If I'm reading the OP correctly, then, based solely on what they've reported, it seems that the denials made by FB and Google were not only truthful, but sincere (as opposed to being either weaselly or outright dishonest or both)...Here's the key passage:
---
> *
“The U.S. government does not have direct access or a ‘back door’ to the information stored in our data centers,” Google’s chief executive, Larry Page, and its chief legal officer, David Drummond, said in a statement on Friday. “We provide user data to governments only in accordance with the law.”*
Statements from Microsoft, Yahoo, Facebook, Apple, AOL and Paltalk made the same distinction.
But instead of adding a back door to their servers, the companies were essentially asked to erect a locked mailbox and give the government the key, people briefed on the negotiations said. Facebook, for instance, built such a system for requesting and sharing the information, they said.
The data shared in these ways, the people said, is shared after company lawyers have reviewed the FISA request according to company practice. It is not sent automatically or in bulk, and the government does not have full access to company servers. Instead, they said, it is a more secure and efficient way to hand over the data.
Tech companies might have also denied knowledge of the full scope of cooperation with national security officials because employees whose job it is to comply with FISA requests are not allowed to discuss the details even with others at the company, and in some cases have national security clearance, according to both a former senior government official and a lawyer representing a technology company.
---
The NYT is talking only about FISA requests, which are a secret process but, as far as everything reported about that process has said, targets individuals. Moreover, when FISA is used on Americans, it's a process that involves a court-approved warrant.
So you can argue that FISA is wrong or that it is administered with a rubber stamp (and in my opinion, yes, this is most definitely worth scrutinizing, and it has been for however many years it's been put in place), or that no ethical company should ever comply with a FISA request...but that's not the same ballpark as what's being alleged with Verizon or with PRISM.
The point about these companies making it "easier" by creating a systematic delivery process, such as a "lockbox", to send over the requested data is an interesting detail, but kind of a non sequitur. Either FISA is OK or it is flat out wrong...what does it matter which digital process is set up to fulfill that request?
This article seems to make the most sense. As a hypothetical example, Google might have been manually fulfilling thousands of FISA requests. It sucked up time, took engineering resources, was error-prone, and lacked the legal paper trail to track such requests. In addition, the government wanted something faster, that used fewer agents to submit/collect data, and could more easily get updates.
So one day, an NSA agent negotiates with Google to build fisarequest.supersecret.google.com. NSA agents can directly upload FISA request documents, as easily as submitting expense receipts. In turn, Google's legal department can view each request and decide to comply with the click of a mouse, as easily as approving an expense report. If authorization is granted, the NSA can now view the emails of the requested user, and new emails can simply be viewed with a refresh of the browser. As Schmidt and Drummond say, Google can decline a request if it's improper or overly broad, and ask for additional information -- again, as easily as a manager looking at a questionable minibar expense on a trip report.
Said NSA agent does this with multiple companies, internally brands this as PRISM, puts together a Powerpoint deck, and declares victory. It's "direct access" since it's coming straight from Google and on a Google server, and it's "real-time" in that a request can be authorized quickly, and there are no more .zip files with data dumps involved.
Google has never actually heard of PRISM, and only knows that they built a tool to make it easier to do what they were already doing with legal FISA requests. To them, the NSA doesn't have "direct access," which is a loaded term for unfettered superuser access.
The entire program costs only $20mm because the government now requires only a few agents to submit requests and collect data. The cost of building the tools is borne by the companies, who see it as a cheaper way to comply with an existing legal obligation.
This is the best explanation I've seen so far. It requires no one to lie. The Washington Post inferred too much from the evidence it had, but I'm thankful this debate has occurred. The NSA denies that it has broad access, the companies deny it, individuals at those companies also deny it. Obama denies it. All of them speak truthfully.
The EFF publishes a timeline of when companies decided to streamline their own access requests, which may well be perfectly truthful.
This is pretty much what I think, knowing no more than what anyone here knows. It's reasonable to argue that NSA-issued request are wrong, period, but that's different from saying that Google is actively assisting them in a para-legal process...not only out of Constitutional concerns, but because building such a backdoor necessarily creates security risks to users, NSA targets or not.
In my layman's opinion, building such a backdoor in an infrastructure as complicated as Google's would require a team as well as an oversight group...someone has to write tests for that "feature" and someone else has to make sure those tests aren't seen by those who don't need to know (I.e. the rest of Google's sizable test department)...this kind if arrangement would seemingly have to be known by someone on the executive team.
The FISA Amendments Act of 2008 granted the government the right to order communication providers to give the government content on foreigners with a broad, non-particularized court order.
This is what PRISM is. The order requires companies to provide assistance and facilities.
A traditional FISA warrant names a citizen or foreigner specifically. A warrant is always needed for this kind of surveillance, but the target is rarely, if ever, told (unlike with a criminal wiretap).
In short, the 2008 Amendment allows the NSA to order companies to help with bulk collection. It's section 702.
> when FISA is used on Americans, it's a process that involves a court-approved warrant.
What? So not being a US citizen makes us second class citizens in game of online privacy? That's ridiculous. And no, these requests were not just for individual foreign users.
> FISA orders can range from inquiries about specific people to a broad sweep for intelligence, like logs of certain search terms, lawyers who work with the orders said.
from the OP.
Who gives the US government the right to see my online private data without my consent? esp when I am not even a US citizen.
However...Google cannot promise that it doesn't give indirect access. They've admitted openly that they comply to tens of thousands of data requests over the years.
> FISA orders can range from inquiries about specific people to a broad sweep for intelligence, like logs of certain search terms, lawyers who work with the orders said.
Looks like personal data could be turned over (well, at least part of your search history) even if you're not being targeted individually.
I think this article shows exactly how two-faced the denials made by FB and Google really are. The NYT is talking about PRISM here, which is implemented via FISA.
While it's possible that NSA does not have "completely unfettered" access to all Google/Facebook/Microsoft databases, it's obvious that they have direct access to a system which provides real-time data. For example in the case of monitoring Skype conversations (voice, video, data), email, and web searches, of a previously identified target. Yes, they sign off at the start, and then they let the system RUN.
Of course data is sent "automatically" and "in bulk" but by themselves these words mean little to nothing. I think the question is do they even bother identifying foci for the search? For Verizon "meta-data" they didn't bother, they just suck it all up. Note well, that URLs are considered "meta-data", even though in most cases they fully describe the content. Note well, GPS location of your phone is "meta-data".
A true and honest debate about whether we want to live under this type of "total surveillance" would require a lot of education for the average American to understand what these systems are truly capable of. Senators Wyden and Udell have been whispering warnings for years, but even they are gagged by FISA. It's so insulting to hear Obama claim he welcomes debate on the subject, while he continues to obfuscate the true scope of the surveillance.
If the PRISM slides are accurate about the "2 degrees of separation" then even targeting an individual at the start is meaningless. 2 degrees of separation along what axis? You think it's just 2 degrees of "sent mail"? There are spooks who do nothing but think about this shit all day long... "Two degrees of separation" could mean the warrant automatically broadens itself up to 2 hops from the foci, based on any "contact" along:
- Outgoing / Incoming email
- Facebook, Skype, Google Groups, contact lists
- IRC channel members
- Common web searches
- Common URLs visited
- Common brick & mortor shops visited
You can taint a LOT of people with only 2 degrees of separation if you starting thinking along multiple dimensions of contact.
It's specifically this "social network" which the FBI is interested in. You need these "support systems" installed at Google/Facebook/Microsoft if you want to build the graph out efficiently. The document was leaked, the government acknowledged how vital and important they believe it is for them to have access to this data. I'm not sure what more do you need to see?
Frankly, the blog posts the way they are worded don't deny anything at all. If Google was willing and able, they could tell us unequivocally the process, format, and scope of the data they share with the NSA. A Google Analytics for "NSA Spook Activity, Quarterly". Then we can start to have the "public debate".
Wait...how is it "obvious" that "they have direct access to a system which provides real-time data"...? Isn't that direct access what Google and Facebook are said to have explicitly denied?
The NYT doesn't seem to be talking about PRISM here. It seems to be talking about FISA. From the WaPo and Guardian's reports, I thought that PRISM was concocted as a response to what the NSA saw as "shortcomings" in FISA?
FISA doesn't preclude "real-time" data - that's one of the points of the surveillance. The original intention of the law was to listen to phone calls as they happened.
What's unclear between the original descriptions of what the slides called Prism and these descriptions is just how automatic the system is - if the steps of lawyers individually reviewing each request still exist.
---
> * “The U.S. government does not have direct access or a ‘back door’ to the information stored in our data centers,” Google’s chief executive, Larry Page, and its chief legal officer, David Drummond, said in a statement on Friday. “We provide user data to governments only in accordance with the law.”*
Statements from Microsoft, Yahoo, Facebook, Apple, AOL and Paltalk made the same distinction.
But instead of adding a back door to their servers, the companies were essentially asked to erect a locked mailbox and give the government the key, people briefed on the negotiations said. Facebook, for instance, built such a system for requesting and sharing the information, they said.
The data shared in these ways, the people said, is shared after company lawyers have reviewed the FISA request according to company practice. It is not sent automatically or in bulk, and the government does not have full access to company servers. Instead, they said, it is a more secure and efficient way to hand over the data.
Tech companies might have also denied knowledge of the full scope of cooperation with national security officials because employees whose job it is to comply with FISA requests are not allowed to discuss the details even with others at the company, and in some cases have national security clearance, according to both a former senior government official and a lawyer representing a technology company.
---
The NYT is talking only about FISA requests, which are a secret process but, as far as everything reported about that process has said, targets individuals. Moreover, when FISA is used on Americans, it's a process that involves a court-approved warrant.
So you can argue that FISA is wrong or that it is administered with a rubber stamp (and in my opinion, yes, this is most definitely worth scrutinizing, and it has been for however many years it's been put in place), or that no ethical company should ever comply with a FISA request...but that's not the same ballpark as what's being alleged with Verizon or with PRISM.
The point about these companies making it "easier" by creating a systematic delivery process, such as a "lockbox", to send over the requested data is an interesting detail, but kind of a non sequitur. Either FISA is OK or it is flat out wrong...what does it matter which digital process is set up to fulfill that request?