Showing posts with label HR 726. Show all posts
Showing posts with label HR 726. Show all posts

Wednesday, February 18, 2015

HR 726 Introduced – NSA Backdoors

As I mentioned earlier Rep. Lofgren (D,CA) introduced HR 726, the Secure Data Act of 2015. While the bill does not specifically mention the National Security Agency (NSA) it was obviously written in response to revelations that the NSA obtained backdoor access to various computer systems and software. Similar bills (HR 5800 and S 2981) were introduced last year during the close of the 113th Congress without any subsequent action.

The bill’s requirements are fairly straightforward. It states that no government agency “may mandate or request that a manufacturer, developer, or seller of covered products design or alter the security functions in its product or service to allow the surveillance of any user of such product or service, or to allow the physical search of such product, by any agency” {§2(a)}.

The one loop hole in this bill that I identified in my discussion of the bills introduced last year remains in the definition of ‘covered products’. That term is defined as “any computer hardware, computer software, or electronic device that is made available to the general public[emphasis added]”  {§2(c)(2)}. It could certainly be argued that servers and the software for many internet based services are not ‘available to the general public’.

The bill is careful to ensure that the language does not interfere with court ordered access to digital communications as authorized under 47 USC 1001 et seq. Even those provisions prohibit law enforcement agencies from requiring “any specific design of equipment, facilities, services, features, or system configurations to be adopted by any provider of a wire or electronic communication service, any manufacturer of telecommunications equipment, or any provider of telecommunications support services” {47 USC 1002(b)(1)(A)}.


I suspect that if this bill were to make it to the floor of the House that it would pass with substantial bipartisan support. The question is if Lofgren has the political connections to get this bill considered in either of the two committees to which it has been referred. She is a member of the Judiciary Committee so I would expect that this would be the first committee to see any action on this bill.

Thursday, February 5, 2015

Bills Introduced – 2-4-15

There were 82 bills introduced in the House and Senate yesterday. Five of the bills may be of specific interest to readers of this blog:

HR 702 To adapt to changing crude oil market conditions. Rep. Barton, Joe [R-TX-6]

HR 705 To amend the authorization in title 49, United States Code, for capital grants for rail line relocation projects. Rep. Maloney, Sean Patrick [D-NY-18]

HR 710 To require the Secretary of Homeland Security to prepare a comprehensive security assessment of the transportation security card program, and for other purposes. Rep. Jackson Lee, Sheila [D-TX-18]

HR 726 To prohibit Federal agencies from mandating the deployment of vulnerabilities in data security technologies. Rep. Lofgren, Zoe [D-CA-19]

S 356 A bill to improve the provisions relating to the privacy of electronic communications. Sen. Lee, Mike [R-UT]

HR 702 was actually introduced the day before, but it was assigned the number ‘HR 666’. Apparently this was considered a bad sign by Congressman Barton so the bill was re-introduced today. To be fair, anything that makes it hard for any member to vote for a bill is probably something to be avoided.


The two cybersecurity bills will probably not receive future mention here as I suspect that they are principally IT related bills. Control system language could creep in though.
 
/* Use this with templates/template-twocol.html */