Showing posts with label NSA. Show all posts
Showing posts with label NSA. Show all posts

Saturday, September 05, 2020

U.S. court: Mass surveillance program exposed by Snowden was illegal

Seven years after former National Security Agency contractor Edward Snowden blew the whistle on the mass surveillance of Americans’ telephone records, an appeals court has found the program was unlawful - and that the U.S. intelligence leaders who publicly defended it were not telling the truth. In a ruling handed down on Wednesday, the U.S. Court of Appeals for the Ninth Circuit said the warrantless telephone dragnet that secretly collected millions of Americans’ telephone records violated the Foreign Intelligence Surveillance Act and may well have been unconstitutional. Evidence that the NSA was secretly building a vast database of U.S. telephone records - the who, the how, the when, and the where of millions of mobile calls - was the first and arguably the most explosive of the Snowden revelations published by the Guardian newspaper in 2013. Up until that moment, top intelligence officials publicly insisted the NSA never knowingly collected information on Americans at all. After the program’s exposure, U.S. officials fell back on the argument that the spying had played a crucial role in fighting domestic extremism, citing in particular the case of four San Diego residents who were accused of providing aid to religious fanatics in Somalia. The ruling will not affect the convictions of Moalin and his fellow defendants; the court ruled the illegal surveillance did not taint the evidence introduced at their trial. Nevertheless, watchdog groups including the American Civil Liberties Union, which helped bring the case to appeal, welcomed the judges’ verdict on the NSA’s spy program. “Today’s ruling is a victory for our privacy rights,” the ACLU said in a statement, saying it “makes plain that the NSA’s bulk collection of Americans’ phone records violated the Constitution.”...MORE

I have embedded the court's opinion (U.S. v. Moalin) below and have shared it here
If you have any interest at all in federal surveillance, you will find this an interesting read.


Monday, November 13, 2017

Security Breach and Spilled Secrets Have Shaken the N.S.A. to Its Core


WASHINGTON — Jake Williams awoke last April in an Orlando, Fla., hotel where he was leading a training session. Checking Twitter, Mr. Williams, a cybersecurity expert, was dismayed to discover that he had been thrust into the middle of one of the worst security debacles ever to befall American intelligence. Mr. Williams had written on his company blog about the Shadow Brokers, a mysterious group that had somehow obtained many of the hacking tools the United States used to spy on other countries. Now the group had replied in an angry screed on Twitter. It identified him — correctly — as a former member of the National Security Agency’s hacking group, Tailored Access Operations, or T.A.O., a job he had not publicly disclosed. Then the Shadow Brokers astonished him by dropping technical details that made clear they knew about highly classified hacking operations that he had conducted. America’s largest and most secretive intelligence agency had been deeply infiltrated. “They had operational insight that even most of my fellow operators at T.A.O. did not have,” said Mr. Williams, now with Rendition Infosec, a cybersecurity firm he founded. “I felt like I’d been kicked in the gut. Whoever wrote this either was a well-placed insider or had stolen a lot of operational data.” The jolt to Mr. Williams from the Shadow Brokers’ riposte was part of a much broader earthquake that has shaken the N.S.A. to its core. Current and former agency officials say the Shadow Brokers disclosures, which began in August 2016, have been catastrophic for the N.S.A., calling into question its ability to protect potent cyberweapons and its very value to national security. The agency regarded as the world’s leader in breaking into adversaries’ computer networks failed to protect its own. “These leaks have been incredibly damaging to our intelligence and cyber capabilities,” said Leon E. Panetta, the former defense secretary and director of the Central Intelligence Agency. “The fundamental purpose of intelligence is to be able to effectively penetrate our adversaries in order to gather vital intelligence. By its very nature, that only works if secrecy is maintained and our codes are protected.”...more

But don't worry, all your medical records, et c.are safe in government hands

Friday, May 08, 2015

Federal Appeals Court Rules NSA Spying Illegal

A federal appeals court ruled Thursday that the National Security Agency's bulk collection of billions of U.S. phone records is illegal, dealing a startling blow to the program just as Congress is weighing reforms to the government's expansive surveillance authorities. A three-judge panel of the 2nd Circuit U.S. Court of Appeals deemed that dragnet collection of American call data does not constitute information relevant to terrorism investigations under Section 215 of the Patriot Act. The controversial program, exposed publicly nearly two years ago by Edward Snowden, "exceeds the scope of what Congress has authorized," Judge Gerard Lynch wrote in his decision.  Two other appeals courts have in recent months heard arguments considering the legality of the NSA bulk telephone program, but neither has issued a ruling yet. Any split among the courts likely will prompt a Supreme Court review. The NSA's domestic surveillance of phone metadata—the numbers, time stamps, and duration of calls, but not their content—came under intense scrutiny following the program's disclosure by Snowden, a former NSA contractor, in June 2013...more

Wednesday, July 09, 2014

In NSA-intercepted data, those not targeted far outnumber the foreigners who are

Ordinary Internet users, American and non-American alike, far outnumber legally targeted foreigners in the communications intercepted by the National Security Agency from U.S. digital networks, according to a four-month investigation by The Washington Post. Nine of 10 account holders found in a large cache of intercepted conversations, which former NSA contractor Edward Snowden provided in full to The Post, were not the intended surveillance targets but were caught in a net the agency had cast for somebody else. Many of them were Americans. Nearly half of the surveillance files, a strikingly high proportion, contained names, e-mail addresses or other details that the NSA marked as belonging to U.S. citizens or residents...The surveillance files highlight a policy dilemma that has been aired only abstractly in public. There are discoveries of considerable intelligence value in the intercepted messages — and collateral harm to privacy on a scale that the Obama administration has not been willing to address...Many other files, described as useless by the analysts but nonetheless retained, have a startlingly intimate, even voyeuristic quality. They tell stories of love and heartbreak, illicit sexual liaisons, mental-health crises, political and religious conversions, financial anxieties and disappointed hopes. The daily lives of more than 10,000 account holders who were not targeted are catalogued and recorded nevertheless....The material spans President Obama’s first term, from 2009 to 2012, a period of exponential growth for the NSA’s domestic collection. Taken together, the files offer an unprecedented vantage point on the changes wrought by Section 702 of the FISA amendments, which enabled the NSA to make freer use of methods that for 30 years had required probable cause and a warrant from a judge. One program, code-named PRISM, extracts content stored in user accounts at Yahoo, Microsoft, Facebook, Google and five other leading Internet companies. Another, known inside the NSA as Upstream, intercepts data on the move as it crosses the U.S. junctions of global voice and data networks...more

Sunday, March 16, 2014

It's time to break up the NSA

By Bruce Schneier

The NSA has become too big and too powerful. What was supposed to be a single agency with a dual mission -- protecting the security of U.S. communications and eavesdropping on the communications of our enemies -- has become unbalanced in the post-Cold War, all-terrorism-all-the-time era.

Putting the U.S. Cyber Command, the military's cyberwar wing, in the same location and under the same commander, expanded the NSA's power. The result is an agency that prioritizes intelligence gathering over security, and that's increasingly putting us all at risk. It's time we thought about breaking up the National Security Agency.

Broadly speaking, three types of NSA surveillance programs were exposed by the documents released by Edward Snowden. And while the media tends to lump them together, understanding their differences is critical to understanding how to divide up the NSA's missions.
The first is targeted surveillance.

This is best illustrated by the work of the NSA's Tailored Access Operations (TAO) group, including its catalog of hardware and software "implants" designed to be surreptitiously installed onto the enemy's computers. This sort of thing represents the best of the NSA and is exactly what we want it to do. That the United States has these capabilities, as scary as they might be, is cause for gratification.

The second is bulk surveillance, the NSA's collection of everything it can obtain on every communications channel to which it can get access. This includes things such as the NSA's bulk collection of call records, location data, e-mail messages and text messages.

This is where the NSA overreaches: collecting data on innocent Americans either incidentally or deliberately, and data on foreign citizens indiscriminately. It doesn't make us any safer, and it is liable to be abused. Even the director of national intelligence, James Clapper, acknowledged that the collection and storage of data was kept a secret for too long.

The third is the deliberate sabotaging of security. The primary example we have of this is the NSA's BULLRUN program, which tries to "insert vulnerabilities into commercial encryption systems, IT systems, networks and endpoint communication devices." This is the worst of the NSA's excesses, because it destroys our trust in the Internet, weakens the security all of us rely on and makes us more vulnerable to attackers worldwide.

That's the three: good, bad, very bad. Reorganizing the U.S. intelligence apparatus so it concentrates on our enemies requires breaking up the NSA along those functions.

...Second, all surveillance of Americans should be moved to the FBI.

The FBI is charged with counterterrorism in the United States, and it needs to play that role. Any operations focused against U.S. citizens need to be subject to U.S. law, and the FBI is the best place to apply that law. That the NSA can, in the view of many, do an end-run around congressional oversight, legal due process and domestic laws is an affront to our Constitution and a danger to our society. The NSA's mission should be focused outside the United States -- for real, not just for show.





Wednesday, March 12, 2014

NSA pretended to be Facebook to infect millions of computers


by Andrew Couts  

As part of its efforts to install malware on “millions” of computers worldwide, the National Security Agency impersonated Facebook to trick targets into downloading malicious code.
    “In some cases the NSA has masqueraded as a fake Facebook server, using the social media site as a launching pad to infect a target’s computer and exfiltrate files from a hard drive,” reports The Intercept in its latest expose based on top-secret documents obtained by Edward Snowden.
    “[The NSA] has sent out spam emails laced with the malware, which can be tailored to covertly record audio from a computer’s microphone and take snapshots with its webcam. The hacking systems have also enabled the NSA to launch cyberattacks by corrupting and disrupting file downloads or denying access to websites.”
    The Facebook trick was called QUANTUMHAND by the NSA, and was initially tested on “about a dozen targets” before being launched on a larger scale in 2010, the documents show.
    What began as a way to hit “hart-to-reach” targets – around 100 to 150 of them, as of 2004 – the NSA’s malware-spreading efforts have since proliferated to potentially millions of computers around the globe using an automated system known internally as TURBINE. Using TURBINE, documents reveal, gave members of the NSA’s Tailored Access Operations (TAO) unit the ability to tap into, or destroy, computers on a massive scale.
    Here’s how The Intercept’s Ryan Gallagher and Glenn Greenwald describe some of the various tailored malware the NSA deploys into targeted machines:
One implant, codenamed UNITEDRAKE, can be used with a variety of “plug-ins” that enable the agency to gain total control of an infected computer.
An implant plug-in named CAPTIVATEDAUDIENCE, for example, is used to take over a targeted computer’s microphone and record conversations taking place near the device. Another, GUMFISH, can covertly take over a computer’s webcam and snap photographs. FOGGYBOTTOM records logs of Internet browsing histories and collects login details and passwords used to access websites and email accounts. GROK is used to log keystrokes. And SALVAGERABBIT exfiltrates data from removable flash drives that connect to an infected computer.
    The documents also indicate that some of these viruses disable targets’ ability to use encryption software to mask Internet activity or send emails privately. This and other malware efforts are part of what the NSA documents call its “Owning the Net” program.

Fox

Thursday, February 20, 2014

Will US expand NSA surveillance?

The federal government may actually expand the controversial surveillance program that collects Americans’ phone records in a bid to preserve evidence for the multiple lawsuits filed against the National Security Agency, the Wall Street Journal reported Wednesday. The decision comes despite President Obama’s instruction in a speech on American surveillance practices last month that government officials find a way to end the data collection program. Obama tasked Attorney General Eric Holder and members of the intelligence community with finding a way to wind down the government program without eroding the government’s intelligence capabilities. But, according to the Journal, government lawyers are worried that if they shut down the program, they could violate evidence preservation rules requiring them to maintain the databases amid ongoing litigation. Civil liberties groups like the ACLU and Electronic Frontier Foundation have filed lawsuits charging the surveillance program is unconstitutional. Sen. Rand Paul (R-Ky.) has also led a class-action suit against the government program. In fact, concerns over the legal challenges could even effectively expand the phone record database. At present, the government only maintains five years of call data, purging older information at least twice per year. But the government may now opt to maintain that older data in the interest of preserving evidence. The concerns raised by the government lawyers are only likely to complicate the already difficult task of deciding how to wind down the metadata program...more 

That'll teach us private citizens who sue to protect our rights, now won't it.  Then there's this:

 The concerns raised by the government lawyers are only likely to complicate the already difficult task of deciding how to wind down the metadata program.

Complicated? Difficult?  Its called a plug...pull it.  

Thursday, January 16, 2014

NSA collects millions of text messages daily in 'untargeted' global sweep

The National Security Agency has collected almost 200 million text messages a day from across the globe, using them to extract data including location, contact networks and credit card details, according to top-secret documents. The untargeted collection and storage of SMS messages – including their contacts – is revealed in a joint investigation between the Guardian and the UK’s Channel 4 News based on material provided by NSA whistleblower Edward Snowden. The NSA program, codenamed Dishfire, collects “pretty much everything it can”, according to GCHQ documents, rather than merely storing the communications of existing surveillance targets. The NSA has made extensive use of its vast text message database to extract information on people’s travel plans, contact books, financial transactions and more – including of individuals under no suspicion of illegal activity. The revelation the NSA is collecting and extracting personal information from hundreds of millions of global text messages a day is likely to intensify international pressure on US president Barack Obama, who on Friday is set to give his response to the report of his NSA review panel...more

Wednesday, January 15, 2014

N.S.A. Devises Radio Pathway Into Computers

The National Security Agency has implanted software in nearly 100,000 computers around the world that allows the United States to conduct surveillance on those machines and can also create a digital highway for launching cyberattacks. While most of the software is inserted by gaining access to computer networks, the N.S.A. has increasingly made use of a secret technology that enables it to enter and alter data in computers even if they are not connected to the Internet, according to N.S.A. documents, computer experts and American officials. The technology, which the agency has used since at least 2008, relies on a covert channel of radio waves that can be transmitted from tiny circuit boards and USB cards inserted surreptitiously into the computers. In some cases, they are sent to a briefcase-size relay station that intelligence agencies can set up miles away from the target. The radio frequency technology has helped solve one of the biggest problems facing American intelligence agencies for years: getting into computers that adversaries, and some American partners, have tried to make impervious to spying or cyberattack. In most cases, the radio frequency hardware must be physically inserted by a spy, a manufacturer or an unwitting user. President Obama is scheduled to announce on Friday what recommendations he is accepting from an advisory panel on changing N.S.A. practices. The panel agreed with Silicon Valley executives that some of the techniques developed by the agency to find flaws in computer systems undermine global confidence in a range of American-made information products like laptop computers and cloud services...more

Tuesday, January 14, 2014

Report suggests NSA program has thwarted few terrorist plots

A report released Monday suggests a National Security Agency domestic surveillance program “has had no discernible impact on preventing acts of terrorism.” The New America Foundation, a Washington-based nonprofit, analyzed 225 terrorism cases in the United States since Sept. 11, 2001, and says that the telephone metadata collection program has “only the most marginal of impacts on preventing terrorist-related activity.” The NSA’s telephone metadata program, the report says, only helped initiate 1.8 percent of the cases reviewed. The agency’s programs monitoring foreign citizens outside the United States helped initiate 4.4 percent of those terrorism cases. The report says that President Obama, NSA Director Gen. Keith Alexander and even members of Congress, including House Intelligence Committee Chairman Mike Rogers (R-Mich.), have charged that the program has helped stop and thwart at least 50 terrorist plots around the world. Those claims, New America says, are “overblown and even misleading.” In three terrorism cases, New America found government officials might have “exaggerated” the role of the NSA and the significance of threats, including one to blow up the New York Stock Exchange. “The overall problem for U.S. counterterrorism officials is not that they need vaster amounts of information from the bulk surveillance programs, but that they don’t sufficiently understand or widely share the information they already possess that was derived from conventional law enforcement and intelligence techniques,” the report says. Obama, meanwhile, discussed a report that examines the NSA’s reach with lawmakers last week. The White House also announced Obama will unveil reforms to the agency on Friday.  The Hill

Monday, January 06, 2014

NSA statement does not deny 'spying' on members of Congress

The National Security Agency on Saturday released a statement in answer to questions from a senator about whether it “has spied, or is … currently spying, on members of Congress or other American elected officials”, in which it did not deny collecting communications from legislators of the US Congress to whom it says it is accountable. In a letter dated 3 January, Senator Bernie Sanders of Vermont defined “spying” as “gathering metadata on calls made from official or personal phones, content from websites visited or emails sent, or collecting any other data from a third party not made available to the general public in the regular course of business”. The agency has been at the centre of political controversy since a former contractor, Edward Snowden, released thousands of documents on its activities to media outlets including the Guardian.
In its statement, which comes as the NSA gears up for a make-or-break legislative battle over the scope of its surveillance powers, the agency pointed to “privacy protections” which it says it keeps on all Americans' phone records. The statement read: “NSA’s authorities to collect signals intelligence data include procedures that protect the privacy of US persons. Such protections are built into and cut across the entire process.  Members of Congress have the same privacy protections as all US persons. NSA is fully committed to transparency with Congress. Our interaction with Congress has been extensive both before and since the media disclosures began last June...more

 Even if they denied it, would you believe them?

Wednesday, January 01, 2014

The NSA Can Use Your iPhone To Spy On You, Expert Says

A well-known privacy advocate has given the public an unusually explicit peek into the intelligence world's tool box, pulling back the curtain on the National Security Agency's arsenal of high-tech spy gear. Independent journalist and security expert Jacob Appelbaum on Monday told a hacker conference in Germany that the NSA could turn iPhones into eavesdropping tools and use radar wave devices to harvest electronic information from computers, even if they weren't online. Appelbaum told hundreds of computer experts gathered at Hamburg's Chaos Communications Conference that his revelations about the NSA's capabilities "are even worse than your worst nightmares." "What I am going to show you today is wrist-slittingly depressing," he said. Even though in the past six months there have been an unprecedented level of public scrutiny of the NSA and its methods, Appelbaum's claims — supported by what appeared to be internal NSA slideshows — still caused a stir. One of the slides described how the NSA can plant malicious software onto Apple Inc.'s iPhone, giving American intelligence agents the ability to turn the popular smartphone into a pocket-sized spy. "Apple has never worked with the NSA to create a backdoor in any of our products, including iPhone," the company said in a statement to AllThingsD. "Additionally, we have been unaware of this alleged NSA program targeting our products." Another slide showcased a futuristic-sounding device described as a "portable continuous wave generator," a remote-controlled device which — when paired with tiny electronic implants — can bounce invisible waves of energy off keyboards and monitors to see what is being typed, even if the target device isn't connected to the Internet. A third slide showcased a piece of equipment called NIGHTSTAND, which can tamper with wireless Internet connections from up to 8 miles (13 kilometers) away...more

Tuesday, December 17, 2013

Would You Believe Zero Terrorist Attacks Foiled by the NSA's Phone Record Dragnet?

When U.S. District Judge Richard Leon issued his preliminary injunction against the NSA's phone record database yesterday, part of hisanalysis (which I will discuss in my column tomorrow) concerned whether the collection of telephone metadata counts as a "search" under the Fourth Amendment. But Leon also considered whether such a search might be "reasonable," even without an individualized warrant, because of its usefulness in preventing terrorist attacks. That part of the analysis was pretty straightforward, since the government had presented no evidence that the database has been useful in preventing terrorist attacks:
The Government does not cite a single instance in which analysis of the NSA's bulk metadata collection actually stopped an imminent attack, or otherwise aided the Government in achieving any objective that was time-sensitive in nature. In fact, none of the three "recent episodes" cited by the Government that supposedly "illustrate the role that telephony metadata analysis can play in preventing and protecting against terrorist attack" involved any apparent urgency....
Given the limited record before me at this point in the litigation—most notably, the utter lack of evidence that a terrorist attack has ever been prevented because searching the NSA database was faster than other investigative tactics—I have serious doubts about the efficacy of the metadata collection program as a means of conducting time-sensitive investigations in cases involving imminent threats of terrorism.
Leon's conclusion on this question is striking, since you'd think the Obama administration would be highly motivated to show that the database has been crucial in saving lives. If the government cannot muster a single plausible example, how can such a massive invasion of privacy possibly be justified?...more

Monday, December 16, 2013

Judge Deals Blow to NSA Phone Spying

A federal judge on Monday ruled against the National Security Agency's collection of phone records, saying the program "almost certainly does violate" the Constitution. However, the ruling will have little immediate effect and faces a lengthy future of court proceedings. U.S. District Judge Richard Leon, who was nominated to the Washington, D.C., bench by former President George W. Bush, issued a 68-page ruling in favor of Larry Klayman, a conservative activist and lawyer. Mr. Klayman filed suit in June, claiming that the program violated his Fourth Amendment right against unreasonable search. On a daily basis, the NSA collects records of nearly every call made in the U.S. and enters them into a database in order to search for possible contacts among terrorism suspects. The scope of the program was revealed when former NSA contractor Edward Snowden leaked documents describing the program this spring. The ruling came on Mr. Klayman's request for an injunction barring the government from collecting any telephone records associated with Mr. Klayman and another plaintiff. In the ruling, Judge Leon ordered the government to destroy any such records it currently has. However, "in light of the significant national security interests at stake in this case and the novelty of the constitutional issues,'' the judge suspended his own order while the government pursues an expected appeal. In issuing his ruling, the judge disagreed with a central premise of the program's defenders—that a 1979 Supreme Court ruling allowing investigators to look at the phone records of a Maryland robbery suspect gave them the authority to collect phone records of nearly every American. Judge Leon ruled that the technology of both phones and phone surveillance has changed so much in the intervening years that the Smith decision is of little value in assessing the NSA program. "The almost-Orwellian technology that enables the government to store and analyze the phone metadata of every telephone user in the United States is unlike anything that could have been conceived in 1979,'' the judge wrote, adding: "I believe that bulk telephony metadata collection and analysis almost certainly does violate a reasonable expectation of privacy.''...more