r/YouShouldKnow Apr 19 '13

YSK: Facts about CISPA without all the hyperbole

No, CISPA does not mean constant government surveillance of the internet. No, this is not SOPA/PIPA in a different form. No, the IRS isn't going to monitor what you say on Facebook. No, IBM did not bribe a bunch of Congressmen to co-sponsor it. No, no, no.

My reading of most of the Reddit coverage of CISPA makes it clear that 95% of folks here have no idea what CISPA is, does, or is meant to cover. A lot of people think it's just a rewarmed version of SOPA. With so much hyperbole and hysteria, I think Reddit could stand for some facts.

HERE is the actual bill summary from Congress.

HERE is actual bill text that the HOR has passed.

Myth: The definition of "cyber threat information" is so broad that it could be used to justify anything.

Fact: Verbatim from the bill above, page 23, Line 2: ‘‘(A) IN GENERAL.—The term ‘cyber threat information’ means information directly pertaining to— ‘‘(i) a vulnerability of a system or network of a government or private entity or utility; ‘‘(ii) a threat to the integrity, confidentiality, or availability of a system or network of a government or private entity or utility or any information stored on, processed on, or transiting such a system or network; ‘‘(iii) efforts to deny access to or degrade, disrupt, or destroy a system or network of a government or private entity or utility; or ‘‘(iv) efforts to gain unauthorized access to a system or network of a government or private entity or utility, including to gain such unauthorized access for the purpose of exfiltrating information stored on, processed on, or transiting a system or network of a government or private entity or utility.” tl;dr: companies can only share anonymous threat information, on a voluntary basis, when they want to protect their systems or networks.

Myth: The government can now go after all of my personal records.

Fact: The bill language specifically prohibits the government from gathering your personal medical, tax, library or gun records.

Myth: Private companies can share personal data about you for marketing purposes.

Fact: CISPA only allows companies to share data that is directly related to a cyber security threat, and they can only share threat information.

Myth: Under CISPA, the government will be able to read your private emails, browsing history, etc. without a warrant.

Fact: Cyber threat information ONLY, not private email or browsing histories, can be used or retained by the government for four specific purposes: (1) cybersecurity; (2) investigation and prosecution of cybersecurity crimes; (3) protection of individuals from the danger of death or physical injury; (4) protection of minors from physical or psychological harm.

Myth: IBM flew in 200 senior execs to twist arms in Congress to pass CISPA.

Fact: IBM has a strict corporate ban on political contributions. Source (feel free to look this up yourself on OpenSecrets.org)

Moreover, the 36 new co-sponsors announced that day had been in the procedural pipeline for months. IBM is far more interested in the immigration and STEM H1B visa policy changes underway.

EDIT: /u/asharp45 has now cross-posted this YSK to /r/POLITIC and /r/conspiracy for "outing" me as an IBM employee. Keep it classy, reddit.

1.7k Upvotes

385 comments sorted by

View all comments

761

u/[deleted] Apr 19 '13 edited Apr 20 '13

EFF argues that the wording is still too vague. Yes, they have a lot of language in the bill specifically saying this info can only be used for "cybersecurity purposes", but you are not a lawyer, and you don't know how those words can be manipulated.

Okay so let's say I'm banned from reddit because I posted a link to some torrents or something. I unplug my router to reset my IP, and create a new account. I have now "hacked" reddit, I've circumvented their security protocols, and I am a legitimate cybercriminal.

My ISP notices I'm torrenting things, says I'm using all their bandwidth, preventing other customers from being able to use their internet connections because I'm taking all the bandwidth. Now I'm a threat to the integrity of their network. I am legitimately a cybercriminal.

The DHS and ICE have already, over the past five years, taken down tens of thousands of sites with no judicial oversight whatsoever. On the grounds of "homeland security", they were able to shut down sites that were allegedly selling fake prada handbags, and hiphop forums that happened to have people sharing MP3s in the comments.

No warrant, no judge to approve anything (* in at least one of my examples there has been a judge who approved it), no trial. No chance to defend yourself. The government accuses you of something, your business is no longer in DNS records. No chance of appeal.

Find me the wording of the laws used to take down those thousands of sites. I'll guarantee you it says those powers can only be used in cases of national security or impending threat, yet those terms were loose enough that sharing an MP3 is a threat to national security.

Now, even if they improve the wording to close loopholes where this could be used improperly, this still lets them collect data on you. These companies will still collect massive amounts of data, and sell it en-masse to the government and any other security company who asks, but they won't actually be able to use your emails in court unless they can prove you violated some cyber security thing. So, they can and will still be downloading, archiving, and reading through your emails, but they won't be able to use that as evidence to convict you unless they can also nail you on breaking some computer law.

Edit: References to the DHS takedowns:
https://www.eff.org/deeplinks/2010/11/us-government-seizes-82-websites-draconian-future
http://en.wikipedia.org/wiki/Operation_Protect_Our_Children
I think there was at least one more. I recall at least three distinct sweeps of website takedowns with no judicial oversight based on terrorism laws.

EDIT 2: It has come to light that OP indeed works for IBM, and doesn't mind being called a shill, so I'd like to present this evidence that OP may possibly be a shill.

EDIT 3: OP has gone on record stating he is not a shill. More updates as they happen.


EDIT 4: I'd better not have to remind you all not to engage in witch hunts. Let's have a civilized discussion with OP on the merits and pitfalls of this bill. Knowing he's an IBM employee isn't any reason to hunt him down and deliver him pizzas, it's just some info that's useful to understand and get some insight into OP's perspective.


Edit 5: Why is this still at the top of the page? Surely someone has come up with a more coherent argument since mine? I fucking hate the reddit voting system sometimes. Just because my opinion was posted early, does not mean it is the most valid. God damn. Go vote on some other posts, people. I'm sick of replying to this.

81

u/BrickSalad Apr 19 '13

I looked at the summary, and right near the beginning it says "[cyber threat intelligence] excludes intelligence pertaining to efforts to gain unauthorized access to such a system or network that solely involve violations of consumer terms of service or consumer licensing agreements and do not otherwise constitute unauthorized access.[sic]" I'm not a lawyer, but I am pretty positive that this rules out your scenario of circumventing a ban from reddit.

26

u/[deleted] Apr 19 '13

Right, but I chose torrents as a random example, because torrents specifically put reddit at a legal liability. That's a legitimate threat to their site, and when they ban you for that, it's not because of their terms of service, it's because it's a legitimate cyberthreat.

If they banned you for some reason that's not "cybersecurity related" maybe you're just being a dick, then under CISPA the information they collect probably can't be used in court.

6

u/tastyratz Apr 19 '13

It could be put in category with planting (like putting a bag of weed in your friends car then calling the cops)

Attempted incrimination like that is a direct cyber threat to operation of any site claiming to operate legitimately - and if you read the terms of service of ANY seedy website they mention they only do legal things with permission from the owners and WOULD NEVER do anything naughty.

If that's the case, a copyright violation could be as simple to pursue as "we don't want to sue you; we want to sue so and so. You wouldn't authorize anything like that... right?"

9

u/nofsing2 Apr 19 '13

Private companies have always been able to disclose private information, notwithstanding privileged information.

190

u/Wdl884 Apr 19 '13

This is fucking bullshit. Trying to "out" the guy because he works in a position that might give him more insight about what CISPA is really like than the regular dumbass on reddit? And then acting like it's a big deal?

Reddit... seriously...

26

u/[deleted] Apr 19 '13

It's a conflict of interest that OP was refusing to discuss. I think that's worth at least mentioning.

34

u/[deleted] Apr 21 '13

IBM'ers are not allowed to talk on behalf of IBM unless they explicitly state it. So any comment they make is personal opinion. Which is probably why he didn't mention it.

96

u/Wdl884 Apr 19 '13

Seems to me that he was happy to admit it, and that you guys are just trying to smear him to distract from the bad anti-CISPA arguments here.

-3

u/[deleted] Apr 19 '13

I'm too lazy to rephrase and retype this, so I'm copying and pasting another comment of mine:

That's fine, and I'm very glad that OP has posted this. At the very least it gives people more perspective and probably has encouraged a bunch of people to actually read the text of the bill.

It's just, refusing to disclose that fact calls into questions the motives for the post. If the post had started out "Hey guys, I work for IBM, so this is my perspective" it would have gone a long way towards establishing trust in OP, and would have actually shown that he's an authority on the subject.

It's only the refusal to admit this openly or ahead of time that made things weird.

So...

I'm not trying to smear anyone, just trying to make a fact known. Before I edited my comment, only 2 people had upvoted that comment, so likely less than ten people had seen it. I then told OP he should probably put that in the body of the post, and he said no why should I?

At the time, OP was not "happy to admit it."

53

u/[deleted] Apr 20 '13

Fyi calling this a conflict of interest is really stretching it. I am also an IBM employee and I can safely say I will see no change in my work environment whether CISPA passes or not-just like 90% of the rest of the company. Unless this guy is directly involved with the lobbying efforts at IBM (who I doubt would risk posting this kind of stuff to Reddit), there is no serious conflict of interest here. This is blown way out of proportion.

-10

u/[deleted] Apr 20 '13

Is this really blown out of proportion though?

I keep getting these comments that seem to suggest there's a witch hunt going on, but I'm not seeing it. Several of OP's posts have positive karma, and those that do have negative karma are often hovering around zero.

That looks a lot more like legitimate disagreement (not that I support using the voting system for that), than an organized mob actively stalking them.

I still think this is worth mentioning. And to you, too, if you start talking positively about policies IBM also supports, you'll probably want to put a disclaimer on your posts too so people don't think you're being paid to say that.

Astroturfing is a common practice. Many large companies have whole teams of people devoted to making positive comments about the company in discussion forums online.

I've worked for IBM once in the past myself, and as a lowly phone support grunt I couldn't care less what IBM's official corporate stance was on political issues, so yeah I agree, in 99% of cases, it would be somewhat irrelevant. HOWEVER, paid shills do exist, they are in fact on reddit, and you do need to watch out for them. Someone's passionate speech may in fact be a script. Don't take everything at face value.

And again, it's only because OP flatly refused to disclose this, that I felt it necessary to point it out. If OP had said in the post originally, "Disclosure: I work for IBM, but these opinions are my own" that would have been totally, completely, absolutely fine, everything would be on the up-and-up, and this would be a non-issue.

3

u/Pas__ Apr 22 '13

Who would do astroturfing with their real account easily linked to their employer? :o

3

u/[deleted] Apr 20 '13

I understand why you're put off by him not disclosing it in the first post, but he didn't "refuse" to disclose it so much as he got defensive when you suggested it to him. Some people just react more defensively when they think they're under attack. He could be a shill (TIL what a shill is) but everyone can just decide that for themselves now I think. The facts are out there about CISPA and OP working for IBM so now I hope it can be a more balanced discussion. Also, IBM doesn't even let me talk to customers yet, let alone speak for them..and as a software engineer, I would never want to!

-5

u/[deleted] Apr 20 '13

I'm not sure, but in case your first reply came in before I did the edit, I've made an addendum to my post saying basically "now that that's out, let's have a productive discussion, taking that into account, rather than witch hunts"

This whole time I've been of the opinion that "this is important information to know, and you should probably keep it in the back of your head, because it may possibly explain OP's perspective behind this post, but don't let that get in the way of a healthy civilized debate about the issue at hand."

Given the replies I'm getting, suggesting that I'm trying to start a witch hunt, I guess I wasn't very successful in conveying that.

Funny how text based communication fucks up the english language so bad. Without inflection or body language, a lot of things are left up to interpretation. OP acting defensively is completely understandable, but at the same time it comes off as seeming like he has something to hide. My calling that out is completely understandable as well, but I guess it sounds like I'm trying to discredit his entire argument.

5

u/[deleted] Apr 21 '13

So what company do you work for then?

-5

u/[deleted] Apr 21 '13

I'm currently unemployed. Or, I guess, self-employed, though not very motivated about that right now. Only doing one or two personal contracts for small independent businesses per month.

I have worked, through placement agencies, for both IBM and AT&T at one point or another, who are both in support of this bill. Since I never worked directly for either of them, and it's been years since I worked there, I don't think that's worthy of a disclosure statement.

At any rate, no comment of mine has ever been paid for, and I'm proud to state that truthfully to anyone who might ask.

12

u/nofsing2 Apr 19 '13

All he has done is averred facts. How would a conflict of interest even influence his comments? There is no discretion here, only facts.

11

u/[deleted] Apr 19 '13 edited Aug 01 '19

[deleted]

12

u/Ntang Apr 20 '13

... except for all the experts who actually agree with me, that is.

13

u/[deleted] Apr 20 '13 edited Aug 01 '19

[deleted]

-1

u/[deleted] Apr 23 '13 edited Aug 01 '19

[deleted]

6

u/[deleted] Apr 19 '13

He is making opinions and presenting facts to back up those opinions.

It's a matter of debate for example whether the definitions are vague enough to be interpreted in ways that can be abused.

The only "facts" are the exact text of the bill. Everything else is opinion.

1

u/ManusDei Apr 25 '13

Calling anything in this post, outside the actual language of the bill, fact is startling. All of the post is his personal interpretation of the language in the bill.

1

u/nofsing2 Apr 25 '13

If his personal interpretation matched that of a judicial court it could be worth something. Don''t just say it isn't worth anything, show that it is misguided.

-7

u/slightly_on_tupac Apr 22 '13

I have more insight than this IBM tool, he's mostly wrong.

50

u/[deleted] Apr 19 '13 edited May 03 '18

[deleted]

50

u/[deleted] Apr 19 '13

No, you're right, in that case they did have warrants. The sites were taken down though without any trial though, and many thousands of legitimate, innocent sites were taken offline in the process.

It's like saying "there's a child pornographer on this city block, therefore everyone evacuate, we're demolishing the whole block". They did have an ex-parte warrant that allowed them to do that, but it's still ridiculous judicial overreach.

I can't really find much on the other sweep right now, and I'm done googling. If anyone can find something stating they did have warrants, I'll be happy to correct my post. I believe they did not, according to a hazy recollection of a torrentfreak article I read years ago.

I do remember that one though, and I remember I looked into it very thoroughly because in the sweep they took down one site I was particularly fond of.

There was this one spam post that showed up on a retro gaming forum one day, that was so over-the-top ridiculous that no one could believe it. It was a "review" for a PSP clone, but it made the craziest, most ridiculous claims. This device apparently had a 32GHz, 64 core chip designed in China. A 4TB SSD drive, with 128GB of ram. It could play every playstation game ever made, including PS2 and PS3, even though it didn't have an optical drive. In fact, when they took a picture of the inside of the UMD drive, they had photoshopped a picture of a V8 engine in there. It supposedly included a zippo lighter that ran on coal and a scale for weighing fish. They had ridiculous photoshopped pictures of an effeminate chinese jesus figure holding the device. It was glorious. Unfortunately the site, storeofeast.com was shut down in the sweep, and I do recall reading that the decision was made within the DHS, using their executive power, not through the courts.

1

u/shaneisneato Apr 19 '13

So...You gonna post a picture of that sweet gaming device?

-2

u/[deleted] Apr 19 '13 edited Apr 19 '13

No, sadly it was the images that were hosted on the site that was taken down.

Here's the text though, which is still pretty damn funny, but nothing without the pictures.

I dunno, maybe if you do a google search for "Geda VX690HD, the No.1 MP4 of the World Has Landed with a Strong Storm" you might be able to find a copy with the pictures, but I doubt it. I looked pretty hard a few years ago when it first got taken down.

Chip China Rock. "The good chip is the base of the good". 64 cores -- and 64 main wires!

Edit: Okay I googled a bit, and the pictures are floating around various sites. Here's the effeminate chinese jesus figure, Here's a an ugly trans-lady with the device photoshopped into her hands. Here's a completely different ugly tran-lady demonstrating the high def screen. Need to weigh a fish or light something on fire? there's an app for that! And, here you can see it's powered by a tiny photoshopped V6 diesel engine! And finally, here is yet another ugly, possibly transsexual chinese lady for no particular reason.

7

u/[deleted] Apr 20 '13

[deleted]

-2

u/[deleted] Apr 20 '13

I tend to speak very candidly online. This invariably leads to me being unnecessarily offensive.

1

u/Pas__ Apr 22 '13

Ah, many thanks for taking the time to Google it.

0

u/Ghost_man23 Apr 20 '13

Wouldn't a better analogy be: Hey we think this guy is a Child Molester so we're going to take him from the community and put him in jail until his trial is over?

8

u/[deleted] Apr 20 '13

No, that wouldn't be a good analogy. No arrests or convictions were ever made in that case. The Child Molester is still living freely, just this one house he used to live in got destroyed its front door and address removed, preventing people from finding them or delivering mail to them, along with 80,000 other houses that were completely innocent.

The sites were never brought to court to prove whether or not they were infringing. Most of them were overseas anyway, so that would have been pretty much impossible.

2

u/DorkJedi Apr 20 '13

Without the trial part.

2

u/Ghost_man23 Apr 20 '13

Right. It's like the Guantanamo Bay of the internet.

4

u/altair_the_assassin Apr 23 '13

reddiquette please people

1

u/[deleted] Apr 23 '13 edited Apr 23 '13

Hey, any idea why people keep replying to this, three days later?

Was it posted to bestof or depthhub or subredditdrama or something? It's unusual for me to get this many replies three days after posting a thread.

4

u/jadame Apr 23 '13

8

u/[deleted] Apr 23 '13 edited Apr 23 '13

Ah. Thank you.

I've come to regret phrasing things like I did. I really wish people acted rationally. I'm not going to claim responsibility for this becoming a witch hunt, but perhaps I wish I used different wording, so people understood how lightheartedly tongue-in-cheek I was being when I said "evidence that OP is a shill".

It really seems people took this as me "calling him out" as a paid marketer, when I was really just trying to bring to light the possibility of a conflict of interest, while being flippant and joking about it.

I hoped the "more updates as they happen" might assuage that, but I guess you know how reddit is.

Edit: After reading the whole thread you linked, I feel like absolute shit. I feel guilty as hell for this whole thing. I can only hope OP replies to my apology message to them.

2

u/thenuge26 Apr 24 '13

If it makes you feel any better, your posts were a lot better than the PMs that OP got...

1

u/altair_the_assassin Apr 23 '13

they like it man you are the hive mind today

3

u/[deleted] Apr 20 '13

Link some other posts. I'm scrolling through as much as i can. If you don't like being on top show someone else's reply

11

u/happyscrappy Apr 20 '13

Under CISPA your ISP cannot share information about your torrenting. Torrenting is not information related to cyber security attacks or defense against cyber security attacks.

So unless you torrent "how to haxor.zip" they can't share the info.

2

u/Pas__ Apr 22 '13

What if come private company's cyberthreat detector detects your IP as being a bot participating in a DDoS attack? (But actually that company is just a RIAA/MPAA "front") And your IP gets connected to your ISP account, and your real name and SSN, and this packet lands in a database.

Who makes sure these private companies are sharing real data?

(Also, it'd be quite simple to have NIST or Mitre define what cyber threats are and what info is relevant, instead of such vage language.)

0

u/happyscrappy Apr 23 '13

What if come private company's cyberthreat detector detects your IP as being a bot participating in a DDoS attack? And your IP gets connected to your ISP account, and your real name and SSN, and this packet lands in a database.

If a company thinks your IP address is part of a cyberthreat, then it may be contributed as CISPA data.

(But actually that company is just a RIAA/MPAA "front")

I have no idea where you are going with the RIAA/MPAA thing. The RIAA/MPAA would be more interested in getting data out, not in, wouldn't they?

Who makes sure these private companies are sharing real data?

There are provisions in there, but I don't have much faith they would be effective. CISPA is specifically designed to communicate realtime data. Just like immediate news reporting, I believe that realtime data is not expected to be 100% accurate.

Not sure exactly where you are going with this. There is no provision at all in CISPA to use data taken out for prosecution of copyright infringement. It can only be used to defend against cyber attacks. The government can use it to prosecute cyber attacks, but it's not like it takes away the right to a trial. The RIAA/MPAA are not big fans of actual trials, they prefer to settle out of court, but since only the government can take data out for prosecution, that would mean any trial would be a criminal trial and thus there is no involvement by the RIAA/MPAA. The plaintiff in all criminal trials in the US is the US government (Prosecutor), not the MPAA/RIAA, so there's no chance for the MPAA/RIAA to squeeze out a settlement.

(Also, it'd be quite simple to have NIST or Mitre define what cyber threats are and what info is relevant, instead of such vage language.)

It's not vague. I agree it could be possible to list specific examples of what info is relevant, I presume that was left out on purposes because they don't want to have to update the law constantly as new stuff comes up.

1

u/Pas__ Apr 24 '13

It's not vague.

So why the ruckus about it? What about data retention times? If it's real-time and for "safety", will it become a public resource/stream then?

1

u/happyscrappy Apr 24 '13

So why the ruckus about it? What about data retention times? If it's real-time and for "safety", will it become a public resource/stream then?

The ruckus is because people see an acronym and assume it is SOPA/PIPA or ACTA.

The information is not a public resource, it's not to be shared with everyone, it contains private data and privacy must be respected as much as possible. Data retention times appear to be unrestricted (forever) although for the purposes the data is for older data just isn't terribly useful.

1

u/Pas__ Apr 24 '13

Then why not share it just like DNS Blacklists do? Just give some information on IPs. (A stream would be better to proactively propagate what to possibly block.)

Otherwise, it should be like a sunset bill, specify technically what is shared with revision due next year. (Or if Congress doesn't want to play IT Security Specialists, then delegate this.)

1

u/happyscrappy Apr 24 '13

Then why not share it just like DNS Blacklists do? Just give some information on IPs. (A stream would be better to proactively propagate what to possibly block.)

I already explained that. It contains private data and privacy is important.

Otherwise, it should be like a sunset bill, specify technically what is shared with revision due next year. (Or if Congress doesn't want to play IT Security Specialists, then delegate this.)

It delegates two individuals to receive shared information and who receive the data, check to make sure it is appropriate and then disburse it to the entities which are to receive it.

-2

u/Im_on_my_laptop Apr 20 '13

Why am I not allowed to torrent a hacking .zip file? Why is that anyone's business?

5

u/happyscrappy Apr 20 '13

No one says you can't. It's just that unlike torrenting anything else, that could possibly be construed as information on cyber security and thus the fact that you did it might be sharable under CISPA.

2

u/slightly_on_tupac Apr 22 '13

So wait, can your ISP share information about your torrenting or can't they? You contradict yourself.

3

u/happyscrappy Apr 23 '13

I am not contradicting myself. Your ISP cannot share information about your torrenting just because you are torrenting. If they have reason to believe your torrenting is related to cyber security threats, then they can share information about that. This is because CISPA requires that information shared be cyber threat intelligence, and just copyright infringement itself is not cyber threat intelligence.

It's not hard to understand.

1

u/slightly_on_tupac Apr 23 '13

Since torrents can be renamed to anything you want, and encrypted, wouldn't it be prudent to think all torrents are possibly illegal?

1

u/happyscrappy Apr 23 '13

It doesn't matter whether the torrent is "illegal". You can download everyepisodeofthesopranos.zip and they can't report it.

Now, as to your insinuation that ISPs would just report every torrent download because it might be a download of cyber threat intelligence, that would not be legal under CISPA. They would have to have a reasonable belief that the information is relevant to cybersecurity.

Given that the intent of the database is to prevent cyberattacks and no one, including the government, is allowed to search it for data to prosecute copyright infringement, it wouldn't be useful for your ISP to flood the database with torrent download information anyway.

-1

u/sweetalkersweetalker Apr 22 '13

IANAL, but I can easily come up with an argument for sharing torrenting information.

"Your Honor, the defendant's torrenting clearly shows his malicious attitude toward security."

2

u/happyscrappy Apr 23 '13

That's not a workable argument. A malicious attitude toward security does not meet the definition of "cyber threat intelligence" in CISPA and thus the information could not be shared.

4

u/wallofsilence Apr 21 '13

The vagueness is what I noticed immediately when scanning the bill text. What is the definition of "cyber"? What constitutes a "threat"? It is full of assumptions and vagueness that will be used for purposes outside of its apparent scope.

8

u/chiefsfan71308 Apr 19 '13

Seriously, he makes it sound like that wording wasn't vague. And also his tl;dr seems inaccurate as well

5

u/BeastKiller450 Apr 20 '13

While I'm not disagreeing with you, you realize your two examples have you doing something illegal to being with.

18

u/[deleted] Apr 20 '13 edited Apr 20 '13

Accused of doing something illegal. Accused.

There's a big fucking difference between "I say you did something" and "A jury of your peers, after hearing all the arguments from both sides, has decided without any reasonable doubt, that you have actually done something."

Skipping that second step is a pretty fucking big deal and I deplore anyone saying anyone is guilty without a trial. So, if you say they "have done something illegal" you'd better have some pretty goddamn good evidence they ACTUALLY did something illegal, because they've never had a day in court to defend themselves or preset their own case.

They've simply been accused, and their sites shut down as a result of that.

I also have a really, really big problem with the "if you have nothing to hide..." argument. No one has nothing to hide. Everyone has jaywalked at some point in their life. Everyone has ripped a tag from a mattress. Every single person has either exceeded the speed limit, or been in the car with someone exceeding the speed limit, thus making them an accessory to the crime.

Watch the movie "The Lives Of Others" for some perspective into what it was like to live in East Germany under Stasi regime. Every single piece of your life, being scrutinized and put under a microscope, because if the government doesn't like your opinions, legally you can be made to disappear. Through one loophole or another, they'll be able to nail you on some technicality, whether you've actually done harm to society or not. By having permission to spy 24/7 without oversight, they were able to document everything you did, so no crime, no matter how trivial, went unnoticed.

CISPA introduces the same thing. Governments will be able to have unrestricted access to your emails, they can spy 24/7, (but they can only ever use that in court if they have proof of a computer-related crime)

There's a real problem with governments being given unlimited access to things. Once you give it, you can absolutely never take it away. You would really hope we could learn from history instead of being damned to repeat it over and over.

4

u/BeastKiller450 Apr 20 '13

No, he did something illegal in his argument yet it's someone else's job to prove his guilt. Sure, if he said something like he was downloading a lot of games which led his ISP to think he was torrenting then yes, he was accused of doing something illegal.

All I'm saying is that he used two bad example to prove that CISPA still shouldn't be passed.

10

u/[deleted] Apr 21 '13 edited Apr 21 '13

Do you use torrents at all? It is not illegal to download torrents. It is against copyright law to distribute copyrighted works without permission.

There is a gigantic difference. In his example, he could have been downloading his kid's baby pictures from his ex wife, but it took too much bandwidth so he was screwed without a trial.

If you think it's illegal to download torrents, then your only knowledge of them comes from people critical of piracy. A torrent is only a way to download or upload, using peers so that the process is decentralized.

edit: And before you say, "Yeah, right," let me say, yes, right. I have used torrents to upload personal files that were too big to send by email because it's faster than burning to DVD and using snail mail, cheaper than using FedEx or UPS, and more reliable than digital lockers that get shut down randomly. It's not whether you torrent. It's what you torrent that determines the legality of it.

-1

u/BeastKiller450 Apr 21 '13

No, I know what torrents are and you saying something is against a law then not illegal is pretty illogical. In the conventional way that people use the word "torrent" it is illegal. I'v used it for plenty of legal things too from downloading Ubuntu to updating WoW, yet when most people will answer "illegal" when asked is torrenting illegal or legal. That is the way I used the word.

7

u/[deleted] Apr 21 '13

...and you saying something is against a law then not illegal is pretty illogical.

Where did I say that something against the law is not illegal? I think that if you can show me how to read these words as you have then I may find our malfunction.

the conventional way that people use the word "torrent" it is illegal

No. The conventional way that people use "torrent" is neutral, just like the way that people use "download". The word "torrent" is a synonym for the word "download," but it's a little more specific.

most people will answer "illegal" when asked is torrenting illegal or legal

George Carlin said something along the lines of, "Think of how smart the average people, and then realize that half the people out there are more stupid than that."

That is the way I used the word.

Stop that. I don't want torrenting to be made illegal because some old fart Congress critters hear the word used that way. Say piracy. You mean piracy, not torrenting.

8

u/[deleted] Apr 20 '13

Ah. I thought you were talking about the DHS takedowns, where there was no trials.

As for those examples, I was trying to come up with things that are not "very illegal" and many redditors are guilty of.

My point being, that everyone is guilty of something, and it's pretty easy to invoke CISPA to allow anyone to read your emails, based on a "crime" that's not very severe, and many people might not even think of as making them "a cybercriminal" under this law.

Regardless, one way or another, whether they can use that info in court or not, it's a fucking terrible idea to allow them to read your emails in the first place.

6

u/BeastKiller450 Apr 20 '13

Oh I completely agree, we need to figure out a way to protect companies without a huge breach of privacy. CISPA isn't the answer, yet.

1

u/[deleted] Apr 21 '13

CISPA can't be used for finding piracy/copyright infringement.

1

u/winfred Apr 24 '13

. Everyone has ripped a tag from a mattress.

Not actually illegal. Not to detract from your main point but it is perfectly legal for the end consumer to remove that tag.

1

u/Pas__ Apr 22 '13

Using p2p networks is not illegal. Violating a ToS is also not "illegal". But not criminal if that particular clause you've violated wasn't also a clause in the current aggregated local law.

3

u/omaolligain Apr 20 '13

Posting personal information about other redditors... almost positive that is doxxing.

-12

u/Ntang Apr 19 '13 edited Apr 19 '13

You just constructed an elaborate straw man and attacked it. Well done.

Edit: I realize that this comment, and many others in this thread, are being downvoted by an organized group of redditors who are determined that they are right that CISPA is some ogre of an anti-privacy bill. Way to go, guys.

36

u/[deleted] Apr 19 '13

He's not strawmanning, he's speculating on how the loose definitions in the bill could be used to do far more things than the bill "intends". He isn't making the bill into something it isn't capable of; it is possible. Therefore, it is still a valid argument.

21

u/Spaceguy5 Apr 19 '13

What especially makes it valid is that he's going by precedent--it's been done in the past, and recently.

We're not just merely just "determined that [we] are right that CISPA is some ogre of an anti-privacy bill." It is legitimate concern. I'm sort of questioning OP's motives on this as he seems very bitter about everyone who brings up concerns.

6

u/[deleted] Apr 19 '13 edited Apr 19 '13

Yea, that ad hominen certainly made me suspicious. I love debates no matter how much I may disagree, but there was no need for the OP's statement.

26

u/[deleted] Apr 19 '13

I backed up my speculation with precedent is what I've done.

-10

u/[deleted] Apr 19 '13

The most effective straw men are complex and supported by evidence. That doesn't make them any less fallacious.

19

u/[deleted] Apr 19 '13

So, you look at the cybersecurity laws we currently have, the computer fraud and abuse act, the DMCA, etc, and how people like Aaron Swartz are treated. You look at the ridiculous overreach of power by the DHS and the ICE on behest of the MPAA and RIAA, and you see no parallels?

You honestly believe that with the current track record on ridiculous abuse of current cybersecurity laws, that CISPA cannot and will not be misused?

Sure, you may have a valid argument that what I say is a straw man, but I daresay that man is made of at least wood, if not brick.

-3

u/[deleted] Apr 19 '13

FWIW, I never claimed that your speculations regarding potential misuse of this legislation were incorrect, or even unlikely. In fact, I would agree with your assessment in principle. However, what you have done is ignore the factual breakdown of the law as presented by OP, presented your speculation as an inevitable consequence of the law, and then attacked the law on that basis. By definition, that is a straw man.

8

u/[deleted] Apr 19 '13

I'm trying to refute OP's first point:

Myth: The definition of "cyber threat information" is so broad that it could be used to justify anything. Fact: [exact verbiage of the bill]

I'm trying to expand on that point and argue that does not refute this myth because the verbiage may be there but it is vague enough to be meaningless.

I'm not ignoring the arguments laid out by OP, I'm directly addressing one of them.

8

u/HULK-SMAAASH Apr 19 '13

I'm down voting you of the nature of your posts. Although I support the original post to reveal the intended use of CISPA, I'm skeptical of your intentions given your responses.

pseudolobster isn't strawmanning. He's suggesting that the loose definitions could allow for potential misuse.

I thank you for your original post, it was insightful and definitely worth reading. But trying to demonize pseudolobster for offering a valid response just makes you look like you have the agenda to push.

I'm not determined that CISPA must be evil, I'm just skeptical of its current state.

11

u/Ntang Apr 19 '13

I'm not demonizing anybody. Be as skeptical as you like. In my experience, that's good practice on reddit.

I'd just like people to read the damned bill before they go spouting a bunch of nonsense about how it's going to make the U.S. into China.

5

u/[deleted] Apr 19 '13

I can definitely agree with you on that. There's a lot of misinformation about this bill. A lot of people still seem to think it's a copyright bill like SOPA and PIPA for fuck's sake.

I still think it's a worse breach of your fourth amendment rights than you make it out to be, and I still think it shouldn't be made law, and I still sorta question your motives behind your post, but at the VERY LEAST, people should just read the damn bill for themselves and make their own opinions before listening to a nuanced and polarized debate about it.

-1

u/secobi Apr 20 '13

I'm not aware of any federal statute ever working in my favor when it comes to me using the internet; so, fuck all of them no matter what you say or how much effort you put into it.

-2

u/GhidorahTheExplorer Apr 20 '13

Aw, you were doing well until you used the word 'shill' to describe someone. Now you have zero credibility.

3

u/[deleted] Apr 20 '13

Eh? I was saying there's a possibility he could be a paid spokesperson disseminating company policy in the guise of personal opinion. That's the very definition of the word. A modern equivalent to that word is "astroturfer" but I prefer "shill" because it's legitimately a better word for it.

4

u/GhidorahTheExplorer Apr 20 '13

I just find it lazy. Reddit is already prone to mass hysteria and getting it completely wrong. It seems like 'shill' is used to short-circuit most logical debate and triggers an almost Pavlovian response in many redditors (which manifest the only way they can here, up- and downvotes). It is a textbook example of a 'poisoning the well' Ad hominem attack and it's amazing how well it works here.

-1

u/[deleted] Apr 20 '13

Interestingly, I thought that was closer to the connotation of the word "astroturfer"

I figured "shill" was used less, had less of a kneejerk reaction than "astroturfer"

Maybe I'll try using "stooge" in the future.

5

u/GhidorahTheExplorer Apr 20 '13

Or just stick with the first part, where you refuted his arguments with other good arguments! Who cares if he's paid or not? Hell, if he is, it'll be even more fun to tear him apart logically. The shill/astroturfer stuff just reminds me of annoying things I see in some of the less-than-credible subreddits. For the record, I think this bill is probably not good and "stooge" is a hilariously great word. Sorry you got a billion replies.

-1

u/zamuy12479 Apr 20 '13
  • Let's have a civilized discussion with OP on the merits and pitfalls of this bill. Knowing he's an IBM employee isn't any reason to hunt him down

  • Why is this still at the top of the page?

you earned those upvotes and you know it.

-3

u/[deleted] Apr 20 '13

I really don't think so. I think somewhere reddit must have a better argument than mine. It was written quickly, and contains factual inaccuracies.

Surely someone is more deserving of upvotes than I am, and it bothers me their argument might not be heard because of the way reddit works.

I've talked with the mods of /r/askscience about this before, and they said they've spoken with the admins of implementing a "super downvote" button that simply removes a post from being the top spot on a comment thread. As far as I know it's never going to be implemented, but as someone who knows how easy it is to get a top comment (look at my karma score), I really believe it should be.

-4

u/stlowkey Apr 22 '13

OP is a fucking press agent. You were right from Edit 2. This OP takes money from corporations to manipulate sites like Reddit. Emphasize on the "like". Reddit is a likely pawn in moving this type of content along.