Showing posts with label Cybersecurity. Show all posts
Showing posts with label Cybersecurity. Show all posts

Tuesday, November 13, 2012

ITU Ill-Suited to Regulate Cybersecurity

The issue of cybersecurity perfectly illustrates why the International Telecommunication Union (ITU) should not be given expanded regulatory authority to include matters of Internet governance. The UN body is meeting this December as Member States renegotiate its core telecommunications treaty, and CDT and others have been warning of the risks to online freedom and innovation. In a paper issued today, we examine in detail some of the proposals pending before the ITU relating to cybercrime and cybersecurity.

On the one hand, cybersecurity is undeniably a critical issue for the future of telecommunications and indeed for global commerce, development, and human rights. On the other hand, it is ill-suited to the kind of centralized, government-dominated policymaking that the ITU represents.

Cybersecurity requires agility: Given the pace of technological change, governmental bodies are not likely to be the source of effective technical solutions. Instead, those solutions will emerge from multi-stakeholder efforts, involving ICT companies, technologists, academics, and civil society advocates, as well as governments.

Moreover, the cybersecurity issue inevitably leads straight into questions of human rights and governmental power: surveillance, privacy, and free expression. None of these are issues the ITU has any expertise in or any ability to assess and balance. Rather than adopting vague wording that could be used by governments as justification for repressive measures, the ITU should endorse existing standards initiatives such as those underway at the IETF and continue to serve as one forum among many for the development of consensus based, private sector-led efforts.


View the original article here

Saturday, November 10, 2012

Will the White House Executive Order on Cybersecurity Look Like CISPA?

White House officials have signaled recently that the President may issue an executive order on cybersecurity to do by administrative fiat some of what Congress has not (yet?) done through legislation. Key Senators have called for the White House to act.

I haven't seen the draft executive order described in this Open Congress blog post or in this Washington Post story.

But, it's important to keep in mind that the three worst parts of CISPA from a privacy perspective were that (i) it drove a bulldozer through all of the privacy statutes by authorizing ISPs to share customer communications information "notwithstanding any law," (ii) empowered companies to share those communications directly with the super secret military-intelligence agency, the NSA, and (iii) allowed the NSA to use the info it received for any national security purpose.

An executive order from the White House couldn't do the first of these, and given the Administration's position on cybersecurity, would probably not do the other two.  It can't drive a bulldozer through the privacy laws because it would need a statutory exception to those laws in order to start the bulldozer. It probably won't do the latter two because it both proposed it's own contrary legislation in May 2011 and endorsed the contrary position in the Lieberman-Collins bill.

An executive order on cybersecurity could make some needed changes that are entirely within the control of government. It could, for example, encourage intelligence agencies to declassify more cyber threat signatures and share them with the private sector, and share more classified threat signatures with cleared network operators. It could require agencies to report when they receive cybersecurity disclosures under existing law from companies in the private sector, and make public the extent of such disclosures.

I don't know what to expect in an Executive Order on cybersecurity, and I don't know whether it will be good or bad for privacy and innovation, but don't expect the White House to attempt to enact a CISPA-like, privacy-invading cybersecurity program through executive order. After all, the White House threatened to veto CISPA, in very strong language, in large part on privacy grounds.


View the original article here

Monday, October 29, 2012

ITU Ill-Suited to Regulate Cybersecurity

The issue of cybersecurity perfectly illustrates why the International Telecommunication Union (ITU) should not be given expanded regulatory authority to include matters of Internet governance. The UN body is meeting this December as Member States renegotiate its core telecommunications treaty, and CDT and others have been warning of the risks to online freedom and innovation. In a paper issued today, we examine in detail some of the proposals pending before the ITU relating to cybercrime and cybersecurity.

On the one hand, cybersecurity is undeniably a critical issue for the future of telecommunications and indeed for global commerce, development, and human rights. On the other hand, it is ill-suited to the kind of centralized, government-dominated policymaking that the ITU represents.

Cybersecurity requires agility: Given the pace of technological change, governmental bodies are not likely to be the source of effective technical solutions. Instead, those solutions will emerge from multi-stakeholder efforts, involving ICT companies, technologists, academics, and civil society advocates, as well as governments.

Moreover, the cybersecurity issue inevitably leads straight into questions of human rights and governmental power: surveillance, privacy, and free expression. None of these are issues the ITU has any expertise in or any ability to assess and balance. Rather than adopting vague wording that could be used by governments as justification for repressive measures, the ITU should endorse existing standards initiatives such as those underway at the IETF and continue to serve as one forum among many for the development of consensus based, private sector-led efforts.


View the original article here

Sunday, October 28, 2012

Will the White House Executive Order on Cybersecurity Look Like CISPA?

White House officials have signaled recently that the President may issue an executive order on cybersecurity to do by administrative fiat some of what Congress has not (yet?) done through legislation. Key Senators have called for the White House to act.

I haven't seen the draft executive order described in this Open Congress blog post or in this Washington Post story.

But, it's important to keep in mind that the three worst parts of CISPA from a privacy perspective were that (i) it drove a bulldozer through all of the privacy statutes by authorizing ISPs to share customer communications information "notwithstanding any law," (ii) empowered companies to share those communications directly with the super secret military-intelligence agency, the NSA, and (iii) allowed the NSA to use the info it received for any national security purpose.

An executive order from the White House couldn't do the first of these, and given the Administration's position on cybersecurity, would probably not do the other two.  It can't drive a bulldozer through the privacy laws because it would need a statutory exception to those laws in order to start the bulldozer. It probably won't do the latter two because it both proposed it's own contrary legislation in May 2011 and endorsed the contrary position in the Lieberman-Collins bill.

An executive order on cybersecurity could make some needed changes that are entirely within the control of government. It could, for example, encourage intelligence agencies to declassify more cyber threat signatures and share them with the private sector, and share more classified threat signatures with cleared network operators. It could require agencies to report when they receive cybersecurity disclosures under existing law from companies in the private sector, and make public the extent of such disclosures.

I don't know what to expect in an Executive Order on cybersecurity, and I don't know whether it will be good or bad for privacy and innovation, but don't expect the White House to attempt to enact a CISPA-like, privacy-invading cybersecurity program through executive order. After all, the White House threatened to veto CISPA, in very strong language, in large part on privacy grounds.


View the original article here

Wednesday, September 26, 2012

Will the White House Executive Order on Cybersecurity Look Like CISPA?

White House officials have signaled recently that the President may issue an executive order on cybersecurity to do by administrative fiat some of what Congress has not (yet?) done through legislation. Key Senators have called for the White House to act.

I haven't seen the draft executive order described in this Open Congress blog post or in this Washington Post story.

But, it's important to keep in mind that the three worst parts of CISPA from a privacy perspective were that (i) it drove a bulldozer through all of the privacy statutes by authorizing ISPs to share customer communications information "notwithstanding any law," (ii) empowered companies to share those communications directly with the super secret military-intelligence agency, the NSA, and (iii) allowed the NSA to use the info it received for any national security purpose.

An executive order from the White House couldn't do the first of these, and given the Administration's position on cybersecurity, would probably not do the other two.  It can't drive a bulldozer through the privacy laws because it would need a statutory exception to those laws in order to start the bulldozer. It probably won't do the latter two because it both proposed it's own contrary legislation in May 2011 and endorsed the contrary position in the Lieberman-Collins bill.

An executive order on cybersecurity could make some needed changes that are entirely within the control of government. It could, for example, encourage intelligence agencies to declassify more cyber threat signatures and share them with the private sector, and share more classified threat signatures with cleared network operators. It could require agencies to report when they receive cybersecurity disclosures under existing law from companies in the private sector, and make public the extent of such disclosures.

I don't know what to expect in an Executive Order on cybersecurity, and I don't know whether it will be good or bad for privacy and innovation, but don't expect the White House to attempt to enact a CISPA-like, privacy-invading cybersecurity program through executive order. After all, the White House threatened to veto CISPA, in very strong language, in large part on privacy grounds.


View the original article here

Tuesday, September 25, 2012

Why Fibbing About Your Age Is Relevant to the Cybersecurity Bill

[Editors Note: This is one in a of series of blog posts from CDT on the Cybersecurity Act, S. 3414, a bill co-sponsored by Senators Lieberman and Collins that is slated to be considered on the Senate floor soon.]  

Congress is about to decide whether it is a crime to violate terms of service governing your use of Gmail, Facebook, Hulu, or any other on-line service.

One of the amendments to the Cybersecurity Act that the Senate is likely to take up this week would substantially increase already severe penalties for violations of the Computer Fraud and Abuse Act (CFAA), an important law designed to prevent malicious computer activity, such as hacking.  The amendment would eliminate provisions setting lower sentences for first time offenders, establish mandatory minimum sentences for many offenders, make computer crimes "racketeering" predicates, and subject homes to civil asset forfeiture for computer crimes committed inside.  The problem is, there is widespread agreement that the statute is already overly broad, sweeping in common online conduct, and the Department of Justice has interpreted it in a way that turns many – maybe most – Internet users into potential criminals.

A fix has been proposed, but the Justice Department is opposing it.  The DOJ wants all the enhanced penalties, without narrowing the scope of the bill to focus on true hacking.

The CFAA makes it a crime to use a computer "in excess" of "authorization." This has been read to mean that it is illegal to use a computer in a manner that violates contractual agreements.  People regularly use websites with broad and ambiguous "Terms of Service" prohibitions, and violations of terms of service are commonplace.  For example, Gmail's Terms of Service bar users younger than age 13, but there is little doubt that thousands of pre-teens lie about their age so they can use Gmail.  Under the reading of the Justice Department, they are all criminals and should be subject to the law's harsh penalties.

As another example, the 150 million users of Facebook in the U.S. agree to a Statement of Rights and Responsibilities that ban:

•    Accessing someone else's Facebook account, even with their permission
•    Sharing your Facebook password, or letting anyone else access your account
•    Posting any false personal information on Facebook
•    Using Facebook "to do anything malicious"
•    Using Facebook "to do anything misleading"

Any of these actions would constitute a computer use that is in excess of authorization.  As such, in the view of the Department of Justice, each action is a candidate to prosecuted as a federal crime punishable by a fine, asset forfeiture, or prison time.  

Fortunately, lawmakers are attempting correct this problem, and ensure that Americans cannot be charged with a felony for actions that merely violate a website's Terms of Service.  In September, the Senate Judiciary Committee adopted unanimously an amendment by Senators Grassley (R-IA), Franken (D-MN) and Lee (R-UT) to fix the statute so that most terms of service violations are not CFAA crimes.  Organizations and individuals from across the philosophical spectrum endorsed their amendment.  

The Grassley/Franken/Lee language has been incorporated into the larger CFAA amendment mentioned earlier, which Senator Patrick Leahy has proposed to the Cybersecurity Act, soon to be taken up by the Senate.

Weighing in on the issue are a group of individuals and organizations from across the philosophical spectrum; CDT is among that group. The group sent a letter today to Senate leadership highlighting the flaws noted earlier and asking that, should the Leahy CFAA come to a vote, that it include the Grassley/Franklin/Lee provisions, which they called "an important step forward for security and civil liberties."

However, the Justice Department is trying to strip out the common-sense amendment of Senators Grassley, Franken and Lee.  The CFAA is an important law, but Congress should make sure that it does not criminalize fibbing about your age on the Internet.


View the original article here

Sunday, September 23, 2012

ITU Ill-Suited to Regulate Cybersecurity

The issue of cybersecurity perfectly illustrates why the International Telecommunication Union (ITU) should not be given expanded regulatory authority to include matters of Internet governance. The UN body is meeting this December as Member States renegotiate its core telecommunications treaty, and CDT and others have been warning of the risks to online freedom and innovation. In a paper issued today, we examine in detail some of the proposals pending before the ITU relating to cybercrime and cybersecurity.

On the one hand, cybersecurity is undeniably a critical issue for the future of telecommunications and indeed for global commerce, development, and human rights. On the other hand, it is ill-suited to the kind of centralized, government-dominated policymaking that the ITU represents.

Cybersecurity requires agility: Given the pace of technological change, governmental bodies are not likely to be the source of effective technical solutions. Instead, those solutions will emerge from multi-stakeholder efforts, involving ICT companies, technologists, academics, and civil society advocates, as well as governments.

Moreover, the cybersecurity issue inevitably leads straight into questions of human rights and governmental power: surveillance, privacy, and free expression. None of these are issues the ITU has any expertise in or any ability to assess and balance. Rather than adopting vague wording that could be used by governments as justification for repressive measures, the ITU should endorse existing standards initiatives such as those underway at the IETF and continue to serve as one forum among many for the development of consensus based, private sector-led efforts.


View the original article here

Cybersecurity Amendments Would Modernize 25-Year-Old Privacy Law

[Editors Note: This is one in a of series of blog posts from CDT on the Cybersecurity Act, S. 3414, a bill co-sponsored by Senators Lieberman and Collins that is slated to be considered on the Senate floor soon.]

Two amendments to the Senate cybersecurity bill now being debated would require government agents to get a warrant before reading a person's email or secretly tracking someone through their mobile phone.  The amendments, if adopted, would be a huge privacy gain and address a long-standing civil liberties goal of modernizing the Electronic Communications Privacy Act, the 25-year old law setting rules for when government agents can access our electronic communications and other private data.
The amendments, one from Senator Leahy and another from Senator Wyden, would implement reforms sought by a diverse coalition from across the political spectrum.  Supporters include AT&T, Google, the ACLU, Americans for Tax Reform, EFF, and IBM, among others.
Including these reforms in the Cybersecurity Act is appropriate:  the information sharing, monitoring and countermeasures provisions of the bill all effectively amend ECPA and the Wiretap Act, permitting companies to share user information notwithstanding privacy protections in those laws.  Congress should strengthen the underlying laws to counterbalance these changes.

ECPA Reform Is Long Overdue

The amendments respond to the dramatic technological changes in the 25 years since ECPA became law. Digital communications services are now ubiquitous in modern life. The government has a huge appetite for the data generated when we use the Internet and our mobile phones.  Last year, government agencies made over 1.3 million demands for text messages, location data and other information about mobile subscribers alone.

ECPA was forward-looking when adopted.  Court decisions of this outdated law now create a crazy patchwork of rules for government collection of communications and location data. This lack of clarity serves no one. It confuses users and law enforcement, as well as the companies in the middle that have to respond to government demands while protecting users. One federal appeals court has held part of the statute unconstitutional.  

Leahy Amendment

The Leahy amendment requires government agents to get a search warrant, based on probable cause, before they are allowed access to the content of users' private communications or documents stored "in the cloud," except in some circumstances.

Americans today routinely use some sort of electronic communication for confidential correspondence ranging from business deals to personal letters. Most people save their emails indefinitely, with much of the data stored on the computers of communications service providers.  Tens if not hundreds of millions of people store calendars, draft documents, private photos and videos online.  Senator Leahy's amendment would eliminate the outdated rule in ECPA that permits the government read someone's stored documents and email without a warrant.

The Leahy amendment also would cure a constitutional defect in ECPA.  In December 2010, the Sixth Circuit ruled in U.S. v. Warshak that the provision of ECPA allowing the government to access email over 180 days old with a subpoena is unconstitutional.  In response, many providers – including providers in other court circuits – now require a warrant before granting law enforcement access to communications content. By requiring warrants for content, Senator Leahy's amendment would make the law clearly constitutional and put companies and prosecutors back on firm legal footing.

The amendment also modifies the Video Privacy Protection Act to make it easier for online video services to get consent from consumers to share data about movie rentals. A similar tweak was adopted last year in the House of Representatives.

A diverse coalition of groups and companies supports the Leahy amendment.

Wyden Amendment

The cell phones that we carry with us all the time are tracking devices. Even when no call is being made, mobile devices placed in pockets, purses and on night stands constantly signal their location to service providers. The government is increasingly collecting location data from service providers in order to track citizens. GPS is only a part of this invasive surveillance:  data indicating which cell towers a device is near at any given time can be readily available to the government.

Senator Wyden's amendment would require a warrant if the government wants to track someone using that person's mobile phone, except in emergencies or when a person calls 911. The amendment mirrors the GPS Act introduced in both the House and the Senate by a bipartisan group of lawmakers, introduced last year. Under Wyden's amendment, the government would need a court-approved warrant, based on probable cause, to obtain information about a person's location that is generated by use of a mobile device such as a cell phone. Similar to Senator Leahy's amendment, Wyden's location amendment would replace complex and constitutionally-suspect rules with a clear warrant requirement.

Senator Wyden's location tracking amendment would also implement a reform supported by companies, trade associations, and groups from across the political spectrum. 


View the original article here