The COICA is a proposed law that gives the US Government the ability to block websites that are deemed to infringe on copyrighted works.
One of the primary roles of an auditor is to stay on top of new laws, regulations, and industry compliance requirements that could impact a business. In September, The Combating Online Infringement and Counterfeits Act (COICA) was put forth for consideration to provide the government the power to block access to websites that were deemed to promote piracy, intellectual property theft, and counterfeit goods. ISPs would be forced to block sites like The Pirate Bay and Demonoid placing the Attorney General and US Courts and in a position to determine the intent of a specific website and whether or not US citizens are allowed access to it. If You Tube has copyrighted material submitted by users it could be blocked based on this law. This alarms me on a number of levels. First we have seen the Department of Homeland Securities attempts at preventing access to air transportation for people that, as Bruce Schnier put it best ” are too dangerous to let fly, but not dangerous enough to arrest”. Grandmas and children have been placed on the infamous “no-fly list” requiring herculean amounts of effort and ancient Tibetan rituals to be removed. If this is an indication of how the government would handle a “no access” list of websites, I have a feeling we are in for rough times as technologists attempting to conduct business on the Internet and security researchers trying to disclose potential vulnerabilities. The Court system could become the ultimate form of Denial of Service!
The concept of a “blacklist” is nothing new. Security conscious companies have been restricting access to unallocated or reserved internet address space and frequently abused network addresses for years using access control lists (Bogon lists) on routers. This in conjunction with URL filtering at the gateway provides a reasonable mechanism for enforcing policy and compliance within an organization. At Cisco these functions are further enhanced with Reputation based filtering that tracks constantly changing web addresses that are know to be malicious or hosting malware as a mechanism to address the whack-a-mole nature of these “bad sites”. The reputation as a filtering mechanism has been integrated into Cisco’s IPS, ASA, and the Ironport Web Security Appliance. The intent of these products are as a means for corporations to enforce acceptable use policies for users which would allow businesses to be in compliance with a law like this. The tracking of these bad websites is accomplished through thousands of reporting network devices throughout the globe. In order to indentify these “infringing sites” does the Government go into the Internet surveillance and monitoring business or spend enormous amounts of money letting the courts add and remove sites on these block lists? Doesn’t sound like good use of taxpayer money to me.
If the government does go down this path, it would be an enormous burden placed on the service provider and create an Internet police that no one really wants. Who would be responsible for identifying malicious websites? The DHS? What recourse would a company have if their site or service was placed on this list or served a cease and desist? Internet time is measured in milliseconds; court time is measured in months or years. The time lag alone could kill a business. Luckily this bill has not been enacted into law allowing us time to inform our representatives of our thoughts regarding the impact these measures could have. For more information on this proposed law and access to a petition you can sign to stop this bill can be located at the following link:
https://demandprogress.org/blacklist/
What do you think? Is it the government’s job to filter our Internet access and police websites?




