Showing posts with label Electronic Frontier Foundation. Show all posts
Showing posts with label Electronic Frontier Foundation. Show all posts

Wednesday, September 11, 2013

NSA Credibility Problem

On Tuesday 9/10/2013 the government finally declassified FISA and NSA court documents that reveal the agency lied to the court and Congress about their activities for years, and perpetuated those lies until Edward Snowden blew the whistle on them.

After years of government stalling and stonewalling, they finally released data to both the ACLU and Electronic Frontier Foundation who had filed FOIA requests on the court rulings.  Both the EFF and ACLU have had only a few hours to examine the documents, but here are their initial comments.

ACLU
“These documents show that the NSA repeatedly violated court-imposed limits on its surveillance powers, and they confirm that the agency simply cannot be trusted with such sweeping authority,” said Alex Abdo, staff attorney with the ACLU National Security Project. “The abuses revealed in these documents are alarming but also predictable. These violations are the inevitable result of allowing the NSA to assemble a vast database of sensitive information about every American. The documents provide further evidence that secret and one-sided judicial review is not an adequate check on the NSA’s surveillance practices.
EFF
Clapper's Continued Trouble with the Truth
On June 6, just days after the Guardian newspaper published the first of many articles on NSA spying, Director of National Intelligence Clapper attempted to reassure the public that the NSA telephone record program was limited and restrained. "The information acquired does not include ... the identity of any subscriber."
Documents released today show this to be false.  In an August 3, 2009 declaration to the FISA court, NSA Director Keith Alexander wrote that "the collected metadata thus holds contact information that can be immediately access as a new terrorist-associated telephone identified are identified."  While it is not surprising that the NSA can correlate a phone number to a person (phone book technology has been available for some time), here we have it in black and white that Dir. Clapper attempted to mislead the public.
The NSA's Word Games Confuse Even the NSA
As we've noted time and time again, the NSA plays with language, using words in non-standard ways.  After not reporting violations to the FISC for years, the NSA had this explanation: "there was never a complete understanding among the key personnel who reviewed the report ... regarding what each individual meant by the terminology used in the report."  The NSA presents this as an excuse why it misled the court.
Want to Know Why the NSA gave Raw Access to the CIA, FBI and NCTC in violation of a Court Order?
So did the Court, who ordered the NSA to explain the violation of its prior order. So did we. However, you're not going to find out today. Four pages of NSA Director Alexander's response to this question are redacted.
The Guardian published some analysis of the documents.
A judge on the secret surveillance court was so disturbed by the National Security Agency's repeated violations of privacy restrictions that he questioned the viability of its bulk collection of Americans' phone records, according to newly declassified surveillance documents.
Darrell Issa, the California Republican who chairs the powerful House committee on oversight and government reform, said that he backed legislation to "permanently cease" the bulk phone records collection.
"Government actions that violate the constitution cannot be tolerated and Congress must act to ensure the NSA and the intelligence community permanently cease such acts and hold the appropriate individuals accountable," Issa wrote to House majority leader Eric Cantor on Tuesday.

Friday, August 9, 2013

NSA Spying Killing Internet

The Center for Internet and Society at the Stanford Law School wrote about anonymous-EMail providers Lavabit and Silent Circle that are choosing to close rather than turn over their client Emails to the NSA.  This is what the blog called "the canary in the coal mine", probably the first of a series of bad news for Internet freedom.
There are two sad lessons to learn from the (potentially temporary) demise of Lavabit.
First, communications service providers are at a severe disadvantage when it comes to resisting even abusive or overbroad government surveillance demands. The court processes and the reasons for surveillance are kept secret from the companies. The cases that interpret the government's powers under the law are secret. Knowledgeable counsel is hard to find… and expensive.
Yet, in a world where the FISA court has rubber stamped government collection of every phone record on everybody, where foreigners have no rights and the contents of Americans’ international communications are regularly scooped up, where the FBI is installing malware on phones and laptops, and where spies are demanding user passwords and SSL network decryption keys, complying with court process can be directly at odds with protecting your customers’ right to privacy. Some lawyers believe there is little, if anything, companies can say to successful challenge even potentially dangerous forms of surveillance. Yet, failure to comply can mean fines, or jail time, or, potentially worse, seizure of the business’ servers.
So, in the choice between complicity or death, Lavabit chose death.
Second, the fact that neither Americans nor foreigners trust the U.S. government and its NSA anymore puts the U.S. communications companies at a severe competitive disadvantage. American law provides almost no protection for foreigners, who comprise a growing majority of any global company's customers. And even though Americans receive more nominal legal protection, we now know that these legal protects haven’t stopped the NSA from wiretaps fiber optic cables inside the United States, warrantlessly gathering Americans’ emails and chats from service providers like Google, Microsoft, Yahoo and Apple, collecting phone records on every American for the past seven years, or demanding that companies build, or at least maintain, surveillance backdoors in products advertised as secure from eavesdropping.
The Electronic Frontier Foundation published the letter from Lavabits founder announcing they were quitting rather than turn over data to the NSA.

Monday, June 3, 2013

Government Secrecy makes us less secure

Senator Ron Wyden, the unrelenting champion of transparency and opponent of secrecy, revealed last July that:
Wyden has stated that on “at least one occasion” the Foreign Intelligence Surveillance Court held that “some collection” carried out under the revised law “was unreasonable under the Fourth Amendment.”
The FISA Amendments Act allows the government to collect, inside the United States and without a warrant, the communication of foreign targets located abroad. Americans’ communications can be picked up if they are talking to, or e-mailing, the foreign target. The communications are gathered from commercial providers under a directive from senior government officials, following court approval.
So what happened?  If the DOJ has their way we'll never know, they are opposing making the breach public on "National Security" grounds.  The Electronic Frontier Foundation has filed a Freedom of Information Act request, but DOJ wants to block it.
David Sobel, an attorney for the Electronic Frontier Foundation, said the government is playing “a shell game.” He noted that in 2007, when the American Civil Liberties Union asked the surveillance court to release a different opinion, the Justice Department argued that the group should file an FOIA request to the department.
This “DOJ-imposed Catch-22 blocks the public from knowing more about the government’s illegal surveillance,” the group said in a statement.
In a letter to Wyden last year, Kathleen Turner, director of legislative affairs for the Office of the Director of National Intelligence, said the government had “remedied” the surveillance court’s concerns.
Do you feel more secure now?