Did Yahoo Mail even use HTTPS? In that case a FISA warrant would just be an extra level of assurance that they got everything from that person's inbox (plus inboxes of 3 hops of everyone they ever emailed). Otherwise they were just an XKeyscore query, probably filtered by US geodata, away from getting whatever email they wanted (plus unlimited hops).
Otherwise they would collect any email ever sent unencrypted via submarine fiber wiretaps. While feeds into XKeyscore.
> Turns out the data collection is not so limited. In testimony yesterday before the House Judiciary Committee, National Security Agency Deputy Director Chris Inglis said that the NSA’s probing of data in search of terrorist activity extended “two to three hops” away from suspected terrorists. Previously, NSA leaders had said surveillance was limited to only two “hops” from a suspect.
> Inglis said that the NSA looks at two to three hops from a suspect. To determine how many hops you are from Osama, for example, the NSA’s data analysis engine software constantly plows through information and builds a model of all the relationships between every phone number on record and every IP address. Other software robots query the graph to discover which “nodes”—phone numbers, IP addresses and email accounts—fall within three degrees of separation from an established suspect.
> If you have a direct relationship with a suspected terrorist or target (you’ve called them, you’ve emailed them, you’ve visited their website) that’s a “one hop” relationship; there’s a solid line connecting you to that person in the NSA’s relationship graph. If you talk with, e-mail, or visit the Facebook page or website of someone who’s got a one-hop relationship, you’re two hops away. Add one more person in between in the graph, and you’re three hops away.
> Under the NSA’s FISA requests, Google, Microsoft, and other Internet services companies can be compelled to hand over relevant data from their servers on any account that falls within the three-hop range and is flagged as belonging to a person of interest. If you’ve won this lottery, the NSA will get access to your e-mails on Gmail or Outlook.com as well as your chats and Web-stored contacts, your documents, your synced data from computers and mobile devices, your backups, and anything else that can be handed over—at least, so the documents Snowden leaked imply.
> Your raw Internet traffic will get more attention as well. Your IP address will be watched more carefully by deep packet inspection hardware at the NSA’s 'Net taps, and what you do online will get extra scrutiny.
https://www.google.ca/amp/arstechnica.com/information-techno...
I'm not sure if you're just a casual spectator, willfully spreading disinformation, or inclined to ignorance but the boogeyman dismissive posturing boat has long sailed. PRISM's only purpose is to fill in the gaps of passive collection by directly sourcing data, otherwise it comes in primarily from submarine wiretaps and the multitude of other various passive collection sources. Or associated five eyes programs.
And yes FISA warrants include 3 hops and if you know anything about the Internet you know that is a hell of a lot of data for a single warrant. And public data shows the FISA court only deny around 0.1% of warrant requests. Even rubber stamps have to pretend they are doing their job.
PRISM doesn't "fill in gaps." It is their main source of actionable intelligence according to the leaked slides, and it only contains the data of the person being watched, requested via court order, approved by the company, and then sent to the FBI.
Further proof:
> 50 U.S.C. § 1861 (b)(2)(C). These call detail orders cannot last longer than 180 days. Additionally, in an application for call records “two hops” from target—call records from people in contact with the identified target—the government must base its request on “session-identifying information or a telephone calling card number identified by the specific selection term” used in its first request. In December of 2015, the FISC ruled that USA Freedom does not require the government to show that these “two hops” call records are relevant to an ongoing investigation.
The only development Ive found has been that they promised to use 2 hops instead of 3. Which is good. But I'm not convinced the 2, previously 3, hops is limited to simply metadata.
Additionally this whole discussion of FISA warrants and limitations are strictly for Americans. They can collect full content and metadata of every foreign traffic they passively intercept.
The issue with metadata that was debated is primarily because they had unlimited warrantless access to American metadata since it's basically public data in their view. No one cared about non-americans. The FISA orders are for granting analysts access to full content on Americans (most likely they already have most of this data, they just aren't allowed to query it without a warrant.
They don't need warrants to collect metadata.
Your "further proof" also shows that they don't ask for three hops. It says that in order to request call records (phone call metadata, not the communications themselves: https://en.wikipedia.org/wiki/Call_detail_record), the investigator must show that the user is two hops by communication from a target. They determine this from the full-take phone metadata collection program that ended last year (https://www.washingtonpost.com/world/national-security/nsas-...) despite being ruled legal by the courts (http://www.reuters.com/article/us-usa-court-surveillance-idU...). According to Snowden's leaked documents, analysts have neither the authority nor the tools to look at anybody's call records in that full-take data but are only able to query it in specific ways (e.g., list the anonymized numbers that are 3 hops away from a particular number). The government can then apply for a court order to request the call records for a particular number according the rules you quoted.
> They can collect full content and metadata of every foreign traffic they passively intercept.
They can, but according to Snowden's leaks, they don't outside of a handful of hostile countries. The poster's friend is unlikely to live in one of those countries. This is not unique to the US -- Pretty much every country's laws allow the government to collect any data on foreigners.
> The issue with metadata that was debated is primarily because they had unlimited warrantless access to American metadata since it's basically public data in their view.
Also false, as I explained above. They have legal access to collect it, as I showed above, but the law allows them to query it in only a few restricted ways.
> The FISA orders are for granting analysts access to full content on Americans (most likely they already have most of this data, they just aren't allowed to query it without a warrant.
Completely wrong. FISA Section 702 orders can only be for non-Americans living outside of America. Data for a non-American living in the US cannot be requested, and data for an American living outside the US also cannot be requested. You're thinking of NSLs, which also must specify the particular user whose data is requested.
Unverifiable comments like this are harmful.