Showing posts with label CATCH-ALL. Show all posts
Showing posts with label CATCH-ALL. Show all posts

May 16, 2011

CATCH-ALL Revisited

From an important new Jane Mayer piece:

When Binney heard the rumors, he was convinced that the new domestic-surveillance program employed components of ThinThread: a bastardized version, stripped of privacy controls. “It was my brainchild,” he said. “But they removed the protections, the anonymization process. When you remove that, you can target anyone.” He said that although he was not “read in” to the new secret surveillance program, “my people were brought in, and they told me, ‘Can you believe they’re doing this? They’re getting billing records on U.S. citizens! They’re putting pen registers’ ”—logs of dialled phone numbers—“ ‘on everyone in the country!’

(Our insights went even further - scarfing everything - is still too hot for anyone else but SMC to have discussed.)

Aid, the author of the N.S.A. history, suggests that ThinThread’s privacy protections interfered with top officials’ secret objective—to pick American targets by name. “They wanted selection, not just collection,” he says.

...

Binney, for his part, believes that the agency now stores copies of all e-mails transmitted in America, in case the government wants to retrieve the details later. In the past few years, the N.S.A. has built enormous electronic-storage facilities in Texas and Utah. Binney says that an N.S.A. e-mail database can be searched with “dictionary selection,” in the manner of Google. After 9/11, he says, “General Hayden reassured everyone that the N.S.A. didn’t put out dragnets, and that was true. It had no need—it was getting every fish in the sea.”

Jul 2, 2008

CATCH-All Shadows


Cross-border communications intercepts are all the rage these days, both in terms of the publicity and public debate generated - and by measure of the flurry of international legislative activities in motion to retroactively cloak in legalese the amassing activities that have already been well in place for considerable time among our duteous SIGINT allies - and that as integral piecemeal part of that ol´ jig-saw puzzle we've oft & melodramatically referred to as our Catch-All program.

Of perhaps fleeting interest to some of our readers comes a feebly related judgment handed down by the European Court of Human Rights earlier this week in a case brought by Liberty (the National Council for Civil Liberties), the Irish Council for Civil Liberties and British Irish Rights Watch against the United Kingdom. The judgment found that UK surveillance laws had lacked the necessary clarity and accountability to prevent abuses of power when used to intercept cross-border communications.

According to the EHCR,
[it]does not consider that the domestic law at the relevant time indicated with sufficient clarity, so as to provide adequate protection against abuse of power, the scope or manner of exercise of the very wide discretion conferred on the State to intercept and examine external communications. In particular, it did not, as required by the Court’s case-law, set out in a form accessible to the public any indication of the procedure to be followed for selecting for examination, sharing, storing and destroying intercepted material. The interference with the applicants’ rights under Article 8 (the right to privacy) was not, therefore, “in accordance with the law.”
A puniest of victories for privacy advocates - a pebbly bump in the road for CATCH-ALL.

Nov 7, 2007

CATCH-ALL: Suck It Up - All Of It


As we recently boasted,
for over a year and a half, readers here have been treated to details of the CATCH-ALL program that are only now being uncovered by our intrepid news media.
An article hacked & jacked from today's business section of the Washington Post might be of some interest to our readers that have followed SMC's mumbling & fumbling exposition of the Catch-All saga from scratch.

The plain-spoken, bespectacled Klein, 62, said he may be the only person in the country in a position to discuss firsthand knowledge of an important aspect of the Bush administration's domestic surveillance program. He is retired, so he isn't worried about losing his job. He did not have security clearance, and the documents in his possession were not classified, he said. He has no qualms about "turning in," as he put it, the company where he worked for 22 years until he retired in 2004.

In an interview yesterday, he alleged that the NSA set up a system that vacuumed up Internet and phone-call data from ordinary Americans with the cooperation of AT&T . Contrary to the government's depiction of its surveillance program as aimed at overseas terrorists, Klein said, much of the data sent through AT&T to the NSA was purely domestic. Klein said he believes that the NSA was analyzing the records for usage patterns as well as for content.

He said the NSA built a special room to receive data streamed through an AT&T Internet room containing "peering links," or major connections to other telecom providers. The largest of the links delivered 2.5 gigabits of data -- the equivalent of one-quarter of the Encyclopedia Britannica's text -- per second, said Klein, whose documents and eyewitness account form the basis of one of the first lawsuits filed against the telecom giants after the government's warrantless-surveillance program was reported in the New York Times in December 2005.

In summer 2002, Klein was working in an office responsible for Internet equipment when an NSA representative arrived to interview a management-level technician for a special job whose details were secret.

"That's when my antennas started to go up," he said. He knew that the NSA was supposed to work on overseas signals intelligence.

"What the heck is the NSA doing here?" Mark Klein, a former AT&T technician, said he asked himself.

The job entailed building a "secret room" in an AT&T office 10 blocks away, he said. By coincidence, in October 2003, Klein was transferred to that office and assigned to the Internet room. He asked a technician there about the secret room on the 6th floor, and the technician told him it was connected to the Internet room a floor above. The technician, who was about to retire, handed him some wiring diagrams.

"That was my 'aha!' moment," Klein said. "They're sending the entire Internet to the secret room."

The diagram showed splitters, glass prisms that split signals from each network into two identical copies. One fed into the secret room, the other proceeded to its destination, he said.

"This splitter was sweeping up everything, vacuum-cleaner-style," he said. "The NSA is getting everything. These are major pipes that carry not just AT&T's customers but everybody's."

One of Klein's documents listed links to 16 entities, including Global Crossing, a large provider of voice and data services in the United States and abroad; UUNet, a large Internet provider in Northern Virginia now owned by Verizon; Level 3 Communications, which provides local, long-distance and data transmission in the United States and overseas; and more familiar names such as Sprint and Qwest. It also included data exchanges MAE-West and PAIX, or Palo Alto Internet Exchange, facilities where telecom carriers hand off Internet traffic to each other.

"I flipped out," he said. "They're copying the whole Internet. There's no selection going on here. Maybe they select out later, but at the point of handoff to the government, they get everything."

Another document showed that the NSA installed in the room a semantic traffic analyzer made by Narus, which Klein said indicated that the NSA was doing content analysis.

Claudia Jones, an AT&T spokeswoman, said she had no comment on Klein's allegations. "AT&T is fully committed to protecting our customers' privacy. We do not comment on matters of national security," she said.

The NSA and the White House also declined comment on Klein's allegations.

Klein is in Washington this week to share his story in the hope that it will persuade lawmakers not to grant legal immunity to telecommunications firms that helped the government in its anti-terrorism efforts

Klein is urging Congress not to block Hepting v. AT&T, a class-action suit pending in federal court in San Francisco, as well as 37 other lawsuits charging carriers with illegally collaborating with the NSA. He was accompanied yesterday by lawyers for the Electronic Frontier Foundation, which filed Hepting v. AT&T in 2006. Together, they are urging key U.S. senators to oppose a pending White House-endorsed immunity provision that would effectively wipe out the lawsuits. The Judiciary Committee is expected to take up the measure Thursday.

Aug 14, 2007

Hint: It's Not About Fighting Terrorism


For over a year and a half, readers here have been treated to details of the CATCH-ALL program that are only now being uncovered by our intrepid news media.

A California appeals court will examine two cases this week that could impact the federal government's high-tech surveillance of Americans. The Wednesday hearings come after a new law that broadens intelligence officials' eavesdropping power.

The Bush administration wants the 9th U.S. Circuit Court of Appeals to dismiss the lawsuits, contending that they could jeopardize highly sensitive "state secrets." Because the privilege prevents litigants from obtaining classified data, the cases lack standing, the Justice Department argued.

The Supreme Court ruled in 1953 that the executive branch could bar evidence from court if it was deemed a national security threat, senior agency officials told reporters Monday. When the material in question is scrubbed from a case, the complaint may or may not fall apart, they said.

"We're not arguing that this means the judges should look at classified material secretly and rule in favor of the government on the merits of the claims," one staffer said. The government is simply pushing for "a decision that the case can't be litigated in light of national security interests involved."

In one case, the Electronic Frontier Foundation accused AT&T of collaborating with the National Security Agency in illegal spying on millions of customers. ...

In the AT&T case, EFF claims that the telecommunications firm provided the NSA a "dragnet" that collects "all or substantially all of the communications of U.S. citizens," a Justice official said. The second claim pertains to the alleged preservation of AT&T customers' call records.


Touché (but you have to wonder about the WaPo's capacity for embarrassment at how badly they were scooped):

So far, evidence in the case suggests a massive effort by the NSA to tap into the backbone of the Internet to retrieve millions of e-mails and other communications, which the government could sift and analyze for suspicious patterns or other signs of terrorist activity, according to court records, plaintiffs' attorneys and technology experts.

"The scale of these deployments is . . . vastly in excess of what would be needed for any likely application or any likely combination of applications, other than surveillance," says an affidavit filed by J. Scott Marcus, the senior Internet adviser at the Federal Communications Commission from 2001 to 2005. Marcus analyzed evidence for the plaintiffs in the case. ...

Tomorrow's hearing will focus only on whether the two lawsuits should be dismissed on the basis of the government's assertion of a "state secrets privilege." The outcome could determine whether the courts will ever rule on the legality of surveillance conducted by the NSA without judicial oversight between 2001 and January 2007, when the Bush administration first subjected the program to the scrutiny of a special intelligence court.

"If the courts take the position that the state-secrets privilege prevents the case from going forward, I think effectively there'll never be a decision about the legality of the program," said Cindy Cohn, the Electronic Frontier Foundation's legal director. ...

President Bush and his aides have confirmed that the NSA, beginning in late 2001, monitored electronic communications between the United States and overseas without warrants in cases in which one of the parties was believed to be affiliated with al-Qaeda. But administration officials have recently acknowledged that the NSA program was broader, and intelligence sources inside and outside the government have described a vast effort to collect and analyze telephone and e-mail communications that were later scrutinized by the government for desired information. ...

Some of the evidence also suggests that the NSA efforts were not limited to overseas e-mail communications and included the collection of purely domestic traffic. ...

Marcus, the former FCC adviser, said in a legal declaration recently unsealed in the case that the operation described by Klein "is neither modest nor limited" and was far more extensive than needed if it was focused only on international communications or on tasks other than surveillance.

"I conclude that AT&T has constructed an extensive -- and expensive -- collection of infrastructure that collectively has all the capability necessary to conduct large-scale covert gathering of [Internet protocol]-based communications information, not only for communications to overseas locations, but for purely domestic communications as well," said Marcus, a veteran computer network executive who worked at GTE, Genuity and other companies before joining the FCC.

James X. Dempsey, policy director at the Center for Democracy and Technology, said the evidence gleaned from the AT&T case appears to confirm that "there is a massive surveillance capability built into the network" by the federal government. But, Dempsey added, "the mere fact that the capability has been built and utilized still does not answer the fundamental question -- has it been exercised under constitutional parameters? That, in a way, is what these cases are trying to get to."


For a concise explanation of why the CATCH-ALL program is a fraud as advertized, see: Effective Counterterrorism and the Limited Role of Predictive Data Mining.

Jul 17, 2007

"I've Got Nothing To Hide"


From a new paper on government surveillance and data mining by George Washington University Law School Professor Daniel J. Solove, 'I've Got Nothing to Hide' and Other Misunderstandings of Privacy (25 page pdf):

Far too often, discussions of the NSA surveillance and data mining define the problem solely in terms of surveillance. To return to my discussion of metaphor, the problems are not just Orwellian but Kafkaesque. The NSA programs are problematic even if no information people want to hide is uncovered. In The Trial, the problem is not inhibited behavior, but rather a suffocating powerlessness and vulnerability created by the court system's use of personal data and its exclusion of the protagonist from having any knowledge or participation in the process. The harms consist of those created by bureaucracies – indifference, errors, abuses, frustration, and lack of transparency and accountability.

One such harm, for example, which I call "aggregation," emerges from the combination of small bits of seemingly innocuous data. When combined, the information become much more telling about a person. For the person who truly has nothing to hide, aggregation is not much of a problem. But in the stronger less absolutist form of the "nothing to hide" argument, people are arguing that certain pieces of information are not something they would hide.

Aggregation, however, means that by combining pieces of information we might not care to conceal, the government can glean information about us that we might really want to conceal. Part of the allure of data mining for the government is its ability to reveal a lot about our personalities and activities by sophisticated means of analyzing data. Therefore, without greater transparency in data mining, it is hard to claim that programs like the NSA data mining program will not reveal information people might want to hide, as we do not know precisely what is revealed.

Moreover, data mining aims to be predictive of behavior. In other words, it purports to prognosticate about our future actions. People who match certain profiles are deemed likely to engage in a similar pattern of behavior. It is quite difficult to refute actions that one has not yet done. Having nothing to hide will not always dispel predictions of future activity.

Another problem in the taxonomy, which is implicated by the NSA program, is the problem I refer to as "exclusion." Exclusion is the problem caused when people are prevented from having knowledge about how their information is being used, as well as barred from being able to access and correct errors in that data. The NSA program involves a massive database of information that individuals cannot access. Indeed, it was kept secret for years. This kind of information processing, which forbids people's knowledge or involvement, resembles in some ways a kind of due process problem. It is a structural problem involving the way people are treated by government institutions. Moreover, it creates a power imbalance between individuals and the government. To what extent should the Executive Branch, and an agency such as the NSA, which is relatively insulated from the political process and public accountability, have a significant power over citizens? This issue is not about whether the information gathered is something people want to hide, but rather about the power and the structure of government. ...

A related problem involves "secondary use." Secondary use is the use of data obtained for one purpose for a different unrelated purpose without the person's consent. The Administration has said little about how long the data will be stored, how it will be used, and what it could be used for in the future. The potential future uses of any piece of personal information are vast, and without limits or accountability on how that information is used, it is hard for people to assess the dangers of the data being in the government's control.

Therefore, the problem with the "nothing to hide" argument is that it focuses on just one or two particular kinds of privacy problems – the disclosure of personal information or surveillance – and not others. It assumes a particular view about what privacy entails, and it sets the terms for debate in a manner that is often unproductive.

It is important to distinguish here between two ways of justifying a program such as the NSA surveillance and data mining program. First is to not recognize a problem. This is how the "nothing to hide" argument works. It denies even the existence of a problem. The second manner of justifying such a program is to acknowledge the problems but contend that the benefits of the NSA program outweigh the privacy harms. The first justification influences the second, for the low value given to privacy is based upon a narrow view of the problem.

Jul 14, 2007

Showdown Coming Next Week Over NSA CATCH-ALL Document Subpoenas


President Bush has until Wednesday to decide whether the White House will wage a Constitutional war on two fronts, when subpoenaed documents about the scope and legality of the President's warrantless wiretapping program are due to the Senate Judiciary Committee.

If Bush decides to buck the Senate's demands by asserting Executive Privilege, Senator Patrick Leahy -- the the sharp-tongued Vermont Democrat helming the committee, will likely initiate contempt proceedings, as is happening in the House, where the President has prevented testimony in the controversy over the politically-motivated firings of U.S. Attorneys.

Leahy subpoenaed the White House, the Vice President, the National Security Council and the Justice Department on June 27, seeking documents about the legal opinions justifying the spy program, spying agreements with the nation's telecoms and documents related to denying Justice Department investigators security clearances to look into the program.

According to the government's admission, the program, given the tautological moniker Terrorist Surveillance Program by the government, spied on Americans emails and phone calls when the National Security Agency believed that one of the parties to the conversation had links to terrorism and that one end of the conversation was outside the United States.

Given the administration is trying to squash suits against itself and against its alleged telecom partners in the warrantless snooping based on the notion, there's little chance the Administration will give their Democratic foe the documents he wants. Instead, they will likely find another way to re-send the message that Vice Presidet Cheney famously sent Leahy. But how will they do it? Turn over a limited number of almost blank papers? Flat out refuse to testify or give documents, citing executive privilege? A horse head in Leahy's bed? Will someone from the Administration eventually end up in Congress's little known jail cell?

The spying matter is now playing on the big screen both in Congress and the courts.

The president's spying program recently surmounted one legal challenge when an appeals court struck down a lower court decision that the program was illegal, ruling that the journalists and lawyers who sued couldn't prove they were spied on so had no standing to sue.

However, another suit now enmeshed in the Ninth Circuit may be able to evade that Catch-22, since the plaintiffs claim that the government accidentally gave them a document showing they were spied upon without a warrant.

For those of you who like to keep track, ACLU has a illustrated scorecard on who has been subpoenaed and what documents the group wants to see requested. The Administration is likely to signal its intentions prior to Wednesday's deadline, so start your popcorn maker now.

Jul 5, 2007

The Relativity of Eavesdropping


Britain may have more CCTV cameras per head than anywhere else in the world but when it comes to electronic surveillance the country is way behind Italy, the Netherlands and even Sweden.

Official figures have revealed UK law enforcement agencies and other government bodies made 439,000 requests to monitor telephones and email addresses in a 15 month period between 2005 and 2006, leading to comments that Britain led the world in spying on its citizens.

The UK figures might sound high but are dwarfed by interception statistics from other countries. According to figures from German scientific think-tank the Max Planck Society, Italy leads the world with 76 intercepts per 100,000 head of population, shortly ahead of the Netherlands (62), and with third-placed Sweden some way back (33). Germany comes in fourth with 23.5 intercepts per 100,000 head of population with England and Wales trailing on six intercepts per head of population.

The Netherlands came up with a standard for IP interception and championed a framework for electronic surveillance when it held the EU presidency in 2004, so it can be seen as an evangelist for technology its ready to apply on its own populace. Corruption inquiries are perceived as the reason why Italy tops the global wiretap league.

Electronic surveillance levels in US are roughly on par with those of the UK. Based on a Department of Justice intercept report to Congress, 1.2m requests to tap telephones and email addresses were made in 2005, the last year for which figures are available. Most involved requests to obtain historic lists of telephone calls with only 48,000 requests looking for real-time call data and 2,600 involving the interception of communications.

These official figures exclude so-called warrantless domestic wiretaps approved by the Bush Administration and also exclude the NSA's related and diligent efforts as part and parcel of CATCH-ALL.

For examples of rather mundane vendors making a buck by providing turn-key solutions for governments to hack into your life, take a peek at SS8 Networks , AQSACOM, and Bivio.
-Hacked & Addended Excerpt From The Register

May 25, 2007

Just Being Neighborly

Mexico is expanding its ability to tap telephone calls and e-mail using money from the U.S. government, a move that underlines how the country's conservative government is increasingly willing to cooperate with the United States on law enforcement.

The expansion comes as President Felipe Calderon is pushing to amend the Mexican Constitution to allow officials to tap phones without a judge's approval in some cases. Calderon argues that the government needs the authority to combat drug gangs, which have killed hundreds of people this year.

Mexican authorities for years have been able to wiretap most telephone conversations and tap into e-mail, but the new $3-million Communications Intercept System being installed by Mexico's Federal Investigative Agency will expand their reach.

The system will allow authorities to track cellphone users as they travel, according to contract specifications. It includes extensive storage capacity and will allow authorities to identify callers by voice. The system, scheduled to begin operation this month, was paid for by the U.S. State Department and sold by Verint Systems Inc., a politically well-connected firm based in Melville, N.Y., that specializes in electronic surveillance.

Although information about the system is publicly available, the matter has drawn little attention so far in the United States or Mexico. The modernization program is described in U.S. government documents, including the contract specifications, reviewed by The Times.

They suggest that Washington could have access to information derived from the surveillance. Officials of both governments declined to comment on that possibility.

"It is a government of Mexico operation funded by the U.S.," said Susan Pittman, of the State Department's Bureau of International Narcotics and Law Enforcement Affairs. Queries should be directed to the Mexican government, she said.


Anyone wishing to conduct such an inquiry would be well advised to leave contact information, travel itinerary, and names and addresses of next-of-kin, with the U.S. Embassy in Mexico City before proceeding.

May 24, 2007

Catching Up With CATCH-ALL - NSA Domestic Surveillance

Is the NSA's domestic surveillance program far greater in scope than anyone, save SMC, has admitted to?



We might just have caught an indirect glimpse of the behemoth SMC has referred to as CATCH-ALL by observing the interference pattern generated by former Deputy Attorney General James Comey's cross-illuminated testimony in the Senate on May 15.

Former Deputy Attorney General James Comey claimed that the entire leadership of the Justice Department was prepared to resign over their disagreement with the White House, in particular with Cheney and his lawyer Addington - and specifically over circumstances pertaining to the NSA's domestic surveillance program.

What are these circumstances? Do they comprise the significant difference between what has hitherto been admitted and what SMC has long dubbed & described as CATCH-ALL?

For a moment last week we thought we might just have laid a morning misty eye on ol' Nessie coming up for air. Then she dove - if that was her at all.

May 16, 2007

DOJ Determined NSA CATCH-ALL Program Was Illegal

The blogosphere is reacting to the story of Alberto Gonzales' and Andrew Card's visit to pressure then-Attorney General John Ashcroft on his sick bed as if it is "news."
Hardly.

On New Year's Day 2006, the story was featured on EFFWIT, with the added revelation that the episode was behind Ashcroft's resignation as AG.

-Excerpt From EFFWIT

May 14, 2007

'Risk Assessment' Data On Travelers Demanded From Europe

The EU knows that the U.S. -- if denied by European officials -- will alternately get the data from the private sector. But we want to be polite and ask nicely first.

(T)he Bush administration is asking the European Union to lift its objections to the sharing of airline passenger information with American intelligence agencies, said the secretary of homeland security, Michael Chertoff.

On the fringes of a meeting of European interior ministers here Saturday, Mr. Chertoff argued that other countries, no matter how friendly, could not decide who entered the United States. He plans to repeat the message before a European Parliament panel in Brussels on Monday.

"While we reassure Europe, we have to insist that we can't tie our hands in keeping dangerous people out of the United States," Mr. Chertoff said in an interview here.

Under an interim accord between Washington and the European Union, data that overseas passengers routinely give airlines — address, credit card, passport, phone and other information — is being used for screening on arrival at American airports.

But the accord expires July 31, and some European governments and data protection advocates have strenuously objected to what they call an invasion of privacy and possible misuse of personal information.

At the heart of the discussions between Mr. Chertoff and the Europeans is the issue of how Washington can screen passengers who, as citizens of 15 European Union countries, do not need to apply for a visa for stays of up to 90 days. The nations include Britain, France, Germany and Italy but not the most recent entrants to the European Union, like Poland, Hungary and Romania.

Gaining access to data on British citizens of Pakistani origin has been a priority for Washington since the 2005 London transit system attack in which three of the four suicide bombers were of Pakistani descent.

The British home secretary, John Reid, who was at the conference, said he was "utterly opposed" to screening based on ethnicity.

Mr. Chertoff held discussions with Britain last month on immigration matters. He said there was no attempt to single out Britain for separate treatment. But, he said: "The visa process does afford a level of protection. The visa waiver countries by definition do not give us that. We need to find some way for a comparable level of protection."

That protection, the Homeland Security Department argues, can best be provided by feeding the passenger names and other information gathered in Europe by the airlines into another data system, the Automated Targeting System, based in Washington.

The data system, established after 9/11 to build "risk assessments" of incoming passengers, runs the names of travelers and their data against lists of known or suspected terrorists.

Some members of Congress and privacy advocates have objected to the targeting system, saying it could be used indiscriminately by Homeland Security and other agencies for "data mining" against people.

Those concerned about invasion of privacy have said that along with basic data, airlines share such things as passengers' food preferences — for example, orders for halal meals — and that this could be used to single out Muslim passengers.

May 4, 2007

CATCH-ALLish Booty

A while back we ran a post about a little company originally out of Sweden called Spotfire that attracted investment from the CIA's venture capital vehicle In-Q-Tel and Soros Fund Management.

Spotfire develops nifty data mining software that facilitates massive surveillance operations against the domestic population and taunts with promises of predicative capabilities.

Tibco, a Palo Alto, California software company, has now said it has agreed to buy the business intelligence software company Spotfire, of Somerville, Mass. for about $195 million in cash. (In case anyone has failed to notice, domestic population surveillance is by and large conducted by private sector parties that offer their wares and services to various State entities entangled in legal and extra-legal mass surveillance of various population subsets.)

Tibco said its own software, which gives companies a way to manage their data infrastructure in “real time,” would be complimented by Spotfire’s business intelligence offering. It is the latest in a string of acquisitions of business intelligence companies.

Bush Trying To Immunize Telecos Over CATCH-ALL

The White House is still playing CYA on the CATCH-ALL program.

The Bush administration is urging Congress to pass a law that would halt dozens of lawsuits charging phone companies with invading ordinary citizens' privacy through a post-Sept. 11 warrantless surveillance program.

The measure is part of a legislative package drafted by the Justice Department to relax provisions in the 1978 Foreign Intelligence Surveillance Act (FISA) that restrict the administration's ability to intercept electronic communications in the United States. If passed, the proposed changes would forestall efforts to compel disclosure of the program's details through Congress or the court system.

The proposal states that "no action shall lie . . . in any court, and no penalty . . . shall be imposed . . . against any person" for giving the government information, including customer records, in connection with alleged intelligence activity the attorney general certifies "is, was, would be or would have been" intended to protect the United States from terrorist attack. The measure, which has not yet been filed, is contained in a proposed amendment to the fiscal 2008 intelligence authorization bill. ...

Though laws exist that could immunize companies against civil and criminal liability in surveillance cases, invoking them would acknowledge that the firm cooperated with the government. Such knowledge could allow a terrorist to adjust tactics, the government argues.

Government lawyers crafted the immunity bill using terms deliberately vague in referring to activity that "would be or would have been" aimed at protecting the country from attack to avoid indicating whether a company cooperated.

But civil libertarians charged that blanket immunity would amount to a legislative pardon to telecommunications companies and others that have aided the government's warrantless surveillance, without explaining the pardon's basis. ...

The measure would gut Congress's efforts to conduct inquiries into the administration's surveillance program because a subpoenaed company or government official could invoke immunity, said Tim Sparapani, legislative counsel for the American Civil Liberties Union, which has sued the government to force a halt to its wiretapping program.

"The end result is not only will the Bush administration continue to stonewall Congress in its request for information on warrantless wiretapping, but no one who participated will have any threat above their head," Sparapani said. "You could just face a congressional subpoena and say, 'I'm sorry, I'm immunized.' "

Dec 14, 2006

Effective Counterterrorism and the Limited Role of Predictive Data Mining

From Effective Counterterrorism and the Limited Role of Predictive Data Mining, by Jeff Jonas [engineer and chief scientist with IBM's Entity Analytic Solutions Group] and Jim Harper [director of information policy studies at the Cato Institute]:

"Though data mining has many valuable uses, it is not well suited to the terrorist discovery problem. It would be unfortunate if data mining for terrorism discovery had currency within national security, law enforcement, and technology circles because pursuing this use of data mining would waste taxpayer dollars, needlessly infringe on privacy and civil liberties, and misdirect the valuable time and energy of the men and women in the national security community." ...

One of the fundamental underpinnings of predictive data mining in the commercial sector is the use of training patterns. Corporations that study consumer behavior have millions of patterns that they can draw upon to profile their typical or ideal consumer. Even when data mining is used to seek out instances of identity and credit card fraud, this relies on models constructed using many thousands of known examples of fraud per year.

Terrorism has no similar indicia. With a relatively small number of attempts every year and only one or two major terrorist incidents every few years -- each one distinct in terms of planning and execution -- there are no meaningful patterns that show what behavior indicates planning or preparation for terrorism.

Unlike consumers' shopping habits and financial fraud, terrorism does not occur with enough frequency to enable the creation of valid predictive models. Predictive data mining for the purpose of turning up terrorist planning using all available demographic and transactional data points will produce no better results than the highly sophisticated commercial data mining done today. The one thing predictable about predictive data mining for terrorism is that it would be consistently wrong.

Without patterns to use, one fallback for terrorism data mining is the idea that any anomaly may provide the basis for investigation of terrorism planning. Given a "typical" American pattern of Internet use, phone calling, doctor visits, purchases, travel, reading, and so on, perhaps all outliers merit some level of investigation. This theory is offensive to traditional American freedom, because in the United States everyone can and should be an "outlier" in some sense. More concretely, though, using data mining in this way could be worse than searching at random; terrorists could defeat it by acting as normally as possible.

Treating "anomalous" behavior as suspicious may appear scientific, but, without patterns to look for, the design of a search algorithm based on anomaly is no more likely to turn up terrorists than twisting the end of a kaleidoscope is likely to draw an image of the Mona Lisa.

Mar 2, 2006

Da' NSA...Exposé (Now That! Rhymes)


How to keep shocking news simple. Well how about this failed attempt:

The NSA and its programme affiliates in the CATCH ALL project (SMC's nomenclature) are building the infrastructure of steady-state capture and storage of absolutely every volley of electronic communication generated within or sent to the U.S.A. The establishment of that infrastructure is well under way and much of it is already in plodding place.

Added to that are various novel and evolving tools and covert programmes that focus on trawling about in this huge repository of stored communications for whatever one might feel the need to be in search of for the moment - or for the party.

So the poetry of this is: one need not target a person or a group for wiretapping to monitor the webbing of their tattlings - everyone is already monitored (or targeted to soon be). All one need do is mine the gargantuan, and growing at that , repository of collected communications with the correct mining tools. One slick aspect of all this is that collection of communications is seperated from the analysis of the collected communications. It's no longer a matter of simultaneous collect & listen. Nifty. You better believe Gonzalez likes that!

In odd lot instances, old-fashioned targeted wiretaps are indeed still necessitated when all the content components of a particular communication exchange are required or when the targeted individuals' communication network is not yet incorporated into the CATCH ALL collection infrastructure. The huge CATCH ALL project does not yet record and store all of the anecdotal content in any given collected communication - this primarily due to purely technical limitations facing the project to date. But for now the vacuuming of near all transactional data will do quite nicely indeed.

We'll just keep on trying to explain this baby with meatballish mumblings as the days grind on. Our 15 minutes of rolling meatballs are up.

Feb 24, 2006

Only All The Meatballs Are Enough


Every single electronic communication is being collected and stored - or is targeted for such eventual capture. That means every electronic communication. At a bare minimum the forensic trace evidence of each and every electronic communication is being collected and stored for good. At most the actual exhaustive contents of each volley of electronic communication is being collected and stored.

We are not speaking of data mining per se here - that is an entirely different matter albeit one that stands to make productive use of this CATCH ALL program . We are speaking of a Manhattan Project type effort to collect and store ALL communications within the United States for present and future exploitation.

What has been publicly exposed to date are various forms of dubious data mining activities and fuzzy-legal snoopings into the communications of domestic subpopulations of relatively limited size. These activities however represent only a minute fraction of the scope of the real stinker that belies these surface ripples. More tomorrow.