Showing posts with label nsa. Show all posts
Showing posts with label nsa. Show all posts
Sunday, October 6, 2013
#NSA & #GCHQ Target #Tor Anonymity Network
Wednesday, September 25, 2013
#NSA accused of hacking into India's nuclear systems
from thehindu.com: The public assertions made by Indian and American officials that no content was taken from India’s internet and telephone networks by U.S.’s National Security Agency (NSA) and that the American surveillance programs just looked at “patterns of communication” as a counter-terrorism measure are far from the truth, if not outright misleading.
According to a top secret document disclosed by NSA whistleblower Edward Snowden and obtained by The Hindu, the PRISM programme was deployed by the American agency to gather key information from India by tapping directly into the servers of tech giants which provide services such as email, video sharing, voice-over-IPs, online chats, file transfer and social networking services.
And, according to the PRISM document seen by The Hindu, much of the communication targeted by the NSA is unrelated to terrorism, contrary to claims of Indian and American officials.
Instead, much of the surveillance was focused on India’s domestic politics and the country’s strategic and commercial interests.
This is the first time it’s being revealed that PRISM, which facilitates extensive, in-depth surveillance on live communications as well as stored information, was used by the world’s largest surveillance organization to intercept and pick content on at least three issues related to India’s geopolitical and economic interests. They are: Nuclear, Space and Politics.
The top-secret NSA document, which carries the seal of “Special Source Operations”, is called “A Week in the Life of PRISM reporting” and it shows “Sampling of Reporting topics from 2-8 Feb 2013”. Marked with a green slug that reads “589 End product Reports’’, the document carries the brand logos of companies like Gmail, Facebook, MSN, Hotmail, Yahoo!, Google, Apple, Skype, YouTube, paltalk.com and AOL on the top of the page.
“End products” are official reports that are distillations of the best raw intelligence.
In a section titled “India”, the document clearly mentions numerous subjects about which content was picked from various service providers on the worldwide web in just one week early this year.
This document is strong evidence of the fact that NSA surveillance in India was not restricted to tracking of phone calls, text messages and email logs by Boundless Informant, an NSA tool that was deployed quite aggressively against India. “As politics, space and nuclear are mentioned as “end products” in this document, it means that emails, texts and phones of important people related to these fields were constantly monitored and intelligence was taken from them, and then the NSA prepared official reports on the basis of raw intelligence. It means, they are listening in real time to what our political leaders, bureaucrats and scientists are communicating with each other,” an official with an India intelligence agency told The Hindu, speaking strictly on condition of anonymity.
But, top ministers and officials have continued to live in denial.
After it was reported by The Guardian on June 7 that the PRISM program allowed the NSA “to obtain targeted communications without having to request them from the service providers and without having to obtain individual court orders”, both U.S. and Indian officials claimed that no content was being taken from the country’s networks and that the programs were intended to “counter terrorism”.
Kerry’s dissembling
During his visit to New Delhi on June 24 to take part in the India-U.S. Strategic Dialogue, U.S. Secretary of State John Kerry denied that the American agency programmes were accessing online content. “It does not look at individual emails. It does not listen to people’s telephone conversation. It is a random survey by computers of anybody’s telephone, of just the numbers and not even the names…It takes those random numbers and looks whether those random numbers are connected to other numbers, that they know, by virtue of other intelligence, linked to terrorists in places where those terrorists operate,” Mr. Kerry had said, stressing that only when an “adequate linkage” is formed, the authorities go to a special court to get permission to obtain further data.
Even Indian officials have been repeating these lines since the NSA activities in India were disclosed. Replying to a question in Rajya Sabha on August 26, Communications and Information Technology Minister Kapil Sibal said the U.S. agencies only “trace origin and destination of the data, but never try to get access to the content, which requires a court approval”. “It would be a matter of concern for government if intrusive data capture has been deployed against Indian citizens or government infrastructure. Government has clearly conveyed these concerns to the U.S. government,” the minister had said, adding that the violation of any Indian law relating to privacy of information of ordinary Indian citizens by surveillance programs was “unacceptable”.
This “unacceptable” line might have been crossed by the NSA millions of times through the PRISM program as, according to the documents disclosed by Mr. Snowden, it is able to reach directly into the servers of the tech companies that are part of the programme and obtain data as well as perform real-time collection on targeted users. “The National Security Agency has obtained direct access to the systems of Google, Facebook, Apple and other U.S. internet giants,” The Guardian had said in its June 7 report, quoting from a 41-slide PowerPoint presentation which was apparently used to train intelligence operatives on the capabilities of the program.
Foreigners are fair game
Tech firms have denied that they allow unfettered access to the NSA. In strongly worded denials of participation in any government surveillance program, they have claimed they allow access to any data to the agency only when required by law.
Here lies the catch. Contrary to denials by tech firms and claims by India’s communication minister that the U.S. agency “requires a court approval” to look into any online content, the NSA used the changes in U.S. surveillance law that allows for the targeting of any customers of participating firms “who live outside the US, or those Americans whose communications include people outside the US”. This law, known as FISA Amendment Act or FAA, was introduced by President George W Bush and renewed under President Barack Obama in December 2012, allows for electronic surveillance on anyone who is “reasonably believed” to be outside the U.S.
No Indian citizen, government department or organisation has any legal protection from NSA surveillance. In a Joint Statement from the Office of the Director of National Intelligence and the National Security Agency on August 21, 2013, it was stated that “FISA is designed to allow the U.S. Government to acquire foreign intelligence while protecting the civil liberties and privacy of Americans.”
So the NSA had no obstacle — technical or legal — in deploying the PRISM tool against India and Indian citizens. Armed with the FAA and with the active cooperation of the world’s biggest internet brands, the NSA was able to tap specific intelligence from India about the issues which have huge implications for its strategic interests in India. While India’s “nuclear” and “space” programmes have clearly significant commercial value for American firms, the surveillance of “politics” has huge implications for its foreign policy objectives in the region.
“If Americans are listening to our politicians and tapping the phones or reading mails of individuals who handle nuclear and space programmes, they have huge advantage over us in all business and diplomatic negotiations. Even before we go to the table, they know what we are going to put on it. It’s not just violation of our sovereignty, it’s a complete intrusion into our decision-making process,” said a senior official of the Ministry of Home Affairs, who admitted in private that the reports about the scale of NSA surveillance have “rattled” the government.
The NSA document also has names of several Asian, African and Latin American countries from where the American agency picked data about subjects ranging from oil to WTO to government policies, making it clear that the NSA spying was focused on commercial and business areas, and not on its stated objective of national security. “If the American intelligence agencies and business corporations are hunting in pairs, we are bound to lose,” added the Indian official.
More than anything, the targeting of India’s politics and space programme by the NSA busts the myth of close strategic partnership between India and US. The document seen by The Hindu is populated with the countries that are generally seen as adversarial by America. When the PRISM program was disclosed first time in June, a U.S. official had said that information “collected under this program is among the most important and valuable intelligence information we collect, and is used to protect our nation from a wide variety of threats.”
Labels:
boundless informant,
india,
nsa,
nuclear,
prism
Wednesday, September 18, 2013
Brazil’s President Cancels White House Visit Over NSA Spying
'Unhappy' With Administration's Response to Surveillance
from antiwar.com: NSA surveillance is a big deal in a lot of countries, but few more than Brazil, where media outlets have covered the spying intensively, and detailed US surveillance of government leaders as well as espionage against major Brazilian companies.The diplomatic fallout for the US was already significant, but is getting worse, as Brazil has announced that they are cancelling a planned state visit by President Dilma Rousseff to the White House.
Brazilian officials say that the move was the response to their annoyance with the Obama Administration’s responses to their complaints about the NSA. The administration says the move was simply meant to “avoid controversy.”
Rousseff’s office has been intensely critical of the NSA surveillance, dubbing it a violation of national sovereignty, and had previously warned the US that the visit could be shelved if they didn’t provide suitable explanations for the NSA’s misdeeds. Needless to say, they didn’t.
Tuesday, September 17, 2013
U.S. Telcos Have Never Challenged #NSA Demands for Your Metadata
from wired.com: Since at least 2006 a secret spy court has continuously compelled the nation’s carriers to hand over records of every telephone call made to, from, or within the United States.
But none of the phone companies have ever challenged the orders in court, according to an August 29 opinion (.pdf) by the Foreign Intelligence Surveillance Court, which was declassified today.
“To this date, no holder of records who has received an Order to produce bulk telephony metadata has challenged the legality of such an Order,” reads the ruling. “Indeed, no recipient of any Section 215 Order has challenged the legality of such an Order, despite the explicit statutory mechanism for doing so.”
The FISC orders cited Section 215 of the Patriot Act to require phone companies like Verizon and AT&T to hand over the phone numbers of both parties involved in all calls, the international mobile subscriber identity (IMSI) number for mobile callers, calling card numbers used in the call, and the time and duration of the calls.
To be sure, any challenge to the surveillance program would have been done before the court in secret, and it’s unlikely one would have been successful.
That carriers willfully provided the metadata without blinking a legal eye, however, is cause for alarm, as the telcos appear to be the only ones so far with legal standing to make a challenge to the bulk collection orders. The Electronic Frontier Foundation, American Civil Liberties and others have brought challenges, but the legal fight on whether they have the right to sue remains undecided.
The bulk collection program came to public light in June, when the Guardian published a FISC order on the topic leaked to the media outlet by NSA whistleblower Edward Snowden.
The court declassified (.pdf) an opinion today in the wake of Snowden’s leaks.
“This Court is mindful that this matter comes before it at a time when unprecedented disclosures have been made about this and other highly-sensitive programs designed to obtain foreign intelligence information and carry out counterterrorism investigations. According to NSA Director Gen. Keith Alexander, the disclosures have caused ‘significant and irreversible damage to our nation,’” according to the opinion.
The metadata surveillance became lawful with a 2006 update to the Patriot Act. But it’s been reported that most major carriers were providing the NSA with bulk metadata voluntarily before then in the wake of the 2001 terror attacks.
So the Electronic Frontier Foundation sued the nation’s carriers. After a San Francisco federal judge refused to toss the lawsuit, Congress in 2008 passed legislation immunizing the telcos from ever being sued for forwarding customer data to the NSA.
“It’s disappointing that the telecoms did not stand up for their users,” Kurt Ospahl, an EFF staff attorney, said in a telephone interview.
The opinion declassified today spells out the court’s interpretation of why it is legal under the Patriot Act that all calling records can be forwarded to the NSA. It also notes that there is no adversarial process, meaning without a third-party challenger, the court relies solely on the government’s assertions. Every 90 days the court orders carriers to forward all calling metadata on a rolling basis.
“To ensure adherence to its Orders, this Court has the authority to oversee compliance … and requires the government to notify the Court in writing immediately concerning any instance of non-compliance. According to the government, in the prior authorization period there have been no compliance incidents,” the court wrote.
The telcos we contacted for this story did not return calls for comment or were not immediately prepared to comment.
A day after the Guardian‘s story, however, Verizon declined to acknowledge the program but also said it was just following orders.
“Verizon continually takes steps to safeguard its customers’ privacy. Nevertheless, the law authorizes the federal courts to order a company to provide information in certain circumstances, and if Verizon were to receive such an order, we would be required to comply,” Randy Milch, Verizon’s general counsel, said in a letter to employees.
On the other hand, tech companies have been pushing for transparency. They are demanding the NSA allow them to be more transparent about what type of customer data they are secretly required to share with the NSA.
But none of the phone companies have ever challenged the orders in court, according to an August 29 opinion (.pdf) by the Foreign Intelligence Surveillance Court, which was declassified today.
“To this date, no holder of records who has received an Order to produce bulk telephony metadata has challenged the legality of such an Order,” reads the ruling. “Indeed, no recipient of any Section 215 Order has challenged the legality of such an Order, despite the explicit statutory mechanism for doing so.”
The FISC orders cited Section 215 of the Patriot Act to require phone companies like Verizon and AT&T to hand over the phone numbers of both parties involved in all calls, the international mobile subscriber identity (IMSI) number for mobile callers, calling card numbers used in the call, and the time and duration of the calls.
To be sure, any challenge to the surveillance program would have been done before the court in secret, and it’s unlikely one would have been successful.
That carriers willfully provided the metadata without blinking a legal eye, however, is cause for alarm, as the telcos appear to be the only ones so far with legal standing to make a challenge to the bulk collection orders. The Electronic Frontier Foundation, American Civil Liberties and others have brought challenges, but the legal fight on whether they have the right to sue remains undecided.
The bulk collection program came to public light in June, when the Guardian published a FISC order on the topic leaked to the media outlet by NSA whistleblower Edward Snowden.
The court declassified (.pdf) an opinion today in the wake of Snowden’s leaks.
“This Court is mindful that this matter comes before it at a time when unprecedented disclosures have been made about this and other highly-sensitive programs designed to obtain foreign intelligence information and carry out counterterrorism investigations. According to NSA Director Gen. Keith Alexander, the disclosures have caused ‘significant and irreversible damage to our nation,’” according to the opinion.
The metadata surveillance became lawful with a 2006 update to the Patriot Act. But it’s been reported that most major carriers were providing the NSA with bulk metadata voluntarily before then in the wake of the 2001 terror attacks.
So the Electronic Frontier Foundation sued the nation’s carriers. After a San Francisco federal judge refused to toss the lawsuit, Congress in 2008 passed legislation immunizing the telcos from ever being sued for forwarding customer data to the NSA.
“It’s disappointing that the telecoms did not stand up for their users,” Kurt Ospahl, an EFF staff attorney, said in a telephone interview.
The opinion declassified today spells out the court’s interpretation of why it is legal under the Patriot Act that all calling records can be forwarded to the NSA. It also notes that there is no adversarial process, meaning without a third-party challenger, the court relies solely on the government’s assertions. Every 90 days the court orders carriers to forward all calling metadata on a rolling basis.
“To ensure adherence to its Orders, this Court has the authority to oversee compliance … and requires the government to notify the Court in writing immediately concerning any instance of non-compliance. According to the government, in the prior authorization period there have been no compliance incidents,” the court wrote.
The telcos we contacted for this story did not return calls for comment or were not immediately prepared to comment.
A day after the Guardian‘s story, however, Verizon declined to acknowledge the program but also said it was just following orders.
“Verizon continually takes steps to safeguard its customers’ privacy. Nevertheless, the law authorizes the federal courts to order a company to provide information in certain circumstances, and if Verizon were to receive such an order, we would be required to comply,” Randy Milch, Verizon’s general counsel, said in a letter to employees.
On the other hand, tech companies have been pushing for transparency. They are demanding the NSA allow them to be more transparent about what type of customer data they are secretly required to share with the NSA.
Sunday, September 15, 2013
New #Snowden Leak Reveals Secret $52.6 Billion Budget for Intelligence Agencies
from IntelliHub.com: A new leak from Edward Snowden shows a massive budget for the military spy industrial complex that is hidden from the public.
The original leaks made my Edward Snowden were enough to totally change the whole collective dialogue about government spying, but those initial leaks were merely the tip of the iceberg. There are countless other pieces of damning evidence that are slowly being leaked out over time. Some of the most recent leaks are extremely interesting, showing a secret budget of almost $53 billion dollars that went to various intelligence agencies.[1]
Here are some of the details of intelligence spending revealed in the report:
“The United States has made a considerable investment in the Intelligence Community since the terror attacks of 9/11, a time which includes wars in Iraq and Afghanistan, the Arab Spring, the proliferation of weapons of mass destruction technology, and asymmetric threats in such areas as cyber-warfare,” Director of National Intelligence James R. Clapper Jr. wrote in response to inquiries from The Post.
“Our budgets are classified as they could provide insight for foreign intelligence services to discern our top national priorities, capabilities and sources and methods that allow us to obtain information to counter threats,” he said.[3]
Sources:
[1] Unprecedented ‘black budget’ leak reveals the scope of $52 billion US spy complex – The Verge
[2] Snowden leaks intelligence ‘black budget’ to Washington Post – Aljazeera
[3] U.S. spy network’s successes, failures and objectives detailed in ‘black budget’ summary – Washington Post
The original leaks made my Edward Snowden were enough to totally change the whole collective dialogue about government spying, but those initial leaks were merely the tip of the iceberg. There are countless other pieces of damning evidence that are slowly being leaked out over time. Some of the most recent leaks are extremely interesting, showing a secret budget of almost $53 billion dollars that went to various intelligence agencies.[1]
Here are some of the details of intelligence spending revealed in the report:
- $11.5 billion of the proposed CIA budget — which overall, was up 56 percent since 2004 — was allocated to “data collection expenses” alone.
- Of the NSA’s $10.8 billion budget, $5.2 billion were marked for “management, facilities and support.”
- Of the National Reconaissance Office’s $10.3 billion, $6 billion were allocated to data collection.
- The requested budget for the National Geospatial Intelligence Program, which supplies “imagery and map-based intelligence” was up 108 percent since 2004.
- $4.4 billion went to the General Defense Intelligence Program, which assesses foreign military activity for policymakers and U.S. military chiefs.[2]
“The United States has made a considerable investment in the Intelligence Community since the terror attacks of 9/11, a time which includes wars in Iraq and Afghanistan, the Arab Spring, the proliferation of weapons of mass destruction technology, and asymmetric threats in such areas as cyber-warfare,” Director of National Intelligence James R. Clapper Jr. wrote in response to inquiries from The Post.
“Our budgets are classified as they could provide insight for foreign intelligence services to discern our top national priorities, capabilities and sources and methods that allow us to obtain information to counter threats,” he said.[3]
Sources:
[1] Unprecedented ‘black budget’ leak reveals the scope of $52 billion US spy complex – The Verge
[2] Snowden leaks intelligence ‘black budget’ to Washington Post – Aljazeera
[3] U.S. spy network’s successes, failures and objectives detailed in ‘black budget’ summary – Washington Post
Wednesday, September 11, 2013
#NSA 'routinely' shares Americans' data with #Israel
from RT.com: The NSA regularly shares raw US intelligence data with Israel without even removing information about American citizens, according to the latest revelation published by the Guardian. The report is based on a document leaked by Edward Snowden.
On Tuesday, September 11, the Guardian published a previously undisclosed document which revealed top-secret policies in place since 2009 that are used to share personal phone and Internet data pertaining to United States citizens with American ally Israel.
The document, a five-page memorandum authorized by the National Security Agency near the beginning of US President Barack Obama’s first administration, outlines a deal between the NSA and Israel’s SIGINT National Unit, or ISNU.
“This agreement,” the memo begins, “prescribes procedures and responsibilities for ensuring” privacy safeguards are implemented to protect the Fourth Amendment rights of US citizens with regards to the direct sharing of raw intelligence collected by the NSA with its Israeli counterpart.
That data, the document later explains, includes raw traffic picked up by the American spy office such as “unevaluated and unminimized transcripts, gists, facsimiles, telex, voice and Digital Network Intelligence (DNI) metadata and content” which is never necessarily scrutinized by US officials before sent to Israeli agents.
Related:
Israel's secret intel unit spawns high-tech tycoons
But while the contents of emails and phone calls involving most US persons are fair game to be collected by Israeli intelligence, a select group of Americans are sparred from international surveillance: elected officials. The memo mandates that the Israelis must "destroy upon recognition" any communication "that is either to or from an official of the US government.” That pool of exempt persons is defined as "officials of the executive branch (including the White House, cabinet departments, and independent agencies), the US House of Representatives and Senate (member and staff) and the US federal court system (including, but not limited to, the Supreme Court)."
The Guardian notes, however, that other leaked documents uncovered as of late indicate that the US intelligence community may have reservations nonetheless with sharing info with even an ally as tried and true as Israel.
"On the one hand, the Israelis are extraordinarily good Sigint partners for us, but on the other, they target us to learn our positions on Middle East problems," a senior NSA official says in a 2008 NSA document seen by the Guardian but not published in Wednesday’s piece. "A NIE [National Intelligence Estimate] ranked them as the third most aggressive intelligence service against the US."
"One of NSA's biggest threats is actually from friendly intelligence services, like Israel. There are parameters on what NSA shares with them, but the exchange is so robust, we sometimes share more than we intended,” the Guardian quotes from the ’08 document.
According to Guardian journalists Glenn Greenwald, Laura Poitras and Ewen MacAskill, a NSA spokesperson pressed for comment wouldn’t deny the validity of the leaked document’s contents, but assured the British newspaper that "Any US person information that is acquired as a result of NSA's surveillance activities is handled under procedures that are designed to protect privacy rights.”
The latest leak comes on the 12-year anniversary of the September 11, 2001 terrorist attacks that many high-ranking US officials have used to justify the surveillance measures enacted in the decade-plus since. It also marks just more than three months since the Guardian first began published leaked NSA documents attributed to Snowden, a 30-year-old former intelligence contractor who has since relocated to Russia where he was granted asylum while avoiding espionage charges in the US.
On Tuesday, September 11, the Guardian published a previously undisclosed document which revealed top-secret policies in place since 2009 that are used to share personal phone and Internet data pertaining to United States citizens with American ally Israel.
The document, a five-page memorandum authorized by the National Security Agency near the beginning of US President Barack Obama’s first administration, outlines a deal between the NSA and Israel’s SIGINT National Unit, or ISNU.
“This agreement,” the memo begins, “prescribes procedures and responsibilities for ensuring” privacy safeguards are implemented to protect the Fourth Amendment rights of US citizens with regards to the direct sharing of raw intelligence collected by the NSA with its Israeli counterpart.
That data, the document later explains, includes raw traffic picked up by the American spy office such as “unevaluated and unminimized transcripts, gists, facsimiles, telex, voice and Digital Network Intelligence (DNI) metadata and content” which is never necessarily scrutinized by US officials before sent to Israeli agents.
Related:
Israel's secret intel unit spawns high-tech tycoons
But while the contents of emails and phone calls involving most US persons are fair game to be collected by Israeli intelligence, a select group of Americans are sparred from international surveillance: elected officials. The memo mandates that the Israelis must "destroy upon recognition" any communication "that is either to or from an official of the US government.” That pool of exempt persons is defined as "officials of the executive branch (including the White House, cabinet departments, and independent agencies), the US House of Representatives and Senate (member and staff) and the US federal court system (including, but not limited to, the Supreme Court)."
The Guardian notes, however, that other leaked documents uncovered as of late indicate that the US intelligence community may have reservations nonetheless with sharing info with even an ally as tried and true as Israel.
"On the one hand, the Israelis are extraordinarily good Sigint partners for us, but on the other, they target us to learn our positions on Middle East problems," a senior NSA official says in a 2008 NSA document seen by the Guardian but not published in Wednesday’s piece. "A NIE [National Intelligence Estimate] ranked them as the third most aggressive intelligence service against the US."
"One of NSA's biggest threats is actually from friendly intelligence services, like Israel. There are parameters on what NSA shares with them, but the exchange is so robust, we sometimes share more than we intended,” the Guardian quotes from the ’08 document.
According to Guardian journalists Glenn Greenwald, Laura Poitras and Ewen MacAskill, a NSA spokesperson pressed for comment wouldn’t deny the validity of the leaked document’s contents, but assured the British newspaper that "Any US person information that is acquired as a result of NSA's surveillance activities is handled under procedures that are designed to protect privacy rights.”
The latest leak comes on the 12-year anniversary of the September 11, 2001 terrorist attacks that many high-ranking US officials have used to justify the surveillance measures enacted in the decade-plus since. It also marks just more than three months since the Guardian first began published leaked NSA documents attributed to Snowden, a 30-year-old former intelligence contractor who has since relocated to Russia where he was granted asylum while avoiding espionage charges in the US.
Labels:
counter-intelligence,
data sharing,
israel,
metadata,
mossad,
nsa,
snowden
Tuesday, September 10, 2013
Declassified files detail blatant violations, abuse of #NSA domestic spying program
from RT.com: For years the National Security Agency has been violating restrictions and misusing the US domestic spying program that collected private data from US citizens, newly released declassified documents show.
The new information from Intelligence Community Documents Regarding Collection under Section 501 of the Foreign Intelligence Surveillance Act (FISA) shows that the government on a daily basis spied on Americans’ telephone numbers, calling patterns as well as users IP addresses during the surveillance of foreign terror suspects.
The information shows that between 2006 and 2009 the NSA violated the court restrictions by spying on telephone calls and lying to judges about how the data was deployed. The spying agency crossed referenced a selected list of some 16,000 phone numbers against databases which contained millions of records, thus violating the law, two senior intelligence officials told Bloomberg.
The metadata program which started in 2006 enabled the NSA to gather more information about a specific number that the agency claimed could be linked to terrorist activity. The agency also kept an alert list that was cross-referenced with new numbers to consider whether they should be added to a list of "reasonable articulable suspicion."
The NSA gathered the bulk phone records under Section 215 of the USA Patriot Act, which requires private companies to turn over evidence that is relevant to a terrorism investigation. However, the Foreign Intelligence Surveillance Court ruled that the NSA must have “reasonable, articulable suspicion” to run that number against a larger database. Only about 2,000 numbers on the list in 2009 met that legal condition, according to sources.
The released documents according to Director of National Intelligence James Clapper relate to “compliance incidents that were discovered by the NSA, reported to the FISC and the Congress, and resolved four years ago.”
The documents were released as part of a lawsuit filed by the Electronic Frontier Foundation and under growing pressure for the administration to shed light on its surveillance activities following Edward Snowden’s leaks.
The new information from Intelligence Community Documents Regarding Collection under Section 501 of the Foreign Intelligence Surveillance Act (FISA) shows that the government on a daily basis spied on Americans’ telephone numbers, calling patterns as well as users IP addresses during the surveillance of foreign terror suspects.
The information shows that between 2006 and 2009 the NSA violated the court restrictions by spying on telephone calls and lying to judges about how the data was deployed. The spying agency crossed referenced a selected list of some 16,000 phone numbers against databases which contained millions of records, thus violating the law, two senior intelligence officials told Bloomberg.
The metadata program which started in 2006 enabled the NSA to gather more information about a specific number that the agency claimed could be linked to terrorist activity. The agency also kept an alert list that was cross-referenced with new numbers to consider whether they should be added to a list of "reasonable articulable suspicion."
The NSA gathered the bulk phone records under Section 215 of the USA Patriot Act, which requires private companies to turn over evidence that is relevant to a terrorism investigation. However, the Foreign Intelligence Surveillance Court ruled that the NSA must have “reasonable, articulable suspicion” to run that number against a larger database. Only about 2,000 numbers on the list in 2009 met that legal condition, according to sources.
The released documents according to Director of National Intelligence James Clapper relate to “compliance incidents that were discovered by the NSA, reported to the FISC and the Congress, and resolved four years ago.”
The documents were released as part of a lawsuit filed by the Electronic Frontier Foundation and under growing pressure for the administration to shed light on its surveillance activities following Edward Snowden’s leaks.
Thursday, September 5, 2013
US and UK spy agencies defeat privacy and security on the internet
from guardian.co.uk: US and British intelligence agencies have successfully cracked much of the online encryption relied upon by hundreds of millions of people to protect the privacy of their personal data, online transactions and emails, according to top-secret documents revealed by former contractor Edward Snowden.
The files show that the National Security Agency and its UK counterpart GCHQ have broadly compromised the guarantees that internet companies have given consumers to reassure them that their communications, online banking and medical records would be indecipherable to criminals or governments.
The agencies, the documents reveal, have adopted a battery of methods in their systematic and ongoing assault on what they see as one of the biggest threats to their ability to access huge swathes of internet traffic – "the use of ubiquitous encryption across the internet".
Those methods include covert measures to ensure NSA control over setting of international encryption standards, the use of supercomputers to break encryption with "brute force", and – the most closely guarded secret of all – collaboration with technology companies and internet service providers themselves.
Through these covert partnerships, the agencies have inserted secret vulnerabilities – known as backdoors or trapdoors – into commercial encryption software.
The files, from both the NSA and GCHQ, were obtained by the Guardian, and the details are being published today in partnership with the New York Times and ProPublica. They reveal:
• A 10-year NSA program against encryption technologies made a breakthrough in 2010 which made "vast amounts" of data collected through internet cable taps newly "exploitable".
• The NSA spends $250m a year on a program which, among other goals, works with technology companies to "covertly influence" their product designs.
• The secrecy of their capabilities against encryption is closely guarded, with analysts warned: "Do not ask about or speculate on sources or methods."
• The NSA describes strong decryption programs as the "price of admission for the US to maintain unrestricted access to and use of cyberspace".
• A GCHQ team has been working to develop ways into encrypted traffic on the "big four" service providers, named as Hotmail, Google, Yahoo and Facebook.
The agencies insist that the ability to defeat encryption is vital to their core missions of counter-terrorism and foreign intelligence gathering.
But security experts accused them of attacking the internet itself and the privacy of all users.
"Cryptography forms the basis for trust online," said Bruce Schneier, an encryption specialist and fellow at Harvard's Berkman Center for Internet and Society. "By deliberately undermining online security in a short-sighted effort to eavesdrop, the NSA is undermining the very fabric of the internet." Classified briefings between the agencies celebrate their success at "defeating network security and privacy".
"For the past decade, NSA has lead [sic] an aggressive, multi-pronged effort to break widely used internet encryption technologies," stated a 2010 GCHQ document. "Vast amounts of encrypted internet data which have up till now been discarded are now exploitable."
An internal agency memo noted that among British analysts shown a presentation on the NSA's progress: "Those not already briefed were gobsmacked!"
The breakthrough, which was not described in detail in the documents, meant the intelligence agencies were able to monitor "large amounts" of data flowing through the world's fibre-optic cables and break its encryption, despite assurances from internet company executives that this data was beyond the reach of government.
The key component of the NSA's battle against encryption, its collaboration with technology companies, is detailed in the US intelligence community's top-secret 2013 budget request under the heading "Sigint [signals intelligence] enabling".
Funding for the program – $254.9m for this year – dwarfs that of the Prism program, which operates at a cost of $20m a year, according to previous NSA documents. Since 2011, the total spending on Sigint enabling has topped $800m. The program "actively engages US and foreign IT industries to covertly influence and/or overtly leverage their commercial products' designs", the document states. None of the companies involved in such partnerships are named; these details are guarded by still higher levels of classification.
Among other things, the program is designed to "insert vulnerabilities into commercial encryption systems". These would be known to the NSA, but to no one else, including ordinary customers, who are tellingly referred to in the document as "adversaries".
"These design changes make the systems in question exploitable through Sigint collection … with foreknowledge of the modification. To the consumer and other adversaries, however, the systems' security remains intact."
The document sets out in clear terms the program's broad aims, including making commercial encryption software "more tractable" to NSA attacks by "shaping" the worldwide marketplace and continuing efforts to break into the encryption used by the next generation of 4G phones.
Among the specific accomplishments for 2013, the NSA expects the program to obtain access to "data flowing through a hub for a major communications provider" and to a "major internet peer-to-peer voice and text communications system".
Technology companies maintain that they work with the intelligence agencies only when legally compelled to do so. The Guardian has previously reported that Microsoft co-operated with the NSA to circumvent encryption on the Outlook.com email and chat services. The company insisted that it was obliged to comply with "existing or future lawful demands" when designing its products.
The documents show that the agency has already achieved another of the goals laid out in the budget request: to influence the international standards upon which encryption systems rely.
Independent security experts have long suspected that the NSA has been introducing weaknesses into security standards, a fact confirmed for the first time by another secret document. It shows the agency worked covertly to get its own version of a draft security standard issued by the US National Institute of Standards and Technology approved for worldwide use in 2006.
"Eventually, NSA became the sole editor," the document states.
The NSA's codeword for its decryption program, Bullrun, is taken from a major battle of the American civil war. Its British counterpart, Edgehill, is named after the first major engagement of the English civil war, more than 200 years earlier.
A classification guide for NSA employees and contractors on Bullrun outlines in broad terms its goals.
"Project Bullrun deals with NSA's abilities to defeat the encryption used in specific network communication technologies. Bullrun involves multiple sources, all of which are extremely sensitive." The document reveals that the agency has capabilities against widely used online protocols, such as HTTPS, voice-over-IP and Secure Sockets Layer (SSL), used to protect online shopping and banking.
The document also shows that the NSA's Commercial Solutions Center, ostensibly the body through which technology companies can have their security products assessed and presented to prospective government buyers, has another, more clandestine role.
It is used by the NSA to "to leverage sensitive, co-operative relationships with specific industry partners" to insert vulnerabilities into security products. Operatives were warned that this information must be kept top secret "at a minimum".
A more general NSA classification guide reveals more detail on the agency's deep partnerships with industry, and its ability to modify products. It cautions analysts that two facts must remain top secret: that NSA makes modifications to commercial encryption software and devices "to make them exploitable", and that NSA "obtains cryptographic details of commercial cryptographic information security systems through industry relationships".
The agencies have not yet cracked all encryption technologies, however, the documents suggest. Snowden appeared to confirm this during a live Q&A with Guardian readers in June. "Encryption works. Properly implemented strong crypto systems are one of the few things that you can rely on," he said before warning that NSA can frequently find ways around it as a result of weak security on the computers at either end of the communication.
The documents are scattered with warnings over the importance of maintaining absolute secrecy around decryption capabilities.
Strict guidelines were laid down at the GCHQ complex in Cheltenham, Gloucestershire, on how to discuss projects relating to decryption. Analysts were instructed: "Do not ask about or speculate on sources or methods underpinning Bullrun." This informaton was so closely guarded, according to one document, that even those with access to aspects of the program were warned: "There will be no 'need to know'."
The agencies were supposed to be "selective in which contractors are given exposure to this information", but it was ultimately seen by Snowden, one of 850,000 people in the US with top-secret clearance. A 2009 GCHQ document spells out the significant potential consequences of any leaks, including "damage to industry relationships".
"Loss of confidence in our ability to adhere to confidentiality agreements would lead to loss of access to proprietary information that can save time when developing new capability," intelligence workers were told. Somewhat less important to GCHQ was the public's trust which was marked as a moderate risk, the document stated.
"Some exploitable products are used by the general public; some exploitable weaknesses are well known eg possibility of recovering poorly chosen passwords," it said. "Knowledge that GCHQ exploits these products and the scale of our capability would raise public awareness generating unwelcome publicity for us and our political masters."
The decryption effort is particularly important to GCHQ. Its strategic advantage from its Tempora program – direct taps on transatlantic fibre-optic cables of major telecommunications corporations – was in danger of eroding as more and more big internet companies encrypted their traffic, responding to customer demands for guaranteed privacy.
Without attention, the 2010 GCHQ document warned, the UK's "Sigint utility will degrade as information flows changes, new applications are developed (and deployed) at pace and widespread encryption becomes more commonplace." Documents show that Edgehill's initial aim was to decode the encrypted traffic certified by three major (unnamed) internet companies and 30 types of Virtual Private Network (VPN) – used by businesses to provide secure remote access to their systems. By 2015, GCHQ hoped to have cracked the codes used by 15 major internet companies, and 300 VPNs.
Another program, codenamed Cheesy Name, was aimed at singling out encryption keys, known as 'certificates', that might be vulnerable to being cracked by GCHQ supercomputers.
Analysts on the Edgehill project were working on ways into the networks of major webmail providers as part of the decryption project. A quarterly update from 2012 notes the project's team "continue to work on understanding" the big four communication providers, named in the document as Hotmail, Google, Yahoo and Facebook, adding "work has predominantly been focused this quarter on Google due to new access opportunities being developed".
To help secure an insider advantage, GCHQ also established a Humint Operations Team (HOT). Humint, short for "human intelligence" refers to information gleaned directly from sources or undercover agents.
This GCHQ team was, according to an internal document, "responsible for identifying, recruiting and running covert agents in the global telecommunications industry."
"This enables GCHQ to tackle some of its most challenging targets," the report said. The efforts made by the NSA and GCHQ against encryption technologies may have negative consequences for all internet users, experts warn.
"Backdoors are fundamentally in conflict with good security," said Christopher Soghoian, principal technologist and senior policy analyst at the American Civil Liberties Union. "Backdoors expose all users of a backdoored system, not just intelligence agency targets, to heightened risk of data compromise." This is because the insertion of backdoors in a software product, particularly those that can be used to obtain unencrypted user communications or data, significantly increases the difficulty of designing a secure product."
This was a view echoed in a recent paper by Stephanie Pell, a former prosecutor at the US Department of Justice and non-resident fellow at the Center for Internet and Security at Stanford Law School.
"[An] encrypted communications system with a lawful interception back door is far more likely to result in the catastrophic loss of communications confidentiality than a system that never has access to the unencrypted communications of its users," she states.
Intelligence officials asked the Guardian, New York Times and ProPublica not to publish this article, saying that it might prompt foreign targets to switch to new forms of encryption or communications that would be harder to collect or read.
The three organisations removed some specific facts but decided to publish the story because of the value of a public debate about government actions that weaken the most powerful tools for protecting the privacy of internet users in the US and worldwide.
The files show that the National Security Agency and its UK counterpart GCHQ have broadly compromised the guarantees that internet companies have given consumers to reassure them that their communications, online banking and medical records would be indecipherable to criminals or governments.
The agencies, the documents reveal, have adopted a battery of methods in their systematic and ongoing assault on what they see as one of the biggest threats to their ability to access huge swathes of internet traffic – "the use of ubiquitous encryption across the internet".
Those methods include covert measures to ensure NSA control over setting of international encryption standards, the use of supercomputers to break encryption with "brute force", and – the most closely guarded secret of all – collaboration with technology companies and internet service providers themselves.
Through these covert partnerships, the agencies have inserted secret vulnerabilities – known as backdoors or trapdoors – into commercial encryption software.
The files, from both the NSA and GCHQ, were obtained by the Guardian, and the details are being published today in partnership with the New York Times and ProPublica. They reveal:
• A 10-year NSA program against encryption technologies made a breakthrough in 2010 which made "vast amounts" of data collected through internet cable taps newly "exploitable".
• The NSA spends $250m a year on a program which, among other goals, works with technology companies to "covertly influence" their product designs.
• The secrecy of their capabilities against encryption is closely guarded, with analysts warned: "Do not ask about or speculate on sources or methods."
• The NSA describes strong decryption programs as the "price of admission for the US to maintain unrestricted access to and use of cyberspace".
• A GCHQ team has been working to develop ways into encrypted traffic on the "big four" service providers, named as Hotmail, Google, Yahoo and Facebook.
The agencies insist that the ability to defeat encryption is vital to their core missions of counter-terrorism and foreign intelligence gathering.
But security experts accused them of attacking the internet itself and the privacy of all users.
"Cryptography forms the basis for trust online," said Bruce Schneier, an encryption specialist and fellow at Harvard's Berkman Center for Internet and Society. "By deliberately undermining online security in a short-sighted effort to eavesdrop, the NSA is undermining the very fabric of the internet." Classified briefings between the agencies celebrate their success at "defeating network security and privacy".
"For the past decade, NSA has lead [sic] an aggressive, multi-pronged effort to break widely used internet encryption technologies," stated a 2010 GCHQ document. "Vast amounts of encrypted internet data which have up till now been discarded are now exploitable."
An internal agency memo noted that among British analysts shown a presentation on the NSA's progress: "Those not already briefed were gobsmacked!"
The breakthrough, which was not described in detail in the documents, meant the intelligence agencies were able to monitor "large amounts" of data flowing through the world's fibre-optic cables and break its encryption, despite assurances from internet company executives that this data was beyond the reach of government.
The key component of the NSA's battle against encryption, its collaboration with technology companies, is detailed in the US intelligence community's top-secret 2013 budget request under the heading "Sigint [signals intelligence] enabling".
Classified briefings between the NSA and GCHQ celebrate their success at 'defeating network security and privacy'. Photograph: Guardian
Among other things, the program is designed to "insert vulnerabilities into commercial encryption systems". These would be known to the NSA, but to no one else, including ordinary customers, who are tellingly referred to in the document as "adversaries".
"These design changes make the systems in question exploitable through Sigint collection … with foreknowledge of the modification. To the consumer and other adversaries, however, the systems' security remains intact."
The document sets out in clear terms the program's broad aims, including making commercial encryption software "more tractable" to NSA attacks by "shaping" the worldwide marketplace and continuing efforts to break into the encryption used by the next generation of 4G phones.
Among the specific accomplishments for 2013, the NSA expects the program to obtain access to "data flowing through a hub for a major communications provider" and to a "major internet peer-to-peer voice and text communications system".
Technology companies maintain that they work with the intelligence agencies only when legally compelled to do so. The Guardian has previously reported that Microsoft co-operated with the NSA to circumvent encryption on the Outlook.com email and chat services. The company insisted that it was obliged to comply with "existing or future lawful demands" when designing its products.
The documents show that the agency has already achieved another of the goals laid out in the budget request: to influence the international standards upon which encryption systems rely.
Independent security experts have long suspected that the NSA has been introducing weaknesses into security standards, a fact confirmed for the first time by another secret document. It shows the agency worked covertly to get its own version of a draft security standard issued by the US National Institute of Standards and Technology approved for worldwide use in 2006.
"Eventually, NSA became the sole editor," the document states.
The NSA's codeword for its decryption program, Bullrun, is taken from a major battle of the American civil war. Its British counterpart, Edgehill, is named after the first major engagement of the English civil war, more than 200 years earlier.
A classification guide for NSA employees and contractors on Bullrun outlines in broad terms its goals.
"Project Bullrun deals with NSA's abilities to defeat the encryption used in specific network communication technologies. Bullrun involves multiple sources, all of which are extremely sensitive." The document reveals that the agency has capabilities against widely used online protocols, such as HTTPS, voice-over-IP and Secure Sockets Layer (SSL), used to protect online shopping and banking.
The document also shows that the NSA's Commercial Solutions Center, ostensibly the body through which technology companies can have their security products assessed and presented to prospective government buyers, has another, more clandestine role.
It is used by the NSA to "to leverage sensitive, co-operative relationships with specific industry partners" to insert vulnerabilities into security products. Operatives were warned that this information must be kept top secret "at a minimum".
A more general NSA classification guide reveals more detail on the agency's deep partnerships with industry, and its ability to modify products. It cautions analysts that two facts must remain top secret: that NSA makes modifications to commercial encryption software and devices "to make them exploitable", and that NSA "obtains cryptographic details of commercial cryptographic information security systems through industry relationships".
The agencies have not yet cracked all encryption technologies, however, the documents suggest. Snowden appeared to confirm this during a live Q&A with Guardian readers in June. "Encryption works. Properly implemented strong crypto systems are one of the few things that you can rely on," he said before warning that NSA can frequently find ways around it as a result of weak security on the computers at either end of the communication.
The documents are scattered with warnings over the importance of maintaining absolute secrecy around decryption capabilities.
A slide showing that the secrecy of the agencies' capabilities against encryption is closely guarded. Photograph: Guardian
The agencies were supposed to be "selective in which contractors are given exposure to this information", but it was ultimately seen by Snowden, one of 850,000 people in the US with top-secret clearance. A 2009 GCHQ document spells out the significant potential consequences of any leaks, including "damage to industry relationships".
"Loss of confidence in our ability to adhere to confidentiality agreements would lead to loss of access to proprietary information that can save time when developing new capability," intelligence workers were told. Somewhat less important to GCHQ was the public's trust which was marked as a moderate risk, the document stated.
"Some exploitable products are used by the general public; some exploitable weaknesses are well known eg possibility of recovering poorly chosen passwords," it said. "Knowledge that GCHQ exploits these products and the scale of our capability would raise public awareness generating unwelcome publicity for us and our political masters."
The decryption effort is particularly important to GCHQ. Its strategic advantage from its Tempora program – direct taps on transatlantic fibre-optic cables of major telecommunications corporations – was in danger of eroding as more and more big internet companies encrypted their traffic, responding to customer demands for guaranteed privacy.
Without attention, the 2010 GCHQ document warned, the UK's "Sigint utility will degrade as information flows changes, new applications are developed (and deployed) at pace and widespread encryption becomes more commonplace." Documents show that Edgehill's initial aim was to decode the encrypted traffic certified by three major (unnamed) internet companies and 30 types of Virtual Private Network (VPN) – used by businesses to provide secure remote access to their systems. By 2015, GCHQ hoped to have cracked the codes used by 15 major internet companies, and 300 VPNs.
Another program, codenamed Cheesy Name, was aimed at singling out encryption keys, known as 'certificates', that might be vulnerable to being cracked by GCHQ supercomputers.
Analysts on the Edgehill project were working on ways into the networks of major webmail providers as part of the decryption project. A quarterly update from 2012 notes the project's team "continue to work on understanding" the big four communication providers, named in the document as Hotmail, Google, Yahoo and Facebook, adding "work has predominantly been focused this quarter on Google due to new access opportunities being developed".
To help secure an insider advantage, GCHQ also established a Humint Operations Team (HOT). Humint, short for "human intelligence" refers to information gleaned directly from sources or undercover agents.
This GCHQ team was, according to an internal document, "responsible for identifying, recruiting and running covert agents in the global telecommunications industry."
"This enables GCHQ to tackle some of its most challenging targets," the report said. The efforts made by the NSA and GCHQ against encryption technologies may have negative consequences for all internet users, experts warn.
"Backdoors are fundamentally in conflict with good security," said Christopher Soghoian, principal technologist and senior policy analyst at the American Civil Liberties Union. "Backdoors expose all users of a backdoored system, not just intelligence agency targets, to heightened risk of data compromise." This is because the insertion of backdoors in a software product, particularly those that can be used to obtain unencrypted user communications or data, significantly increases the difficulty of designing a secure product."
This was a view echoed in a recent paper by Stephanie Pell, a former prosecutor at the US Department of Justice and non-resident fellow at the Center for Internet and Security at Stanford Law School.
"[An] encrypted communications system with a lawful interception back door is far more likely to result in the catastrophic loss of communications confidentiality than a system that never has access to the unencrypted communications of its users," she states.
Intelligence officials asked the Guardian, New York Times and ProPublica not to publish this article, saying that it might prompt foreign targets to switch to new forms of encryption or communications that would be harder to collect or read.
The three organisations removed some specific facts but decided to publish the story because of the value of a public debate about government actions that weaken the most powerful tools for protecting the privacy of internet users in the US and worldwide.
Labels:
fibre optics,
gchq,
nsa,
prism,
sigint,
snowden,
spying,
surveillance
Tuesday, August 27, 2013
German email providers 'seen as surveillance safe haven'
from BBC: #NewsFromElsewhere: Web users are turning to German email providers to avoid US state surveillance, it seems.
"The increased interest in German email providers may be linked to a recent push to promote the country's data networks as some of the most secure in the world," reckons Der Spiegel. It says Deutsche Telekom is among those trying to cash in, recently introducing new security measures making sure that email travelling between three of its services never leave local servers. The firm also notifies users when they're about to email someone whose address does not fall under the programme's protections.
Friday, August 23, 2013
Advocate of Secret Infiltration, Cass Sunstein selected for Obama’s NSA Review Committee
from emptywheel.net: ABC reports that, along with former CIA Deputy Director Mike Morell, former Homeland Security Czar Richard Clarke, and former Obama special assistant for economic policy Peter Swire, the White House (or James Clapper — who knows at this point) has picked Cass Sunstein for its Review Committee on NSA programs.
Frankly, a lot of people are investing misplaced confidence that Richard Clarke will make this committee useful. While he’s good on a lot of issues, he’s as hawkish on cybersecurity as anyone else in this country. And as I keep pointing out, these programs are really about cybersecurity. Richard Clarke is not going to do a damned thing to rein in a program that increasingly serves to surveil US Internet data to protect against cyberthreats.
But Sunstein? Really?
As Glenn Greenwald (yeah — that Glenn; did they really think no one would raise this point?) reported back in 2010, Sunstein wrote a paper in 2008 advocating very creepy stealth measures against “conspiracy theories.”
Well, if Obama and Clapper’s rollout hadn’t already discredited this committee, Sunstein’s selection sure does.
Update: Adding some quotes from Sunstein’s paper.
The importance of undermining conspiracy theories is especially important with terrorism.
Frankly, a lot of people are investing misplaced confidence that Richard Clarke will make this committee useful. While he’s good on a lot of issues, he’s as hawkish on cybersecurity as anyone else in this country. And as I keep pointing out, these programs are really about cybersecurity. Richard Clarke is not going to do a damned thing to rein in a program that increasingly serves to surveil US Internet data to protect against cyberthreats.
But Sunstein? Really?
As Glenn Greenwald (yeah — that Glenn; did they really think no one would raise this point?) reported back in 2010, Sunstein wrote a paper in 2008 advocating very creepy stealth measures against “conspiracy theories.”
In 2008, while at Harvard Law School, Sunstein co-wrote a truly pernicious paper proposing that the U.S. Government employ teams of covert agents and pseudo-”independent” advocates to “cognitively infiltrate” online groups and websites — as well as other activist groups — which advocate views that Sunstein deems “false conspiracy theories” about the Government. This would be designed to increase citizens’ faith in government officials and undermine the credibility of conspiracists. The paper’s abstract can be read, and the full paper downloaded, here.
Sunstein advocates that the Government’s stealth infiltration should be accomplished by sending covert agents into “chat rooms, online social networks, or even real-space groups.” He also proposes that the Government make secret payments to so-called “independent” credible voices to bolster the Government’s messaging (on the ground that those who don’t believe government sources will be more inclined to listen to those who appear independent while secretly acting on behalf of the Government). This program would target those advocating false “conspiracy theories,” which they define to mean: “an attempt to explain an event or practice by reference to the machinations of powerful people, who have also managed to conceal their role.”And remember, a big mandate for this committee is not to review the programs to see if we can make them more privacy-protective, but simply to increase our trust in them. Which goes to the core of what Sunstein was talking about in his paper: using covert government propaganda to, in this case, better sell covert government spying.
Well, if Obama and Clapper’s rollout hadn’t already discredited this committee, Sunstein’s selection sure does.
Update: Adding some quotes from Sunstein’s paper.
The importance of undermining conspiracy theories is especially important with terrorism.
Our main though far from exclusive focus – our running example – involves conspiracy theories relating to terrorism, especially theories that arise from and post-date the 9/11 attacks. These theories exist within the United States and, even more virulently, in foreign countries, especially Muslim countries. The existence of both domestic and foreign conspiracy theories, we suggest, is no trivial matter, posing real risks to the government’s antiterrorism policies, whatever the latter may be. Terrorism-related theories are thus a crucial testing ground for the significance, causes, and policy implications of widespread conspiracy theorizing.True conspiracy theories shouldn’t be undermined.
Of course some conspiracy theories, under our definition, have turned out to be true. The Watergate hotel room used by Democratic National Committee was, in fact, bugged by Republican officials, operating at the behest of the White House. In the 1950s, the Central Intelligence Agency did, in fact, administer LSD and related drugs under Project MKULTRA, in an effort to investigate the possibility of “mind control.” Operation Northwoods, a rumored plan by the Department of Defense to simulate acts of terrorism and to blame them on Cuba, really was proposed by high-level officials (though the plan never went into effect).13 In 1947, space aliens did, in fact, land in Roswell, New Mexico, and the government covered it all up. (Well, maybe not.) Our focus throughout is on false conspiracy theories, not true ones. Our ultimate goal is to explore how public officials might undermine such theories, and as a general rule, true accounts should not be undermined. [my emphasis]
Labels:
cass sunstein,
cybersecurity,
nsa,
obama,
richard clarke,
surveillance
Tuesday, August 20, 2013
'Snowden data destruction won't harm our reporting' - Guardian's Alan Rusbridger
from Russia Today: The British government's attempts to stem the tide of articles on mass surveillance have gone beyond intimidating the journalist behind the publications. Just a day after Glenn Greenwald's partner was detained at Heathrow airport, The Guardian's editor, Alan Rusbridger, came forward describing how the authorities pressured the newspaper to destroy documents provided by NSA leaker Edward Snowden. Mr. Rusbridger has explained why he gave in to pressure from government agents, and destroyed hard-drives carrying information obtained from Edward Snowden.
Related:
Thursday, August 15, 2013
#NewWorldNextWeek: Encrypted Email Providers Shutter Services To Protect Users from Government Snoops
from reason.com: Last week, two companies, first Lavabit (as noted by Scott Shackford) and then Silent Circle, shut down their encrypted email services abruptly and with no warning.Lavabit's announcement was both cryptic and frightening, with owner Ladar Levison strongly implying that the move came to avoid submitting to government surveillance demands. Silent Circle CEO Mike Janke then explicitly stated that his firm was closing the company's email service without warning so the U.S. government would have no opportunity to seize data. Both moves are sad, but commendable, and they stand as scathing indictments of U.S. law and officials. They also suggest that at least one industry, and its related talent and technology, are likely to move off-shore.
Levison's statement reads, in part:
ZDNet interview with Silent Circle's CEO Michael Janke:
Related:
Australian bank closes Bitcoin business' bank accounts
Silent Circle openly acted as a follow-on to Lavabit's move, announcing:
Levison now recommends "against anyone trusting their private data to a company with physical ties to the United States" and is discussing restarting his service outside the country, though probably not with himself at the helm. That's because he fears coming under legal pressure as a U.S. citizen unless he's willing to follow the example of Edward Snowden (who he praises) and leave the country.
Silent Circle plans to reintroduce encrypted email once it can offer a service that's as opaque to scrutiny, revealing no metadata, as its other offerings.
By then, somebody in a a more-privacy friendly jurisdiction will likely be offering encrypted email products that are legally immune to NSA orders, the FISA court and national security letters, though available worldwide over the Internet. That company, and competitors, will attract talent, develop technology, and accumulate wealth in a way that will leave American firms falling behind. That's not because saints hold office elsewhere, but because at least a few countries must see more of a future in competing with Google than with the NSA.
Levison's statement reads, in part:
I have been forced to make a difficult decision: to become complicit in crimes against the American people or walk away from nearly ten years of hard work by shutting down Lavabit. After significant soul searching, I have decided to suspend operations. I wish that I could legally share with you the events that led to my decision. I cannot. I feel you deserve to know what’s going on--the first amendment is supposed to guarantee me the freedom to speak out in situations like this. Unfortunately, Congress has passed laws that say otherwise. As things currently stand, I cannot share my experiences over the last six weeks, even though I have twice made the appropriate requests.In an interview with Democracy Now, Levison added:
I think if the American public knew what our government was doing, they wouldn’t be allowed to do it anymore, which is why I’m here in D.C. today speaking to you. My hope is that, you know, the media can uncover what’s going on, without my assistance, and, you know, sort of pressure both Congress and our efforts through the court system to, in effect, put a cap on what it is the government is entitled to in terms of our private communications....
There’s information that I can’t even share with my lawyer, let alone with the American public. So if we’re talking about secrecy, you know, it’s really been taken to the extreme. And I think it’s really being used by the current administration to cover up tactics that they may be ashamed of.
ZDNet interview with Silent Circle's CEO Michael Janke:
Related:
Australian bank closes Bitcoin business' bank accounts
Silent Circle openly acted as a follow-on to Lavabit's move, announcing:
Silent Circle has preemptively discontinued Silent Mail service to prevent spying.
We designed our phone, video, and text services (Silent Phone, Text and Eyes) to be completely end-to-end secure with all cryptography done on the clients and our exposure to your data to be nil. The reasons are obvious -- the less of your information we have, the better it is for you and for us.
Silent Mail has thus always been something of a quandary for us. Email that uses standard Internet protocols cannot have the same security guarantees that real-time communications has. There are far too many leaks of information and metadata intrinsically in the email protocols themselves. Email as we know it with SMTP, POP3, and IMAP cannot be secure.
And yet, many people wanted it. Silent Mail has similar security guarantees to other secure email systems, and with full disclosure, we thought it would be valuable.In an interview with USA Today, Silent Circle's Janke explained why the plug was pulled so quickly:
However, we have reconsidered this position. We've been thinking about this for some time, whether it was a good idea at all. Yesterday, another secure email provider, Lavabit, shut down their system less they "be complicit in crimes against the American people." We see the writing on the wall, and we have decided that it is best for us to shut down Silent Mail. We have not received subpoenas, warrants, security letters, or anything else by any government, and this is why we are acting now.
"If we announced it, it would have given authorities time to file a national security letter (demanding information). We decided to destroy it before we were asked to turn (information) over. We had to do scorched earth."Silent Circle's other products, including encrypted phone calls and text messaging, remain in place because they leave essentially no information for the company to surrender to government officials.
Levison now recommends "against anyone trusting their private data to a company with physical ties to the United States" and is discussing restarting his service outside the country, though probably not with himself at the helm. That's because he fears coming under legal pressure as a U.S. citizen unless he's willing to follow the example of Edward Snowden (who he praises) and leave the country.
Silent Circle plans to reintroduce encrypted email once it can offer a service that's as opaque to scrutiny, revealing no metadata, as its other offerings.
By then, somebody in a a more-privacy friendly jurisdiction will likely be offering encrypted email products that are legally immune to NSA orders, the FISA court and national security letters, though available worldwide over the Internet. That company, and competitors, will attract talent, develop technology, and accumulate wealth in a way that will leave American firms falling behind. That's not because saints hold office elsewhere, but because at least a few countries must see more of a future in competing with Google than with the NSA.
Labels:
email,
encryption,
lavabit,
nsa,
snowden,
spying,
surveillance
Wednesday, August 7, 2013
Ex-NSA chief calls transparency groups, hackers next terrorists
from salon.com: Michael Hayden equates potential angry reactions to Snowden indictments to al-Qaida operations.
The cyberscare, like the redscare or the greenscare of the ’90′s, is already under way. We’ve seen it take root with the fierce federal persecution of Aaron Swartz, the hefty charges and prison sentence facing LulzSec hacktivist Jeremy Hammond and the three-year jail sentence handed down to Andrew “Weev” Auernheimer for pointing out and sharing a vulnerability in AT&T’s user information network. On Tuesday, former NSA chief Michael Hayden put it into words.
Hayden warned that hackers, cyberactivists and transparency groups who might act in support of NSA leaker Edward Snowden could target the U.S. government — equating such groups and individuals to al-Qaida terrorists. Using trite and old-fashioned descriptions of anarchists and hackers as dangerous loners, Hayden said during a Washington speech Tuesday (as the Guardian reported):
His comments reflect the government’s troubling attitude towards online and open-data activists: they are prefiguratively framed as criminals and terrorists, and are treated as such. Although no longer at the NSA’s helm, Hayden’s attitude suggests with disturbing honesty the potential manner in which the government will treat groups who fight for whistle-blowers like Snowden, who risk their lives to reveal the darker side of U.S.’s nexus of cyberpower.
The cyberscare, like the redscare or the greenscare of the ’90′s, is already under way. We’ve seen it take root with the fierce federal persecution of Aaron Swartz, the hefty charges and prison sentence facing LulzSec hacktivist Jeremy Hammond and the three-year jail sentence handed down to Andrew “Weev” Auernheimer for pointing out and sharing a vulnerability in AT&T’s user information network. On Tuesday, former NSA chief Michael Hayden put it into words.
Hayden warned that hackers, cyberactivists and transparency groups who might act in support of NSA leaker Edward Snowden could target the U.S. government — equating such groups and individuals to al-Qaida terrorists. Using trite and old-fashioned descriptions of anarchists and hackers as dangerous loners, Hayden said during a Washington speech Tuesday (as the Guardian reported):
“If and when our government grabs Edward Snowden, and brings him back here to the United States for trial, what does this group do?” said retired air force general Michael Hayden, who from 1999 to 2009 ran theNSA and then the CIA, referring to “nihilists, anarchists, activists, Lulzsec, Anonymous, twentysomethings who haven’t talked to the opposite sex in five or six years”.
“They may want to come after the US government, but frankly, you know, the dot-mil stuff is about the hardest target in the United States,” Hayden said, using a shorthand for US military networks. “So if they can’t create great harm to dot-mil, who are they going after? Who for them are the World Trade Centers? The World Trade Centers, as they were for al-Qaida.”
Hayden provided his speculation during a speech on cybersecurity to a Washington group, the Bipartisan Policy Center, in which he confessed to being deliberately provocative.It was under Hayden’s directorship that NSA programs designed to hoard data and metadata on almost every online and phone communication within and going out of the U.S. were developed.
His comments reflect the government’s troubling attitude towards online and open-data activists: they are prefiguratively framed as criminals and terrorists, and are treated as such. Although no longer at the NSA’s helm, Hayden’s attitude suggests with disturbing honesty the potential manner in which the government will treat groups who fight for whistle-blowers like Snowden, who risk their lives to reveal the darker side of U.S.’s nexus of cyberpower.
Sunday, August 4, 2013
Has the Gov't Lied on Snooping? Let's Go to the Videotape
from propublica.org: Since Edward Snowden leaked documents detailing the NSA's sweeping surveillance programs, Director of National Intelligence James Clapper was forced to admit that part of his congressional testimony was "erroneous." Here are six claims about NSA surveillance that have been undermined by recent disclosures. Read the full story: http://propub.ca/nsa-claims
Labels:
nsa,
snowden,
surveillance
Wednesday, July 24, 2013
The Truth About Edward Snowden
from FreedomainRadio.com: Stefan Molyneux discusses the truth about Edward Snowden and breaks down the history, origin, legality, and the terrifying reality of warrantless wiretapping, data collection and government spying.
Labels:
nsa,
snowden,
video,
wiretapping
Monday, July 22, 2013
#NSA Can Reportedly Track Phones Even When They're Turned Off
from slate.com: The NSA has a diverse range of surveillance capabilities—from monitoring Google Maps use to sifting through millions of phone call records and spying on Web searches.
But it doesn’t end there. The agency can also track down the location of a cellphone even if the handset is turned off, according to a new report.
On Monday, the Washington Post published a story focusing on how massively the NSA has grown since the 9/11 attacks. Buried within it, there was a small but striking detail: By September 2004, the NSA had developed a technique that was dubbed “The Find” by special operations officers. The technique, the Post reports, was used in Iraq and “enabled the agency to find cellphones even when they were turned off.” This helped identify “thousands of new targets, including members of a burgeoning al-Qaeda-sponsored insurgency in Iraq,” according to members of the special operations unit interviewed by the Post.
It is not explained in the report exactly how this technique worked. But to spy on phones when they are turned off, agencies would usually have to infect the handset with a Trojan that would force it to continue emitting a signal if the phone is in standby mode, unless the battery is removed. In most cases, when you turn your phone off—even if you do not remove the battery—it will stop communicating with nearby cell towers and can be traced only to the location it was in when it was powered down.
In 2006, it was reported that the FBI had deployed spyware to infect suspects’ mobile phones and record data even when they were turned off. The NSA may have resorted to a similar method in Iraq, albeit on a much larger scale by infecting thousands of users at one time. Though difficult, the mass targeting of populations with Trojan spyware is possible—and not unheard of. In 2009, for instance, thousands of BlackBerry users in the United Arab Emirates were targeted with spyware that was disguised as a legitimate update. The update drained users’ batteries and was eventually exposed by researchers, who identified that it had apparently been designed by U.S. firm SS8, which sells “lawful interception” tools to help governments conduct surveillance of communications.
In recent weeks, the NSA’s surveillance programs—both domestic and international—have been the subject of intense scrutiny following a series of leaked secret documents. The NSA says that a vast database that it maintains on phone calls made by millions of Americans does not include location data. But the revelation that the agency has developed a technique that apparently enables it to monitor thousands of cellphones—even when turned off—is likely to only inflame civil liberties groups’ concerns, prompting further questions about the full extent of the agency’s spying efforts.
But it doesn’t end there. The agency can also track down the location of a cellphone even if the handset is turned off, according to a new report.
On Monday, the Washington Post published a story focusing on how massively the NSA has grown since the 9/11 attacks. Buried within it, there was a small but striking detail: By September 2004, the NSA had developed a technique that was dubbed “The Find” by special operations officers. The technique, the Post reports, was used in Iraq and “enabled the agency to find cellphones even when they were turned off.” This helped identify “thousands of new targets, including members of a burgeoning al-Qaeda-sponsored insurgency in Iraq,” according to members of the special operations unit interviewed by the Post.
It is not explained in the report exactly how this technique worked. But to spy on phones when they are turned off, agencies would usually have to infect the handset with a Trojan that would force it to continue emitting a signal if the phone is in standby mode, unless the battery is removed. In most cases, when you turn your phone off—even if you do not remove the battery—it will stop communicating with nearby cell towers and can be traced only to the location it was in when it was powered down.
In 2006, it was reported that the FBI had deployed spyware to infect suspects’ mobile phones and record data even when they were turned off. The NSA may have resorted to a similar method in Iraq, albeit on a much larger scale by infecting thousands of users at one time. Though difficult, the mass targeting of populations with Trojan spyware is possible—and not unheard of. In 2009, for instance, thousands of BlackBerry users in the United Arab Emirates were targeted with spyware that was disguised as a legitimate update. The update drained users’ batteries and was eventually exposed by researchers, who identified that it had apparently been designed by U.S. firm SS8, which sells “lawful interception” tools to help governments conduct surveillance of communications.
In recent weeks, the NSA’s surveillance programs—both domestic and international—have been the subject of intense scrutiny following a series of leaked secret documents. The NSA says that a vast database that it maintains on phone calls made by millions of Americans does not include location data. But the revelation that the agency has developed a technique that apparently enables it to monitor thousands of cellphones—even when turned off—is likely to only inflame civil liberties groups’ concerns, prompting further questions about the full extent of the agency’s spying efforts.
Labels:
cell phone,
nsa,
tracking
Thursday, July 11, 2013
Revealed: How #Microsoft handed the #NSA access to encrypted messages
from guardian.co.uk: Microsoft has collaborated closely with US intelligence services to allow users' communications to be intercepted, including helping the National Security Agency to circumvent the company's own encryption, according to top-secret documents obtained by the Guardian.
The files provided by Edward Snowden illustrate the scale of co-operation between Silicon Valley and the intelligence agencies over the last three years. They also shed new light on the workings of the top-secret Prism program, which was disclosed by the Guardian and the Washington Post last month.
The documents show that:
• Microsoft helped the NSA to circumvent its encryption to address concerns that the agency would be unable to intercept web chats on the new Outlook.com portal;
• The agency already had pre-encryption stage access to email on Outlook.com, including Hotmail;
• The company worked with the FBI this year to allow the NSA easier access via Prism to its cloud storage service SkyDrive, which now has more than 250 million users worldwide;
• Microsoft also worked with the FBI's Data Intercept Unit to "understand" potential issues with a feature in Outlook.com that allows users to create email aliases;
• In July last year, nine months after Microsoft bought Skype, the NSA boasted that a new capability had tripled the amount of Skype video calls being collected through Prism;
• Material collected through Prism is routinely shared with the FBI and CIA, with one NSA document describing the program as a "team sport".
The latest NSA revelations further expose the tensions between Silicon Valley and the Obama administration. All the major tech firms are lobbying the government to allow them to disclose more fully the extent and nature of their co-operation with the NSA to meet their customers' privacy concerns. Privately, tech executives are at pains to distance themselves from claims of collaboration and teamwork given by the NSA documents, and insist the process is driven by legal compulsion.
In a statement, Microsoft said: "When we upgrade or update products we aren't absolved from the need to comply with existing or future lawful demands." The company reiterated its argument that it provides customer data "only in response to government demands and we only ever comply with orders for requests about specific accounts or identifiers".
In June, the Guardian revealed that the NSA claimed to have "direct access" through the Prism program to the systems of many major internet companies, including Microsoft, Skype, Apple, Google, Facebook and Yahoo.
Blanket orders from the secret surveillance court allow these communications to be collected without an individual warrant if the NSA operative has a 51% belief that the target is not a US citizen and is not on US soil at the time. Targeting US citizens does require an individual warrant, but the NSA is able to collect Americans' communications without a warrant if the target is a foreign national located overseas.
Since Prism's existence became public, Microsoft and the other companies listed on the NSA documents as providers have denied all knowledge of the program and insisted that the intelligence agencies do not have back doors into their systems.
Microsoft's latest marketing campaign, launched in April, emphasizes its commitment to privacy with the slogan: "Your privacy is our priority."
Similarly, Skype's privacy policy states: "Skype is committed to respecting your privacy and the confidentiality of your personal data, traffic data and communications content."
But internal NSA newsletters, marked top secret, suggest the co-operation between the intelligence community and the companies is deep and ongoing.
The latest documents come from the NSA's Special Source Operations (SSO) division, described by Snowden as the "crown jewel" of the agency. It is responsible for all programs aimed at US communications systems through corporate partnerships such as Prism.
The files show that the NSA became concerned about the interception of encrypted chats on Microsoft's Outlook.com portal from the moment the company began testing the service in July last year.
Within five months, the documents explain, Microsoft and the FBI had come up with a solution that allowed the NSA to circumvent encryption on Outlook.com chats.
A newsletter entry dated 26 December 2012 states: "MS [Microsoft], working with the FBI, developed a surveillance capability to deal" with the issue. "These solutions were successfully tested and went live 12 Dec 2012."
Two months later, in February this year, Microsoft officially launched the Outlook.com portal.
Another newsletter entry stated that NSA already had pre-encryption access to Outlook email. "For Prism collection against Hotmail, Live, and Outlook.com emails will be unaffected because Prism collects this data prior to encryption."
Microsoft's co-operation was not limited to Outlook.com. An entry dated 8 April 2013 describes how the company worked "for many months" with the FBI – which acts as the liaison between the intelligence agencies and Silicon Valley on Prism – to allow Prism access without separate authorization to its cloud storage service SkyDrive.
The document describes how this access "means that analysts will no longer have to make a special request to SSO for this – a process step that many analysts may not have known about".
The NSA explained that "this new capability will result in a much more complete and timely collection response". It continued: "This success is the result of the FBI working for many months with Microsoft to get this tasking and collection solution established."
A separate entry identified another area for collaboration. "The FBI Data Intercept Technology Unit (DITU) team is working with Microsoft to understand an additional feature in Outlook.com which allows users to create email aliases, which may affect our tasking processes."
The NSA has devoted substantial efforts in the last two years to work with Microsoft to ensure increased access to Skype, which has an estimated 663 million global users.
One document boasts that Prism monitoring of Skype video production has roughly tripled since a new capability was added on 14 July 2012. "The audio portions of these sessions have been processed correctly all along, but without the accompanying video. Now, analysts will have the complete 'picture'," it says.
Eight months before being bought by Microsoft, Skype joined the Prism program in February 2011.
According to the NSA documents, work had begun on smoothly integrating Skype into Prism in November 2010, but it was not until 4 February 2011 that the company was served with a directive to comply signed by the attorney general.
The NSA was able to start tasking Skype communications the following day, and collection began on 6 February. "Feedback indicated that a collected Skype call was very clear and the metadata looked complete," the document stated, praising the co-operation between NSA teams and the FBI.
"Collaborative teamwork was the key to the successful addition of another provider to the Prism system."
ACLU technology expert Chris Soghoian said the revelations would surprise many Skype users. "In the past, Skype made affirmative promises to users about their inability to perform wiretaps," he said.
"It's hard to square Microsoft's secret collaboration with the NSA with its high-profile efforts to compete on privacy with Google."
The information the NSA collects from Prism is routinely shared with both the FBI and CIA. A 3 August 2012 newsletter describes how the NSA has recently expanded sharing with the other two agencies.
The NSA, the entry reveals, has even automated the sharing of aspects of Prism, using software that "enables our partners to see which selectors [search terms] the National Security Agency has tasked to Prism".
The document continues: "The FBI and CIA then can request a copy of Prism collection of any selector…" As a result, the author notes: "these two activities underscore the point that Prism is a team sport!"
In its statement to the Guardian, Microsoft said:
The files provided by Edward Snowden illustrate the scale of co-operation between Silicon Valley and the intelligence agencies over the last three years. They also shed new light on the workings of the top-secret Prism program, which was disclosed by the Guardian and the Washington Post last month.
The documents show that:
• Microsoft helped the NSA to circumvent its encryption to address concerns that the agency would be unable to intercept web chats on the new Outlook.com portal;
• The agency already had pre-encryption stage access to email on Outlook.com, including Hotmail;
• The company worked with the FBI this year to allow the NSA easier access via Prism to its cloud storage service SkyDrive, which now has more than 250 million users worldwide;
• Microsoft also worked with the FBI's Data Intercept Unit to "understand" potential issues with a feature in Outlook.com that allows users to create email aliases;
• In July last year, nine months after Microsoft bought Skype, the NSA boasted that a new capability had tripled the amount of Skype video calls being collected through Prism;
• Material collected through Prism is routinely shared with the FBI and CIA, with one NSA document describing the program as a "team sport".
The latest NSA revelations further expose the tensions between Silicon Valley and the Obama administration. All the major tech firms are lobbying the government to allow them to disclose more fully the extent and nature of their co-operation with the NSA to meet their customers' privacy concerns. Privately, tech executives are at pains to distance themselves from claims of collaboration and teamwork given by the NSA documents, and insist the process is driven by legal compulsion.
In a statement, Microsoft said: "When we upgrade or update products we aren't absolved from the need to comply with existing or future lawful demands." The company reiterated its argument that it provides customer data "only in response to government demands and we only ever comply with orders for requests about specific accounts or identifiers".
In June, the Guardian revealed that the NSA claimed to have "direct access" through the Prism program to the systems of many major internet companies, including Microsoft, Skype, Apple, Google, Facebook and Yahoo.
Blanket orders from the secret surveillance court allow these communications to be collected without an individual warrant if the NSA operative has a 51% belief that the target is not a US citizen and is not on US soil at the time. Targeting US citizens does require an individual warrant, but the NSA is able to collect Americans' communications without a warrant if the target is a foreign national located overseas.
Since Prism's existence became public, Microsoft and the other companies listed on the NSA documents as providers have denied all knowledge of the program and insisted that the intelligence agencies do not have back doors into their systems.
Microsoft's latest marketing campaign, launched in April, emphasizes its commitment to privacy with the slogan: "Your privacy is our priority."
Similarly, Skype's privacy policy states: "Skype is committed to respecting your privacy and the confidentiality of your personal data, traffic data and communications content."
But internal NSA newsletters, marked top secret, suggest the co-operation between the intelligence community and the companies is deep and ongoing.
The latest documents come from the NSA's Special Source Operations (SSO) division, described by Snowden as the "crown jewel" of the agency. It is responsible for all programs aimed at US communications systems through corporate partnerships such as Prism.
The files show that the NSA became concerned about the interception of encrypted chats on Microsoft's Outlook.com portal from the moment the company began testing the service in July last year.
Within five months, the documents explain, Microsoft and the FBI had come up with a solution that allowed the NSA to circumvent encryption on Outlook.com chats.
A newsletter entry dated 26 December 2012 states: "MS [Microsoft], working with the FBI, developed a surveillance capability to deal" with the issue. "These solutions were successfully tested and went live 12 Dec 2012."
Two months later, in February this year, Microsoft officially launched the Outlook.com portal.
Another newsletter entry stated that NSA already had pre-encryption access to Outlook email. "For Prism collection against Hotmail, Live, and Outlook.com emails will be unaffected because Prism collects this data prior to encryption."
Microsoft's co-operation was not limited to Outlook.com. An entry dated 8 April 2013 describes how the company worked "for many months" with the FBI – which acts as the liaison between the intelligence agencies and Silicon Valley on Prism – to allow Prism access without separate authorization to its cloud storage service SkyDrive.
The document describes how this access "means that analysts will no longer have to make a special request to SSO for this – a process step that many analysts may not have known about".
The NSA explained that "this new capability will result in a much more complete and timely collection response". It continued: "This success is the result of the FBI working for many months with Microsoft to get this tasking and collection solution established."
A separate entry identified another area for collaboration. "The FBI Data Intercept Technology Unit (DITU) team is working with Microsoft to understand an additional feature in Outlook.com which allows users to create email aliases, which may affect our tasking processes."
The NSA has devoted substantial efforts in the last two years to work with Microsoft to ensure increased access to Skype, which has an estimated 663 million global users.
One document boasts that Prism monitoring of Skype video production has roughly tripled since a new capability was added on 14 July 2012. "The audio portions of these sessions have been processed correctly all along, but without the accompanying video. Now, analysts will have the complete 'picture'," it says.
Eight months before being bought by Microsoft, Skype joined the Prism program in February 2011.
According to the NSA documents, work had begun on smoothly integrating Skype into Prism in November 2010, but it was not until 4 February 2011 that the company was served with a directive to comply signed by the attorney general.
The NSA was able to start tasking Skype communications the following day, and collection began on 6 February. "Feedback indicated that a collected Skype call was very clear and the metadata looked complete," the document stated, praising the co-operation between NSA teams and the FBI.
"Collaborative teamwork was the key to the successful addition of another provider to the Prism system."
ACLU technology expert Chris Soghoian said the revelations would surprise many Skype users. "In the past, Skype made affirmative promises to users about their inability to perform wiretaps," he said.
"It's hard to square Microsoft's secret collaboration with the NSA with its high-profile efforts to compete on privacy with Google."
The information the NSA collects from Prism is routinely shared with both the FBI and CIA. A 3 August 2012 newsletter describes how the NSA has recently expanded sharing with the other two agencies.
The NSA, the entry reveals, has even automated the sharing of aspects of Prism, using software that "enables our partners to see which selectors [search terms] the National Security Agency has tasked to Prism".
The document continues: "The FBI and CIA then can request a copy of Prism collection of any selector…" As a result, the author notes: "these two activities underscore the point that Prism is a team sport!"
In its statement to the Guardian, Microsoft said:
We have clear principles which guide the response across our entire company to government demands for customer information for both law enforcement and national security issues. First, we take our commitments to our customers and to compliance with applicable law very seriously, so we provide customer data only in response to legal processes.
Second, our compliance team examines all demands very closely, and we reject them if we believe they aren't valid. Third, we only ever comply with orders about specific accounts or identifiers, and we would not respond to the kind of blanket orders discussed in the press over the past few weeks, as the volumes documented in our most recent disclosure clearly illustrate.
Finally when we upgrade or update products legal obligations may in some circumstances require that we maintain the ability to provide information in response to a law enforcement or national security request. There are aspects of this debate that we wish we were able to discuss more freely. That's why we've argued for additional transparency that would help everyone understand and debate these important issues.In a joint statement, Shawn Turner, spokesman for the director of National Intelligence, and Judith Emmel, spokeswoman for the NSA, said:
The articles describe court-ordered surveillance – and a US company's efforts to comply with these legally mandated requirements. The US operates its programs under a strict oversight regime, with careful monitoring by the courts, Congress and the Director of National Intelligence. Not all countries have equivalent oversight requirements to protect civil liberties and privacy.They added: "In practice, US companies put energy, focus and commitment into consistently protecting the privacy of their customers around the world, while meeting their obligations under the laws of the US and other countries in which they operate."
Wednesday, July 10, 2013
#NSA spied on Latin America for energy and military intel
from RT.com: The NSA’s spy program encompasses most countries in Latin America, new cables released by Edward Snowden have confirmed. The data gathered on military affairs and “commercial secrets” has provoked a flurry of furious rhetoric from regional leaders.
Brazilian daily, O Globo, which obtained the cables released by former CIA employee Edward Snowden, published a report on Tuesday detailed the National Security Agency’s initiatives in Latin America.
The US government retrieved key data on a number of issues including the oil market, drugs trade and political movements. Colombia is a top priority for the US, registering the most spy activity, with Mexico, Venezuela and Brazil following closely behind. In addition, Argentina, Ecuador, Panama, Costa Rica, Nicaragua, Honduras, Paraguay, Chile, Peru and El Salvador are under surveillance, though to a lesser degree.
According to the documents obtained by O Globo, the NSA carried out espionage in Latin America in the first quarter of 2013 using at least two data-snooping programs: ‘PRISM,’ from February 2-8 and ‘Boundless Informant’ from January through to March.
‘PRISM’ recorded metadata through Facebook, Google, Microsoft and YouTube, while ‘Boundless Informant’ monitored telephone calls and access to the internet.
O Globo also reported that the NSA gathered information through private Brazilian telecommunications companies using a program called ‘Silverzephyr.’ The daily was unable to identify the companies, but stated that using the program the US gained access to phone calls, faxes and emails.
Furthermore, the leaked information revealed the existence of data-crunching centers in Bogota, Caracas, Mexico City and Panama City and Brasilia that dealt with information intercepted from satellites.
Brazil is currently investigating telecommunication companies believed to be involved in the massive US surveillance program. The country’s president, Dilma Rousseff, was quick to react to the news, stating that if the reports of spying were confirmed it would definitely be a “violation of our sovereignty, without a doubt, just like it’s a violation of human rights.”
Brazil’s Senate foreign relations committee has requested that US ambassador Thomas Shannon to testify on the allegations. It is unclear whether Shannon, who is not legally obliged to provide testimony, will agree.
Gilberto Carvalho, a top aide to President Rousseff, called for a "very hard" response to the United States .
"If we lower our heads, they will trample all over us tomorrow," he said.
President of Argentina Cristina Fernandez de Kirchner said she hopes the US’ actions will be condemned at the next Mercosur (an economic union between Argentina, Brazil, Paraguay, Uruguay, and Venezuela) summit.
“I feel a shiver going down my spine when I see that they are spying on all of us through their services in Brazil,” she said in reference to the O Globo article.
Peruvian President Ollanta Humala, known for his pro-US stance, stated that the reports were “concerning.”
"We are against these kinds of espionage activities," he said in a televised interview. "It would be good for [Peru's] Congress to look with concern at privacy issues related to personal information."
In turn, Colombia has called on the US for an explanation for an “unauthorized” data collection program.
"In rejecting the acts of espionage that violate people's rights and intimacy as well as the international conventions on telecommunication, Colombia requests the corresponding explanations from the United States government through its ambassador to Colombia," the Colombian Foreign Ministry said in the statement.
Mexico, one of the most surveilled countries, has thus far refrained from commenting on the reports .
US whistleblower Edward Snowden, who currently has an extradition order against his name from Washington, is holed up in Moscow’s Sheremetyevo Airport unable to leave because his passport has been revoked. He has applied for political asylum in a number of Latin American countries.
Venezuela and Nicaragua have said they are currently assessing his request.
Brazilian daily, O Globo, which obtained the cables released by former CIA employee Edward Snowden, published a report on Tuesday detailed the National Security Agency’s initiatives in Latin America.
The US government retrieved key data on a number of issues including the oil market, drugs trade and political movements. Colombia is a top priority for the US, registering the most spy activity, with Mexico, Venezuela and Brazil following closely behind. In addition, Argentina, Ecuador, Panama, Costa Rica, Nicaragua, Honduras, Paraguay, Chile, Peru and El Salvador are under surveillance, though to a lesser degree.
According to the documents obtained by O Globo, the NSA carried out espionage in Latin America in the first quarter of 2013 using at least two data-snooping programs: ‘PRISM,’ from February 2-8 and ‘Boundless Informant’ from January through to March.
‘PRISM’ recorded metadata through Facebook, Google, Microsoft and YouTube, while ‘Boundless Informant’ monitored telephone calls and access to the internet.
O Globo also reported that the NSA gathered information through private Brazilian telecommunications companies using a program called ‘Silverzephyr.’ The daily was unable to identify the companies, but stated that using the program the US gained access to phone calls, faxes and emails.
Furthermore, the leaked information revealed the existence of data-crunching centers in Bogota, Caracas, Mexico City and Panama City and Brasilia that dealt with information intercepted from satellites.
Brazil is currently investigating telecommunication companies believed to be involved in the massive US surveillance program. The country’s president, Dilma Rousseff, was quick to react to the news, stating that if the reports of spying were confirmed it would definitely be a “violation of our sovereignty, without a doubt, just like it’s a violation of human rights.”
Brazil’s Senate foreign relations committee has requested that US ambassador Thomas Shannon to testify on the allegations. It is unclear whether Shannon, who is not legally obliged to provide testimony, will agree.
Gilberto Carvalho, a top aide to President Rousseff, called for a "very hard" response to the United States .
"If we lower our heads, they will trample all over us tomorrow," he said.
President of Argentina Cristina Fernandez de Kirchner said she hopes the US’ actions will be condemned at the next Mercosur (an economic union between Argentina, Brazil, Paraguay, Uruguay, and Venezuela) summit.
“I feel a shiver going down my spine when I see that they are spying on all of us through their services in Brazil,” she said in reference to the O Globo article.
Peruvian President Ollanta Humala, known for his pro-US stance, stated that the reports were “concerning.”
"We are against these kinds of espionage activities," he said in a televised interview. "It would be good for [Peru's] Congress to look with concern at privacy issues related to personal information."
In turn, Colombia has called on the US for an explanation for an “unauthorized” data collection program.
"In rejecting the acts of espionage that violate people's rights and intimacy as well as the international conventions on telecommunication, Colombia requests the corresponding explanations from the United States government through its ambassador to Colombia," the Colombian Foreign Ministry said in the statement.
Mexico, one of the most surveilled countries, has thus far refrained from commenting on the reports .
US whistleblower Edward Snowden, who currently has an extradition order against his name from Washington, is holed up in Moscow’s Sheremetyevo Airport unable to leave because his passport has been revoked. He has applied for political asylum in a number of Latin American countries.
Venezuela and Nicaragua have said they are currently assessing his request.
Labels:
boundless informant,
latin america,
nsa,
prism,
silverzephyr,
snowden,
surveillance
Subscribe to:
Posts (Atom)