---
> * “The U.S. government does not have direct access or a ‘back door’ to the information stored in our data centers,” Google’s chief executive, Larry Page, and its chief legal officer, David Drummond, said in a statement on Friday. “We provide user data to governments only in accordance with the law.”*
Statements from Microsoft, Yahoo, Facebook, Apple, AOL and Paltalk made the same distinction.
But instead of adding a back door to their servers, the companies were essentially asked to erect a locked mailbox and give the government the key, people briefed on the negotiations said. Facebook, for instance, built such a system for requesting and sharing the information, they said.
The data shared in these ways, the people said, is shared after company lawyers have reviewed the FISA request according to company practice. It is not sent automatically or in bulk, and the government does not have full access to company servers. Instead, they said, it is a more secure and efficient way to hand over the data.
Tech companies might have also denied knowledge of the full scope of cooperation with national security officials because employees whose job it is to comply with FISA requests are not allowed to discuss the details even with others at the company, and in some cases have national security clearance, according to both a former senior government official and a lawyer representing a technology company.
---
The NYT is talking only about FISA requests, which are a secret process but, as far as everything reported about that process has said, targets individuals. Moreover, when FISA is used on Americans, it's a process that involves a court-approved warrant.
So you can argue that FISA is wrong or that it is administered with a rubber stamp (and in my opinion, yes, this is most definitely worth scrutinizing, and it has been for however many years it's been put in place), or that no ethical company should ever comply with a FISA request...but that's not the same ballpark as what's being alleged with Verizon or with PRISM.
The point about these companies making it "easier" by creating a systematic delivery process, such as a "lockbox", to send over the requested data is an interesting detail, but kind of a non sequitur. Either FISA is OK or it is flat out wrong...what does it matter which digital process is set up to fulfill that request?