HomeUSPoliticsAmendments to CISA Cybersecurity Bill Fail in All Regards

Amendments to CISA Cybersecurity Bill Fail in All Regards

MARK JAYCOX | EFF

Although grassroots activism has dealt it a blow, the Senate Intelligence Committee’s Cybersecurity Information Sharing Act (CISA) keeps shambling along like the zombie it is. In July, Senator McConnell vowed to hold a final vote on the bill before Congress left for its six-week long summer vacation. In response, EFF and over 20 other privacy groups ran a successful Week of Action, including over 6 million faxes opposing CISA, causing the Senate to postpone the vote until late September.

Senators submitted many amendments to the bill before going on vacation. The amendments, like the original language of the bill, fail to address key issues like the deep link between these government “cybersecurity” authorities and surveillance, as well as the new spying powers the bill would grant to companies.

But “cybersecurity” is already intimately tied to surveillance—a problem CISA would only worsen. Documents released by the New York Times reveal the government used the Comprehensive National Cyber Security Initiative (CNCI) to pay telecommunications companies to spy on consumers using their networks. The CNCI includes initiatives for information gathering, but it’s always been presented to the public as fostering research and encouraging public awareness of cybersecurity problems—not spying on Americans’ Internet traffic.

The revelations are stunning. The NSA paid telecommunications companies nearly $300 million dollars in the 2010 fiscal year to invest in surveillance equipment as part of the CNCI. In fact, STORMBREW’s Breckenridge site was “100% subsidized with CNCI funding.”

In contrast, the DHS only requested $37.2 million during the same time period to support research and development in cybersecurity science and technology. Even if DHS received what it requested, does the American public really want surveillance to outweigh research and education 10 to 1?

The news is compounded by other recently-released Snowden documents that show how the NSA uses foreign intelligence laws to run an intrusion defense system (IDS) on US soil. The documents show that a Justice Department memo gave the agency permission to monitor Internet cables, “without a warrant and on American soil, for data linked to computer intrusions originating abroad — including traffic that flows to suspicious Internet addresses or contains malware.”

CISA—and its amendments—do not even begin to address these serious problems. Instead, they mandate information sharing with the intelligence community, creating even more cyberspying.

EFF will continue to oppose CISA—even if some of these amendments pass—because CISA’s vague definitions, broad legal immunity, and new spying powers allow for a tremendous amount of unnecessary damage to users’ privacy, and it’s highly unlikely that the public will learn about it. Even an amendment (#2612) offered by by Senator Al Franken, which narrows some of the definitions in CISA, does little to clarify its most troubling provisions.

What’s worse is that information-sharing bills like CISA are being painted as silver bullets to data breaches. They aren’t. The bills don’t address problems like unencrypted filespoor computer architecture, un-updated servers, and employees (or contractors) clicking malware links.

Awful Amendments

Plenty of the amendments would make the bill even worse. We’ve already discussed the horrible CFAA amendment, #2626, proposed by Senator Sheldon Whitehouse. The amendment not only increases the scope of the already expansive Computer Fraud and Abuse Act (CFAA) but also authorizes injunctions against botnets (amending 18 U.S.C. § 1345) in a way that creates serious constitutional issues.  After all, much of what DOJ and FBI want to do in shutting down botnets is, arguably, a search or a seizure under the Fourth Amendment; moreover, such injunctions may prevent users from communicating, thus raising First Amendment issues.  The amendment is a great example of how not to amend the draconian CFAA. If the Senate wants to improve the CFAA, it should take a page out of our book.

Senator Carper has proposed another dubious change to CISA, amendment #2627. The bill attempts to codify the Department of Homeland Security’s EINSTEIN program without any public debate. EINSTEIN is an intrusion detection system—the parent of which was created by the NSA—to scan incoming Internet traffic to the federal government like emails and other connections. DHS has not told the public what agencies are using EINSTEIN. It’s possible that when you email your representative, DHS may also receive a copy. Before codifying EINSTEIN, DHS must be more transparent about the program. The most recent update from DHS about the program is from 2013, and many concerns have been raised about EINSTEIN’s legality and privacy implications. Unlike CISA, Senator Carper’s amendment mandates federal agencies create a plan to identify sensitive information and encrypt it; however, the clause exempts the Department of Defense and the intelligence community.  Nor does the amendment authorize additional funding for federal agencies to improve security.

Senator Carper’s attempt to make a horrible bill marginally better is admirable, but he—along with other Senators—should oppose the bill. Even the best amendments fail to fix CISA’s serious flaws.

Not Awful Amendments

Some of the amendments try to narrow the scope of the bill. Senator Chris Coons’ amendment #2552 would limit information sharing to that necessary to describe or identify a cybersecurity threat, while Senator Wyden’s amendment (#2621) would require companies and the government to remove personal information unrelated to the threat.

But these well-meaning changes don’t address the root problems in the bill: the outrageously broad and vague definition of “cybersecurity threat” and the granting of new authorities to spy on users. Senator Franken’s amendment #2612 attempts to address that definition, but even his amendment isn’t enough. Again, no amendment scales back the two new authorities to spy on users and launch countermeasures in the bill.

Other amendments are better, including Senator Patrick Leahy’s #2587, which would remove the current CISA provision exempting all “cyber threat indicators and defensive measures” received by the government from disclosure under the Freedom of Information Act and may help ensure the public can obtain information about how, if CISA is enacted into law, the information “sharing” system actually operates; Senator Jeff Flake’s 6-year sunset (#2582); and, Senator Mike Lee’s email privacy amendment (#2556), which would codify US v. Warshak by amending the Electronic Communications Privacy Act to require warrants for email and other stored content.

While some advocates will paint these amendments as “steps forward,” the amendments merely shuffle deck chairs on the Titanic—even with the better amendments, the bill is still a bad idea. The Senators are going about the wrong strategy. Democrats and libertarian Republicans should be opposing CISA outright. That’s why we’re asking users to continue emailing their Senators to stop this bill. While CISA is the very definition of a zombie bill, the public outcry against it has made a difference. But we can’t stop now. Join us by tweeting, faxing, or emailing your Senator.

Source: EFF

Most Popular

Recent Comments

Toddy Littman on Coronavirus & Dr. Rife
jimjfox on The Islamic Scam
USAPATRIOT✓ on Coronavirus & Dr. Rife
Dumb Bass Fisherman on The Disgrace of Benghazi
Dumb Bass Fisherman on Prosecute Biden the Crook!
Dumb Bass Fisherman on The Disgrace of Benghazi
Christan on Who is Nasim Aghdam?
FarvingStartist on
Swampmom on Stubborn Syria
OhSoGood on SHOCKING Media LIES
Pbranham on
Pbranham on
Fay Butler on Lawfare, living in fear
John Cunningham on The Media and Trump at 100 Days
steve smith on
Worried on
Insanity Personified on
no mo uro on
no mo uro on
Patriotjeff on
OhSoGood on
Steve on
lovelydestruction on
Val Cocora on
Jerry Kenney on
Merlinever on
Phill Crapidy on
Clifford Ishii on
Americanmommy on
Doctor Fine on
reggiec on
DeltamanH20 on
Ms. warrior4Christ on
Comrade Molotov on
reggiec on
JEANNIEMAC2 on
Average Punter on
shamm86 on
Rich on
ort on
Lee Sargeant on
Lee Sargeant on
jcarroll4415 on
Erroldean Andrews on
charles becker on
David Miller on
charles becker on
Sophia Emma on March4Trump
UR.carrion on The Islamic Scam
pbr90 on
John Cornel Kovach on Should Islam Be Banned from America?
Lane Wingham on Rituals of Islam
Lane Wingham on Rituals of Islam
Taylor Crystaloski on Rituals of Islam
lamarlamar on California Dreaming
usaok59 on Smearing Sessions
b.a. freeman on True Islam vs Pseudo Islam
b.a. freeman on True Islam vs Pseudo Islam
Randy McDaniels on True Islam vs Pseudo Islam
Mohammad Izzaterd on True Islam vs Pseudo Islam
Bikinis not Burkas on True Islam vs Pseudo Islam
John Cornel Kovach on Should Islam Be Banned from America?
paramore309 on
Anthony Duhe on
Anthony Duhe on
Dianna9490 on
Guest✓ᵛᵉʳᶦᶠᶦᵉᵈ on Dana Rohrabacher for Secretary of State
Guest✓ᵛᵉʳᶦᶠᶦᵉᵈ on Dana Rohrabacher for Secretary of State
Abu Mohamed on
wellilltellya on The Obama Era is Over
Dianna9490 on The Obama Era is Over
reggiec on Democratic Panic
Tony Donaldson on Why Trump Will Prevail
Charlotte W on Why Trump Will Prevail
Bubba Gump on Why Trump Will Prevail
bas h on
Dianna9490 on Weaponized Immigration
Dianna9490 on Charlotte Burning
Tony Donaldson on Hillary Clinton: Basket Case
SuperDave2 on The Islamic Scam
Truthorlie on Hillary’s Race War
Proud Amelekite on We are in the End of Days
EarthCitizenNumberOne on George Soros’s Open Border Foundations
EarthCitizenNumberOne on George Soros’s Open Border Foundations
Sgt Saunders on We are in the End of Days
Proud Amelekite on We are in the End of Days
Proud Amelekite on We are in the End of Days
Saputra 007 on We are in the End of Days
Kevan Massey on We are in the End of Days
Bonnie Wolf on We are in the End of Days
Bruce Peters on We are in the End of Days
David Collins on We are in the End of Days
Monte Noffsinger on We are in the End of Days
Proud Amelekite on We are in the End of Days
Eddie Clever on The Flying Clintons
jackcandobutwont on
TSM on
Tee Quake on Born in America
shamm86 on Born in America
seersuckerandapanama on The Coming US/Mexico War
Sgt Saunders on Would Jesus Bomb Hiroshima?
michaelhayes on Would Jesus Bomb Hiroshima?
Roberta Dzubow on MUST READ: The Twisting Noose
danstewart on Why Trump Chickened Out
Uzoozy on Paul Ryan's Hijra
JEANNIEMAC2 on Importing Terror
JEANNIEMAC2 on Insane Muslim Terrorists
"The Eastern Diamondback" on King Barack the Lawless Endangers Girls
Jeff Tangen on The Cults of Islam
Joe on
amyinnh on
David Gearhart on Sex Slavery by the Numbers
David Gearhart on Sex Slavery by the Numbers
Uzoozy on The Cults of Islam
Uzoozy on The Cults of Islam
GregAbdul on The Cults of Islam
Sgt Saunders on The Cults of Islam
Uzoozy on The Cults of Islam
Uzoozy on The Cults of Islam
charles becker on American Outlaws!
GregAbdul on The Cults of Islam
GregAbdul on The Cults of Islam
Uzoozy on The Cults of Islam
Uzoozy on The Cults of Islam
Uzoozy on The Cults of Islam
GregAbdul on The Cults of Islam
Uzoozy on The Cults of Islam
Uzoozy on The Cults of Islam
Uzoozy on The Cults of Islam
GregAbdul on The Cults of Islam
GregAbdul on The Cults of Islam
Uzoozy on The Cults of Islam
smacready on The Cults of Islam
Uzoozy on The Cults of Islam
Uzoozy on The Cults of Islam
smacready on The Cults of Islam
Uzoozy on The Cults of Islam
Uzoozy on The Cults of Islam
Uzoozy on The Cults of Islam
TheBucko on The Cults of Islam
TheBucko on The Cults of Islam
smacready on The Cults of Islam
smacready on The Cults of Islam
smacready on The Cults of Islam
smacready on The Cults of Islam
smacready on The Cults of Islam
smacready on The Cults of Islam
GregAbdul on The Cults of Islam
GregAbdul on The Cults of Islam
Robin Morgan on The Cults of Islam
bob250 on The Cults of Islam
SEARING JW TRUTH on The Cults of Islam
Uzoozy on The Cults of Islam
Winston Lawrence on The Satanic Bible's 'Golden Rule'
SEARING JW TRUTH on The Cults of Islam
smacready on The Cults of Islam
sherri palmer on
John Cunningham on Jihad in Brussels
Sebastian Medina on The Coming US/Mexico War
sherri palmer on
BobWhiteRevisited✓ᴺᵃᵗᶦᵒᶰᵃˡᶦˢᵗ on Why I Stump for Trump
sherri palmer on
Kevin Alfred Strom on Support for Trump Backfires on CPAC
marlene on
marlene on
DC on
DC on
Ike_Kiefer on
sherri palmer on
sherri palmer on
Christopher Strunk on Is Trump a Sleeper Agent for Moscow?
Christopher Strunk on Is Trump a Sleeper Agent for Moscow?
usaok59 on
Chris Palmer on
RobSez on
marlene on
MayPA on
spartan111 on
John Cunningham on
Weeping Man on
felix1999 on
felix1999 on
Virgil Cole on
Virgil Cole on
Virgil Cole on
Buzg on
usaok59 on
John Cunningham on
cfd_007 on
alfy on
D Guest on
marlene on
adbj102 on
JEANNIEMAC2 on
Hugh Jass on
JEANNIEMAC2 on
Uzoozy on
TexasOlTimer on
Uzoozy on
Uzoozy on
Waiting on
TexasOlTimer on
TexasOlTimer on
<-----MyFrontDoorBuddy on
<-----MyFrontDoorBuddy on
Sarfaraz A. on
Sarfaraz A. on
Alex Sheibani on
Uzoozy on
sherri palmer on
sviri finq on
No Corporate BS on
SumatraSue on
Ted Johnson on
Waiting on
Jason Woodworth on
Helmut Beintner on
Doug Sterling on
JEANNIEMAC2 on
jwmiller on
sickandtired on
sherri palmer on
VTrobert on
Fredrick Rehders on
usaok59 on
Waiting on
VTrobert on
cool-subzero90 on
michaelhayes on
danstewart on
reggiec on
John Cunningham on
Andrew on
John Cunningham on
Don P on
Britt Brooks on
John Cunningham on
Helmut Beintner on
Jim on
Spectrum on
danstewart on
Helmut Beintner on
Helmut Beintner on
Helmut Beintner on
John Cunningham on
missinger on
adbj102 on
noh1bvisas on
danstewart on
Jigsaw on
Jigsaw on
Patty Villanova on
sherri palmer on
sherri palmer on
sherri palmer on
sherri palmer on
sherri palmer on
sherri palmer on
sherri palmer on
Weeping Man on
Frosty Wooldridge on
Hugh Jass on
danstewart on
Jr1776 on
JEANNIEMAC2 on
Fredrick Rehders on
JEANNIEMAC2 on
ort on
Jared on
dndgaddy on
Thunderbolt #1 on
JEANNIEMAC2 on
reggiec on
David Gearhart on
David Gearhart on
madgrandma on
David Gearhart on
David Gearhart on
John Wesley Bletsch on
Chopko on
LaineeTheCat Wallace on 10 Tips How to Counter Islam
LaineeTheCat ✔Trump on
LaineeTheCat ✔Trump on
danstewart on
marlene on
marlene on
felix1999 on
felix1999 on
felix1999 on
ort on
ort on
felix1999 on
felix1999 on
felix1999 on
<-----MyFrontDoorBuddy on
marlene on
Helmut Beintner on
Whynot be great again222 on
JEANNIEMAC2 on
ort on
michaelhayes on
John Wesley Bletsch on
missinger on
missinger on
missinger on
Whynot be great again222 on
Whynot be great again222 on
Whynot be great again222 on
Whynot be great again222 on
Whynot be great again222 on
Whynot be great again222 on
Whynot be great again222 on
ort on
Allright Hamilton! on
ort on
Allright Hamilton! on
Allright Hamilton! on
TheBucko on
ort on
ort on
ZEPHANIAH54321 on
mzliberty2013 on
JEANNIEMAC2 on
Frosty Wooldridge on
Jim on
Frosty Wooldridge on
Whynot be great again222 on
Jawad Karim on
Tranqual on
Allright Hamilton! on
Whynot be great again222 on
Allright Hamilton! on
danstewart on
ort on
marlene on
satovey on The Islamic Scam
Tranqual on
Tranqual on
madgrandma on
durabo on
Warrior on
marlene on
reggiec on
reggiec on
marlene on
marlene on
marlene on
marlene on
marlene on
deanosslewis . on The Islamic Scam
asinnersavedbygrace on Top Bible Prophecy Stories of 2015
Jill Hasselbach Villalba on The New Terror Threat: Organized Rape
malaka_eneuresis on The Islamic Scam
TexasOlTimer on Trump Gets It: The Snake
maddog0311 on Trump Gets It: The Snake
John Cunningham on US Criminalizing Free Speech?
Michael Bluestein on Burns, Oregon, Is Not Bundy Ranch
John Cunningham on US Criminalizing Free Speech?
John Cunningham on US Criminalizing Free Speech?
John Cunningham on US Criminalizing Free Speech?
John Cunningham on US Criminalizing Free Speech?
sherri palmer on What Muslims Really Believe
David Gearhart on What Muslims Really Believe
wildmanonearth on Sharia Law for the Non-Muslim
Vladsmom on
bruce on Chelm
John Cunningham on ISIS Campaign for Europe
John Cunningham on Being Thankful for the Left
marlene on  GOP Plot Thickens
Fredrick Neal Rehders on Media Darling Conservatives
Sgt Saunders on Red-Faced Fury
Fredrick Neal Rehders on America Isn’t Dead Yet
funk u zionist bedouin on Red-Faced Fury
Fredrick Neal Rehders on Empty the Prisons Bill Now on Fast Track
NetJobsOnline~~~~Earn $97/hour on The Obama Machine Takes Over Canada
NetJobsOnline~~~~Earn $97/hour on The Death of Europe
NetJobsOnline~~~~Earn $97/hour on A Big Stash of Campaign Cash in Marijuana for Paul
kunling on The Death of Europe
Richard N on The Death of Europe
Yours Truly on Sweden Close to Collapse
John Cunningham on Sweden Close to Collapse
michaelhayes on Sweden Close to Collapse
michaelhayes on Sweden Close to Collapse
Doc Eckleberg on Sweden Close to Collapse
John Cunningham on Legitimizing Hillary’s Crimes
John Cunningham on Sweden Close to Collapse
Enos Dapenis on The Coming US/Mexico War
Fucck your lies on The Coming US/Mexico War
BornAgainSouthernPride on Obama and a Doctrine of Dishonesty
GooglePostJobs:::GET $97/h on Chinese Government Runs Circles Around Obama
GooglePostJobs:::GET $97/h on JW Exposes Hillary Clinton Lie
John Cunningham on JW Exposes Hillary Clinton Lie
Yours Truly on I Am Mourning For America
Yours Truly on I Am Mourning For America
Prophetess Anya Kelly on Are We Living In The Last Days?
disqus_NSXp0ZCum6 on Should Christians Call God Allah?
Tee Quake on Nuclear Jihad
ort on
Jim on
Joel Spealman on Is Trump the Real Deal?
RobertLaity on
DENNIS J. MALONE on Is Trump the Real Deal?
ort on
Manorbier on
Bo Wetstone on The Banking Oligarchs
Dannie Poe on
JohnDiLiberto on The Banking Oligarchs
Herman Van Keer on Answering Muslims Conference
Mean Green Law on Donald Trump: American Patriot
Jigsaw on Trumping Trump
b keaton on Trumping Trump