6 ms·
US tech giants knew of NSA data collection, agency's top lawyer insists
- andyjohnson0 13y agoIf the companies knew about the data collection but were prevented from speaking about it due to being served with national security letters, does this admission change what they can talk about? And/or does it indirectly confirm the existence of NSLs?
- lern_too_spel 13y agoNo. They were only prevented from speaking about how many they received, and still are except in broad buckets. The existence of NSLs and the fact that they were about collecting certain users' data have both been directly confirmed by all parties since NSLs existed.
- davesean 13y agoNo one denied complying with 702 orders. The main contention about PRISM isn't that the entities receiving data requests knew that they were receiving these requests, the main contention was/is about the "direct access" allegations which is what these companies actually denied, that and knowing the government codename for the program. Bad reporting.
- poulson 13y agoThe second paragraph of the article claims that companies knew about "upstream" collection as well. This is, from my understanding, the main point, as the Google engineer Brandon Downey issued the very harsh statement, and I quote, "fuck these guys", when the infamous smiley-face slide leaked. EDIT: Apparently the "upstream" collection does not refer to the third capture method in question, which exploited the fact that Google did not (at the time) encrypt its internal communications.
- dlinder 13y agoiirc "upstream" refers to collection out on the Internet - the "fuck those guys" program is MUSCULAR, which is the tapping of private interdatacenter links. http://en.wikipedia.org/wiki/Upstream_collection http://en.wikipedia.org/wiki/Upstream_collection vs http://en.wikipedia.org/wiki/MUSCULAR http://en.wikipedia.org/wiki/MUSCULAR
- davesean 13y agoThe "fuck you"s were directed at interceptions under executive order 12333 which as the second to last paragraph makes clear was not a subject of discussion. PRISM and UPSTREAM featured in the same slide which would explain them being discussed together, but UPSTREAM isn't subject to tech firms' whims so the discussion might have been concerning telecom firms as well. The reporting isn't clear, best read the transcript when available.
- poulson 13y agoI stand corrected. Thank you for clarifying.
- leoc 13y agoI am assuming that this > After the hearing, De said that the same knowledge, and associated legal processes, also apply when the NSA harvests communications data not from companies directly but in transit across the internet, under Section 702 authority. doesn't imply that Facebook is informed when an "upstream collection" request is made to a telco in relation to a Facebook user, but rather that the telco is. It's pretty unclear though.
- gojomo 13y agoFirst, even if the companies did know, there was probably a tacit agreement with the NSA that the NSA would always allow them plausible deniability. "Not only are you doing your country a great (and legally-required) service, but everyone involved will go to their graves with the details. Have you heard about how [competitors/famous-companies X, Y, Z] have fully cooperated for decades? You haven't? Exactly." The NSA seems to have been forced by events to break that likely mutual-understanding. Second, what does it mean for a "company" to know something? What if one compartmentalized group of employees know – perhaps ex-military/intelligence people themselves – and believe they are both compelled to comply and to keep the full details from upper management (for everyone's protection)? Does that count as the "company" knowing? I could see the CEOs saying, as they have, "no", and the NSA saying, as they are here, "yes".
- polarix 13y agoCorrect. Companies are not monolithic. How many people do you need to know about it, in order to hide something from the monitoring systems and management alike? 10? 2?
- Zigurd 13y agoThe lawyer quoted in the article appears to contradict this: “Collection under this program was a compulsory legal process, that any recipient company would receive.” That's not a black bag job.
- gojomo 13y agoJoe who used to work at Ft. Meade – totally stand-up patriot! – is a senior employee in the company's operations department. He is served the compulsory process, and it is implied that under the process, he should not tell anyone else at the company, including superiors and company counsel. In fact, the senior executives may have even tacitly employed Joe for this role for this very purpose: he's been pre-vetted by the security state. That's not quite a 'black bag' job. Nor is it completely legitimate. It's something in-between, which most of the time lets everyone work under convenient fictions, getting on with the rest of their jobs.
- iratedev 13y agoAh - so we've been focusing our hate on the wrong entity?
- dan_bk 13y agoSimply disgusting.
- andyl 13y agoOf course they did (do). Just like telcos. What is amazing is the carelessness that the government shows w.r.t. protecting the interests of American tech firms. NSA could hardly have done more to destroy worldwide trust and credibility in our tech industry.
- eliteraspberrie 13y agoI suppose the grass is greener on the other side. As a Canadian I trust the US tech industry. Everything that has been exposed in the US has been happening here too, and then some. The options are: spend lots of money to be spied on here; spend much less money to be spied on in the US.
- annapurna 13y agoCouldn't agree more.
- Zigurd 13y agoThis is what should be the central point of the discussion here. NSA treats it's informants about as badly as some hick county sherriff does to drug snitches. Except the stakes are $100s of billions in revenue from sovereign governments and economic competitors who would prefer not to just bend over for getting back-doored. The other side of the coin is that the companies collaborating in these programs seem to put themselves at the mercy of the government rather than making products that can be verifiably trusted.
- Zigurd 13y agoTl;dr: They ALL knew. They were ordered to comply. The denials are lies.
- joshstrange 13y agoNo, it appears this is only talking about the FISA court orders >> “All 702 collection is pursuant to court directives, so they have to know,” De reiterated to the Guardian. So, yes, companies knew they were being served with FISA warrants (that they complied with) but AFAICT they were unaware that the NSA was tapping their data lines like the example where they tapped data lines between Google's (and others) data centers. [1] [1] http://www.washingtonpost.com/world/national-security/nsa-infiltrates-links-to-yahoo-google-data-centers-worldwide-snowden-documents-say/2013/10/30/e51d661e-4166-11e3-8b74-d89d714ca4dd_story.html http://www.washingtonpost.com/world/national-security/nsa-in...
- newman314 13y agoIt would be nice if these were illustrated. It's hard to keep track if who said what in context to particular directives/warrants etc.
- Zigurd 13y ago> Section 702 is not the only legal authority the US government possesses to harvest data transiting the internet.
- mpyne 13y agoThe existence of other legal authorities does not imply that tech firms are voluntarily working with NSA to help NSA harvest their data transiting the Internet. It doesn't even make sense anyways; what does Facebook have to do with surreptitiously tapping into a router in Belgrade or Quito?
- Zigurd 13y agoWhether cooperation is voluntary, or not, is not the issue. Nor is tapping the carriers, with or without their cooperation. The article says that cooperation can be compelled. The issue is that some of the participants in PRISM denied providing "direct access" to their data. Some people here are saying those denials are meaningful when we do not have a complete picture of how cooperation is compelled.
- magicalist 13y agoAs davesean points out below, this isn't talking about fiber tapping and whatnot, this is talking about FISA orders > Neither De nor any other US official discussed data taken from the internet under different legal authorities. Different documents Snowden disclosed, published by the Washington Post, indicated that NSA takes data as it transits between Yahoo and Google data centers, an activity reportedly conducted not under Section 702 but under a seminal executive order known as 12333. So the companies knew that they were receiving secret court orders to disclose data. Well, duh. Edit: he even says so explicitly: > “All 702 collection is pursuant to court directives, so they have to know,” De reiterated to the Guardian. Thanks for saving that for the last line. All the rest is just trying to connect dots they have no new evidence for.
- pktgen 13y agoThrowing the tech companies under the bus...
- Fasebook 13y agoWell, they're all playing in traffic together. It's like their mothers never told them to look both ways before crossing the street, or to not play in traffic, for that matter. Or maybe their mothers hated them and told them to go play in traffic and that's why they hate the world. There are so many ways this allegory works. Ultimately, they're all going to get paved over by a road crew, if not hit by a very large bus. (cough, ahem, HD video, excuse me my digestion hasn't been right lately).
- jrochkind1 13y agoThis caps off some pretty amazing reasoning. Earlier, the government insisted that simply collecting information in their databases was not a 4th ammendment violation, because the actual 'search' only occured when they _search_ the database, not when they collect and put in their database. (I think maybe they even defined 'collect' so it somehow only applied when they did a search, not when they actually collected?) Now they: > ...strongly rejected suggestions by the panel that a court authorise searches for Americans’ information inside the 702 databases. “If you have to go back to court every time you look at the information in your custody, you can imagine that would be quite burdensome,” deputy assistant attorney general Brad Wiegmann told the board. > De argued that once the Fisa court permits the collection annually, analysts ought to be free to comb through it, and stated that there were sufficient privacy safeguards for Americans after collection and querying had occurred. “That information is at the government’s disposal to review in the first instance,” De said. Combine them both, and, well, you see where you get.
- Fasebook 13y agoOoops this universally installed and standardized language is universally installed and standardized, how did that happen?
- deleted 13y ago[deleted]
- znowi 13y agoI suppose if at some point Larry Page himself confirms that they did know all about NSA surveillance and actively participated, people will still find ways to acquit the beloved company :) I'm not sure if it's the force of the "no evil" brand or maybe inherent dislike of the government, but user loyalty in PRISM companies is quite remarkable.
- psbp 13y agoWhy single out Page and Google?
- jeremyjh 13y agoThey singled themselves out with "don't be evil". Which was an implicit critique of other tech giants.
- lern_too_spel 13y agoThat's because PRISM deals with court orders for specific users' data. Every company in the world complies with those court orders. Why should we demonize these companies for doing something everybody else does and that everybody has always known they do?
- patrickg_zill 13y agoSheryl Sandberg has received a lot of press coverage, most of it pretty positive, for her book "Lean In". As COO of Facebook, she must have known a great deal about what was going on... it would be very interesting for me, given her talk of leadership, if she were asked some questions about this....
- linuxhansl 13y ago> “If you have to go back to court every time you look at the information in your custody, you can imagine that would be quite burdensome,” deputy assistant attorney general Brad Wiegmann told the board. Come again...? So we're breaking the separation of the three powers because otherwise the authorities have to be inconvenienced with the "quite burdensome" task of "going back to court"? He can't be serious.