Hacker News new | ask | show | jobs
by jellicle 3895 days ago
> Example from today's AMA is FFTF's claim that CISA "exempts itself from FOIA", making it impossible to challenge in court: they're referring to Sec 4 (d) (4) (b), which exempts from FOIA individual shared indicators, which of course must be the case, because indicators are things like compromised account names and passwords. That's all the law exempts from disclosure.

Nope. The bill clearly defines "cyber threat indicators" to include the entire content of whatever these companies disclose to the government. The things that make up "cyber threat indicators" go on for an entire page, and it's an "or" list rather than an "and" list. For Facebook, it would probably be something like a particular Facebook post that tripped their "threat" trigger, plus all the info that Facebook has about that user account (maybe every post that account ever made), including IP addresses that posted to that account and everything else.

And yes, every single thing "shared" with the government (I'm reminded of "the sharing economy" with this usage) is entirely exempt from FOIA disclosure, as the CISA bill clearly says. And of course no cause of action shall lie in any court, so there's no help there either. So no, there will never be any way to review the scope or magnitude of this "sharing", apart from whatever information (truthful or not) the government deigns to share.

Your description of CISA is the one that is straight up dishonest.

1 comments

I'm not sure who you're arguing with. Are there people advocating for CISA by saying it's only about metadata? I'm not one of those people.
I'm arguing with your lies that the only thing CISA exempts from disclosure are "compromised account names and passwords".
You write that as if my comment isn't right there for everyone to read. That's obviously not what I said.

I even took the time, elsewhere on the thread, to summarize all the different classes of data that CISA deems "indicators":

https://news.ycombinator.com/item?id=10454172