Showing posts with label DHS. Show all posts
Showing posts with label DHS. Show all posts

Tuesday, December 31, 2019

While You Slept, Government Created Internal Passports

AIER.  November 4, 2019
The deadline of yet another, and perhaps the most insidious, element of the post-9/11 initiatives (a partial list of which includes the establishment of the Transportation Security Agency, the Department of Homeland Security, and a never-ending international war against a nebulously-defined, noncorporeal enemy, “terror”) is less than one year from coming to fruition. Beginning no later than October 1, 2020, citizens of all US states and territories will be required to have a Real ID compliant card or US passport to board a commercial plane or enter a Federal government facility. Pundits citing the inevitability of what amounts to a national ID card have, regrettably, been vindicated.

To be sure, some states have resisted, but dependence upon Federal aid and other programs administered from Washington D.C. makes their ultimate surrender and compliance inevitable. 
Looking back, Social Security numbers and the cards bearing them broke ground for the path to a national identification system — thank you, Franklin Delano Roosevelt. For decades there have been pointed reminders that the cards were intended to be account numbers and not integrated into a government registry of American citizens. 

Repeated efforts, starting in the 1970s, to forge identifiers from the Social Security system have been rebuffed: in 1971, 1973, and 1976. The Reagan Administration indicated its “explicit oppos[tion]” to a national identification system. Both the Clinton healthcare reform plan (1993) and a provision of the Illegal Immigration Reform and Immigrant Responsibility Act of 1996 requiring Social Security Numbers on driver’s licenses were rejected (the latter in 1999) to some extent upon the basis of tacitly constituting national identifiers for Americans.
 
There are any number of reasons why the alleged trade off between liberty and security that a national ID card represents are being misrepresented. Any system designed, maintained, and run by human beings is ultimately flawed, and in any case corruptible. The existing documents from which the information fed into the Real ID program are eminently vulnerable to forgery. To provide just one example: tens (perhaps hundreds) of thousands of Americans don’t have verifiable, “official” birth certificates.

Wednesday, December 23, 2015

The controversial 'surveillance' act Obama just signed


President Barack Obama signs the budget bill in the Oval Office of the White House December 18, 2015 in Washington, DC.
President Barack Obama signed into law a $1.1 trillion spending bill last Friday, staving off a potential government shutdown — and in the process, quietly inaugurated what some have called a second Patriot Act.

As part of the more-than-2,000-page document, the 14th rider to be exact, the appropriations omnibus includes the Cybersecurity Act of 2015. Buried within that section is the text of the Cybersecurity Information Sharing Act (CISA), a bill that seeks to permit private companies to handover information to federal agencies.

In essence, the law allows companies to directly share information with the Department of Defense (including the National Security Agency) without fear of being sued. This info can be used for cybersecurity purposes, but critics have keyed into the law's allowance for using the data to address or investigate a "specific threat" of death, serious bodily harm, serious economic harm, terrorism, harm to a minor and more.

As Wired noted, an earlier bill only allowed information sharing in the case of "imminent threats," but the new "specific" verbiage disregards any timeliness.
The House Committee on Rules described the information sharing measure as "a voluntary cybersecurity information sharing process that will encourage public and private sector entities to share cyberthreat information, without legal barriers and the threat of unfounded litigation — while protecting private information."

As benign as that description may sound, several legislators released comments decrying the implications of the CISA measures.

"I was unable to vote for the omnibus spending bill today because it included an extraneous provision purported to facilitate cybersecurity information sharing that — in effect — will function as a surveillance tool," California Rep. Zoe Lofgren said in a statement.

Oregon Sen. Ron Wyden was even more critical, saying the "unacceptable surveillance provisions" are a "black mark" on the rest of the appropriations bill. He even implied that the information sharing provisions are worse than in previous incarnations.

"Ultimately, I cannot vote for this badly flawed CISA bill. The latest version of CISA is the worst one yet — it contains substantially fewer oversight and reporting provisions than the Senate version did," he said in a statement. "That means that violations of Americans' privacy will be more likely to go unnoticed."

To Wyden's point, 55 civil society groups, security experts and academics, wrote earlier this year that CISA would "seriously threaten privacy and civil liberties, and could undermine cybersecurity, rather than enhance it."

These complaints may be blowing the scope of the bill out of proportion, according to Randy Sabett, vice chair of the privacy and data protection group at the law firm Cooley.

"I try to maintain a relatively open mind toward the arguments that people raise when they start talking about privacy and civil liberties, but I guess where I have difficulty is with some of these sweeping statements that it's a pure surveillance bill," he said.
 
Sabett pointed to CISA's voluntary nature — it doesn't compel any company to share data with the government, only prevents them from being sued for it. On the other hand, the law unequivocally requires both federal authorities and companies to scrub personal information from shared data.

Additionally, the law compels the government to issue regular privacy update reports to monitor any abuses, Sabett said.

And there are many who support the information sharing law, including Obama administration officials and industry groups.

"Cybersecurity is a top priority for DHS and the Obama administration, and this bipartisan effort is a significant step forward in strengthening our nation's cybersecurity," Homeland Security Secretary Jeh Johnson said in a statement after the omnibus spending bill was passed. "I look forward to working with Congress on further strengthening DHS' cybersecurity mission."

The U.S. Chamber of Commerce also put its support behind the new law. Recognizing that cybercrime targets both government and businesses, the Chamber's president and CEO, Thomas Donohue, said in a statement that CISA will allow businesses to voluntarily work with authorities "to better prevent, detect and mitigate threats."

"This legislation, long championed by the Chamber, is our best chance yet to help address this economic and national security priority in a meaningful way and help prevent further attacks," Donohue said.

Financial sector groups, such as the Securities Industry and Financial Markets Association and the American Bankers Association, have applauded CISA. Members of the Cyber Threat Alliance — which is made up of four companies: Palo Alto Networks, Fortinet, Symantec and Intel Security Group — were largely positive on the CISA measures in October.

"I have seen companies benefit from information sharing: To be in a situation where that information is like pulling teeth, and then to see the benefits that come out of it is an eye-opening experience," Sabett told CNBC. "Getting something on the books is going to have a lot more positive effects than the negative effects that the critics are pointing to."   CNBC
 
Everett Rosenfeld Staff Writer