> Define in as much detail as you can what "direct access" means.
> Define in as much detail as you can what "direct access" means.
"More detail on how direct NSA's accesses are is coming, but in general, the reality is this: if an NSA, FBI, CIA, DIA, etc analyst has access to query raw SIGINT databases, they can enter and get results for anything they want. Phone number, email, user id, cell phone handset id (IMEI), and so on - it's all the same. The restrictions against this are policy based, not technically based, and can change at any time. Additionally, audits are cursory, incomplete, and easily fooled by fake justifications. For at least GCHQ, the number of audited queries is only 5% of those performed."
Also, by the way, 5% auditing is an very high rate. With a 5% audit rate, you'll catch evil-doers in no time at all.
For example, checking out your neighbor, girlfriend or a public person's records for curiosity is probably a big red flag.
It is my experience that systems auditors rely heavily on sysadmins to do their jobs. At a minimum the auditors are "just" another set of users and the sysadmins' responsibilities include supporting the auditors even more closely than they support regular users of classified systems. Frequently the auditors themselves do not have systems-level knowledge of the computers they are auditing.
Security on every classified system that I've seen was generally limited to a series of a checklists that some talented specialists once put down in a manual and are left to low-skilled employees to check off each day/week/month - if it isn't specifically on the checklist they have little to no knowledge of it. That includes glaring procedural holes. Essentially security is all CYA, so that everybody involved can say they followed the rules and not lose their job if something goes wrong.
I don't remember him using that particular phrase at all at least in his initial video - I remember him talking about the ease with which they could access data using a 'selector' like an email address, not making claims about specific connections to servers or anything similar. He's not responsible for what journalists say, and we can't expect them to clearly restate it all the time, but what we do know about the extent of surveillance is disturbing. It's still unclear exactly what is recorded, when and how and I'm sure we'd all love to know more, but in the meantime it's not very useful to try to discredit his claims based on the interpretations of others.
https://eslkevin.wordpress.com/2013/06/10/edward-snowden-int...
My beef with the phrase though is that Greenwald keeps repeating it and sticks by the story that the NSA slides said it so it must mean something, without bothering to ask his supposedly very knowledgable source to expand further on the topic.
I think it is completely feasible that the NSA would or does collect all or a great deal of voice traffic, because that's a tiny piece of network traffic these days.
edit: I found this on the issue: http://www.zdnet.com/the-real-story-in-the-nsa-scandal-is-th...
Going from "NSA has direct access to servers of major internet companies" to "Some NSA analysts' database accesses inadequately audited, according to random sysadmin" is a textbook walk-back. Of course you will never see the latter headline on Greenwald's blog.
"...Not only that, when NSA makes a technical mistake during an exploitation operation, critical systems crash. ..."
Well, if they have no access to the actual company servers, how could you then reconcile the above statement?
He didn't answer the question that the person asking probably wanted an answer to, which was about direct access in regard to Prism. But that's the fault of the person asking not being precise...
You have to remember there are tons of programs going on. To the people who have been paying attention to the Prism "direct access" debate, it's probably pretty clear what the person asking the question was getting at. But it makes total sense that someone as familiar with the programs as a whole would answer about "direct access" in general.
"Anthony De Rosa 17 June 2013 2:18pm 1) Define in as much detail as you can what "direct access" means.
2) Can analysts listen to content of domestic calls without a warrant?"
Answer (Snowden)
"1) More detail on how direct NSA's accesses are is coming, but in general, the reality is this: if an NSA, FBI, CIA, DIA, etc analyst has access to query raw SIGINT databases, they can enter and get results for anything they want. Phone number, email, user id, cell phone handset id (IMEI), and so on - it's all the same. The restrictions against this are policy based, not technically based, and can change at any time. Additionally, audits are cursory, incomplete, and easily fooled by fake justifications. For at least GCHQ, the number of audited queries is only 5% of those performed."