Cybersecurity

Our world runs on computers and the Internet. We use them for everything, from communicating with long-lost classmates to managing our bank accounts to buying anything from cars to diapers. The effort to keep these systems secure is known as cybersecurity. Unfortunately, all too often, simple, effective cybersecurity steps are not taken, like changing passwords routinely or updating and patching holes in software. Even when they are, sophisticated hackers can sometimes get around these defenses. The government is using this threat to try to expand its power and permit companies to funnel our sensitive, personal online information to it. Learn more >>

Friday links roundup

By Jay Stanley, Senior Policy Analyst, ACLU Speech, Privacy and Technology Project at 5:38pm

A few links that have caught our eye this past week:

Paul Rosenzweig has posted a nice piece on Lawfare on the reasons to be skeptical of the need for cybersecurity regulation. He breaks cybersecurity down into its constituent parts (as we have urged) of cybercrime, cyber espionage, and truly catastrophic “digital Pearl Harbor” attacks. He suggests that the first two do not justify regulation, and (like us) is skeptical about the degree of risk of the third. In explaining that skepticism, he provides an elegant analysis of the electric grid, the taking down of which is a frequent cyber-attack scenario, and makes the point that the pro-regulation viewpoint “mistakes vulnerability for risk”—in other words, there can be a vulnerability in a system, but still a low risk that anyone will actually be able to or try to exploit it.

New Senate Cyber Bill No Better Than Last Version

By Michelle Richardson, Legislative Counsel, ACLU Washington Legislative Office at 5:41pm

Yesterday, Republican Senators introduced a rewrite of their cybersecurity bill, known as SECURE IT. Advocates registered their opposition to the bill last month and its CISPA-like expansion of military authority to collect sensitive information on Americans’ internet use.  

Despite claims the contrary, the new bill has not been substantially amended and still does not meaningfully limit the amount or type of information that the government can collect from companies that hold very private and personal data. Most importantly,

Next Round in Cybersecurity Battle: The Senate

By Michelle Richardson, Legislative Counsel, ACLU Washington Legislative Office at 3:36pm

Two weeks ago, the House of Representatives passed the Cyber Intelligence Sharing and Protection Act (CISPA). But thanks to internet activism and advocacy by organizations like the ACLU and the Electronic Frontier Foundation, 168 Congressmen voted “no,” including 28 Republicans, the House Democratic leadership, and a chunk of members who sit on the Intelligence and Homeland Security Committees.

On the Agenda: Week of May 14–18, 2012

By Suzanne Ito, ACLU at 12:39pm

This week the House will debate the NDAA for fiscal year 2013. We'll be monitoring the debate and pulling for an amendment that fixes the terrible detention provisions in last year's bill.

Cybersecurity Legislation and Common Sense – Still Waiting for the Two to Meet

By Zachary Katznelson, Senior Staff Attorney, ACLU National Security Project at 1:25pm

During the past two weeks, we’ve been highlighting cybersecurity and the dangers that various legislative proposals pose to our civil liberties. One major concern is the prospect of private companies sharing vast amounts of our personal information with the military and other government agencies, without a warrant or any court oversight. Much of the cybersecurity debate has been distorted by the conflation of scary stories of possible terrorist cyberattacks (scenarios that frequently fall apart when confronted by the facts) with troubling, but much lower-grade incidents of credit card and other theft. The result is a pervasive crisis atmosphere, which is then used to justify sweeping aside civil liberties in the name of security.

On the Agenda: Week of April 30 – May 5, 2012

By Suzanne Ito, ACLU at 12:00pm

Congress is out this week, but May will be a busy month with cybersecurity in the Senate, the 2013 NDAA and the arraignment of Khalid Sheikh Mohammed.

This Week in Civil Liberties (4/27/2012)

By Rekha Arulanantham, ACLU at 5:23pm

What law threatens the Occupy movement’s and other activists’ right to protest?

What bill recently passed by the House did the President threaten to veto because of its privacy problems?

Which court heard arguments this week regarding Arizona’s anti-immigrant bill, S.B. 1070?

In which state does U.S. citizen and ACLU plaintiff Jim Shee carry his passport at all times because the color of his skin makes him look suspicious?

Civil Liberties in the Digital Age: Weekly Highlights (4/27/2012)

By Anna Salem, ACLU of Northern California at 4:01pm

In the digital age that we live in today, we are constantly exposing our personal information online. From using cell phones and GPS devices to online shopping and sending e-mail, the things we do and say online leave behind ever-growing trails of personal information. The ACLU believes that Americans shouldn’t have to choose between using new technology and keeping control of your private information. Each week, we feature some of the most interesting news related to technology and civil liberties that we’ve spotted from the previous week.

House Passes Controversial Cybersecurity Measure CISPA [Wired]
"The House on Thursday approved cybersecurity legislation that privacy groups have decried as a threat to civil liberties… Its goal is a more secure internet, but privacy groups fear the measure breaches Americans' privacy along the way."
     See Also Keep Domestic Cybersecurity Efforts in Civilian Hands [ACLU]
     See Also Insanity: CISPA Just Got Way Worse, And Then Passed On Rushed Vote [Techdirt]
     See Also The CISPA Amendments We Really Need [Read Write Web]
     See Also White House Threatens Veto, ACLU Says CISPA Amendments Not Enough [Reason]

Keep Domestic Cybersecurity Efforts in Civilian Hands

By Michelle Richardson, Legislative Counsel, ACLU Washington Legislative Office at 8:37am

Last night the House of Representatives passed HR 3523, the Cyber Intelligence Sharing and Protection Act, or CISPA. We’ve written about the many privacy problems with this bill, but here I would like to focus on one of its biggest and most fundamental flaws: it empowers the military, including agencies like the NSA, to collect the internet records of Americans’ everyday internet use.

House of Representatives Passes Privacy-Busting CISPA

By Ateqah Khaki at 6:33pm

CISPA is a dangerously overbroad bill that would allow companies to share our private and sensitive information with the government without a warrant and without proper oversight.

Statistics image