EFF Asks Judge to Rule NSA Internet Backbone Spying Techniques Unconstitutional
eff.org
eff.org
I expect if the court comes to review the facts in this matter they will either be impeded in succeeding due to national security concerns or find a way to decide for the plaintiffs in the smallest possible way to not upset the established order. Very rarely are judicial decisions groundbreaking in precedent. They are more like the tree trimmers of legislation and executive privilege, they typically only trim branches not cut down entire trunks as this ruling would possibly do for Internet surveillance.
So this the world we live in, encrypt your life.
Absolutely. The problem is: communication is a "network good", you don't do it alone. How do you want the "Facebook people" to understand the gravity of the situation? We all do communicate with Facebook people.
GCHQ supposedly operates under UK law and needs warrants to search their huge databases and operates under the oversight of elected representatives. While that's unacceptable it's more regulated than the chaos of corporate data misuse.
They are a prime example of an agency gone rogue, and their efforts for mass surveillance and against encryption are not a new thing - ask Brian Gladman.
Which laws do you think GCHQ have broken?
Normally when I ask people this they mention things like RIPA, but fail to notice the excemptions in RIPA for a bunch of GCHQ activity.
Here's what IOCCO say: http://www.iocco-uk.info/
Its not that people accept one and not the other, its that one is much more serious, and is impossible to opt out of.
They may want to mine my data to display the appropriate Target ad to me, but that feels a lot more benign than surveillance purely for the sake of possibly removing my freedoms.
This is a tiny fraction of the fucking scary things that big companies do today.
CocaCola- http://news.bbc.co.uk/1/hi/world/south_asia/3096893.stm
Nestlé- http://www.babymilkaction.org/nestlefree
Shell torturing and murdering campaigners- http://news.bbc.co.uk/1/hi/world/africa/8090493.stm
To restate: being a Facebook user in Europe feels safer than government surveillance. Dealing with Nestlé or Coca Cola in poor countries - obviously not so much.
Also thanks for the other two examples, haven't heard about them before.
/the little plot of employee housing in Menlo Park is not what I'm referring to - company towns are usually a financial trap
If you do, here's a little something to shaken that belief:
http://www.theguardian.com/uk-news/2014/may/09/edward-snowde...
I'd say its a weeeeee bit of a difference. Admittedly, the average person may not be able to do the first part...so its probably something that should be reduced and legislated.
We have lost what we used to think of as privacy. We need to find a new model for managing data / information. IP law is not really upto it but at least has a fairly coherent model.
But yes, government is evil, capitalism is nice does not wash.
This is almost sure to come up if the case proceeds without being torpedoed by the national secrets defense..and I hope the EFF absolutely prevails in crushing this malarkey.
Given this graphic in the article, I would guess this the main topic the EFF is pursuing.
While I can see how the NSA's word games can confuse the issue regarding searching, what I've never understood is how nobody seems to notice that those same word games admit to seizing evidence. It's as if everybody forgot the 4th Amendment said "...unreasonable searches and seizures..." or something.
It is shocking to compare this to the past. I've just finished reading "Team of Rivals", a biography of Lincoln, and the amount of deeply sensitive stuff that these high-level politicians shared in personal letters to their loved ones and colleagues is astonishing. No politician today would ever put such stuff in writing - if it got into the wrong hands, it could cause incalculable damage to their reputations, relationships, etc. Those guys were being entirely honest in hand-written letters that were delivered days away in different states by a very rudimentary postal system. They clearly had complete trust in the sanctity of the privacy of their letters.
This level of trust in the US government (or any, in fact) is pretty much unthinkable today. We (the people) have lost a lot of valuable ground here.
They find it far more practical to use collected metadata from addresses to identify postal traffic flows, however, and target their interception based on that.
Take that, loophole.
For starters, clusters of data are dangerous in terms of privacy and theft, exponentially with their size. Is it allowed to have a firecracker at home? Is it allowed to have several thousand of them? Same goes for data, whether you're a corporation or a state.
If that is a tortured definition, then it's the same tortured definition used here (as well as many other places) to justify music and movie piracy.
Because while you say it is a tortured definition many people wouldn't be able to see it like that. To those people it doesn't make much difference if the data is on the Internet or in a black box, so long as limited specific searches are used and they only happen after warrants.
It's the sharing of this information that should be dramatically limited. Other government agencies (at federal, state, and local levels) need to be prevented from actively spying on citizens. Corporations also need to be prevented from spying on citizens, they are just as bad and just as careless with data.
I'd love some discussion on this topic, please convince me I'm wrong.
Of course there needs to be more regulation on the long-term storage of this data (1-2 years max seems sufficient) and the sharing of this data (absolutely no sharing with other agencies unless it's a major threat to national security) and absolutely no sharing any access of these databases with foreign governments.
The NSA plays a critical role in keeping the country safe. It's becoming easier and easier for crazy, misguided, and foreign enemies to harm the nation and it's citizens, somebody has to protect us.
Other countries are not going to give up their NSA equivalents and eliminating the NSA would cripple US intelligence. Knowledge is power is especially true when dealing with the scale that governments deal with. The fact is that the US is one of the prime targets for terrorism, both independent and foreign nation sponsored.
http://gigaom.com/2014/07/16/un-human-rights-report-blows-ap...
My main thought is that the US must stay ahead of other nations intelligence agencies. Other than protecting myself, my family, and the country I don't really have a good reason for this though.
The solution to this is to make surveillance hard for everybody. Pass laws and build technologies that make bulk surveillance not only prohibited but impractical regardless of third party lawlessness. The goal is not to thwart only the NSA, that barely accomplishes anything. You also have to thwart China, Russia, organized crime, malicious corporations, etc.
(Note that I'm not saying that there shouldn't be limits on what the NSA can do, only that stopping other malicious actors isn't applicable in this case)
Because it gets the NSA and its budget out of the "make security worse" business and puts them back full in the "make security better" business. Because if they aren't allowed to do it then they won't want anyone else to be able to do it either.
Or as another example, consider what happens when the NSA discovers a security vulnerability in a common crypto library. If the NSA is allowed to use it for surveillance then they will do that instead of disclosing it, meanwhile the vulnerability persists in the wild just waiting for someone even worse to discover it. You can imagine the epic fail if the Chinese government got hold of Heartbleed six months before the OpenSSL maintainers.
Regarding Heartbleed, the NSA denied having knowledge of the bug before its disclosure. There was a follow up post on the Whitehouse blog[2] that discussed some of the criteria the administration would use in determining whether or not the NSA should disclose a 0-day.
It sounds like you're wanting them to actively search for vulnerabilities in software they didn't write and might not even be used by their targets (the Chinese government could have taken advantage of Heartbleed, but I don't know how many Chinese government sites use OpenSSL). That's not what we currently fund them to do, and I get the impression that most American tech companies wouldn't want the NSA's help anyways.
[2] http://www.whitehouse.gov/blog/2014/04/28/heartbleed-underst...
That's a truism, but oddly at least one Supreme Court Justice thinks that the US Constitution hasn't changed. See http://www.claremontmckenna.edu/salvatori/publications/RARSc... for some elaboration.
I personally think this is a perverse view, leading to weird contradictions like the "Third Party Doctrine".
Given the history of US intelligence agencies (COINTELPRO, SHAMROCK, etc), my main thought is that they're a bigger threat to me, my family and my country than just about anything else.
If this is true, why aren't all the NSA apologists trying to promote a constitutional amendment? The drafters of the constitution knew that the original document wouldn't be sufficient for the changing needs in the future, and gave a very clear method to modify tour "highest law".
While I suspect I wouldn't agree with such an amendment, I would certainly give the argument for it a full hearing and debate. Given how mixed attitudes are, it's hard to predict how successful such a proposal would be in practice.
What I do know, for now, is that trying to subvert the constitution's guarantees in an attempt to skip the necessary amendment with "vigilante justice" is at a minimum a violation of some people's oath to defend the constitution. At worst, trying to subvert the constitution (and the guarantees it provides) might even qualify as sedition. Reality is probably somewhere between those points, of course.
The question is whether we need the NSA, and whether we're willing to forfeit our rights and principles to provide them with all information.
Presidents being shot. Planes flying into buildings. A nuclear weapon or any bomb being detonated inside of the country are all things that I do not want to happen. I don't know how to prevent these without SIGINT dominance.
If these events can be prevented without the chance of any human using the collected data for any other purpose and the data only being stored for a very short period of time, then I'd have to say I'm on the side of the NSA.
I think that corporations and law-enforcement agencies using intelligence and mass collection techniques are much more of a threat.
Yes, the sharing and data-retention of the NSA should be greatly limited and controlled and monitored in my opinion, but eliminating their ability to protect the country (their ultimate goal) might not be worth it.
The result of the "base rate fallacy" in the context of the bulk data collection program is that the false positives will swamp the true positives in any general search results from the data-set.
Just look at the Ford Pinto. It was calculated that it would be cheaper to pay the families of victims than it was to fix the exploding gas tank.
You don't mean this. If you did, you would support mandatory exercise regimens and diet monitoring, and aggressive eugenics programs that include mandatory sterilization of folks at very high risk for nonviable offspring.
> [Pinto anecdote]
The facts seem to disagree with you. Read page eight (listed as page 1020 in the text) of this PDF: http://www.pointoflaw.com/articles/The_Myth_of_the_Ford_Pint...
You can't compare dying in a terrorist attack to the personal choice of not exercising or eating unhealthy.
On page 1037 of the Schwartz Paper you linked to it stated that the California Supreme Court's opinion was that it actually encouraged auto manufacturers to consider the safety trade-offs in the sake of cost. I fundamentally disagree with this.
I personally think that consumer responsibility to research every safety aspect of every product they purchase is bullshit. There should be no corners cut when it comes to safety and if there are then it should be made known to the customer before purchasing the product.
The majority of people and decision makers disagree with me, but that's the great thing about this country and the internet, freedom to disagree and participate in open discussion.
Indeed - after all, the risk from a terrorist attack is so many orders of magnitude less likely we can often ignore it completely. It's noise, and deserves little special preparation.
On the other hand, heart disease and other diet related problems are one of the largest risks faced.
I should have the choice to decide whether or not I am unhealthy, it doesn't affect anyone but myself (and my family if they are dependent on me).
The government should not have the choice on whether or not to protect citizens, that's their job, citizens are depending on them to perform that action.
While I know people would be healthier and "better off" by eating healthy, I have no right to force people to eat a certain way.
If I want to smoke cigarettes, drink alcohol, or smoke marijuana, that should be my choice, not yours to make for me, as long as it doesn't affect you.
If I want to ask the government or a company to delete all information they have about me, I should have the right to do that, just my opinion of course.
> The government should not have the choice on whether or not to protect citizens, that's their job, citizens are depending on them to perform that action.
And this:
> If I want to smoke cigarettes, drink alcohol, or smoke marijuana, that should be my choice, not yours to make for me, as long as it doesn't affect you.
Makes perfect sense to me, do you still think that they are mutually exclusive statements?
What's that - you still want the freedom to drive? Even though it involves a fairly significant (0.01%) risk of dying because of things not under your control? Well, some people want the freedom to not be monitored all the time, even though it involves a much smaller than 0.01% risk of dying because of a terrorist attack. And all people should, and would, if terrorism didn't capture the imagination so vividly.
Maybe you're right, maybe we're both partially correct, it's a complicated issue and I do appreciate the discussion.
You also have no right to go through their private communications unless you have a direct probable cause. (IANAL, the exact terms are probably different, but you get the idea)
Except that the chances of each occurring are wildly different.
Chance of dying from terrorist attack in the US from 2007 to 2011: 1 in 20 million [1].
Chance of dying from choking from inhalation and ingestion of food: 1 in 3,649 [2].
20,000,000 / 3,649 => 5,480.
You are five thousand eight hundred forty times more likely to die from choking on your breakfast/lunch/dinner than to die from a terrorist attack. The difference is so extreme that you'd be better off ignoring the terrorist attack threat and instead installing a feeding tube so you no longer need to chew and swallow your food. You'd statistically live longer that way than worrying about protecting yourself from terrorist threats.
[1]http://swampland.time.com/2013/05/06/chances-of-dying-in-a-t...
[2] http://www.nsc.org/news_resources/injury_and_death_statistic... linked from here: http://www.nsc.org/news_resources/injury_and_death_statistic...
One of the thing that always bugs me is that whenever privacy/security issues come up is that everyone seems to assume that the authorities are naturally going to gravitate to the least efficient, most invasive means of carrying out their job, simultaneously implying that it's preferable to have (in this example) 100 terrorist operating amongst us and not do anything than to put our heads together and propose an intelligent solution.
Have you flown in the past 10 years? Shuffling through TSA checkpoints in my socks makes me feel like authorities do gravitate to stupid measures.
I don't think it's necessary, but if they didn't require that then people would be blaming them for not taking enough action.
The times I've flown it hasn't been too much of a hassle, though I suppose it's highly dependent on the airports you pass through and whether or not it's an international flight coming into the US.
I agree about the TSA checkpoints, though. There are plenty of examples on both sides of the arguments. My point is that the general assumption seems to gravitate to "they'll implement it stupidly, so they shouldn't have that capability at all". It's not necessarily a binary choice between no security and stupid implementation.
There, fixed that for you. Now, I'll admit, a large part of the time the owner is also the driver, but with speed cameras it is not the "driver" who receives the fine, but the _owner of the vehicle_.
The one difference with "speed cameras" and the NSA's data mining is that measurement of the rate of travel of a vehicle (assuming a properly calibrated and non-malfunctioning speed measurement device) is so close to 100% accurate as to be considered 100% accurate.
No "connect the dots, infer here, infer there" data mining in the NSA's dataset will ever be even within several orders of magnitude of accurate as compared to a properly functioning, properly calibrated, speed measurement device.
And that underlying, non zero, error rate is what triggers the base rate fallacy issue in statistical analysis. When an occurrence of X is extremely rare in a very large population without X, then the test for X has to be impossibly accurate for the results to not be swamped by false positives. And this is a completely counter intuitive result, which is why it is so often overlooked.
Pertinent quote from the Shiner article at https://www.schneier.com/blog/archives/2006/03/data_mining_f...:
"Let's look at some numbers. We'll be optimistic. We'll assume the system has a 1 in 100 false positive rate (99% accurate), and a 1 in 1,000 false negative rate (99.9% accurate).
Assume one trillion possible indicators to sift through: that's about ten events -- e-mails, phone calls, purchases, web surfings, whatever -- per person in the U.S. per day. Also assume that 10 of them are actually terrorists plotting.
This unrealistically-accurate system will generate one billion false alarms for every real terrorist plot it uncovers. Every day of every year, the police will have to investigate 27 million potential plots in order to find the one real terrorist plot per month. Raise that false-positive accuracy to an absurd 99.9999% and you're still chasing 2,750 false alarms per day -- but that will inevitably raise your false negatives, and you're going to miss some of those ten real plots.
This isn't anything new. In statistics, it's called the "base rate fallacy," and it applies in other domains as well. For example, even highly accurate medical tests are useless as diagnostic tools if the incidence of the disease is rare in the general population. Terrorist attacks are also rare, any "test" is going to result in an endless stream of false alarms."
Exactly as it should be. It's your responsibility as a vehicle owner to not let bad drivers use your vehicle.
RE base rate fallacy - true, but I guess that's why they want even more data. A single test may swamp you with false positives, but positive results from many different sources can correlate into useful info.
I read the fine print in everything that I sign. I never noticed any such language in either the state driving regulations, or the restrictions imposed by my automobile insurer. I did notice obligations to operate one's vehicle in a safe and prudent manner at all times.
This also doesn't match with real-world numbers that we know on the NSA metadata program. Schneier was saying immediately after 9/11, the FBI was getting thousands of tips per month, which may very well have been the case back then. But the Presidential Review Group report stated that in 2012 a total of 12 tips were passed to the FBI[1]. To me, that indicates that they've become much better at getting rid false positives.
Schneier's hypothetical program also isn't analogous because it starts by scanning everyone to determine if one is or is not a terrorist, but the actual NSA metadata program (according to Review Group, same article cited above) starts out by examining people the NSA has already identified as terrorists through other means - the controversy isn't in the accuracy rate, it's in the method of collection.
[1] http://www.huffingtonpost.com/geoffrey-r-stone/nsa-meta-data...
Schneier has written on this problem a number of times.
I suspect this problem may be caused by the well-known problems many people have with Bayes Theorem and how to properly use it.
Chaotic events happen. People are terrified of them but having billions of dollars worth of surveillance state does not reduce the risk one iota.
This simply can't/won't happen. Human nature dictates that this data can't be held and dealt with responsibly.
But I do disagree.
Do not assume mass surveillance can happen "without the chance of any human using the collected data for any other purpose". That's fairy tales. Look up "Loveint",think about everyone you ever dated and their exes. Commercial use is not unheard of, either. Even if - if! - nothing much darker goes on yet, what would stop corruption in the future? That's a much greater threat than terrorism.
I don't think they can be prevented with "SIGINT dominance" either.
But more importantly, to me: the idea of consitutional and human rights is that it was agreed, roughtly, that "these things are required to live a dignified, free life". Not literally, but I do think that is the rough idea. So taking away from that is akin to killing everybody. It's not even burning the village to save the village, it's burning the whole village to save a tiny part of it.
In a follow-upp comment you said "when we are talking about peoples lives, it's worth saving as many as possible in my opinion" and I agree. For example, stop mass surveillance, stop selling weapons like candy, persecute war criminals (I mean the ones having a ball and getting invited to gala dinners on home soil, not the ones around the globe in areas of geostrategic interest), that sort of stuff. Otherwise, I'll stick with believing a lot of "security" stuff is just lip service, a way to transfer tax payer money into private pockets without achieving anything other than more control of the domestic population. I'm not talking about cogs in the machine, mind you, but the machine itself. I don't doubt many people in the NSA or elsewhere have good intentions, I just think that's worth very little in the bigger scheme of things.
But you're just avoiding the issue. The fact that there is an international peering point in San Francisco is no excuse for them to be capturing traffic between San Francisco and Houston or New York.
How am I avoiding the issue? I have absolutely no problem with the NSA intercepting foreign traffic - that's their job. The EFF page shows them filtering out domestic traffic in their diagram, and Mark Klein's testimony, on which the EFF is building their Jewel v. NSA case, doesn't actually demonstrate any interception of US traffic.
"First, the government unconstitutionally seizes plaintiffs’ Internet communications. Technology at plaintiffs’ Internet service provider, AT&T, automatically creates and delivers to the government a copy of plaintiffs’ online activities, along with those of millions of other innocent Americans—including email, live chat, reading and interacting with websites, Internet searching, and social networking.
Second, the government unconstitutionally searches the content of much of the communications stream it has seized. The government admits that it searches the content of the online communications that it has seized if it believes there is some indication that the origin or destination of the communication is outside the United States."
As I scroll through the statement of facts, I see Mark Klein's testimony, the PCLOB 702 report and Barton Gellman's article from earlier this month cited. Klein's testimony is key to this case because that's how the EFF is establishing that the plaintiffs have standing.
> The NSA is not capturing only traffic between Russia and Venezuela or only traffic that crosses a national border.
The EFF itself is saying right in their article and court filing[2] that the NSA is discarding purely domestic traffic.
> They are sitting on the links into Google's data centers. Google is a domestic entity. So either they're sitting on a link and then filtering out 100% of the traffic (which is preposterous) or they're sitting on a link where 100% of the traffic goes to and from a domestic entity and not filtering it out.
There is absolutely no evidence of this. I assume you're making a reference to the Barton Gellman's MUSCULAR reporting[3], which claimed that the NSA was making use of GCHQ's tapping of international fiber to scan Google's unencrypted international communications for their targets.
[1] https://www.eff.org/document/plaintiffs-jewel-knutzen-and-wa... (see page 7)
[2] Same as above, page 10
[3] http://www.washingtonpost.com/blogs/the-switch/wp/2013/11/04...
First, we don't even know what the contents of the executive order (!!!) that created the NSA are. Their very basis may be illegitimate.
Second, evidence says that the complete secrecy they demand just grows like weeds until it encompasses everything. Then, the follow-on paranoia about the secrecy means they can't use the information they've got. I'll offer the DEA's "parallel construction" as support here.
The NSA, as currently based and constituted, is utterly useless. It only supports a very rigid power structure in doing things that power structure shouldn't do in the first place.
Might be worth working at not doing things that make one a prime target instead. This would be a better investment from what I can see. Just look at the growth of ISIS in Iraq. Our governments seem to create more enemies with every attempt to quash them.
There are interviews with special operations soldiers saying that they would receive a kill list, they would work their way down the list, then the next month the new kill list would be much longer.
If you raid a house, kill the father/brother/uncle and maybe have some collateral damage, it doesn't matter whether or not that person was against America, you've converted several people in that family and community against America because we just became the terrorists.
America not being a popular target for terrorism is a much more difficult problem to solve. People are crazy, ignorance combined with religion leads to misguided people, even jealousy is a factor. Foreign nations will do almost anything to increase the wealth of their country, that would be very difficult to prevent.
Is that truly an established fact? And if so, why not figure out why (as suggested by another comment) instead of simply retaliating?
That number probably directly relates to deaths caused by terrorism.
"When you do things right, people won't be sure you've done anything at all."
So what's stopping the NSA from claiming they prevent alien invasions on a daily basis? After all, it's classified, so how would you know either way?
Unfortunately, such a compromise might be difficult to enforce. Parallel construction[0] can be used to hide the original reason someone came under suspicion.
So I don't know. But I think it's worth thinking about.
Other agencies argued that they couldn't properly do their job because they didn't have access to the information the NSA collected.
I think it should go back the way it was. Only filtered data that is critical to national security should leave the NSA. There should be public reports and committees to ensure that is happening.
The Patriot Act pretty much says, "here is access to everything, you can even share it with other nations".
(emphasis mine)
"...Today, the SOD offers at least three services to federal, state and local law enforcement agents: coordinating international investigations such as the Bout case; distributing tips from overseas NSA intercepts, informants, foreign law enforcement partners and domestic wiretaps; and circulating tips from a massive database known as DICE. ...
...Wiretap tips forwarded by the SOD usually come from foreign governments, U.S. intelligence agencies or court-authorized domestic phone recordings. Because warrantless eavesdropping on Americans is illegal, tips from intelligence agencies are generally not forwarded to the SOD until a caller's citizenship can be verified, according to one senior law enforcement official and one former U.S. military intelligence analyst."
[1] http://www.reuters.com/article/2013/08/05/us-dea-sod-idUSBRE...
I keep hoping the water will get shut off to the datacenters across the valley.
Edit: I'm actually wrong here, I looked up the source I originally read this on and realized I misinterpreted it. It's only one possible answer, not the answer: there is no case law, it hasn't been tested yet.
A district court originally ruled that Jewel et al didn't have standing, but the 9th Circuit disagreed[1], ruling that the allegation was a concrete and particular injury that was easily traceable to the NSA's actions. This was also well before Snowden's revelations, which only added (significantly) more evidence to the EFF's case.
[1] http://cdn.ca9.uscourts.gov/datastore/opinions/2011/12/29/10...
http://www.vox.com/2014/7/17/5910299/5-ways-obama-may-have-v...