Showing posts with label CISPA. Show all posts
Showing posts with label CISPA. Show all posts

Friday, October 12, 2012

Panetta: CISPA necessary to avert “Cyber-Pearl Harbor”


US Defense Secretary Leon Panetta (AFP Photo / Thierry Charlier)

Source: Russia Today
http://rt.com/usa/news/cyber-pearl-harbor-us-238/

The US faces widespread hacking attacks that could result in a “Cyber-Pearl Harbor,” Leon Panetta said. He invoked the greatest military disaster in US history to make the case for the CISPA bill, roundly criticized for violating privacy laws.

In light of this “pre-9/11 moment,” the US should act preemptively to protect “national interests in cyberspace,” the US Secretary of Defense said.

“A Cyber-Pearl Harbor that would cause physical destruction and the loss of life, an attack that would paralyze and shock the nation and create a profound new sense of vulnerability,” Panetta said during a speech at the Intrepid Sea, Air and Space Museum in New York. He claimed that cyber-attackers had developed new technologies that could knock out entire city power grids, derail trains and contaminate water supplies.

Panetta branded China, Russia and Iran, along with extremist military groups, the greatest cyber-threats to the US.

“An aggressor nation or extremist group could use these kinds of cyber tools to gain control of critical switches,” Panetta said. “They could derail passenger trains, or even more dangerous, derail passenger trains loaded with lethal chemicals.”

He did not elaborate on details about where or how these cyber-strikes would occur.

According to Panetta, the only way to effectively “protect the US democracy” is to pass a cybersecurity bill in Congress that enables the sharing of private information between companies and the government.

The US Senate voted against the Cyber Intelligence Sharing and Protection (CISPA) legislation amid complaints that it gravely violated personal freedoms and could be used to spy on citizens.

Despite the widespread opposition, the Obama administration said it would sign an executive order effectively forcing companies to instate new cybersecurity standards.

Mr. Panetta claimed the laws would not violate people’s rights or liberties, “but if there is a code, if there’s a worm that’s being inserted, we need to know when that’s happening,” he told the New York Times prior to his speech.
­

‘Defense alone is not enough’

“If we detect an imminent threat of attack that will cause significant physical destruction in the United States or kill American citizens, we need to have the option to take action against those who would attack us, to defend this nation when directed by the president,” Panetta said during the speech.

To this end, the US invested significant funds and research into developing techniques to pinpoint the origin of cyber-attacks, with the aim of striking preemptively in the name of “national cyber-security,” he said.

“There is no substitute for comprehensive legislation, [but] we need to move as far as we can in the meantime,” Panetta said. “We have no choice because the threat we face, as I’ve said, is already here.”

According to media reports, the US played a major part in the development of the Stuxnet and Flame viruses that attacked Iran’s nuclear program and extracted classified information.

The White House also confirmed that hackers linked to the Chinese government mounted a cyber-attack in October. The ‘spear-phishing’ attempt struck an unclassified network and failed to extract valuable data, although such attacks are “not infrequent,” officials said.

 

Friday, April 27, 2012

CISPA passes House in unexpected last-minute vote


AFP Photo / Paul J. Richards

Source: Russia Today
http://rt.com/news/house-cispa-vote-thursday-083/

The House of Representatives has approved Cyber Intelligence Sharing and Protection Act with a vote count of 248-168. The bill is now headed for the Senate. President Barack Obama will be able to sign or cancel it pending Senate approval.

Initially slated to vote on the bill Friday, the House of Representatives decided to pass Cyber Intelligence Sharing and Protection Act (CISPA) Thursday after approving a number of amendments.

Apart from cyber and national security purposes, the bill would now allow the government to use private information obtained through CISPA for the investigation and prosecution of “cybersecurity crime,” protection of individuals and the protection of children. The new clauses define “cybersecurity crime” as any crime involving network disruption or hacking.

“Basically this means CISPA can no longer be called a cyber security bill at all. The government would be able to search information it collects under CISPA for the purposes of investigating American citizens with complete immunity from all privacy protections as long as they can claim someone committed a 'cybersecurity crime.' Basically it says the Fourth Amendment does not apply online, at all,” Techdirt's Leigh Beadon said.

Declan McCullagh, correspondent from CNET News, says CISPA will cause more trouble than is immediately apparent.

“The most controversial section of CISPA is the language – that notwithstanding any other portion the of law, companies can share what they want as long as it’s for what they call a ‘cyber security purpose,'" he told RT.

The CISPA battleground in numbers

CISPA was introduced in the House last November. Critics chided the bill, saying its broad wording could allow the government to spy on individual Internet users and block websites that publish vaguely defined ‘sensitive’ data.

"[CISPA] doesn’t really have any protections against cyber threats, all it does is make people share their information. But that’s not going to solve the problem. What’s going to solve the problem is actual security measures, protecting the service in the first place, not spying on people after the fact," Internet activist Aaron Swartz told RT.

The White House issued a statement Wednesday saying President Barack Obama would be advised to veto the bill if he receives it. The Obama administration denounces the proposed law for potentially giving the government cyber-sleuthing powers that would allow both federal authorities and private businesses to sneak into inboxes and online activities in the name of combating Internet terrorism tactics.

We asked our Twitter followers what they think of CISPA's possible adoption into law – and they don't seem happy.


Earlier, the House of Representatives and Senate also considered adopting the Stop Online Piracy Act (SOPA) and Protect IP Act (PIPA). These bills sought to entitle the US government to curb access to “rogue websites” that illegally hosted intellectual property. The bills could effectively force search engines to remove these websites from search results, an action many private companies considered intrusive.

PIPA and SOPA were opposed by many Internet giants including Google, Mozilla, Facebook, Yahoo!, Wikipedia and Reddit. Google organized a petition against the legislation, while Wikipedia held a 24-hour blackout to protest the bill in January. As a result, SOPA was recalled while PIPA was postponed indefinitely.

However, CISPA was actually backed by Facebook, despite its opposition to SOPA and PIPA. In a blog post on April 13, Joel Kaplan, Vice President of US Public Policy at Facebook, argued that if enacted into law, the bill would “give companies like ours the tools we need to protect our systems and the security of our users’ information, while also providing those users confidence that adequate privacy safeguards are in place.”

A number of big companies, including AT&T, Microsoft, Boeing, Verizon and Oracle have also supported CISPA


CISPA: Patriot Act for the web’ – Internet activist






AFP Photo / David Gannon

Source: Russia Today
http://rt.com/usa/news/cispa-patriot-web-swartz-081/

With the House of Representatives' approval of the controversial CISPA bill, Internet users are worried about possible consequences. RT spoke to Internet activist Aaron Swartz, who said CISPA could be used to spy on people.

RT: Can you explain the difference between this legislation and the previous controversial bills aimed at combating piracy?

Aaron Swartz: The previous bills were about giving the government the power to censor the Internet. And this is more like a Patriot Act for the Internet. It sort of lets the government run roughshod over privacy protections and share personal data about you, take it from Facebook and Internet providers and use it without the normal privacy protections that are in the law.

RT: So as far as individuals are concerned, is it worse than the previous ones?

AS: Yes, it’s worse because it does allow the government to shut down websites for ‘national security' reasons. It does have all the censorship problems the previous bill did. But it also goes much further and allows them to spy on people using the Internet, to get their personal data and e-mails. It’s an incredibly broad and dangerous bill.

RT: It’s not popular amongst Internet users, but it is popular with big companies like Facebook, IBM, and Microsoft – they’re backing CISPA. How can protesters compete with major corporations and companies like that?

AS: Well, it’s true. Big corporations are supporting the bill, especially big corporations that make money off of violating people's privacy. So it’s not a big surprise they’re in favor. But we’re seeing that the same way grassroots efforts were able to stop SOPA – despite millions of dollars of Hollywood lobbyists behind it – are now also being able to stop this bill. I mean everyone said, this is just a consensus in Washington, you couldn’t do anything. And now, even the White House is coming out against this bill with strong language, much stronger than they used against SOPA.

RT: The Obama administration is planning to veto the bill despite the fact that over two hundred in Congress are supporting it. Is this more about political point-scoring or preserving online privacy?

AS: I think the White House is obviously interested in repairing its reputation. But I think there are some people in the White House who really do care about privacy. The fact is, when they looked at this bill and investigated it, they saw how incredibly bad it was and that forced them to speak out.

RT: This bill, though, at the end of the day is meant to enforce cyber security and prevent threats. If these are real threats, then surely the US does need something to safeguard against them. What’s your alternative?

AS: Well the thing about this bill is it doesn’t really have any protections against cyber threats, all it does is make people share their information. But that’s not going to solve the problem. What’s going to solve the problem is actual security measures, protecting the service in the first place, not spying on people after the fact. So what I’d like to see is what a bunch of security experts have proposed – a bill that really does secure computer systems, makes them harder to attack, rather than one that involves more spying and watching people.

RT: Across Europe, we’ve seen thousands come out to protest the planned global Anti-Counterfeiting Trade Agreement, or ACTA. But depending on Friday’s vote in Congress, do you expect the same kind of response in the US over CISPA?

AS: We’ve already seen quite an outcry. I don’t think it’s going to be on the level we’ve seen in other countries. Almost a million people have signed a petition on the Internet. Many representatives have spoken out against it. This is a tougher fight, no question, because it’s harder to go up against this notion of cyber terrorism that they’re using. But I think we’re making a lot of progress and I think we’ll see the bill eventually defeated.

CISPA was introduced in the House of Representatives last November by Mike Rogers (R-MI) and has since been amended on a number of occasions. Numerous critics, including World Wide Web founder Tim Bernars-Lee and Representative Ron Paul, continue to criticize its overly broad wording, which would permit private companies to submit personal user data to the government.

Congress had previously failed to approve SOPA and PIPA, which sought to bar access to websites containing illegally published copyrighted information. The bills were shelved in January, after a day of protests by major Internet companies, during which Wikipedia and Reddit among others remained inaccessible for 24 hours.

An international equivalent of SOPA and PIPA, ACTA was signed by eight countries plus the EU and all of its members. However, the agreement was met with a bevy of protests throughout Europe and has so far not been ratified by any country


Wednesday, April 4, 2012

Even worse than SOPA: New CISPA cybersecurity bill will censor the Web





Source: Russia Today
http://rt.com/usa/news/cispa-bill-sopa-internet-175/

An onrush of condemnation and criticism kept the SOPA and PIPA acts from passing earlier this year, but US lawmakers have already authored another authoritarian bill that could give them free reign to creep the Web in the name of cybersecurity.

As congressmen in Washington consider how to handle the ongoing issue of cyberattacks, some legislators have lent their support to a new act that, if passed, would let the government pry into the personal correspondence of anyone of their choosing.

H.R. 3523, a piece of legislation dubbed the Cyber Intelligence Sharing and Protection Act (or CISPA for short), has been created under the guise of being a necessary implement in America’s war against cyberattacks. But the vague verbiage contained within the pages of the paper could allow Congress to circumvent existing exemptions to online privacy laws and essentially monitor, censor and stop any online communication that it considers disruptive to the government or private parties. Critics have already come after CISPA for the capabilities that it will give to seemingly any federal entity that claims it is threatened by online interactions, but unlike the Stop Online Privacy Act and the Protect IP Acts that were discarded on the Capitol Building floor after incredibly successful online campaigns to crush them, widespread recognition of what the latest would-be law will do has yet to surface to the same degree.

Kendall Burman of the Center for Democracy and Technology tells RT that Congress is currently considering a number of cybersecurity bills that could eventually be voted into law, but for the group that largely advocates an open Internet, she warns that provisions within CISPA are reason to worry over what the realities could be if it ends up on the desk of President Barack Obama. So far CISPA has been introduced, referred and reported by the House Permanent Select Committee on Intelligence and expects to go before a vote in the first half of Congress within the coming weeks.

“We have a number of concerns with something like this bill that creates sort of a vast hole in the privacy law to allow government to receive these kinds of information,” explains Burman, who acknowledges that the bill, as written, allows the US government to involve itself into any online correspondence, current exemptions notwithstanding, if it believes there is reason to suspect cyber crime. As with other authoritarian attempts at censorship that have come through Congress in recent times, of course, the wording within the CISPA allows for the government to interpret the law in such a number of degrees that any online communication or interaction could be suspect and thus unknowingly monitored.

In a press release penned last month by the CDT, the group warned then that CISPA allows Internet Service Providers to “funnel private communications and related information back to the government without adequate privacy protections and controls.

The bill does not specify which agencies ISPs could disclose customer data to, but the structure and incentives in the bill raise a very real possibility that the National Security Agency or the DOD’s Cybercommand would be the primary recipient,” reads the warning.

The Electronic Frontier Foundation, another online advocacy group, has also sharply condemned CISPA for what it means for the future of the Internet. “It effectively creates a ‘cybersecurity'’ exemption to all existing laws,” explains the EFF, who add in a statement of their own that “There are almost no restrictions on what can be collected and how it can be used, provided a company can claim it was motivated by ‘cybersecurity purposes.’”

What does that mean? Both the EFF and CDT say an awfully lot. Some of the biggest corporations in the country, including service providers such as Google, Facebook, Twitter or AT&T, could copy confidential information and send them off to the Pentagon if pressured, as long as the government believes they have reason to suspect wrongdoing. In a summation of their own, the Congressional Research Service, a nonpartisan arm of the Library of Congress, explains that “efforts to degrade, disrupt or destroy” either “a system or network of a government or private entity” is reason enough for Washington to reach in and read any online communiqué of their choice.

The authors of CISPA say the bill has been made “To provide for the sharing of certain cyber threat intelligence and cyber threat information between the intelligence community and cybersecurity entities,” but not before noting that the legislation could be used “and for other purposes,” as well — which, of course, are not defined.

“Cyber security, when done right and done narrowly, could benefit everyone,” Burman tells RT. “But it needs to be done in an incremental way with an arrow approach, and the heavy hand that lawmakers are taking with these current bills . . . it brings real serious concerns.”

So far CISPA has garnered support from over 100 representatives in the House who are favoring this cybersecurity legislation without taking into considerations what it could do to the everyday user of the Internet. And while the backlash created by opponents of SOPA and PIPA has not materialized to the same degree yet, Burman warns Congress that it could be only a matter of time before concerned Americans step up to have their say.

“One of the lessons we learned in the reaction to SOPA and PIPA is that when Congress tries to legislate on things that are going to affect Internet users’ experience, the Internet users are going to pay attention,” says Burman. H.R. 3523, she cautions, “Definitely could affect in a very serious way the internet experience.” Luckily, adds Burman, “People are starting to notice.” Given the speed that the latest censorship bill could sneak through Congress, however, anyone concerned over the future of the Internet should be on the lookout for CISPA as it continues to be considered on Capitol Hill.

ICJ delivers ruling in favour of South Africa

South Africa's Closing Argument Against Israel for Genocide at the ICJ