• Buro Jansen & Janssen, gewoon inhoud!
    Jansen & Janssen is een onderzoeksburo dat politie, justitie, inlichtingendiensten, overheid in Nederland en de EU kritisch volgt. Een grond- rechten kollektief dat al 40 jaar, sinds 1984, publiceert over uitbreiding van repressieve wet- geving, publiek-private samenwerking, veiligheid in breedste zin, bevoegdheden, overheidsoptreden en andere staatsaangelegenheden.
    Buro Jansen & Janssen Postbus 10591, 1001EN Amsterdam, 020-6123202, 06-34339533, signal +31684065516, info@burojansen.nl (pgp)
    Steun Buro Jansen & Janssen. Word donateur, NL43 ASNB 0856 9868 52 of NL56 INGB 0000 6039 04 ten name van Stichting Res Publica, Postbus 11556, 1001 GN Amsterdam.
  • Publicaties

  • Migratie

  • Politieklachten

  • US tech giants knew of NSA data collection, agency’s top lawyer insists (2014)

    NSA general counsel Rajesh De says big tech companies like Yahoo and Google provided ‘full assistance’ in legally mandated collection of data

    The senior lawyer for the National Security Agency stated on Wednesday that US technology companies were fully aware of the surveillance agency’s widespread collection of data.

    Rajesh De, the NSA general counsel, said all communications content and associated metadata harvested by the NSA under a 2008 surveillance law occurred with the knowledge of the companies – both for the internet collection program known as Prism and for the so-called “upstream” collection of communications moving across the internet.

    Asked during a Wednesday hearing of the US government’s institutional privacy watchdog if collection under the law, known as Section 702 or the Fisa Amendments Act, occurred with the “full knowledge and assistance of any company from which information is obtained,” De replied: “Yes.”

    When the Guardian and the Washington Post broke the Prism story in June, thanks to documents leaked by whistleblower Edward Snowden, nearly all the companies listed as participating in the program – Yahoo, Apple, Google, Microsoft, Facebook and AOL – claimed they did not know about a surveillance practice described as giving NSA vast access to their customers’ data. Some, like Apple, said they had “never heard” the term Prism.

    De explained: “Prism was an internal government term that as the result of leaks became the public term,” De said. “Collection under this program was a compulsory legal process, that any recipient company would receive.”

    After the hearing, De added that service providers also know and receive legal compulsions surrounding NSA’s harvesting of communications data not from companies but directly in transit across the internet under 702 authority.

    The disclosure of Prism resulted in a cataclysm in technology circles, with tech giants launching extensive PR campaigns to reassure their customers of data security and successfully pressing the Obama administration to allow them greater leeway to disclose the volume and type of data requests served to them by the government.

    Last week, Facebook founder Mark Zuckerberg said he had called US president Barack Obama to voice concern about “the damage the government is creating for all our future.” There was no immediate response from the tech companies to De’s comments on Wednesday.

    It is unclear what sort of legal process the government serves on a company to compel communications content and metadata access under Prism or through upstream collection. Documents leaked from Snowden indicate that the NSA possesses unmediated access to the company data.

    The secret Fisa court overseeing US surveillance for the purposes of producing foreign intelligence issues annual authorisations blessing NSA’s targeting and associated procedures under Section 702.After winning a transparency battle with the administration in the Fisa court earlier this year, the companies are now permitted to disclose the range of Fisa orders they receive, in bands of 1,000, which presumably include orders under 702.

    Passed in 2008, Section 702 retroactively gave cover of law to a post-9/11 effort permitting the NSA to collect phone, email, internet and other communications content when one party to the communication is reasonably believed to be a non-American outside the United States. The NSA stores Prism data for five years and communications taken directly from the internet for two years.

    While Section 702 forbids the intentional targeting of Americans or people inside the United States – a practice known as “reverse targeting” – significant amounts of Americans’ phone calls and emails are swept up in the process of collection.

    In 2011, according to a now-declassified Fisa court ruling, the NSA was found to have collected tens of thousands of emails between Americans, which a judge on the court considered a violation of the US constitution and which the NSA says it is technologically incapable of fixing.

    Renewed in December 2012 over the objections of senate intelligence committee members Ron Wyden and Mark Udall, Section 702 also permits NSA analysts to search through the collected communications for identifying information about Americans, an amendment to so-called “minimisation” rules revealed by the Guardian in August and termed the “backdoor search loophole” by Wyden.

    De and his administration colleagues, testifying before the Privacy and Civil Liberties Oversight Board, strongly rejected suggestions by the panel that a court authorise searches for Americans’ information inside the 702 databases. “If you have to go back to court every time you look at the information in your custody, you can imagine that would be quite burdensome,” deputy assistant attorney general Brad Wiegmann told the board.

    De argued that once the Fisa court permits the collection annually, analysts ought to be free to comb through it, and stated that there were sufficient privacy safeguards for Americans after collection and querying had occurred. “That information is at the government’s disposal to review in the first instance,” De said.

    De also stated that the NSA is not permitted to search for Americans’ data from communications taken directly off the internet, citing greater risks to privacy.

    Section 702 is not the only legal authority the US government possesses to harvest data transiting the internet.

    Neither De nor any other US official discussed data taken from the internet under different legal authorities. Different documents Snowden disclosed, published by the Washington Post, indicated that NSA takes data as it transits between Yahoo and Google data centers, an activity reportedly conducted not under Section 702 but under a seminal executive order known as 12333.

    De and his administration colleagues were quick to answer the board that companies were aware of the government’s collection of data under 702, which Robert Litt, general counsel for the director of national intelligence, told the board was “one of the most valuable collection tools that we have.”

    “All 702 collection is pursuant to court directives, so they have to know,” De reiterated to the Guardian.

    • This article was amended on 20 March 2014 to remove statements in the original that the testimony by Rajesh De contradicted denials by technology companies about their knowledge of NSA data collection. It was also updated to clarify that the companies challenged the secrecy surrounding Section 702 orders. Other minor clarifications were also made.

    Spencer Ackerman in Washington
    theguardian.com, Wednesday 19 March 2014 18.40 GMT

    Find this story at 19 March 2014

    © 2014 Guardian News and Media Limited or its affiliated companies. All rights reserved.

    Apple, Google and AT&T meet Obama to discuss NSA surveillance concerns (2013)

    Silicon Valley companies concerned at effect on business as revelations over US government spying spread more widely

    Barack Obama hosted a summit on government surveillance and digital privacy attended by Apple chief executive Tim Cook, Google vice-president Vint Cerf and the boss of US telecoms network AT&T on Thursday.

    The US president attended in person, sources told the Politico blog, as did other technology company executives. Additional attendees included representatives of the Center for Democracy and Technology and Gigi Sohn, leader of internet campaign group Public Knowledge.

    The meeting was apparently prompted by growing concerns among US technology companies that revelations from the Guardian and others about the extent and depth of surveillance by the National Security Agency, and the companies’ obligation to allow access to data under secret court rules, could be damaging their reputation and commercial interests abroad.

    The gathering followed a closed-doors meeting earlier this week with Obama’s chief of staff Denis McDonough and general counsel Kathy Ruemmler at the White House.

    On the agenda at Tuesday’s meeting were the surveillance activities of the NSA, commercial privacy issues and the online tracking of consumers.

    “This is one of a number of discussions the administration is having with experts and stakeholders in response to the president’s directive to have a national dialogue about how to best protect privacy in a digital era, including how to respect privacy while defending our national security,” one official told Politico.

    McDonough and Ruemmler met members of the Information Technology Industry Council, TechNet and Tech America, which represent a range of companies from defence contractors to digital giants Facebook, Google and Microsoft.

    Campaigners including the American Civil Liberties Union and the Electronic Privacy information Center were also present, Politico’s Tony Romm reported.

    The Guardian’s revelations about the breadth of the NSA’s access to data, particularly relating to foreign individuals, has created PR problems for US companies. Apple has set its sights on China as a huge potential growth market, but if people there fear eavesdropping by the US government it could harm sales. And Google stands to lose business in cloud computing to European rivals if customers fear similar eavesdropping. Cloud computing companies have estimated they could lose billions of dollars of business as a result.

    The White House is also battling to respond to growing unrest over surveillance of citizens by the state and the vast caches of data many digital giants are now storing about individual consumers.

    Obama has promised more public debate about the country’s counterterrorism activities and privacy safeguards in general amid signs of widespread support for NSA whistleblower Edward Snowden, but officials have so far declined to provide details about this week’s technology summits.

    The meetings came as a wave of Americans posted messages of support to the former security contractor, whose leaks exposed the extent of government sponsored surveillance in the US and Europe.

    A website launched by the digital rights group Fight for the Future on Wednesday has attracted more than 10,000 posts expressing support for Snowden’s actions. Billed as an exercise to put faces to statistics, the website features a combination of photographs of individuals holding up signs and written words of support.

    In June, Reuters/Ipsos found 31% of respondents believed Snowden was a patriot, while 23% thought he was a traitor. Another 46% said they did not know. Gallup found in June that 53% of respondents disapproved of government snooping programmes, while just 37% approved and 10% had no opinion.

    In a statement, Fight for the Future cofounder Tiffiniy Cheng said: “We’ve seen an unbelievable response already – the messages keep streaming in. The government reads the same polls that we do. They know that Snowden has the public’s support. But now we’re adding faces to those statistics. As someone who volunteered and worked for Obama’s election, I feel totally burned by the president’s civil liberties and human rights records. If he truly cares about representing the American people, he should turn his attention to shutting down the NSA’s illegal surveillance programs, and leave Mr Snowden alone.”

    The website was launched shortly before Obama pulled out of a presidential meeting with Russia’s leader Vladimir Putin in Moscow next month. This followed Russia’s decision to grant Snowden asylum.

    Juliette Garside
    theguardian.com, Friday 9 August 2013 17.37 BST

    Find this story at 9 August 2013

    © 2014 Guardian News and Media Limited or its affiliated companies. All rights reserved.

    BT and Vodafone among telecoms companies passing details to GCHQ (2013)

    Fears of customer backlash over breach of privacy as firms give GCHQ unlimited access to their undersea cables

    Some of the world’s leading telecoms firms, including BT and Vodafone, are secretly collaborating with Britain’s spy agency GCHQ, and are passing on details of their customers’ phone calls, email messages and Facebook entries, documents leaked by the whistleblower Edward Snowden show.

    BT, Vodafone Cable, and the American firm Verizon Business – together with four other smaller providers – have given GCHQ secret unlimited access to their network of undersea cables. The cables carry much of the world’s phone calls and internet traffic.

    In June the Guardian revealed details of GCHQ’s ambitious data-hoovering programmes, Mastering the Internet and Global Telecoms Exploitation, aimed at scooping up as much online and telephone traffic as possible. It emerged GCHQ was able to tap into fibre-optic cables and store huge volumes of data for up to 30 days. That operation, codenamed Tempora, has been running for 20 months.

    On Friday Germany’s Süddeutsche newspaper published the most highly sensitive aspect of this operation – the names of the commercial companies working secretly with GCHQ, and giving the agency access to their customers’ private communications. The paper said it had seen a copy of an internal GCHQ powerpoint presentation from 2009 discussing Tempora.

    The document identified for the first time which telecoms companies are working with GCHQ’s “special source” team. It gives top secret codenames for each firm, with BT (“Remedy”), Verizon Business (“Dacron”), and Vodafone Cable (“Gerontic”). The other firms include Global Crossing (“Pinnage”), Level 3 (“Little”), Viatel (“Vitreous”) and Interoute (“Streetcar”). The companies refused to comment on any specifics relating to Tempora, but several noted they were obliged to comply with UK and EU law.

    The revelations are likely to dismay GCHQ and Downing Street, who are fearful that BT and the other firms will suffer a backlash from customers furious that their private data and intimate emails have been secretly passed to a government spy agency. In June a source with knowledge of intelligence said the companies had no choice but to co-operate in this operation. They are forbidden from revealing the existence of warrants compelling them to allow GCHQ access to the cables.

    Together, these seven companies operate a huge share of the high-capacity undersea fibre-optic cables that make up the backbone of the internet’s architecture. GCHQ’s mass tapping operation has been built up over the past five years by attaching intercept probes to the transatlantic cables where they land on British shores. GCHQ’s station in Bude, north Cornwall, plays a role. The cables carry data to western Europe from telephone exchanges and internet servers in north America. This allows GCHQ and NSA analysts to search vast amounts of data on the activity of millions of internet users. Metadata – the sites users visit, whom they email, and similar information – is stored for up to 30 days, while the content of communications is typically stored for three days.

    GCHQ has the ability to tap cables carrying both internet data and phone calls. By last year GCHQ was handling 600m “telephone events” each day, had tapped more than 200 fibre-optic cables and was able to process data from at least 46 of them at a time.

    Each of the cables carries data at a rate of 10 gigabits per second, so the tapped cables had the capacity, in theory, to deliver more than 21 petabytes a day – equivalent to sending all the information in all the books in the British Library 192 times every 24 hours.

    This operation is carried out under clandestine agreements with the seven companies, described in one document as “intercept partners”. The companies are paid for logistical and technical assistance.

    The identity of the companies allowing GCHQ to tap their cables was regarded as extremely sensitive within the agency. Though the Tempora programme itself was classified as top secret, the identities of the cable companies was even more secret, referred to as “exceptionally controlled information”, with the company names replaced with the codewords, such as “GERONTIC”, “REMEDY” and “PINNAGE”.

    However, some documents made it clear which codenames referred to which companies. GCHQ also assigned the firms “sensitive relationship teams”. One document warns that if the names emerged it could cause “high-level political fallout”.

    Germans have been enraged by the revelations of spying by the National Security Agency and GCHQ after it emerged that both agencies were hoovering up German data as well. On Friday the Süddeutsche said it was now clear that private telecoms firms were far more deeply complicit in US-UK spying activities than had been previously thought.

    The source familiar with intelligence maintained in June that GCHQ was “not looking at every piece of straw” but was sifting a “vast haystack of data” for what he called “needles”.

    He added: “If you had the impression we are reading millions of emails, we are not. There is no intention in this whole programme to use it for looking at UK domestic traffic – British people talking to each other.” The source said analysts used four criteria for determining what was examined: security, terror, organised crime and Britain’s economic wellbeing.”The vast majority of the data is discarded without being looked at … we simply don’t have the resources.”

    Nonetheless, the agency repeatedly referred to plans to expand this collection ability still further in the future.

    Once it is collected, analysts are able to search the information for emails, online chats and browsing histories using an interface called XKeyscore, uncovered in the Guardian on Wednesday. By May 2012, 300 analysts from GCHQ and 250 NSA analysts had direct access to search and sift through the data collected under the Tempora program.

    Documents seen by the Guardian suggest some telecoms companies allowed GCHQ to access cables which they did not themselves own or operate, but only operated a landing station for. Such practices could raise alarm among other cable providers who do not co-operate with GCHQ programmes that their facilities are being used by the intelligence agency.

    Telecoms providers can be compelled to co-operate with requests from the government, relayed through ministers, under the 1984 Telecommunications Act, but privacy advocates have raised concerns that the firms are not doing enough to challenge orders enabling large-scale surveillance, or are co-operating to a degree beyond that required by law.

    “We urgently need clarity on how close the relationship is between companies assisting with intelligence gathering and government,” said Eric King, head of research for Privacy International. “Were the companies strong-armed, or are they voluntary intercept partners?”

    Vodafone said it complied with the laws of all the countries in which its cables operate. “Media reports on these matters have demonstrated a misunderstanding of the basic facts of European, German and UK legislation and of the legal obligations set out within every telecommunications operator’s licence … Vodafone complies with the law in all of our countries of operation,” said a spokesman.

    “Vodafone does not disclose any customer data in any jurisdiction unless legally required to do so. Questions related to national security are a matter for governments not telecommunications operators.”

    A spokeswoman for Interoute said: “As with all communication providers in Europe we are required to comply with European and local laws including those on data protection and retention. From time to time we are presented with requests from authorities. When we receive such requests, they are processed by our legal and security teams and if valid, acted upon.”

    A spokeswoman for Verizon said: “Verizon continually takes steps to safeguard our customers’ privacy. Verizon also complies with the law in every country in which we operate.”

    BT declined to comment.

    James Ball, Luke Harding and Juliette Garside
    The Guardian, Friday 2 August 2013 18.36 BST

    Find this story at 2 August 2013

    © 2014 Guardian News and Media Limited or its affiliated companies. All rights reserved.

    Newly declassified documents on phone records program released (2013)

    Obama administration officials faced deepening political skepticism Wednesday about a far-reaching counterterrorism program that collects millions of Americans’ phone records, even as they released newly declassified documents in an attempt to spotlight privacy safeguards.

    The previously secret material — a court order and reports to Congress — was released by Director of National Intelligence James R. Clapper as a Senate Judiciary Committee hearing opened Wednesday morning in which lawmakers sharply questioned the efficacy of the collection of bulk phone records. A senior National Security Agency official conceded that the surveillance effort was the primary tool in thwarting only one plot — not the dozens that officials had previously suggested.

    Read the documents
    NSA
    Secret FISA court order to Verizon
    The Obama administration declassified government documents related to NSA collection of telephone metadata records on Wednesday.
    Graphic
    How the secret FISA court works Click Here to View Full Graphic Story
    How the secret FISA court works
    Click here to subscribe.

    In recent weeks, political support for such broad collection has sagged, and the House last week narrowly defeated a bipartisan bid to end the program, at least in its current form. On Wednesday, senior Democratic senators voiced equally strong doubts.

    “This bulk-collection program has massive privacy implications,” said Senate Judiciary Committee Chairman Patrick J. Leahy (Vt.). “The phone records of all of us in this room — all of us in this room — reside in an NSA database. I’ve said repeatedly, just because we have the ability to collect huge amounts of data does not mean that we should be doing so. . . . If this program is not effective, it has to end. So far, I’m not convinced by what I’ve seen.”

    Administration officials defended the collection effort and a separate program targeting foreigners’ communication as essential and operating under stringent guidelines.

    “With these programs and other intelligence activities, we are constantly seeking to achieve the right balance between the protection of national security and the protection of privacy and civil liberties,” Deputy Attorney General James Cole said. “We believe these two programs have achieved the right balance.”

    Cole nonetheless said the administration is open to amending the program to achieve greater public trust. Legislation is pending in the Senate that would narrow its scope.

    The NSA program collecting phone records began after the September 2001 terrorist attacks and was brought under the supervision of the Foreign Intelligence Surveillance Court in 2006. But its existence remained hidden until June, when the Guardian newspaper in Britain published a classified FISC order to a U.S. phone company to turn over to the NSA all call records. Former NSA contractor Edward Snowden leaked the order to the newspaper.

    On Wednesday, the Guardian published new documents provided by Snowden that outlined previously unknown features of an NSA data-retrieval system called XKeyscore. The newspaper reported that the search tool allowed analysts to “search with no prior authorization through vast databases containing emails, online chats and the browsing histories of millions of individuals.”

    NSA slides describing the system published with the Guardian article indicated that analysts used it to sift through government databases, including Pinwale, the NSA’s primary storage system for e-mail and other text, and Marina, the primary storage and analysis tool for “metadata.” Another slide described analysts using XKeyscore to access a database containing phone numbers, e-mail addresses, log-ins and Internet user activity generated from other NSA programs.

    The newspaper said the disclosures shed light on Snowden’s claim that the NSA’s surveillance programs allowed him while sitting at his desk to “wiretap anyone, from you or your accountant, to a federal judge or even the president, if I had a personal ­e-mail.” U.S. officials have denied that he had such capability.

    In a statement responding to the Guardian report, the NSA said “the implication that NSA’s collection is arbitrary and unconstrained is false. NSA’s activities are focused and specifically deployed against — and only against — legitimate foreign intelligence targets.” The agency further said: “Access to XKEYSCORE, as well as all of NSA’s analytic tools, is limited to only those personnel who require access for their assigned tasks. . . . Not every analyst can perform every function, and no analyst can operate freely. Every search by an NSA analyst is fully auditable, to ensure that they are proper and within the law.”

    On Wednesday, Clapper disclosed the FISA court’s “primary” order that spells out the program’s collection rules and two reports to Congress that discussed the program, which is authorized under Section 215 of the “business records” provision of the Foreign Intelligence Surveillance Act. Administration officials released the documents to reassure critics that the program is strictly supervised and minimally invasive.

    For instance, the primary order states that only “appropriately trained and authorized personnel” may have access to the records, which consist of phone numbers of calls made and received, their time and duration, but not names and content. Officials call this metadata. The order also states that to query the data, there must be “reasonable, articulable suspicion,” presumably that the number is linked to a foreign terrorist group.

    But the documents fueled more concern about the program’s scope among civil liberties advocates who are pressing the administration to release the legal rationale that might explain what makes such large numbers of records relevant to an authorized investigation. Perhaps most alarming to some critics was the disclosure, in the order, that queries of the metadata return results that are placed into a “corporate store” that may then be searched for foreign intelligence purposes with fewer restrictions.

    That disclosure takes on significance in light of Deputy NSA Director John C. Inglis’s testimony last month that analysts could extend their searches by “three hops.” That means that starting from a target’s phone number, analysts can search on the phone numbers of people in contact with the target, then the numbers of people in contact with that group, and then the numbers of people in contact with that larger pool. That is potentially millions of people, said Jameel Jaffer, deputy legal director of the American Civil Liberties Union, who also testified Wednesday.

    The Office of the DNI earlier released a statement that fewer than 300 numbers were queried in 2012. That could still mean potentially hundreds of millions of records, Sen. Richard J. Durbin (D-Ill.) said at the hearing.

    Also, according to the order, the NSA does not need to audit the results of searches of the corporate store.

    The order asserts that phone metadata could be obtained with a grand jury subpoena. That may be true for one person or even a group of people, but not for all Americans’ phone records, critics said.

    Privacy advocates criticized redactions in the reports to Congress of information about the NSA’s failure to comply with its own internal rules. That is “among the most important information that the American public needs to critically assess whether these programs are proper,” said Mark Rumold, a staff lawyer at the Electronic Frontier Foundation.

    At the hearing, Leahy voiced upset with the administration for suggesting that the program was as effective in thwarting terrorist plots as another NSA program, authorized under Section 702 of FISA and targeting foreigners’ communications. “I don’t think that’s a coincidence when we have people in government make that comparison, but it needs to stop,” he said of attempts to conflate the two programs’ utility.

    He noted that senior officials had testified that the phone logging effort was critical to thwarting 54 plots, but after reviewing NSA material, he said that assertion cannot be made — “not by any stretch.” Pressed by Leahy on the point, Inglis admitted that the program “made a contribution” in 12 plots with a domestic nexus, but only one case came close to a “but-for” or critical contribution.

    Carol D. Leonnig and William Branigin contributed to this report.

    By Ellen Nakashima, Published: July 31, 2013

    Find this story at 31 July 2013

    © 1996-2014 The Washington Post

    Telekom-Riesen helfen den Geheimdiensten (2013)

    Der britische Geheimdienst wurde bei Abhöraktionen umfangreicher von Telekommunikationsfirmen unterstützt als bislang bekannt. Das berichten “Süddeutsche Zeitung” und NDR. Sogar Programmierarbeit soll an die Firmen ausgelagert worden sein.

    Berlin – Laut übereinstimmenden Berichten des NDR und der “Süddeutschen Zeitung” (SZ) sind einige private Telekommunikationsunternehmen stärker in die Abhöraktionen ausländischer Geheimdienste verwickelt als bisher angenommen. Der britische Geheimdienst GCHQ etwa, ein enger Partner des US-Diensts NSA, arbeite beim Abhören des Internetverkehrs mit sieben großen Firmen zusammen.

    NDR und “Süddeutsche Zeitung” beziehen sich in ihren Berichten auf Dokumente des ehemaligen NSA-Vertragsmitarbeiters Edward Snowden, die sie einsehen konnten. Die interne Präsentation von 2009 nennt neben den internationalen Unternehmen British Telecom, Verizon und Vodafone auch die Netzwerkbetreiber Level 3, Interoute, Viatel und Global Crossing als Schlüsselpartner des GCHQ. Global Crossing wurde inzwischen von Level 3 gekauft.

    Gemeinsam spannen die Unternehmen laut NDR und “SZ” ein engmaschiges Datennetz über Europa und weite Teile der Welt. Einige Firmen wie Level 3 betreiben in Deutschland demnach große Datenzentren. Demnach betreibt Level 3 Rechenzentren in mehreren deutschen Städten, ein Transatlantikkabel von Global Crossing ist in Westerland auf Sylt mit deutschen Netzen verbunden. Das Unternehmen Interoute, das den Unterlagen zufolge auch mit dem GCHQ kooperiert, betreibt 15 Netzknoten in Deutschland.

    Teilweise sei die Kooperation mit dem Geheimdienst über den einfachen Zugang zu den Datennetzen hinausgegangen, berichten “SZ” und NDR. Einige Firmen sollen laut den Dokumenten sogar Computerprogramme entwickelt haben, um dem britischen Geheimdienst das Abfangen von Daten aus ihren Netzen zu erleichtern. Faktisch habe der GCHQ einen Teil seiner Ausspäharbeit an Privatunternehmen delegiert.

    Viatel bestreitet Zusammenarbeit

    Die meisten der Unternehmen verwiesen laut NDR und “SZ” auf Gesetze, die Regierungen erlaubten, Firmen unter bestimmten Umständen zur Herausgabe von Informationen zu verpflichten. Viatel widersprach den Angaben und erklärte, nicht mit dem GCHQ zu kooperieren und dem Geheimdienst auch keinen Zugang zur eigenen Infrastruktur oder zu Kundendaten zu gewähren.

    02. August 2013, 09:20 Uhr

    Find this story at 2 August 2013

    © SPIEGEL ONLINE 2013

    Agreements with private companies protect U.S. access to cables’ data for surveillance (2013)

    The U.S. government had a problem: Spying in the digital age required access to the fiber-optic cables traversing the world’s oceans, carrying torrents of data at the speed of light. And one of the biggest operators of those cables was being sold to an Asian firm, potentially complicating American surveillance efforts.

    Enter “Team Telecom.”

    In months of private talks, the team of lawyers from the FBI and the departments of Defense, Justice and Homeland Security demanded that the company maintain what amounted to an internal corporate cell of American citizens with government clearances. Among their jobs, documents show, was ensuring that surveillance requests got fulfilled quickly and confidentially.

    This “Network Security Agreement,” signed in September 2003 by Global Crossing, became a model for other deals over the past decade as foreign investors increasingly acquired pieces of the world’s telecommunications infrastructure.

    The publicly available agreements offer a window into efforts by U.S. officials to safeguard their ability to conduct surveillance through the fiber-optic networks that carry a huge majority of the world’s voice and Internet traffic.

    The agreements, whose main purpose is to secure the U.S. telecommunications networks against foreign spying and other actions that could harm national security, do not authorize surveillance. But they ensure that when U.S. government agencies seek access to the massive amounts of data flowing through their networks, the companies have systems in place to provide it securely, say people familiar with the deals.

    Negotiating leverage has come from a seemingly mundane government power: the authority of the Federal Communications Commission to approve cable licenses. In deals involving a foreign company, say people familiar with the process, the FCC has held up approval for many months while the squadron of lawyers dubbed Team Telecom developed security agreements that went beyond what’s required by the laws governing electronic eavesdropping.

    The security agreement for Global Crossing, whose fiber-optic network connected 27 nations and four continents, required the company to have a “Network Operations Center” on U.S. soil that could be visited by government officials with 30 minutes of warning. Surveillance requests, meanwhile, had to be handled by U.S. citizens screened by the government and sworn to secrecy — in many cases prohibiting information from being shared even with the company’s executives and directors.

    “Our telecommunications companies have no real independence in standing up to the requests of government or in revealing data,” said Susan Crawford, a Yeshiva University law professor and former Obama White House official. “This is yet another example where that’s the case.”

    The full extent of the National Security Agency’s access to fiber-optic cables remains classified. The Office of the Director of National Intelligence issued a statement saying that legally authorized data collection “has been one of our most important tools for the protection of the nation’s — and our allies’ — security. Our use of these authorities has been properly classified to maximize the potential for effective collection against foreign terrorists and other adversaries.”

    It added, “As always, the Intelligence and law enforcement communities will continue to work with all members of Congress to ensure the proper balance of privacy and protection for American citizens.”

    Collecting information

    Documents obtained by The Washington Post and Britain’s Guardian newspaper in recent weeks make clear how the revolution in information technology sparked a revolution in surveillance, allowing the U.S. government and its allies to monitor potential threats with a reach impossible only a few years earlier.

    Yet any access to fiber-optic cables allows for possible privacy intrusions into Americans’ personal communications, civil libertarians say.

    As people worldwide chat, browse and post images through online services, much of the information flows within the technological reach of U.S. surveillance. Though laws, procedural rules and internal policies limit how that information can be collected and used, the data from billions of devices worldwide flow through Internet choke points that the United States and its allies are capable of monitoring.

    This broad-based surveillance of fiber-optic networks runs parallel to the NSA’s PRISM program, which allows analysts to access data from nine major Internet companies, including Google, Facebook, Microsoft, Yahoo, AOL and Apple, according to classified NSA PowerPoint slides. (The companies have said the collection is legal and limited.)

    One NSA slide titled, “Two Types of Collection,” shows both PRISM and a separate effort labeled “Upstream” and lists four code names: Fairview, Stormbrew, Blarney and Oakstar. A diagram superimposed on a crude map of undersea cable networks describes the Upstream program as collecting “communications on fiber cables and infrastructure as data flows past.”

    The slide has yellow arrows pointing to both Upstream and PRISM and says, “You Should Use Both.” It also has a header saying “FAA 702 Operations,” a reference to a section of the amended Foreign Intelligence Surveillance Act that governs surveillance of foreign targets related to suspected terrorism and other foreign intelligence.

    Under that provision, the government may serve a court order on a company compelling it to reach into its networks for data on multiple targets who are foreigners reasonably believed to be overseas. At an Internet gateway, the government may specify a number of e-mail addresses of foreigners to be targeted without the court signing off on each one.

    When the NSA is collecting the communications of a foreign, overseas target who is speaking or e-mailing with an American, that American’s e-mail or phone call is considered to be “incidentally” collected. It is considered “inadvertently” collected if the target actually turns out to be an American, according to program rules and people familiar with them. The extent of incidental and inadvertent collection has not been disclosed, leading some lawmakers to demand disclosure of estimates of how many Americans’ communications have been gathered. No senior intelligence officials have answered that question publicly.

    Using software that scans traffic and “sniffs out” the targeted e-mail address, the company can pull out e-mail traffic automatically to turn over to the government, according to several former government officials and industry experts.

    It is unclear how effective that approach is compared with collecting from a “downstream” tech company such as Google or Facebook, but the existence of separate programs collecting data from both technology companies and telecommunications systems underscores the reach of government intelligence agencies.

    “People need to realize that there are many ways for the government to get vast amounts of e-mail,” said Chris Soghoian, a technology expert with the American Civil Liberties Union.

    Controlling the data flow

    The drive for new intelligence sources after the Sept. 11, 2001, attacks relied on a key insight: American companies controlled most of the Internet’s essential pipes, giving ample opportunities to tap the torrents of data flowing by. Even terrorists bent on destruction of the United States, it turned out, talked to each other on Web-based programs such as Microsoft’s Hotmail.

    Yet even data not handled by U.S.-based companies generally flowed across parts of the American telecommunications infrastructure. Most important were the fiber-optic cables that largely have replaced the copper telephone wires and the satellite and microwave transmissions that, in an earlier era, were the most important targets for government surveillance.

    Fiber-optic cables, many of which lie along the ocean floor, provide higher-quality transmission and greater capacity than earlier technology, with the latest able to carry thousands of gigabits per second.

    The world’s hundreds of undersea cables now carry 99 percent of all intercontinental data, a category that includes most international phone calls, as well, says TeleGeography, a global research firm.

    The fiber-optic networks have become a rich source of data for intelligence agencies. The Guardian newspaper reported last month that the Government Communications Headquarters, the British equivalent of the NSA, taps and stores data flowing through the fiber-optic cables touching that nation, a major transit point for data between Europe and the Americas. That program, code-named Tempora, shares data with the NSA, the newspaper said.

    Tapping undersea transmission cables had been a key U.S. surveillance tactic for decades, dating back to the era when copper lines carrying sensitive telephone communications could be accessed by listening devices divers could place on the outside of a cable’s housing, said naval historian Norman Polmar, author of “Spy Book: The Encyclopedia of Espionage.”

    “The U.S. has had four submarines that have been outfitted for these special missions,” he said.

    But the fiber-optic lines — each no thicker than a quarter — were far more difficult to tap successfully than earlier generations of undersea technology, and interception operations ran the risk of alerting cable operators that their network had been breached.

    It’s much easier to collect information from any of dozens of cable landing stations around the world — where data transmissions are sorted into separate streams — or in some cases from network operations centers that oversee the entire system, say those familiar with the technology who spoke on the condition of anonymity to discuss sensitive intelligence matters.

    Expanding powers

    In the aftermath of the Sept. 11 attacks, the NSA said its collection of communications inside the United States was constrained by statute, according to a draft report by the agency’s inspector general in 2009, which was obtained by The Post and the Guardian. The NSA had legal authority to conduct electronic surveillance on foreigners overseas, but the agency was barred from collecting such information on cables as it flowed into and through the United States without individual warrants for each target.

    “By 2001, Internet communications were used worldwide, underseas cables carried huge volumes of communications, and a large amount of the world’s communications passed through the United States,” the report said. “Because of language used in the [Foreign Intelligence Surveillance] Act in 1978, NSA was required to obtain court orders to target e-mail accounts used by non-U.S. persons outside the United States if it intended to intercept the communications at a webmail service within the United States. Large numbers of terrorists were using such accounts in 2001.”

    As a result, after White House and CIA officials consulted with the NSA director, President George W. Bush, through a presidential order, expanded the NSA’s legal authority to collect communications inside the United States. The President’s Surveillance Program, the report said, “significantly increased [NSA’s] access to transiting foreign communications.”

    Gen. Michael Hayden, then the NSA director, described that information as “the real gold of the program” that led to the identification of threats within the United States, according to the inspector general’s report.

    Elements of the President’s Surveillance Program became public in 2005, when the New York Times reported the government’s ability to intercept e-mail and phone call content inside the United States without court warrants, sparking controversy. The FISA court began oversight of those program elements in 2007.

    As these debates were playing out within the government, Team Telecom was making certain that surveillance capacity was not undermined by rising foreign ownership of the fiber-optic cables that the NSA was using.

    The Global Crossing deal created particular concerns. The company had laid an extensive network of undersea cables in the world, but it went bankrupt in 2002 after struggling to handle more than $12 billion in debt.

    Two companies, one from Singapore and a second from Hong Kong, struck a deal to buy a majority stake in Global Crossing, but U.S. government lawyers immediately objected as part of routine review of foreign investment into critical U.S. infrastructure.

    President Gerald Ford in 1975 had created an interagency group — the Committee on Foreign Investment in the United States, or CFIUS — to review deals that might harm U.S. national security. Team Telecom grew out of that review process. Those executive branch powers were expanded several times over the decades and became even more urgent after the Sept. 11 attacks, when the Defense Department became an important player in discussions with telecommunications companies.

    The Hong Kong company soon withdrew from the Global Crossing deal, under pressure from Team Telecom, which was worried that the Chinese government might gain access to U.S. surveillance requests and infrastructure, according to people familiar with the negotiations.

    Singapore Technologies Telemedia eventually agreed to a slate of concessions, including allowing half of the board of directors of a new subsidiary managing the undersea cable network to consist of American citizens with security clearances. They would oversee a head of network operations, a head of global security, a general counsel and a human resources officer — all of whom also would be U.S. citizens with security clearances. The FBI and the departments of Defense, Justice and Homeland Security had the power to object to any appointments to those jobs or to the directors who had to be U.S. citizens.

    U.S. law already required that telecommunications companies doing business in the United States comply with surveillance requests, both domestic and international. But the security agreement established the systems to ensure that compliance and to make sure foreign governments would not gain visibility into the working of American telecommunications systems — or surveillance systems, said Andrew D. Lipman, a telecommunications lawyer who has represented Global Crossing and other firms in negotiating such deals.

    “These Network Security Agreements flesh out the details,” he said.

    Lipman, a partner with Bingham McCutchen, based in Washington, said the talks with Team Telecom typically involve little give and take. “It’s like negotiating with the Motor Vehicle Department,” he said.

    Singapore Technologies Telemedia sold Global Crossing in 2011 to Level 3 Communications, a company based in Colorado. But the Singaporean company maintained a minority ownership stake, helping trigger a new round of review by Team Telecom and a new Network Security Agreement that added several new conditions.

    A spokesman for Level 3 Communications declined to comment for this article.

    By Craig Timberg and Ellen Nakashima, Published: July 7, 2013

    Find this story at 7 July 2013

    © 1996-2014 The Washington Post

    Microsoft handed the NSA access to encrypted messages (2013)

    • Secret files show scale of Silicon Valley co-operation on Prism
    • Outlook.com encryption unlocked even before official launch
    • Skype worked to enable Prism collection of video calls
    • Company says it is legally compelled to comply

    Microsoft has collaborated closely with US intelligence services to allow users’ communications to be intercepted, including helping the National Security Agency to circumvent the company’s own encryption, according to top-secret documents obtained by the Guardian.

    The files provided by Edward Snowden illustrate the scale of co-operation between Silicon Valley and the intelligence agencies over the last three years. They also shed new light on the workings of the top-secret Prism program, which was disclosed by the Guardian and the Washington Post last month.

    The documents show that:

    • Microsoft helped the NSA to circumvent its encryption to address concerns that the agency would be unable to intercept web chats on the new Outlook.com portal;

    • The agency already had pre-encryption stage access to email on Outlook.com, including Hotmail;

    • The company worked with the FBI this year to allow the NSA easier access via Prism to its cloud storage service SkyDrive, which now has more than 250 million users worldwide;

    • Microsoft also worked with the FBI’s Data Intercept Unit to “understand” potential issues with a feature in Outlook.com that allows users to create email aliases;

    • In July last year, nine months after Microsoft bought Skype, the NSA boasted that a new capability had tripled the amount of Skype video calls being collected through Prism;

    • Material collected through Prism is routinely shared with the FBI and CIA, with one NSA document describing the program as a “team sport”.

    The latest NSA revelations further expose the tensions between Silicon Valley and the Obama administration. All the major tech firms are lobbying the government to allow them to disclose more fully the extent and nature of their co-operation with the NSA to meet their customers’ privacy concerns. Privately, tech executives are at pains to distance themselves from claims of collaboration and teamwork given by the NSA documents, and insist the process is driven by legal compulsion.

    In a statement, Microsoft said: “When we upgrade or update products we aren’t absolved from the need to comply with existing or future lawful demands.” The company reiterated its argument that it provides customer data “only in response to government demands and we only ever comply with orders for requests about specific accounts or identifiers”.

    In June, the Guardian revealed that the NSA claimed to have “direct access” through the Prism program to the systems of many major internet companies, including Microsoft, Skype, Apple, Google, Facebook and Yahoo.

    Blanket orders from the secret surveillance court allow these communications to be collected without an individual warrant if the NSA operative has a 51% belief that the target is not a US citizen and is not on US soil at the time. Targeting US citizens does require an individual warrant, but the NSA is able to collect Americans’ communications without a warrant if the target is a foreign national located overseas.

    Since Prism’s existence became public, Microsoft and the other companies listed on the NSA documents as providers have denied all knowledge of the program and insisted that the intelligence agencies do not have back doors into their systems.

    Microsoft’s latest marketing campaign, launched in April, emphasizes its commitment to privacy with the slogan: “Your privacy is our priority.”

    Similarly, Skype’s privacy policy states: “Skype is committed to respecting your privacy and the confidentiality of your personal data, traffic data and communications content.”

    But internal NSA newsletters, marked top secret, suggest the co-operation between the intelligence community and the companies is deep and ongoing.

    The latest documents come from the NSA’s Special Source Operations (SSO) division, described by Snowden as the “crown jewel” of the agency. It is responsible for all programs aimed at US communications systems through corporate partnerships such as Prism.

    The files show that the NSA became concerned about the interception of encrypted chats on Microsoft’s Outlook.com portal from the moment the company began testing the service in July last year.

    Within five months, the documents explain, Microsoft and the FBI had come up with a solution that allowed the NSA to circumvent encryption on Outlook.com chats

    A newsletter entry dated 26 December 2012 states: “MS [Microsoft], working with the FBI, developed a surveillance capability to deal” with the issue. “These solutions were successfully tested and went live 12 Dec 2012.”

    Two months later, in February this year, Microsoft officially launched the Outlook.com portal.

    Another newsletter entry stated that NSA already had pre-encryption access to Outlook email. “For Prism collection against Hotmail, Live, and Outlook.com emails will be unaffected because Prism collects this data prior to encryption.”

    Microsoft’s co-operation was not limited to Outlook.com. An entry dated 8 April 2013 describes how the company worked “for many months” with the FBI – which acts as the liaison between the intelligence agencies and Silicon Valley on Prism – to allow Prism access without separate authorization to its cloud storage service SkyDrive.

    The document describes how this access “means that analysts will no longer have to make a special request to SSO for this – a process step that many analysts may not have known about”.

    The NSA explained that “this new capability will result in a much more complete and timely collection response”. It continued: “This success is the result of the FBI working for many months with Microsoft to get this tasking and collection solution established.”

    A separate entry identified another area for collaboration. “The FBI Data Intercept Technology Unit (DITU) team is working with Microsoft to understand an additional feature in Outlook.com which allows users to create email aliases, which may affect our tasking processes.”

    The NSA has devoted substantial efforts in the last two years to work with Microsoft to ensure increased access to Skype, which has an estimated 663 million global users.

    One document boasts that Prism monitoring of Skype video production has roughly tripled since a new capability was added on 14 July 2012. “The audio portions of these sessions have been processed correctly all along, but without the accompanying video. Now, analysts will have the complete ‘picture’,” it says.

    Eight months before being bought by Microsoft, Skype joined the Prism program in February 2011.

    According to the NSA documents, work had begun on smoothly integrating Skype into Prism in November 2010, but it was not until 4 February 2011 that the company was served with a directive to comply signed by the attorney general.

    The NSA was able to start tasking Skype communications the following day, and collection began on 6 February. “Feedback indicated that a collected Skype call was very clear and the metadata looked complete,” the document stated, praising the co-operation between NSA teams and the FBI. “Collaborative teamwork was the key to the successful addition of another provider to the Prism system.”

    ACLU technology expert Chris Soghoian said the revelations would surprise many Skype users. “In the past, Skype made affirmative promises to users about their inability to perform wiretaps,” he said. “It’s hard to square Microsoft’s secret collaboration with the NSA with its high-profile efforts to compete on privacy with Google.”

    The information the NSA collects from Prism is routinely shared with both the FBI and CIA. A 3 August 2012 newsletter describes how the NSA has recently expanded sharing with the other two agencies.

    The NSA, the entry reveals, has even automated the sharing of aspects of Prism, using software that “enables our partners to see which selectors [search terms] the National Security Agency has tasked to Prism”.

    The document continues: “The FBI and CIA then can request a copy of Prism collection of any selector…” As a result, the author notes: “these two activities underscore the point that Prism is a team sport!”

    In its statement to the Guardian, Microsoft said:

    We have clear principles which guide the response across our entire company to government demands for customer information for both law enforcement and national security issues. First, we take our commitments to our customers and to compliance with applicable law very seriously, so we provide customer data only in response to legal processes.

    Second, our compliance team examines all demands very closely, and we reject them if we believe they aren’t valid. Third, we only ever comply with orders about specific accounts or identifiers, and we would not respond to the kind of blanket orders discussed in the press over the past few weeks, as the volumes documented in our most recent disclosure clearly illustrate.

    Finally when we upgrade or update products legal obligations may in some circumstances require that we maintain the ability to provide information in response to a law enforcement or national security request. There are aspects of this debate that we wish we were able to discuss more freely. That’s why we’ve argued for additional transparency that would help everyone understand and debate these important issues.

    In a joint statement, Shawn Turner, spokesman for the director of National Intelligence, and Judith Emmel, spokeswoman for the NSA, said:

    The articles describe court-ordered surveillance – and a US company’s efforts to comply with these legally mandated requirements. The US operates its programs under a strict oversight regime, with careful monitoring by the courts, Congress and the Director of National Intelligence. Not all countries have equivalent oversight requirements to protect civil liberties and privacy.

    They added: “In practice, US companies put energy, focus and commitment into consistently protecting the privacy of their customers around the world, while meeting their obligations under the laws of the US and other countries in which they operate.”

    • This article was amended on 11 July 2013 to reflect information from Microsoft that it did not make any changes to Skype to allow Prism collection on or around July 2012.

    Glenn Greenwald, Ewen MacAskill, Laura Poitras, Spencer Ackerman and Dominic Rushe
    The Guardian, Friday 12 July 2013

    Find this story at 12 July 2013

    © 2014 Guardian News and Media Limited or its affiliated companies. All rights reserved.

    Microsoft soll seit Jahren mit US-Ermittlern kooperieren (2013)

    Microsoft arbeitet angeblich intensiv mit US-Geheimdiensten zusammen. Nach Informationen, die Edward Snowden dem “Guardian” zugespielt hat, soll der Konzern den Ermittlern Zugang zu E-Mails und Skype-Gesprächen gewährt und sogar die firmeneigene Verschlüsselung ausgehebelt haben.

    Hamburg/London – Edward Snowden hat mit seinen Enthüllungen über die globale Datenschnüffelei der US-Geheimdienste nicht nur die amerikanische Politik in helle Aufregung versetzt, sondern auch die dortige IT-Branche. Giganten wie Facebook, Apple, Google und Microsoft haben bisher versucht, den Eindruck zu erwecken, ihre Zusammenarbeit mit den US-Behörden beschränke sich auf das Nötigste.

    Jetzt aber berichtet der britische “Guardian”, wie Microsoft mit den Ermittlern kooperiert. Demnach zeigen Informationen von Snowden, dass das Unternehmen seit drei Jahren intensiv mit US-Geheimdiensten zusammenarbeitet.

    Die National Security Agency (NSA) habe etwa die Sorge geäußert, Web-Chats auf dem neuen Outlook.com-Portal nicht mitlesen zu können. Microsoft habe daraufhin der NSA geholfen, die konzerneigene Verschlüsselungstechnik zu umgehen. Dieses Vorgehen soll sich dem Bericht zufolge nicht auf die Web-Chats beschränkt haben: Die NSA soll auch Zugang zu E-Mails auf Outlook.com und Hotmail trotz der Verschlüsselung gehabt haben.

    Auch der Internettelefoniedienst Skype, den Microsoft im Oktober 2011 gekauft hat, geriet ins Visier der NSA: Laut “Guardian” hat die Firma Geheimdiensten ermöglicht, im Rahmen des “Prism”-Überwachungsprogramms sowohl Video- als auch Audio-Unterhaltungen mitzuschneiden.

    Microsoft begründete sein Vorgehen mit rechtlichen Zwängen: “Wenn wir Produkte verbessern, müssen wir uns weiterhin Anfragen beugen, die mit dem Gesetz in Einklang sind.” Das Unternehmen betonte, dass es Kundendaten nur auf Anfrage der Regierung herausgebe – und auch das nur, wenn es um spezifische Konten oder Nutzer gehe.

    Spannungen zwischen Silicon Valley und Obama-Regierung

    Aus den Unterlagen geht laut “Guardian” hervor, dass das durch “Prism” gesammelte Material routinemäßig an das FBI und den US-Auslandsgeheimdienst CIA geht. In einem NSA-Dokument sei von einem “Mannschaftssport” die Rede.

    Die neuen Informationen zeigen nach Angaben des “Guardian” auch, dass es Spannungen zwischen dem Silicon Valley, Standort zahlreicher Computerunternehmen, und der Regierung von US-Präsident Barack Obama gibt. Alle großen Technologiefirmen drängten die US-Regierung, ihnen zu erlauben, das Ausmaß der Zusammenarbeit mit den Behörden öffentlich zu machen, um den Datenschutzbedenken ihrer Kunden gerecht zu werden.

    11. Juli 2013, 23:34 Uhr

    Find this story at 11 July 2013

    © SPIEGEL ONLINE 2013

    Edward Snowden: US government spied on human rights workers

    Whistleblower tells Council of Europe NSA deliberately snooped on groups such as Human Rights Watch and Amnesty International

    The US has spied on the staff of prominent human rights organisations, Edward Snowden has told the Council of Europe in Strasbourg, Europe’s top human rights body.

    Giving evidence via a videolink from Moscow, Snowden said the National Security Agency – for which he worked as a contractor – had deliberately snooped on bodies like Amnesty International and Human Rights Watch.

    He told council members: “The NSA has specifically targeted either leaders or staff members in a number of civil and non-governmental organisations … including domestically within the borders of the United States.” Snowden did not reveal which groups the NSA had bugged.

    The assembly asked Snowden if the US spied on the “highly sensitive and confidential communications” of major rights bodies such as Amnesty and Human Rights Watch, as well as on similar smaller regional and national groups. He replied: “The answer is, without question, yes. Absolutely.”

    Snowden, meanwhile, dismissed NSA claims that he had swiped as many as 1.7m documents from the agency’s servers in an interview with Vanity Fair. He described the number released by investigators as “simply a scare number based on an intentionally crude metric: everything that I ever digitally interacted with in my career.”

    He added: “Look at the language officials use in sworn testimony about these records: ‘could have,’ ‘may have,’ ‘potentially.’ They’re prevaricating. Every single one of those officials knows I don’t have 1.7m files, but what are they going to say? What senior official is going to go in front of Congress and say, ‘We have no idea what he has, because the NSA’s auditing of systems holding hundreds of millions of Americans’ data is so negligent that any high-school dropout can walk out the door with it’?”

    In live testimony to the Council of Europe, Snowden also gave a forensic account of how the NSA’s powerful surveillance programs violate the EU’s privacy laws. He said programs such as XKeyscore, revealed by the Guardian last July, use sophisticated data mining techniques to screen “trillions” of private communications.

    “This technology represents the most significant new threat to civil liberties in modern times,” he declared.

    XKeyscore allows analysts to search with no prior authorisation through vast databases containing emails, online chats, and the browsing histories of millions of individuals.

    Snowden said on Tuesday that he and other analysts were able to use the tool to select an individual’s metadata and content “without judicial approval or prior review”.

    In practical terms, this meant the agency tracked citizens not involved in any nefarious activities, he stressed. The NSA operated a “de facto policy of guilt by association”, he added.

    Snowden said the agency, for example, monitored the travel patterns of innocent EU and other citizens not involved in terrorism or any wrongdoing.

    The 30-year-old whistleblower – who began his intelligence career working for the CIA in Geneva – said the NSA also routinely monitored the communications of Swiss nationals “across specific routes”.

    Others who fell under its purview included people who accidentally followed a wrong link, downloaded the wrong file, or “simply visited an internet sex forum”. French citizens who logged on to a suspected network were also targeted, he said.

    The XKeyscore program amounted to an egregious form of mass surveillance, Snowden suggested, because it hoovered up data from “entire populations”. Anyone using non-encrypted communications might be targeted on the basis of their “religious beliefs, sexual or political affiliations, transactions with certain businesses” and even “gun ownership”, he claimed.

    Snowden said he did not believe the NSA was engaged in “nightmare scenarios”, such as the active compilation of a list of homosexuals “to round them up and send them into camps”. But he said that the infrastructure allowing this to happen had been built. The NSA, its allies, authoritarian governments and even private organisations could all abuse this technology, he said, adding that mass surveillance was a “global problem”. It led to “less liberal and safe societies”, he told the council.

    At times assembly members struggled to follow Snowden’s rapid, sometimes technical delivery. At one point the session’s chairperson begged him to slow down, so the translators could catch up.

    Snowden also criticised the British spy agency GCHQ. He cited the agency’s Optic Nerve program revealed by the Guardian in February. It was, he said, one of many “abusive” examples of state snooping. Under the program GCHQ bulk collects images from Yahoo webcam chats. Many of these images were “intensely private” Snowden said, depicting some form of nudity, and often taken from the “bedrooms and private homes” of people not suspected of individualised wrongdoing. “[Optic Nerve] continued even after GCHQ became aware that the vast majority had no intelligence value at all,” Snowden said.

    Snowden made clear he did believe in legitimate intelligence operations. “I would like to clarify I have no intention to harm the US government or strain [its] bilateral ties,” he asserted, adding that he wanted to improve government, not bring it down.

    The exiled American spy, however, said the NSA should abandon its electronic surveillance of entire civilian populations. Instead, he said, it should go back to the traditional model of eavesdropping against specific targets, such as “North Korea, terrorists, cyber-actors, or anyone else.”

    Snowden also urged members of the Council of Europe to encrypt their personal communications. He said that encryption, used properly, could still withstand “brute force attacks” from powerful spy agencies and others. “Properly implemented algorithms backed up by truly random keys of significant length … all require more energy to decrypt than exists in the universe,” he said.

    The international organisation defended its decision to invite Snowden to testify. In a statement on Monday, it said: “Edward Snowden has triggered a massive public debate on privacy in the internet age. We hope to ask him what his revelations mean for ordinary users and how they should protect their privacy and what kind of restrictions Europe should impose on state surveillance.”

    The council invited the White House to give evidence but it declined.

    In the Vanity Fair interview the whistleblower said he paid the bill in the Mira Hotel using his own credit card because he wanted to demonstrate he was not working for a foreign intelligence agency. “My hope was that avoiding ambiguity would prevent spy accusations and create more room for reasonable debate,” he told the magazine. “Unfortunately, a few of the less responsible members of Congress embraced the spy charges for political reasons, as they still do to this day.”

    The NSA says Snowden should have brought his complaints to its own internal oversight and compliance bodies. Snowden, however, insisted he did raise concerns formally, including through emails sent to the NSA’s lawyers. “I directly challenge the NSA to deny that I contacted NSA oversight and compliance bodies directly via email,” he stated.

    Luke Harding
    The Guardian, Tuesday 8 April 2014 16.49 BST

    Find this story at 8 April 2014

    © 2014 Guardian News and Media Limited or its affiliated companies. All rights reserved.

    GCHQ and European spy agencies worked together on mass surveillance

    Edward Snowden papers unmask close technical cooperation and loose alliance between British, German, French, Spanish and Swedish spy agencies

    The German, French, Spanish and Swedish intelligence services have all developed methods of mass surveillance of internet and phone traffic over the past five years in close partnership with Britain’s GCHQ eavesdropping agency.

    The bulk monitoring is carried out through direct taps into fibre optic cables and the development of covert relationships with telecommunications companies. A loose but growing eavesdropping alliance has allowed intelligence agencies from one country to cultivate ties with corporations from another to facilitate the trawling of the web, according to GCHQ documents leaked by the former US intelligence contractor Edward Snowden.

    The files also make clear that GCHQ played a leading role in advising its European counterparts how to work around national laws intended to restrict the surveillance power of intelligence agencies.

    The German, French and Spanish governments have reacted angrily to reports based on National Security Agency (NSA) files leaked by Snowden since June, revealing the interception of communications by tens of millions of their citizens each month. US intelligence officials have insisted the mass monitoring was carried out by the security agencies in the countries involved and shared with the US.

    The US director of national intelligence, James Clapper, suggested to Congress on Tuesday that European governments’ professed outrage at the reports was at least partly hypocritical. “Some of this reminds me of the classic movie Casablanca: ‘My God, there’s gambling going on here,’ ” he said.

    Sweden, which passed a law in 2008 allowing its intelligence agency to monitor cross-border email and phone communications without a court order, has been relatively muted in its response.

    The German government, however, has expressed disbelief and fury at the revelations from the Snowden documents, including the fact that the NSA monitored Angela Merkel’s mobile phone calls.

    After the Guardian revealed the existence of GCHQ’s Tempora programme, in which the electronic intelligence agency tapped directly into the transatlantic fibre optic cables to carry out bulk surveillance, the German justice minister, Sabine Leutheusser-Schnarrenberger, said it sounded “like a Hollywood nightmare”, and warned the UK government that free and democratic societies could not flourish when states shielded their actions in “a veil of secrecy”.

    ‘Huge potential’

    However, in a country-by-country survey of its European partners, GCHQ officials expressed admiration for the technical capabilities of German intelligence to do the same thing. The survey in 2008, when Tempora was being tested, said the Federal Intelligence Service (BND), had “huge technological potential and good access to the heart of the internet – they are already seeing some bearers running at 40Gbps and 100Gbps”.

    Bearers is the GCHQ term for the fibre optic cables, and gigabits per second (Gbps) measures the speed at which data runs through them. Four years after that report, GCHQ was still only able to monitor 10 Gbps cables, but looked forward to tap new 100 Gbps bearers eventually. Hence the admiration for the BND.

    The document also makes clear that British intelligence agencies were helping their German counterparts change or bypass laws that restricted their ability to use their advanced surveillance technology. “We have been assisting the BND (along with SIS [Secret Intelligence Service] and Security Service) in making the case for reform or reinterpretation of the very restrictive interception legislation in Germany,” it says.

    The country-by-country survey, which in places reads somewhat like a school report, also hands out high marks to the GCHQ’s French partner, the General Directorate for External Security (DGSE). But in this case it is suggested that the DGSE’s comparative advantage is its relationship with an unnamed telecommunications company, a relationship GCHQ hoped to leverage for its own operations.

    “DGSE are a highly motivated, technically competent partner, who have shown great willingness to engage on IP [internet protocol] issues, and to work with GCHQ on a “cooperate and share” basis.”

    Noting that the Cheltenham-based electronic intelligence agency had trained DGSE technicians on “multi-disciplinary internet operations”, the document says: “We have made contact with the DGSE’s main industry partner, who has some innovative approaches to some internet challenges, raising the potential for GCHQ to make use of this company in the protocol development arena.”

    GCHQ went on to host a major conference with its French partner on joint internet-monitoring initiatives in March 2009 and four months later reported on shared efforts on what had become by then GCHQ’s biggest challenge – continuing to carry out bulk surveillance, despite the spread of commercial online encryption, by breaking that encryption.

    “Very friendly crypt meeting with DGSE in July,” British officials reported. The French were “clearly very keen to provide presentations on their work which included cipher detection in high-speed bearers. [GCHQ’s] challenge is to ensure that we have enough UK capability to support a longer term crypt relationship.”

    Fresh opportunities

    In the case of the Spanish intelligence agency, the National Intelligence Centre (CNI), the key to mass internet surveillance, at least back in 2008, was the Spaniards’ ties to a British telecommunications company (again unnamed. Corporate relations are among the most strictly guarded secrets in the intelligence community). That was giving them “fresh opportunities and uncovering some surprising results.

    “GCHQ has not yet engaged with CNI formally on IP exploitation, but the CNI have been making great strides through their relationship with a UK commercial partner. GCHQ and the commercial partner have been able to coordinate their approach. The commercial partner has provided the CNI some equipment whilst keeping us informed, enabling us to invite the CNI across for IP-focused discussions this autumn,” the report said. It concluded that GCHQ “have found a very capable counterpart in CNI, particularly in the field of Covert Internet Ops”.

    GCHQ was clearly delighted in 2008 when the Swedish parliament passed a bitterly contested law allowing the country’s National Defence Radio Establishment (FRA) to conduct Tempora-like operations on fibre optic cables. The British agency also claimed some credit for the success.

    “FRA have obtained a … probe to use as a test-bed and we expect them to make rapid progress in IP exploitation following the law change,” the country assessment said. “GCHQ has already provided a lot of advice and guidance on these issues and we are standing by to assist the FRA further once they have developed a plan for taking the work forwards.”

    The following year, GCHQ held a conference with its Swedish counterpart “for discussions on the implications of the new legislation being rolled out” and hailed as “a success in Sweden” the news that FRA “have finally found a pragmatic solution to enable release of intelligence to SAEPO [the internal Swedish security service.]”

    GCHQ also maintains strong relations with the two main Dutch intelligence agencies, the external MIVD and the internal security service, the AIVD.

    “Both agencies are small, by UK standards, but are technically competent and highly motivated,” British officials reported. Once again, GCHQ was on hand in 2008 for help in dealing with legal constraints. “The AIVD have just completed a review of how they intend to tackle the challenges posed by the internet – GCHQ has provided input and advice to this report,” the country assessment said.

    “The Dutch have some legislative issues that they need to work through before their legal environment would allow them to operate in the way that GCHQ does. We are providing legal advice on how we have tackled some of these issues to Dutch lawyers.”

    European allies

    In the score-card of European allies, it appears to be the Italians who come off the worse. GCHQ expresses frustration with the internal friction between Italian agencies and the legal limits on their activities.

    “GCHQ has had some CT [counter-terrorism] and internet-focused discussions with both the foreign intelligence agency (AISE) and the security service (AISI), but has found the Italian intelligence community to be fractured and unable/unwilling to cooperate with one another,” the report said.

    A follow-up bulletin six months later noted that GCHQ was “awaiting a response from AISI on a recent proposal for cooperation – the Italians had seemed keen, but legal obstacles may have been hindering their ability to commit.”

    It is clear from the Snowden documents that GCHQ has become Europe’s intelligence hub in the internet age, and not just because of its success in creating a legally permissive environment for its operations. Britain’s location as the European gateway for many transatlantic cables, and its privileged relationship with the NSA has made GCHQ an essential partner for European agencies. The documents show British officials frequently lobbying the NSA on sharing of data with the Europeans and haggling over its security classification so it can be more widely disseminated. In the intelligence world, far more than it managed in diplomacy, Britain has made itself an indispensable bridge between America and Europe’s spies.

    Julian Borger
    The Guardian, Friday 1 November 2013 17.02 GMT

    Find this story at 1 November 2013

    © 2014 Guardian News and Media Limited or its affiliated companies. All rights reserved.

    NSA spy row: France and Spain ‘shared phone data’ with US

    Spain and France’s intelligence agencies carried out collection of phone records and shared them with NSA, agency says

    European intelligence agencies and not American spies were responsible for the mass collection of phone records which sparked outrage in France and Spain, the US has claimed.
    General Keith Alexander, the head of the National Security Agency, said reports that the US had collected millions of Spanish and French phone records were “absolutely false”.
    “To be perfectly clear, this is not information that we collected on European citizens,” Gen Alexander said when asked about the reports, which were based on classified documents leaked by Edward Snowden, the former NSA contractor.
    Shortly before the NSA chief appeared before a Congressional committee, US officials briefed the Wall Street Journal that in fact Spain and France’s own intelligence agencies had carried out the surveillance and then shared their findings with the NSA.
    The anonymous officials claimed that the monitored calls were not even made within Spanish and French borders and could be surveillance carried on outside of Europe.

    In an aggressive rebuttal of the reports in the French paper Le Monde and the Spanish El Mundo, Gen Alexander said “they and the person who stole the classified data [Mr Snowden] do not understand what they were looking at” when they published slides from an NSA document.
    The US push back came as President Barack Obama was said to be on the verge of ordering a halt to spying on the heads of allied governments.
    The White House said it was looking at all US spy activities in the wake of leaks by Mr Snowden but was putting a “special emphasis on whether we have the appropriate posture when it comes to heads of state”.
    Mr Obama was reported to have already halted eavesdropping at UN’s headquarters in New York.
    German officials said that while the White House’s public statements had become more conciliatory there remained deep wariness and that little progress had been made behind closed doors in formalising an American commitment to curb spying.
    “An agreement that you feel might be broken at any time is not worth very much,” one diplomat told The Telegraph.
    “We need to re-establish trust and then come to some kind of understanding comparable to the [no spy agreement] the US has with other English speaking countries.”
    Despite the relatively close US-German relations, the White House is reluctant to be drawn into any formal agreement and especially resistant to demands that a no-spy deal be expanded to cover all 28 EU member states.
    Viviane Reding, vice-president of the European Commission and EU justice commissioner, warned that the spying row could spill over and damage talks on a free-trade agreement between the EU and US.
    “Friends and partners do not spy on each other,” she said in a speech in Washington. “For ambitious and complex negotiations to succeed there needs to be trust among the negotiating partners. It is urgent and essential that our US partners take clear action to rebuild trust.”
    A spokesman for the US trade negotiators said it would be “unfortunate to let these issues – however important – distract us” from reaching a deal vital to freeing up transatlantic trade worth $3.3 billion dollars (£2bn) a day.
    James Clapper, America’s top national intelligence, told a Congressional hearing yesterday the US does not “spy indiscriminately on the citizens of any country”.
    “We do not spy on anyone except for valid foreign intelligence purposes, and we only work within the law,” Mr Clapper said. “To be sure on occasions we’ve made mistakes, some quite significant, but these are usually caused by human error or technical problems.”
    Pressure from European leaders was added to as some of the US intelligence community’s key Congressional allies balked at the scale of surveillance on friendly governments.
    Dianne Feinstein, the chair of powerful Senate intelligence committee, said she was “totally opposed” to tapping allied leaders and called for a wide-ranging Senate review of the activities of US spy agencies.
    “I do not believe the United States should be collecting phone calls or emails of friendly presidents and prime ministers,” she said.
    John Boehner, the Republican speaker of the house and a traditional hawk on national security, said US spy policy was “imbalanced” and backed calls for a review.
    Mr Boehner has previously been a staunch advocate of the NSA and faced down a July rebellion by libertarian Republicans who tried to pass a law significantly curbing the agency’s power.

    By Raf Sanchez, Peter Foster in Washington8:35PM GMT 29 Oct 2013 Comments15 Comments

    Find this story at 29 October 2013

    © Copyright of Telegraph Media Group Limited 2014

    Officials alert foreign services that Snowden has documents on their cooperation with U.S.

    U.S. officials are alerting some foreign intelligence services that documents detailing their secret cooperation with the United States have been obtained by former National Security Agency contractor Edward Snowden, according to government officials.

    Snowden, U.S. officials said, took tens of thousands of military intelligence documents, some of which contain sensitive material about collection programs against adversaries such as Iran, Russia and China. Some refer to operations that in some cases involve countries not publicly allied with the United States.

    The process of informing officials in capital after capital about the risk of disclosure is delicate. In some cases, one part of the cooperating government may know about the collaboration while others — such as the foreign ministry — may not, the officials said. The documents, if disclosed, could compromise operations, officials said.

    The notifications come as the Obama administration is scrambling to placate allies after allegations that the NSA has spied on foreign leaders, including German Chancellor Angela Merkel. The reports have forced the administration to play down operations targeting friends while also attempting to preserve other programs that depend on provisional partners. In either case, trust in the United States may be compromised.

    “It is certainly a concern, just as much as the U.S. collection [of information on European allies] being put in the news, if not more, because not only does it mean we have the potential of losing collection, but also of harming relationships,” a congressional aide said.

    The Office of the Director of National Intelligence is handling the job of informing the other intelligence services, the officials said. ODNI declined to comment.

    In one case, for instance, the files contain information about a program run from a NATO country against Russia that provides valuable intelligence for the U.S. Air Force and Navy, said one U.S. official, who requested anonymity to discuss an ongoing criminal investigation. Snowden faces theft and espionage charges.

    “If the Russians knew about it, it wouldn’t be hard for them to take appropriate measures to put a stop to it,” the official said.

    Snowden lifted the documents from a top-secret network run by the Defense Intelligence Agency and used by intelligence arms of the Army, Air Force, Navy and Marines, according to sources, who spoke on the condition of anonymity to discuss sensitive matters.

    Snowden took 30,000 documents that involve the intelligence work of one of the services, the official said. He gained access to the documents through the Joint Worldwide Intelligence Communications System, or JWICS, for top-secret/sensitive compartmented information, the sources said.

    The material in question does not deal with NSA surveillance but primarily with standard intelligence about other countries’ military capabilities, including weapons systems — missiles, ships and jets, the officials say.

    Although Snowden obtained a large volume of documents, he is not believed to have shared all of them with journalists, sources say. Moreover, he has stressed to those he has given documents that he does not want harm to result.

    “He’s made it quite clear that he was not going to compromise legitimate national intelligence and national security operations,” said Thomas Drake, a former NSA executive who visited Snowden in Moscow this month. Snowden separately told Drake and a New York Times reporter that he did not take any documents with him to Russia. “There’s a zero percent chance the Russians or Chinese have received any documents,” Snowden told the Times in an online interview last week.

    Indeed, Drake said, Snowden made clear in their conversation that he had learned the lessons of prior disclosures, including those by an Army private who passed hundreds of thousands of diplomatic cables to the anti-
    secrecy organization WikiLeaks, which posted them in bulk online. “It’s telling,” Drake said, “that he did not give anything to WikiLeaks.”

    Nonetheless, the military intelligence agencies remain fearful, officials said. The NSA in recent months has provided them with an accounting of the documents it believes Snowden obtained.

    Intelligence officials said that they could discern no pattern to the military intelligence documents taken and that Snowden appeared to have harvested them at random. “It didn’t seem like he was targeting something specific,” the U.S. official said.

    The notifications are reminiscent of what the State Department had to do in late 2010 in anticipation of the release of hundreds of thousands of sensitive diplomatic cables by WikiLeaks. The department feared that embarrassing details in some of the cables would lead to tension in relations between the United States and other countries.

    In the case of WikiLeaks, the State Department had a number of months to assess the potential impact of the cables’ release and devise a strategy, former State Department spokesman P.J. Crowley said.

    “I’m not sure there were that many startling surprises in the cables,” he said. But there was damage on a country-by-country basis, he said.

    For instance, some of the cables reflected unfavorably on ­then-Libyan leader Moammar Gaddafi, alleging that he feared flying over water and almost never traveled without his “voluptuous blonde” Ukrainian nurse. “All of a sudden we found there were some unsavory guys following” then-U.S. Ambassador to Libya Gene Cretz, Crowley said. “We brought him home for consultations and did not send him back.”

    “But broadly speaking,” Crowley said, “relationships are guided by interests, rather than personalities, and, over time, interests carry the day.”

    The fundamental issue is one of trust, officials said. “We depend to a very great extent on intelligence-sharing relationships with foreign partners, mostly governments — or, in some cases, organizations within governments,” a second U.S. official said. “If they tell us something, we will keep it secret. We expect the same of them. [If that trust is undermined,] these countries, at a minimum, will be thinking twice if they’re going to share something with us or not.”

    Snowden has instructed the reporters with whom he has shared records to use their judgment to avoid publishing anything that would cause harm. “I carefully evaluated every single document I disclosed to ensure that each was legitimately in the public interest,” he told the Guardian newspaper. “There are all sorts of documents that would have made a big impact that I didn’t turn over, because harming people isn’t my goal. Transparency is.”

    It is those documents that may not be subject to journalistic vetting or may be breached by hackers that worry some intelligence officials. Snowden is known to have given documents in any quantity to only three journalists: The Post’s Barton Gellman, independent filmmaker Laura Poitras and former Guardian columnist Glenn Greenwald.

    So far, Drake said, no such documents have been released. Snowden’s disclosures about the NSA have prompted a global debate about the proper scope and purpose of U.S. espionage — against its own and other countries’ citizens.

    “I consider that a good thing,” Drake said.

    By Ellen Nakashima, Published: October 24

    Find this story at 24 October 2013

    © The Washington Post Company

    ‘Success Story’; NSA Targeted French Foreign Ministry

    Espionage by the US on France has already strained relations between the two countries, threatening a trans-Atlantic trade agreement. Now a document seen by SPIEGEL reveals that the NSA also spied on the French Foreign Ministry.

    America’s National Security Agency (NSA) targeted France’s Foreign Ministry for surveillance, according to an internal document seen by SPIEGEL.

    Dated June 2010, the “top secret” NSA document reveals that the intelligence agency was particularly interested in the diplomats’ computer network. All of the country’s embassies and consulates are connected with the Paris headquarters via a virtual private network (VPN), technology that is generally considered to be secure.

    Accessing the Foreign Ministry’s network was considered a “success story,” and there were a number of incidents of “sensitive access,” the document states.

    An overview lists different web addresses tapped into by the NSA, among them “diplomatie.gouv.fr,” which was run from the Foreign Ministry’s server. A list from September 2010 says that French diplomatic offices in Washington and at the United Nations in New York were also targeted, and given the codenames “Wabash” and “Blackfoot,” respectively. NSA technicians installed bugs in both locations and conducted a “collection of computer screens” at the one at the UN.

    A priority list also names France as an official target for the intelligence agency. In particular, the NSA was interested in the country’s foreign policy objectives, especially the weapons trade, and economic stability.

    US-French relations are being strained by such espionage activities. In early July, French President François Hollande threatened to suspend negotiations for a trans-Atlantic free trade agreement, demanding a guarantee from the US that it would cease spying after it was revealed that the French embassy in Washington had been targeted by the NSA.

    “There can be no negotiations or transactions in all areas until we have obtained these guarantees, for France but also for all of the European Union, for all partners of the United States,” he said at the time.

    The NSA declined to comment to SPIEGEL on the matter. As details about the scope of the agency’s international spying operations continue to emerge, Washington has come under increasing pressure from its trans-Atlantic partners. Officials in Europe have expressed concern that negotiations for the trade agreement would be poisoned by a lack of trust.

    09/01/2013 09:32 AM

    Find this story at 1 September 2013

    © SPIEGEL ONLINE 2013

    Snowden Documents Reveal Covert Surveillance and Pressure Tactics Aimed at WikiLeaks and Its Supporters

    Top-secret documents from the National Security Agency and its British counterpart reveal for the first time how the governments of the United States and the United Kingdom targeted WikiLeaks and other activist groups with tactics ranging from covert surveillance to prosecution.

    The efforts – detailed in documents provided previously by NSA whistleblower Edward Snowden – included a broad campaign of international pressure aimed not only at WikiLeaks founder Julian Assange, but at what the U.S. government calls “the human network that supports WikiLeaks.” The documents also contain internal discussions about targeting the file-sharing site Pirate Bay and hacktivist collectives such as Anonymous.

    One classified document from Government Communications Headquarters, Britain’s top spy agency, shows that GCHQ used its surveillance system to secretly monitor visitors to a WikiLeaks site. By exploiting its ability to tap into the fiber-optic cables that make up the backbone of the Internet, the agency confided to allies in 2012, it was able to collect the IP addresses of visitors in real time, as well as the search terms that visitors used to reach the site from search engines like Google.

    Another classified document from the U.S. intelligence community, dated August 2010, recounts how the Obama administration urged foreign allies to file criminal charges against Assange over the group’s publication of the Afghanistan war logs.

    A third document, from July 2011, contains a summary of an internal discussion in which officials from two NSA offices – including the agency’s general counsel and an arm of its Threat Operations Center – considered designating WikiLeaks as “a ‘malicious foreign actor’ for the purpose of targeting.” Such a designation would have allowed the group to be targeted with extensive electronic surveillance – without the need to exclude U.S. persons from the surveillance searches.

    In 2008, not long after WikiLeaks was formed, the U.S. Army prepared a report that identified the organization as an enemy, and plotted how it could be destroyed. The new documents provide a window into how the U.S. and British governments appear to have shared the view that WikiLeaks represented a serious threat, and reveal the controversial measures they were willing to take to combat it.

    In a statement to The Intercept, Assange condemned what he called “the reckless and unlawful behavior of the National Security Agency” and GCHQ’s “extensive hostile monitoring of a popular publisher’s website and its readers.”

    “News that the NSA planned these operations at the level of its Office of the General Counsel is especially troubling,” Assange said. “Today, we call on the White House to appoint a special prosecutor to investigate the extent of the NSA’s criminal activity against the media, including WikiLeaks, its staff, its associates and its supporters.”

    Illustrating how far afield the NSA deviates from its self-proclaimed focus on terrorism and national security, the documents reveal that the agency considered using its sweeping surveillance system against Pirate Bay, which has been accused of facilitating copyright violations. The agency also approved surveillance of the foreign “branches” of hacktivist groups, mentioning Anonymous by name.

    The documents call into question the Obama administration’s repeated insistence that U.S. citizens are not being caught up in the sweeping surveillance dragnet being cast by the NSA. Under the broad rationale considered by the agency, for example, any communication with a group designated as a “malicious foreign actor,” such as WikiLeaks and Anonymous, would be considered fair game for surveillance.

    Julian Sanchez, a research fellow at the Cato Institute who specializes in surveillance issues, says the revelations shed a disturbing light on the NSA’s willingness to sweep up American citizens in its surveillance net.

    “All the reassurances Americans heard that the broad authorities of the FISA Amendments Act could only be used to ‘target’ foreigners seem a bit more hollow,” Sanchez says, “when you realize that the ‘foreign target’ can be an entire Web site or online forum used by thousands if not millions of Americans.”
    GCHQ Spies on WikiLeaks Visitors

    The system used by GCHQ to monitor the WikiLeaks website – codenamed ANTICRISIS GIRL – is described in a classified PowerPoint presentation prepared by the British agency and distributed at the 2012 “SIGDEV Conference.” At the annual gathering, each member of the “Five Eyes” alliance – the United States, United Kingdom, Canada, Australia and New Zealand – describes the prior year’s surveillance successes and challenges.

    In a top-secret presentation at the conference, two GCHQ spies outlined how ANTICRISIS GIRL was used to enable “targeted website monitoring” of WikiLeaks (See slides 33 and 34). The agency logged data showing hundreds of users from around the world, including the United States, as they were visiting a WikiLeaks site –contradicting claims by American officials that a deal between the U.K. and the U.S. prevents each country from spying on the other’s citizens.

    The IP addresses collected by GCHQ are used to identify individual computers that connect to the Internet, and can be traced back to specific people if the IP address has not been masked using an anonymity service. If WikiLeaks or other news organizations were receiving submissions from sources through a public dropbox on their website, a system like ANTICRISIS GIRL could potentially be used to help track them down. (WikiLeaks has not operated a public dropbox since 2010, when it shut down its system in part due to security concerns over surveillance.)

     

    In its PowerPoint presentation, GCHQ identifies its target only as “wikileaks.” One slide, displaying analytics derived from the surveillance, suggests that the site monitored was the official wikileaks.org domain. It shows that users reached the targeted site by searching for “wikileaks.org” and for “maysan uxo,” a term associated with a series of leaked Iraq war logs that are hosted on wikileaks.org.

    The ANTICRISIS GIRL initiative was operated by a GCHQ unit called Global Telecoms Exploitation (GTE), which was previously reported by The Guardian to be linked to the large-scale, clandestine Internet surveillance operation run by GCHQ, codenamed TEMPORA.

    Operating in the United Kingdom and from secret British eavesdropping bases in Cyprus and other countries, GCHQ conducts what it refers to as “passive” surveillance – indiscriminately intercepting massive amounts of data from Internet cables, phone networks and satellites. The GTE unit focuses on developing “pioneering collection capabilities” to exploit the stream of data gathered from the Internet.

    As part of the ANTICRISIS GIRL system, the documents show, GCHQ used publicly available analytics software called Piwik to extract information from its surveillance stream, not only monitoring visits to targeted websites like WikiLeaks, but tracking the country of origin of each visitor.

    It is unclear from the PowerPoint presentation whether GCHQ monitored the WikiLeaks site as part of a pilot program designed to demonstrate its capability, using only a small set of covertly collected data, or whether the agency continues to actively deploy its surveillance system to monitor visitors to WikiLeaks. It was previously reported in The Guardian that X-KEYSCORE, a comprehensive surveillance weapon used by both NSA and GCHQ, allows “an analyst to learn the IP addresses of every person who visits any website the analyst specifies.”

    GCHQ refused to comment on whether ANTICRISIS GIRL is still operational. In an email citing the agency’s boilerplate response to inquiries, a spokeswoman insisted that “all of GCHQ’s work is carried out in accordance with a strict legal and policy framework which ensures that our activities are authorized, necessary and proportionate, and that there is rigorous oversight.”

    But privacy advocates question such assurances. “How could targeting an entire website’s user base be necessary or proportionate?” says Gus Hosein, executive director of the London-based human rights group Privacy International. “These are innocent people who are turned into suspects based on their reading habits. Surely becoming a target of a state’s intelligence and security apparatus should require more than a mere click on a link.”

    The agency’s covert targeting of WikiLeaks, Hosein adds, call into question the entire legal rationale underpinning the state’s system of surveillance. “We may be tempted to see GCHQ as a rogue agency, ungoverned in its use of unprecedented powers generated by new technologies,” he says. “But GCHQ’s actions are authorized by [government] ministers. The fact that ministers are ordering the monitoring of political interests of Internet users shows a systemic failure in the rule of law.”
    Going After Assange and His Supporters

    The U.S. attempt to pressure other nations to prosecute Assange is recounted in a file that the intelligence community calls its “Manhunting Timeline.” The document details, on a country-by-country basis, efforts by the U.S. government and its allies to locate, prosecute, capture or kill alleged terrorists, drug traffickers, Palestinian leaders and others. There is a timeline for each year from 2008 to 2012.

     

    An entry from August 2010 – headlined “United States, Australia, Great Britain, Germany, Iceland” – states: “The United States on August 10 urged other nations with forces in Afghanistan, including Australia, United Kingdom, and Germany, to consider filing criminal charges against Julian Assange.” It describes Assange as the “founder of the rogue Wikileaks Internet website and responsible for the unauthorized publication of over 70,000 classified documents covering the war in Afghanistan.”

     

    In response to questions from The Intercept, the NSA suggested that the entry is “a summary derived from a 2010 article” in the Daily Beast. That article, which cited an anonymous U.S. official, reported that “the Obama administration is pressing Britain, Germany, Australia, and other allied Western governments to consider opening criminal investigations of WikiLeaks founder Julian Assange and to severely limit his nomadic travels across international borders.”

    The government entry in the “Manhunting Timeline” adds Iceland to the list of Western nations that were pressured, and suggests that the push to prosecute Assange is part of a broader campaign. The effort, it explains, “exemplifies the start of an international effort to focus the legal element of national power upon non-state actor Assange, and the human network that supports WikiLeaks.” The entry does not specify how broadly the government defines that “human network,” which could potentially include thousands of volunteers, donors and journalists, as well as people who simply spoke out in defense of WikiLeaks.

    In a statement, the NSA declined to comment on the documents or its targeting of activist groups, noting only that the agency “provides numerous opportunities and forums for their analysts to explore hypothetical or actual circumstances to gain appropriate advice on the exercise of their authorities within the Constitution and the law, and to share that advice appropriately.”

    But the entry aimed at WikiLeaks comes from credentialed officials within the intelligence community. In an interview in Hong Kong last June, Edward Snowden made clear that the only NSA officials empowered to write such entries are those “with top-secret clearance and public key infrastructure certificates” – a kind of digital ID card enabling unique access to certain parts of the agency’s system. What’s more, Snowden added, the entries are “peer reviewed” – and every edit made is recorded by the system.

    The U.S. launched its pressure campaign against WikiLeaks less than a week after the group began publishing the Afghanistan war logs on July 25, 2010. At the time, top U.S. national security officials accused WikiLeaks of having “blood” on its hands. But several months later, McClatchy reported that “U.S. officials concede that they have no evidence to date that the documents led to anyone’s death.”

    The government targeting of WikiLeaks nonetheless continued. In April 2011, Salon reported that a grand jury in Virginia was actively investigating both the group and Assange on possible criminal charges under espionage statutes relating to the publication of classified documents. And in August of 2012, the Sydney Morning Herald, citing secret Australian diplomatic cables, reported that “Australian diplomats have no doubt the United States is still gunning for Julian Assange” and that “Australia’s diplomatic service takes seriously the likelihood that Assange will eventually be extradited to the US on charges arising from WikiLeaks obtaining leaked US military and diplomatic documents.”

    Bringing criminal charges against WikiLeaks or Assange for publishing classified documents would be highly controversial – especially since the group partnered with newspapers like The Guardian and The New York Times to make the war logs public. “The biggest challenge to the press today is the threatened prosecution of WikiLeaks, and it’s absolutely frightening,” James Goodale, who served as chief counsel of the Times during its battle to publish The Pentagon Papers, told the Columbia Journalism Review last March. “If you go after the WikiLeaks criminally, you go after the Times. That’s the criminalization of the whole process.”

    In November 2013, The Washington Post, citing anonymous officials, reported that the Justice Department strongly considered prosecuting Assange, but concluded it “could not do so without also prosecuting U.S. news organizations and journalists” who had partnered with WikiLeaks to publish the documents. According to the Post, officials “realized that they have what they described as a ‘New York Times problem’” – namely, that any theory used to bring charges against Assange would also result in criminal liability for the Times, The Guardian, and other papers which also published secret documents provided to WikiLeaks.
    NSA proposals to target WikiLeaks

    As the new NSA documents make clear, however, the U.S. government did more than attempt to engineer the prosecution of Assange. NSA analysts also considered designating WikiLeaks as a “malicious foreign actor” for surveillance purposes – a move that would have significantly expanded the agency’s ability to subject the group’s officials and supporters to extensive surveillance.

    Such a designation would allow WikiLeaks to be targeted with surveillance without the use of “defeats” – an agency term for technical mechanisms to shield the communications of U.S. persons from getting caught in the dragnet.

    That top-secret document – which summarizes a discussion between the NSA’s Office of the General Counsel and the Oversight and Compliance Office of the agency’s Threat Operations Center – spells out a rationale for including American citizens in the surveillance:

    “If the foreign IP is consistently associated with malicious cyber activity against the U.S., so, tied to a foreign individual or organization known to direct malicious activity our way, then there is no need to defeat any to, from, or about U.S. Persons. This is based on the description that one end of the communication would always be this suspect foreign IP, and so therefore any U.S. Person communicant would be incidental to the foreign intelligence task.”

    In short, labeling WikiLeaks a “malicious foreign target” would mean that anyone communicating with the organization for any reason – including American citizens – could have their communications subjected to government surveillance.

    When NSA officials are asked in the document if WikiLeaks or Pirate Bay could be designated as “malicious foreign actors,” the reply is inconclusive: “Let us get back to you.” There is no indication of whether either group was ever designated or targeted in such a way.

    The NSA’s lawyers did, however, give the green light to subject other activists to heightened surveillance. Asked if it would be permissible to “target the foreign actors of a loosely coupled group of hackers … such as with Anonymous,” the response is unequivocal: “As long as they are foreign individuals outside of the US and do not hold dual citizenship … then you are okay.”
    NSA Lawyers: “It’s Nothing to Worry About”

    Sanchez, the surveillance expert with the Cato Institute, says the document serves as “a reminder that NSA essentially has carte blanche to spy on non-Americans. In public statements, intelligence officials always talk about spying on ‘terrorists,’ as if those are the only targets — but Section 702 [of the 2008 FISA Amendments Act] doesn’t say anything about ‘terrorists.’ They can authorize collection on any ‘persons reasonably believed to be [located] outside the United States,’ with ‘persons’ including pretty much any kind of group not ‘substantially’ composed of Americans.”

    Sanchez notes that while it makes sense to subject some full-scale cyber-attacks to government surveillance, “it would make no sense to lump together foreign cyberattackers with sites voluntarily visited by enormous numbers of Americans, like Pirate Bay or WikiLeaks.”

    Indeed, one entry in the NSA document expressly authorizes the targeting of a “malicious” foreign server – offering Pirate Bay as a specific example –“even if there is a possibility that U.S. persons could be using it as well.” NSA officials agree that there is no need to exclude Americans from the surveillance, suggesting only that the agency’s spies “try to minimize” how many U.S. citizens are caught in the dragnet.

    Another entry even raises the possibility of using X-KEYSCORE, one of the agency’s most comprehensive surveillance programs, to target communications between two U.S.-based Internet addresses if they are operating through a “proxy” being used for “malicious foreign activity.” In response, the NSA’s Threat Operations Center approves the targeting, but the agency’s general counsel requests “further clarification before signing off.”

    If WikiLeaks were improperly targeted, or if a U.S. citizen were swept up in the NSA’s surveillance net without authorization, the agency’s attitude seems to be one of indifference. According to the document – which quotes a response by the NSA’s Office of General Counsel and the oversight and compliance office of its Threat Operations Center – discovering that an American has been selected for surveillance must be mentioned in a quarterly report, “but it’s nothing to worry about.”

    The attempt to target WikiLeaks and its broad network of supporters drew sharp criticism from the group and its allies. “These documents demonstrate that the political persecution of WikiLeaks is very much alive,” says Baltasar Garzón, the Spanish former judge who now represents the group. “The paradox is that Julian Assange and the WikiLeaks organization are being treated as a threat instead of what they are: a journalist and a media organization that are exercising their fundamental right to receive and impart information in its original form, free from omission and censorship, free from partisan interests, free from economic or political pressure.”

    For his part, Assange remains defiant. “The NSA and its U.K. accomplices show no respect for the rule of law,” he told The Intercept. “But there is a cost to conducting illicit actions against a media organization.” Referring to a criminal complaint that the group filed last year against “interference with our journalistic work in Europe,” Assange warned that “no entity, including the NSA, should be permitted to act against a journalist with impunity.”

    Assange indicated that in light of the new documents, the group may take further legal action.

    “We have instructed our general counsel, Judge Baltasar Garzón, to prepare the appropriate response,” he said. “The investigations into attempts to interfere with WikiLeaks’ work will go wherever they need to go. Make no mistake: those responsible will be held to account and brought to justice.”

    By Glenn Greenwald and Ryan Gallagher
    18 Feb 2014, 1:50 AM EST

    Find this story at 18 February 2014

    © 2014 First Look Productions, Inc.

    Leaked NSA documents show debate over tracking WikiLeaks, The Pirate Bay, and others

    Leaked documents posted by Glenn Greenwald and Ryan Gallagher hint at the discussions that took place around online actors like WikiLeaks, The Pirate Bay, and Anonymous, as well as the standards for spying on foreign and domestic internet users. At The Intercept, Greenwald and Gallagher have revealed details about when the NSA and agencies abroad believe it’s acceptable to target a person or site without “defeats” or measures to prevent collecting American information, with an eye towards groups that have proved a thorn in the side of government agencies.

    Julian Assange appears in national security ‘Manhunting Timeline’

    “Can we treat a foreign server who stores, or potentially disseminates leaked or stolen US data on it’s [sic] server as a ‘malicious foreign actor’ for the purpose of targeting with no defeats? Examples: WikiLeaks, thepiratebay.org, etc.” says one of several frequently asked questions apparently posted to an intelligence wiki for the US and other nations in the Five Eyes surveillance partnership. “Let us get back to you,” said a response from the NSA/CSS [Central Security Service] Threat Operation Center and the NSA’s Office of General Counsel. Another question asks whether it’s legal to target members of Anonymous who operate outside the US. “As long as they are foreign individuals outside of the US and do not hold dual citizenship… then you are okay,” came the answer. Agencies were not, however, apparently allowed to store copies of classified documents leaked by Anonymous or other groups in order to analyze the data.

    WikiLeaks in particular came under fire. In addition to these questions, The Intercept leaked parts of a “Manhunting Timeline” that details where and how the US government is attempting to find, capture, or kill terrorists, drug traffickers, and others. This timeline apparently included information on Julian Assange, including attempts to pressure foreign governments into taking legal action against him and “the human network that supports WikiLeaks.” None of this comes as a surprise — the government’s attempts to get governments to put pressure on Assange is well known. Likewise, Anonymous has allegedly compromised government computers, and it’s not strange that the NSA wants to monitor it. The question of treating leaked document repositories as malicious foreign actors is thornier, playing into much larger debates over whether non-traditional journalism should be given the same protection as older outlets like The New York Times.

    “If you ‘guess’ foreign and it’s not, then it is a serious violation.”

    More generally, the document shows a complicated dance between minimizing US data collection and casting an expansive net over foreign surveillance. According to the FAQ, it’s legal to monitor foreign servers that Americans visit (The Pirate Bay is cited again) so long as agents attempt to filter out US information. The same goes for botnets that are operated from hacked US computers by a foreign source. As before, the document points to a fairly low standard for being certain that a target is foreign: 51 percent. A more complicated question is how agents are allowed to search traffic from US-based web giants like Gmail and Twitter. If an agency knows that a foreign potential threat is using one of these sites, it’s theoretically possible to look for traffic from it. But “if you ‘guess’ foreign and it’s not, then it is a serious violation.” In general, though, accidentally making queries a US person who was believed to be foreign was “nothing to worry about,” although it had to be logged for the Office of General Counsel.

    The revelations here are far less conclusive than many of the leaked documents published so far. One slide apparently from an expanded version of this GCHQ document shows an analytics page that seems to monitor visits to WikiLeaks, including which countries visitors came from and how they found the site. But it’s not clear whether this is an ongoing program or a proof of concept test, especially given how few visits appear to be logged. The results are also broadly similar to what someone would get from a basic analytics page, not detailed user information. This slideshow and the FAQ do, however, give us a look into how the NSA and other agencies view online spycraft, both inside and outside the US.

    By Adi Robertson on February 18, 2014 10:36 am

     

    Find this story at 18 February 2014

    © 2014 Vox Media,

    << oudere artikelen  nieuwere artikelen >>