National Defense Authorization Act for Fiscal Year 2016

Floor Speech

Date: June 10, 2015
Location: Washington, DC

BREAK IN TRANSCRIPT

Mr. WYDEN. Mr. President, I wish to speak this afternoon about a controversial proposal, the Cybersecurity Information Sharing Act, otherwise known as CISA, which was filed yesterday as an amendment to the Defense authorization bill.

I want to begin by saying to the Senate that I believe tacking this legislation onto the Defense bill would, in my view, be a significant mistake. I expect our colleagues are going to have a wide range of views about this legislation, and I hope the Senate can agree that bills as controversial as this one ought to be subject to public debate and an open-ended process, not stapled onto unrelated legislation with only a modest amount of discussion.

This is particularly true given the issue of cyber security, which is going to have a significant impact on the security and the well-being of the American people and obviously the consumer rights and the privacy of law-abiding Americans. Because it is designed to increase government collection of information from private companies, I am of the view that for the Senate to have this expansion of collecting so much information about the people of the United States, for it to have real legitimacy in the eyes of the public, it is important to have open debate, with votes on amendments from Senators who have a wide variety of opinions on the issue of cyber security. Trying to rush this bill through the Senate, in my view, is not going to increase public confidence.

So let me be clear about the process and talk a bit about the substance of the legislation as well. I believe tacking it onto the Defense bill is a flawed process. But I think there are also significant flaws with the substance of the legislation as well. Dozens of independent experts agree this legislation will have serious consequences and do little to make our Nation more secure at a time when cyber threats are very real. The issue of cyber threats requires more than a placebo, and this legislation is a bandaid on a gaping wound. I believe the Senate, having the time for adequate reflection and amendment, can do better.

In beginning, I would like the Senate to know just how much controversy and concern this legislation has generated among those who are considered independent experts on cyber security. Shortly before the Intelligence Committee, which I have been honored to serve on for more than 14 years--shortly before the committee marked up this legislation, a coalition of nearly 50 organizations and security experts wrote to the members of the Intelligence Committee expressing serious concerns about the legislation.

BREAK IN TRANSCRIPT

Attached to this letter is an actual example of a threat signature containing data that helps system administrators secure their networks. You'll see that the information does not contain users' private information.

Waiving privacy rights will not make security sharing better. The more narrowly security practitioners can define these IoCs and the less personal information that is in them, the better. Private information about individual users is often a detriment in developing threat signatures because we need to be able to identify an attack no matter where it comes from and no matter who the target is. Any bill that allows for and results in significant sharing of personal information could decrease the signal-to-noise ratio and make IoCs less actionable.

Further, sharing users' private information creates new security risks. Here are just three examples: First, any IoC that contains personal information exacerbates the danger of false-positives, that innocent behavior will erroneously be classified as a threat. Second, distribution of private data like passwords could expose our users to unauthorized access, since, unfortunately, many people use the same password across multiple sites. Third, private data contained in personal emails or other messages can be abused by criminals developing targeted phishing attacks in which they masquerade as known and trusted correspondents.

For these reasons, we do not support any of the three information sharing bills currently under consideration--the Cybersecurity Information Sharing Act (CISA), the Protecting Cyber Networks Act (PCNA), or the National Cybersecurity Protection Advancement Act of 2015. These bills permit overbroad sharing far beyond the IoCs described above that are necessary to respond to an attack, including all ``harms'' of an attack. This excess sharing will not aid cybersecurity, but would significantly harm privacy and could actually undermine our ability to effectively respond to threats.

As a general rule, when we do need to share addressing information, we are sharing the addresses of servers which are used to host malware, or to which a compromised computer will connect for the exfiltration of data. In these cases, this addressing information helps potential victims block malicious incoming connections. These addresses do not belong to subscribers or customers of the victims of a security breach or of our clients whose systems we are helping to secure. Sharing this kind of addressing is a common current practice. We do not see the need for new authorities to enable this sharing.

BREAK IN TRANSCRIPT

Mr. WYDEN. The signers of the letter expressed very serious concerns about the legislation and were particularly concerned it would ``significantly undermine privacy and civil liberties.'' Unfortunately, as the signers of the legislation will report, these concerns were not adequately addressed in the committee markup.

Shortly after the committee markup, a group of 65 technologists and cyber security professionals wrote to Chairman Burr and Vice Chairman Feinstein expressing their opposition to this legislation.

BREAK IN TRANSCRIPT

Mr. WYDEN. This is a particularly important letter. We have some of the most distinguished independent experts from across the country--whether Amazon or Sysco, Stanford University, Dartmouth, some of the leading experts in the private sector and academia--expressing real concerns about this legislation and its House companion.

BREAK IN TRANSCRIPT


Source
arrow_upward