Obama proposes legislation to protect firms that share cyberthreat data with the government, criminalize sale of botnets and stolen financial info, more
Context & Ripple Effects
This proposal lands mid-surge in Obama's January 2015 cybersecurity push: two days earlier he laid out companion bills covering student privacy and mandatory consumer breach notification (breach-disclosure legislation), and a week later he pressed the same theme from the podium at his State of the Union address. The throughline is liability relief for information-sharing plus sharper penalties for the underground market.
The significance is that the White House is trying to fix what it sees as the core market failure in threat intelligence — companies hoarding indicators because sharing exposes them legally — while critics like Errata Security immediately flagged that criminalizing hacking tools and stolen-data sales risks sweeping up legitimate security professionals.
First-order effects
- Firms that share cyberthreat data with the government gain promised legal protection, lowering the cost of reporting breaches and attack indicators they currently sit on; sellers of botnets and stolen financial information face a newly codified criminal charge.
Second-order effects
- Security researchers and penetration testers push back hard, as Errata Security's critique shows, forcing any final bill to draw a line between malicious tool-selling and defensive work; meanwhile Congress's slow response pushes the White House toward unilateral action.
Third-order effects
- When the legislative route stalls, the administration pivots to an [[a:826379|executive order urging companies to share threat information with each other and the government]], showing that sharing architecture gets built by presidential action even without a signed statute.
- The pattern scales into institutionalized federal spending: a year later Obama follows up with a $19B Cybersecurity National Action Plan and a requested 35% funding increase, signaling that threat-sharing was the opening move of a standing national cybersecurity apparatus rather than a one-off bill.
The trend: US cybersecurity policy is consolidating from scattered corporate practice into a federally codified threat-sharing framework, advanced through whichever lever — bill, speech, or executive order — clears resistance fastest.