BREAK IN TRANSCRIPT
Mr. Speaker, I thank the gentleman from Georgia for yielding me the customary 30 minutes, and I yield myself such time as I may consume.
Mr. Speaker, I rise in opposition to the rule and the underlying legislation.
Today, the House is convening to debate a matter that we all agree is critical for our national security, our economic competitiveness, our prosperity, and the success of our private sector.
The recent cyber attacks on Sony and Anthem are but two prominent examples of cases in which American businesses or government entities have come under attack by hackers, among many other instances that haven't even been reported.
I want to recognize the work that the House Intelligence and Homeland Security Committees did on these pieces of legislation and their attempts to address these issues. Unfortunately, in spite of their hard work and the work of those that went into crafting these two bills, I regret that they fall short of their goals and would likely do more harm than good.
Not only do both bills, particularly the Protecting Cyber Networks Act, raise enormous concerns about inappropriate sharing of personal information and surveillance on Americans' private lives, but they are built on the premise that many security experts have warned is fundamentally flawed, that sharing information with the Federal Government should be the central focus of our efforts to protect American cyber networks, rather than simply one aspect to a multipronged strategy to defeat hackers, foreign and domestic.
Now, before I address the substance of these two bills, I want to discuss this unusual rule before us and how it treats two bills which contradict each other in significant ways.
Ordinarily, when two committees share jurisdiction over a matter--in this case, the Homeland Security Committee and the Intelligence Committee--they collaborate. One committee handles one portion of the bill, reports it out; the other committee handles the other portion, reports it out, and they work together to bring a single piece of legislation to the floor for Members to debate, amend, and vote for or against.
This is what happened, for example, with the recent SGR repeal legislation, which had components under the jurisdiction of no less than six different committees in this body, but was presented before us as a single bill.
In this case, however, because there seems to be some kind of turf war between the Intelligence Committee and the Homeland Security Committee, we are actually voting on two overlapping bills that, in several respects, contradict one another.
For instance, the bills have drastically different determinations of what kind of information may be shared, what purposes the government may use the information for, and what hacking countermeasures companies are allowed to take to protect their networks.
Instead of having a meaningful debate on the merits of each bill's approach, this body, if this rule passes, would forego that, and we would simply debate and vote on each bill separately, and if they both pass, the rule directs the Clerk to mesh them together through something called conforming amendments.
Not only would this leave businesses to wade their way through two separate, contradictory regulatory schemes, but it leaves it unclear which bill's provisions would actually prevail in practice and under which circumstances. It actually would create more uncertainty in the marketplace, rather than less.
I don't think anybody could reasonably call this an open process. We shouldn't be depriving our constituents of an open debate on important issues. The major amendments of this bill that would have restored privacy, many of which I was a cosponsor, are not even allowed to be debated on the floor of the House, not for 10 minutes, not for 5 minutes, not even for 1 minute.
My colleagues and I on both sides of the aisle are being denied a vote on the very amendments that we feel could address the concerns we have with the cybersecurity legislation and make sure that we keep American networks safe.
Mr. Speaker, in the 2 years since the NSA's shockingly broad data collection program PRISM came to light, we have heard from many of our constituents. The American people want an end to unwarranted surveillance. They want Congress to restore desperately needed accountability and transparency to our Nation's often out-of-control intelligence-gathering apparatus.
It is bewildering to many people that, at the very time the American people have spoken out that we want more safeguards, instead, we are bringing forward two bills whose central objective is to facilitate the flow of more personal information to the Federal Government, when we continue to put off the question of surveillance reform and bringing an end to the NSA's bulk data collection without warrants.
It is especially disappointing in light of the fact that several PATRIOT Act provisions will sunset at the end of next month, giving Congress a crucial opportunity to reexamine and rein in Federal surveillance programs.
By putting off that issue and bringing mass information sharing to the floor, Congress is asking the American people for a blank check. Congress is saying: Trust the President. No President would allow this information sharing to infringe on your civil liberties, even though we have utterly failed to pass a single piece of legislation to end the privacy abuses that we know have occurred under this administration and the prior administration.
The problem with these bills is that they go far beyond, and they open up additional loopholes and potential abuses with regard to privacy abuses, particularly H.R. 1560, the so-called Protecting Cyber Networks Act. Both bills open up Americans' private information to inappropriate scrutiny by the Federal Government.
Now, I expect we will hear proponents of both bills argue at length that the protections against sharing personal information are sufficiently robust.
For instance, under both bills, they will cite that cyber threat data is scrubbed twice for personal information, once by private entities before they transmit it to the government and once by government entities before they store the information or share it with anybody else.
Now, that sounds good, but, unfortunately, the devil is in the details, and a close reading of the bill shows that there is an enormous loophole in the information-scrubbing component and that it fails to offer Americans safeguards for the personal information.
Under both bills, any Federal entity in receipt of cyber data threat information may store and share personal information it receives--unscrubbed information--if they believe that it is related to a cybersecurity threat.
Now, this standard isn't too vague, considering that information ``related'' to a cybersecurity threat could be interpreted to mean just about anything, but it is also incredibly broad. It includes an implicit assumption that Americans' personal information should be shared, unless Federal officials have information that it is not related to a cybersecurity threat. In many cases, the burden is to show that the personal information is not related to a cybersecurity threat for it to be scrubbed, rather than the other way around.
BREAK IN TRANSCRIPT
So, yes, companies and Federal entities are required to scrub the data for information that can be used to identify a specific person. But the loophole then calls on them not to remove any personally identifiable information unless they can show that it is not related to cybersecurity. Even if there is an off chance that something at some point might be pertinent to some kind of investigation, it puts Americans' personal information--without warrants, without due process, including information about patterns of Internet use, location, content of online communications--at great risk.
We have seen before that the Federal Government has a poor track record of safeguarding our personal information when they are entrusted with it. The last thing we should be doing is empowering Federal agencies even more with a broad discretion to look at personal information unless there is clear evidence that doing so would combat a cybersecurity threat.
I introduced, along with my colleagues on both sides of the aisle, a number of amendments to both bills--one with the gentlewoman from California, Representative Zoe Lofgren, and one with Representative Zoe Lofgren and the gentleman from Michigan, Representative Justin Amash--to impose a higher standard on Federal entities who are entrusted with this personal information. Our proposal would simply require the Federal Government to remove personally identifiable information unless it is directly necessary to identify or mitigate a cybersecurity threat--the purported purpose of this bill.
These amendments would have imposed no additional burdens on private companies, but they would have given our Nation's technology companies and the customers who keep them globally competitive more confidence that private information shared under these bills would not be subjected to inappropriate mass scrutiny by the government.
Sadly, our amendments met the same fate as nearly two dozen others put forth to add in important privacy safeguards.
The potential for abuse of private information under H.R. 1560 is even more far-reaching. The Homeland Security bill at least makes clear that the information companies transmit to DHS should be shared specifically with other agencies that need it to protect critical infrastructure. But the circumstances under which information can be shared under the Intelligence bill--and who it can be shared with--are fuzzier and broader.
Under the approach taken by H.R. 1560, every cyber threat indicator shared with a civilian agency of the Federal Government is immediately shared with a host of other government agencies, including the NSA. This increases the threat to cybersecurity by having repositories of information replicated across numerous government agencies, creating additional avenues for attack by malicious hackers. That means that private sector companies will not be able to participate in the program and promise their users they will not share information with NSA or other government agencies unless required by law.
Furthermore, it is true that the Homeland Security bill includes some troubling provisions that allow the government to use cybersecurity threat information for criminal investigations unrelated to cybersecurity. Fortunately, the Rules Committee made in order an amendment by Representatives John Katko, Zoe Lofgren, and Anna Eshoo that would address this problem in the Homeland Security bill. I hope that my colleagues adopt this amendment.
Unfortunately, no such amendment is being considered to address this issue within the Intelligence bill, H.R. 1560, where the problem actually runs much deeper. H.R. 1560 permits cyber threat data, including Americans' private information, that is shared with the Federal Government to be stored and used for a raft of unrelated purposes, unconstrained by congressional directive, including investigations and potential prosecution of crimes completely unrelated to cybersecurity.
Obviously, all of us want law enforcement agencies to be equipped to prevent and prosecute violent crime, but the inclusion of these matters completely unrelated to cybersecurity broadens the scope of the measure far beyond what it is purported to be: a cybersecurity bill. In fact, it reduces the focus of our efforts on combating cybersecurity when you open it up to everything under the sun.
By including a vast array of other reasons the government can invoke to store and share personal information, the authors of the bill essentially transformed the information-sharing initiative into a broad new surveillance program.
Yes. Rather than a cybersecurity measure, effectively, these bills are a stalking horse for broad new surveillance authority by multiple agencies of the Federal Government without warrants, without oversight.
H.R. 1560 empowers Federal entities to hold onto any information about an individual that may be ``related to'' any of the many law enforcement purposes lumped into the bill. That gives the Federal Government enormous incentive to retain and scrutinize personal information, even if it is unrelated to a cybersecurity threat.
The scope of the use authorizations also undermines due process protections that exist to protect Americans against unwarranted search and seizure. Private information about a person that was transmitted warrantlessly to the NSA under a program that was purportedly designed to combat hackers should not be admissible or used in court against them on an unrelated offense--not related to cybersecurity, not related to hacking. It would render all of our due process protections invalid simply because of the medium of the information that is used with regard to these matters in this case: Internet and cyber-related mediums and communications through them.
I joined Representatives Zoe Lofgren, Darrell Issa, and Blake Farenthold on an amendment to make clear that information sharing may only be used for the purpose of mitigating cybersecurity threats, again, the purported purpose of this bill. If the proponents of this bill are serious about combating cybersecurity, why did the Rules Committee deny Members the opportunity to limit the provisions of this bill to cybersecurity rather than a whole host of unrelated offenses?
I also joined the gentleman from Kansas, Representative Kevin Yoder, to sponsor an amendment to address a longstanding due process issue that has plagued our Nation's legal system and our privacy rights.
While the government is required to get a warrant if it wants to search through a person's physical mail, it is not required to get a warrant to search through somebody's old emails, provided the emails are older than 6 months. That contradiction and loophole was based on a 1986 law that was written before most people knew what email was.
Representative Yoder and I sponsor a bipartisan bill that has 261 cosponsors, and yet when we offered a provision on this bill, we were not given a chance to vote on it and pass it in spite of the grave due process implications that the underlying legislation has.
In addition to these privacy and due process concerns, I am alarmed by the prospect that H.R. 1560 will actually invite attempts by both private and public entities to deliberately weaken the integrity of software systems in the name of cybersecurity.
H.R. 1560, for instance, authorizes companies to deploy countermeasures that are called defensive measures in the form of hack backs that would otherwise be illegal. A countermeasure operated on one network should never cause harm to another that is prohibited by the Federal antihacking statute, the Computer Fraud and Abuse Act. But that is precisely what can happen when a company places malware on its own network, because if that data gets stolen along with other valuable data, it can harm or lead to unauthorized or backdoor access of other proprietary networks or information.
The gentleman from Virginia, Representative Gerry Connolly, put forward two amendments to address this issue in a very thoughtful manner. Regrettably, neither one will be allowed to be debated or receive a vote on the floor of the House unless we can defeat this rule.
Furthermore, both bills present the risk that Federal entities will use the threat information they receive from private companies to circumvent the security protections safeguarding those same private companies' information systems, effectively creating their own back doors which could later be exploited by malicious hackers.
As a matter of routine, our intelligence apparatus already demands that private companies include defects in their encryption system for the purported purpose of conducting backdoor surveillance. Today's legislation only makes it easier for the NSA to find and exploit more of these back doors and, therefore, easier--not harder--for hackers to find and exploit these very same security weaknesses.
Once again, Representative Lofgren put forward an amendment that would actually improve cybersecurity by making it clear that Federal entities could not use data obtained through information sharing to demand that private entities create new encryption weaknesses to enable backdoor hacking. Sadly, once again, her amendment will not be heard on the floor of the House, and this bill will encourage and allow additional venues for the illicit hacking it purports to combat.
Mr. Speaker, I don't doubt the intentions and the goals of my colleagues on the Intelligence and Homeland Security Committees, but these bills simply represent a step backwards rather than a step forward, present risks on too many fronts, from privacy, to due process, to the threats that they add to the integrity of the very networks that these bills are designed to safeguard.
In addition, the bills' focus on information sharing negates an important conversation about more important mechanisms Congress should be looking at to protect cyber systems, mechanisms that are not as fraught with risks to our civil liberties and are more effective at protecting our networks. We should be doing more, for instance, to educate businesses and governments about basic network security.
Even here in Congress, we have seen evidence of how woefully lacking even elementary knowledge about cyber threats is. Helping businesses prevent cyber attacks doesn't have to mean that the government vacuums up endless amounts of personal data about how individual Americans are using the Internet and their personal communications.
In fact, if we stop allowing the NSA to demand that U.S. businesses deliberately weaken their own networks for the purpose of government surveillance, that, in itself, would be a big step forward to strengthening our national cybersecurity.
Sadly, today's rule doesn't even allow for a debate or for a vote on the most significant concerns surrounding this legislation and denies Members the opportunity to consider changes that would address the issues that we have raised and improve cybersecurity under this bill. For these reasons, I hope my colleagues join me in opposing the rule and the underlying legislation.
I reserve the balance of my time.
BREAK IN TRANSCRIPT
Mr. Speaker, I would just add that demanding that private companies deliberately include defects in their own encryption systems for the purpose of allowing the NSA to conduct backdoor surveillance only increases the risk of our cybersecurity networks rather than decreases it, which is exactly what the bill does.
BREAK IN TRANSCRIPT
Mr. Speaker, I yield myself the balance of my time.
Mr. Speaker, it is ironic that on this very day, leaders on the Judiciary Committee will introduce legislation designed to reform and rein in the Federal Government's surveillance programs. I haven't had the opportunity to review those bills yet, so I can't speak to their merits. But I hope that if it is a strong bill, it will make its way through both Chambers and become law.
But, today, this body is considering a rule that would take us in the wrong direction. Recent history has shown that this body shares the American people's concerns that we don't take the threat of unwarranted surveillance seriously enough and that Congress needs to pass meaningful reforms that balance our liberties, our freedoms, and our privacy with the need to keep America safe.
Senate Majority Leader Mitch McConnell introduced legislation yesterday that would extend the NSA's surveillance program without any of the reforms that many of us on both sides of the aisle have advocated to rein them in. This is despite the national outcry and, indeed, international embarrassment that has been counterproductive to the very American security goals that these provisions are designed to advance.
This makes me fear that Congress is not learning from the mistakes of the past, mistakes of overly broad surveillance authorities, but instead is about to repeat them. So before we approve faster, broader, and easier sharing of vast amounts of personal information from innocent Americans with the Federal Government, Congress should be taking up legislation to prove that we have the ability to curb abuse and the Federal Government's penchant for abusing its access to this kind of data.
So far Congress has not shown its aptitude for preventing this kind of abuse. Yet today we ask the American people to trust us, to trust the President, yet again, by opening up even more information to the NSA and other surveillance agencies.
Our experience with the NSA has shown us that to protect American civil liberties from an overzealous surveillance apparatus, the authorities to review and share Americans' personal information need to be construed as narrowly, as unambiguously, and as specifically as possible by the United States Congress. We need to limit very specifically to a specific set of circumstances under which sharing data and information is necessary for mitigating a security threat.
We offered to do that through bipartisan amendments, working with Representative Lofgren, Representative Issa, and others, but none of those amendments are allowed to be discussed or debated under this rule.
Both the Protecting Cyber Networks Act and the National Cybersecurity Protection Advancement Act fall well short of the standard--and in the case of the Protecting Cyber Networks Act can even be counterproductive and falls woefully short.
These pieces of legislation would enable Federal agencies to store and share Americans' private information, such as Internet usage patterns, even the content of online communications, based on a vague or broad standard that doing so is not unrelated to a cybersecurity threat.
Again, not affirmatively, they don't have to prove that it is related to a cybersecurity threat; the burden of proof is to show that it is not unrelated to a cybersecurity threat. How can you demonstrably show that about anything?
It would make it easier for government agencies to deliberately weaken software systems for the purpose of creating new surveillance back doors that foreign nation-states and hackers can presumably also exploit.
It would leave the door wide open to more NSA surveillance by allowing the sharing of personal information for a raft of purposes unrelated to cybersecurity. We can do better.
By rejecting this rule, Members of Congress will show that, yes, we take cybersecurity seriously, so seriously that we want to take the time to get it right. Whether that takes another week or 2 weeks or 3 weeks, getting it right means allowing Members of this body input into the formulation of the final bill meaningfully through the kinds of amendments that have been rejected outright under this rule without discussion, without debate, without a vote.
Unfortunately, the rule before us today denies us the ability to consider amendments that would have addressed many of the concerns with the bill.
Mr. Speaker, I ask unanimous consent to insert the text of the amendment in the Record, along with extraneous material, immediately prior to the vote on the previous question.
BREAK IN TRANSCRIPT