The USA FREEDOM Act, the President’s Review Group and the Biggest Intelligence Reform in 40 Years

The USA FREEDOM Act, the President’s Review Group and the Biggest Intelligence Reform in 40 Years
https://privacyassociation.org/news/a/the-usa-freedom-act-the-presidents-review-group-and-the-biggest-intelligence-reform-in-40-years/
 
Two years after the first story based on Edward Snowden’s leaks hit the press, the U.S. government enacted the USA FREEDOM Act, ending bulk collection under Section 215. As one of five members of President Obama’s Review Group on Intelligence and Communications Technology, I applaud its passage—the biggest pro-privacy change to U.S. intelligence law since the original enactment of the Foreign Intelligence Surveillance Act in 1978.
There is a close fit between the Review Group’s work and the new law as well as multiple significant reform measures the Obama administration has already adopted without legislative change. In this era of partisan gridlock, the U.S. system of government has proved more responsive and resilient than many skeptics had predicted.
<snip>

US Dept of Commerce seeks comments on proposed export changes

The Wassenaar Arrangement (full name: The Wassenaar Arrangement on Export Controls for Conventional Arms and Dual-Use Goods and Technologies) is a multilateral export control regime (MECR) with 41 participating states including many former COMECON (Warsaw Pact) countries.
An FRN issued on 5/20/2015

https://www.federalregister.gov/articles/2015/05/20/2015-11642/wassenaar-arrangement-2013-plenary-agreements-implementation-intrusion-and-surveillance-items

describes a proposal by Department of Commerce’s Bureau of Industry and Security (BIS) for a license requirement for the export, reexport, or transfer (in-country) of systems, equipment or components specially designed for the generation, operation or delivery of, or communication with, intrusion software; software specially designed or modified for the development or production of such systems, equipment or components; software specially designed for the generation, operation or delivery of, or communication with, intrusion software; technology required for the development of intrusion software; Internet Protocol (IP) network communications surveillance systems or equipment and test, inspection, production equipment, specially designed components therefor, and development and production software and technology therefor.
The FRN notes that BIS is seeking information about the effect of this rule and would appreciate the submission of comments, and especially answers to the following questions:
1. How many additional license applications would your company be required to submit per year under the requirements of this proposed rule? If any, of those applications:
a. How many additional applications would be for products that are currently eligible for license exceptions?
b. How many additional applications would be for products that currently are classified EAR99?
2. How many deemed export, reexport or transfer (in-country) license applications would your company be required to submit per year under the requirements of this rule?
3. Would the rule have negative effects on your legitimate vulnerability research, audits, testing or screening and your company’s ability to protect your own or your client’s networks? If so, explain how.
4. How long would it take you to answer the questions in proposed paragraph (z) to Supplement No. 2 to part 748? Is this information you already have for your products?
* The ADDRESSES section of this proposed rule includes information about how to submit comments.

[ECP] Educational CyberPlayGround K12 Newsletters

Teen Changes Wallpaper On Teacher’s Computer; Gets Charged With A Felony
“Even though some might say this is just a teenage prank, who knows what this teenager might have done,” — Sheriff Nocco
Yep, unauthorized access, CFAA violation, that’s a felony.
 

Calling Security experts / technologists opposing purported info sharing bills that actually waive privacy laws and enable more surveillance.

Hello,
As you may know, there are three cybersecurity information sharing bills pending before Congress right now. These bills would weaken privacy laws and enable surveillance at a time when we need stronger privacy protections. These are surveillance bills, not security bills.
Every one of the bills is an end run around privacy laws in the name of improving security information sharing with the Department of Homeland Security (DHS). The bills define “cyber threat indicators” in a confusing manner that could include server logs, the contents of emails, damage estimates, and more. This kind of private data is not what is generally needed to secure systems. Nevertheless, the bills say that private entities will be immune from liability for sharing this information  with DHS (and other parts of government) “notwithstanding” any privacy laws.
Surveillance reform advocates are trying to stop these bills. There is a lot of support in Congress and from the White House. So, to succeed, we need your help and we need it now. We expect the bills to come to a vote mid-April.
As a security expert, would you be willing to sign a letter helping to educate Congress about what kind of information experts actually share to further cybersecurity and secure systems from future attack? By helping Congress understand what information is useful in security, we can stop a bill that would needlessly waive privacy.
Please let me know if you can sign on by no later than 8pm ET Sunday, April 12. Email to jennifer at law.stanford.edu your name, title and affiliation. We plan to use your titles and affiliations for information purposes only, not to indicate that your employer is also signing the letter. For example, my signature would be Jennifer Stisa Granick, Director of Civil Liberties, Stanford Center for Internet and Society* and the asterick text would say “*Titles and affiliations are for information purposes only.” If you want to sign but don’t want to include your title or affiliation, or don’t have one, please indicate so, and we will respect your wishes.
My plan is to circulate the letter to the sponsors of the bills and to the rest of Congress on Monday, April 13.
Please feel free to email me or set up a call with me if you have any questions about the bills or the letter.
Once again, I can be reached at jennifer at law.stanford.edu
Finally, please do forward this request to anyone you think might be knowledgeable about security information sharing, and interested in sighing the letter.
For more information on these laws, you can read here:
Jennifer Granick—The Right Way to Share Information and Improve Cybersecurity: http://justsecurity.org/21498/share-information-improve-cybersecurity/
OTI—VERSION 2.0 OF THE SENATE INTELLIGENCE COMMITTEE’S CYBER INFORMATION SHARING ACT IS CYBER-SURVEILLANCE, NOT CYBERSECURITY:http://www.newamerica.org/oti/version-20-of-the-senate-intelligence-committees-cyber-information-sharing-act-is-cyber-surveillance-not-cybersecurity/
CDT—Analysis of Cybersecurity Information Sharing Act of 2014: https://cdt.org/insight/analysis-of-feinstein-chambliss-cybersecurity-information-sharing-act-of-2014/
Thank you for your time, attention, and assistance in this important matter.
Jennifer Granick