Martin Michaels
The U.S. House Intelligence Committee passed a cyber-security bill Wednesday in an overwhelming 18-2 vote. Although the bill has yet to become law, The Cyber Intelligence Sharing and Protection Act (CISPA) of 2013 has already drawn condemnation from privacy advocates who say that the proposal fails to protect critical personal information on the web, possibly allowing corporations to share personal information with intelligence agencies.
For the Obama administration, CISPA remains an essential measure needed to curb the increasing number of cyberattacks launched by China, Iran, North Korea and other countries targeting U.S. government sites and private corporations.
“Congress must act … by passing legislation to give our government a greater capacity to secure our networks and deter attacks,” said President Obama during his 2013 State of the Union address. Obama’s speech precedes a comprehensive report by Mandiant, a private security firm that reported a sharp increase in the number of cyberattacks in February.
According to the 60-page study, Mandiant claims to have conclusive evidence linking the Chinese military to cyberattacks against more than 140 U.S. and other foreign corporations and entities.
With only two Democrats voting against the bill, the CISPA proposal heads to the U.S. House of Representatives where it could be put to a full vote next week.
Privacy groups fear that CISPA legislation is stripped of most protections that would prevent private corporations from sharing online consumer information with intelligence agencies. Consumers fear that credit card data, financial information and transaction histories with online companies could fall into the hands of intelligence agencies.
“While no portion of CISPA requires companies to share data with the feds, major telecommunications providers have illegally shared customer data with the NSA [National Security Agency] before, leading to a congressional grant of retroactive immunity in 2008,” CNET reporter Declan McCullagh reports.
Although not as sharp in her criticism, Rep. Jan Schakowsky (D-Illinois) voted against the latest version of CISPA during Wednesday’s closed-door markup meeting, offering amendments that would have strengthened privacy protections.
“My amendments would have strengthened privacy protections, ensured that consumers can hold companies accountable for misuse of their private information, required that companies report cyber threat information directly to civilian agencies and maintained the long-standing tradition that the military doesn’t operate on U.S. soil against American citizens,” Schakowsky told reporters after the vote.
Obama, originally opposed the bill when it was first introduced Nov. 30, 2011 by Congressman Michael Rogers (R-Mich.) and 111 co-sponsors. It was passed in the House of Representatives on April 26, 2012, but failed to receive the necessary support in the Senate.
At that time, President Obama’s advisers argued that the bill lacked confidentiality and civil liberties safeguards and they advised the president to veto it. Two months ago, the bill was reintroduced in the House, still lacking what privacy advocates claim are essential protections for average Internet users.
“I strongly agree with the need to enact effective cybersecurity legislation, and commend the bipartisan effort of the House Intelligence Committee, but this bill doesn’t sufficiently protect individual privacy rights,” Schakowsky said.