

SUBSCRIBE TO OUR FREE NEWSLETTER
Daily news & progressive opinion—funded by the people, not the corporations—delivered straight to your inbox.
5
#000000
#FFFFFF
To donate by check, phone, or other method, see our More Ways to Give page.


Daily news & progressive opinion—funded by the people, not the corporations—delivered straight to your inbox.
The Oregon Democrat also informed colleagues of his staff's findings that "senators have been kept in the dark about executive branch surveillance of Senate phones," in apparent violation of companies' contracts.
U.S. Sen. Ron Wyden shared the results of his staff's probe into major phone companies in a Wednesday letter to congressional colleagues and also publicly highlighted which carriers disclose government spying to their customers.
"An investigation by my staff revealed that until recently, senators have been kept in the dark about executive branch surveillance of Senate phones, because the three major phone carriers—AT&T, Verizon, and T-Mobile—failed to establish systems to notify offices about surveillance requests, as required by their Senate contracts," states the letter, published on Wyden's (D-Ore.) congressional website.
"While now rectified for Senate-funded lines, significant gaps remain, especially for the campaign and personal phones used by most senators. I urge your support for legislative changes to allow the sergeant at arms (SAA) to protect senators' phones and accounts from cyber threats, both foreign and domestic," he wrote. "I also urge you to consider switching your campaign and personal phone lines to other carriers that will provide notice of government surveillance."
Wyden noted that "while AT&T and Verizon only provide notice of surveillance of phone lines paid for by the Senate, T-Mobile has informed my staff that it will provide notice for senators' campaign or personal lines flagged as such by the SAA. Three other carriers—Google Fi Wireless, U.S. Mobile, and Cape—have policies of notifying all customers about government demands whenever they are allowed to do so. The latter two companies adopted these policies after outreach from my office."
In a Wednesday statement announcing the letter and the above chart, Wyden's office warned that "beyond members of Congress, journalists, political activists, people seeking reproductive healthcare, and other law-abiding Americans who could be targeted by the government all have reason to be concerned about secret surveillance of their communications and location data."
The findings of his staff include details relevant to every American with a cellphone, but much of Wyden's letter is focused on improving protections for lawmakers. He pointed to "two troubling incidents" that "highlight the vulnerability of Senate communications" to foreign adversaries and U.S. law enforcement: Chinese Salt Typhoon hackers and the U.S. Department of Justice, during the first Trump administration, both collected records of lawmakers and their staff.
"Executive branch surveillance poses a significant threat to the Senate's independence and the foundational principle of separation of powers," Wyden argued. "If law enforcement officials, whether at the federal, state, or even local level, can secretly obtain senators' location data or call histories, our ability to perform our constitutional duties is severely threatened."
"This kind of unchecked surveillance can chill critical oversight activities, undermine confidential communications essential for legislative deliberations, and ultimately erode the legislative branch's co-equal status," he continued. Wyden called on senators to support his proposals for the next annual appropriations bill "that would allow the SAA to protect senators' phones and accounts—whether official, campaign, or personal—against cyber threats, just as we have for executive branch employees."
The longtime privacy advocate's letter to fellow senators was first reported by Politico, which noted that T-Mobile did not immediately respond to requests for comment while spokespeople for AT&T and Verizon defended their companies.
"We are complying with our obligations to the Senate sergeant at arms," AT&T spokesperson Alex Byers said in a statement to the outlet. "We have received no legal demands regarding Senate offices under the current contract, which began last June."
Verizon spokesperson Richard Young told Politico that "we respect the senator's view that providers should give notice to senators if we receive legal process regarding their use of their personal devices, but disagree with his policy position."
Meanwhile, Sean Vitka, executive director of Demand Progress—an advocacy group long critical of government spying on lawmakers and warrantless surveillance—said in response to the revelations from Wyden's office that "we now know that Comcast, Verizon, T-Mobile, and other phone companies have followed AT&T's unprecedented efforts to facilitate secret government surveillance of their own customers, with some even allowing the government to secretly spy on senators."
"This is a bright, red warning sign at a time when the Trump administration keeps blowing past constitutional checks on executive power and is siccing the Justice Department on elected lawmakers," Vitka added. "These companies should be shamed and ashamed until they fix this."
"If the plundering of Americans' data wasn't concerning enough, the targeted, physical threats and surveillance... takes this to another level," said the whistleblower's attorney.
Despite finding a letter with "threatening language, sensitive personal information, and overhead pictures of him walking his dog" taped to his door, a technology expert at a federal labor agency has become a whistleblower, urging U.S. officials to investigate data practices by President Donald Trump and billionaire Elon Musk's so-called Department of Government Efficiency.
NPR on Tuesday published a lengthy report about whistleblower Daniel Berulis' submission to Congress and the U.S. Office of Special Counsel sounding the alarm over DOGE employees' recent activities at the National Labor Relations Board (NLRB)—which the president also has tried to effectively shut down, leading to court battles.
While DOGE didn't respond to NPR's request for comment, Tim Bearese, the NLRB's acting press secretary, claimed that the Musk-led entity had not requested access to the agency's system, and the NLRB had not granted it. He also said the agency investigated after Berulis raised concerns but "determined that no breach of agency systems occurred."
"As an agency protecting employee rights, the NLRB respects its employee's right to bring whistleblower claims to Congress and the Office of Special Counsel, and the agency looks forward to working with those entities to resolve the complaints," he added.
Those who spoke with NPR struck a much different tone. The reporting features interviews with Bearese, his attorney—Andrew Bakaj of Whistleblower Aid—and dozens of other experts in tech, law enforcement, the labor movement, and government. It adds to mounting worries about what DOGE is doing across various agencies under the reign of the richest man on Earth.
"I can't attest to what their end goal was or what they're doing with the data," Berulis—who found evidence of up to around 10 gigabytes of data, or the equivalent of a full stack of encyclopedias, leaving the NLRB system—told NPR. "But I can tell you that the bits of the puzzle that I can quantify are scary... This is a very bad picture we're looking at."
There's always been reason to believe DOGE was hacking govt systems. Now a whistleblower has substantiated it at NLRB, precisely the kind of data compromise labor unions worried about when they sued re DOL.
[image or embed]
— emptywheel ( @emptywheel.bsky.social) April 15, 2025 at 6:26 AM
"The amount of data that was taken is the equivalent to a section of the New York Public Library, and the amount of people it could impact is in the hundreds of millions," Berulis noted in a Tuesday statement from Whistleblower Aid. "Our information systems appear to have been assaulted, and someone with the capacity and mandate to investigate needs to do so."
According to NPR, labor law experts "fear that if the data gets out, it could be abused, including by private companies with cases before the agency that might get insights into damaging testimony, union leadership, legal strategies and internal data on competitors—Musk's SpaceX among them. It could also intimidate whistleblowers who might speak up about unfair labor practices, and it could sow distrust in the NLRB's independence."
Russ Handorf, who spent a decade in cybersecurity roles at the Federal Bureau of Investigation, reviewed Berulis' records and told NPR that "all of this is alarming" and "if this was a publicly traded company, I would have to report this [breach] to the Securities and Exchange Commission."
Sharon Block, a former NLRB board member and now executive director of Harvard Law School's Center for Labor and a Just Economy, said that "there is nothing that I can see about what DOGE is doing that follows any of the standard procedures for how you do an audit that has integrity and that's meaningful and will actually produce results that serve the normal auditing function, which is to look for fraud, waste, and abuse."
"The mismatch between what they're doing and the established, professional way to do what they say they're doing... that just kind of gives away the store, that they are not actually about finding more efficient ways for the government to operate," she told NPR.
It's not just DOGE affiliates, including Musk, who may have access to the data taken from federal agencies, including the NLRB. NPR reported that "if the data isn't properly protected after it leaves the agency or if DOGE left a digital door open to the agency itself, data could also be exposed to potential sale or theft by criminals or foreign adversaries."
In Whistleblower Aid's statement, Bakaj said that "what is particularly alarming is that in addition to private data being exfiltrated out of NLRB systems—and within minutes of DOGE personnel creating service/user accounts in NLRB systems—someone or something within Russia appeared to attempt to login using all of the correct credentials (e.g. usernames/passwords) on several occasions. This near real-time unlimited access by Russian actors heightens concerns to a level not previously seen and could have destroyed the agency's entire infrastructure in a matter of minutes."
"If the compromise of American's data wasn't concerning enough, the targeted, physical threats and surveillance of my client takes this to another level," he added. "It is time for Congress to act and investigate to keep our democracy from slipping away, something that could take generations to repair."
While NPR readers called the report "sickening" and shared warnings of "technofascism," there is also some optimism in this story: Berulis hopes that he not only prompts a probe but also provides a roadmap for other government employees to come forward.
"I believe with all my heart that this goes far beyond just case data," the whistleblower said. "I know there are [people] at other agencies who have seen similar behavior. I firmly believe that this is happening maybe even to a greater extent at other agencies."
"It is long overdue that Microsoft and other Big Tech monopolies are broken up—for good," said one expert.
Digital rights advocates responded to Friday's havoc-wreaking global technology outage by sounding the alarm on the Big Tech monopolies.
The outage—which is being attributed to a software update by the U.S.-based cybersecurity firm CrowdStrike—sparked worldwide chaos on Friday, causing so-called "blue screens of death" on computers using Microsoft Windows. The outage grounded commercial flights and caused serious disruptions to transportation, financial, and healthcare systems.
"Today's massive global Microsoft outage is the result of a software monopoly that has become a single point of failure for too much of the global economy," George Rakis, executive director of the advocacy group NextGen Competition, said in a statement.
"For decades, Microsoft's pursuit of a vendor lock-in strategy has prevented the public and private sectors from diversifying their IT capabilities," he continued. "From airports to hospitals to 911 call centers to financial systems, millions today are feeling the consequences of the greed and ego of one of the most egregious offenders in Big Tech."
Emily Peterson-Cassin, who heads Demand Progress' corporate power program, said that "today's outage shows how one software issue stemming from only one or two companies can ground flights, take down hospital systems, stop 911 calls, and cut off access to the internet in one fell swoop."
"Economy-wide reliance on a few giant companies is a serious fundamental risk to Americans," she asserted. "No one regulatory or legislative intervention will prevent this kind of situation, but there are plenty of policies that can reduce the danger. Efforts to empower regulators' ability to tackle the risks posed by concentrated corporate actors are critical to protecting Americans from these kinds of failures."
Bloomberg columnist Parmy Olson—who focuses on tech issues—said that Friday's outage "should spur Microsoft and other IT firms to do more than simply administer a Band-aid."
"The bigger problem is the supply chain itself for cloud computing and, by extension, cybersecurity services, which has left too many organizations vulnerable to a single point of failure," she noted. "When just three companies—Microsoft, Amazon, and Google—dominate the market for cloud computing, one minor incident can have global ramifications."
European Union nations "are furthest ahead in addressing the market stranglehold that these so-called hyperscalers have with the new E.U. Data Act, which aims to lower the cost of switching between cloud providers and improve interoperability," Olson noted.
"U.S. legislators should get in the game too," she argued. "One idea might be to force companies in critical sectors like healthcare, finance, transportation, and energy to use more than just one cloud provider for their core infrastructure, which tends to be the status quo."
"Instead, a new regulation could force them to use at least two independent providers for their core operations, or at least ensure that no single provider accounts for more than about two-thirds of their critical IT infrastructure," Olson added. "If one provider has a catastrophic failure, the other can keep things running."
However, most congressional efforts to rein in Big Tech monopoly power and encourage competition have failed or languished amid opposition and obstruction from lobbyists and corporate lawmakers.
Ultimately, Rakis stressed, "it is long overdue that Microsoft and other Big Tech monopolies are broken up—for good."
"Microsoft has turned a blind eye to cybersecurity vulnerabilities for years and enough is enough," Rakis said. "Not only are these monopolies too big to care, they're too big to manage. And despite being too big to fail, they have failed us. Time and time again. Now, it's time for a reckoning. We can't continue to let Microsoft's executives downplay their role in making all of us more vulnerable."
"This is basically what we were all worried about with Y2K, except it's actually happened this time."
A global technology outage attributed to a software update by the U.S.-based cybersecurity firm CrowdStrike sparked chaos around the world Friday as flights were grounded and healthcare, banking, and ground transportation systems experienced major disruptions.
George Kurtz, the president and CEO of CrowdStrike, said in a statement Friday morning that the company is "actively working with customers impacted by a defect found in a single content update for Windows hosts"—a glitch that affected Microsoft users around the world.
"This is not a security incident or cyberattack," Kurtz added. "The issue has been identified, isolated, and a fix has been deployed. We refer customers to the support portal for the latest updates and will continue to provide complete and continuous updates on our website. We further recommend organizations ensure they're communicating with CrowdStrike representatives through official channels. Our team is fully mobilized to ensure the security and stability of CrowdStrike customers."
The Financial Times explained that Crowdstrike is "one of the world's largest providers of 'endpoint' security software, used by companies to monitor for security problems across a huge range of devices, from desktop PCs to checkout payment terminals."
Troy Hunt, a security consultant, wrote on social media that "this will be the largest IT outage in history."
"This is basically what we were all worried about with Y2K, except it's actually happened this time," Hunt added.
The impacts of the outage cascaded rapidly. Wired noted that "in the early hours of Friday, companies in Australia running Microsoft's Windows operating system started reporting devices showing Blue Screens of Death (BSODs)."
"Shortly after," the outlet continued, "reports of disruptions started flooding in from around the world, including from the U.K., India, Germany, the Netherlands, and the U.S.: TV station Sky News went offline, and U.S. airlines United, Delta, and American Airlines issued a 'global ground stop' on all flights."
As The New York Times observed, the National Health Service in the United Kingdom "was crippled throughout the morning on Friday, as a number of hospitals and doctors offices lost access to their computer systems."
The agreement "is a step in the right direction for security," said one observer, "but that's not the only area where AI can cause harm."
Like an executive order introduced by U.S. President Joe Biden last month, a global agreement on artificial intelligence released Sunday was seen by experts as a positive step forward—but one that would require more action from policymakers to ensure AI isn't harmful to workers, democratic systems, and the privacy of people around the world.
The 20-page agreement, first reported Monday, was reached by 18 countries including the U.S., U.K., Germany, Israel, and Nigeria, and was billed as a deal that would push companies to keep AI systems "secure by design."
The agreement is nonbinding and deals with four main areas: secure design, development, deployment, and operation and maintenance.
Policymakers including the director of the U.S. Cybersecurity and Infrastructure Security Agency, Jen Easterly, forged the agreement with a heavy focus on keeping AI technology safe from hackers and security breaches.
The document includes recommendations such as implementing standard cybersecurity best practices, monitoring the security of an AI supply chain across the system's life cycle, and releasing models "only after subjecting them to appropriate and effective security evaluation."
"This is the first time that we have seen an affirmation that these capabilities should not just be about cool features and how quickly we can get them to market or how we can compete to drive down costs," Easterly told Reuters. The document, she said, represents an "agreement that the most important thing that needs to be done at the design phase is security."
Norm Eisen, senior fellow at the think tank Brookings Institution, said the deal "is a step in the right direction for security" in a field that U.K. experts recently warned is vulnerable to hackers who could launch "prompt injection" attacks, causing an AI model to behave in a way that the designer didn't intend or reveal private information.
"But that's not the only area where AI can cause harm," Eisen said on social media.
Eisen pointed to a recent Brrokings analysis about how AI could "weaken" democracy in the U.S. and other countries, worsening the "flood of misinformation" with deepfakes and other AI-generated images.
"Advocacy groups or individuals looking to misrepresent public opinion may find an ally in AI," wrote Eisen, along with Nicol Turner Lee, Colby Galliher, and Jonathan Katz last week. "AI-fueled programs, like ChatGPT, can fabricate letters to elected officials, public comments, and other written endorsements of specific bills or positions that are often difficult to distinguish from those written by actual constituents... Much worse, voice and image replicas harnessed from generative AI tools can also mimic candidates and elected officials. These tactics could give rise to voter confusion and degrade confidence in the electoral process if voters become aware of such scams."
At AppleInsider, tech writer Malcolm Owen denounced Sunday's agreement as "toothless and weak," considering it does not require policymakers or companies to adhere to the guidelines.
Owen noted that tech firms including Google, Amazon, and Palantir consulted with global government agencies in developing the guidelines.
"These are all guidelines, not rules that must be obeyed," wrote Owen. "There are no penalties for not following what is outlined, and no introduction of laws. The document is just a wish list of things that governments want AI makers to really think about... And, it's not clear when or if legislation will arrive mandating what's in the document."
European Union member countries passed a draft of what the European Parliament called "the world's first comprehensive AI law" earlier this year with the AI Act. The law would require AI systems makers to publish summaries of the training material they use and prove that they will not generate illegal content. It would also bar companies from scraping biometric data from social media, which a U.S. AI company was found to be doing last year.
"AI tools are evolving rapidly," said Eisen on Monday, "and policymakers need to keep up."
"There is no more urgent task than understanding and mitigating the potential risks posed by the interaction of advancing cyber capabilities with nuclear weapons systems."
A report published Wednesday by a U.S. nonprofit group recommends cooperation between the United States and Russia aimed at reducing the threat of a nuclear war sparked by cyberattacks on nuclear weapon systems.
"In the modern nuclear age, there is no more urgent task than understanding and mitigating the potential risks posed by the interaction of advancing cyber capabilities and nuclear weapons systems," the Nuclear Threat Initiative (NTI) asserted in the report, entitled Reducing Cyber Risks to Nuclear Weapons: Proposals From a U.S.-Russia Expert Dialogue.
The publication "highlights the critical need for a global diplomatic approach to address growing cyber risks, including, where possible, through cooperation between the United States and Russia."
"Despite significant current geopolitical tensions, the United States and Russia have a mutual interest in avoiding the use of nuclear weapons and an obligation to work together to do so based on the understanding that a cyberattack on a nuclear weapons system could trigger catastrophic and unintended conflict and escalation," the group said in an implied reference to strained relations amid Russia's ongoing invasion of Ukraine.
NTI drew from talks between U.S. and Russian nonproliferation experts that took place in 2020 and 2021 prior to last year's invasion of Ukraine.
"While acknowledging the challenges posed by an already charged political environment, the dialogue emphasized the importance of maintaining cooperation between the United States and Russia on key nuclear security issues, the value of unilateral risk reduction actions, and the benefit of developing ideas for cooperative steps to be advanced when the political situation improves," the organization noted.
The talks yielded six recommendations for the U.S. and Russia to reduce cyber risks:
"Today, the United States and Russia still possess roughly 90% of the world's nuclear weapons and are also among the most proficient and active developers and users of information and communications technology (ICT)," the report notes. "Nuclear weapons policies, however, have not kept up with these technological advancements."
"Meanwhile," the publication continues, "the ubiquity of advanced digital ICT tools, as well as their fulsome functional benefits, have led both countries' nuclear weapons enterprises to incorporate digital technologies into their nuclear weapons, warning, command, control, and communications systems."
"Both the United States and Russia should prioritize cyber-nuclear weapons risk-reduction as they pursue future bilateral and multilateral arms control, confidence-building, and transparency initiatives."
"With that modernization come vulnerabilities and openness to cyberattacks that could prompt dangerous miscalculations or accidents, leading to nuclear use," NTI stated, adding that "in the mid- to long-term, cybersecurity can be improved in the
context of ongoing nuclear weapons systems modernization."
"Mutual commitments can be codified through various political or legal formats," the report states. "Nuclear force modernization in each country presents an opportunity to clarify, isolate, and distinguish which systems are involved in nuclear deterrence missions from civilian infrastructure, critical national assets, and conventional warfighting systems."
"Modernization also provides opportunities to improve system resiliency and upgrade cybersecurity measures and practices," the publication adds. "Both the United States and Russia should prioritize cyber-nuclear weapons risk-reduction as they pursue future bilateral and multilateral arms control, confidence-building, and transparency initiatives."
The new report came a day after the U.S. Department of Defense published an unclassified summary of its 2023 Cyber Strategy, the first update in five years, in which the Pentagon stated it would "use cyberspace operations for the purpose of campaigning, undertaking actions to limit, frustrate, or disrupt adversaries' activities below the level of armed conflict and to achieve favorable security conditions."
The Pentagon added that it would "remain closely attuned to adversary perceptions and will manage the risk of unintended escalation."
Russia's war and U.S. support for Ukrainian efforts to oust invaders have heightened international calls for disarmament, with U.N. Secretary-General António Guterres recently warning that nuclear modernization and rising global mistrust is "a recipe for annihilation."
In case you weren't already convinced that CISA is a surveillance bill masquerading as a cybersecurity bill, today, the Senate rejected four separate amendments to the bill that attempted to protect Americans' privacy better. Senator Wyden had an amendment to require the removal of personal information before information could be shared, which was voted down 55 to 41. Senator Heller had an amendment that was a backstop against the Wyden amendment, saying that if the Wyden amendment didn't pass, Homeland Security would be responsible for removing such personal information. That amendment also failed with 49 to 47 votes. Senator Leahy had an amendment that would have removed FOIA exemptions in the bill (making it much less transparent how CISA was used). That amendment was voted down 59 to 37. Senator Franken then had an amendment that would have "tightened" the definition of cybersecurity threats so that the shared information needed to be "reasonably likely" to cause damage, as opposed to the current "may" cause damage. And (you guessed it because you're good at this), it was also voted down by a 60 to 35 vote.
Meanwhile, Marcy Wheeler notes that the revised version of the bill by Senators Burr and Feinstein, which claimed to incorporate greater transparency requirements proposed by Senator Tester, actually takes away a lot of transparency and actually makes it more difficult for Congress to learn whether or not CISA is being used for domestic surveillance:
That Burr and DiFi watered down Tester's measures so much makes two things clear. First, they don't want to count some of the things that will be most important to count to see whether corporations and agencies are abusing this bill. They don't want to count measures that will reveal if this bill does harm.
Most importantly, though, they want to keep this information from Congress. This information would almost certainly not show up to us in unclassified form, it would just be shared with some members of Congress (and on the House side, just be shared with the Intelligence Committee unless someone asks nicely for it).
But Richard Burr and Dianne Feinstein want to ensure that Congress doesn't get that information. Which would suggest they know the information would reveal things Congress might not approve of.
Once again, these actions only make sense if CISA is being used to justify warrantless domestic surveillance. This raises the question of why Congress is willing to proceed with such a surveillance bill. We just went through a process showing that the public is uncomfortable with secret laws and interpretations that lead to surveillance. Why would they immediately push for a new secret law that expands surveillance and rejects any attempts to protect the privacy of the American public or any sort of transparency and accountability in how the bill is used?
The bill is positioned as a cybersecurity bill, but you'd be hard-pressed to find a single computer security expert who thinks it is useful or necessary. I've been trying, and so far, I can't find any.
Update:
| #StopCISA Tweets |
On Tuesday, the U.S. Senate passed the Cybersecurity Information Sharing Act (CISA) without any of the proposed amendments that would have strengthened user protections. The bill passed 74-21 (see the roll call here).
Rights groups immediately called for President Obama to veto the bill and vowed to keep the pressure up.
"Every senator supporting #CISA today voted against a world with freedom, democracy, and basic human rights," tweeted digital rights organization Fight for the Future. "If President Obama does not veto this bill, he'll show that his administration never truly cared about the open Internet."
"This vote will go down as the moment Congress codified the US government's unconstitutional spying. A sad day for the Internet," the group added.
In its response to CISA's passage in the Senate, the Electronic Frontier Foundation marked its disappointment. It said: "The bill is fundamentally flawed due to its broad immunity clauses, vague definitions, and aggressive spying authorities."
With the bill now moving to conference committee, EFF expressed no confidence that it would be improved.
"The passage of CISA reflects the misunderstanding many lawmakers have about technology and security," EFF continued. "Computer security engineers were against it. Academics were against it. Technology companies, including some of Silicon Valley's biggest companies, such as Twitter and Salesforce, were against it. Civil society organizations were against it. And constituents sent over 1 million faxes opposing CISA to Senators."
EFF vowed that the fight against the bill would continue through the conference committee process, where the group would urge lawmakers to add privacy provisions. "We will never stop fighting for lawmakers to either understand technology or when they need to listen to the people who do," the group said.
The official Senate roll call to the vote follows:
Alphabetical by Senator Name
|
Alexander (R-TN), Yea Ayotte (R-NH), Yea Baldwin (D-WI), Nay Barrasso (R-WY), Yea Bennet (D-CO), Yea Blumenthal (D-CT), Yea Blunt (R-MO), Yea Booker (D-NJ), Nay Boozman (R-AR), Yea Boxer (D-CA), Yea Brown (D-OH), Nay Burr (R-NC), Yea Cantwell (D-WA), Yea Capito (R-WV), Yea Cardin (D-MD), Nay Carper (D-DE), Yea Casey (D-PA), Yea Cassidy (R-LA), Yea Coats (R-IN), Yea Cochran (R-MS), Yea Collins (R-ME), Yea Coons (D-DE), Nay Corker (R-TN), Yea Cornyn (R-TX), Yea Cotton (R-AR), Yea Crapo (R-ID), Nay Cruz (R-TX), Not Voting Daines (R-MT), Nay Donnelly (D-IN), Yea Durbin (D-IL), Yea Enzi (R-WY), Yea Ernst (R-IA), Yea Feinstein (D-CA), Yea Fischer (R-NE), Yea |
Flake (R-AZ), Yea Franken (D-MN), Nay Gardner (R-CO), Yea Gillibrand (D-NY), Yea Graham (R-SC), Not Voting Grassley (R-IA), Yea Hatch (R-UT), Yea Heinrich (D-NM), Yea Heitkamp (D-ND), Yea Heller (R-NV), Nay Hirono (D-HI), Yea Hoeven (R-ND), Yea Inhofe (R-OK), Yea Isakson (R-GA), Yea Johnson (R-WI), Yea Kaine (D-VA), Yea King (I-ME), Yea Kirk (R-IL), Yea Klobuchar (D-MN), Yea Lankford (R-OK), Yea Leahy (D-VT), Nay Lee (R-UT), Nay Manchin (D-WV), Yea Markey (D-MA), Nay McCain (R-AZ), Yea McCaskill (D-MO), Yea McConnell (R-KY), Yea Menendez (D-NJ), Nay Merkley (D-OR), Nay Mikulski (D-MD), Yea Moran (R-KS), Yea Murkowski (R-AK), Yea Murphy (D-CT), Yea Murray (D-WA), Yea |
Nelson (D-FL), Yea Paul (R-KY), Not Voting Perdue (R-GA), Yea Peters (D-MI), Yea Portman (R-OH), Yea Reed (D-RI), Yea Reid (D-NV), Yea Risch (R-ID), Nay Roberts (R-KS), Yea Rounds (R-SD), Yea Rubio (R-FL), Not Voting Sanders (I-VT), Nay Sasse (R-NE), Yea Schatz (D-HI), Yea Schumer (D-NY), Yea Scott (R-SC), Yea Sessions (R-AL), Yea Shaheen (D-NH), Yea Shelby (R-AL), Yea Stabenow (D-MI), Yea Sullivan (R-AK), Nay Tester (D-MT), Nay Thune (R-SD), Yea Tillis (R-NC), Yea Toomey (R-PA), Yea Udall (D-NM), Nay Vitter (R-LA), Not Voting Warner (D-VA), Yea Warren (D-MA), Nay Whitehouse (D-RI), Yea Wicker (R-MS), Yea Wyden (D-OR), Nay |
Earlier:
As the U.S. Senate gears up for a vote on Tuesday's controversial Cybersecurity Information Sharing Act (CISA), privacy advocates are galvanizing an 11th-hour push against the bill they say does nothing more than expand government spying powers.
A slew of digital rights groups, including Fight for the Future and the Electronic Frontier Foundation, along with whistleblower Edward Snowden and outspoken CISA opponent Sen. Ron Wyden (D-Ore.), joined forces Monday night for an Ask Me Anything (AMA) session on Reddit, which has also come out against the bill. The session was the latest action by civil society groups, activists, and tech companies calling on Congress to reject CISA for its anti-privacy provisions.
"CISA isn't a cybersecurity bill," Snowden wrote during the Q&A. "It's not going to stop any attacks. It's not going to make us any safer. It's a surveillance bill."
Supporters of CISA--including Sens. Dianne Feinstein (D-Calif.) and Richard Burr (R-N.C.)--say the bill would make it easier for tech companies to share data in cases of security breaches and other digital attacks. But critics say there aren't enough safeguards in place to protect user privacy, and the bill only works to serve intelligence agencies in domestic surveillance operations.
"What it allows is for the companies you interact with every day--visibly, like Facebook, or invisibly, like AT&T--to indiscriminately share private records about your interactions and activities with the government," Snowden wrote on Monday. "CISA allows private companies to immediately share a perfect record of your private activities the instant you click a link, log in, make a purchase, and so on--and the government with reward for doing it by granting them a special form of legal immunity for their cooperation."
Fight for the Future campaign director Evan Greer said the Senate's vote on Tuesday "will go down in history as the moment that lawmakers decided not only what sort of Internet our children and our children's children will have, but what sort of world they will live in."
The campaigns, which are being waged under the hashtag #StopCISA, urge senators to oppose the bill and protect civil liberties.
Greer added, "Every Senator who votes for CISA will be voting for a world without freedom of expression, a world without true democracy, a world without basic human rights. And they will be voting for their removal from office because the Internet will not forget which side of history they stood on."
Following several dedicated grassroots campaigns by consumer rights advocates, technology companies are opposing the Cybersecurity Information Sharing Act (CISA) as the controversial surveillance bill approaches a vote in the U.S. Senate.
Some industry titans now publicly opposing CISA are Google, Apple, and Twitter, among other well-known companies, while those who support the bill include Verizon, AT&T, and Cisco.
CISA would allow tech companies to share user data with the National Security Agency (NSA) and other intelligence offices in cases of "cybersecurity threats." Critics say the bill only expands government surveillance powers and guts consumer protections.
Apple publicly came out against CISA on Tuesday as the Senate began gearing up for the vote, citing concerns over privacy and users' rights.
"We don't support the current CISA proposal," Apple said. "The trust of our customers means everything to us, and we don't believe security should come at the expense of their privacy."
Apple's strong stance on the issue earned it a top spot on digital rights group Fight for the Future's "Digital Scorecard," which tracks where tech firms stand in the battle for privacy. Companies that have publicly supported reform for the Electronic Communications Privacy Act (ECPA) and opposed CISA and other legislation that would give governments a backdoor into encrypted devices were named "Team Internet."
Those who did any less were dubbed "Team NSA."
"People trust these companies with a staggering amount of personal information, and we need ways to hold them accountable to ensure they keep our data safe from both attackers and the government," said Fight for the Future's campaign director Evan Greer. "It's not enough for companies to employ basic security practices; they must actively fight for their users' basic rights when key policy questions arise. Politicians constantly claim the tech industry's support when attempting to undermine our privacy, so these companies have a responsibility to fight back."
As Freedom of the Press Foundation co-founder Trevor Timm wrote in an op-ed for the Guardian on Tuesday, CISA is nothing more than "a surveillance bill in disguise." That opposition is coming from the likes of Google and Amazon--no strangers to privacy scandals--shows how bad the bill really is, Timm wrote.
Also in the internet's corner is Dropbox, marking a significant shift for a company that recently added surveillance advocate Condoleezza Rice to its board of directors and which NSA whistleblower Edward Snowden once called "a wannabe PRISM partner" for its anti-privacy policies.
"While the public and private sector needs to share relevant data about emerging threats, that type of collaboration should not come at the expense of users' privacy," Amber Cottle, head of Dropbox global public policy and government affairs, said on Tuesday.
Some of the other firms that also got high marks on the Digital Scorecard, including Apple and Microsoft, reversed course after initially giving their support to CISA--which resulted in a massive email campaign, also organized by Fight for the Future, threatening to quit using their products, services, and platforms if the bill went through.
The digital rights group said the pressure is on Congress and offered a similar warning to lawmakers.
"It's outrageous that Congress is even considering passing a law that would further erode Internet users' privacy and security at a time when both are already so fragile," Greer said. "CISA's supporters have repeatedly claimed that the tech industry needs this legislation, but now nearly every major tech company has come out opposing it, not only because they know it won't stop cyber attacks, but also because it's supremely unpopular with their users."
"Congress should remember that those users are also voters," Greer said.
Since the most successful hack launched against government servers compromised the personal information of more than 4.2 million government employees, the government has been scrambling to prevent it from happening again.
On June 4, the Office of Personnel Management announced it had been hacked, and officials have speculated that Chinese sources are to blame.
With FBI officials concerned about their ability to defend national security, FBI Director James Comey has called on companies such as Apple and Google to build "back doors" into encryption to protect user information from hacks but allow government agencies to access the data.
The main problem with Comey's request is that there is no feasible way to create a back door to encryption for government access without making it susceptible to hacks from other sources. An open window is an open window, explained Bill Buddington, a software engineer for the Electronic Frontier Foundation.
"If history serves as any lesson, we know that once there's a back door for one government agency, then it's not a far jump to see that that back door is also accessible to others--to hackers and to malicious third parties," Buddington told Truthdig. "There's no way to build a back door so the government can get access to your device and no one else can," he said. An ironic aspect of this situation is that President Obama has criticized countries like China for proposing to make U.S. companies hand over encryption keys in the name of fighting terrorism.
According to Buddington, the FBI's own website used to recommend that citizens use encryption, because the agency knew that that added safeguard would help protect their information. Now, since the surveillance state has ramped up, the agency wants to make sure it can access any data it deems necessary to access. Even though the FBI can still perform targeted surveillance operations and get warrants to access this data, Buddington notes, it wants more options for retrieving intel.
As Johns Hopkins cryptography professor Matthew Green has stated, forcing companies such as Google and Apple to break their own encryption will do absolutely nothing to prevent terrorism. "You could strangle the whole U.S. tech industry, and ISIS would *still* be able to communicate with their followers using encryption," he tweeted in early June. Essentially, companies dealing with the data of ordinary U.S. citizens and employees would be wide open to hacks, while the people the FBI wants to go after would still just use encryption by other means. Even if encryption was made entirely illegal, there's little reason to believe terrorists would be afraid of breaking the law.
Beyond that, there is reason to believe that the data of more than 300 million people who don't work for the federal government could be extremely valuable to foreign entities. "If there are foreign governments that find value in getting U.S. government employee data, then there is no reason they'd stop [going after civilian data]," Buddington notes. He said a government that opposes the United States could do a lot with the metadata of U.S. citizens. "To see who is talking to whom, who is communicating with whom and who's meeting--these kind of diverse interactions are the bread and butter of intelligence-gathering more generally for nation-states," he said. "To know the movements of populations is to know how information flows more generally, and that can affect foreign policy decisions and national security decisions."
Malicious governments or other entities could collect all the information they want and then dive in to look for specific patterns or interactions. Information such as financial data, for example, could be of value to many hackers. What is thought to be the biggest bank heist ever involved more than 100 banks in 30 nations that were hacked by a cybercrime gang, and it is believed well over $300 million was lost--and possibly as much as $1 billion.
Buddington and other experts say citizens and government agencies should be encrypting all communications and data. As for the government's cybersecurity, Buddington says the technology it's using is antiquated and needs to be replaced to respond to evolving threats. He said the government also needs more cybersecurity experts at every level to advise those who may not know how to protect themselves. Keeping government data protected is important, but the country isn't any safer if only its leaders are out of the line of fire, he notes.