Before the FAA passed, there were no requirements or oversight governing collection of non US persons communicating over a US carrier. And in fact, existing legal precedent does not treat the carrier as party to the communication, so collection under those circumstances was likely legal. That's exactly the loophole the previous administration exploited to compel third-party compliance in foreign intelligence collection without oversight.
http://thomas.loc.gov/cgi-bin/bdquery/z?d110:s.01927: Notwithstanding any other law, the Director of National Intelligence and the Attorney General, may for periods of up to one year authorize the acquisition of foreign intelligence information concerning persons reasonably believed to be outside the United States...
http://thomas.loc.gov/cgi-bin/bdquery/z?d110:H.R.6304: Notwithstanding any other provision of law... the Attorney General and the Director of National Intelligence may authorize jointly, for a period of up to 1 year from the effective date of the authorization, the targeting of persons reasonably believed to be located outside the United States...
I didn't say they were identical, just that they were similar. Though each does use the identical language about limits on targeting "persons reasonably believed to be located outside the United States" -- and we found out from last week's leaks how far that language can be stretched.
Even those passages you're citing are night and day apart. The first authorizes collection against US persons on foreign soil, which flew in the face of 50 years of precedent. Whereas the second is truncated to the point of being almost meaningless, but in context it defines some terms of collection against non US persons outside the US--something legal for all of US history. The only similarities between the two are the responsible parties and the duration, which are basically boilerplate.
See: http://www.guardian.co.uk/world/interactive/2013/jun/20/exhi..., page 4, paragraph 1.
If the NSA does not know whether someone is a US person or a foreigner, the agency assumes that the person is a foreigner. That matters a lot if, for example, you're using Tor.
You might also want to look at the recently leaked minimization rules, which permit the retention of purely domestic communications collected under the FAA, if that information can be used to develop and exploit security vulnerabilities. Given where you work now, and what you work on, that might be somewhat important.
See: http://www.guardian.co.uk/world/interactive/2013/jun/20/exhi..., page 5, paragraph 3.
The Section 215 program in which the NSA has been collecting metadata about every domestic telephone call would appear to violate that rule, even if, as we are told, only a couple dozen NSA employees can query the database, and even if they only use it for investigations related to terrorism.
Likewise, the non-us persons targeting rules leaked last week suggest that the NSA has ongoing access to GSM Home Location Register data for the entire United States. While this doesn't pinpoint someone's location to a house or street, we're still talking about the NSA getting city-level location data for hundreds of millions of innocent Americans.
See page 6 of: http://www.guardian.co.uk/world/interactive/2013/jun/20/exhi...
Given how compartmentalized NSA is, it seems quite reasonable that your former team (which, I assume, penetrated the computers of foreign targets) would have no contact at all with the teams tasked with collecting domestic communications.
http://www.guardian.co.uk/world/2013/jun/27/nsa-online-metad... It relied, legally, on "FAA Authority", a reference to the 2008 Fisa Amendments Act that relaxed surveillance restrictions.
I just happened to be reading that Greenwald article around the same time I saw your response, but I'm not relying on his analysis: I posted excerpts from both bills. They are similar, not identical, and I wrote about both at the time they were enacted.
I'm going to decline to speculate about personal biases and motivations.