Vote imminent on controversial US cyber security 'sharing' bills

Could amendments quell privacy fears?

Cyber Defence Summit US Senate and House committee members are confident twin security bills will be passed in the coming weeks, making serious inroads into the perennial failure that is cyber security information sharing.

The bipartisan bills would offer liability protection to organisations who supply de-anonymised security threat information with the US government.

The Protecting Cyber Networks Act passed through the House of Representatives in March with 307 to 116 votes, with amendments.

In April, detractors, including a string of civil liberties outfits, penned a letter arguing the bill will hurt user privacy if their data is handed to spy agencies.

Diane Rinaldo, professional staff member of the House Permanent Select Committee on Intelligence, said the bill has wide support but also some opponents, who are mainly concerned about the impact to user privacy of sharing data with the government.

The bill is now 70 pages long (from its eight original) due to amendments including privacy protections.

Diane Rinaldo (centre), and Stephen Vina (right)

"This is one of those pieces of legislation that the Republicans support, the Democrats support, and the White House supports, and we just need to iron-out the edges of how we get this done," Rinaldo told Vulture South.

"We are currently waiting on the Senate, and hear that it may bring it across next week, fingers crossed," she added.

The Senate Homeland Security Committee passed a separate bill – Cybersecurity Information Sharing – which would largely emulate Rinaldo's bill but offer liability protection only if threat data is reported through a Department of Homeland Security portal.

The former would grant protection if information is shared with any Federal Government agency.

Committee chief counsel Stephen Vina said several procedural votes still have to happen before the final vote. "There is talk that it could come up very soon in this next work period [and] we're all waiting to see how that will play out," Vina told the Cyber Defence Summit in Washington DC.

"The positioning that is going on right now is trying to figure out the level of support," he added. "It had very wide bipartisan support, and they are expecting that [support] when it finally gets to the Senate floor."

He said this is the "last big challenge" after The Federal Information Security Management Act and other security bills.

However, the bill faces "strong opposition" among some members who harbour privacy concerns, said Vina, but he maintains some 20 amendments may help to win that support.

The bills ask organisations to strip user data from threat feeds and require the receiving government agency to sieve through the info to ensure that has been done.

The pair say the bills are important to lift the level of information sharing with the government, which has failed to expand among organisations fearful of litigation.

Sharing of security information is a mainstay of keynotes and government speeches, yet many in the Australian and US security communities fail to see the benefit of opening their organisations up to legal action or IP theft from competitors. ®

Darren Pauli travelled to Washington DC as a guest of FireEye.

Similar topics

Other stories you might like

  • Minimal, systemd-free Alpine Linux releases version 3.16
    A widespread distro that many of its users don't even know they have

    Version 3.16.0 of Alpine Linux is out – one of the most significant of the many lightweight distros.

    Version 3.16.0 is worth a look, especially if you want to broaden your skills.

    Alpine is interesting because it's not just another me-too distro. It bucks a lot of the trends in modern Linux, and while it's not the easiest to set up, it's a great deal easier to get it working than it was a few releases ago.

    Continue reading
  • Verizon: Ransomware sees biggest jump in five years
    We're only here for DBIRs

    The cybersecurity landscape continues to expand and evolve rapidly, fueled in large part by the cat-and-mouse game between miscreants trying to get into corporate IT environments and those hired by enterprises and security vendors to keep them out.

    Despite all that, Verizon's annual security breach report is again showing that there are constants in the field, including that ransomware continues to be a fast-growing threat and that the "human element" still plays a central role in most security breaches, whether it's through social engineering, bad decisions, or similar.

    According to the US carrier's 2022 Data Breach Investigations Report (DBIR) released this week [PDF], ransomware accounted for 25 percent of the observed security incidents that occurred between November 1, 2020, and October 31, 2021, and was present in 70 percent of all malware infections. Ransomware outbreaks increased 13 percent year-over-year, a larger increase than the previous five years combined.

    Continue reading
  • Slack-for-engineers Mattermost on open source and data sovereignty
    Control and access are becoming a hot button for orgs

    Interview "It's our data, it's our intellectual property. Being able to migrate it out those systems is near impossible... It was a real frustration for us."

    These were the words of communication and collaboration platform Mattermost's founder and CTO, Corey Hulen, speaking to The Register about open source, sovereignty and audio bridges.

    "Some of the history of Mattermost is exactly that problem," says Hulen of the issue of closed source software. "We were using proprietary tools – we were not a collaboration platform before, we were a games company before – [and] we were extremely frustrated because we couldn't get our intellectual property out of those systems..."

    Continue reading

Biting the hand that feeds IT © 1998–2022