...Huh.arstechnica.com wrote:A report published Thursday evening in The Washington Post highlights top-secret documents that show the National Security Agency (NSA) collects unauthorized surveillance on Americans thousands of times per year.
The documents are a May 2012 audit that the NSA performed on its operations. Most of the privacy violations were unintended, the results of things like typographical errors by analysts and programming errors. Some were much more serious, including one that involved unauthorized use of data on more than 3,000 US citizens. In that incident, which occurred in February 2012, thousands of files containing telephone records were retained despite the fact that the NSA had been ordered to destroy them by a surveillance court.
Overall, the audit found 2,776 "incidents" in which the NSA broke its own privacy rules while collecting information. The report breaks out data about the first quarter of 2012, in which 195 violations occurred.
Of those violations, 72 were a result of computer error, including 67 incidents where a computer system didn't recognize a "roamer," or a foreigner bringing a mobile phone into the US. "Operator error" accounted for the other 123 incidents, which included 60 incidences where an operator had a "workload issue" such as inaccurate research. Meanwhile, in 39 incidents, the operator didn't follow operating procedures, and in 21 incidents, typographical errors or "overly broad search terms" led to illegal data collection. The report stated that of the 195 incidents in that quarter, 185 of them were a result of "unintentional collection."
Was that a call to Cairo, or Columbia Heights?
In one incident, a programming error mistook the US area code (202), which serves Washington, D.C., for +20, the international dialing code for Egypt. As a result, a "large number" of domestic American phone calls were intercepted.
In what may be the most serious incident, the NSA mixed together US and foreign e-mails that it collected from tapping into a fiber-optic cable that passes through the United States. However, NSA lawyers told the Foreign Intelligence Surveillance Court that it couldn't filter out which emails belonged to Americans. In October 2011, the FISC Court responded that the email collection effort must stop, and was "deficient on statutory and constitutional grounds."
The audit that provides the basis for the Post's report is one of many documents that were provided to the Post a few months ago by former NSA contractor Edward Snowden. It's essentially a catalogue of the NSA's mistakes, only intended to be seen by the NSA's top leadership. Even Sen. Diane Feinstein (D-CA), chairperson of the Senate Intelligence Committee, didn't get a copy until she was asked about the audit by the Post.
Indeed, the Post reports that fewer than 10 percent of members of Congress have a staff member with the security clearance to read such reports and advise lawmakers on them. Members of Congress themselves may read the documents unredacted, but must do it in a "special secure room, and they are not allowed to take notes."
The Post has made the full report available online, with a few redactions. Other documents include:
- A copy of the top-secret "SSO News" article which noted that the FISA court found the NSA in violation of privacy rules in 2011.
- A slide used in NSA training telling analysts what to do when they accidentally, or intentionally, collect US person data they shouldn't have
- A document telling NSA analysts how to explain their "target rationale" to the Department of Justice and Director of National Intelligence, which warns them not to provide too much information to their "overseers"
The Post has some of the same documents that Edward Snowden leaked to The Guardian, a newspaper based in the United Kingdom.
In a tweet on Thursday evening, Glenn Greenwald, the reporter for The Guardian who has published the most information based on Snowden's leaks, acknowledged he still has more documents as well, writing: "I'm actively working on them every day."
Civil libertarians immediately chastised the government and its spy agencies for such legal violations.
“The number of ‘compliance incidents’ is jaw-dropping. The rules around government surveillance are so permissive that it is difficult to comprehend how the intelligence community could possibly have managed to violate them so often,” said Jameel Jaffer, the American Civil Liberties Union's deputy legal director, in a statement. “Obviously it’s important to know what precisely these compliance incidents involved, and some are more troubling than others. But at least some of these incidents seem to have implicated the privacy of thousands or millions of innocent people.”
Newly published leaks show NSA’s many privacy violations
Moderator: frigidmagi
- rhoenix
- The Artist formerly known as Rhoenix
- Posts: 7998
- Joined: Fri Dec 22, 2006 4:01 pm
- 19
- Location: "Here," for varying values of "here."
- Contact:
#1 Newly published leaks show NSA’s many privacy violations
"Before you diagnose yourself with depression or low self-esteem, make sure that you are not, in fact, just surrounded by assholes."
- William Gibson
- William Gibson
Josh wrote:What? There's nothing weird about having a pet housefly. He smuggles cigarettes for me.
- General Havoc
- Mr. Party-Killbot
- Posts: 5245
- Joined: Wed Aug 10, 2005 2:12 pm
- 21
- Location: The City that is not Frisco
- Contact:
#2 Re: Newly published leaks show NSA’s many privacy violations
As I've long said, the job that people purport the NSA capable of performing is flat impossible, and even a fraction of it will be riddled with basic errors of this sort.
Gaze upon my works, ye mighty, and despair...
Havoc: "So basically if you side against him, he summons Cthulu."
Hotfoot: "Yes, which is reasonable."
Havoc: "So basically if you side against him, he summons Cthulu."
Hotfoot: "Yes, which is reasonable."
- Josh
- Resident of the Kingdom of Eternal Cockjobbery
- Posts: 8114
- Joined: Mon Jun 06, 2005 4:51 pm
- 21
- Location: Kingdom of Eternal Cockjobbery
#3 Re: Newly published leaks show NSA’s many privacy violations
Oh hell yes. People will quote that line from Enemy of the State over and over about keywords and bullshit like that.General Havoc wrote:As I've long said, the job that people purport the NSA capable of performing is flat impossible, and even a fraction of it will be riddled with basic errors of this sort.
Okay, so if every time I say "I'm going to nuke dinner" it kicks in and records my call, precisely how would anything be extracted from that morass of data and what would even be the purpose? One would generally expect the bad guys to employ the most basic of security measures, such as perhaps using words with different common meanings to stand in for the words which actually reference the nefarious deeds they're planning. I think that's called a 'code' or somesuch. Arcane concept, I know.
ETA: Just wanted to add that I think the NSA employs great, hardworking, underappreciated people and that the chemicals in the shed are for the pool.
When the Frog God smiles, arm yourself.
"'Flammable' and 'inflammable' have the same meaning! This language is insane!"
GIVE ME COFFEE AND I WILL ALLOW YOU TO LIVE!- Frigid
"Ork 'as no automatic code o' survival. 'is partic'lar distinction from all udda livin' gits is tha necessity ta act inna face o' alternatives by means o' dakka."
I created the sound of madness, wrote the book on pain
"'Flammable' and 'inflammable' have the same meaning! This language is insane!"
GIVE ME COFFEE AND I WILL ALLOW YOU TO LIVE!- Frigid
"Ork 'as no automatic code o' survival. 'is partic'lar distinction from all udda livin' gits is tha necessity ta act inna face o' alternatives by means o' dakka."
I created the sound of madness, wrote the book on pain