Showing posts with label Infosec. Show all posts
Showing posts with label Infosec. Show all posts

Tuesday, July 15, 2014

How Not to Stay Neutral on Net Neutrality

Net Neutrality has been an issue of great concern to people who work online. The end of it may likely mean an end to those smaller operations, or new ideas looking for a place to blossom. It has also been of great concern to corporate interests and the Telecomms, who all look to cement their control on what we see and use. It all comes down to how neutral we will see information and services online treated.

FCC after Dark - from College Humor
But the FCC (Federal Trade Commission) is eyeing an end to neutrality. Not surprising from a collective largely made up of former and future executives of the Telecomm Industry. And the head of the FCC thinks it makes perfect sense to end neutrality, but make a caveat that all access must be kept at least at the levels they currently are at.

That would be great if time and technology stood still. But that's the point of the statement from the FCC. Sound good, mean nothing. Throw out a platitude while handing the power, wealth making potential, and speed to their corporate friends.

These Assholes - By College Humor
After that, we are all left to the whims of Internet Service Providers, and to the select online services that have paid up large sums to run suitably. And for many in power, that is how the world should work. You shouldn't have things if you can't pay up a nice size fee for it. Schooling. Water. Knowledge.

Well, that is garbage. The Internet is supposed to be a marketplace of ideas, amusement, and disappointment.


Among those trying to advocate for no neutrality think that not all sites deserve to be treated equal. Money should buy access. The Internet should operate like many other areas of business where the barriers to entry should be high. For many of them, Net Neutrality is a regulation. And that means taxes. And, "The government will control the Internet!!!".

The attitude is that they fear/hate the government, but tolerate/respect the old boy network of corporate elite making decision on this.

I don't, obviously, trust the people at the FCC. We need a better quality of regulator there. But if I have to choose between the power being in the FCC's and the Telecomms grasp, I pick the FCC. Whipping the FCC into shape is easier. And, once industry has it's way with the Internet, we'll have to wait a decade or more to right things.

We rely on regulation by government for a good reason. Industry rarely does a fair to decent job of watching over itself.

Tuesday, April 23, 2013

CISPA: Bad law on bad.

In considering CISPA in the last piece I mentioned SOPA, the last iteration of these efforts to broaden government access and control of personal information. It managed to scare and anger many. And with numerous powerful online and tech interest opposed, it was given a lot of unwanted attention that helped lead to its demise in Congress. 

It was overly broad law. It was bad law. It was unpopular law, with the industrial deep pockets elected figures like to please.

So the lesson the lobbyist and Congressional supporters took away from that fight was to make it more palatable to industry. Nothing else really changed. Bad bill language stayed. Broad powers stayed. It just shows an interesting level of cluelessness.

Now, it was politician smart. They don't want to have to get yelled at by the businesses they rely on for fundraising. So it's a no lose fight to their reelection campaigns.

But this cluelessness does have impact. SOPA would have been bad law, like CISPA before it, and now. But other like law are already on the books. Like CFAA, the Computer Fraud and Abuse Act. This law is outdated 80's law against computer hacking (Hey. Remember all those bad 80's hacking movies? It's that old a law.). But it is badly worded and outdated law. This is the law that was used all too recently to hound a rather young and brilliant civil liberties advocate (and vocal opponent of SOPA) Aaron Schwartz for relatively benign activity. But under this law the DA was trying to put him in prison for decades (Because it was the law...kinda.). (And those efforts sadly led to his suicide.) It was punitive action through bad law.

CFAA is exactly an example about why we do need legislation, new legislation, for cybersecurity. Things do need to change. And PIPA, SOPA, and CISPA are examples of why it has to be GOOD law, SOUND law, and INTELLIGENT law; all things these bills are not. We need change, but these laws based more on paranoia and control will not do the job. Our law crafters have to do better.

CISPA is just too vague in how it will be applied, much like CFAA. It will inevitably be used poorly and people will be made to unfairly suffer. And now before it is law is the time to act. Congress needs to do a better job. Looking at CFAA, even many changes suggested for it focus more on increasing punishments and making the violations of the act a more vague and unclear matter. The legislators making the decisions here are not doing a good. job. They have to do better. We have to make them do better, particularly as all the loud voices with the deep pockets are walking away from the fray. It is up to us.

Get informed. Get involved.


I also wanted to note that in passing CISPA through the House of Representatives, even some good Democratic representatives supported it (like Duckworth). The backers of CISPA are spending a lot and schmoozing a lot to ensure it gets supported. This includes overselling it's national security value. So, I think, it would be a good idea to reach out to your representative in Congress (and contact your senators to) and let them know what you think about CISPA and why you don't want it to pass. We to can make them informed voters (in Congress).
It is likely it won't pass the senate. And the president has said he would veto it. But, as I've pointed out, it will be back. And our representatives need to be ready and understand our concerns when it does. They may even, if informed, be able to amend it to be good law. But it starts with us.



Monday, April 22, 2013

CISPA, And Why People Are Pissed and Scared

CISPA, or Cyber Intelligence Sharing and Protection Act, is a bill that broadly expands the power government and business to share and use information, your information. It is an annoying bill, to say the least. Not in particular because it is one that refuses to stay down. A number of attempts have been made to pass it or similar bill in the last few years. Remember SOPA and PIPA? It's proving worse than a bad movie slasher. Not even a Son of CISPA. (But it is a curse.)

So. It is back, like a bad slasher movie remake (Don't worry. I'm killing these comparisons now.). And like before the idea is to sell it as a beneficent new law meant to help us, and keep us safe. Trouble comes in how it opens up the citizenry to new levels of privacy invasions. If the government says the words "national security", POP!, you're privacy rights and agreements online are no longer valid. (Lifehacker, Verge, and here look some more at the  CISPA bill and it's troubles.)

Here's the bill language.

 What this means is that when the government sees a threat, or deems one is rising, it can request an online provider hand over certain persons data. The provider can then just hand over all of the persons information. And under the new law the provider is protected from any lawsuits for violating promises about protecting personal data. It is all a quick and legal transaction between business and government.

And that is the key to CISPA now. SOPA got industrial opposition (the major business interests) because they were stuck in the middle and open to being held accountable. But now they will be made immune, while the law will still be able to screw the users over. But Twitter, Facebook  etc. will be fine (Phew!). The key thing is that this means these players aren't backing us now. For instance, AT&T and Verizon, along with the Telecom lobbyists, have come out in eager support now of CISPA.

And this is troubling. Troubling for peoples ability to speak freely. Troubling for privacy. Troubling for being able to feel confident in out constitutional rights.

CISPA is a very broadly defined law. It will make it extremely easy to bypass your legal rights. In my previous post I mentioned the Public Safety exemption to the Miranda rights. That currently just bends your constitutional rights. But it creates a future risk. With CISPA, as it is right now, it sets out a way to just disregard parts of the constitution, a constitutional bypass.

No warrants. No courts. No oversight. The American Library Association noted with the last attempt to pass this:

... 
The ALA is concerned that all private electronic communications could be obtained by the government and used for many purposes–and not just for cybersecurity activities. H.R. 3523 would permit, and sometimes even require, Internet service providers and other entities to monitor all electronic communications and share personal information with the government without effective oversight by claiming the sharing is for “cybersecurity purposes.” 
...
It isn't directly meant to be a new spy tool. But it is built so it can be instantly re-purposed as one. And when government is given a tool like this, it tends to find a reason to make use of it, like with the RICO law.


Now we should remember that laws need to be changed and updated. And cyber laws do need to move with the times. But their is a difference between what we need on the books to reasonably protect and serve society and what is just a means to easily control. When is it overreach? Miranda is an inconvenience to law enforcement. But it is a good one. It helps some people get the aid they need to not be abused. The need to get warrants before scouring your personal data is another important protection. This law leaves us vulnerable, while doing to little to actual protect us.


More from the Electronic Frontier Foundation on this.

Fight for the Future - CISPA is Back


Right now. Many people are planning to use today as a CISPA blackout, where they will have no presence online, in protest to the effect this law could have on online activity. I am still deciding whether to do this to (Yes. Based on my clock, I am over the deadline a little already. But time is relative, and it's still Sunday in some of the US still.) I am tempted to. But I am also tempted to see if I can write anything of use tomorrow, focused o this. We'll see.

Still, whether blacked out or not, CISPA is back. And it's passed the House of Representatives. President Obama has indicated he'd VETO it's current form if it passed the Senate. But if he's pressured to do otherwise... Or, if enough support is bought in the Senate, how close would they be to being able to override a veto?


As EFF above asks. Contact your senator now. Be sure they know where you stand, and why you stand there.

Be informed. Be involved. These are your rights.

Thursday, February 12, 2009

Oh, Dianne...

Crooks and Liars is taking note of Sen Dianne Feinstein's work to add a little something to the Stimulus package.

Is Diane Feinstein trying to sneak draconian internet control legislation into the stimulus bill? It sure looks that way.

The Register:

US Senator Dianne Feinstein hopes to update President Barack Obama's $838bn economic stimulus package so that American ISPs can deter child pornography, copyright infringement, and other unlawful activity by way of "reasonable network management."

Clearly, a lobbyist whispering in Feinstein's ear has taken Comcast's now famous euphemism even further into the realm of nonsense.

According to Public Knowledge, Feinstein's network management amendment did not find a home in the stimulus bill that landed on the Senate floor. But lobbyists speaking with the Washington DC-based internet watchdog said that California's senior Senator is now hoping to insert this language via conference committee - a House-Senate pow-wow were bill disputes are resolved.

...

Monday, February 11, 2008

Being Anonymous

RichardDawkins.net are linked to an interesting article looking at a group called Anonymous, that has been hacking and garnering protest against the Church of Scientology. As has been pointed out to the group, Denial of Service attacks and similar acts only gets law enforcement on your back, and gives the real trouble makers the victims and apt to garner sympathy. And that should be the last thing they want.



If you are looking for an understanding of the troubles and concerns over Scientology, or the latest that they are up to try Operation: Clambake and XENU TV.

Monday, January 14, 2008

A story to be thinking about

TPM:
Here's another section from Lawrence Wright's New Yorker piece on Director of National Intelligence Mike McConnell that shouldn't be overlooked. Wright reports on McConnell's Cyber-Security Policy, a plan that "will propose restrictions that are certain to be unpopular....

In order for cyberspace to be policed, Internet activity will have to be closely monitored. Ed Giorgio, who is working with McConnell on the plan, said that would mean giving the government the authority to examine the content of any e-mail, file transfer, or Web search. "Google has records that could help in a cyber-investigation," he said. Giorgio warned me, "We have a saying in this business: 'Privacy and security are a zero-sum game.'" (my emphasis)


With the cyber-security initiative, McConnell is asking the country to confront a dilemma: Americans will have to trust the government not to abuse the authority it must have in order to protect our networks, and yet, historically, the government has not proved worthy of that trust. "FISA reform will be a walk in the park compared to this," McConnell said. "This is going to be a goat rope on the Hill. My prediction is that we're going to screw around with this until something horrendous happens."


After Siobhan Gorman of The Baltimore Sun -- now of The Wall Street Journal -- first broke the story of the Cyber-Security Policy in September, the plan seemed relatively close to completion. But then Democrats on the Hill, namely House Homeland Security Chairman Bennie Thompson (D-MS), demanded to review it before it was launched. Since then, it hasn't been clear how close it is to completion. Wright reports that it's still in "the draft stage." With the FISA debate far from over, it seems likely that the Cyber-Security plan will remain on hold.

We will have to trust the government with maintaining the facade of privacy, hmm? There are a number of serious network threats, from individuals, groups, and nations. But this quiet and covert move to take this control is troubling.

Tuesday, December 11, 2007

An excellent reminder of the state of the stewardship of the nation

AMERCIAblog:

Lives are at risk because the U.S. Food and Drug Administration is woefully behind in the latest scientific advances and is underfunded for its vast responsibilities, an expert panel will tell the FDA on Monday.

...
Yeah...I've known this for years. The FDA and other regulatory bodies are being underfunded. The move to let business regulate itself is sadly a strong one. And haven't the toy makers been making a good go of supporting that argument? As have spinach producers and meat packers.

Regulation is a needed step. Business will rarely regulate itself. Hence the parts of HIPAA that regulate medical service use of patient data, and the FDIC's pull with financial institutions. Hospital and banks would not take the needed steps without the pressure on them to do the right thing. It just is not prudent for business demands.


It is like the current issues with credit cards. The pressure is on getting rates lower for people in debt. Fine. That is good. But what about your digits? The ones in the system, at the stores, in those databases, just sitting there. Are they protected? What are the rules? There are no rules and inadequate protection. Moves in the industry to regulate are slow and whines about. If government stepped in and said, certain cards would no longer be allowed, if changes weren't made, or a chain store would not be allowed to take cards, unless...Well, change and security would sweep in.


With critical industry, we need regulation. And for regulation, funding and support.

In many cases lives are at stake.

But as a liberal I obviously only just want big government.