Communiversity

Afrikan Liberation Institute => Math and Science (STEM) => Topic started by: Ajamu on Jun 07, 2013, 03:04 PM

Title: NSA has backdoor access to Internet companies' databases-gctid83505
Post by: Ajamu on Jun 07, 2013, 03:04 PM
NSA has backdoor access to Internet companies' databases | Politics and Law - CNET News (http://news.cnet.com/8301-13578_3-57588143-38/nsa-has-backdoor-access-to-internet-companies-databases/)

Apple,  Microsoft, Yahoo, Facebook and other large tech companies let the  National Security Agency search through confidential customer data,  according to the Washington Post.
   (http://www.cnet.com/profile/declan00/)    by Declan McCullagh (http://www.cnet.com/profile/declan00/)
    June 6, 2013 3:20 PM PDT

(https://www.abibitumikasa.com/proxy.php?request=http%3A%2F%2Fasset2.cbsistatic.com%2Fcnwk.1d%2Fi%2Ftim2%2F2013%2F06%2F06%2Fnsa_610x430.jpg&hash=c36b62bae64e2621b66bacfcb767e9b7dc4dbeb9)
NSA director Keith Alexander
  (Credit: Getty Images)  

  A top-secret surveillance program gives the National Security Agency  surreptitious access to customer information held by Microsoft, Yahoo,  Apple, Google, Facebook, and other Internet companies, according to a  pair of new reports.

  The program, code-named PRISM, reportedly allows NSA analysts to peruse  exabytes of confidential user data held by Silicon Valley firms by  typing in search terms. PRISM reports have been used in 1,477 items in  President Obama's daily briefing last year, according to an internal  presentation to the NSA's Signals Intelligence Directorate obtained by the Washington Post (http://www.washingtonpost.com/investigations/us-intelligence-mining-data-from-nine-us-internet-companies-in-broad-secret-program/2013/06/06/3a0c0da8-cebf-11e2-8845-d970ccb04497_story.html) and the Guardian (http://www.guardian.co.uk/world/2013/jun/06/us-tech-giants-nsa-data) newspapers.

   (https://www.abibitumikasa.com/proxy.php?request=http%3A%2F%2Fasset2.cbsistatic.com%2Fcnwk.1d%2Fi%2Ftim2%2F2013%2F06%2F06%2FPRISM-slide-crop-001_270x193.jpg&hash=f406b2331028cd44f73241f6c4972ced1da17004)  (http://i.i.com.com/cnwk.1d/i/tim2/2013/06/06/PRISM-slide-crop-001.jpg)
Excerpt from top-secret PRISM presentation. Click for larger image
 
  This afternoon's disclosure of PRISM follows another report (http://news.cnet.com/8301-13578_3-57587929-38/nsa-secretly-vacuumed-up-verizon-phone-records/)  yesterday that revealed the existence of another top-secret NSA program  that vacuums up records of millions of phone calls made inside the  United States.

  Other services that are reportedly part of PRISM include PalTalk, Skype,  and AOL. Dropbox is listed in the presentation as "coming soon."

  Some of the companies named in the pair of news reports responded this  afternoon with statements indicating they did not provide direct server  access, or PRISM was not as described. Apple said (http://www.cnbc.com/id/100797046?__source=ft&par=ft):  "We have never heard of PRISM. We do not provide any government agency  with direct access to our servers, and any government agency requesting  customer data must get a court order."

  Joe Sullivan, Facebook's chief security officer, said (http://www.guardian.co.uk/world/2013/jun/07/prism-tech-giants-shock-nsa-data-mining):  "We do not provide any government organization with direct access to  Facebook servers. When Facebook is asked for data or information about  specific individuals, we carefully scrutinise any such request for  compliance with all applicable laws, and provide information only to the  extent required by law." A Google spokesman said: "We disclose user  data to government in accordance with the law, and we review all such  requests carefully."

  Microsoft's statement (http://www.microsoft.com/en-us/news/Press/2013/Jun13/06-06statement.aspx) is probably the most detailed: We provide customer data only when we receive a legally binding order or  subpoena to do so, and never on a voluntary basis. In addition we only  ever comply with orders for requests about specific accounts or  identifiers. If the government has a broader voluntary national security  program to gather customer data we don't participate in it.


The carefully-worded statements leave open the possibility, however,  that the NSA would be given indirect access to company servers that  would still permit queries for user information to be submitted. NBC  News confirmed (http://www.cnbc.com/id/100797046?__source=ft&par=ft) from two sources this afternoon that a data collection program called PRISM exists.

  Separately, the Wall Street Journal reported (http://online.wsj.com/article/SB10001424127887324299104578529112289298922.html)  this evening that the NSA's monitoring includes AT&T and Sprint --  not only Verizon -- and extends to credit card companies. The story also  said the spy agency "obtains access to data from Internet service  providers on Internet use such as e-mail or Web site visits," citing  former government officials, without elaborating.

  The spy agency's apparent direct access -- the FBI is used as an  intermediary, but NSA analysts perform the searches -- appears to be the  result of Section 215 of the Patriot Act, which authorizes secret court  orders that force U.S. companies to turn over business records. That  sweeps in metadata and also the content of confidential communications,  including e-mail, video and voice chat, videos, and photos, the leaked  presentation says.

  The Washington Post said it received the classified PowerPoint slides  about PRISM and other supporting documents from a "career intelligence  officer" who wanted to "expose what he believes to be a gross intrusion  on privacy." The documents are recent, with dates as recent as April  2013.

  PRISM access appears intended to be used primarily for NSA agents to  monitor the activities non-U.S. citizens (the majority of Facebook and  Gmail users, for instance, live in other countries). But without  oversight and other checks, such a powerful capability could be abused.

  The PRISM slides suggest the program started one month after Congress  approved a controversial wiretapping law in August 2007 that opened the  networks of telecommunications companies to the NSA. A CNET FAQ (http://news.cnet.com/FAQ-How-far-does-the-new-wiretap-law-go/2100-1029_3-6201032.html)  at the time said: "The new law effectively expands the National  Security Agency's power to eavesdrop on phone calls, e-mail messages and  other Internet traffic with limited court oversight. Telecommunications  companies can be required to comply with government demands, and if  they do so they are immune from all lawsuits."

  The U.S. national intelligence chief responds

 National  intelligence director James Clapper released two statements this evening  addressing both sets of disclosures. Talking about the Internet  companies, he said there are "extensive procedures, specifically approved by the court (http://www.dni.gov/index.php/newsroom/press-releases/191-press-releases-2013/869-dni-statement-on-activities-authorized-under-section-702-of-fisa),  to ensure that only non-U.S. persons outside the U.S. are targeted, and  that minimize the acquisition, retention and dissemination of  incidentally acquired information about U.S. persons."

  Clapper also addressed the revelations about Verizon (http://www.dni.gov/index.php/newsroom/press-releases/191-press-releases-2013/868-dni-statement-on-recent-unauthorized-disclosures-of-classified-information)  and the other phone companies. "All information that is acquired under  this program is subject to strict, court-imposed restrictions on review  and handling," he said.

Yesterday's disclosure of the Verizon surveillance offers hints of how  the phone companies may be forced to comply. That secret order, issued  by the Foreign Intelligence Surveillance Court, relies on Section 215 of  the Patriot Act, 50 USC 1861 (http://www.law.cornell.edu/uscode/text/50/1861),  better known as the "business records" portion. It allows the  government to obtain any "tangible thing," including "books, records,  papers, documents, and other items," a broad term that includes dumps  from private-sector computer databases with limited judicial oversight.

  The Justice Department's secret interpretation of Section 215 was what  alarmed Sens. Ron Wyden (D-Oregon) and Mark Udall (D-Colorado) when the  Patriot Act was up for renewal two years ago. Both senators served on  the intelligence committee and were briefed on the NSA's activities.

  FBI Director Robert Mueller hinted during a 2011 congressional hearing  that there was a secret legal memorandum prepared by the Justice  Department's Office of Legal Counsel that authorized a broader use of  Section 215 than is publicly known.

  Wyden, who was present at that hearing, told Mueller that he was  "increasingly troubled" that intelligence agencies are "relying on a  secret interpretation" of the Patriot Act. "I believe that the American  people would be absolutely stunned," Wyden said, if they knew what was  actually going on.

  Here's more from the Post's report: Analysts who use the system from a Web portal at Fort Meade key in  "selectors," or search terms, that are designed to produce at least 51  percent confidence in a target's "foreignness." That is not a very  stringent test. Training materials obtained by the Post instruct new  analysts to submit accidentally collected U.S. content for a quarterly  report, "but it's nothing to worry about." ...   Like market researchers, but with far more privileged access, collection  managers in the NSA's Special Source Operations group, which oversees  the PRISM program, are drawn to the wealth of information about their  subjects in online accounts. For much the same reason, civil  libertarians and some ordinary users may be troubled by the menu  available to analysts who hold the required clearances to "task" the  PRISM system.

 
There has been "continued exponential growth in tasking to Facebook and  Skype," according to the 41 PRISM slides. With a few clicks and an  affirmation that the subject is believed to be engaged in terrorism,  espionage or nuclear proliferation, an analyst obtains full access to  Facebook's "extensive search and surveillance capabilities against the  variety of online social networking services."

Title: NSA has backdoor access to Internet companies' databases-gctid83521
Post by: Ɔbenfo Ọbádélé on Jun 07, 2013, 06:24 PM
Notice Abibitumi Kasa isn't on that list thanks to our top flight Abibifahodie Kuo security personnel. :soldiert::soldierg::soldiert:
Title: NSA has backdoor access to Internet companies' databases-gctid84309
Post by: Ajamu on Jun 14, 2013, 03:41 PM
Did Microsoft Lie About NSA Skype Spying? Evidence Suggests They Did - HotHardware (http://hothardware.com/News/Did-Microsoft-Lie-About--NSA-Skype-Spying-Evidence-Suggests-They-Did/)

Did Microsoft Lie About  NSA Skype Spying? Evidence Suggests They Did


                              Friday, June 14, 2013                 - by                      Joel                     Hruska (mailto:%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20Joel%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20Hruska)

                              In the week since word of the NSA's Boundless Informant (http://hothardware.com/Tags/boundless-informant.aspx) and Prism (http://hothardware.com/Tags/prism.aspx)  programs leaked online, there's been a great deal of concern over to  what degree various companies cooperated with the NSA's requests. Some  companies, like Google, have pointed to their repeated requests for  greater transparency. Twitter, of course, is the major social app that isn't  on Prism's list at all. And then, there's Microsoft. It's been notably  quiet since the Prism leak, and while the PR team has had its hands full  dealing with the fallout over the Xbone (http://hothardware.com/Tags/xbone.aspx)  E3 debacle, there's certainly been bandwidth for a situation as serious  as the idea that MS is facilitating the NSA's access to its user  databases. Worse, the company may have lied about it.

(https://www.abibitumikasa.com/proxy.php?request=http%3A%2F%2Fhothardware.com%2Fnewsimages%2FItem26124%2Fprism-slide-5.jpg&hash=66603b508436be145b0efa74862f012f7f6f1d59)

First, the facts:  Since acquiring Skype (http://hothardware.com/Tags/skype.aspx)  in 2011, Microsoft has moved away from the VoIP client's original  distributed node method of organization in favor of a smaller number of  'supernodes.' The company justified these changes by claiming that the  supernode architecture would improve software rollout speeds and  efficient communication. They may well have done so, but a centralized  system is intrinsically easier to spy on than a decentralized one. A  year after buying Skype, Microsoft was granted a patent on "legal  intercept" technology that's explicitly designed to allow a company to  make a silent copy of a voIP stream. Is that patent proof that Microsoft  deployed such a system for snooping on Skype? No. But Skype's terms of  service explicitly allow for such a process.

In March of this year, after intense pressure, Microsoft finally agreed (https://www.microsoft.com/about/corporatecitizenship/en-us/reporting/transparency/)  to reveal data on government requests for Skype information. The report  revealed that the PC version of Skype is fully encrypted (the  tablet/phone version isn't) and implied that the total amount of content  released was quite small in relation to the amount of content  requested. That's true -- but Microsoft's report claims that it never  handed any content over to the United States government from Skype. The  NSA report paints a different picture. According to it, Skype joined the  program in early 2011, well before the Microsoft purchase. We've  already discussed the fact that the gag letters from the FISA court  could make it legally impossible for Microsoft to acknowledge that it  had ever received such requests for data. As far as the system is  concerned, those requests never happened.

If that's true, it means the company's tranparency and privacy report is  a sham. Microsoft may have avoided disclosing the data its users were  most interested in, out of fear that the NSA would react poorly to any  public disclosure. Unlike other companies, like Google, which made it  clear that there were directives in play that it couldn't talk about,  Microsoft chose to perpetuate the myth that Skype remained beyond the  reach of governments.

We're Back To Oversight

Does this reflect poorly on Microsoft? In a sense, yes. It's  inconceivable to believe that the NSA successfully compelled Verizon,  Google, and other companies to turn over data and yet has no visibility  into Skype -- a program which has been identified as a major thorn in  the side of organizations like the FBI. Instead, what's far more likely  is that Microsoft simply ommitted those requests from its reporting.

Google has chosen to fight such requests head-on, a move that's  laudable, but also opens the company up to the possibility of either  indirect punishment or even a lawsuit from the federal government in the  event that its efforts are defeated. Yes, Google gets points on this  for being more willing to stand up to the government, but getting stuck  on that point is like arguing over who filled sandbags more  effectively during the middle of a Mississippi flood. The problem isn't  the sand -- it's the river.

(https://www.abibitumikasa.com/proxy.php?request=http%3A%2F%2Fadmin.hothardware.com%3A8081%2FImages%2FMississippiFlooding.jpg&hash=1b05817aa69e1c6c74dcc1ef588ad65d1cb8aca7)
Ok, now, nobody's allowed to pee for at least a week

Microsoft took the safest path with NSA disclosures. In doing so, it  perpetuated a false claim about Skype. But when the alternative is  risking serious federal lawsuits and the courts have proven unwilling to  take the government to task over expansive claims of national security.  In a situation where the judiciary is giving full legal cover to the  actions of the NSA and FBI and both major parties are loudly advocating  such measures as necessary components of the War on Terror, it's  difficult to argue that Microsoft should be the trailblazer. Redmond,  perhaps adopting a 'better late than never' strategy, has joined Twitter (http://www.guardian.co.uk/world/2013/jun/12/microsoft-twitter-rivals-nsa-requests)  in calling for greater transparency in disclosing when the government  has asked for data and what information it's required to hand over.