Cybersecurity

Our world runs on computers and the Internet. We use them for everything, from communicating with long-lost classmates to managing our bank accounts to buying anything from cars to diapers. The effort to keep these systems secure is known as cybersecurity. Unfortunately, all too often, simple, effective cybersecurity steps are not taken, like changing passwords routinely or updating and patching holes in software. Even when they are, sophisticated hackers can sometimes get around these defenses. The government is using this threat to try to expand its power and permit companies to funnel our sensitive, personal online information to it. Learn more >>

Government Doesn’t Need Your Private Info for Cybersecurity—But Members of Congress Still Want It

By Robyn Greene, ACLU Washington Legislative Office at 1:33pm

Last Thursday, the House Intelligence Committee held a hearing that focused on...

CISPA Explainer #1: What Information Can Be Shared?

By Michelle Richardson, Legislative Counsel, ACLU Washington Legislative Office at 10:05am

We've written extensively about CISPA over the last year, but since the House Permanent Select Committee on Intelligence is set to mark the bill up next week, and the full House to vote on it the week after that, we're posting in more depth about its shortcomings. Information sharing isn't offensive per se; it's really a question of what can be shared, with whom, and what corporations and government agencies can do with it. First up:

Thank You Mr. President – In Big Win for Privacy, Administration Issues CISPA Veto Threat!

By Robyn Greene, ACLU Washington Legislative Office at 12:32pm

Over the last few months, more than 50,000 ACLU supporters signed our petition to the president urging him to veto CISPA if it made it to his desk. Not only did the president hear your calls – yesterday, he answered them with a resounding win for your privacy and civil liberties and threatened to veto CISPA, the dangerous privacy-busting cybersecurity bill.

The president's veto threat echoed many of our concerns, and those that he raised last year when he threatened to veto CISPA 1.0. We have long warned that CISPA threatens Americans' privacy and civil liberties by allowing for companies to share our private information, like our internet records and the content of our emails, with the government. Yesterday's veto threat makes it clear that in spite of recent amendments, CISPA still fails to adequately protect our privacy. As the veto threat states:

CISPA Remains Fatally Flawed After Secret Committee Markup

By Michelle Richardson, Legislative Counsel, ACLU Washington Legislative Office at 12:20pm

The House Permanent Select Committee on Intelligence on Wednesday marked up CISPA, the controversial cybersecurity bill that allows companies to share their customers' sensitive internet information with each other and the government. The bill's sponsors and corporations are not only declaring victory, but aggressively arguing that all privacy and civil liberties problems have been solved.

This couldn't be further from the truth.

We have flagged four general categories of problems in CISPA that have to be fixed before it is passed, and the markup only substantially fixed one of them:

CISPA Explainer #3: What Can Be Done With Information After It Is Shared?

By Michelle Richardson, Legislative Counsel, ACLU Washington Legislative Office at 11:09am

We've written extensively about CISPA over the last year, but since the House Permanent Select Committee on Intelligence is set to mark the bill up...

President Obama Shows No CISPA-like Invasion of Privacy Needed to Defend Critical Infrastructure

By Michelle Richardson, Legislative Counsel, ACLU Washington Legislative Office at 1:48pm

Last night the President signed an executive order (EO) aimed at ramping up the cybersecurity of critical infrastructure...

CISPA Explainer #4: Is There Anything Besides Information-Sharing Hidden in CISPA?

By Michelle Richardson, Legislative Counsel, ACLU Washington Legislative Office at 10:13am

We've written extensively about CISPA over the last year, but since the House Permanent Select Committee on Intelligence is set to mark the bill...

CISPA Explainer #2: With Whom Can Information Be Shared?

By Michelle Richardson, Legislative Counsel, ACLU Washington Legislative Office at 10:20am

We've written extensively about CISPA over the last year, but since the House Permanent Select Committee on Intelligence is set to mark the bill up next week, and the full House to vote on it the week after that, we're dissecting its shortcomings. Information sharing isn't offensive per se; it's really a question of what can be shared, with whom, and what corporations and government agencies can do with it. Yesterday we told you what could be shared (read: your personally identifiable information) and today we discuss where that information ends up.

Cyber Protection Act Too Broad, Infringes on Our Privacy Rights

By Michelle Richardson, Legislative Counsel, ACLU Washington Legislative Office at 11:12am

This week is “Cybersecurity Week” in the House of Representatives, and members will vote on a handful of bills intended to protect cybersecurity — the ability to prevent and respond to threats from foreign governments, terrorists and criminals over the Internet. Some of the bills are civil-liberties-neutral but, as usual when addressing a security issue, Congress is considering a bill that overreaches — this time by allowing companies to share private and sensitive information with the government without a warrant and without much oversight.

From POLITICO: The Privacy Risks of CISPA

By Michelle Richardson, Legislative Counsel, ACLU Washington Legislative Office at 11:11am

Reports of significant data breaches make headlines ever more frequently, but lost in the cloak and dagger stories of cyberespionage is the impact proposed cybersecurity programs can have on privacy. The same Internet that terrorists, spies and criminals exploit for nefarious purposes is the same Internet we all use daily for intensely private but totally innocuous purposes.

Unfortunately, in their pursuit to protect America's critical infrastructure and trade secrets, some lawmakers are pushing a dangerous bill that would threaten Americans' privacy while immunizing companies from any liability should that cyberinformation-sharing cause harm.

Statistics image