The Guardian walks back claims of direct NSA access to servers of tech companies
mediaite.com
mediaite.com
Someone on Twitter (sorry) said that Google and Facebook "looked like angels" compared to Verizon. That sounds about right to me, too. But what incentive do they have to do that when their reward is conspiracy-theoretic nonsense about how NSA has their TLS keys and 3rd party contractors are used to keep them from "lying" when they say NSA has no direct access?
There's definitely some extreme speculation going on--both from those trying to maximize as well as those trying to minimize this issue. It will take some time to get to the truth. This article is a perfect example of an extreme attempt to minimize this issue.
This article seeks to minimize the Guardian's original story by saying the Guardian is "walking back" their claims. That doesn't seem to be the case. This article cites a paragraph near the end of a minor story published days later as the passage where they "walk back" their original story. The intent of the paragraph seems to be to illustrate that both the "direct access" claim from the NSA and the "no direct access" claims from tech companies can both be true. The original article doesn't seem to be changed.
Beyond that, the Guardian never claimed the NSA had "direct access". They claimed that the NSA slides stated the NSA had direct access. The Guardian has not stated they read too much into "direct access" in the slides, and the original article is pretty clear that "direct access" is simply the NSA claim in the slides, not the Guardian's verdict.
There is another remaining issue: the original article claims access to "live communications", which has yet to be supported by a slide, but it would pretty much rule out the SFTP-only possibility that some people seem to be accepting as fact at this point. Maybe there is direct access to live information from Skype and Apple, but Google insisted on SFTP? We still have a lot to find out.
It could be that the Guardian did exaggerate. But it is far too early to conclude that with so many questions remaining. Not all the companies have described their systems.
One thing is certain: the Guardian does not seem to be walking back their claim.
This separate article covers the story that the original article broke. This paragraph in the article gives an attempt to reconcile the competing claims from the NSA and the companies. What makes you say this attempt should invalidate the original story?
> When the FAA was first enacted, defenders of the statute argued that a significant check on abuse would be the NSA's inability to obtain electronic communications without the consent of the telecom and internet companies that control the data. But the Prism program renders that consent unnecessary, as it allows the agency to directly and unilaterally seize the communications off the companies' servers.
As soon as people suggested that "collection directly from the servers" actually meant a FISA workflow-automation system involving an API and maybe dropbox servers, Glenn Greenwald indignantly denied, or maybe didn't understand, the possibility that the companies' statements could actually be compatible with the PRISM document https://twitter.com/ggreenwald/status/343421926057861121 https://twitter.com/ggreenwald/status/343422182589870081 https://twitter.com/ggreenwald/status/343423399609131008 https://twitter.com/ggreenwald/status/343423727066824705 . Meanwhile both the Washington Post and the Guardian started backing down from the NSA-has-root idea. The paragraph WaPo added to its original story
> It is possible that the conflict between the PRISM slides and the company spokesmen is the result of imprecision on the part of the NSA author. In another classified report obtained by The Post, the arrangement is described as allowing “collection managers [to send] content tasking instructions directly to equipment installed at company-controlled locations,” rather than directly to company servers.
plus the later story it printed http://www.washingtonpost.com/world/national-security/us-com... both help to make clear that the Post did intend its original PRISM story to be understood as NSA-has-root.
"But the Prism program renders that consent unnecessary, as it allows the agency to directly and unilaterally seize the communications off the companies' servers" is a strong statement. I agree that it is probably not compatible with the details Google has divulged about its "SFTP and manually by human only" process. But that is only one of the many companies.
I understand the "slides or GTFO" attitude that I'm seeing in these claims that the original story is inaccurate, but I think it's a bit arrogant and premature. A journalist who has seen the entire slide deck continues to tell us that the nature of what the whole presentation reveals is more invasive than a digital lockbox with workflow management software where humans meaningfully verify, evaluate, and approve requests. He could have misinterpreted the slides, but I doubt he would stick to the report so steadfastly once all these objections arose if he were not pretty confident he understood the claims in the Prism presentation.
We shouldn't accept that the NSA can grab a user profile without explicit, individual legal approval from the company as fact yet--there's a lot more we will hopefully learn. And how true this is could vary from company to company. But it's silly to ignore that a credible voice who has seen the presentation is telling us something.
One is that AFAIK the Guardian and the WaPo both have access to all the same materials Greenwald has, and they have both been backing away from the NSA-has-root claim for some time. But an even bigger factor is how Greenwald defended his claim. If he'd said "there's still-unreleased material which proves me right, hold tight" that would be one thing. But instead he quoted the "collection directly from the servers" text and linked the new slide it came from, implying that the quotation unambiguously ruled out the drop-box/API interpretation and supported the NSA-has-root interpretation. But in fact "collection directly from the servers" is not at all unambiguous between the two interpretations. And even worse, the You Should Use Both slide, which Greenwald produced as his trump card, provides context which clearly undermines the NSA-has-root interpretation! In that slide it's clear that "collection directly from the servers" is being contrasted with upstream collection of IP data from the telcos. The fact that Greenwald evidently didn't pick up on this himself is pretty clear evidence that his understanding of the presentation is imperfect, whether because it's being distorted by his desire for a bigger and more damning scoop or just impeded by a lack of technical savvy.
The truth that has spread around the world is that there is a surveillance system in the US which spies on Americans.
If you feel journalists have misinterpreted the capabilities of the system, feel free to call the PRISM hotline for clarification and tell us what you find out.
"The National Security Agency has obtained direct access to the systems of Google, Facebook, Apple and other US internet giants, according to a top secret document obtained by the Guardian."
They're not any less guilty than other papers, though. "Categorical statement, according to Source" is a common construct in journalism. But I don't like it, because it de-emphasizes the uncertainty in the statement. Reversing the phrases would put the correct emphasis, I think.
I suppose you could say that some of the statements are speculative in that they say "if the claims in the Prism presentation are true, then...", but I think that's speculative in a very narrow way. It makes sense to draw out possible consequences of the program as expressed in the source material that are rooted in fact and not in speculation.
The article is definitely not speculative in the dangerous sense; it does not say things like "direct access probably means root access to production servers" or "since this program costs only $20 million it's likely to keep growing".
It does make claims we have not yet seen evidence for, but there's no indication they're speculative...
http://media.hotair.com/wp/wp-content/uploads/2013/06/prism-...
This is not a reasonable position for anyone with a technical background. Because anyone with such a background should surely realize that the two statements are not mutually exclusive, and there are plenty of ways for data to be collected which the NSA might reasonable categorize as "direct" while leaving Google with plausible grounds to categorize as "indirect" or otherwise deny knowledge of.
And let's go back to a quote in this article, which seems to have been edited since I originally read it: http://www.washingtonpost.com/world/national-security/us-com...
“The server is controlled by the FBI,” an official with one of the companies said. “We do not offer a download feature from our server.”
Well. Now what?
It's easy to see how this sentence, in light of the entire "dropbox" thing, means that NSA grabs data directly from the "dropbox" set up and operated by the company.
There is ambiguity and room for interpretation in almost all language, especially the vagueness of a Powerpoint presentation.
the "direct collection" is a part of "FAA702 operations". The FAA702 is unrestricted collection of data of "non-USPER"sons, and in particular no individualized FISC orders required.
Now there is a choice - either Google combs their data, decides who is FAA 702 "eligible" and of interest to NSA and dumps the "non-USPER" data it has identified to the "dropbox" or the NSA does the combing/identifications itself (and if NSA does the combing - where it does it? on NSA servers attached to Google datacenters or does it transfer all data to NSA datacenter and combs it there?). What do you think NSA has chosen?
doesn't sound like it. 2nd slide:
http://www.aclu.org/files/pdfs/natsec/faafoia20101129/FAAFBI...
500K pales in comparison with all the tens (or even hundred) of millions in this _one_ FISC order
http://www.guardian.co.uk/world/interactive/2013/jun/06/veri...
Again, for FAA 702 collection no individualized FISC required. 1 order for the whole Facebook, 1 order for whole Google, ... it seems that NSA does really need that server farm in Uta.
> http://www.guardian.co.uk/world/interactive/2013/jun/06/veri....
> Again, for FAA 702 collection no individualized FISC required.
That's not a FAA 702 order though. In fact it's in a different category to all the 70* orders, which fall under the "electronic survellance and/or physical searches" category in the https://www.fas.org/irp/agency/doj/fisa/2012rept.pdf annual report. The Verizon order would be a FAA 501 order, though people only ever seem to refer to it as a 50 USC § 1861 order. They're the "Applications for Access to Certain Business Records (Including the Production of Tangible Things)" on the annual report. These orders seem to be intended for things like the Verizon metadata, which it seems (IANAL) are considered to be unprotected by the probable-cause requirement even for USPERS. So I presume a 501 order couldn't be used to grab users' full private data from Google. In any case Google has denied that it has ever complied with http://www.wired.com/threatlevel/2013/06/google-uses-secure-... (or even been served http://googleblog.blogspot.ie/2013/06/what.html ) any order nearly as broad as the Verizon one, and Facebook and MS have more or less followed suit.
http://www.dailydot.com/news/us-immigration-german-au-pair-f...
This seems to be the entire issue to me with PRISM - whether it's an unprecedented level of access or merely a statement of what has known to have been going on, and what was covered under FISA, for years, but just in a more technically expedient manner.
http://media.hotair.com/wp/wp-content/uploads/2013/06/prism-...
Especially given the fact that the leaked documents specifically encourage analysts to use a range of tools (i.e. "You should use both"), he has no technical grounds for suggesting that such a minor semantic debate (between NSA and Google) discredits the claims of multiple people with first-hand experience of the NSA who are coming forward with claims of its abuse of power.
That deck was put together by a mid- to low-level government program manager who owned the program. He is playing politics, making his program sound like the most awesome thing EVAR so he gets promoted. It's not an "official" document, despite all the fancy markings.
You cannot interpret every word as gospel.
The interpretation wasn't extreme, it was literal. What it looks like is that the NSA claimed to have direct access while the denials that have been make it seem like they indeed might not have it.
The thing is that the NSA said they had this kind of power to someone, in a power-point presentation. They have said that they wanted it. And the regime of secrecy today makes it extremely difficult to determine for certain what they do and don't have.
I mean, if the NSA director was being truthful to congress in saying they weren't systematically spying, he's being very coy now when confronted with apparently contradictory evidence. Possibly, like many secret bureaucracies, the NSA was as wedded to telling someone, likely a high official, that they were ubber-powerful, and were by the token, attached getting the direct access even if they indeed currently lack it.
I mean, I think the NSA is discovering the weakness of secret approaches - that it makes all denials and all limits implausible. Hopefully, this will force a situation where all the "secret laws" and such get done away with.
The exact quote is "Collection directly from the servers of..."
This - depending on say, the context and narration, can mean any number of things and considering the intended audience and what PRISM actually is, would've meant "we collect this data that's stored on Google's servers" rather then perhaps "we seize individual computers" or wiretap the information some other way.
Which is a pretty obvious way to interpret those slides! But of course this is the NSA - clearly the first thing we must to is ignore the simplest explanation and start proposing hardware backdoors in Intel processor instead.
Why is this tidbit such a big deal to you? I think you have unrealistic expectations.
Have you ever tried to get a story published in the "mainstream" media?
I've done technical writing. I also spent years explaining my pet issue to journalists, reports, policy makers, other lobbyists.
It's a miracle if the message gets thru mostly correctly.
You ever read a story about topic in which you're an expert? Then you know the press never get the story completely "right".
Even if lawyer Greenwald understood what computer expert Snowden was trying to explain, he'd still have a hard to time running that explanation past his editors. And I'm absolutely certain that whoever is reporting tried to explain novel ideas using layperson's language.
My problem is with people who appear convicted of the idea that Google's leadership are conspiring with NSA to deceive its customers, or that NSA is employing exotic and outrageous methods (like optical signal intercepts --- it's right there in the name Prism!), or that Palantir is somehow involved in Google-related surveillance, or that NSA is "disappearing" people... the list goes on and on.
I have a problem with the idea of conversations on HN reifying speculation that Google or Facebook are defrauding their customers; I also have a problem with bullshit stories clouding the very real problems we do have with overreaching surveillance.
I understand your frustration, but I think you're attacking the signal instead of the noise you're talking about.
There's definitely a lot of nonsense floating around (optical signal intercepts from these providers, etc.). This is noise.
But there is also a very real signal. A journalist with an inside source is telling us about a program that indicates some of these companies have given the NSA a level of access than most of us who know anything about systems would not be comfortable with.
While the degree to which this is happening has not been supported with evidence, numerous other claims have been. It has already forced the declassification of orders to the phone companies. This seems to be a very credible source.
Instead of attacking the noise, I see you attacking the signal. You're saying "These companies could not be doing this! Why would you believe someone saying they are!"
Maybe there is no such program, maybe the NSA doesn't even know what it's doing enough to make an accurate presentation, maybe the presentation was planted for the guy to find, and maybe the journalists are hacks. These are all possibilities. But with what we know, these are the extreme possibilities, and speculation about them is mostly noise. Defending hack-job articles attacking the source and messenger isn't increasing the quality of the conversation.
It seems that from what we're getting from the government and companies, we're getting closer to answers, but we're not there yet.
If the question you're raising is about the nature of the Prism program, I am very much looking forward to an answer to that. But I think the best approach is to see the evolution of responses from government and companies rather than smear the journalist as a hack for not immediately releasing the whole presentation.
To be fair, no one actually said Google and Facebook are defrauding advertisers
Agreed. For future, I encourage you to state your objections plainly. Like this (above). And perhaps focus on the issues, facts, details and less about the players.
http://en.m.wikipedia.org/wiki/Room_641A
All the pennies (and beam splitters) have yet to drop. I would be shocked if the NSA wasn't coupling company cooperation with direct packet inspection/backbone wiretapping. They could even use the FISA requests as training data under some scenarios to help reverse engineer protocols.
You really want to bet that there is nothing more to see here, that more Room 641As don't exist? As for "conspiracy-theoretic-nonsense", a hidden conspiracy to wiretap hundreds of millions of Americans (derided as a "myth" by the NSA lawyer Rajesh De and lied about in front of Congress by Clapper) was just revealed -- because a man risked his life and freedom to leak the first FISA order in 35 years. Given that senior government officials are actually admitting in realtime to past untruths, it might be a good idea to be a wee bit less credulous when it comes to our government overlords.
The NSA is tapping undersea cables and sucking up e-v-e-r-y-t-h-i-n-g that crosses them AND getting data through court orders and national security letters AND getting all phone metadata from all phone companies AND tapping into the backbones at appropriate places and sucking up everything that crosses those places AND listening in to every satellite communication AND......
It's AND, not OR.
Simple terms. If either of those two points come to light (NSA backbone taps of Internet companies or clandestine NSA/IC operatives planted in Internet companies, perhaps in foreign subsidiaries of the same) you publicly post that you were wrong/credulous and the "conspiracy theorists" were right.
After all, if the FBI infiltrated [2] the unimportant KKK, the US government definitely has an incentive to infiltrate the all-important Google.
[1] http://www.wired.com/threatlevel/2012/03/ff_nsadatacenter/al...
Former director of the NSA’s World Geopolitical and
Military Analysis Reporting Group, William Binney, has
estimated that 10 to 20 such facilities have been
installed throughout the nation
[2] http://www.fbi.gov/news/stories/2010/october/kkk_102910/kkk_...And who even knows what the NSA's "lawful charter" is? Secret interpretations of laws (meaning secret laws) evidently mean it's ok for them to capture the phone records (and, as reported, credit card statements) of everyone. They lie about what they are doing under oath and they hunt, jail, and kill those who tell the truth.
They prevented these unconstitutional secret interpretations of the law from getting to the courts or to the public. That's the only reason why they haven't been struck down.
I responded, "tapping overseas cables is NSA's stated mission, and so it doesn't follow that they're tapping domestic communications".
You responded that of course they're exceeding their legal bounds, because the Fourth Amendment restricts them, which of course begs the question.
"tapping overseas cables is NSA's stated mission, and so it
doesn't follow that they're tapping domestic
communications".
http://bigstory.ap.org/article/secret-prism-success-even-big... Deep in the oceans, hundreds of cables carry much of the
world's phone and Internet traffic. Since at least the
early 1970s, the NSA has been tapping foreign cables. It
doesn't need permission. That's its job.
But Internet data doesn't care about borders. Send an email
from Pakistan to Afghanistan and it might pass through a
mail server in the United States, the same computer that
handles messages to and from Americans. The NSA is
prohibited from spying on Americans or anyone inside the
United States. That's the FBI's job and it requires a
warrant.
Despite that prohibition, shortly after the Sept. 11
terrorist attacks, President George W. Bush secretly
authorized the NSA to plug into the fiber optic cables that
enter and leave the United States, knowing it would give
the government unprecedented, warrantless access to
Americans' private conversations.http://thehill.com/blogs/blog-briefing-room/news/305047-dem-...
So if PRISM is just the tip of the iceberg, what method do you suggest for speculating as to what exactly they are doing domestically? Maybe, say, look what they are doing overseas?
Day 1: We see some out of context powerpoint implying Google, Facebook, et al. have given the NSA full access to private info.
Day 2: We find out that wasn't true at all.
Days 3+: We keep filling HN with articles about how awful it is that Google, Facebook, et al. gave the NSA full access to private info.
The tech media really dropped the ball on this one. It's absolutely insane to think all of the CEOs who said they'd never heard of PRISM or given the NSA any special access were lying. The CEO of a large publicly traded firm would be taking a huge risk and be certain to be caught for such bold-faced lies.
It reminds me of a great joke Stephen Colbert told about George W. Bush at the White House Correspondent's Dinner. Paraphrasing: "he'll think the same thing on Wednesday that he thought on Monday, no matter what happened on Tuesday."
"In 2006, USA Today published an article that revealed that Verizon, AT&T and BellSouth (since acquired by AT&T) were voluntarily providing the NSA with millions of call logs. It also said another landline provider, Qwest (since acquired by CenturyLink), refused to hand over logs without a warrant, and that the NSA had rejected Qwest's insistence that the matter go before the FISC.
In 2007, former Qwest CEO Joseph Nacchio was convicted on 19 counts of insider stock trading. During an appeal, Nacchio's lawyers claimed the charges were retaliation for Nacchio's refusal to go along with the warrantless surveillance program while he ran Qwest."
http://www.technewsdaily.com/18302-national-security-agency....
Just like it's a pure coincidence, of course, that of all the people out there hiring escorts, Elliot Spitzer gets rumbled.
Edit: and by the way, it was a jury trial. So not only was the SEC acting on behalf of the NSA, and the judge who sentenced him, but so was a 12 person jury. That's more believable.
How is it an "extreme interpretation" to read that as something "direct" is likely to be happening involving "servers of these U.S. Service Providers"?
Why should we bend over backwards to convince ourselves that what they really meant (but didn't say) was that they had indirect access only through intermediate layers of privacy-preserving systems that we architect from whole cloth in our own imagination?
Snowden's rationale is that he was in a position to understand exactly what was going on and that he leaked because he felt it was necessary for the public to know what he knew. Snowden himself contrasted his situation with Manning - he pointed out that Manning leaked hundreds of thousands of documents indiscriminately without possibly being able to read them all or understand their consequences or the risks and benefits involved in leaking them. Snowden said that, by contrast, he was very selective in what he leaked and he understood the issues completely.
But if one of the most serious claims that Snowden is making is wrong, it calls into question whether Snowden really had the knowledge that he claims he had.
Snowden's undoing may be trying to have the baby half way. People are really pissed off about this and are going to be looking for someone to blame. I wonder if he's going to end up looking even worse than Assange in the end by assuming personal responsibility for the effectiveness of the selective editing and redaction.
Personally, I don't feel like the weight of this story turns on the specifics of the interception hardware and the "directness" of the access. There's a slide deck that says "Dates when PRISM collection began for each provider" and "Collection of communications on fiber cables and infrastructure as data flows past". And that's just the four slides that The Guardian and WaPo didn't feel were too hot to handle.
What does it matter which server establishes the socket connection?
I wrote the backend for the exchange of electronic medical records. We used numerous protocols: scp, ftp, http, etc. And numerous formats: csv, hl7, xml, etc. We had numerous partners: pharma, labs, hospitals & clinics, EMTs, CDC, etc.
In all cases, I'd feel comfortable saying we had "direct access". Because in all cases, the audience of doctors, nurses, execs, admins knew enough to make policy decisions.
Would you drop this chew toy if the Guardian had written "near realtime live data feed"?
I'm willing to bet that the truth lies somewhere in between all of this, and that Snowden and Page can both be standing near the truth, leaving the administration and NSA out in the cold.
If the people freaking about "direct access" think it's wrong, I'd very much like them to correct the record.
tptacek? Care to explain precisely how the NSA slurps up all the data?
?
I'd like to think you are more intelligent than this, but the only real other option is that you are trolling, and neither are attractive or plausible.
"Our story was written from the start to say NSA claimed this, telecoms deny-we wanted them to have to work it out in public what they do. We reported - accurately - what the NSA claims. We reported - accurately - what the companies claim. It conflicts. That's why we reported it."
https://news.ycombinator.com/item?id=5845649
edited to be less conclusive
"The National Security Agency has obtained direct access to the systems of Google, Facebook, Apple and other US internet giants, ___according to a top secret document obtained by the Guardian___." (Em mine)
This is text from the message of yours which you are linking to here. It agrees with the quote bstrand provided.
Complete paragraph quote. Both claims in the last sentence --- that NSA has direct access, and can unilaterally sieze comms off servers --- now appear to be true, so much so that the Guardian itself is now walking them back.
The deck identified specific providers as on board or coming on board. Their denials looked similar. The deck characterized access as "direct"--direct in some context. As a wordsmith yourself, you certainly recognize such semantic fuzz, the loose context-dependent coupling of sign and signified.
And yet, you collapse the possibilities down, giving credence to authority. You cast scorn and ridicule, you narrow the bounds of respectable opinion with language like "extreme interpretations" and "conspiracy-theoretic nonsense".
One cannot have an informed opinion on a secret program. The harder you try, the more vulnerable you become to information censoring. Try the holistic approach, and reserve judgement.
I'm not the only person with these concerns. Here's Karl Fogel of QuestionCopyright.org:
http://www.rants.org/2013/06/11/epic_botch_of_prism_story/
And here's Mark Jaquith of Wordpress:
Because you are responsible for your opinions. What other people say is orthogonal to your own exercise of judgment. /schoolmarm
If they were innocent, we'd expect their denials to look similar. So why are so many people taking their denials looking similar as indicating guilt?
Isn't this a misdirection?
Personally, I believe there is a possibility that the name PRISM itself is an allusion to the method of data slurping the NSA has been using. Where there are plenty of articles talking about their fiber splicing actions etc...
I take PRISM to mean they were taking streams and were able to focus on a particular 'wavelength' in the stream and mirror it to their own systems.
I don't think they had "direct" access to FB systems - even though there are plenty of former CIA/SS/Military (and potentially NSA moles) already openly working as actual employees of FB - I don't think they necessarily needed full and direct access - the NSA taps the ISPs directly.
What I want to know is how much of that signal are they (a) storing indefinitely, (b) DPI or SSL decrypting, and (c) merely keyword analyzing. If they're storing it indefinitely and/or utilizing SSL MITM then we're pretty much done as far as privacy is concerned. But if they're just keyword analyzing cleartext packets then honestly who gives a shit.
My gut is telling me they're decrypting SSL. FB and Google moved to HTTPS everywhere a few years ago and they're clearly getting this data somehow so...
I think this probably nails it - but in reverse order:
They peel a stream off, keyword analyze it - in conjunction with other weights (i.e. who is talking, to whom, between where, what medium, when (i.e. the meta data)) and then they store the key ones.
If I am talking to my Grandma, the drop it. If I am talking to an unknown number in [foreign country] they test for keywords, if any are hits - they store it and add more meta-data.
I mean - the whole thing is what I understood the Mythical Project Echelon to be -- but there was never any concrete evidence of Echelon to the degree that it was rumored to be, until now.
Now we know that they definitely trap any packet they can wrangle.
The tech side of HOW they are seeing everything is inconsequential to the fact that they ARE seeing everything crossing the pipes.
The NSA requested all metadata from Verizon. That tells us something new.
What matters is how direct that access is. Does the government have to submit a warrant to get user-specific data, and then gets that data back in a drop box like system? Then there's nothing illegal, surprising, or even sketchy about that. Can the government get direct access to Facebook's servers without going through their legal department? Then that's a big deal!
It's indeed very sketchy that the NSA asks for the metadata of all the Verizon customers.
#define metadata DNA samples for breeding a clone armyGreenwald is our version of Richard Land. Not even interesting sociologically.
What we do know is:
Snowdon leaked slides showing a Boundless informant program to catalogue data - almost 3 billion records collected over the month of March 2013 just from US sources - that's a huge amount of data for an agency that doesn't have a remit to surveill Americans.
Every phone call in the US is now being recorded by the NSA - that is almost the biggest story here, since we don't know if they also tap email headers, which would probably be worse.
Oversight of the NSA and other agencies is impotent, and most of congress simply wasn't aware of even the broad scope of the surveillance, let alone details.
DNI Clapper lied to congress with impunity over surveillance of Americans, the NSA lied over not having counts of records.
The NSA's standards are incredibly lax (allowing this leak to happen - he shouldn't have reached the front door with this data), and their interpretation of their remit worryingly broad (extending to collecting at least phone (and probably more) metadata on every single American and company). If the IT tech Snowdon had access to all this data, other countries probably have it already by other means.
Snowdon leaked slides on PRISM claiming 'collection directly from the servers' - this was presented by Greenwald and the Guardian as a claim to be verified and contrasted with Google's denial of direct access (I feel both are probably true - the slide in a broad sense, and Google in a narrow sense). The quotemarks in Guardian articles are there to attribute, not to undermine the content quoted.
Snowdon claims to have had access to anyone's email at providers like Google without obstruction at his relatively high clearance level (unverified) - I think he wanted to point out the lack of supervision of the process (hence ref. to president's personal email), and the lack of interaction with Google staff - the truth of this claim has yet to be tested and various important points (how quickly, what supervision, what sort of data etc) are elided. I'd like to hear more from Snowdon and Greenwald (or the US gov) on this.
If you are truly interested in all the issues raised by these leaks, you should address those very real and serious topics, not minor quibbles over whether a journalist's interpretation of the technical details of a transfer of records is correct. I can see why people might have jumped to conclusions over 'direct access', and do feel it's important to get to the bottom of the real process (I'm sure Google would love to tell if only to put the wilder theories to bed), but the reality without that is bad enough - given the many other programs we know about, and the admitted details of PRISM/FISA requests. I was a bit dishearted by the initial Google response but am pleased they are now pressuring the government to release figures for FISA requests, so that people can see the extent of the program as it impacts Google, but this issue is about more than Google and Facebook and records they might return on the basis of FISA requests. That would help define the scope of one of the many programs.
That reality of broad surveillance without adequate supervision is enough to put people off doing business in the US or hosting data there, and the acknowledged facts are enough to make it very easy for an unscrupulous president like Nixon to turn the US into a surveillance state and capture all the levers of power very quickly - something that should worry all American citizens. That is what Snowdon was warning against (see the last part of his video), and that is the most insidious part of this sort of widespread surveillance unchecked by public law and public courts - not how it is used today, but what it might enable if it is allowed to continue.
I haven't heard this at all, from reading the top 10 stories on HN.
The facts are getting buried in the outrage about the facts.
http://www.guardian.co.uk/world/2013/jun/08/nsa-boundless-in...
and the secret Verizon order on phone records:
http://www.guardian.co.uk/world/2013/jun/06/nsa-phone-record...
although again this is unattributed and simply 'obtained by the Guardian', but the story was written by Glen Greenwald just before the Snowdon video, and I seriously doubt they have two sources with top secret clearance in the NSA.
And of course there are the assertions in his video, which I also consider a leak (though so far without details to back it up).
For all ordinary people, i.e., most of the world outside HN, the "access" part is the element that constitutes the scandal. "Direct" merely hints at the method, of which the details are considerably less relevant to most people than they are to us.
If the NSA had received the data via flash drives attached to carrier pigeons it wouldn't have made any difference to the core of the story.
It definitely doesn't make the story "a lie", at least not to anyone else but lawyers and techies.
What is a big deal is that my personal conversations and yours and your mother's are being recorded, read and stored to be used against us later. That is a big deal. Human rights. Civil liberties. Not living in constant fear. Those are the real issues.
Given that his suggestions are 100% speculation, I'd be willing to put any amount of money on the line that it's nonsense.
This is a data center designed to, supposedly, store data on the scale of a yottabyte. I only say "a" yottabyte, because to assume even slightly greater than that is sheer lunacy.
That is freaking massive. If you took all terrorist cells and all terrorist activity for the history of terrorism and terrorist activity, you would not even touch a fraction of a percent utilization. We're talking rain drops in the ocean.
There is no way the NSA is merely watching the bad guys here. The data center is a few magnitudes too large for such a task.
I would assume right now they are merely recording all data, in hopes that one day they will have technology to quickly crack encryption. However, even without knowing what is said (the content), the metadata of connections gives plenty of information on what people are doing.
and yes, agreed - analogous on so many levels - a publicly admitted places where secret government things happen, which can be invoked to give an aura of reality to conspiracy theories true and false alike.
Exabytes are eminently reasonable; yottabytes are not.
I expect these sizing claims (which presumably come from some sort of government statements about the facility) are based on a timeline on the order of ten years or more. A YB in 2024 is going to take a lot less physical space than a YB in 2014.
I tracked down what appears to be the origin of these yottabyte claims: http://www.nybooks.com/articles/archives/2009/nov/05/whos-in...
Based on that, it sounds like the yottabyte claims refer to raw, unprocessed data collected. Off the bat, I'm willing to believe in a 2 orders of magnitude decrease after data reduction techniques are applied to the raw data. My experience with data collected from telescopes was that we got about 100:1 reduction on the raw data versus what went into permanent storage.
The San Antonio site was news to me, though obviously no big secret since that book was published years ago.
We already know about Room_641A[1]
Most of the large-scale sites are doing SSL offloading, so one of the first things that happens is the traffic is decrypted. Often this happens in the front end load balancer.
If the set up is as the WP described:
> “collection managers [to send] content tasking instructions directly to equipment installed at company-controlled locations,”
and this equipment is installed behind the SSL offload devices, it would see all the customer data in the clear.
Perfect forward secrecy in TLS is a bit different in that the ephemeral diffie-hellman key exchange sets up a shared key that is protected from a _passive_ attacker that observes the TLS encrypted communication and later gets a copy of the server's public key.
http://en.wikipedia.org/wiki/Secure_Socket_Layer
For instance, on HN, Chrome is currently doing this:
Your connection to news.ycombinator.com is encrypted with 128-bit encryption.
The connection uses TLS 1.2.
The connection is encrypted using AES_128_CBC, with SHA256 for message
authentication and ECDHE_RSA as the key exchange mechanism.
Using ECDHE_RSA, my browser and HN's server will agree upon a key to use for encryption using AES128 in CBC mode. Now in order to read what the server sends me and what I send to the server, you need to break the crypto:1. Brute force the 128 bit key. This is.. probably not going to happen?
2. Via a weakness in the AES128 algorithm or implementation, you can simplify a brute force into feasibility (AFAIK, no such attack currently exists).
3. Via a passive attack on ECDHE_RSA, you could potentially guess the shared key efficiently and decipher our communications (AFAIK, no such attack currently exists).
So it's not quite as simple as recording encrypted information and obtaining the SSL keys. You need the server to actively remember the keys used for every encrypted connection, and obtain those, too. Or MITM everything and record the unencrypted data.
Although your post did bring up another question that I never thought about. Does Google even "send" email when it goes from one Gmail user to another? That could theoretically all be handled internally, but it never crossed my mind that they wouldn't use SMTP.
Looking at a random email in my Gmail account from a different Gmail user, it looks like they do use SMTP, or at least they are adding headers as if it went by SMTP. But both ends of the SMTP are at the same IP address:
X-Received: from mr.google.com ([10.229.72.135])
by 10.229.72.135 with SMTP id m7mr3900891qcj.17.1370903118607 (num_hops = 1);
Mon, 10 Jun 2013 15:25:18 -0700 (PDT)If you were in their shoes, had immunity, guys with guns, and billions of dollars, would you not find the weakest link and exploit it? For saving the children from terrorists, of course.
And I'm 80% sure that what it means in that context is that the source of the data received has no middleman. I.e. they pull Google's records straight from Google, not from a wiretap or SIGINT, just like for Facebook, PalTalk, etc.
Robert O'Harrow et. al.'s followon article from the Washington post had more details [2]
Intelligence community sources said that this description, although inaccurate from a technical perspective, matches the experience of analysts at the NSA. From their workstations anywhere in the world, government employees cleared for PRISM access may “task” the system and receive results from an Internet company without further interaction with the company’s staff....
According to a more precise description contained in a classified NSA inspector general’s report, also obtained by The Post, PRISM allows “collection managers [to send] content tasking instructions directly to equipment installed at company-controlled locations,” rather than directly to company servers. The companies cannot see the queries that are sent from the NSA to the systems installed on their premises, according to sources familiar with the PRISM process.
[1] http://www.guardian.co.uk/world/2013/jun/08/nsa-prism-server...
[2] http://www.washingtonpost.com/world/national-security/us-com...
FTP or direct acces, it makes no practical difference if the employee on the other end rubber stamps the requests when they get them. The real question is how much data can the NSA get and what procedures do they have to prevent the targeting of US person?
what checks does e.g Google actually run on the requests? If the procedure is email FISA@google.com and then some google employee rubber stamps it and sticks the data in an SFTP server, the NSA effectively has unfettered access.
Its clear that you don't need a warrant for targeting a foreign person, so the employee can't check that it came for FISC. Even if they did, FISC seems to be willing to rubber stamp things themselves. So aside from maybe checking if the account is typically accessed from a US IP, whats Google going to do? I pick on Google here specifically only because they have a reputation for trying to automate everything including a lot of customer support and I suspect that if they don't have any discretion on these cases, they may well have automated it.
Of course, maybe they didn't, maybe there are rigorous checks both at the NSA and at the receiving companies. But we don't know and we need to.
With direct access, they could have pulled everything.
In the case of Verizon/AT&T - the Government has everything, and, in the event of a new law/govt/executive branch - they would be able to do anything with the data they had already collected.
I was very concerned that US Govt had access had direct access to Google/Facebook servers. I'm not particularly worried about their ability to do authorized requests for user information.
Hopefully Verizon/AT&T will now transition to the same place as google/facebook are - having those entire databases of all telephone data is ripe for abuse, regardless of what claims they might make about safeguards are in place.
For example: "Our legal team reviews each and every request, and frequently pushes back when requests are overly broad or don’t follow the correct process."
Now what happens if the NSA issues thousands of those requests? They are not broad, they are for specific people.
As to following proper procedure, it appears rather strongly that secret procedures allows the NSA to request a hell of a lot legally and may not provide much safeguard for preventing abuse. We don't know because the procedures are secret.
Again, the companies in question appear to have little choice in the matter and that probably absolves them of a lot, but that doesn't mean the situation is ok from the view of what they were compeled to do.
Sure, google and facebook and whatever should push back, but it's clear that if the government really wants to abuse its power, they won't stop it. Given the current witch-hunt on whistleblowers, it's clear that those in power do not appreciate being questioned. Trust is fine, but verification is better.
However, I think you're focusing on the wrong party here - I think it's a lot more reasonable to request this of the government than of companies. There's no reason not to require the government to publish the general structure of what they're doing in great detail, and to let others make up their own mind if it's overstepping its bounds.
In short: I want an independent parties to have free access and be allowed to verify what's going on.
Google has specifically denied having a drop box facility:
"We cannot say this more clearly—the government does not have access to Google servers—not directly, or via a back door, or a so-called drop box."
https://plus.google.com/+google/posts/TMh6gUVrwMq
Among other features WashPo specifically describes live interception which would require more sophisticated integration than a mere drop box facility:
"Google’s offerings include Gmail, voice and video chat, Google Drive files, photo libraries, and live surveillance of search terms."
http://www.washingtonpost.com/investigations/us-intelligence...
Not to mention NYT's independent source:
"In one recent instance, the National Security Agency sent an agent to a tech company’s headquarters to monitor a suspect in a cyberattack, a lawyer representing the company said. The agent installed government-developed software on the company’s server and remained at the site for several weeks to download data to an agency laptop.
In other instances, the lawyer said, the agency seeks real-time transmission of data, which companies send digitally."
http://www.nytimes.com/2013/06/08/technology/tech-companies-...
It will be interesting to see what degree of commitment each of these companies showed to the privacy of its users. It appears that however Twitter was complying with requests, it wasn't as convenient for the NSA as Prism access...
Here's how it works (this is my opinion as a web developer, not verified details from Snowden leak):
1) Fancy user interface developed by Booz Allen Hamilton. Enter email address (good choice for a unique identifier, used as unique key in many databases).
2) Backend uses curl to send a request to NSA-certified web api on each service shown on the slide. This serves as a legally-binding FISA request either regarding a foreign agent - no court order required - or a domestic agent - secret FISA court order required (see http://www.npr.org/2013/06/13/191226106/fisa-court-appears-t...) and assumed to be fulfilled by the api.
3) Kick off NSA equivalent of gearman worker that checks contents of "dropbox"-like service from each company for updates.
4) Services (Google, Facebook, etc) automatically grant request without question as it is a legally binding FISA order. This saves them a ton of money and, hey, it's legal! They have some custom code that allows them to look up a user by their email address - almost guaranteed to be indexed in their database - join it to relevant data sets, and dump it to the "dropbox"-like system.
5) Fancy frontend shows progress bar, while skinny backend compresses retrieved data into zip file for easy download.
This is the most efficient, cost-effective way to do this without venturing into science fiction, ie storing a mirror of all the data which would be stupid on NSA's part. It still verifies our worst fears and answers the question as to how such a program can cost "only" $20 million per year as reported by the slides.
The trick is in the legal framework, not the technical details. This is why the FISA courts are secret.
I've been looking for this since I read your comment but can't seem to find it. Perhaps you could point me to the article to which you're referring?
If true that would be great, but to fulfill the constrains set by the information we do know, it is possible that most companies have drop boxes, while Google opted out. Do you recall what Facebook said about human review and drop box existence?
Edit: I also wonder how many requests are appealed. The human overseers you're referring to may be little more than mechanical turks and that data is returned in near-realtime.
You mean you've been shooting off here on HN without even reading?
At Google's official blog post, they stated that review each request.
Don't ask people for a link. Do your research first before you comment.
+++ATH0
NO CARRIER> NO CARRIER
Now now, let's not resort to modem violence.
Services (Google, Facebook, etc) automatically grant request without question as it is a legally binding FISA order
... with the court order the NYT linked to from FAS, where Yahoo is seen to go several rounds with the FISC after having received a lawful directive from NSA to initiate surveillance?
From exactly what evidence do you argue that Google (or any other Internet company) automatically approves all FISA requests?
Edit: Also, your tweet quoting me sarcastically was also unnecessary. I'm trying to be helpful and you're being rude.
4) Services (Google, Facebook, etc) automatically grant request without question as it is a legally binding FISA order
with nothing more than the fact that you're a professional web developer. Replace that with the equally valid 'amateur lion-tamer' just to get get a more disinterested sense of how it sounds.
Relevant part of the article:
>In a secret court in Washington, Yahoo’s top lawyers made their case. The government had sought help in spying on certain foreign users, without a warrant, and Yahoo had refused, saying the broad requests were unconstitutional. Related
>The judges disagreed. That left Yahoo two choices: Hand over the data or break the law.
>So Yahoo became part of the National Security Agency’s secret Internet surveillance program, Prism, according to leaked N.S.A. documents, as did seven other Internet companies.
From the court order:
"After a careful calibration of this balance and consideration of the myriad of legal issues presented, we affirm the lower court's determinations that the directives at issue are lawful and that compliance with them is obligatory."
Seems to me that tptacek is supporting my hypothesis
they did their job as well as they could. they had what appeared to be interesting data, but instead of just saying, "wow, XXX" they were very careful to not go beyond what was said.
i jumped to conclusions too. but then i realised i was probably wrong. it happens. but i don't then blame the reporters who did their job reasonably well. i made the mistake, not them.
Isn't it possible that a slide written for newbies (within NSA, or those who work with the NSA) might have also been written by someone who is not an all-star in technical communication?
I’m going to put it all out there and let the chips fall where they may: I’m increasingly convinced that Glenn Greenwald’s reporting on the NSA story is tainted by his well-known agenda, leading him to make broad claims for the purposes of inciting outrage.
http://thedailybanter.com/2013/06/greenwald-sticks-with-his-...
See also:
This detail is a major one. This would mean the NSA cannot simply log on to Facebook and query for whatever they want. It means the system is simply a way for companies to comply with FISA requests, something that they were already required to do.
So: even though Twitter doesn't use PRISM, there is really no difference between what the NSA can access on Twitter and what they can access on Facebook. Twitter just complies through some other manner.
Google has claimed these requests are infrequent and narrowly focused, and they have requested permission from the government to publish some statistics. I hope they get it.
The threat to this model is the idea that a FISA warrant might not be required until monitoring has gone on for 72 hours, but that was just as much of a threat with the prior model, where the data were manually extracted and sent by the company instead of using the automated dropbox setup.
There's nothing necessarily wrong with something like PRISM (especially since we don't even know what it is), but the choice about whether it's right or wrong belongs to the people as a whole, most certainly not to a few people happened to have grabbed that power.
What's the point of democracy and accountability if it's unclear what people are accountable for nor what you're voting on? This kind of system should never ever have been introduced in secrecy.
Does the public go down and tell the Admirals how to staff a warship? Or what controls to use when deciding to launch weapons? Those are life and death decisions where the military essentially handles its own oversight with Congress and government civil servants involved at the higher levels to handle public interest in accountability and oversight. Yet I don't see the public up in arms about that.
Now, if the people say they don't like Prism and don't want it then the NSA should gut it; that's the right of the people to decide.
But I wish we wouldn't be so quick to jump to the idea that the public must personally audit and review all such government programs as a rule, because as far as I can tell from the seats I've sat in the public has never actually believed that in general at all, and are normally quite content to allow their Congressmen and our shared values as citizens (for those actually doing the work) to provide that oversight.
That's just guesswork, of course. I think it's easy for us (and the Guardian) to imply a lot of detail where none exists. I don't think the Guardian has anything to apologize for. It'd be great if we all got a better technical view of these systems. But asking to receive it third-hand through a leaker and a non-technical reporter is probably a bit much.
That's underhanded for any media publication that aspires to the idea of "journalism".
In addition they could have at least mentioned the idea that other theories emerged as to what the slides they presented might actually mean that way people would be aware that there were other valid conclusions that could possibly be drawn, especially by those with tech and government experience.
Seems to me that the claim from the article re scare quotes is nonsense.
There are no scare quotes in the guardian piece. There are, however, lots of quotes.
The things that the article claims are scare quotes (the relevant passage "...That has allowed the companies to deny that there is “direct or indirect” NSA access, to deny that there is a “back door” to their systems, and that they only comply with “legal” requests...") are, if you actually read the guardian's article and see the context, clearly terms quoted from the companies' denials (given more fully earlier in the article), the point of the passage being to explain why the companies denials were true given the specific terms used.
It's hard to lie effectively when you don't know how much of the truth is known.
It does call into doubt the credibility of Snowden's OPINIONS about the scope of NSA technology and procedures.
The technology error -- or more precisely the lack of rapid correction -- isn't one of Greenwald's finer moments, but in general he's done such an awesome job on this issue that I give him a pass on that blunder.
The idea that this technology is being used for anything other than mass control is bullshit. I don't want to sound like a member of the tinfoil-hat-brigade, but sadly, I just don't see terrorists using any of the resources offered by the PRISM mentioned US corporations. I do see a very dangerous threat to democracy.
http://littlegreenfootballs.com/article/42126_Greenwald_give...
https://twitter.com/ggreenwald/status/345315199257047040
onekade: Confused about this. The Guardian "correction" doesn't walk back its initial claim at all. mediaite.com/online/fulsome…
ggreenwald: @onekade Not remotely - they're desperate to discredit all the spying, but it's not going to work. Documents are too powerful
Bool is_NSA_authorized(int fisa_id) const
{
return True; // Our hands are tied by FAA 702.
// We really don't want to be doing this.
// But we have no choice, its "legal".
// I hope the NSA has some procedures
// to make sure this isn't abused.
// Otherwise they could get anything
// they want from us.
}My comment wasn't meant as a dig at Google, they are forced to comply with what ever the law actually authorized. My point was we need to know how much they can actually be forced to hand over and what checks there are on that power being abused.
Edit: this does rely on the NSA having access to routers, not servers, so it still isn't exactly what they said