back
166 comments
Did I call this? Yes, I think I called this. The Obama bill (note: Obama-supportin' Democrat here) is worse than CISPA: an everything-and-the-kitchen-sink bill that randomly creates incentive programs, new research organizations, a "cybersecurity tip line", and federally funds research into DNSSEC (DNSSEC: Rated S for Statutory).

Also worth noting: nothing in the Lieberman bill that this EO is patterned on creates enforcement mechanisms for IP and copyright enforcement, or for collecting customer information from ISPs. Of course, neither did the GOP's CISPA bill. That's because neither regulatory effort is about user information.

The problems both of these ill-conceived bills are addressing are simple.

Problem 1: There is no coherent strategy in the (vast, sprawling, chaotic) federal government, which is the largest IT operator in probably the world. Every agency does something slightly different. This means (a) nobody is doing exactly the right thing (usually, they aren't doing anything close to the right thing) and (b) it is prohibitively difficult to introduce new technology to help fix things, because everyone you'd get to buy it has a different set of hoops to jump through.

Problem 2: If you were a foreign adversary who wanted to cripple the US with electronic attacks, you probably wouldn't bother hitting government IT systems. Instead, you'd go for something like the power grid, or a trading exchange. Those systems are privately operated, and so nothing the government does to try to track, monitor, or deflect online attacks can benefit them.

I am glad that HN is even able to discuss politics with some sanity.

Was just scrolling through Reddit to find their take on the subject, but after the 10th "Romney eat my hamster" story I just gave up.

This leads of cause to my conspiracy, that Reddit was highly active in the anti-CISPA movement, and the recent Obama visit political motivated to create goodwill for the upcoming executive order.

Just curious, how can you support a president who is so blatantly a hypocrite and liar? I am not suggesting that Romney is a better alternative by any means, just curious as to why smart people like yourself continue to stand by this man who could care less about civil liberties?
I ask myself, what would I rather do? Vote for a guy who wants to close Guantanamo Bay but not enough, and who wants guaranteed-issue health care enough to stake his Presidency on it... or, implicitly or explicitly, vote for a guy who doesn't want to close Guantanamo Bay and who has said his first action after election will be to set in motion the repeal of guaranteed-issue health care?

I guess I'm just a dummy.

I know you're not a dummy and don't mean to insinuate that, but I've had this conversation with people over and over and am just trying to understand it. We are choosing between the lesser of two evils here and it's extremely frustrating. I feel like it's time to stick to principles here and affect change like we would want to see in the business world. When there is a major problem in business, our instinct is to disrupt it to make money. Why do we throw our hands up in the air and say 'oh well' when we see such major problems in government?
You could vote (any) 3rd party. Not because you hope they win; they won't. And because they won't, a vote for 3rd party is a vote for none of the above (two). Which I think is the best possible vote, because the two current stewards of democracy, debate and engagement are failing.
References on Obama supporting Internet privacy?

I believe Obama's publicly stated position in 2008 was to set up this system: http://www.politifact.com/truth-o-meter/promises/obameter/pr... and http://www.politifact.com/truth-o-meter/promises/obameter/pr... and http://www.politifact.com/truth-o-meter/promises/obameter/pr....

Hard to be a hypocrite and a liar when you follow through with your own policies. Not that I agree with this one though.

Solution to 1 & 2: Make use of Windows on any Federal computer or power grid control system illegal, punishable by public whipping.

Let's call this EO what it is: erosion of privacy, redux.

This has nothing to do with political parties. This is about money. Stinks of MPAA...

In exactly what sense does this EO have anything to do with privacy? It is a more limited version of Lieberman-Collins; you can read that bill online right now, and it's linked from the story. You should be able to find a clause or pattern of clauses that points to "erosion of privacy".
>Solution to 1 & 2: Make use of Windows on any Federal computer or power grid control system illegal, punishable by public whipping.

Huh?

Obama has been shameful on civil liberties. The sad thing is that it has traditionally been the Republicans who push against the limits of civil liberties and the Dems who at least pretend to care. Thanks to Obama, the Dems have flipped over so completely against civil liberties that there really is no remaining government interest protecting us. It's a Nixon goes to China moment, Obama has done more to destroy civil liberties than any Republican ever could have dreamed.
The Democratic Party has completely removed civil liberties policies from their platform for 2012, even though it was one of the main things they ran on in 2008.

http://www.motherjones.com/mojo/2012/09/democrats-retreat-ci...

Romney would obviously be even worse for this, but yeah - this is what you get with a 2 party system. It just gets worse and worse. My only hope is that once Republicans lose this one, then by 2014 or even 2016 they reform the party, and the libertarians inside the party get to heavily influence the platform towards more civil liberties, and attack the Democrat Party on it at the next elections, so they can win on it. Other than that, I'm not sure how you'll get either the Democratic Party or the Republican one to start caring about this again.

Civil liberties weren't one of the main things Obama ran on in 2008. Obama ran on the economy and on a fixed timetable for ending the Iraq war.

To make the argument that civil liberties were a key focus of the Obama 2008 campaign, you should be able to provide a Google News search query from (say) July-October '08 that demonstrates that fact. I just tried to find one and couldn't.

We are (mostly, and myself included) social liberals on HN, and Obama was the liberal mainstream candidate in 2008, so I think we tend to project things onto him that aren't really there. Obama is first and foremost a pragmatist. Closing Gitmo was worth less to Obama than getting health care passed.

Romney would be better and I give only one reason.

If we start making these guys all one term Presidents maybe, just maybe, they might know who they are beholden too.

So anyone is better than the current guy and so and so on.

So I am quite willing to put up with four years of Romney if it means a message is being delivered. I am quite willing to get him out as fast too.

It's called the Democratic party. "Democrat party" is a slur used by Republicans, and its usage suggests someone who either views the party in a derogatory way or who is underexposed to non-right-wing news sources.

See http://en.wikipedia.org/wiki/Democrat_Party_%28epithet%29

> Romney would obviously be even worse for this

I am not sure how you come to this conclusion. Is it something he said, or history of his actions, or a general attitude against the Republican party, or something else?

I am hoping they will be motivated by a Gary Johnson victory.
Obama has done more to destroy civil liberties than any Republican ever could have dreamed.

Ridiculous. I understand the perspective that civil liberties online are under a constant assault by the government, but no reading of the actual facts could lead someone to the informed belief that Obama's DOJ and NSA are worse than Bush's, or, for that matter, Clinton's or Bush I's.

The Patriot Act alone is a decent case that Bush and Obama (by passing and reauthorizing, respectively) have been worse than their predecessors. And Obama has taken many transgressions farther than Bush, both in direct actions and in attempts to hide information about actions, including government immunity for surveillance violations [1], citing exceptions to open record laws [2], ignoring FOIA requests [3], prosecuting whistleblowers [4], use of national security letters, saying that they can't tell us how many Americans they've spied on[5], etc, etc. The TSA seems to gotten more annoying, too.

[1] http://www.eff.org/deeplinks/2009/04/obama-doj-worse-than-bu...

[2] http://www.sunjournal.com/node/815552

[3] http://www.politico.com/news/stories/0312/73606.html

[4] http://www.nytimes.com/2012/02/12/sunday-review/a-high-tech-...

[5] http://www.wired.com/dangerroom/2012/06/nsa-spied/

no reading of the actual facts could lead someone to the informed belief that Obama's DOJ and NSA are worse than Bush's, or, for that matter, Clinton's or Bush I's.

Oh? What about everything related to civil liberties going severely downhill since Bush? Take the NSA "spy center" in Utah we're all aware of by now. How's that for Change You Can Believe In?

Now, why is it that whenever there's a post about the US government being up to no good, you are all over the place defending the government or making things seem less serious, or like this time, just mixing things up?

Are you some kind of perception management agent or what?

Last time there was a post that um.. required your intervention, the thread was like half-full of your posts. Seriously. What the fuck? What are you doing?

Everyone who lives in reality knows you've got quite a police state going on over there. Everyone knows your government is totally owned by Wall Street and other elites [1]. Everyone knows your police force is full of thugs that tase people to death for fun. Countless Americans have had their houses fraudulently foreclosed on by the banks.

America is swirling down the drain. What the hell are you trying to accomplish here on Hacker News by trying to polish the turd of reality?

[1] Well, except for Ron Paul and a couple of other people.

The thing is, I don't think Obama has cut any of the stuff Bush added. So if he's made things even a little bit worse than it's the worst ever...
QoTD: "America is swirling down the drain. What the hell are you trying to accomplish here on Hacker News by trying to polish the turd of reality?"

See also: http://www.pbs.org/wgbh/pages/frontline/iraq-war-on-terror/t...

Your statement is ridiculous - by your own logic Obama took it from them and then assault is continued by his government.
Interestingly, since Obama is "democrat" he can easily push right-wing changes and get away with it. His supporters then go "he is a good guy, but evil republicans forced him to". If any republican would try it, there would be strong outcry.

There is a good article at Political Compass: http://www.politicalcompass.org/uselection2012

(Also, take the test, you'll be surprised.)

Have you guys read Lieberman-Collins? It's linked from the story. You should, if this EO is truly an indicator of Obama's retreat on civil liberties, easily be able to point out clauses from the bill that make that point.

I've read it. I don't think it'll be as easy as these comments make it sound.

That was a terrible quiz for several reasons.

1) Some of the questions simply don't make sense, i.e. "Multinational companies are unethically exploiting the plant genetic resources of developing countries." The what resources?

2) It completely conflates personal beliefs with those I would want to see forced upon society at large.

3) Some of the questions have totally ambiguous interpretations in terms of the two given axes. If I agree with "An eye for an eye and a tooth for a tooth", does that make me more or less authoritarian? What about "Abstract art that doesn't represent anything shouldn't be considered art at all"?

Also, the points assigned to famous political figures are totally arbitrary. Neither Hitler nor Hu Jintao have taken this quiz, so the author is simply making up answers for them.

I agree that Obama has been shameful re: civil liberties...so have recent Republicans. But please hold your denigration from the Democrats. They don't care. At all. 95% of Congress doesn't care. At all. Regarding Nixon in China, you need to read up on your history. For all of Nixon's faults (and they could build a mighty big Five Guys burger's worth)...the fact is that he opened up China for the first time ever for this country. That is the big deal. So, your implication is that Obama has done the same for our civil liberties? Are you implying that Nixon sacrificed our civil liberties in order to dialogue with the Chinese? I'm not even sure what you're implying. Please enlighten me.
In political circles it is thought that a Democrat president could never have been the first to go to China because they would have been accused of supporting communists. Only a Republican president could do it because he was insulated from attacks from the right. The idea I was trying to express in my comment is that Obama can go further to attack civil liberties because the left won't criticize him. When Bush was president liberals would frequently criticize civil liberties issues, nowadays they are silent.
There is that somewhat famous quote by Joseph de Maistre that translates to "every nation gets the government it deserves".

Judging on the government that America currently has, and recently had, I am starting to wonder if the American People really are so bad as to truly deserve that....

It's more of a 'Wilson pushes for WWI despite having campaigned against it' moment.
What did you expect? Even before getting elected Obama voted for telco-immunity, and then picked Biden as VP, who not only helped write the DMCA and is a well known drug warrior, but who proudly claimed to have written most of what become the PATRIOT Act.
Senator Dodd gave a very impassioned and long speech on the floor arguing against that retroactive immunity.

It didn't involve identical issues as his efforts for the MPAA, but it is a pretty radical change in sentiments nonetheless.

If we can be unpleasantly surprised, it would be nice to be pleasantly surprised every now and then, too.

Another review from someone who has seen the draft: http://www.federalnewsradio.com/241/3026867/White-House-draf...
After Anonymous (or an individual in Anonymous) shut down millions of small business websites today, this legislation or executive order is now far more likely to happen. Enough people with clout will want to prevent "hackers" from messing with their businesses and will accept whatever line of thinking is promised to deliver them from this evil.
There are major successful attacks against networks and businesses every single day. Not just small businesses; I'm talking about banks, power companies, etc. You only hear about the ones that make the news, which is almost none of them. But they are definitely happening, which is why there is urgency to do something on cybersecurity now.
I like how this happens after his reddit IAmA where he espoused in a specific answer that he would work in the interests of internet users to maintain a free internet and not enact, support or enforce policies/legislature of this nature.

This is politics as usual.

I especially like the fact that the reddit hive mind has completely ignored this story, but any time some pizza guy gives President Obama a hug, or Mitt Romney stumbles on his words, it makes the front page.
Most of the comments in this thread are about either defending or bashing Obama. I personally only care in finding ways to limit the means our government has of needlessly gathering information on us. I am aware that this is a losing battle but the idea of civil liberties and the societies that they encourage are more important then a tit-for-tat discussion about who did what.
My position on the security-liberty spectrum, as with many on HN, tends towards liberty. But the risk of an offensive cyber hit on critical infrastructure is real. If not a voluntary bulletin and audit network, how should the U.S. ensure the viability of its critical infrastructure against cyber attack without compromising civil liberties?
As someone who has a more insider perspective on critical infrastructure perspective, I think that what really needs to change for the better is the culture of awareness and understanding of modern software in the SCADA world. Right now it's where IT was in the early 90s, IMO.

My personal opinion is that certain facilities and services (say, water management systems or the electric grid) must be federally regulated, with aggressive fines and various charges for negligence and slackness. There must be a real and definite risk factor to being a slacker. Right now, there isn't- not really. The risk is very small for the cost involved in upgrading infrastructure and having annoying security people telling you that the Internet is a source of problems and to stop communicating over telnet. :-)

I used to follow the SCADASEC mailing list which had several excellent descriptions of the culture problem.

This, by the way, is the original Democratic "Rockefeller bill" take on the "cybersecurity" problem, and what I was actually invoking when I said Obama's preferred version of CISPA was worse than CISPA; what he actually came up with (this EO) is less bad than what I assumed he'd come up with (the Rockefeller bill).

In short:

The Rockefeller solution to the critical infrastructure problem is:

1. Allow the government to, with some due process mechanism, designate private entities as "critical infrastructure"

2. Allow the government to define, more or less by fiat, a set of qualified auditors for critical infrastructure

3. Mandate that critical infrastructure operators get audited

Between this and his sponsorship of DOJ domain seizures ,without due process of any kind, it's hard to see how any technologist could support Obama.
Excuse my ignorance, but what is CISPA like about this? The Federal News Radio link talks about the EO is significantly more detail.
CISPA is very short and merely establishes a voluntary mechanism by which a power grid operator (for instance) could subscribe to an iDefense-like service operated by the government to get updates about attacks and push back updates about probes they themselves had noticed.

Lieberman-Collins does the same thing, but also establishes a "cybersecurity tip line" and a regulatory regime for who in the FedGov can receive info from that tip line, something like 20 different new research mandates, a certification program from critical infrastructure operators that exempts them from civil liability, a mandatory periodic research report to congress on DNSSEC, a retention program for cybersecurity workers in the government, new GSA regulations making sure that people don't buy fake Cisco routers, and like 40 other things I forgot after reading the bill.

Nice! I was being somewhat facetious so hopefully people came to the conclusion themselves that the situation is nothing like what the title of this thread is describing. Pretty sad that the copyright lobby has poisoned the water so badly that "get out your pitchforks!" will be a standard reaction to any cybersecurity legislation for years to come :-(.

From the Federal News Talk Radio article, I don't see why any of the following are unnecessary or wasteful. Sounds pretty straightforward and at least somewhat useful to me:

One subsection would ask industry to voluntarily submit cyber threat information to the government. The draft order says this data wouldn't be used for regulatory purposes or used against companies. Sources say there aren't any liability protections in the EO because that could only come from Congress.

A second subsection would require DHS to undertake privacy assessments of the data they collect around critical infrastructure.

A third subsection limits what critical infrastructure is included under the draft EO, and makes clear that First Amendment protections will apply to how the government identifies critical infrastructure.

A fourth subsection would address acquisition and the preferences for products and services that meet the cyber standards developed by the DHS-led council.

The final subsection would call for a report within 120 days discussing possible incentives such as liability protection, expedited security clearances and recognition by the government that the critical-infrastructure owner and operator meet the voluntary standards.