Cybersecurity

Our world runs on computers and the Internet. We use them for everything, from communicating with long-lost classmates to managing our bank accounts to buying anything from cars to diapers. The effort to keep these systems secure is known as cybersecurity. Unfortunately, all too often, simple, effective cybersecurity steps are not taken, like changing passwords routinely or updating and patching holes in software. Even when they are, sophisticated hackers can sometimes get around these defenses. The government is using this threat to try to expand its power and permit companies to funnel our sensitive, personal online information to it. Learn more >>

Friday links roundup

By Jay Stanley, Senior Policy Analyst, ACLU Speech, Privacy and Technology Project at 5:38pm

A few links that have caught our eye this past week:

Paul Rosenzweig has posted a nice piece on Lawfare on the reasons to be skeptical of the need for cybersecurity regulation. He breaks cybersecurity down into its constituent parts (as we have urged) of cybercrime, cyber espionage, and truly catastrophic “digital Pearl Harbor” attacks. He suggests that the first two do not justify regulation, and (like us) is skeptical about the degree of risk of the third. In explaining that skepticism, he provides an elegant analysis of the electric grid, the taking down of which is a frequent cyber-attack scenario, and makes the point that the pro-regulation viewpoint “mistakes vulnerability for risk”—in other words, there can be a vulnerability in a system, but still a low risk that anyone will actually be able to or try to exploit it.

New Senate Cyber Bill No Better Than Last Version

By Michelle Richardson, Legislative Counsel, ACLU Washington Legislative Office at 5:41pm

Yesterday, Republican Senators introduced a rewrite of their cybersecurity bill, known as SECURE IT. Advocates registered their opposition to the bill last month and its CISPA-like expansion of military authority to collect sensitive information on Americans’ internet use.  

Despite claims the contrary, the new bill has not been substantially amended and still does not meaningfully limit the amount or type of information that the government can collect from companies that hold very private and personal data. Most importantly,

Statistics image