Pres. Obama Remarks on Intelligence Programs [video]
c-span.org
c-span.org
EDIT: After having very quickly skimmed the PPD, here's something interesting:
The collection of foreign private commercial information or trade secrets is authorized only to protect the national security of the United States or its partners an d allies. It is not an authorized foreign intelligence or counterintelligence purpose to collect such information to afford a competitive advantage to U.S. companies and U.S. business sectors commercially.
Bascially what they're saying is that, in the name of security, we can do whatever the fuck we want. Good luck trying to stop an agency operating in total secrecy from abusing these powers.
More fundamentally, let's follow the money.
Who is going to fund this corporation? If they take money from the USG, money which is then paid to corporations to persuade those corporations to give up personal data or allow network taps and collocated spying equipment, that is no different from the current situation.
But they felt there would be recrimination if the fact that it was voluntary on their part came out and so requested to be ordered to do so (if that makes sense).
But you're right, at best there will be a third-party private company setup to hold the records and act as an "independent" review of the request, since none of the telecoms want to maintain the records themselves, since now that it's public it would risk discovery motions in every random case until the end of time.
And now that we would have an "independent" third party watching the NSA, who watches the watchers? At least NSA analysts are trained from Day 0 about the Constitution, USSID 18, FISA, etc. Who monitors the shell company to verify that they're not doing evil things with the database? Perhaps we could have FBI constantly monitor their comms and at least spread the risk around.
AFAICT the NSA analysts have been operating under the assumption that they are following the law as written and interpreted by the Courts (Supreme and FISC), and handling incidental abuses that they discover via the same types of procedures (albeit more strict) used in other branches of government.
The fact that the lawyers and courts happen to disagree on your personal interpretation of the law and Constitution doesn't mean they weren't trying to follow it.
And however bad their actions are, there's no telling how bad it will get when you introduce profit motive.
If the reform is actually just:
1) We stop spying on prominent politicians in heavily allied countries; and
2) We shut down the mass collection of call records and implement a new system that only does mass collection of international calls and traffic;
That would make the vast majority of people perfectly happy.
Most of them just want to hear "I will fix this" and "we won't spy on YOU". Many could care less if you spy on the other guys, let alone other world leaders.
In any given scandal that's not of truly titanic proportions, "addressing the concerns of the majority of people" inherently is papering-over any problems without addressing them - since the majority is going to be concerned with other stuff and no have that much of an opinion.
And your claims of the reactionary-ness of the majority hasn't been born-out by polls. The majority may indeed be satisfiable by simple thing but the rhetoric of that is not so much democratic as demagogic.
- More technically inclined people have more (for some, I'd say an order of magnitude more, however you want to define that) of their life online, so they (a) have more data online and thus more to lose, and (b) tend to care much more about anything which affects their activities, since it is more important to them.
- Having a connection, direct or broad, with the technologies and the people responsible for securing things can make their subversion feel more violating; so can knowing that many things (email, Google's backend) could have been secured better but weren't, partially due to a false belief that the US Internet didn't need to be treated as an adversary.
- Connections in the "tech community" causing a bandwagon effect in topics that spread well beyond technology itself. In the context of one forum, such as this one, this is quite clear (the political norm here is very far from the mainstream in areas that have nothing to do with tech); less so the more broadly you define the community, but I think there is some group bias to be found even if you include every programmer in the US.
1) Congressional oversight, even if it's a special committee. NSA can't be completely outside of elected governance. There should be NO level of access that is "too classified" for this committee. If "super access" like that needs to exist in some fashion it should NOT be under the jurisdiction of the NSA. As it stands, that excuse is a loophole that undermines the concept of oversight and the NSA is way too big of an organization to have that power. Just moving "super secret" stuff to a smaller, more concentrated organization would improve things immensely.
2) Clear and open communication over access rights. The structure of which roles have what access should not be considered a secret. If this somehow weakens our security, so be it - that's the price of democracy.
3) Better access control. From what has been leaked, it's clear the NSA is putting a lot of value in security through obscurity. As we all know, this isn't a great approach. At the same time, contractors are given access to actually get stuff done. The terms of access, tracking of usage, etc. need to be discussed in a more open way because right now that's the biggest problem of the NSA.
Your 1) has already happened, AFAIK. Perhaps we need to have different (i.e. more active and intrusive) Congressmen on the subcommittee so that they don't act so shocked when details come out, but that's a different issue.
Another key note is that unlike almost every other subcommittee, these Congressional overseers don't get the ability for political patronage out of what they do. The Chairman of the House Armed Services Committee, for instance, can be greatly influential in drawing massive DoD dollars to their district, but there's not much the Intelligence committees can do in the same vein, aside from random data centers perhaps.
Even then, I know there was a determination by Sen. Feinstein earlier that EO 12333 collection was not in their oversight bailiwick. That wasn't NSA refusing to discuss it, it was the subcommittee deciding it was out of their jurisdiction.
There are many Federal agencies and groups that do monitor EO 12333 (though it is certainly unclear what type of oversight they are providing across the totality of programs).
Beyond all that, I do agree that nothing going on within NSA should be out-of-scope for oversight (including Congressional oversight, if it comes to it). From the nuclear propulsion perspective, we had routine audits of essentially every major program, institutionalized. I don't know how the Congressional subcommittees do their business but it would be a good idea to institute the same there, and also ensure that NSA/IC staff (contractors too) can always feel comfortable coming to a staffer from that Congressional subcommittee with details of abuses.
I'd give the NSA some credit on security through obscurity because you're talking about intelligence programs, not computer code or algorithms. A rule of thumb from crypto research does not necessarily directly apply to anything with the word "communications" in it. ;)
In fact the only real problem I see in 3) is that (assuming you're talking about public discussion) the people who most need to care (the American public) are going to have their eyes glaze over immediately, the people who might actually be able to craft countermeasures would be intensely interested, and it wouldn't even prevent government abuse; how easy is it to craft a good system of access controls for public approval but then add workarounds as needed in practice?
That's not an accurate paraphrasing. Of course when it comes to "foreign private commercial information or trade secrets" it is the sovereign right of the U.S. to "do whatever the fuck we want." The paraphrased language actually makes a concession: we will only use this information for security purposes as opposed to commercial purposes.
They obviously wouldn't lie, would they? And I guess abuse also never happens.
I thought the point of this was to implement mechanisms that would make occurrence of abuse less likely, instead they're just trying to calm people down.
The only lie would be if they said they were going to stop monitoring foreign Internet comms completely.
Beyond that, if you're assuming the government will lie as a matter of course then it doesn't matter what Obama said in his speech, as there's nothing he could have said to conclusively guarantee anything you'd want.
In other words, to say that the U.S. can't say tap international fiber cables and record all French traffic, you must be able to point to a treaty where we agree not to do that. And even then, since nobody can enforce that treaty against us, we follow it only to the extent we find it convenient. Sovereign nations exist amongst themselves in a state of nature, and those are the rules of nature.
Sovereignty and the lack of some treaty preventing some behavior X does nothing to prevent other sovereigns from becoming angry and or retaliating in kind. Doing something 'because we can' does not make it wise.
I won't discuss the fact that 12 years of surveillance have led to no results on stopping any terrorist plots, as the NSA has already admitted, but the NSA has actually made cyberattacks more likely because they are undermining the security of everything, including US infrastructure.
As Schneier says, it's not a question of whether we allow the NSA to spy on everyone or not. It's a question of whether we allow every attacker to spy or attack our networks - or we try to make everything more secure by default.
So when president Obama implies that NSA should keep hoarding their vulnerabilities into systems, he's choosing the former, rather than the latter. He's making cyberattacks more likely, not less. The way you defend against cyberattacks is by increasing security, not by increasing your offense capabilities.
If they really cared about the security of US infrastructure, they'd divulge the vulnerabilities they found or bought from the black market that exploit the security of these systems, so those systems can be fixed, and no one else can exploit them with these exploits. Instead they keep them for themselves so they can exploit them. That's not just wrong. It's incredibly dangerous and reckless, especially from an agency that supposedly wants to "protect us".
He certainly never implied that "NSA should keep hoarding their vulnerabilities into systems."
Are you arguing that the US should be the only large country without intelligence or counter-intelligence programs?
From the perspective of civil liberties NSA is the threat because of its extensive capabilities.
But it is exactly that suite of capabilities that makes it useful for USCYBERCOM. You wouldn't expect to see USSTRATCOM without its collection of silos, bombers, and SSBNs, would you?
Splitting up CYBERCOM and NSA would leave the capabilities substantially still in the hands of NSA, so they'd still need to coordinate often (but now it would be much more difficult, reducing military readiness for CYBERCOM). But it wouldn't eliminate the threat to civil liberties from NSA (since those come substantially from the NSA's capabilities).
If you instead give CYBERCOM equivalent capability to NSA (at great expense, mind you), you'd simply have two large octopi that are civil liberties risks, instead of one. And only one of those would be substantially overseen by FISC and Congress, since the President would have direct military control over CYBERCOM's actions. Does this sound better?
Leaving CYBERCOM dependent on NSA for its ability to conduct overseas cyberattack actually makes it easier to ensure civil liberties oversight is implemented and performed, and that NSA can't evade those oversight controls by pawning off an illegal search on their friendly neighborhood CYBERCOM with equivalent (or better) cyber capability.
Source?
The major question was the effectiveness of 215 phone metadata surveillance in particular, which is the thing that was hotly debated. But even leaving out 215 metadata there were still about least a dozen plots with actual planning/action taken for them and probably 35-ish more that were detected and either stopped before they reached that point, or verified to have trailed off on their own.
Things are slightly different when you're spying on private citizens rather than just foreign governments, but then again the whole point of terrorism is that it involves private citizens instead of governments.
The NSA has claimed throughout that this is not what they're trying to do. Even their "untargeted" programs (when they can get authority to intercept data without a selector, such as overseas) are not to be used willy-nilly, and even their untargeted programs still seems to involve selectiveness from what I can tell.
E.g. the "200 million SMS messages per day" story from the other day represents ~3.3% of SMS traffic, despite not having selectors attached to that data interception.
Now I don't know that literally every program they have is never being used against private citizens. I would agree strongly with you that they should not be.
But the Internet is packet-switched, not virtual circuits, which means you can't simply install one tap for one IP address. The data needs to be seen before the event, not after it. Sometimes it's not possible to do the right filtering at the selection point itself (I would imagine this is the case with SMS), so you have to do the big data equivalent of map/reduce, and grab everything, collate it, and then filter it to see what comes up.
The problem is that it's a hard problem, with long-standing recriminations when they get it wrong (such as with the 2009 underwear bomber in the USA, who NSA had got shit on for missing completely; it was only luck that his mission hadn't succeeded).
Other countries are spying on the US and the US is spying on other countries - that's the state of things right now. Let's not pretend the US is doing something other nations are not.
The larger concern is probably simply that as long as any party to a communication is a non-U.S. person outside the U.S., that communication is fair game for the NSA under EO 12333 authority alone.
Legally the Fourth Amendment probably does not apply.
Constitutional protections are provided only within US jurisdiction. If you are a US citizen outside of US jurisdiction, then the government isn't required to extend those protections to you.
The lack of spying on US citizens outside of US borders is more of a courtesy - the government doesn't yet consider it worth rolling the Supreme Court dice.
The most restrictive requirement seen in courts appears to be a "reasonableness" requirement judging by the totality of the circumstances involved: http://www.volokh.com/posts/1227548515.shtml
[1] http://www.law.cornell.edu/supct/html/06-1195.ZO.html
[2] http://www.salon.com/2010/02/01/collins_5/
I'm not naive enough to believe that any regime would show restraint as a result of the existence of these rulings, but hey, they exist.
Taking the fact that there are still people in Guantanamo being denied their rights after a court determined that they should be granted a trial into consideration clearly demonstrates that just because such court decisions have been made does not mean the executive will respect them. Certainly this means that my cynicism is justified, albeit cliche.
Our government's first responsibility is to the security and liberties of its citizens and (legal[1]) residents. As much as possible, I'd want it to protect those in ways that also help the security and liberties of those in other parts of the world, but those are not equal obligations.
In any case, being spied on by a foreign country is considerably less bad than being spied on by your own. In the wet dreams of conspiracy theorists, our government spies on its citizens to discover their political views, and then imprisons those with views it doesn't like. There's no equivalent evil that France's government could pull off.
[1] In my view, "legal" shouldn't need to be there, but that's not very realistic.
Arresting you when you have to enter France for business or personal reasons is one possibility.
EDIT: If France has some agents in your country there's a lot of evil they could pull off even without you leaving the country.
I do agree we should refrain from mass surveillance on non-US citizens, but I don't think that achieving that is realistic at this juncture. The intelligence community is in excited-puppy mode about all the cool things they can do with the internet[1], and it'll be a bit before they and their elected overlords figure out what's useful, what's not, and how surveillance can be better performed without playing godzilla to the city of rights.
For now, what I think is reasonable is a more straightforward, open disclosure of what and how the NSA monitors.
And now I need to stop commenting on this article until I've actually read the proposed reform in its entirety. (And you all should too. Hah.)
[1] Calling it an "insurance policy", really? "We've never had to use it, but it's too cool to give up."
in general terms, in most places, the law is applies equally to everyone in the country[+].
in contrast, in the usa, many things apparently depend on whether you are a citizen or not.
those are quite different approaches. both can be made to work (neither "falls apart"). the american one appears arbitrary and unfair to me.
[+] obviously there are exceptions - immigration, for example.
If you've so much as ever applied for a green card, you are now a "U.S. person" as far as NSA is concerned.
U.S. treatment of non-citizens outside of the U.S. is different in some (not all) ways, that much is true. But other countries take that tack as well. E.g. even privacy-friendly Germany allows their foreign intel agency, BND, to spy on the communications of non-Germans.
In any case, it's not a distinction between citizens and non-citizens, but the territorial scope of the Constitution. Just as the Constitution can't create obligations that apply to say the French in France, it can't create rights that apply to them.
"we'll think about alternatives"
"we have unique capabilities to protect our friends"
"as the nation that developed the internet, the world expects us ...."
"as a nation that has faced totalitarianism the world expects us ... "
"the readiness of certain individuals to expect the worst of our readiness to protect the world(not fully correct quote) can be frustrating"
haha wtf dude. this is more of a justification than a change notification. we'll make sure the data we collect is better accepted by you people
> The collection of foreign private commercial information or trade secrets is authorized only to protect the > national security of the United States or its partners and allies. It is not an authorized foreign intelligence > or counterintelligence purpose to collect such information to afford a competitive advantage
can you tell me where the change is? The document reads more of a "hey trust me, we're really the good guys"
http://sina.is/2014sigint.mem_.ppd_.rel_.pdf
care to explain where the real change is?
EDIT: since i can't reply. it's all about thinking and discussing if dissemination and retention makes sense. and reducing people that have access to it. and we may put a special person in charge to take care of these things. but that doesn't mean at&t will suddenly stop feeding data into nsa data centers.
is that true?
William O. Douglas, Supreme Court Justice 1939-1975
Eisenhower, today in 1961.
It was nice while it lasted, guys.
Let's hope that Snowden has drummed up enough opposition to prevent it from being extended again.
(Do you support) expanded government monitoring of cell phones and email, to intercept communications?
2001: 54 favor, 41 oppose
2006: 52 favor, 46 oppose
2013: 38 favor, 59 oppose
Regardless of how we got here?
It’s Martin Luther King day on Monday. A day named after the person that got us as a country to make ‘important decisions’ about how to ‘sustain our leadership in the world’ and ‘uphold our civil liberties’.
Mr. President we don’t disregard the individuals that make us examine our weaknesses in order to make our country better, we embrace them as heroes, even if that self reflection is uncomfortable and difficult at the time.
So let's not pretend that being for the people automatically makes all of your subsequent actions right or moral.
On the other hand, the USG is the one entity chartered by "We the People of the United States", which makes me always at least initially suspicious of people whose plan is to hurt the government (which must almost invariably hurt the people, as long as the government stands).
But independent of whether Snowden is fighting the people or the government, the bigger question is whether his actions have hurt the people. In many cases they have.
Leaking details of NSA attacks on Chinese networks doesn't help the American people. Nor does leaking details about "targeted access operations" (which, since they must be targeted, cannot be used for mass surveillance essentially by definition).
I could go on and on, but the point is simply that Snowden has indeed thrown a few bones with civil liberty implications. But that's not all that he has leaked, and given that he claimed from the beginning that he was very careful in what he selected, it is proper to hold him accountable for his actions, insofar as they do end up being against the American people.
Let me ask a facetious question: does spying on Petrobras help prevent terrorism in the US?
NSA has a much wider remit than counter-terrorism, and for good reason.
It was not that long ago when European companies were routinely using bribery to land contracts at the expense of American companies, bribes which were sometimes detected and revealed to the world thanks to NSA. When the contract was re-competed without the bribe the American company often won, funny that...
http://www.techdirt.com/articles/20140117/09011025919/presid...
In some sense, who collects, stores, and accesses the data is important. But it seems more important to look at the culture, rules, and oversight in place. Asking anyone to design such a system is daunting.
Let's say, for the point of argument, that specific, limited, legal, accountable collection is the primary goal and we could design a new system to accomplish that. What are some of the best designs of security protocols and entity structures to protect this information? How far can you get with correct system administration policy? I suspect you need quite a bit beyond currently available tools.
http://thecaucus.blogs.nytimes.com/2014/01/17/live-coverage-...
> President Obama is announcing that he wants to end the National Security Agency’s bulk call records program as it currently exists.
Why, of course, "as it currently exists" it has a lot of problems. I'm sure the current version can be "ended" and a much more insidious version can be designed.
As of the 11:47 update there is nothing of note in there.
The new program will be far more secretive.
By the logic that arrives to this conclusion, the government can not protect against terrorists and cyber threats without penetrating domestic networks either.
The government already does this kind of stuff, only through the FBI instead of the NSA.
You would "penetrate" a foreign network when there is no ability to expect cooperation and no ability to compel.
It's about wanting to be angry and see punishments more than achieving anything specific