> The reasonable expectation one would have about statistics released by (say) Yahoo pursuant to this process is that they would capture every directive received by the provider, since providers don't get the certifications.
Furthermore, Google etc. didn't just provide the number of directives, warrants, etc. served on them (within a range), they also listed the total number of accounts affected (again within a range, of course). The latter numbers were higher, but not 10×+ higher.
> Just a quick reminder: the USG does not need and has never needed and probably will never need a warrant to spy on a foreign entity not on US soil
And again, it's not actually super-obvious to most people that this applies to US cloud data. The USG apparently (IANAL) can't search the empty New York bachelor pad of a Russian oligarch or Saudi oil prince without a warrant - that apparently it can nonetheless turn over their GMail account (basically) at will is therefore pretty surprising.
There's also the matter that US cloud-data firms have been making true-but-misleading statements apparently calculated to give their users the impression that they have the ability (as well as the willingness) to contest demands for individual users' data without a court finding of probable cause or something like it, when for a large majority of the PRISM-company users this is not the case.
Finally, US citizens might like to check out the FISA appeals court's opinion about a foreign-intelligence exception to the Fourth Amendment. https://news.ycombinator.com/item?id=5923606