On the recordApril 23, 2015
The amendment that I am offering makes a fine bill even better. It clarifies that the definition of ``cybersecurity risk''--and, by extension, the definition of ``cybersecurity purpose''--does not apply to actions that solely involve the violation of consumer terms of service or consumer licensing agreements. This is a small but important change that will protect Americans' privacy and ensure that white hat security researchers are not inadvertently monitored. The cyber threat data that will help turn the tide against malicious actors are security vulnerabilities, attack vectors, and indicators of compromise. What will not help is knowing that a consumer has violated a Byzantine terms of service agreement or that a researcher is testing software for exploitable bugs that he or she will then share with the security community. While not every terms of service violation is well-meaning or born of ignorance, there is no doubt in my mind that the existing body of contract law is more than capable of facilitating dispute resolution in these cases. The exclusion my amendment proposes is not new to this floor. Both the 2012 and the 2013 versions of CISPA, which I worked on very closely while a member of the House Intelligence Committee, contained similar exclusions, and the Protecting Cyber Networks Act that passed the House yesterday also includes this language.…





