Showing posts with label collection. Show all posts
Showing posts with label collection. Show all posts

Friday, 27 September 2013

NSA: Surveillance court says no upper limit on phone records collection

A U.S. surveillance court has given the National Security Agency no limit on the number of U.S. telephone records it collects in the name of fighting terrorism, the NSA director said Thursday.

The NSA intends to collect all U.S. telephone records and put them in a searchable “lock box” in the interest of national security, General Keith Alexander, the NSA’s director, told U.S. senators.

“There is no upper limit” on NSA telephone-records collection, Alexander said. “I believe it is in the nation’s best interest to put all the phone records into a lock box that we can search when the nation needs to do it.”

The NSA would need to notify the U.S. Foreign Intelligence Surveillance Court and Congress before collecting some other types of U.S. communications, including mobile-phone location information, Alexander told senators. The NSA doesn't currently have plans to collect mobile-phone location information, he said.

Alexander, other intelligence officials and several members of the Senate Select Committee on Intelligence defended the NSA’s data collection and surveillance efforts during a committee hearing.

The NSA collection of U.S. phone records, disclosed by former NSA contractor Edward Snowden earlier this year, are “lawful, effective and constitutional,” said Senator Dianne Feinstein, a California Democrat and chairwoman of the committee.

Nevertheless, Feinstein said she's working on a bill that would add transparency to the data collection process at the NSA and the surveillance court. Some of the provisions she described would reinforce current NSA practices, but the bill would also give the NSA new authority to continue to conduct surveillance on foreign suspects who enter the U.S. while the agency seeks court-ordered warrants.

Feinstein, chairwoman of the committee that's supposed to oversee the NSA surveillance programs, at one point interrupted witness Tim Edgar, a former director of privacy and civil liberties for the White House, when he talked about the NSA's unauthorized collection of some U.S. communications. Feinstein defended the NSA, saying the agency immediately reported the mistake to the surveillance court.

"I really believe the NSA is extraordinarily careful in what they do," she said. "I have great faith in the NSA."

Alexander, Director of National Intelligence James Clapper, and some committee members blamed what they called inaccurate media reports on the Snowden leaks for creating an environment of mistrust in the NSA by the general public.

Some media organizations are feeding “raw meat to people who refuse to look at the facts” that the NSA’s data collections are legal and protect privacy, said Senator Dan Coats, an Indiana Republican.

“It’s very frustrating to know that we have programs that comply with the law, that have been approved by the Congress, that have been approved by the president of the United States, that are saving Americans’ lives, and there are efforts to compromise those programs to convince a nontrusting public,” Coats said. “Had we not had these programs in place, I’d hate to think of what we’d be talking about” at the hearing.

Clapper agreed with Coats. Intelligence officials are frustrated in their efforts to “counter the popular narrative” about the surveillance programs, he said.

But Senator Ron Wyden, an Oregon Democrat and critic of the NSA programs, pointed his finger back at U.S. intelligence officials. Abuses alleged in the NSA programs were bound to be made public, said Wyden, who introduced legislation Wednesday that would prohibit bulk collection of phone records by the NSA.

“I believe that any government official who thought that the intrusive, constitutionally flawed surveillance system would never be disclosed was ignoring history,” Wyden said. “The leadership of your agencies built an intelligence collection system that repeatedly deceived the American people. Time and time again, the American people were told one thing about domestic surveillance in public forums, while government agencies did something else in private.”

Updated at 3:25 p.m. PT with additional information about mobile-phone location data collection.

Grant Gross covers technology and telecom policy in the U.S. government for The IDG News Service.
More by Grant Gross, IDG News Service


View the original article here

Saturday, 31 August 2013

Microsoft will move forward with litigation over NSA data collection

Computerworld - Microsoft general counsel Brad Smith said on Friday that the company would move ahead with its lawsuit against the U.S. government, seeking permission to release more information on demands Microsoft receives from the National Security Agency (NSA) and others for Internet user data.

In a blog post, Smith dismissed as inadequate the Obama Administration's announcement late on Thursday that it would begin publishing, on an annual basis, the total number of national security requests for customer data made to Internet and telecom service providers.

"The Government's decision represents a good start. But the public deserves and the Constitution guarantees more than this first step," Smith said.

He noted that it is vital for companies such as Microsoft to be able to publish data that clearly distinguishes between government requests for actual user content and government requests for metadata like the subscriber information related to a particular email address.

Such information can be published in a manner that poses no risk to national security. Any discussion on service provider obligations and government data collection practices under the anti-terror Foreign Intelligence Surveillance Act (FISA) would remain incomplete unless this type of information is publicly released, Smith said.

However, in a blog post announcing intention to release data on the number of NSA requests each year, the Director of National Intelligence, James Clapper, made clear that this is as much information the government is willing to provide for now.

"FISA and national security letters are an important part of our effort to keep the nation and its citizens safe, and disclosing more detailed information about how they are used and to whom they are directed can obviously help our enemies avoid detection," Clapper said.

Both Google and Microsoft sued the government in June over the issue. Both companies are among the several major Internet players from whom the NSA and other intelligence agencies are gathering large volumes of data on Internet users under FISA orders.

Under the anti-terror statute, the companies are currently prohibited from disclosing any details about the information they are required to provide, or even how many requests they receive each year from the NSA and other U.S. intelligence agencies.

Microsoft and others have vigorously argued that their inability to disclose such information is hurting them and had resulted in all sorts of misperceptions about the government having direct access to their systems. Their concerns are also likely being fueled by recent warnings that the NSA's data collection activities could cost U.S. cloud companies billions of dollars in business going forward.

In his blog post, Smith noted that since June the U.S. Department of Justice has filed six extensions for time to respond to the complaints aired by Microsoft and Google in their lawsuits. Microsoft agreed to those extensions, he said.

Last month, the company asked U.S. Attorney General Eric Holder to personally help Microsoft and others share more complete information on how they handle national security requests for customer data.

"We hoped that these discussions would lead to an agreement acceptable to all," Smith wrote. "While we appreciate the good faith and earnest efforts by the capable Government lawyers with whom we negotiated, we are disappointed that these negotiations ended in failure."

As a result, the company will "move forward with litigation in the hope that the courts will uphold our right to speak more freely," Smith wrote. "And with a growing discussion on Capitol Hill, we hope Congress will continue to press for the right of technology companies to disclose relevant information in an appropriate way."

Jaikumar Vijayan covers data security and privacy issues, financial services security and e-voting for Computerworld. Follow Jaikumar on Twitter at Twitter @jaivijayan or subscribe to Jaikumar's RSS feed Vijayan RSS. His e-mail address is jvijayan@computerworld.com.

See more by Jaikumar Vijayan on Computerworld.com.

Read more about Privacy in Computerworld's Privacy Topic Center.

How Cloud Communications Reduce Costs and Increase ProductivitySmall and midsize businesses are moving to the cloud to host their communications capabilities. Learn how enterprise-quality phone benefits, online management, conferencing, auto attendant, and ease of use are built into a system that is half the cost of a PBX.

Read now.


View the original article here

Thursday, 1 August 2013

U.S. senators push for changes in NSA data collection

Several U.S. senators will push for changes in the way the National Security Agency collects the telephone records of millions of U.S. residents, with lawmakers saying they will focus on making the NSA program more transparent to the public.

Some members of the Senate Judiciary Committee said Wednesday they will introduce legislation targeting the NSA telephone records collection program.

Senator Al Franken, a Minnesota Democrat, said he will introduce a bill this week that requires the NSA and other agencies to make public the number of U.S. residents they have collected information on, and how many resident have had their information reviewed by federal agents. The bill would also allow companies to disclose the number of surveillance requests they get from government agencies, a change Google, Microsoft and other companies have asked for.

“There is a critical problem at the center of this debate and that’s the lack of transparency around these programs,” Franken said at a committee hearing on NSA surveillance programs. The secrecy around the NSA surveillance programs is “bad for privacy and bad for democracy,” he added.

Senator Richard Blumenthal, a Connecticut Democrat, said he will push for the data collection process at the Foreign Intelligence Surveillance Court to include lawyers serving as public advocates who can oppose surveillance requests from the NSA and other agencies. Including opposing lawyers would help create public trust in the program, he said.

But Stewart Baker, a partner at the Steptoe & Johnson law firm and a former NSA general counsel, questioned if adding new public advocates to the surveillance request process would calm public fears about the NSA programs, revealed in June by former NSA contractor Edward Snowden.

With the public advocate lawyers paid by the U.S. government, some critics may still argue the process is “really just a sham,” Baker said.

Even Senator Dianne Feinstein, D-California, chairwoman of the Senate Intelligence Committee and vocal supporter of NSA surveillance programs, called for the agency to make its efforts more transparent. The agency should reduce the number of years it keeps phone records from five to two or three and should release more information about the number of times a company has to give up records, she said.

Committee members didn’t call for the NSA to abolish the surveillance programs, however. Civil liberties groups, however, called for wider changes to the programs, beyond transparency and new public advocates in the court process.

“It’s become clear that the NSA is engaged in far-reaching, intrusive and unlawful surveillance of Americans’ phone calls and electronic communications,” said Jameel Jaffer, deputy legal director of the American Civil Liberties Union, which has filed a lawsuit against the NSA. An overhaul of the program and the law behind it is needed, he said.

On Wednesday, more than 100 digital rights and other organizations released a list of 13 principles related to human rights and electronic surveillance. Governments must “limit surveillance to that which is strictly and demonstrably necessary to achieve a legitimate aim,” and they must conduct surveillance only when there’s a “high degree of probability that a serious crime has been or will be committed,” the document said.

Among the groups signing the human rights document were the Electronic Frontier Foundation, Free Press, the Free Software Foundation Europe and Reporters Without Borders.

Several members of the committee, both Republicans and Democrats, questioned the breadth of the NSA telephone records collection program, with senators asking how the NSA can classify nearly all U.S. telephone records as relevant to an antiterrorism investigation, as required in the Patriot Act. The hearing largely ignored the NSA’s so-called Prism program, which collects the content of email and other Internet communications of targets believed to be outside the U.S.

The U.S. government needs to find a better balance between security needs and privacy, said Senator Patrick Leahy, a Vermont Democrat and committee chairman.

“We could have more security if we strip-searched everybody who came into every building in America, but we’re not going to do that,” Leahy sad. “We could have more security if ... we put a wiretap on everybody’s cell phone in America, if we search everybody’s home. But there are certain areas of our own privacy that we Americans expect.”

Other senators defended Prism and the phone records collection, saying they have helped keep the U.S. safe from terrorist attacks. The phone records collection program doesn’t collect the content of phone calls and several courts have ruled that the collection of business records doesn’t violate the U.S. Constitution’s Fourth Amendment protecting U.S. residents from unreasonable searches and seizures, said Senator Jeff Sessions, an Alabama Republican.

“I’m inclined to think all of these actions are consistent with the Constitution and laws of the United States,” he said.

The phone records program has played an important part in several antiterrorism investigations, added Sean Joyce, deputy director of the U.S. Federal Bureau of Investigation. Terrorists are “trying to harm America,” he said. “They’re trying to strike America. We need all these tools.”

Still, representatives of the NSA and U.S. Department of Justice said they are open to making changes to the records collection program so that the public can have more confidence in the process. President Barack Obama’s administration is open to changes that would make the programs more transparent to the public, said Robert Litt, general counsel of the U.S. Office of the Director of National Intelligence.

Grant Gross covers technology and telecom policy in the U.S. government for The IDG News Service.
More by Grant Gross, IDG News Service


View the original article here

US appeals court upholds warrantless collection of phone location data

Warrants are not required by the U.S. government to access historical cell site information, an appeals court ruled in an order.

The Fourth Amendment to the U.S. Constitution protects only reasonable expectations of privacy, the U.S. Court of Appeals for the Fifth Circuit wrote in a 2-1 ruling on Tuesday. The Fourth Amendment protects against unreasonable searches and seizures.

"Because a cell phone user makes a choice to get a phone, to select a particular service provider, and to make a call, and because he knows that the call conveys cell site information, the provider retains this information, and the provider will turn it over to the police if they have a court order, he voluntarily conveys his cell site data each time he makes a call," the court added.

Cell site information is clearly a business record, collected by the service provider for its own business purposes, and without being asked to so by the government, the court said in the order.

The dispute hinged around whether law enforcement agents can access cell site data with a relatively easy-to-obtain order under section 2703 (d) of the Stored Communications Act, which is based on a showing of "specific and articulable facts," instead of using a search warrant after showing probable cause.

Rights groups American Civil Liberties Union and Electronic Frontier Foundation and others have argued that the government should be required to seek a warrant to access the location information, because it is sensitive and can reveal a great deal about a person. The groups argued in court that SCA grants courts the discretion to require the government to obtain a warrant based upon probable cause before accessing historical cell phone location data.

Ruling that compelled warrantless disclosure of cell site data violates the Fourth Amendment, a magistrate judge earlier denied a government request for the historical cell site data in three applications filed in October, 2010 under the SCA for seeking evidence relevant to three separate criminal investigations. The judge, however, allowed for providing subscriber information.

Following an appeal by the government, a district court held that data "disclosing the location of the telephone at the time of particular calls may be acquired only by a warrant issued on probable cause," as the records would show the date, time called, number, and location of the telephone when the call was made, which is constitutionally protected.

The Fifth Circuit court clarified that its ruling only covered section 2703(d) orders to obtain historical cell site information, and did not address, for example, orders requesting data from all phones that use a tower during a particular interval or "situations where the Government surreptitiously installs spyware on a target's phone or otherwise hijacks the phone's GPS, with or without the service provider's help."

The Supreme Court of New Jersey ruled earlier this month that cellphone users have a reasonable expectation of privacy of their cellphone location information, and police are required to get a search warrant before accessing the information. People are not promoting the release of personal information to others when making disclosures to phone companies, the court said in an unanimous ruling.

John Ribeiro covers outsourcing and general technology breaking news from India for The IDG News Service. Follow John on Twitter at @Johnribeiro. John's e-mail address is john_ribeiro@idg.com

John Ribeiro covers outsourcing and general technology breaking news from India for The IDG News Service.
More by John Ribeiro, IDG News Service


View the original article here