

SUBSCRIBE TO OUR FREE NEWSLETTER
Daily news & progressive opinion—funded by the people, not the corporations—delivered straight to your inbox.
5
#000000
#FFFFFF
To donate by check, phone, or other method, see our More Ways to Give page.


Daily news & progressive opinion—funded by the people, not the corporations—delivered straight to your inbox.
You may have heard that Juniper Networks announced what amounts to a backdoor in its virtual private network products. Here's Kim Zetter's accessible intro of what security researchers have learned. And here's some technical background from Matthew Green.
As Zetter summarizes, the short story is that some used weaknesses encouraged by the NSA to backdoor the security product protecting many American businesses.
They did this by exploiting weaknesses the NSA allegedly placed in a government-approved encryption algorithm known as Dual_EC, a pseudo-random number generator that Juniper uses to encrypt traffic passing through the VPN in its NetScreen firewalls. But in addition to these inherent weaknesses, the attackers also relied on a mistake Juniper apparently made in configuring the VPN encryption scheme in its NetScreen devices, according to Weinmann and other cryptographers who examined the issue. This made it possible for the culprits to pull off their attack.
As Green describes, the key events probably happened as early as 2007 and 2012 (contrary to the presumption of surveillance hawk Stewart Baker, who is looking to scapegoat those calling for more security). This means this can't be a response to the Snowden document, which strongly suggests the NSA had pushed those weaknesses in Dual_EC.
I find that particularly interesting, because it suggests whoever did this either used public discussions about the weakness of Dual_EC, dating to 2007, to identify and exploit this weakness, or figured out what (it is presumed) the NSA was up to. That suggests two likely culprits for what has been assumed to be a state actor behind this: Israel (because it knows so much about NSA from having partnered on things like StuxNet) or Russia (which was getting records on the FiveEyes' SIGINT activities from its Canadian spy, Jeffrey Delisle). The UK would be another obvious guess, except an Intercept article describing how NSA helped UK backdoor Juniper suggests they used another method.
This leads me back to an interesting change I noted between CISA -- the bill passed by the Senate back in October -- and OmniCISA -- the version passed last week as part of the omnibus funding bill. OmniCISA still required the Intelligence Community to provide a report on the most dangerous hacking threats, especially state actors, to the Intelligence Committees. However, it eliminated a report for the Foreign Relations Committees on the same topic. I joked at the time that that was probably to protect Israel, because no one wants to admit that Israel spies and has greater ability to do so by hacking than other nation-states, especially because it surely learns our methods by partnering with us to hack Iran.
Whoever hacked Juniper, the whole incident offers a remarkable lesson in the dangers of backdoors. Even as the FBI demands a backdoor into Apple's products, it is investigating who used a prior US-sponsored backdoor to do their own spying.
Congress just passed an enormous omnibus-spending bill to keep the government running -- but what's in this bill besides funding for various agencies?
Here's the low-down on the good, the bad and the ugly parts of the bill:
Really Good: No Net Neutrality Sneak Attacks
Congress just passed an enormous omnibus-spending bill to keep the government running -- but what's in this bill besides funding for various agencies?
Here's the low-down on the good, the bad and the ugly parts of the bill:
Really Good: No Net Neutrality Sneak Attacks
After fighting last summer to keep out budget riders that would have undermined the FCC's open Internet rules, we knew we couldn't allow this dangerous language to make a comeback in the omnibus bill. Thousands of Net Neutrality supporters picked up the phone and urged Congress to leave these vital open Internet rules alone. Your voices made a difference: None of the riders made it into the spending bill.
Good: Financial Services Agencies and Privacy for Our Emails
Both the Securities and Exchange Commission and the Federal Trade Commission believe they should be able to read our emails and other online messages without a warrant, thanks to a loophole in the Electronic Communications Privacy Act (ECPA). Thanks to Rep. Kevin Yoder (R-Kansas) and others, the spending bill requires these financial agencies to behave in accordance with the Fourth Amendment when it comes to our online communications. The language applies only to financial services agencies, and it's no substitute for a comprehensive ECPA fix, but we believe it's an important first step.
Really Bad: Cyber Surveillance Bill Made Law
CISA is back. A quick refresher: A number of bills brought up last year encourage companies to monitor and share our personal data with the government, in theory to detect hacking threats. In return, these companies get legal immunity from existing privacy laws. Varying versions of this so-called "cybersecurity" legislation passed both the House and Senate, but instead of letting the chambers settle their differences leadership decided to do an end run around the process by attaching it to the budget bill. This newly passed version is even worse than all of the previous ones, and that means more invasive government surveillance and a dangerous blow to privacy safeguards.
Bad: Civil Liberties Oversight Board Gutted
Congress also worked in a provision that would prevent the Privacy and Civil Liberties Oversight Board (PCLOB) from gaining access to any information about government covert-action programs. The PCLOB is an independent agency designed to protect Americans' privacy and civil liberties by conducting oversight of counterterrorism programs. The language in the budget bill could allow surveillance programs to evade oversight if agencies claim they're connected to broadly defined "covert-action programs." Congress should be working to improve surveillance oversight, not remove it.
Bad: Waivers for Big Media Consolidation
The budget bill also includes a waiver allowing broadcasting conglomerates to hold on to Joint Sales Agreements (JSAs) that allow them to evade the FCC's media ownership limits. Sharing agreements like JSAs allow a single media giant to maintain control of multiple local TV stations while claiming that independent owners are in charge. JSAs and other similar schemes force out local ownership, damage media diversity, homogenize newsrooms and hurt journalists and communities of color, yet Congress decided to bail out broadcasters via the omnibus bill.
Update:
Following publication, Sari Feldman, president of the American Library Association, told Common Dreams that librarians are "proud to stand with groups from every part of the political spectrum to expose and oppose the latest legislative attempt to advance a new mass surveillance law."
"Shoehorning a new version of 'CISA' hostile to personal privacy into a massive omnibus spending bill is troubling as a matter of substance and process," Feldman added, saying the group calls on Congress "to reject this latest assault on privacy and democracy."
Earlier:
Digital rights groups are sounding the alarm after sources reportedly confirmed on Monday that the controversial cyber-surveillance bill formerly known as CISA has been slipped into the "must-pass" omnibus spending bill that Congress is expected to vote on later this week.
Fight for the Future, a leading digital rights group that has organized fierce grassroots resistance to CISA (otherwise known as Cybersecurity Information Sharing Act) and similar bills, issued a statement saying that all eyes will be on President Barack Obama should the legislation reach his desk.
"Now is when we'll find out whether President Obama really cares about the Internet and freedom of speech, or whether he's happy to roll over and allow technologically illiterate members of Congress break the Internet in the name of cybersecurity," said the group's campaign director, Evan Greer.
Negotiators have been working to pass some version of the CISA bill, which would allow the sharing of Internet traffic information between the U.S. government and technology and manufacturing companies, for more than three years.
After the Senate passed its Intelligence Committee-originated version in October, lawmakers have been trying meld that rule with two similar versions that recently passed in the House--amounting to a bill which critics warn is completely gutted of any privacy protections.
Now, citing "media reports and sources close to legislative negotiations," privacy advocates say that the legislation has been tacked on to the budget bill. According to The Hill, "Most observers believe the tactic gives the cyber bill its best shot of getting through Congress in 2015, as only a handful of legislative days remain before the upcoming recess."
Fight for the Future on Monday launched a petition campaign calling on the president to reject the bill, which it warns would allow "unlimited surveillance" thus destroying online privacy, make users more vulnerable to hackers, and eliminate any incentive that private technologies might have to improve cyber security.
"This administration promised to veto any information sharing bill that did not adequately protect Internet users' privacy, and the final version of this bill doesn't even come close," Greer continued.
Close to 20 civil liberties organizations on Wednesday issued a letter urging U.S. lawmakers to oppose a controversial surveillance bill after the release of its final text revealed any previous privacy protections from prior drafts had been "gutted."
"The final version of this bill is an insult to the public and puts all of us in greater danger of cyber attacks and government surveillance," said Evan Greer, campaign director of the digital rights group Fight for the Future, which organized the letter. "This was already a fundamentally flawed piece of legislation, and now even the meager privacy protections it provided have been gutted, exposing it for what it really is: a bill to dramatically expand abusive government spying."
The so-called "conference" bill combines language from three separate cybersecurity proposals passed by Congress earlier this year--the Protecting Cyber Networks Act (PCNA) and the National Cybersecurity Protection Advancement Act of 2015 (NCPAA), which passed the House of Representatives in April, and the Cybersecurity Information Sharing Act of 2015 (CISA), approved by the Senate in October.
But critics say the "reconciled" version is neither an improvement on the previous bills nor a suitable safeguard against cyber attacks. In fact, as Mike Masnick wrote at Techdirt on Tuesday, "Basically, it looks like Congressional leadership decided to pull the worst parts from the various bills and mash them together into a super bill of pure terribleness."
CISA in particular has long been criticized by privacy advocates who say it does nothing more than expand government surveillance powers. The letter from 19 civil liberties groups, including Demand Progress, Free Press Action Fund, and OpenMedia, adds that the bill was drafted in secret meetings between House and Senate negotiators that ignored critical recommendations by experts from the House Committee on Homeland Security.
"Basically, it looks like Congressional leadership decided to pull the worst parts from the various bills and mash them together into a super bill of pure terribleness."
--Mike Masnick, Techdirt
Specifically, the groups said, the bill would:
"The current version of these bills is the result of secret negotiations between the House and Senate intelligence committees," the letter continues. "[It] would build a government regime that makes it impossible for companies to guarantee the protection of customers' civil liberties and privacy, while also failing to meaningfully improve cybersecurity."
Moreover, opponents say the final version would exacerbate the existing anti-privacy measures in each individual bill, particularly CISA.
"Because it fails to resolve these weaknesses originally present within the three bills and makes new and alarming changes to them, we strongly object to the intelligence committee's latest iteration of 'cybersecurity' legislation and the undemocratic process that produced it," the letter continues.
CISA's proponents say the bill would streamline the process for tech companies to share data in cases of security breaches and other digital attacks. Following the Senate's vote in October, Fight for the Future slammed the lawmakers who supported its passage, tweeting, "Every senator supporting #CISA today voted against a world with freedom, democracy, and basic human rights."
According to The Hill, the two chambers have escalated efforts to have the final version of their bill on President Barack Obama's desk by the end of the year. An official conference could begin this week.
Under the vague guise of "cybersecurity", the Senate voted Tuesday to pass the Cybersecurity Information Sharing Act (Cisa), a spying bill that essentially carves a giant hole in all our privacy laws and allows tech and telecom companies to hand over all sorts of private information to intelligence agencies without any court process whatsoever. Make no mistake: Congress has passed a surveillance bill in disguise, with no evidence it'll help our security.
All that is needed for companies to hand over huge swaths of information to the government is for it to contain "cyber threat indicators" - a vague phrase that can be interpreted to mean pretty much anything. Your personal information - which can include the content of emails - will be handed over to the Department of Homeland Security, the agency supposedly responsible for the nation's cybersecurity. From there the information can be sent along to the NSA, which can add it to databases or use it to conduct even more warrantless searches on its internet backbone spying (which once again, a judge ruled last week could not be challenged in court because no one can prove the NSA is spying on them, since the agency inevitably keeps that information secret).
Try asking the bill's sponsors how the bill will prevent cyberattacks or force companies and governments to improve their defenses. They can't answer. They will use buzzwords like "info-sharing" yet will conveniently ignore the fact that companies and the government can already share information with each other as is.
There were barely any actual cybersecurity experts who were for the bill. A large group of respected computer scientists and engineers were against it. So were cyberlaw professors. Civil liberties groups uniformly opposed (and were appalled by) the bill. So did consumer groups. So did the vast majority of giant tech companies. Yet it still sailed through the Senate, mostly because lawmakers - many of whom can barely operate their own email - know hardly anything about the technology that they're crafting legislation about.
This is the state of "cybersecurity" legislation in this country, where lawmakers wanted to do something, but lacking any sort of technical expertise - or any clue at all what to do - just decided to cede more power to intelligence agencies like the NSA. The bill, which used to be known as Cispa, has been festering in Congress for years, and now it looks like it will finally head to the President's desk.
Along the way, the Senate decided to reject a handful of common sense privacy amendments that could've protected that information. One by one, privacy and transparency amendments that would've at least made the bill less awful were voted down on Tuesday.
First, they voted down Senator Ron Wyden's amendment that would've forced companies to strip out personally identifiable information before handing data over to the government. They voted down Senator Patrick Leahy's amendment that would've prevented Cisa from carving out a new exemption to the Freedom of Information Act, which will prevent news organizations and others from using the transparency law to find out what types of information companies are handing over to the government.
In an era of secret law, where the government has no problem completely re-interpreting laws in complete secrecy to allow mass spying on Americans, we now have another law on the books that carves a hole in our privacy laws, contains vague language that can be interpreted any which way, and that has provisions inserted into it specifically to prevent us from finding out how they're using it.
In case you weren't already convinced that CISA is a surveillance bill masquerading as a cybersecurity bill, today, the Senate rejected four separate amendments to the bill that attempted to protect Americans' privacy better. Senator Wyden had an amendment to require the removal of personal information before information could be shared, which was voted down 55 to 41. Senator Heller had an amendment that was a backstop against the Wyden amendment, saying that if the Wyden amendment didn't pass, Homeland Security would be responsible for removing such personal information. That amendment also failed with 49 to 47 votes. Senator Leahy had an amendment that would have removed FOIA exemptions in the bill (making it much less transparent how CISA was used). That amendment was voted down 59 to 37. Senator Franken then had an amendment that would have "tightened" the definition of cybersecurity threats so that the shared information needed to be "reasonably likely" to cause damage, as opposed to the current "may" cause damage. And (you guessed it because you're good at this), it was also voted down by a 60 to 35 vote.
Meanwhile, Marcy Wheeler notes that the revised version of the bill by Senators Burr and Feinstein, which claimed to incorporate greater transparency requirements proposed by Senator Tester, actually takes away a lot of transparency and actually makes it more difficult for Congress to learn whether or not CISA is being used for domestic surveillance:
That Burr and DiFi watered down Tester's measures so much makes two things clear. First, they don't want to count some of the things that will be most important to count to see whether corporations and agencies are abusing this bill. They don't want to count measures that will reveal if this bill does harm.
Most importantly, though, they want to keep this information from Congress. This information would almost certainly not show up to us in unclassified form, it would just be shared with some members of Congress (and on the House side, just be shared with the Intelligence Committee unless someone asks nicely for it).
But Richard Burr and Dianne Feinstein want to ensure that Congress doesn't get that information. Which would suggest they know the information would reveal things Congress might not approve of.
Once again, these actions only make sense if CISA is being used to justify warrantless domestic surveillance. This raises the question of why Congress is willing to proceed with such a surveillance bill. We just went through a process showing that the public is uncomfortable with secret laws and interpretations that lead to surveillance. Why would they immediately push for a new secret law that expands surveillance and rejects any attempts to protect the privacy of the American public or any sort of transparency and accountability in how the bill is used?
The bill is positioned as a cybersecurity bill, but you'd be hard-pressed to find a single computer security expert who thinks it is useful or necessary. I've been trying, and so far, I can't find any.
Update:
| #StopCISA Tweets |
On Tuesday, the U.S. Senate passed the Cybersecurity Information Sharing Act (CISA) without any of the proposed amendments that would have strengthened user protections. The bill passed 74-21 (see the roll call here).
Rights groups immediately called for President Obama to veto the bill and vowed to keep the pressure up.
"Every senator supporting #CISA today voted against a world with freedom, democracy, and basic human rights," tweeted digital rights organization Fight for the Future. "If President Obama does not veto this bill, he'll show that his administration never truly cared about the open Internet."
"This vote will go down as the moment Congress codified the US government's unconstitutional spying. A sad day for the Internet," the group added.
In its response to CISA's passage in the Senate, the Electronic Frontier Foundation marked its disappointment. It said: "The bill is fundamentally flawed due to its broad immunity clauses, vague definitions, and aggressive spying authorities."
With the bill now moving to conference committee, EFF expressed no confidence that it would be improved.
"The passage of CISA reflects the misunderstanding many lawmakers have about technology and security," EFF continued. "Computer security engineers were against it. Academics were against it. Technology companies, including some of Silicon Valley's biggest companies, such as Twitter and Salesforce, were against it. Civil society organizations were against it. And constituents sent over 1 million faxes opposing CISA to Senators."
EFF vowed that the fight against the bill would continue through the conference committee process, where the group would urge lawmakers to add privacy provisions. "We will never stop fighting for lawmakers to either understand technology or when they need to listen to the people who do," the group said.
The official Senate roll call to the vote follows:
Alphabetical by Senator Name
|
Alexander (R-TN), Yea Ayotte (R-NH), Yea Baldwin (D-WI), Nay Barrasso (R-WY), Yea Bennet (D-CO), Yea Blumenthal (D-CT), Yea Blunt (R-MO), Yea Booker (D-NJ), Nay Boozman (R-AR), Yea Boxer (D-CA), Yea Brown (D-OH), Nay Burr (R-NC), Yea Cantwell (D-WA), Yea Capito (R-WV), Yea Cardin (D-MD), Nay Carper (D-DE), Yea Casey (D-PA), Yea Cassidy (R-LA), Yea Coats (R-IN), Yea Cochran (R-MS), Yea Collins (R-ME), Yea Coons (D-DE), Nay Corker (R-TN), Yea Cornyn (R-TX), Yea Cotton (R-AR), Yea Crapo (R-ID), Nay Cruz (R-TX), Not Voting Daines (R-MT), Nay Donnelly (D-IN), Yea Durbin (D-IL), Yea Enzi (R-WY), Yea Ernst (R-IA), Yea Feinstein (D-CA), Yea Fischer (R-NE), Yea |
Flake (R-AZ), Yea Franken (D-MN), Nay Gardner (R-CO), Yea Gillibrand (D-NY), Yea Graham (R-SC), Not Voting Grassley (R-IA), Yea Hatch (R-UT), Yea Heinrich (D-NM), Yea Heitkamp (D-ND), Yea Heller (R-NV), Nay Hirono (D-HI), Yea Hoeven (R-ND), Yea Inhofe (R-OK), Yea Isakson (R-GA), Yea Johnson (R-WI), Yea Kaine (D-VA), Yea King (I-ME), Yea Kirk (R-IL), Yea Klobuchar (D-MN), Yea Lankford (R-OK), Yea Leahy (D-VT), Nay Lee (R-UT), Nay Manchin (D-WV), Yea Markey (D-MA), Nay McCain (R-AZ), Yea McCaskill (D-MO), Yea McConnell (R-KY), Yea Menendez (D-NJ), Nay Merkley (D-OR), Nay Mikulski (D-MD), Yea Moran (R-KS), Yea Murkowski (R-AK), Yea Murphy (D-CT), Yea Murray (D-WA), Yea |
Nelson (D-FL), Yea Paul (R-KY), Not Voting Perdue (R-GA), Yea Peters (D-MI), Yea Portman (R-OH), Yea Reed (D-RI), Yea Reid (D-NV), Yea Risch (R-ID), Nay Roberts (R-KS), Yea Rounds (R-SD), Yea Rubio (R-FL), Not Voting Sanders (I-VT), Nay Sasse (R-NE), Yea Schatz (D-HI), Yea Schumer (D-NY), Yea Scott (R-SC), Yea Sessions (R-AL), Yea Shaheen (D-NH), Yea Shelby (R-AL), Yea Stabenow (D-MI), Yea Sullivan (R-AK), Nay Tester (D-MT), Nay Thune (R-SD), Yea Tillis (R-NC), Yea Toomey (R-PA), Yea Udall (D-NM), Nay Vitter (R-LA), Not Voting Warner (D-VA), Yea Warren (D-MA), Nay Whitehouse (D-RI), Yea Wicker (R-MS), Yea Wyden (D-OR), Nay |
Earlier:
As the U.S. Senate gears up for a vote on Tuesday's controversial Cybersecurity Information Sharing Act (CISA), privacy advocates are galvanizing an 11th-hour push against the bill they say does nothing more than expand government spying powers.
A slew of digital rights groups, including Fight for the Future and the Electronic Frontier Foundation, along with whistleblower Edward Snowden and outspoken CISA opponent Sen. Ron Wyden (D-Ore.), joined forces Monday night for an Ask Me Anything (AMA) session on Reddit, which has also come out against the bill. The session was the latest action by civil society groups, activists, and tech companies calling on Congress to reject CISA for its anti-privacy provisions.
"CISA isn't a cybersecurity bill," Snowden wrote during the Q&A. "It's not going to stop any attacks. It's not going to make us any safer. It's a surveillance bill."
Supporters of CISA--including Sens. Dianne Feinstein (D-Calif.) and Richard Burr (R-N.C.)--say the bill would make it easier for tech companies to share data in cases of security breaches and other digital attacks. But critics say there aren't enough safeguards in place to protect user privacy, and the bill only works to serve intelligence agencies in domestic surveillance operations.
"What it allows is for the companies you interact with every day--visibly, like Facebook, or invisibly, like AT&T--to indiscriminately share private records about your interactions and activities with the government," Snowden wrote on Monday. "CISA allows private companies to immediately share a perfect record of your private activities the instant you click a link, log in, make a purchase, and so on--and the government with reward for doing it by granting them a special form of legal immunity for their cooperation."
Fight for the Future campaign director Evan Greer said the Senate's vote on Tuesday "will go down in history as the moment that lawmakers decided not only what sort of Internet our children and our children's children will have, but what sort of world they will live in."
The campaigns, which are being waged under the hashtag #StopCISA, urge senators to oppose the bill and protect civil liberties.
Greer added, "Every Senator who votes for CISA will be voting for a world without freedom of expression, a world without true democracy, a world without basic human rights. And they will be voting for their removal from office because the Internet will not forget which side of history they stood on."
Facebook Incorporated is once again facing criticism from internet freedom and privacy advocates, this time for deception on their lobbying activities related to the Cybersecurity Information Sharing Act (CISA). CISA is the latest iteration of a long legislative effort by the government and various corporate interests to destroy legal privacy protections for internet users.
Previous versions of CISA such as SOPA and PIPA were ultimately defeated in Congress after public outrage and opposition from an alliance of powerful tech firms scared politicians off.
According to Fight For The Future, though the multi-billion dollar social networking site claims publicly to oppose it, Facebook is working behind the scenes to get CISA passed. In other words, Facebook is doing some things in private it does not want everyone to know about.
The value of CISA to Facebook, as Fight For The Future notes, is that the current version of the bill gives legal immunity to companies such as Facebook for violating privacy laws as long as the company shares information with the government. A get out of jail and civil lawsuit free card for a company constantly dealing with legal issues for its privacy practices.
Under CISA, as long as Facebook cuts the government in on the action it can violate user privacy and face no accountability for it, at least in the US. So it would not be a surprise if the company was trying to see CISA enacted, Facebook has a direct interest in getting the legal immunity contained in the bill.
The national security state's interest in CISA is not hard to decipher, either. If CISA becomes law, much of the domestic spying performed by the NSA and other agencies has stronger legal ground to stand on. CISA also facilitates increased collaboration between private companies with the legal immunity provision that will allow companies like Facebook, Verizon, Google, and AT&T to violate their users privacy without having to worry about legal consequences.
With no check from the users, those companies will primarily face trouble from the government for not complying with secret orders. CISA could be a fatal blow to what remains of privacy rights online.
Fight For The Future has launched a petition to ask Facebook to "come clean" on their CISA lobbying.
The U.S. Senate has moved forward the Cybersecurity Information Sharing Act (CISA)--legislation denounced by its many critics as "a surveillance bill in disguise."
With bipartisan support, CISA passed 83-14 in a procedural vote on Thursday.
"The Senate just did a really bad thing," Techdirt's Mike Masnick wrote Thursday, and offered a list of the senators he said "just voted to increase surveillance and decrease trust in our internet companies, thereby harming the American economy and innovation."
As to why the legislation, touted by its supporters as strengthening national cybersecurity, is bad, Freedom of the Press Foundation's Trevor Timm has written that CISA is "really a surveillance bill in disguise." He continues:
The main crux of the bill is to carve a giant exception into all our current privacy laws so as to allow tech companies like Google and Amazon to hand over huge amounts of our information without any legal process whatsoever, as long as they have a vague cybersecurity purpose.
But tech companies including Google are among those in the industry that have joined the chorus of those coming out against the legislation.
The Electronic Frontier Foundation further noted Thursday:
CISA is fundamentally flawed. The bill's broad immunity clauses, vague definitions, and aggressive spying powers combine to make the bill a surveillance bill in disguise. Further, the bill does not address problems from the recent highly publicized computer data breaches that were caused by unencrypted files, poor computer architecture, un-updated servers, and employees (or contractors) clicking malware links.
Among the 14 senators who voted against the bill is Patrick Leahy (D-Vt.), who echoed Timm's comments in stating ahead of the vote that CISA "giv[es] large corporations more liability protection and even more leeway on how to use and share our personal information with the government--without adequate privacy protections."
The American Library Association (ALA) is also among the groups against CISA, and joined dozens of civil society organizations and security experts in issuing a letter (pdf) to senators earlier this year urging them to vote against the legislation.
"When librarians oppose a bill with 'information sharing' in its name you can be sure that the bill is decidedly more than advertised," ALA president Sari Feldman stated last week, and added that CISA "could function, as a practical matter, as a new warrantless surveillance tool."
Prompted by the vote, some of the organizations against the legislation, including Fight for the Future, CODEPINK, and Restore the Fourth, staged a CISA protest on Thursday night outside the U.S. Capitol building.
"The U.S. government's deplorable surveillance programs and pathetic cybersecurity have already severely damaged the public's trust in tech companies and their members of Congress," Evan Greer, campaign director of Fight for the Future, said in a statement issued Friday.
"If they choose to ignore the blatantly overwhelming opposition to this bill and pass it anyway, that damage could become irreparable," Greer's statement continued. "This moment will go down in history, and politicians need to decide which side of history they want to be on: the side that fought for freedom or the side that gave it away."
The legislation is set for a final vote on Tuesday. The House has already passed its version of the bill.
Following several dedicated grassroots campaigns by consumer rights advocates, technology companies are opposing the Cybersecurity Information Sharing Act (CISA) as the controversial surveillance bill approaches a vote in the U.S. Senate.
Some industry titans now publicly opposing CISA are Google, Apple, and Twitter, among other well-known companies, while those who support the bill include Verizon, AT&T, and Cisco.
CISA would allow tech companies to share user data with the National Security Agency (NSA) and other intelligence offices in cases of "cybersecurity threats." Critics say the bill only expands government surveillance powers and guts consumer protections.
Apple publicly came out against CISA on Tuesday as the Senate began gearing up for the vote, citing concerns over privacy and users' rights.
"We don't support the current CISA proposal," Apple said. "The trust of our customers means everything to us, and we don't believe security should come at the expense of their privacy."
Apple's strong stance on the issue earned it a top spot on digital rights group Fight for the Future's "Digital Scorecard," which tracks where tech firms stand in the battle for privacy. Companies that have publicly supported reform for the Electronic Communications Privacy Act (ECPA) and opposed CISA and other legislation that would give governments a backdoor into encrypted devices were named "Team Internet."
Those who did any less were dubbed "Team NSA."
"People trust these companies with a staggering amount of personal information, and we need ways to hold them accountable to ensure they keep our data safe from both attackers and the government," said Fight for the Future's campaign director Evan Greer. "It's not enough for companies to employ basic security practices; they must actively fight for their users' basic rights when key policy questions arise. Politicians constantly claim the tech industry's support when attempting to undermine our privacy, so these companies have a responsibility to fight back."
As Freedom of the Press Foundation co-founder Trevor Timm wrote in an op-ed for the Guardian on Tuesday, CISA is nothing more than "a surveillance bill in disguise." That opposition is coming from the likes of Google and Amazon--no strangers to privacy scandals--shows how bad the bill really is, Timm wrote.
Also in the internet's corner is Dropbox, marking a significant shift for a company that recently added surveillance advocate Condoleezza Rice to its board of directors and which NSA whistleblower Edward Snowden once called "a wannabe PRISM partner" for its anti-privacy policies.
"While the public and private sector needs to share relevant data about emerging threats, that type of collaboration should not come at the expense of users' privacy," Amber Cottle, head of Dropbox global public policy and government affairs, said on Tuesday.
Some of the other firms that also got high marks on the Digital Scorecard, including Apple and Microsoft, reversed course after initially giving their support to CISA--which resulted in a massive email campaign, also organized by Fight for the Future, threatening to quit using their products, services, and platforms if the bill went through.
The digital rights group said the pressure is on Congress and offered a similar warning to lawmakers.
"It's outrageous that Congress is even considering passing a law that would further erode Internet users' privacy and security at a time when both are already so fragile," Greer said. "CISA's supporters have repeatedly claimed that the tech industry needs this legislation, but now nearly every major tech company has come out opposing it, not only because they know it won't stop cyber attacks, but also because it's supremely unpopular with their users."
"Congress should remember that those users are also voters," Greer said.