Sources: NSA sucks in data from 50 companies
theweek.com
theweek.com
Each data processing tool, collection platform, mission and source for raw intelligence is given a specific numeric signals activity/address designator, or a SIGAD. The NSA listening post at Osan in Korea has the SIGAD USA-31. Clark Air Force Base is USA-57.
PRISM is US-984XN.
Each SIGAD is basically a collection site, physical or virtual; the SIGAD alphanumerics are used to indicate the source of intelligence FOR a particular report.
The NSA often assigns classified code names to the product of SIGADs. These can be confused with the nicknames or proper names of the collection platforms themselves, which may or may not be classified. What PRISM does is classified; the fact that there is a "PRISM" tool that does something is not.
...
So: An analyst sits down at a desk. She uses a tool, like PRISM, to analyze information collected and deposited in a database, like CONTRAOCTAVE. Then she uses another tool, perhaps CPE (Content Preparation Environment), to write a report based on the analysis. That report is stored in ANOTHER database, like MAUI. MAUI is a database for finished NSA intelligence products. Anchory is an intelligence community-wide database for intelligence reports.
---------------
And here is the core of it:
This is all very complicated, and that is on purpose. But this brief tutorial is important. PRISM is a kick-ass GUI that allows an analyst to look at, collate, monitor, and cross-check different data types provided to the NSA from internet companies located inside the United States.
The programs that use PRISM are focused, as the government said yesterday, on foreign intelligence. A lot of foreign intelligence runs through American companies and American servers.
...
Now, these accounts are being updated in real-time. So Facebook somehow creates a mirror of the slice of stuff that only the NSA can access. The selected/court-ordered accounts are updated in real-time on both the Facebook server and the mirrored server. PRISM is the tool that puts this all together. Facebook has no idea what the NSA is doing with the data, and the NSA doesn't tell them.
So, PRISM is the name of the software application(s) used by an analyst that allows them to pull together all the various pieces of data that they receive from these companies, along with other sources, for their analysis.
Which of course, explains why the companies have never heard of this name. There is no reason for them to have.
And what the NSA has isn't necessarily "direct access" to the servers - PRISM gives the analyst "direct access" to the data that has already been collected by many different means.
Right, the data may be provided directly from the servers rea time to the collection that the analyst uses, but the NSA wouldn't directly access the provider's servers. In fact, that would be counterproductive, as then users with privileged access to the provider's servers (provider side admins) could monitor what the NSA was doing with the data.
> Now, these accounts are being updated in real-time. So Facebook somehow creates a mirror of the slice of stuff that only the NSA can access. The selected/court-ordered accounts are updated in real-time on both the Facebook server and the mirrored server.
Does this "slice" contain material and accounts gathered only after the legal review that Facebook claims that it performs?
If so, then this story gels with what the NYT reported, that some organizations have built a secure framework to expedite the transmission of requested data...which makes sense, depending on the nature of the investigation...that is...if the NSA has requested data on a suspect on an ongoing case...then they'd probably want that datastore to be updated...in the same way that they want wiretaps to stay on the wire during the investigation.
Note: this is not to say that such surveillance is justified, but that this program makes sense with what Facebook and Google said yesterday and with the reports by the WaPo and the Guardian. Whether this is substantially worse than the other apparatuses we have in place, such as NSL, is also up for debate.
So given that, I think it's worthwhile to actually test their assertion (I.e. not rush to judgment) rather than patting ourselves on the back with the logical fallacies of:
* "Well, the reports about Facebook and Google must be true because it comes from a group that is itself evil and who I would normally not believe" (the enemy of my enemy is my friend)
* "Well, what else would you expect an obviously evil entity to say after being accused of evil acts?" (circular reasoning).
Again, it's not because Google and Facebook are poor disenfranchised groups that must be sympathized with, but because it feels a little dishonest to subject them to the same kind of inescapable logical trap that our government has used to go after and prosecute suspected enemies of the state
Just out of curiosity...can you really not imagine a less transparent corporation than either Google or Facebook?
And I don't think it's an either-or situation: either it's the truth and they deny, or it's false and they deny. There's a third option: it's true, and they remain silent.
If you can find a more transparent company when it comes to government data requests I would love to know about that company.
And no shit Facebook and Google are in damage control mode. They'd be in damage control mode regardless of if they are guilty or innocent, this is a huge PR disaster for both of them and nobody seems to give a shit what the facts are - this went from a few bad power point slides to national panic overnight.
Of course, it could be that Google and everyone else is just lying for no reason at all and people who have talked about PRISM to marc and others in the media are spreading disinformation but I doubt it.
One official likened the NSA's collection authority to a van full of sealed boxes that are delivered to the agency. A court order, similar to the one revealed by the Guardian, permits the transfer of custody of the "boxes." But the NSA needs something else, a specific purpose or investigation, in order to open a particular box. The chairman of the Senate intelligence committee, Sen. Dianne Feinstein, said the standard was "a reasonable, articulatable" suspicion, but did not go into details.
Legally, the government can ask companies for some of these records under a provision of the PATRIOT Act called the "business records provision." Initially, it did so without court cognizance. Now, the FISC signs off on every request.
Armed with what amounts to a rubber stamp court order, however, the NSA can collect and store trillions of bytes of electromagnetic detritus shaken off by American citizens. In the government's eyes, the data is simply moving from one place to another. It does not become, in the government's eyes, relevant or protected in any way unless and until it is subject to analysis. Analysis requires that second order.
So, the govt and NSA distinguish between 'having the data' (receiving a van full of boxes, in the metaphor above) and 'subjecting the data to analysis' (opening a box, in the metaphor). They have a broad order for having the data, but need more specific sign-off to process or analyse the data.
This differentiation between 'having data' and 'analysing data' is not one we'd generally make in the IT world - because if they already have the boxes in their possession, how do we know they are getting the right permission before they open the boxes? How is any oversight possible in that situation?
I don't think it is possible: that's precisely why it's not a distinction made in the IT world: we don't have the apparatus of courts and judges. In the IT world, the primary issue is about security. You have a walled garden and you don't want to let bad people in. Logistics is secondary. Whereas in the IC world, logistics appears to be the harder problem, and keeping the bad people out is already solved to their satisfaction. The challenge is to make sure everyone who needs the data has it.
In the past for instance the ACLU has pointed out that about 2/3 of the US population lives within 100 miles of a land or coastal border, and that border security law can be construed so that all of these people are subject to searches in a way not prohibited by the fourth amendment protections.
More than I think those searches are an issue right now is the possibility that legislators could have not recognized how much of the county's population is within 100 miles of a land or coastal border.
The terminology has been pretty folksy, but it seems absurd to imagine that are very many people who don't have someone adjacent to them in their social graph who is adjacent to a node that has been suspected of being a terrorist.
If the description of how they use the data is correct, then it probably is truthful that counting the number of people whose data have been collected would index those people in such a way that their privacy would be further compromised. However, it seems plausible to guess that the scope of the call data could be estimated, and that most people's data has been collected if not analyzed, indexed and mapped.
However, is the existence of all that data an enormous liability for the future?
During the 1930s the brightest minds in the country were asking fundamental questions about the very nature of how we should organize our country, including crazy ideas involving fascism or communism which probably seemed to make more sense in the context of possible societal collaps. Later in the 50s, the brightest minds were no longer as likely to be working on public service (or on a war effort) yet a paranoia of dunces filled the government, and the country had to deal with their efforts to blacklist people and shape the country as they pleased.
What percentage of interesting people doing the best things in the world right now weren't even heard of twenty years ago or even ten? How many of them unseated someone else's vested interests and who would have preferred not to be surpassed?
Though bad things will be done by people in the future who we've never heard of before, unknown people will also be stomped on by those who are already successful, using whatever tools they can find.
The point isn't that people with wealth and power or people unheard of are more likely to do good or bad things, but that powerful tools in the wrong hands, and anything that encourages self-censoring and slows the flow of information limits possibilities and the talent pool.
It is difficult to understand how unquestioning some of the trust is when top executives really didn't seem to see how anti-competive practices like gentleman's agreement's agreements about poaching each others' employees was wrong, and Congress has such a difficult time putting anything in place to effectively limit their insider trading privileges. And finally for those who do implicitly trust officials right now, did they notice how close people they'd trust less often get to winning elections?
Prism is probably no more than a mail-merge program that will take your (i.e. NSA agent's) signed court order and convert it into whatever format each company requires. Then it will make the request quickly and easily - Say Google requires a PGP encrypted email, Microsoft wants a HTTPS PUT request, Facebook needs you to upload to SFTP server etc.
The other side though is this -- if you let such requests be quick and easy, you will get more of them. If you want to take a position against such surveillance you should make the process as long and drawn out as you legally can. Insist on hard copies hand-delivered. Insist on manual review by lawyers of hard copies, and the like.
But if you make it easy to get information you will get more requests for them.
NSA is part of the Dept. of Defense, and there are lots of laws/rules/etc. that limit what it can do with US citizens.
This NSA infrastructure is sufficient for an extremely effective domestic spying network and the only thing stopping them from starting up such a program is the FISA court, where EVERYTHING IS COMPARTMENTALIZED. Do you see a problem with that?
The NSA is chartered and bound to not do domestic spying.
The only thing stopping anybody from doing anything is the law, and the threat of potentially violent enforcement of that law upon them. It's no different for the Agency.
Wrong. They limit what it can legally do. This really reminds me of Dr. Strangelove: "How could this happen (nuclear strike order)?" "Well, I don't want to jump to any conclusions before all the facts are in, but it appears that General Ripper exceeded his authority."
Sure they aren't allowed to do these things. But since no one is allowed to check up on them, they aren't prevented from doing those things.
Google have also specifically stated that they don't provide a "drop box" facility for FISA requests.
Further more the fact that slide 2 of the deck is about network traffic routing implies that it isn't just about FISA requests for which such information would be irrelevant.
[1] http://www.washingtonpost.com/investigations/us-intelligence...
It is possible that the conflict between the PRISM slides and the company
spokesmen is the result of imprecision on the part of the NSA author.
In another classified report obtained by The Post, the arrangement
is described as allowing “collection managers [to send] content
tasking instructions directly to equipment installed at company-
controlled locations,” rather than directly to company servers.
I don't think slide 2 is relevant, though. The whole deck sounds like a presentation to senior govt officials who are not tech savvy at all, and is just introductory slide that reminds the audience, "The Internet is big and lots of the data flows through the US where we have legal powers." However, there are likely many more slides that were not been disclosed.Fair point about the drop box denial.
[1] http://thenextweb.com/us/2013/06/07/wapost-backtracks-on-cla...;
It is not clear how the NSA interfaces with the companies. It cannot use standard law enforcement transmission channels to do, since most use data protocols that are not compatible with that hardware. Several of the companies mentioned in the Post report deny granting access to the NSA, although it is possible that they are lying, or that the NSA's arrangements with the company are kept so tightly compartmentalized that very few people know about it. Those who do probably have security clearances and are bound by law not to reveal the arrangement.
This arrangement allows the U.S. companies to "stay out of the intelligence business," one of the officials said. That is, the government bears the responsibility for determining what's relevant, and the company can plausibly deny that it subjected any particular customer to unlawful government surveillance. Previously, Congressional authors of the FAA said that such a "get out of jail free" card was insisted by corporations after a wave of lawsuits revealed the extent of their cooperation with the government.
People who self-identify as 'pirates' sometimes refer to the internet as 'the open seas' (similarly representing freedom from oppression and authoritarianism) so it's interesting to see governments establishing 'internet navies' with offensive capabilities given as much attention as defensive capabilities.
Nothing could go wrong with this :)
I seem to remember stories about quasi-government hacker groups. Of course that may very well have been spin that allowed those doing that reporting to blame the chinese government for the actions of their civilians.
In particular, this explanation of what PRISM actually does-
"PRISM works well because it is able to handle several different types of data streams using different basic encryption methods, the person said. It is a "front end" system, or software, that allows an NSA analyst to search through the data and pull out items of significance, which are then stored in any number of databases. PRISM works with another NSA program to encrypt and remove from the analysts' screen data that a computer or the analyst deems to be from a U.S. person who is not the subject of the investigation, the person said."
It mostly sounds like a typical DB query front end, which accesses DBs built up from individual record requests from the tech companies.
But then there's the part about handling different kinds of encryption on the input side, which is puzzling.
The legal process, the person said, is akin to how law enforcement request information in criminal investigations: the government delivers an order to obtain account details about someone who's specifically identified as a non-U.S. individual, with a specific finding that they're involved in an activity related to international terrorism.
Surveillance isn't just about receiving your past activity and data that already exists - they want to watch suspects use these systems to communicate in realtime to find out who else they are talking to.
> A FISA order is required to continue monitoring and analyzing these datasets, although the monitoring can start before an application package is submitted to the Foreign Intelligence Surveillance Court.
That doesn't seem to fit with more recent claims that PRISM is just a streamlined interface for presenting FISA warrants to companies. That might be one component, but there appears to be data collection (just not analysis) pre-warrant.
- "Bitmessage should run on any OS though it is only lightly tested on OSX."
- "Bitmessage is in need of an independent audit to verify its security."
You can't distribute large files like in Usenet, though. Look into I2P + BitTorrent for that, or GnuNet.
I too would like to avoid these companies.