U.S., companies: Internet surveillance does not indiscriminately mine data
washingtonpost.com
washingtonpost.com
1. The original title for the article is "U.S., company officials: Internet surveillance does not indiscriminately mine data"
2. The excerpt that the submitted title refers to is this: "Executives at some of the participating companies, who spoke on the condition of anonymity, acknowledged the system’s existence and said it was used to share information about foreign customers with the NSA and other parts of the nation’s intelligence community."
Some, not all of the companies involved. So too soon to conclude that the public statements were lies...but Zuckerberg and Page, at the least, could be said to have lied if the companies referred to in the OP are them (both Page and Zuckerberg said that they (they as in "we") had no prior knowledge of PRISM at all)
"government employees cleared for PRISM access may “task” the system and receive results from an Internet company without further interaction with the company’s staff."
What does that mean? Does the company have any oversight over what's being requested? It doesn't sound like it. How does that square with the statements from the CEOs that each request is carefully considered and restricted?
“The server is controlled by the FBI,” an official with one of the companies said. “We do not offer a download feature from our server.”
This is a very fine distinction that doesn't matter much. Word games are being played here.
This was covered yesterday, in the NYT article http://www.nytimes.com/2013/06/08/technology/tech-companies-... :
> The data shared in these ways, the people said, is shared after company lawyers have reviewed the FISA request according to company practice. It is not sent automatically or in bulk, and the government does not have full access to company servers. Instead, they said, it is a more secure and efficient way to hand over the data.
So, it seems, there are Google-lawyer mechanical Turks clicking "OK" or "Contest" (or whatever) for each FISA order in the Google FISA-order queue. If the lawyer clicks "OK" it seems the requested information is slurped automatically from the Google user-data servers into the PRISM server's outbox (and/or a live data feed is set up). If the lawyer clicks "Contest" then presumably something messier and more manpower-intensive happens. A system like this raises plenty of questions - but it doesn't at all automatically conflict with or falsify what the tech CEOs said.
EDIT: Actually there's apparently a direct conflict between the NYT's version and what WaPo appears to be saying here:
> According to a more precise description contained in a classified NSA inspector general’s report, also obtained by The Post, PRISM allows “collection managers [to send] content tasking instructions directly to equipment installed at company-controlled locations,” rather than directly to company servers. The companies cannot see the queries that are sent from the NSA to the systems installed on their premises, according to sources familiar with the PRISM process.
That seems to imply that there's no Google-lawyer mechanical Turks reviewing the individual FISA orders. Given that that would contradict both the NYT report and the statement from (for example) Page and Drummond http://googleblog.blogspot.ie/2013/06/what.html this is a big deal. Given the WaPo's demonstrated ability to misunderstand information from NSA sources, for the moment I'm inclined to assume that the Post has got this wrong, too - but let's see. (Another possiblity might be that some companies are waving FISA orders of the form "give us the personal data of Suspect X" through automatically, while others still have a lawyer clicking "OK".)
> According to a more precise description contained in a classified NSA inspector general’s report, also obtained by The Post, PRISM allows “collection managers [to send] content tasking instructions directly to equipment installed at company-controlled locations,” rather than directly to company servers. The companies cannot see the queries that are sent from the NSA to the systems installed on their premises, according to sources familiar with the PRISM process.
Could refer to queries on accounts/targets that have already been approved. In that sense, it's not much different from a traditional wiretap...once it's in place, the government investigators want the ability to monitor it continuously...the difference in this context is that this "wiretap" encompasses Internet activity, which may require active querying beyond passive listening.
How so? They said they had no system for direct access, and indeed PRISM is apparently not a system for direct access. They said they hadn't heard of PRISM, but it's at least quite possible that they weren't familiar with the NSA's "PRISM" moniker, as opposed to the system itself.
[1] http://guardiannews.com/world/2013/jun/08/nsa-prism-server-c...
If PRISM means the NSA has unsupervised access to any records they want from these providers, that's pretty disturbing, irrespective of word-games over the meaning of 'direct'. The scope for abuse of this sort of unregulated access rubber stamped by a secret court is huge, and there doesn't appear to be any effective supervision as people like clapper are happy to lie to congress about the extent and methods of the various surveillance programs, and the companies are obliged to lie about the program and conceal its existence.
>The presentation claims Prism was introduced to overcome what the NSA regarded as shortcomings of Fisa warrants in tracking suspected foreign terrorists. It noted that the US has a "home-field advantage" due to housing much of the internet's architecture. But the presentation claimed "Fisa constraints restricted our home-field advantage" because Fisa required individual warrants and confirmations that both the sender and receiver of a communication were outside the US.
>"Fisa was broken because it provided privacy protections to people who were not entitled to them," the presentation claimed. "It took a Fisa court order to collect on foreigners overseas who were communicating with other foreigners overseas simply because the government was collecting off a wire in the United States. There were too many email accounts to be practical to seek Fisas for all."
http://www.guardian.co.uk/world/2013/jun/06/us-tech-giants-n...
No matter what checks and balances the US may employ to make sure legitimate access stays within bounds, any time you have an automated system, you're open to the possibility that someone can get access and automate it in ways you don't like.
Intelligence Fusion Center Collection Manager
Requires proficiency with PRISM, RMS, and Coliseum and Top Secret clearance, amongst other things.
No it wouldn't. You'd be after the things Chinese spies are already after: trade and military secrets. They don't care who's calling who.
China's also known for doing indirect attacks, where they try to compromise one system in order to get clues on how to compromise another. Having access to PRISM, depending on how it's implemented, would potentially open up access to all sorts of information collected by American tech companies. Heck, if they had access to social-graph data, they could determine who is friends with a lot of employees of the targeted company, and that would be a likely person to try to mine for trade secrets.
China is demonstrably interested in this. When they broke into Google's network, they went straight for the private emails of Chinese dissidents. (With, apparently, much less success than they would like.) When they broke into the NY Times, they went looking for any information about dissidents that the NY times might have.
From the sounds of it, access to PRISM gives them that, all nicely gift wrapped and correlated with other signals of interest, tools to locate known associates, etc.
Why are they interested in this? The Chinese leadership apparently do not see a war with the USA as their top risk. (Though they do prepare for the possibility.) That is because they know that the USA is not in the habit of lightly invading nuclear powers which could easily level multiple US cities in retaliation. But overthrow by revolution is something they are terrified of, with good cause.
But don't blame the companies involved. They're following the law, as laid down by duly-elected representatives. The alternative is that their executives go to jail for contempt of court.
What now?
Data mining exists at every company because of its value.
I'm much more concerned that private companies (Lexis Nexis I'm looking at you) have access to so much of my data and have no obligation to inform me of what data they have.
The US government exists to protect the United States and its citizens. If we put left vs right politics aside, why is there inherit distrust of the government? What would make you trust them? More transparency?
If anybody is to blame it is congress. As elected representatives, they should have ultimate responsibility as to what happens in this country. They should also be held liable for ALL of their actions, but good luck getting them to approve that. How can congress enact laws that only affect themselves or give them more power? That is corruption and should be considered treason.
The US government can throw me in jail, private companies cannot. The US government can sick the IRS, FBI, and Secret Service after me; private companies cannot.
Congress has a lot of the liability, but so does the President. Read up on FDR's use of the IRS and what happened to the various Tea Party groups in 2010 with 501(c)4 status[1]. This is why the expansion of federal government reach is feared.
1) someone will argue about the nature of 501(c)4 so just remember that Obama's reelection campaign relaunched as one to advocate for his political agenda for his 2nd term.
> In my opinion, that is just another loophole that needs to be closed, same as religious organization tax exemption
Regardless of your wish to close loopholes, the current law needs to be followed: equally and fairly. Going back to how taxes should work is a side trail and not relevant to how the government has acted against different parties.
The incentives of private companies tend to be fairly transparent, and they can be replaced (not necessarily easily) when no longer aligned with the welfare of the public. The incentives of the government are not nearly so transparent, and there is no escaping them. That makes many people quite wary of the government.
(That said, yes, more transparency would make me much more inclined to trust them.)
I hate the idea of prosecuting whistle-blowers. On the other hand, I definitely realize the importance of protecting national secrets and information in an ongoing investigation.
In my mind, it's not a battle between the US govt and its citizens, this is a battle between nations. Some activists, political party supporters, extremists, criminals, and innocents might be targeted/embarrassed/prosecuted by these programs, that that is not only unacceptable, but disgusting. The US govt simply cannot be as transparent as citizens would like it to because information is available globally. We do still have a significant amount of room to allow for transparency in the govt and we are slowly (too slowly) working on it, but please understand that SIGINT and foreign relations is complicated as shit. The US has it's nose in every other countries business, they befriend questionable sources for information, they deceive (can't deceive another country without deceiving our own citizens), and they do what it takes to maintain world stability and US dominance in all areas (economic, information, military, "freedom").
I don't know of an easy fix-all solution. Online voting might help, that would remove power from congress and give it back to the people.
What's to stop them from classifying... say .... computer hacking... as a threat to National Security?
1. NSA goes to Facebook and tells them to install a server/rack in their data center. The server needs to be on a port that can "see" all traffic unencrypted. The servers then transparently record data and analysts on the backend parse it into something useful.
2. NSA puts servers on premises but instead they are pushed formatted feeds of data. This would require them to work more closely with the company to make sure they provide a feed that is workable. They would store the data and as requests for data came in the server would feed it back.
The NSA has been in the IT security game for a very long time, they employ the best of the best, and have practically unlimited funds. I'd imagine that very complicated algorithms determine who to monitor and what keywords to look for. Images from the middle east or a VPN are likely more heavily analyzed than images from a college campus inside the US.
Why set up shop at specific social media companies when they have physical access to backbone routers and root certificate private keys?
Yes, it would be easier to just ask FB/Google/Apple to give them unlimited read access to their databases, but that would be a scandal waiting to happen.
The slide with the explicit formulation was published, written by NSA, that made claims of "not inside companies" much less believable:
"Collection directly from the servers of these U.S. Service Providers: Microsoft, Yahoo, Google, Facebook, Paltalk, AOL, Skype, YouTube, Apple."
This supports the claims of Glenn Greenwald's article and is exactly what companies claimed not existing.
Read the slide: they explicitely name the collecition on the "fat pipes" under other code names. As they have the access to the big pipes, the real time data (c.f. the other slides, earlier) from the inside of companies is certainly unencrypted.
"Never attribute to malice that which is adequately explained by stupidity." --Robert Hanlon. Despite the duplicitous and overly narrow statements about PRISM that skirt the truth, there's no reason to suggest they are all overtly lying, when a much simpler explanation is that some NSA employee overstated their technical capabilities on an internal powerpoint.
> Until this week’s reports, we had never heard of the broad type of order that Verizon received—an order that appears to have required them to hand over millions of users’ call records. We were very surprised to learn that such broad orders exist. Any suggestion that Google is disclosing information about our users’ Internet activity on such a scale is completely false.
It would also be hard to square Microsoft's statement that
> In addition we only ever comply with orders for requests about specific accounts or identifiers.
http://www.microsoft.com/en-us/news/Press/2013/Jun13/06-06st... with compliance with a Verizon-style broad order.
http://www.wired.com/threatlevel/2011/04/fourth-amendment-em...
"As the law stands now, the authorities may obtain cloud e-mail without a warrant if it is older than 180 days, thanks to the Electronic Communications Privacy Act adopted in 1986."
Your link is broken, should be: http://www.guardian.co.uk/world/2013/jun/08/nsa-prism-server...
Now, what do they do with it? The guardian is claiming that 77,000 reports have referenced PRISM but it is also the name of an internal accounting program (http://www.dot.gov/individuals/privacy/pia-prism)
We have a long way to go with this NSA issue. I believe that they are a great agency but have a very difficult job to preform, and unfortunately their mission sometimes requires questionable actions. They're powerful enough to make anything they want legal retro-actively, which isn't necessarily a good thing.
Many people assume that the NSA has been "spying" domestically for decades, because it's arguably necessary in order to sufficiently protect the country. I love technology but am already tired of this debate. You are not going to prevent the NSA from data-mining, end of story.
The Federal Aviation Administration's "PRISM" is obviously not the one discussed now in public, and not the one ending in the reports to the president. I invite everybody once again to read the Post and Guardian, they obviously have so much material and try to post only as much as to make the public aware of the legal aspects of the system: the blanket special court orders, allowing companies not to do anything, not even track what is being requested, the orders valid for months and practically automatically renewed. It is "legal."
http://www.guardian.co.uk/world/2013/jun/08/nsa-prism-server...
"PRISM allows “collection managers [to send] content tasking instructions directly to equipment installed at company-controlled locations,” rather than directly to company servers. The companies cannot see the queries that are sent from the NSA to the systems installed on their premises"
"From their workstations anywhere in the world, government employees cleared for PRISM access may “task” the system and receive results from an Internet company without further interaction with the company’s staff."
Now we know why they phrased their statements so specifically.
[1] http://peterhassett.tumblr.com/post/52499296411/exclamation-...
If you want to find problems with the various companies' responses, you sure can. I am positive things have happened with Google, Microsoft, Yahoo, Apple, etc. and the government that most people would find offensive. But playing semantic games that push particular agendas without the full story is misleading and imprudent.
(Of course Yahoo! isn't volunteering information, that is not concern at all, if the NSA demands then its not volunteering information)
The issue is that all the PR from Facebook, Google and Yahoo! are using very specific non-broad language to say they are not doing a very certain thing, a thing that is not the concern. The concern is about lawful access to all servers and not one piece of PR said this was not happening.
(In the current definition everything the NSA is doing would be considered lawful as the Government post 9/11 is able to use its various provisions to allow for a whole manner of things that we might disagree with, but we are not writing the law, they are.)
That's the problem with all of these statements. They're very specific with their language.
Intelligence community sources said that this description[direct access], although inaccurate from a technical perspective, matches the experience of analysts at the NSA. From their workstations anywhere in the world, government employees cleared for PRISM access may “task” the system and receive results from an Internet company without further interaction with the company’s staff.
So they get data from an ad-hoc query without interaction with the company's staff. And yet it is not direct access? I've read the other back-and-forths but I'm still not sure what this could even trying to imply.
Edit: and read - According to a more precise description contained in a classified NSA inspector general’s report, also obtained by The Post, PRISM allows “collection managers [to send] content tasking instructions directly to equipment installed at company-controlled locations,” rather than directly to company servers. The companies cannot see the queries that are sent from the NSA to the systems installed on their premises, according to sources familiar with the PRISM process.
But that the meaning is no more clear. Or the meaning is, we buy an "indirect access cable at Best Buy and so everything is OK", ie, the distinction is nothing but word games.