Question To Ask Anyone Who Supports CISA: What Breach Would It Have Stopped?
from the simple-questions dept
We've asked this before and no one answered. But with the faux "cybersecurity" CISA bill back on track for another vote, it's time to ask the question again: Can defenders of CISA explain what data breach it would have stopped? This is important, because many of the defenders of CISA keep pointing to things like the OPM hack as an example of why we need "cybersecurity regulations." Just yesterday, Senator John McCain used various recent high profile hacks as proof of why we need such a bill:The chairman of the joint chiefs of staff is uncomfortable about the cyberthreats to this nation -- which just took place where millions -- MILLIONS! -- of Americans had their privacy hacked into. God only knows what the consequences of that are. And the other side has decided to object to proceeding with a bill that passed through the Intelligence Committee by a vote of 14 to 1. This is disgraceful.But as policy counsel at the Open Technology Institute, Robyn Greene, recently noted on Twitter, none of the recent hacks would have been stopped if CISA was law.
When will Senators realize that NONE of the breaches (OPM, Sony, Anthem, Home Depot, etc.) would have been stopped is #CISA was law?
— Robyn Greene (@Robyn_Greene) August 4, 2015
John McCain wants to talk about "disgraceful"? Isn't it more disgraceful to point to an attack that this bill would not have helped with as a key argument for why this bill needs to pass?
This is some pretty serious hand-waving on the part of the politicians. Of course, the truth is that they simply don't understand the details enough to know what they're doing. They just hear from surveillance/law enforcement types saying that we "need cybersecurity legislation" and then they hear about these breaches and they immediately connect the two. Yet, they don't know what the law really does or why it's needed, and certainly don't understand how breaches happen or what it would take to prevent them (if that were even possible). So they just say "well, cybersecurity!" as if that's good enough.
It's not.
The changes brought about by CISA could have a pretty serious impact on our privacy and security and if Congress is going to pass it by pointing to these breaches, they should first be required to explain how the law would have helped to stop any of those breaches. We'll wait.
Thank you for reading this Techdirt post. With so many things competing for everyone’s attention these days, we really appreciate you giving us your time. We work hard every day to put quality content out there for our community.
Techdirt is one of the few remaining truly independent media outlets. We do not have a giant corporation behind us, and we rely heavily on our community to support us, in an age when advertisers are increasingly uninterested in sponsoring small, independent sites — especially a site like ours that is unwilling to pull punches in its reporting and analysis.
While other websites have resorted to paywalls, registration requirements, and increasingly annoying/intrusive advertising, we have always kept Techdirt open and available to anyone. But in order to continue doing so, we need your support. We offer a variety of ways for our readers to support us, from direct donations to special subscriptions and cool merchandise — and every little bit helps. Thank you.
–The Techdirt Team
Filed Under: breach, cisa, cybersecurity, hack, john mccain
Reader Comments
Subscribe: RSS
View by: Time | Thread
Cyber is a scary word
[ link to this | view in chronology ]
[ link to this | view in chronology ]
Re:
[ link to this | view in chronology ]
[ link to this | view in chronology ]
Pass-A-Law Bingo!
Child Porn!
Another 9/11!
Prevent Hacks!
Copyright Theft!
Stimulate the Economy!
True Americans!
Freedom (in the center)!
Safety!
Security!
[ link to this | view in chronology ]
I am suspect of true intentions
[ link to this | view in chronology ]
Then ask...
[ link to this | view in chronology ]
As opposed to the privacy hacked into by the NSA?
[ link to this | view in chronology ]
Yet Another Risk
A real personal security breach hazard.
[ link to this | view in chronology ]
So much for the "moral hight ground."
We've been hegemonic a-holes around on the other side of the globe, State Dept. & CIA fomenting rubblizing wars. Stirred up shit in Ukraine & blamed Russia for it. Used a "training exercise" to fool some low-level rocket-launch guy into thinking the Dutch airliner was the enemy so he'd blow it up, then pointed the finger of blame at the evil Russkies. What ever became of the plane's black box again?
The OPM family jewels have been "exfiltrated." But keep pokin' that bear. Go ahead, tweak Putin's nose again & see what happens.
Will anything be learned? We had more to lose than anyone else & we lost it. Thought we were too clever. Don't look now but they've got our balls in a jar.
[ link to this | view in chronology ]
There is problem #1. You are a peasant. There is no 'should' for humanoids of your type. Your program is faulty. Report for re-programming (you may have heard of this being called 're-education' - that just proves (as if it were needed, ha!) how out of date your software version is). Do it immediately.
[ link to this | view in chronology ]
We'll wait.
[ link to this | view in chronology ]
Re: We'll wait.
[ link to this | view in chronology ]