- Would end the NSA's authorization to collect bulk call records from telephony providers under §215.
- Would require the NSA to require court approval prior to every §215 call record request. Up to 2 hops worth of call records would be included.
- Won't require that telecoms maintain anything more than the 18 months of call records that they are already obliged to hold.
The devil's in the details, but it sounds like a big change from the existing call records program. If Congress passes something along these lines, it'd be a major win.
But the §215 call records program is just a very small component of the objectionable surveillance programs. Here's just a sampling of the others:
"Upstream" collection: The sort of thing that happens in AT&T's Room 641A - fiber optic cables intercepted, data captured (under program names Fairview, Blarney, Stormbrew, Oakstar). Auth'd under Executive Order 12333 and the various FISA laws [1]. Searched using the XKEYSCORE frontend. GCHQ has similar program called Tempora which the NSA has access to.
MUSCULAR: Jointly run by GCHQ and NSA, collects data as it passes between the backend servers of services like Yahoo and Google. [2]
PRISM: Auth'd under §702, allows NSA to request data from tech companies about anyone who might be "reasonably believed" to be outside the US.
BULLRUN: Various efforts to break encryption, including attempts to insert vulnerabilities into encryption standards. Snowden's security clearance wasn't high enough to get any real details on exactly what the NSA has achieved as part of BULLRUN [4].
I think the scariest of those is Bullrun. We don't (and likely won't) know to what degree the NSA has managed to break or circumvent encryption [5].
[1] http://en.wikipedia.org/wiki/Upstream_collection
[2] http://www.washingtonpost.com/world/national-security/nsa-in...
[3] http://www.theguardian.com/uk/2013/jun/21/gchq-cables-secret...
[4] http://www.eweek.com/blogs/security-watch/nsa-bullrun-911-an...
[5] https://twitter.com/nicoleperlroth/status/376481848760606720