Evidence that the NSA Is Storing Voice Content, Not Just Metadata
schneier.com
schneier.com
A person browses the web at a doctor's office. Forty-five minutes later, that person calls their spouse, then an oncologist. A few days later, their spouse checks email from the oncologists office. An hour later a call is made to a diagnostic center by the first person. The next day, they call their mother and a surgeon. [see interview with Susan Landau: http://www.democracynow.org/2013/6/12/more_intrusive_than_ea... ]
The conclusions which can be drawn from that meta-data are far more solid than can be drawn from listening in to any or all of the phone calls.
Your phone calls don't show what time you get up in the morning, or when you get to work or walk the dog to the park. The meta-data does.
The focus on the content of calls is 50 years out of date. The meta-data show the best time to burgle your house or fake your identity online. They show where you go and who you associate with. There's no need to know what you said.
It's the timing and individuals and the sequence of events which matter.
And now I am reminiscing fondly about the days when our biggest national concern was a blowjob.
I think people are worried that they will say something well within their first amendment rights on a seemingly private channel, that will then get them marked as a "dissenter" of some kind.
I don't think anyone, be it government or corporate, should be capturing and storing detailed data like this for extended periods of time. It's just asking for trouble. I haven't seen any proof of a worse case scenario more severe than ads being a bit less targeted if strict limits were placed on data retention and identification.
> The conclusions which can be drawn from that meta-data are far more solid than can be drawn from listening in to any or all of the phone calls.
This is just false. If you were a lawyer trying to draw a portrait of intentions with the metadata in court, obviously it would help your case if you could play the tapes and show what was said in each of the calls, so the other side can't propose equally valid situations like I did and create reasonable doubt.
I think we can be so fascinated by the power of having data, that much like the other powerful forensic tools used in the courtroom, we are eager to connect all the dots like we see TV shows like CSI doing. It can be difficult to remind people that more data (particularly meta-data and not content) produces more plausible hypotheses as often as it narrows them down.
The metadata would not end with that phone call - the pattern of continuing activities would make fairly evident what the prognosis had been. (Of course this doesn't meet the "beyond all reasonable doubt" standard of criminal court, but it meets the standard for justifying digging deeper into their affairs, or setting insurance rates for that matter.)
The conclusions which can be drawn from that meta-data are far more solid than can be drawn from listening in to any or all of the phone calls.
You cannot derive more information from meta-data than you can from the data itself. That's why we call it meta-data. "Honey, I may have cancer, I'm making an appointment with Dr. O. N'conlogist as soon as possible." is more compact, just as complete, and is more tolerant to missing parts.
"Honey, it's bad news," or "Darling, I need you to hold me," or "<sobbing>" don't say squat...unless you know they were made from the doctor's office and what calls were made afterwards.
Consider, knowing that someone went to Walmart around noon doesn't say much. They could have done a lot. Knowing they specifically bought ____, is a different matter.
Hell, that is the entire point to this. You are having to aggregate lots of meta-data to determine the data of the call itself. How is this even an argument?
To put it another way, Google doesn't know that I am interested in a new iPod because the I used Gmail to tell my friends, "I'm interested in a new iPod." They know it because I have been browsing pages offering iPods for sale. And that says a lot more about when I plan to purchase one than the statement sent via Gmail.
I didn't tell Kroger, "Hey, I've got a dog." I bought dogfood - and now that Witty is dead, they can tell from the change in my purchase habits that my big dog died - they don't print me coupons for Alpo anymore when I check out.
The content of the call indeed contains information beyond the meta-data about the call. But it's not just meta-data about voice calls that's being collected, it's meta-data about all modes of mobile and static communications - and geolocations when calls are not being made.
Take your Kroger example. You could have just stopped buying dog food from them. We completely stopped buying dog food from a store because we had trouble getting the dogs to take to the food without skin problems. Is it valid for them to assume that our dog is dead? Or just stick with the safe assumption that we aren't buying dog food from them anymore? :)
Now, I completely agree with the idea that collecting just the meta data is already pretty far reaching. I struggle to see why collecting it all is not even more far reaching.
If I stop pissing in the ocean, I'm not going to prevent rising sea levels.
Likewise the contents of your receipt is data, not metadata. It's literally the bill of goods that authorizes you to take the named items from the store and (with your additional purchase creds) authorized Kroger to charge your credit card $X.XX. Kroger may have inferred more than you wished, but they did it with the data.
My receipt is not the items I purchased. It is information about them. E.g.
Power Systems: Conversations on Global
Democratic Uprisings and the New
Challenges to U.S. Empire, $18.75
is not the text itself. It is information about something I did, not something I read or might have read or might read.Likewise, my purchase of dogfood was not dogfood, nor my dog nor my feeding of it.
It's turtles all the way up.
The Supreme Court has already ruled that metadata is not warrant-protected, so I'd be highly leery of equating data with metadata. (edit: spelling fix)
Can you derive back to what you did, given 'information' as meta-data?
This helps make it distinct from metadata. Metadata then describes the data itself (tags, classifications, etc.), whereas paradata describes the data's lifecycle and use (e.g. who used it where and when how, etc).
[1]: http://en.wikipedia.org/wiki/Paradata_%28Learning_Resource_A...
The public was lied to. At the least, a lie of omission.
The lying authority figures are now attempting to (re)establish their credibility -- or at least hang on to their authority and power.
Fool me twice?
The only way to obfuscate the content of a call is if both parties agree in advance to speak in code.
"Hi honey, the sparrow has left the nest. There may be a bee in the bathwater."
"John is that you? What the heck are you talking about? How did the cancer test go?"
Can anyone think of a more likely scenario?
By "secure", I mean "not shared within the agency". Obviously, everything is locked down within the agency, but there'd be a limit to how much the staff would be allowed to see (except the sysadmins, like Snowden, who need wide-ranging access).
I think we can safely assume that you have privacy only when speaking in-person, and that's if you're not under some sort of investigation. Otherwise, find a windy place outdoors (near a large body of water for dramatic effect) and mumble through your conversation even if you're just a Hipster preparing for next weekend's party.
Their word manipulations are sickening. I just wish all of this went to a trial already and to the Supreme Court. Let's see them lie through their teeth to the judges then, who will actually understand everything they're saying or avoiding saying (unlike most of the press, or people out there).
Technical Details
www.schneier.com uses an invalid security certificate.
The certificate expired on 18/06/13 11:55. The current time is 18/06/13 14:02.(Error code: sec_error_expired_certificate)
It doesn't mean that it's malicious, but it doesn't mean it's not.
Right?
Edit: So, my question "Right?" was a legitimate question. If I am wrong, I'd like to know how. Note that this is an expired, non revoked certificate scenario we are talking about. Meaning the identity was established before, and to nobody's knowledge has it been stolen. Simply now that identity has not been established for a long time.
So, either you (and the others in this comment thread) manually changed the URL, or you have some browser extension that automatically switches to HTTPS, etc. I'm sure more of us would've caught the issue if indeed more of us were exposed to the issue in the first place.
At the time, storing such a quantity of data was completely infeasible within the physical space & budgetary constraints of the proposed program was completely infeasible. We told them so, and the project went away. However, given that:
1.) They were trying to do this 15 years ago, and
2.) Both their budget and the technological state of the art has improved substantially since then, and
3.) The government these days seems happy to treat citizens' rights with the same general contempt as non-citizens' rights, given some creative re-definitions of terms and rubber-stamp lawyering...
...I would not be at all surprised to learn that a program like this was in fact well-established by this point.
What else is to gain from monitoring loads of targets without obvious security reasons?
I do? If they are suspect in a crime for specific reasons, why are those specific reasons not enough leads to follow?
As Chomsky said, if you're so worried about terrorism, stop participating in it... as in, The Iraq "War" alone killed so many more people than 9/11, and nobody could even be arsed to look at the debris of the latter before destroying it. This is akin to a wolf saying the chicken need to tell him where they are at all times, to better protect them. Feel free to fall for that once, but then please join the rest of us in the real world.
More likely:
2. To award huge government contracts to the collectors and grow the institution at the same time.
Oh wait no, it's the Deputy Attorney General
He says the 4th amendment doesn't apply to phone records.
Footer says "NSA director to reveal terror plots stopped by surveillance"
This has also been bugging me. Metadata is a very general term, and it doesn't explain what the NSA claims its doing (whether they're doing anything else is beside this particular point). Moreover, the use of such a general term seems like it's part of the propaganda, to make us less scared: "We're not collecting data, we're collecting meta-data." Well, it turns out that they are one and the same anyway.
Not new evidence.
Does storing them for later use count as listening?
[1] http://www.cbsnews.com/8301-250_162-57589732/obama-on-nsa-pr...
Go check out all the things that are not protected by the first amendment. http://en.wikipedia.org/wiki/United_States_free_speech_excep...
If we held people accountable for all the false statements of fact they make, FOX News would have been off the air years ago and all their newscasters thrown in jail. Basically, millions of people could be subject to database queries, considering how many loopholes there are.
One example they cite using the 215 was the NSA provided a phone number to the FBI, the FBI served notice to the court to find out who the number belonged to, and they then arrested and convicted the guy for giving money to a foreign organization that the USA labels a terrorist organization. So don't do business with anyone who might know a group of freedom fighters.
Of course, if you're already targeting a specific individual, and you can get a human to listen to the voice content, the debate is academic - both kinds of data compliment each other and are equally powerful. Metadata still acts as a better "gateway drug" for narrowing down individuals though.
Schneier is a great cryptologist, I've read his books, I've carried them around, I'm a big fan of his work.
BUT.
He's seriously lagging behind in his coverage of this scandal, it's like he's just reposting what others have already said and often stating the obvious.
So the NSA has the capability to store voice? No, really? Like since 1940????
Sorry, Bruce, but this article is shit.