Scrolling box

computer hardware

Breaking News

Social Icons

Recent Comments

Showing posts with label NSA. Show all posts
Showing posts with label NSA. Show all posts

Wednesday, March 19, 2014

NSA can reportedly record every call made in a foreign country

Surveillance system has the capability to store recordings of billions of calls for up to 30 days, according to confidential documents obtained by The Washington Post.
NSA headquarters in Fort Meade, Md.

The National Security Agency has the capability to record "100 percent" of the telephone calls placed in a foreign country and play them back up to a month later, according to a report Tuesday by The Washington Post.
Known as MYSTIC, the surveillance system dates back to 2009, according to documents supplied to the newspaper by former NSA contractor Edward Snowden. The program, which wasn't fully operational until 2011, intercepts and records and stores billions of calls for 30 days on a rolling buffer that purges the oldest recordings as new ones arrive, according to one classified summary cited by the newspaper.
The Post said it withheld, at the request of US officials, the identity of the targeted nation and other nations where the program's use was envisioned.
The revelation is just the latest to emerge from a trove of confidential documents leaked to the media by Snowden, detailing the NSA's controversial surveillance programs. Previous revelations showed how the NSA collected metadata associated with phone calls; this program reportedly extends surveillance to the content of conversations.
Earlier reports have indicated that the NSA has the ability to record nearly all domestic and international phone calls. Wired magazinedisclosed in 2012 that the NSA has established "listening posts" that allow the agency to collect and sift through billions of phone calls through a massive new data center in Utah, "whether they originate within the country or overseas."
The NSA declined to discuss the existence of the MYSTIC recording program but insisted that all of the agency's operations strictly adhere to the rule of law.
"NSA does not conduct signals intelligence collection in any country, or anywhere in the world, unless it is necessary to advance US national security and foreign policy interests and to protect its citizens and the citizens of its allies and partners from harm," NSA spokesperson Vanee Vines said in an email.
Civil libertarians said the revelation raised fresh concerns over the NSA's surveillance capabilities.
"This is a truly chilling revelation, and it's one that underscores how high the stakes are in the debate we're now having about bulk surveillance," Jameel Jaffer, American Civil Liberties Union deputy legal director, said in a statement. "The NSA has always wanted to record everything, and now it has the capacity to do so."


Read more ...

Tuesday, March 11, 2014

Microsoft, Google to sue over FISA gag order

Google and Microsoft plan to sue the government, demanding the right to publicly discuss any surveillance requests served up by the FISA court.
Microsoft general counsel Brad Smith.

Stonewalling by the Department of Justice has led Google and Microsoft to decide to file a lawsuit so that they can publicly discuss Foreign Intelligence Surveillance Court-approved surveillance orders.
Microsoft general counsel Brad Smith announced Friday that the company, in collaboration with Google, would sue the government despite its statement on Thursday that it would  publish some surveillance request information  annually.
Google and Microsoft are requesting the ability to publish "aggregate information" about FISA court orders directed at the companies in the hopes of being more transparent to their customers, the companies have said.
Google originally filed the motion to claim a First Amendment right to publish information such as how many requests it has received from under the Foreign Intelligence Surveillance Act. Section 702 of the act was amended in 2008 to allow the government to declare even the number of requests issued under the act subject to gag orders.
Before the National Security Agency document leaks from Edward Snowden, the FISA orders had been declared so secret that Google, Microsoft, and other companies served with them were barred from acknowledging in public that they had received the requests.
As part of the procedure for the lawsuit to proceed, Google and Microsoft will be amending their petitions filed with the Foreign Intelligence Surveillance Court, a source close to the matter told CNET. The companies received a 10-day extension, so the government isn't expected to respond by Friday's deadline.
The government's response to the original filing's deadline was delayed six times by the Department of Justice, leading to frustration on the part of the tech companies, which has culminated in the announcement of the lawsuit.
The source, who requested anonymity because the person lacked authorization to speak on the record, said that Google and Microsoft will be amending their petitions to more closely reflect the details of an open letter signed by most major tech companies (PDF) and sent after the initial FISA court filing from the Center for Democracy and Transparency to the heads of the US government and intelligence agencies.
It is likely that the government will consolidate the various petitions into the Microsoft lawsuit to avoid potentially having disparate decisions for different companies.
Read more ...

Google to feds: Let us talk about government surveillance, please

Attorney General Eric Holder has prohibited tech companies from revealing what information they're legally required to disclose to the feds. Google wants to lift the gag orders.
Attorney General Eric Holder, shown here earlier today, has not permitted Google to disclose what information it is -- and isn't -- forced to turn over to the feds

Google today asked the U.S. government to lift a legal gag order and let it clear up speculation and erroneous reports about what information it's forced to turn over to the feds.
In an open letter to Attorney General Eric Holder and FBI Director Robert Mueller asking for "transparency," the Mountain View, Calif.-based company is effectively applying an unusual amount of public pressure to the Obama administration. President Obama has claimed to have"the most transparent administration in history," though critics have argued otherwise.
Google, Apple, Yahoo, Microsoft, Facebook, and other Internet companies were left reeling after a pair of articles last Thursday alleged that they provided the National Security Agency with "direct access" to their servers. By late Friday, however, CNET reported that was not true, and the Washington Post backtracked from its original story on PRISM. In an editorial today, the paper said the process met legal "standards" and was subject to "judicial review."
But for Silicon Valley companies that rely on user trust -- and are trying to usher in a future where more data is stored in the cloud -- even lingering misgivings over privacy are worth eliminating.
Today's letter, signed by David Drummond, Google's chief legal officer, asks for the right to disclose information about how many orders the company receives under the Foreign Intelligence Surveillance Act, and how broad they are. It says:
 Google has worked tremendously hard over the past 15 years to earn our users' trust. For example, we offer encryption across our services; we have hired some of the best security engineers in the world; and we have consistently pushed back on overly broad government requests for our users' data.
We have always made clear that we comply with valid legal requests. And last week, the director of national intelligence acknowledged that service providers have received Foreign Intelligence Surveillance Act (FISA) requests.
Assertions in the press that our compliance with these requests gives the U.S. government unfettered access to our users' data are simply untrue. However, government nondisclosure obligations regarding the number of FISA national security requests that Google receives, as well as the number of accounts covered by those requests, fuel that speculation.
We therefore ask you to help make it possible for Google to publish in our Transparency Report aggregate numbers of national security requests, including FISA disclosures -- in terms of both the number we receive and their scope. Google's numbers would clearly show that our compliance with these requests falls far short of the claims being made. Google has nothing to hide.
Google appreciates that you authorized the recent disclosure of general numbers for national security letters. There have been no adverse consequences arising from their publication, and in fact more companies are receiving your approval to do so as a result of Google's initiative. Transparency here will likewise serve the public interest without harming national security.
The Justice Department and the FBI did not immediately respond to a request for comment from CNET.
Google already releases many statistics about government surveillance as part of itstransparency report, including, as of March, information on secret National Security Letters sent by the FBI. But a source familiar with the situation said the company has not secured permission to disclose information about secret court orders.
James Clapper, the head of national intelligence, confirmed last week that the Internet companies were receiving legal orders sent to them "pursuant to Section 702 of the Foreign Intelligence Surveillance Act."
After the Foreign Intelligence Surveillance Court limited a Bush-era warrantless surveillance program's scope, Congress enacted the FISA Amendments Act, which established a new procedure for foreign surveillance.
That Section 702 procedure works like this: The Justice Department must demonstrate that its surveillance will not intentionally target anyone present in the United States or any American who's overseas. And the surveillance process must comply with the Fourth Amendment.
Section 702 also requires that the government obtain the secret Foreign Intelligence Surveillance Court's approval of "targeting" and "minimization" procedures, and that the court review the agencies' certification describing how proposed surveillance techniques will comply with the law. Judges must consider whether the targeting procedures are "reasonably designed" to exclude Americans and purely domestic surveillance.
A former government official who is intimately familiar with this process of data acquisition and spoke on condition of anonymity told CNET last week that the government delivers an order to obtain account details about someone who's specifically identified as a non-U.S. individual, with a specific finding that they're involved in an activity related to international terrorism. Both the contents of communications and metadata, such as information about who's talking to whom, can be requested.

Amnesty International and journalists launched a legal challenge to Section 702 (which is sometimes called 1881a, for its location in the law books). They argued their confidential communications with foreign correspondents would be intercepted under Section 702 in violation of the Fourth Amendment. But in February 2013, the U.S. Supreme Court rejected their challenge by a 5-4 vote, with Justice Samuel Alito writing that their allegations were too "speculative" and the Section 702 process is subject to ongoing "oversight" and "review."
Read more ...

Justice Dept. weighs Google's request to lift NSA gag order

Microsoft, Google, and Facebook are asking the Obama administration for permission to clear their names by disclosing surveillance details. The Justice Department has not yet responded.
Attorney General Eric Holder, who has not lifted a gag order on Internet companies

The U.S. Department of Justice confirmed Tuesday that it is considering requests from Google, Facebook, and Microsoft that would let them clear their names after allegations they opened their networks to government spies, although U.S. Attorney General Eric Holder has not yet issued a decision on the matter.
In response to queries from CNET, the Justice Department said late this afternoon: "The department has received the letter from the chief legal officer at Google. We are in the process of reviewing their request."
David Drummond, Google's chief legal officer,  sent an open letter  to Holder and FBI Director Robert Mueller today asking them to lift a gag order so they could clear up misconceptions about National Security Agency eavesdropping. The ongoing gag order fuels incorrect "speculation," Drummond said.
Microsoft followed shortly afterward with a statement saying "government should take action to allow companies to provide additional transparency." And Facebook's general counsel, Ted Ullyot, called on the feds to allow "companies to include information about the size and scope of national security requests we receive, and look forward to publishing a report that includes that information."
The three requests from some of the United States' largest tech companies increases pressure on the Obama administration to permit more disclosure of what's happening in terms of national security-related surveillance. So does a parallel move today by Democratic senators to support legislation that would partially lift the veil on the secret Foreign Intelligence Surveillance Court.
Google, Apple, Yahoo, Microsoft, Facebook, and other Internet companies were left reeling after a pair of articles on Thursday alleged that they provided the National Security Agency with "direct access" to their servers. By late Friday, however, CNET reported that was not true, and the Washington Post backtracked from its original story on PRISM. In an editorial Tuesday, the paper said the process met legal "standards" and was subject to "judicial review."
Also today, Google told Wired that: "When required to comply with these requests, we deliver that information to the U.S. government -- generally through secure FTP transfers and in person. The U.S. government does not have the ability to pull that data directly from our servers or network."
Google already releases many statistics about government surveillance as part of itstransparency report, including, as of March, information on secret National Security Letters sent by the FBI. But a source familiar with the situation said the company has not secured permission to disclose information about secret court orders.
James Clapper, the head of national intelligence, confirmed last week that the Internet companies were receiving legal orders sent to them "pursuant to Section 702 of the Foreign Intelligence Surveillance Act."
After the Foreign Intelligence Surveillance Court limited a Bush-era warrantless surveillance program's scope, Congress enacted the FISA Amendments Act, which established a new procedure for foreign surveillance.
That Section 702 procedure works like this: The Justice Department must demonstrate that its surveillance will not intentionally target anyone present in the United States or any American who's overseas. And the surveillance process must comply with the Fourth Amendment.
Section 702 also requires that the government obtain the secret Foreign Intelligence Surveillance Court's approval of "targeting" and "minimization" procedures, and that the court review the agencies' certification describing how proposed surveillance techniques will comply with the law. Judges must consider whether the targeting procedures are "reasonably designed" to exclude Americans and purely domestic surveillance.
A former government official who is intimately familiar with this process of data acquisition and spoke on condition of anonymity told CNET last week that the government delivers an order to obtain account details about someone who's specifically identified as a non-U.S. individual, with a specific finding that they're involved in an activity related to international terrorism. Both the contents of communications and metadata, such as information about who's talking to whom, can be requested.
Amnesty International and journalists launched a legal challenge to Section 702 (which is sometimes called 1881a, for its location in the law books). They argued their confidential communications with foreign correspondents would be intercepted under Section 702 in violation of the Fourth Amendment. But in February 2013, the U.S. Supreme Court rejected their challenge by a 5-4 vote, with Justice Samuel Alito writing that their allegations were too "speculative" and the Section 702 process is subject to ongoing "oversight" and "review."
Here are the full statements from Microsoft and Facebook:
 "As Mark said last week, we strongly encourage all governments to be much more transparent about all programs aimed at keeping the public safe. In the past, we have questioned the value of releasing a transparency report that, because of exactly these types of government restrictions on disclosure, is necessarily incomplete and therefore potentially misleading to users. We would welcome the opportunity to provide a transparency report that allows us to share with those who use Facebook around the world a complete picture of the government requests we receive, and how we respond. We urge the United States government to help make that possible by allowing companies to include information about the size and scope of national security requests we receive, and look forward to publishing a report that includes that information." -- Ted Ullyot, general counsel, Facebook
 "Permitting greater transparency on the aggregate volume and scope of national security requests, including FISA orders, would help the community understand and debate these important issues. Our recent Report went as far as we legally could and the government should take action to allow companies to provide additional transparency." -- Microsoft
Also today, Sen. Al Franken, a Minnesota Democrat and head of a Senate privacy panel,downplayed concerns about NSA surveillance, saying: "I availed myself of [briefings by executive branch officials] so nothing surprised me and the architecture of these programs I was very well aware of."

Last updated at 6:50 p.m. PT
Read more ...

Senators call for end to Justice Department's 'secret law'

Obama administration's secret interpretation of the Patriot Act allows it to vacuum up records on all Americans' phone calls. But an earlier effort to fix the law in December failed.
Sen. Ron Wyden has been saying for years that "the American people would be absolutely stunned" if they knew what kind of surveillance has been authorized by the Obama administration's secret Patriot Act interpretation

Obama administration's secret interpretation of the Patriot Act allows it to vacuum up records on all Americans' phone calls. But an earlier effort to fix the law in December failed.
Eight U.S. senators today seized on leaks from the National Security Agency to call for an end to a "secret law" that governs how intelligence agencies electronically spy on Americans.
Secret laws may seem like Kafkaesque jurisprudence borrowed from Soviet Russia, but last week's leak of a secret court order revealed the Obama administration has a secret interpretation of the Patriot Act that allows it to vacuum up logs of all domestic phone calls on a daily basis.
"It is impossible for the American people to have an informed public debate about laws that are interpreted, enforced, and adjudicated in complete secrecy," Sen. Ron Wyden, an Oregon Democrat and member of the Senate Intelligence committee, said in a statement. "When talking about the laws governing intelligence operations, the process has little to no transparency." Sen. Patrick Leahy, the head of the Judiciary committee, also signed on to today's request.
Wyden, along with senators Mark Udall (D-Colo.) and Rand Paul (R-Ky.), have warned for years of the problems with secret interpretations of the Patriot Act. A CNET article from 2011 quoted him as saying at the time: "I believe that the American people would be absolutely stunned" if they knew what was actually going on.
The secret order from U.S. District Judge Roger Vinson, who serves on the secret Foreign Intelligence Surveillance Court, wasdisclosed last week by the Guardian newspaper.
Vinson's order relies on Section 215 of the Patriot Act, 50 USC 1861, better known as the "business records" portion. It allows FBI agents to obtain any "tangible thing," including "books, records, papers, documents, and other items," a broad term that includes dumps from private-sector computer databases with limited judicial oversight -- and not what politicians ever envisioned when enacting the Patriot Act in October 2001.
The eight senators are trying again to enact legislation that would, in general, require decisions of the Foreign Intelligence Surveillance Court to be revealed to the public. It has loopholes, however, including allowing the attorney general to make a "determination that a decision may not be declassified" because of national security reasons.
It was offered -- unsuccessfully -- as an amendment in December 2012 during a debate over renewing the Foreign Intelligence Surveillance Act. The renewal, without the amendment attached, was approved by a vote of 73 to 23.

Separately, Google today asked Attorney General Eric Holder to lift a legal gag order that has prevented the company from revealing what information it's legally required to disclose to the feds.
Read more ...

Google to feds: Let us talk about government surveillance, please

Attorney General Eric Holder has prohibited tech companies from revealing what information they're legally required to disclose to the feds. Google wants to lift the gag orders.
Attorney General Eric Holder, shown here earlier today, has not permitted Google to disclose what information it is -- and isn't -- forced to turn over to the feds

Google today asked the U.S. government to lift a legal gag order and let it clear up speculation and erroneous reports about what information it's forced to turn over to the feds.
In an open letter to Attorney General Eric Holder and FBI Director Robert Mueller asking for "transparency," the Mountain View, Calif.-based company is effectively applying an unusual amount of public pressure to the Obama administration. President Obama has claimed to have"the most transparent administration in history," though critics have argued otherwise.
Google, Apple, Yahoo, Microsoft, Facebook, and other Internet companies were left reeling after a pair of articles last Thursday alleged that they provided the National Security Agency with "direct access" to their servers. By late Friday, however, CNET reported that was not true, and the Washington Post backtracked from its original story on PRISM. In an editorial today, the paper said the process met legal "standards" and was subject to "judicial review."
But for Silicon Valley companies that rely on user trust -- and are trying to usher in a future where more data is stored in the cloud -- even lingering misgivings over privacy are worth eliminating.
Today's letter, signed by David Drummond, Google's chief legal officer, asks for the right to disclose information about how many orders the company receives under the Foreign Intelligence Surveillance Act, and how broad they are. It says:
 Google has worked tremendously hard over the past 15 years to earn our users' trust. For example, we offer encryption across our services; we have hired some of the best security engineers in the world; and we have consistently pushed back on overly broad government requests for our users' data.
We have always made clear that we comply with valid legal requests. And last week, the director of national intelligence acknowledged that service providers have received Foreign Intelligence Surveillance Act (FISA) requests.
Assertions in the press that our compliance with these requests gives the U.S. government unfettered access to our users' data are simply untrue. However, government nondisclosure obligations regarding the number of FISA national security requests that Google receives, as well as the number of accounts covered by those requests, fuel that speculation.
We therefore ask you to help make it possible for Google to publish in our Transparency Report aggregate numbers of national security requests, including FISA disclosures -- in terms of both the number we receive and their scope. Google's numbers would clearly show that our compliance with these requests falls far short of the claims being made. Google has nothing to hide.
Google appreciates that you authorized the recent disclosure of general numbers for national security letters. There have been no adverse consequences arising from their publication, and in fact more companies are receiving your approval to do so as a result of Google's initiative. Transparency here will likewise serve the public interest without harming national security.
The Justice Department and the FBI did not immediately respond to a request for comment from CNET.
Google already releases many statistics about government surveillance as part of itstransparency report, including, as of March, information on secret National Security Letters sent by the FBI. But a source familiar with the situation said the company has not secured permission to disclose information about secret court orders.
James Clapper, the head of national intelligence, confirmed last week that the Internet companies were receiving legal orders sent to them "pursuant to Section 702 of the Foreign Intelligence Surveillance Act."
After the Foreign Intelligence Surveillance Court limited a Bush-era warrantless surveillance program's scope, Congress enacted the FISA Amendments Act, which established a new procedure for foreign surveillance.
That Section 702 procedure works like this: The Justice Department must demonstrate that its surveillance will not intentionally target anyone present in the United States or any American who's overseas. And the surveillance process must comply with the Fourth Amendment.
Section 702 also requires that the government obtain the secret Foreign Intelligence Surveillance Court's approval of "targeting" and "minimization" procedures, and that the court review the agencies' certification describing how proposed surveillance techniques will comply with the law. Judges must consider whether the targeting procedures are "reasonably designed" to exclude Americans and purely domestic surveillance.
A former government official who is intimately familiar with this process of data acquisition and spoke on condition of anonymity told CNET last week that the government delivers an order to obtain account details about someone who's specifically identified as a non-U.S. individual, with a specific finding that they're involved in an activity related to international terrorism. Both the contents of communications and metadata, such as information about who's talking to whom, can be requested.
Amnesty International and journalists launched a legal challenge to Section 702 (which is sometimes called 1881a, for its location in the law books). They argued their confidential communications with foreign correspondents would be intercepted under Section 702 in violation of the Fourth Amendment. But in February 2013, the U.S. Supreme Court rejected their challenge by a 5-4 vote, with Justice Samuel Alito writing that their allegations were too "speculative" and the Section 702 process is subject to ongoing "oversight" and "review."


Read more ...

NSA paid tech firms over Prism, says latest Snowden leak

Google, Facebook, Yahoo, and Microsoft all received money to cover costs related to surveillance requests, the UK's Guardian reports, citing documents provided by former contractor Edward Snowden.
 And the NSA worked to rejigger its 

Tech firms including Google, Facebook, Yahoo, and Microsoft received money from the National Security Agency to cover legal-compliance costs related to the NSA's Prism surveillance program, according to the latest Edward Snowden documents published by the UK's Guardian newspaper.
A 2011 ruling by the Foreign Intelligence Surveillance -- or FISA -- Court found unconstitutional the NSA's inability to collect foreign Internet data without also collecting domestic data. And the NSA worked to rejigger its systems to bring them in line with the law. (The 2011 ruling was released this week as the result of a Freedom of Information Act lawsuit by the Electronic Frontier Foundation.)
The Guardian says of the new Snowden documents:
An NSA newsletter entry, marked top secret and dated December 2012, discloses the huge costs [the NSA compliance effort] entailed. "Last year's problems resulted in multiple extensions to the certifications' expiration dates which cost millions of dollars for Prism providers to implement each successive extension -- costs covered by Special Source Operations," it says.
Special Source Operations, described by Snowden as the "crown jewel" of the NSA, handles all surveillance programs, such as Prism, that rely on "corporate partnerships" with telecoms and Internet providers to access communications data.
The Guardian says the revelation "raises new questions" about tech companies' relationships with the NSA. Yahoo and Microsoft, however, say, as they've been saying, that they're simply complying with the law.
"Microsoft only complies with court orders because it is legally ordered to, not because it is reimbursed for the work," a company spokesperson said. "We could have a more informed discussion of these issues if providers could share additional information, including aggregate statistics on the number of any national security orders they may receive."
The spokesperson also pointed to an item in an FAQ tied to Microsoft's 2012 Law Enforcement Requests Report:

Does Microsoft charge law enforcement for providing data and content?
Yes. Pursuant to the Electronic Communications Privacy Act, Microsoft is entitled to seek reimbursement for costs associated with compliance with a valid U.S. law enforcement request. We only charge U.S. law enforcement entities pursuant to industry rates and only in an attempt to recover some costs associated with the need to comply with U.S. legal demands. We do not, however, charge in emergency situations or in known child exploitation investigations.

Yahoo, for its part, said in a statement that "Federal law requires the US government to reimburse providers for costs incurred to respond to compulsory legal process imposed by the government. We have requested reimbursement consistent with this law."
Facebook told the Guardian it had "never received any compensation in connection with responding to a government data request."
And Google sent the following statement to the Guardian: "We await the US government's response to our petition to publish more national security request data, which will show that our compliance with American national security laws falls far short of the wild claims still being made in the press today."
All 4 firms are among the 63 companies, trade groups, and civil liberties groups that are signatories of a letter that calls on President Barack Obama and Congress to allow Internet and telecommunications companies to offermore details about US government requests for user information. And Google, Microsoft, and Yahoo are involved in individual efforts to win this right.
Suspicion over the involvement of tech firms in the Prism program were fired up by the initial reports about Prism in The Guardian andThe Washington Post, which said the NSA had "direct access" to company servers. CNET's Declan McCullagh subsequently reported that there was no evidence of wholesale access to company servers.

Update, August 24 at 8:41 a.m. PT: A Google spokesperson provided the following statement late Friday evening: "We have not joined Prism or any government surveillance programs. We do not provide any government with access to our systems and we provide user data to governments only in accordance with the law." The spokesperson also pointed to Google CEO Larry Page's June 7 blog post about Prism and Google's involvement with government requests for data, and to the company's open letter asking the government to let Google publish information on how many requests it receives.
Read more ...

NSA swept up thousands of U.S. e-mails as part of illegal program, ruling reveals

Newly released 2011 ruling by Foreign Intelligence Surveillance Court found NSA e-mail and data-collection program illegal and decried government's "substantial misrepresentation" of scope of NSA activities
Declan McCullagh

The U.S. government has released a secret court ruling from 2011 that found some surveillance conducted by the National Security Agency illegal and that estimated the NSA collected many thousands of "wholly domestic communications" between Americans.
The Electronic Frontier Foundation heralded as a "victory" Wednesday's release of the 86-page opinion by the Foreign Intelligence Surveillance Court (FISC), set up under the 1978 Foreign Intelligence Surveillance Act.
In a statement following the release of the court opinion, Director for National Intelligence James Clapper announced the establishment of a group that will review the United States' surveillance capabilities and issue a report by mid-December.
The group will assess "whether the U.S. employs its technical collection capabilities in a manner that optimally protects our national security...while appropriately accounting for other policy considerations, such as the risk of unauthorized disclosure and our need to maintain the public trust."
The court document, dated October 3, 2011, found some of the NSA's collections to be in breach of the Fourth Amendment, which protects against unreasonable searches and seizures.
It's not the first time the opinion has been released -- it was published in January, but the document was so heavily redacted it was impossible to read, bar a single sentence that offered nothing of value.
In the readable (albeit still heavily redacted) opinion, the court said it was "troubled" that government revelations had, for the third time in less than three years, uncovered a "substantial misrepresentation" of the scope of NSA data-collection programs involving Internet traffic.
The now-discontinued "upstream" program diverted large quantities of international data from fiber cables running in and out of the U.S. into a data center, where it could be stored and analyzed. 
Investigative reporting by ZDNet in June first detailed how fiber and telecommunications companies were ordered under law to allow vast amounts of data belonging to U.S. citizens and foreign nationals to be wiretapped. 
Realistically, the NSA was unable to filter out the communications of Americans speaking to other Americans.
According to NSA estimates, as many as 56,000 "wholly domestic communications" may have been acquired, and are being acquired, by the government agency per year.
The NSA acquires more than 250 million Internet communications each year under Section 702 of FISA, the document states. Most are obtained from Internet providers. The court opinion also says the NSA's upstream program constitutes only approximately 9 percent of the total Internet communications being acquired under Section 702.
On Tuesday, a report by The Wall Street Journal claimed the NSA could access as much as 75 percent of all U.S. Internet traffic.
"The exceptions to minimization requirements mean information gathered on Americans could be used in ordinary criminal investigations, according to rules approved" by the FISC, the Journal wrote.
One month after the FISC ruled the upstream program unconstitutional, the NSA adjusted its collection process to filter out wholly American traffic from international traffic. It also purged any domestic traffic that it received. 
"Contrary to the government's repeated assurances, [the] NSA had been routinely running [search] queries of the metadata using querying terms that did not meet the required standard for querying," the FISC opinion said.
The court concluded that this requirement had been "so frequently and systematically violated that it can fairly be said that this critical element of the overall [...] regime has never functioned effectively."
In a joint statement (PDF) issued late Wednesday, the NSA and the Office of the Director of National Intelligence said media reports based on the Journal's article "provide an inaccurate and misleading picture of NSA's collection programs."
"Press reports based on an article published in today's Wall Street Journal mischaracterize aspects of NSA's data collection activities conducted under Section 702 of the Foreign Intelligence Surveillance Act," the statement read. "The NSA does not sift through and have unfettered access to 75 percent of the United States' online communications."

Update, 10 p.m. PT: Adds statement from NSA about Wall Street Journal article.
Read more ...

Exclusive: Secret contract tied NSA and security industry pioneer



Documents leaked by former NSA contractor Edward Snowden show that the NSA created and promulgated a flawed formula for generating random numbers to create a "back door" in encryption products, the New York Times reported in September. Reuters later reported that RSA became the most important distributor of that formula by rolling it into a software tool called Bsafe that is used to enhance security in personal computers and many other products.

Undisclosed until now was that RSA received $10 million in a deal that set the NSA formula as the preferred, or default, method for number generation in the BSafe software, according to two sources familiar with the contract. Although that sum might seem paltry, it represented more than a third of the revenue that the relevant division at RSA had taken in during the entire previous year, securities filings show.

 
Secret contract tied NSA and security industry pioneer 

The earlier disclosures of RSA's entanglement with the NSA already had shocked some in the close-knit world of computer security experts. The company had a long history of championing privacy and security, and it played a leading role in blocking a 1990s effort by the NSA to require a special chip to enable spying on a wide range of computer and communications products.
RSA, now a subsidiary of computer storage giant EMC Corp, urged customers to stop using the NSA formula after the Snowden disclosures revealed its weakness.
RSA and EMC declined to answer questions for this story, but RSA said in a statement: "RSA always acts in the best interest of its customers and under no circumstances does RSA design or enable any back doors in our products. Decisions about the features and functionality of RSA products are our own."
The NSA declined to comment.
The RSA deal shows one way the NSA carried out what Snowden's documents describe as a key strategy for enhancing surveillance: the systematic erosion of security tools. NSA documents released in recent months called for using "commercial relationships" to advance that goal, but did not name any security companies as collaborators.
The NSA came under attack this week in a landmark report from a White House panel appointed to review U.S. surveillance policy. The panel noted that "encryption is an essential basis for trust on the Internet," and called for a halt to any NSA efforts to undermine it.
Most of the dozen current and former RSA employees interviewed said that the company erred in agreeing to such a contract, and many cited RSA's corporate evolution away from pure cryptography products as one of the reasons it occurred.
But several said that RSA also was misled by government officials, who portrayed the formula as a secure technological advance.
"They did not show their true hand," one person briefed on the deal said of the NSA, asserting that government officials did not let on that they knew how to break the encryption.
STORIED HISTORY
Started by MIT professors in the 1970s and led for years by ex-Marine Jim Bidzos, RSA and its core algorithm were both named for the last initials of the three founders, who revolutionized cryptography. Little known to the public, RSA's encryption tools have been licensed by most large technology companies, which in turn use them to protect computersused by hundreds of millions of people.
At the core of RSA's products was a technology known as public key cryptography. Instead of using the same key for encoding and then decoding a message, there are two keys related to each other mathematically. The first, publicly available key is used to encode a message for someone, who then uses a second, private key to reveal it.
From RSA's earliest days, the U.S. intelligence establishment worried it would not be able to crack well-engineered public key cryptography. Martin Hellman, a former Stanford researcher who led the team that first invented the technique, said NSA experts tried to talk him and others into believing that the keys did not have to be as large as they planned.
The stakes rose when more technology companies adopted RSA's methods and Internet use began to soar. The Clinton administration embraced the Clipper Chip, envisioned as a mandatory component in phones and computers to enable officials to overcome encryption with a warrant.
RSA led a fierce public campaign against the effort, distributing posters with a foundering sailing ship and the words "Sink Clipper!"
A key argument against the chip was that overseas buyers would shun U.S. technology products if they were ready-made for spying. Some companies say that is just what has happened in the wake of the Snowden disclosures.
The White House abandoned the Clipper Chip and instead relied on export controls to prevent the best cryptography from crossing U.S. borders. RSA once again rallied the industry, and it set up an Australian division that could ship what it wanted.
"We became the tip of the spear, so to speak, in this fight against government efforts," Bidzos recalled in an oral history.
RSA EVOLVES
RSA and others claimed victory when export restrictions relaxed.
But the NSA was determined to read what it wanted, and the quest gained urgency after the September 11, 2001 attacks.
RSA, meanwhile, was changing. Bidzos stepped down as CEO in 1999 to concentrate on VeriSign, a security certificate company that had been spun out of RSA. The elite lab Bidzos had founded in Silicon Valley moved east to Massachusetts, and many top engineers left the company, several former employees said.
And the BSafe toolkit was becoming a much smaller part of the company. By 2005, BSafe and other tools for developers brought in just $27.5 million of RSA's revenue, less than 9% of the $310 million total.
"When I joined there were 10 people in the labs, and we were fighting the NSA," said Victor Chan, who rose to lead engineering and the Australian operation before he left in 2005. "It became a very different company later on."
By the first half of 2006, RSA was among the many technology companies seeing the U.S. government as a partner against overseas hackers.
New RSA Chief Executive Art Coviello and his team still wanted to be seen as part of the technological vanguard, former employees say, and the NSA had just the right pitch. Coviello declined an interview request.
An algorithm called Dual Elliptic Curve, developed inside the agency, was on the road to approval by the National Institutes of Standards and Technology as one of four acceptable methods for generating random numbers. NIST's blessing is required for many products sold to the government and often sets a broader de facto standard.
RSA adopted the algorithm even before NIST approved it. The NSA then cited the early use of Dual Elliptic Curve inside the government to argue successfully for NIST approval, according to an official familiar with the proceedings.
RSA's contract made Dual Elliptic Curve the default option for producing random numbers in the RSA toolkit. No alarms were raised, former employees said, because the deal was handled by business leaders rather than pure technologists.
"The labs group had played a very intricate role at BSafe, and they were basically gone," said labs veteran Michael Wenocur, who left in 1999.
Within a year, major questions were raised about Dual Elliptic Curve. Cryptography authority Bruce Schneier wrote that the weaknesses in the formula "can only be described as a back door."
After reports of the back door in September, RSA urged its customers to stop using the Dual Elliptic Curve number generator.
But unlike the Clipper Chip fight two decades ago, the company is saying little in public, and it declined to discuss how the NSA entanglements have affected its relationships with customers.

The White House, meanwhile, says it will consider this week's panel recommendation that any efforts to subvert cryptography be abandoned.
Read more ...

Security firm RSA took millions from NSA: report

The National Security Agency paid $10 million to the security firm RSA to implement intentionally flawed encryption, according to a new report.
An RSA SecurID key fob

What's an encryption backdoor cost? When you're the NSA, apparently the fee is $10 million.
Intentional flaws created by the National Security Agency in RSA's encryption tokens werediscovered in September, thanks to documents released by whistleblower Edward Snowden. It has now been revealed that RSA was paid $10 million by the NSA to implement those backdoors, according to a new report in Reuters.
Related stories:

In most-anticipated SXSW talk in years, Snowden fires up Austin
WikiLeaks' Julian Assange: NSA critics got lucky because agency had no PR strategy
Kill the Snowden interview, congressman tells SXSW
Edward Snowden to speak at South by Southwest
Klocwork: Our source code analyzer caught Apple's 'gotofail' bug

Two people familiar with RSA's BSafe software told Reuters that the company had received the money in exchange for making the NSA's cryptographic formula as the default for encrypted key generation in BSafe.
"Now we know that RSA was bribed," said security expert Bruce Schneier, who has been involved in the Snowden document analysis. "I sure as hell wouldn't trust them. And then they made the statement that they put customer security first," he said.
RSA, now owned by computer storage firm EMC Corp, has a long history of entanglement with the government. In the 1990s, the company was instrumental in stopping a government plan to include a chip in computers that would've allowed the government to spy on people.
It has also had its algorithms hacked before, as has RSA-connected VeriSign.
The new revelation is important, Schneier said, because it confirms more suspected tactics that the NSA employs.
"You think they only bribed one company in the history of their operations? What's at play here is that we don't know who's involved," he said.
Other companies that build widely-used encryption apparatus include Symantec, McAfee, and Microsoft. "You have no idea who else was bribed, so you don't know who else you can trust," Schneier said.
In a statement issued Sunday, RSA said it "categorically" denied recent reports.
"We have worked with the NSA, both as a vendor and an active member of the security community. We have never kept this relationship a secret and in fact have openly publicized it," the company said in a statement. "Our explicit goal has always been to strengthen commercial and government security."

The statement goes on to rebut a number of claims, including that the company knowingly introduced a flawed numbers generator into its encryption libraries.
Read more ...
THam khảo: Đầu thu DVB T2 | giàn phơi, lắp đặt giàn phơi quần áo hay giá giàn phơi thông minh tốt nhất cả nước