Cybersecurity

Our world runs on computers and the Internet. We use them for everything, from communicating with long-lost classmates to managing our bank accounts to buying anything from cars to diapers. The effort to keep these systems secure is known as cybersecurity. Unfortunately, all too often, simple, effective cybersecurity steps are not taken, like changing passwords routinely or updating and patching holes in software. Even when they are, sophisticated hackers can sometimes get around these defenses. The government is using this threat to try to expand its power and permit companies to funnel our sensitive, personal online information to it. Learn more >>

CISPA Explainer #3: What Can Be Done With Information After It Is Shared?

By Michelle Richardson, Legislative Counsel, ACLU Washington Legislative Office at 11:09am

We've written extensively about CISPA over the last year, but since the House Permanent Select Committee on Intelligence is set to mark the bill up...

CISPA Explainer #2: With Whom Can Information Be Shared?

By Michelle Richardson, Legislative Counsel, ACLU Washington Legislative Office at 10:20am

We've written extensively about CISPA over the last year, but since the House Permanent Select Committee on Intelligence is set to mark the bill up next week, and the full House to vote on it the week after that, we're dissecting its shortcomings. Information sharing isn't offensive per se; it's really a question of what can be shared, with whom, and what corporations and government agencies can do with it. Yesterday we told you what could be shared (read: your personally identifiable information) and today we discuss where that information ends up.

CISPA's Problem Isn't Bad PR, It’s Bad Privacy

By Robyn Greene, ACLU Washington Legislative Office at 11:28am

Representative Mike Rogers (R-MI) made the argument last week that the privacy community’s significant concerns with CISPA, the privacy-busting cybersecurity bill, don’t stem from actual problems with the bill language, but rather from a misunderstanding of the bill itself. Speaking on behalf of himself and his co-sponsor, Representative Dutch Ruppersberger (D-MD), he told The Hill, “We feel that the bill clearly deals with privacy, that the checks and balances are there, but [we] know there's still a perception and we're still trying to deal with that.”   

With CISPA, "It's all just a little bit of history repeating..."

By Robyn Greene, ACLU Washington Legislative Office at 4:48pm

The Propellerheads may have been talking about fashion trends when they sang that "to me it seems quite clear that it's all just a little bit of history repeating." But that sentiment rings loud and true today when talking about the privacy-busting cybersecurity bill CISPA.

Leaders of the House Intel Committee reintroduced CISPA with the same privacy flaws as last year. While they suggested at its unveiling that they worked with the privacy community and addressed our concerns, they didn't. This is the same bill, with the same problems.

Intel Officials Admit "Cyber Pearl Harbor" Unlikely Soon, Agree Cyber Should be Kept in Civilian Hands

By Robyn Greene, ACLU Washington Legislative Office at 4:27pm

Privacy protection, and the debate about whether to house information-sharing programs in a civilian or military agency, dominated three congressional hearings on cybersecurity this week.

In separate hearings Tuesday in the Senate Select Committee on Intelligence and the Armed Services Committee, leaders of the intelligence community called cyberattacks the greatest threat to the U.S. at this time—but admitted that the kinds of catastrophic attacks imagined by reporters and cyber experts were only a "remote" possibility in the near future.

ACLU to Congress: Keep Cybersecurity Information Sharing Out of Military Hands!

By Robyn Greene, ACLU Washington Legislative Office at 4:49pm

As Congress debates cybersecurity legislation, one of the most significant questions legislators are tackling addresses where to house...

ACLU to Congress: Keep Cybersecurity Information Sharing Out of Military Hands!

By Robyn Greene, ACLU Washington Legislative Office at 4:58pm

UPDATE: Due to a winter storm approaching Washington, D.C., tomorrow's House Homeland Security Committee hearing on cybersecurity has been postponed for a later date.

As Congress debates cybersecurity legislation, one of the most significant questions legislators are tackling addresses where to house an information sharing program that would allow the private sector to hand over Americans' most private online information to the government: in a civilian or a military agency?

Government Doesn’t Need Your Private Info for Cybersecurity—But Members of Congress Still Want It

By Robyn Greene, ACLU Washington Legislative Office at 1:33pm

Last Thursday, the House Intelligence Committee held a hearing that focused on...

Hotel Lock Security Vulnerability is Reminder of Government’s Ambiguous Role in Protecting Security

By Chris Soghoian, Principal Technologist and Senior Policy Analyst, ACLU Speech, Privacy and Technology Project at 10:36am

This summer, at the Black Hat security conference, a security researcher presented details of a troubling security flaw: An electronic lock system, used in more than 4 million hotel rooms around the world, is vulnerable. The researcher, Cody Brocious, revealed that with less than $50 in electronic parts, a device can be built that will open one of the vulnerable locks in seconds. Just a few months after Brocious revealed the flaw, hotels in Texas reported a string of thefts by burglars from rooms, all protected by vulnerable locks.

Data Breach Raises Questions About NASA Policy At Issue in Recent Supreme Court Case

By Jay Stanley, Senior Policy Analyst, ACLU Speech, Privacy and Technology Project at 4:35pm

We hate to say “I told you so.”

In 2010, the Supreme Court heard a case called NASA v. Nelson, which involved the government’s right to carry out highly intrusive background checks. NASA decided to require its employees—many of whom had already been working for the agency for many years in what the government conceded were “low-risk” and “non-sensitive” positions—to fill out a form in which they were required to disclose any illegal drug use or possession within the previous year, along with details on any treatment or counseling received for such use. These employees were also required to sign an authorization permitting NASA’s security people to obtain

Statistics image