After adopting several privacy amendments in a closed door meeting last week, the Senate Intelligence Committee has publicly released the Cybersecurity Information Sharing Act (CISA). The bill would permit companies in the private sector to share information about their users’ Internet activity with the federal government. The Center for Democracy & Technology (CDT) welcomes many of the amendments, but still opposes the legislation.
“We are troubled that the bill continues to authorize companies to share communications information directly with the National Security Agency, and to require that information shared with one federal agency be immediately shared throughout the government, including with the NSA,” said Greg Nojeim, the Director of the Freedom, Security and Technology Project at CDT. “Information sharing is an important element of cybersecurity policy, but it must be approached carefully because the information that would be shared is derived directly from individual users’ activity online,” Nojeim added.
“This bill seems as much about surveillance as it is about cybersecurity: Everything a company shares with the government under the cybersecurity umbrella can be used for law enforcement purposes that present no imminent threat and are completely unrelated to cybersecurity,” Nojeim said. The scope of authorized law enforcement uses is broad, including ID fraud, ID theft, espionage, serious assaults, carjacking with intent to injure, extortion, arson, crimes involving firearms use or possession, bank robberies, drug robberies and many other crimes.
“Information shared for cybersecurity reasons should only be used for cybersecurity,” he concluded.
Referring to amendments that the Senate Intelligence Committee adopted, Nojeim said, “Some of the changes the Intelligence Committee made to address privacy and civil liberties concerns are substantial and welcome. For example, private entities will not be authorized to use countermeasures that destroy data on somebody else’s computer, regardless of the intent of the party operating the countermeasure. However, such countermeasures can be used to gain unauthorized access to users’ data, as well as impair authorized access and cause harm to data, so long as the harm is not ‘substantial.’”
CDT-led Coalition Calls for Transparency for White House AI Framework
CDT and Americans for Responsible Innovation led a broad, bipartisan coalition of over two dozen civil society groups in calling on the White House to release its Framework for review of frontier AI models.
CDT Amicus Brief Calls on Fourth Circuit to Rein In Geofence Warrants
Earlier this year the Supreme Court ruled in Chatrie v United States that the Fourth Amendment protected all cell phone location information, which CDT lauded as a landmark decision, but sent the case back down to the Fourth Circuit to assess the propriety of the geofence warrant at issue.
CDT and Partners Post Floor Alert Opposing CA SB 1013 Automated License Plate Readers Bill
The best way to ensure that Automated License Plate Readers are not abused is to limit the retention of stored data and to keep loopholes to lawful process closed. CA SB 1013 is a step in the wrong direction, and we urge the California legislature to reject this approach.
British Public Oppose Secret Surveillance Powers and Want Strong Protections for Encrypted Communications
CDT released nationally representative polling data revealing that a the British public are broadly concerned about the security, privacy, and free speech consequences of allowing law enforcement to access encrypted communications.