> What does that mean? Does the company have any oversight over what's being requested? It doesn't sound like it. How does that square with the statements from the CEOs that each request is carefully considered and restricted?
This was covered yesterday, in the NYT article http://www.nytimes.com/2013/06/08/technology/tech-companies-... :
> The data shared in these ways, the people said, is shared after company lawyers have reviewed the FISA request according to company practice. It is not sent automatically or in bulk, and the government does not have full access to company servers. Instead, they said, it is a more secure and efficient way to hand over the data.
So, it seems, there are Google-lawyer mechanical Turks clicking "OK" or "Contest" (or whatever) for each FISA order in the Google FISA-order queue. If the lawyer clicks "OK" it seems the requested information is slurped automatically from the Google user-data servers into the PRISM server's outbox (and/or a live data feed is set up). If the lawyer clicks "Contest" then presumably something messier and more manpower-intensive happens. A system like this raises plenty of questions - but it doesn't at all automatically conflict with or falsify what the tech CEOs said.
EDIT: Actually there's apparently a direct conflict between the NYT's version and what WaPo appears to be saying here:
> According to a more precise description contained in a classified NSA inspector general’s report, also obtained by The Post, PRISM allows “collection managers [to send] content tasking instructions directly to equipment installed at company-controlled locations,” rather than directly to company servers. The companies cannot see the queries that are sent from the NSA to the systems installed on their premises, according to sources familiar with the PRISM process.
That seems to imply that there's no Google-lawyer mechanical Turks reviewing the individual FISA orders. Given that that would contradict both the NYT report and the statement from (for example) Page and Drummond http://googleblog.blogspot.ie/2013/06/what.html this is a big deal. Given the WaPo's demonstrated ability to misunderstand information from NSA sources, for the moment I'm inclined to assume that the Post has got this wrong, too - but let's see. (Another possiblity might be that some companies are waving FISA orders of the form "give us the personal data of Suspect X" through automatically, while others still have a lawyer clicking "OK".)