station and a correspondent for a website, in Obaidiya to the east of Bethlehem on 5 February and took him away after searching his home and confiscating personal computers.
Related articles
- Detained journalist boycotts Israeli military court (alethonews.wordpress.com)
UK: Lib Dems hollow promise on snooping
Press TV – April 9, 2012
In yet another of British Liberal Democrats’ face-saving comments on the government’s proposed snooping laws, the party’s president has pledged to “kill” the bill.
Tim Farron said the Lib Dems “are prepared to kill” the controversial plans but watered down his tough rhetoric saying that will happen if the proposed changes, by their senior coalition partners in the Conservative party, become a “threat to a free and liberal society.”
“But we are prepared to kill them [the plans], be absolutely clear about that, if it comes down to it,” Farron told BBC.
“If we think this is a threat to a free and liberal society then there would be no question of unpicking them or compromising, this just simply must not happen.”
The new legislation proposed by the Home Office will give security services unrestricted access on demand to all web usage, emails, chat logs and telephone calls of any individual.
Lib Dem Deputy Prime Minister Nick Clegg said earlier this month that the government is only to publish the plans “in draft” to ensure the changes face a lengthy delay that would open space for further debate on the details of the legislation.
His stance was crucial to save the face of the party, which opposed similar legislation tabled by the former Labour administration when Lib Dems were in the opposition.
It even triggered civil liberties campaign group Big Brother Watch to welcome a “draft bill” as a “significant climbdown” on the matter.
However, Home Secretary Theresa May undermined Clegg’s comments saying, “I would expect us to be able to do this in a Bill in the next session [of parliament],” that is by the next month.
In the context of May’s remarks, Farron’s talk of Lib Dems killing the bill seems another hollow promise to both please Lib Dem supporters and leave space for the government to push ahead with its snooping wishes.
After all, Farron did make it clear that he sees the “need” to give security services wider control power over the digital world.
“I am prepared to recognise that there is obviously a need in modern society with new technology to have a look at what needs to be given to the security services, but only if it is absolutely clear there is no universal access,” he said.
Farron further cemented the point that Lib Dems’ opposition to the bill will not be unconditional saying they will oppose it only “if we think this is a threat to a free and liberal society.”
He did not explain what exactly constitutes a “free and liberal society.”
He also did not clarify whether Lib Dems will define such a society with the same commitment to liberal principles that they exercised when going back on their election pledge to keep university tuition fees unchanged.

