NSA collecting phone records of millions of Americans daily
guardian.co.uk
guardian.co.uk
IT IS HEREBY ORDERED that, the Custodian of Records shall produce to the National Security Agency (NSA) upon service of this Order, and continue production on an ongoing daily basis thereafter for the duration of this Order, unless otherwise ordered by the Court, an electronic copy of the following tangible things: all call detail records or "telephony metadata" created by Verizon for communications (i) between the United States and abroad; or (ii) wholly within the United States, including local telephone calls.
-http://www.guardian.co.uk/world/interactive/2013/jun/06/veri...
It was approved (reapproved?) on April 25, and valid until mid July, and scheduled for declassification in (oops!) 2038. Interesting to note that this order was directed at Verizon, but presumably other carriers have received similar ones?
EDIT: phrasing.
This order authorizes metadata about every call, explicitly not including names, addresses, financial information, or the actual contents of the call.
From the order:
> Telephony metadata does not include the substantive content of any communication, as defined by 18 U.S. §2510(8), or the name, address, or financial information of a subscriber or customer.
Hmm, so what is the point in even collecting if they don't have the names and addresses?
Are you implying that they see 555-444-1234 called 555-444-1235 for 5 minutes and they would have no idea who called who? Why are they bothering. We know government contractor and employment opportunities probably doesn't attract the brightest out there, but you'd think someone would let them know their own data is useless.
It would seem to me they can just do a reverse white pages search and get everything they need. That additional wording "does not include substantive content..." is there as a diversion. "Oh look nothing to worry here..."
No. To the best of my knowledge, I am copying verbatim or summarizing the FISA order.
Why are you doing that? Did you randomly select and copy parts of text or did you pick that particular set of lines for a reason.
You also emphasized the word 'metadata'.
Now you can have a discussion or as soon as people respond to you, you can keep pointing out how they obviously guessed wrong your intentions, maybe finally someone will guess correctly, who knows, until then just reply in short snippets "i didn't say that", "nope not what i meant", "here is an exact quote of what i already wrote".
My reason for posting was to correct factual errors in the discussion. Factual errors seriously reduce the level of quality of discussions of topics such as this one. Things get much more interesting when people hone in on the nuanced elements of the actual fact pattern.
My replies were to correct people who seemed to think that my curation of quotes from the FISA order implied something about my views on whether the order is good or bad.
And now this is an attempt to make the whole series of responses clear.
The news is that the Guardian has got a copy of an actual court order, so we can see the exact language used with the phone companies.
Telephony metadata does not include the substantive contant of any communication or the name, address, or financial information of a subscriber.
http://www.guardian.co.uk/world/interactive/2013/jun/06/veri...
FISA has been sorely abused, but maybe it retained enough coherence to bring us, albeit "inadvertently", one last shred of accountability -- perhaps just in time.
We'll have to see where this goes, now that one document is out.
I can think of technical solutions but it's another matter to get adoption. Also it can't only be an app. The phone can not be trusted. I think you'd need a small device that connects via wifi to your phone and then run some encryption over the top of that. It could be very small with only speaker and mic capabilities. Then you'd have an app on your phone to initial calls and display incoming calls.
Unfortunately right now if you use something like that you simply stick out immediately as interesting traffic to target...
They are keeping track of meta-data, so they are amassing a huge database of who every American associates with over the phone. This "meta data" is a huge part of Signals Intelligence and is very useful even if you can't hear the call itself (which is not to say they are not recording those as well).
The only way around it would be a TOR like system (or a system running on TOR) to obfuscate who everyone talks to.
Behold NSA's own "Mobility Capability" spec
http://www.nsa.gov/ia/_files/Mobility_Capability_Pkg_Vers_2_...
In this spec they define what a mobile device would have to do to be available and good enough to handle government's classified data. How do you know what NSA knows? Usually by looking at what it suggests for government's use. They allegedly know what is already cracked, insecure and exploitable. (For ex. they suggest a specific pattern of erasing hard drives with sensitive data, they might say do it in 3 passes, so maybe assume they can recover data in less than 3 passes, so it gives you a glimpse into what's happening).
So to cut to the chase, how does one hide metadata? Tunneling. You create a device that has some kind of a trusted boot mechanism, loads a trusted OS, and connecst to an exclusive VPN. Nothing enters or leaves the devices via a network that is not _the_ VPN network. Of course in their case the only metadata leaking is that this device is talking to government's central VPN server. Then there are TLS and SRTP channels created that encrypt the voice but metadata is presumably encrypted or hidden by the outer VPN.
Now that is for the government. Now you'd need to set up a a few trusted VPN servers around the world make sure your phone connect to them and all the calls are routed through them as well. That way you could hide the metadata... and probably eventually land on some black list of sorts... ;-) I kid...only slightly
[On a side note there is a known vulnerability in how compressed & encrypted voice data is transmitted that makes it reveal the contents, and that is by analyzing the statistical distribution of data (even encrypted) from that it is possible to deduce the message content -- http://www.cs.jhu.edu/~cwright/oakland08.pdf so, make sure to play relatively loud music in the background , well shit by now I am sure I am on some list somewhere...]
It seems like the better solution would be to just use fixed bitrate compression.
Encrypted content provides you no protection against this sort of analysis.
As others have said, end-to-end encryption this not solve the problem of calculating a persons social networks and the strength of those connections by correlating calling frequency and duration (as the information in the leaked court order could be used to do). For that you would need a Tor-like network. The Guardian Project have attempted to do some work in this area, sending VOIP over Tor, but the latency is quite high at the moment: so it requires using some of the old radio protocols when there was a possibility of interference and to make it clear when you had stopped talking "over and out", "roger" etc.
Citizens of democratic societies should not have to hide their communications from their government. If their government violates this trust, the thing to do is to organize and turn those governments out of office. Encrypting phone calls doesn't solve the problem; the problem isn't the surveillance, it's the contempt for the law and the rights of citizens that the surveillance is just one manifestation of.
However, this is an update to an older story that was apparently broken on May 11th 2006 by USA today. It was covered by CNN tv on that day:
http://mediamatters.org/research/2006/05/11/despite-bipartis...
"HLN, formerly known as CNN Headline News (often abbreviated as HN) and CNN2, is a cable television news channel...Since 2005, however, its format has increasingly shifted to long-form tabloid-, opinion-, crime-, and entertainment news-related programming."
It's not a party issue but rather a power issue, institutions that have it won't give it up on their own.
The only way to do it is to vote, yes— but with your tax dollars. You must emigrate.
If you do it, you'll piss off everyone in charge of homeland security. The second something bad happens, you know these people will do everything to undermine your authority. US elections are already about who's tough enough to protect the USA, imagine after that! Damn if you do, damn if you don't.
Reality is the people's desire for safety and security is the reason surveillance like this exists. Unless the USA stops doing things that make other people want to kill innocent americans, homeland spying, as unacceptable as it may be, is probably the only way to provide that security.
Not sure what the solution to shit like this is but I doubt it's like-minded representatives in Congress.
Evil people, or people with evil intentions, exist. Period. Full stop. There will always be people who want to kill innocent Americans. Period. Full stop. Just as there will always be people who want to kill innocent $CITIZENS_OF_COUNTRY_NAME.
Blaming an entire country for the evil actions and intentions of people who kill innocents is a copout of fantastic proportions. The existence of evil (killing innocents) does not excuse more evil (the government of the United States committing unmitigated mass-scale Orwellian spying on the citizens of the United States).
No blame is put on an entire country but on the actions of its military and whoever/whatever drives those actions.
I also agree the existence of evil should not excuse more evil. Unfortunately, it seems it does in many people's mind.
The problem with a President who chooses to set aside enforcement or use of a law is that it's temporary and the next President is not bound by that decision. This isn't true of legislation.
(A) update their expectations of security to be in line with reality--namely that bad things happen and will happen, are unpredictable, and often unavoidable;
(2) increase their valuation of basic rights and liberties as provided in the Constitution and its amendments, as well as an expectation of vociferous resistance to any encroachments and weakening of said rights and liberties in light of (A) by any person;
(D) regularly invoke a zero-tolerance policy when elected or appointed political leaders trespass against (2).
I think American voters blame too much on the President and let Congress off the hook constantly. If we want to change the laws we should motivate the people who wrote laws, not the person who executes them for 4 years at a time.
So what's the beef?
I probably have a more "original intent" view of privacy than most people. I think privacy is about government intrusion on the sanctity of your home and your person. I struggle to understand how privacy comes into play for things that you don't even attempt to keep private (by virtue of sharing it with a "big evil corporation" like AT&T or Verizon).
Many chat clients have OTR support, SIP has ZRTP, etc. There are alternatives, unfortunately the really popular methods don't make security a priority.
Assuming that the document is real: Thank you Guardian.
Or will we learn later that there's another more secret order for that?
http://news.cnet.com/8301-13578_3-57589495-38/nsa-admits-lis...
This gives you an insight over what the public thinks to know so far: http://www.guardian.co.uk/commentisfree/2013/may/04/telephon...
While this still means that the metadata from millions of phone calls by random people, possibly from phones not even on Verizon who were simply calling VBNS phones, have been vacuumed up by the government, it also means that not "all" Verizon phones are meta-tapped as the article seems to insinuate (tagline, picture caption).
Glenn has done incredible commentary and reporting for many, many years; I hope this story will be only the beginning of his contributions and shake-ups to the discourse and activism against the U.S. surveillance oligarchy. Anyone who hasn't been reading his pieces whenever they come out are missing a phenomenon in human history.
My Verizon iPhone is with "Cellco Partnership d/b/a Verizon Wireless," a separate legal entity.
Do we know that this order actually applies to individuals' phone calls? It seems the document would only apply to enterprise customers.
That makes it no less scary; VBNS has hundreds of thousands of customers and people who make calls to VBNS phones from unrelated also probably had their metadata sent to the government.
My mom doesn't care about electronic surveillance. Neither does my dad, or my wife. The vast majority of my friends (mostly non-techies), don't care. Just look at the success of Facebook and Google. People don't care about electronic privacy in general, and most don't try to draw strained distinctions between data they freely share with big corporations and data they think is okay for the government to have. A lot of them do care about preventing terrorism, however. So how can you sit there and pretend the will of the people isn't being served?
GlennGreenwald:
@strangemartin > Can't help feeling I'm only getting one side of the story here.
There's probably another court order that I've decided to hide from you that reads: "About that last order: just kidding. The government is only entitled to get the phone records of people about whom it has presented evidence of wrongdoing".
http://www.wired.com/threatlevel/2012/05/fbi-seeks-internet-...
In many countries there is a single national telco which is by law or in practice a branch of the government.
> Do modern democracies tend to have laws that protect the public from this sort of indiscriminate surveillance?
Yes, to me this is a defining characteristic of a modern democracy. But they all have a process by which governmental authorities can bypass those protections in specific circumstances such as criminal investigations. This takes the form a court order or a subpoena.
This document appears to be a blanket grant, by a court, of a near-real-time data pipe with no specificity whatsoever.
There has been no shortage of folks on net forums such as this one repeating "The US telcos are largely construed to be supplying data on domestic telephone calls to the NSA". But that just hasn't proven useful without specifics of the sort we saw revealed today.
The NSA interception thing is an additional concern, but given the European Parliament report in to Echelon from 2001, William Binney's recent reports from within the upper management of the NSA, the magnitude of their (black) budget, recent confirmatory comments by other LE parties, and the sheer magnitude of independently verifiable NSA construction projects in progress, it must be difficult to maintain much skepticism there.
http://www.nytimes.com/2012/08/23/opinion/the-national-secur...
His story was corroborated by Mark Klein, a former ATT employee who amassed evidence that the NSA was, with ATT's complicity, running a data-gathering node in room 641A of ATT's San Francisco building:
http://en.wikipedia.org/wiki/Mark_Klein
This is not some conspiracy theory. It's happening, and no one seems to care.
As a side note there are plenty of legitimate reasons to have this metadata for some phone numbers over the past X days. I suspect the original choice was simptly to give them everything vs trying to support these types of lookups after the fact.
PS: AT&T was for a while providing a lot of government services for free simply because they could not get billing correct and it was nobody's job to fix it. Which is why I think this could have easily stared as a hack to solve a technical problem vs. the sort of big brother spying that pops up.
Unix is a ecosystem developed over decades.
Coming to using Windows NT, its likely some 'real manager' is running the show there. Whose only criteria for using a technology is having the ability to hire the cheapest resource on the market. If you were to go ask the person, he won't be able to list 5 differences between Windows and Unix.
Do you ever feel like a frog recognizing the water is boiling and you don't know what to do?
Or like you're looking at what Jefferson, Adams, Washington, and the other founders fought and wrote the Declaration and Constitution over, but everybody is acting like it's easier just to pay the stamp tax?
Or both?
We have lots of levers short of revolution that we can push on to move policy in directions more respectful of the rule of law.
The only question is whether anyone cares enough to use them.
You really think that actually has any significant probability of working in the US?
The refrain of democracy being broken in America is getting old. It's not broken--you just don't like that the majority has a long list of issues it cares more about than privacy. We are getting the things people care about: legalized gay marriage, continued access to abortion, welfare spending, social services for the elderly. We're fighting the good fight on issues that aren't quite there yet: universal healthcare, etc. Democracy is alive and kicking in America.
Twenty years ago gay marriage was a radioactive issue. I know because I was an intern in a Democratic Senator's office back then, and when the Defense of Marriage Act came up I got to watch my boss and a bunch of other normally progressive people rush to vote for it to avoid any possibility of being painted as pro-gay. It was a deeply depressing spectacle.
Now gay marriage is not only thinkable, it's on the verge of becoming the new normal.
Why? How did that happen?
It happened because gay people organized. They spent two decades doing the hard work required to change peoples' minds. And now that work is paying off.
A democracy is not an immovable object. Moving it is hard, but it can be done. You just have to be willing to put your back into it.
I've studied the history of civil rights considerably. This issue strikes me as a far different beast.
I would love to be wrong.
The other problem with this revolution idea is that no one wants to be the first to die for their beliefs.
Maybe people are afraid. If you accuse the NSA of committing crimes that are only slightly unethical (wiretapping US citizens), then you're instantly on "the list" of arguably the most powerful organization in the world.
Not only would the story just end up being, "oh well, greater good", but the NSA would just slightly back off of the monitoring, then make sure that future leaks such as this do not happen again.
They are not an evil nor dark organization, just one with a very important mission, and when you have the real big picture on the table sometimes the unethical option is required to maintain dominance and security.
Imagine having the responsibility of protecting a country that is the #1 target in the world, that has 300+ million people within its borders that have the potential to cause major harm to the country, its citizens, and its allies. The NSA doesn't have a choice but to do everything in its power to maintain information dominance over the world.
The NSAs mission statement requires it to protect the US and provide foreign sigint. They're technically not allowed to spy on US citizens but what if it was absolutely required to protect the country? How many people are really qualified to make that decision?
We're a democracy dammit, or have you forgotten what that actually means?
It's true that no-one seems to care. And what's more, if you do care others will look at you funny, like you're paranoid. "Why do you care so much about anonymity? You don't have anything to hide!"
Literally the only argument that I've ever had luck with is to ask them whether they are okay with the police searching their house whenever they want. After all, you don't have anything to hide, right? This takes them aback. I ask them, so why do you think we need search warrants? And most people agree that we need them, but clearly they've not thought a lot about why we need them, or what life would be like without them.
The odd thing about the situation is that we have a population which has it's head on pretty straight when it comes to search and seizure in the physical domain, and totally uncaring about whether these rules are applied to the digital domain. It's as if information on paper is some sacred thing, but information on disk platters is free for the taking. Very, very strange.
My hope is that, like with pot legalization and gay marriage in many states, public awareness will crystalize and coalesce on the rational position. This is actually a very simple situation where there is unequal application of the 4th amendment depending on media of all things, and this is totally, completely insane.
I don't think you can accuse the public of not taking the "rational position" here. Indeed, I think technologists often take a romanticized position here, ignoring the mechanical nature of the systems in question. People rationally perceive that there is nothing private about who you call or what websites you visit (I mean, how well can Facebook track where you go?) This is quite different from say a conversation one might have in one's home, on one's own property, with the only parties to the conversation being those within one's circle of trust.
Let us just talk about the content that I write, such as anything that I've written and left in Gmail drafts. The fact that Google hosts that data does not give them ownership of that data, nor does it confer the right to access that data for any reason. The data in my drafts folder is exactly the same as data in a paper journal that I have in my house, and is protected by exactly the same law, the 4th amendment. The details of it's representation, even it's physical location, are unimportant.
Extending the 4th Amendment in this way is the only rational thing to do. The only reason why this is not the default is that the public is generally ignorant of both a) how these systems work and b) how they are systematically exploited by government. The reason the government wants access is because it is a convenient and cheap way to achieve some aspects of security. In the post-Bush era, exercising restraint on one's own power is no longer the "done" thing - just ask Cameron Ortiz.
This is what I refer to as the "romanticized view" of technology. Your gmail draft is not like the paper journal you have in your house. It's Google's data on its hardware that its engineers have access to (in clear text!). You want to construct this metaphor, where the "physical location doesn't matter", but that's not the underlying nature of the system.
You say that "representation" shouldn't matter, but you're making the opposite argument. You want different rules for digital representations versus physical ones. The rule right now is that once the information, represented as molecules of ink on fibers of paper, is in someone else's possession, it's not your information anymore. Well at the physical level, your gmail drafts are little flipped magnetic domains on a hard drive platter in a Google data center. If you tried to enter that data center, you'd be thrown out for trespassing. But you think that in this case, the law should construct a metaphor: those bits are "private" even though you don't have possession of them or ownership of the medium on which they reside.
Thought experiment: if I chisel my diary into a rock slab and mail it to Google, do you agree that it's their data now? What if I write it to a magnetic hard drive and mail it to them? No difference, right? So why should it suddenly be different if I send the bits over the internet for Google to write to its own hard drive instead of mailing them a hard drive myself?
It's really that simple, and that is not a romanticized view of technology. Indeed, I'd argue that this is the (reasonable) assumption that most naive internet users make about their data.
Saying it a different way, if javajosh were to concede that your definition of privacy is more useful and concede that you are making a clearer case for how such things developed historically, how does he gain some legal breathing room for his remotely stored documents?
It wouldn't be incoherent at all for a 28th amendment to address various strands of privacy concerns that have arisen over the years. But there needs to be some thought into the design of such an amendment, because it wouldn't be an easy set of analogies from existing protections.
And my normative claim is that this position is totally, completely, batshit insane.
> The data in my drafts folder is exactly the same as data in a paper journal that I have in my house, and is protected by exactly the same law, the 4th amendment.
The use of "is protected" versus "should be protected" seems to me to be inviting an informative discussion, not a normative one.
As an aside, I'm always surprised by how often people on HN talk about "should" versus "is." That's very weird for the engineer in me. You can never make progress in a normative discussion, at best you can boil the disagreement down to a disagreement in principle and leave it at that. E.g. I don't trust the government less than I do Google, Facebook, etc. If I'm willing to write something in my gmail, where a Googler can see it, I'm okay with the government seeing it. You almost certainly have a different perception of privacy and trust. A normative discussion on the subject is thus futile--who is "right" about what who and how much to trust private companies versus the government?
Perhaps we make this distinction because it's an important one. It always surprises me when an engineer confuses the two. "But the courts say that the gov't can access your data if it's not on your property," is NOT a counter argument to the statement "The 4th amendment should extend to data." The conversation cannot move forward unless both sides understand the difference between "should" and "is".
Agreed. It's a strange position to take that because it's technically possible for the government to access the information (owed to the location of the data), then they should be allowed to do so. This could be used to rationalize virtually unlimited access to otherwise private communications in today's hyper-connected world.
But, capabilities that we have had in the past (e.g. wiretapping) have always been checked in order to preserve privacy (or, put more Constitutionally, protect us from unreasonable search and seizure). Phone calls have always involved third-party transmission by the telcos. Why is that different from data sitting on a third-party server?
In general, however, it becomes silly to argue what should be permissible based on the ancillary nuances of technical architecture. It's a bit of a red-herring. The real question is "what is the intent of the protections afforded by the Constitution and are we upholding that intent". To argue that "the government should have a particular right because there's a client-server architecture involved vs. P2P" is spurious in this context.
It's patently ridiculous to call these "ancillary nuances of technical architecture." These are stark distinctions: is the information under your personal control or did you voluntarily give access to and possession of that information to someone else? In this particular case with the NSA, it's even starker: who generated the information? The NSA is collecting information generated by AT&T about activity on AT&T's private network. It strains the imagination to try to define that as an individual's personal information.
> The real question is "what is the intent of the protections afforded by the Constitution and are we upholding that intent"
The intent of the protections was to guard against the invasive physical searches of homes and persons that had occurred under the British. A broader conception of "privacy" is absent from the document. A conception of privacy that is broad enough to encompass information generated by a third party and stored by that third party is purely wishful thinking.
You are saying that by making a phone call, you are voluntarily giving information to someone else (the carrier), and so the government should able to access that data at will. And, I'm being ridiculous?
>who generated the information? The NSA is collecting information generated by AT&T about activity on AT&T's private network
The caller generated the data. AT&T simply collected and indexed it. There would be no data or metadata without the caller. You acknowledged this yourself in the first paragraph when you asked, "is the information under your control or did you voluntarily give possession of that information to someone else?" How could I give AT&T information that it supposedly generated? Once again, you're all over the place.
And, your ridiculous argument that because AT&T offers the pipes, they should be able to do what they please with the data that is generated is tripe. You could just as well extend that to make warrantless wiretapping on all calls legal. It is all merely data on AT&T's private network, right?
>The intent of the protections was to guard against the invasive physical searches of homes and persons that had occurred under the British
Funny how you're so willing to update government powers based upon evolving technology, however, when it comes to the rights conferred by the Constitution to the people, you want to limit those to the technology of that day. In this case, you are literally limiting those protections to redcoats (or similar) showing up at your door and rifling through your papers. I can't believe you expect to be taken seriously.