Showing posts with label NSA. Show all posts
Showing posts with label NSA. Show all posts

Wednesday, 24 July 2013

Critics Question Whether NSA Data Collection is Effective

Critics question whether NSA data collection is effective

by Grant Gross, m.csoonline.com
June 25th 2013

— IDG News Service — The recently revealed mass collection of phone records and other communications by the U.S. National Security Agency may not be effective in preventing terrorism, according to some critics.

The data collection programs, as revealed by former NSA contractor Edward Snowden, is giving government agencies information overload, critics said during the Computers, Freedom and Privacy Conference in Washington, D.C.

"In knowing a lot about a lot of different people [the data collection] is great for that," said Mike German, a former U.S. Federal Bureau of Investigation special agent whose policy counsel for national security at the American Civil Liberties Union. "In actually finding the very few bad actors that are out there, not so good."

The mass collection of data from innocent people "won't tell you how guilty people act," German added. The problem with catching terrorism suspects has never been the inability to collect information, but to analyze the "oceans" of information collected, he said.

Mass data collection is "like trying to look for needles by building bigger haystacks," added Wendy Grossman, a freelance technology writer who helped organize the conference.

But Timothy Edgar, a former civil liberties watchdog in the Obama White House and at the Office of Director of National Intelligence, partly defended the NSA collection programs, noting that U.S. intelligence officials attribute the surveillance programs with preventing more than 50 terrorist actions. Some critics have disputed those assertions.

Edgar criticized President Barack Obama's administration for keeping the NSA programs secret. He also said it was "ridiculous" for Obama to suggest that U.S. residents shouldn't be concerned about privacy because the NSA is collecting phone metadata and not the content of phone calls. Information about who people call and when they call is sensitive, he said.

But Edgar, now a visiting fellow at the Watson Institute for International Studies at Brown University, also said that Congress, the Foreign Intelligence Surveillance Court and internal auditors provide some oversight of the data collection programs, with more checks on data collection in place in the U.S. than in many other countries. Analysts can query the phone records database only if they see a connection to terrorism, he said.

The U.S. has some safeguards that are "meaningful and substantive, although I'm sure many in this room ... and maybe even me, if I think about it long enough, might think they're not good enough," Edgar said.

While German noted that the NSA has reported multiple instances of unauthorized access by employees to the antiterrorism databases, Edgar defended the self-reporting. "It's an indication of a compliance system that's actually meaningful and working," he said. "If you had a compliance system that said there was no violation, there were never any mistakes, there was never any improper targeting that took place ... that would an indication of a compliance regime that was completely meaningless."

The mass data collection combined with better data analysis tools translates into an "arms race" where intelligence officials try to find new connections with the data they collect, said Ashkan Soltani, a technology and privacy consultant. New data analysis tools lead intelligence officials to believe they can find more links to terrorism if they just have "enough data," but that belief is "too much sci fi," he said.

"This is the difficult part, if you're saying that if we have enough data we'll be able to predict the future," the ACLU's German said.

Many U.S. intelligence officials are suspect of tech vendor claims about predictive analysis, Edgar countered. However, link analysis -- the tracking of suspects through communications with other known criminals or terrorists -- is a "very powerful tool," he said. It may be possible to use sophisticated cryptographic techniques to do that kind of analysis without the bulk collection of phone records, he said.

"The [internal] compliance regime is not the best answer for privacy," Edgar said. "The best answer is not to take the data in the first place, then you don't have to worry about compliance."

The ACLU has concerns about link analysis, because it creates a massive list of suspicious people that overwhelms investigators, German said. "What link analysis creates is suspicion upon the people that suspicious people are linked to," he said. "That growing cloud of suspicion can never been cleared."

Grant Gross covers technology and telecom policy in the U.S. government for The IDG News Service. Follow Grant on Twitter at GrantGross. Grant's e-mail address is grant_gross@idg.com.


Tuesday, 2 April 2013

NSA Watch | Scandal

EAVESDROPPING 101: WHAT CAN THE NSA DO?

The recent revelations about illegal eavesdropping on American citizens by the U.S. National Security Agency have raised many questions about just what the agency is doing. Although the facts are just beginning to emerge, information that has come to light about the NSA's activities and capabilities over the years, as well as the recent reporting by the New York Times and others, allows us to discern the outlines of what they are likely doing and how they are doing it.

The NSA is not only the world's largest spy agency (far larger than the CIA, for example), but it possesses the most advanced technology for intercepting communications. We know it has long had the ability to focus powerful surveillance capabilities on particular individuals or communications. But the current scandal has indicated two new and significant elements of the agency's eavesdropping:

  1. The NSA has gained direct access to the telecommunications infrastructure through some of America's largest companies
  2. The agency appears to be not only targeting individuals, but also using broad "data mining" systems that allow them to intercept and evaluate the communications of millions of people within the United States.

The ACLU has prepared a map (see below) illustrating how all this is believed to work. It shows how the military spying agency has extended its tentacles into much of the U.S. civilian communications infrastructure, including, it appears, the "switches" through which international and some domestic communications are routed, Internet exchange points, individual telephone company central facilities, and ISPs. While we cannot be certain about these secretive links, this chart shows a representation of what is, according to recent reports, the most likely picture of what is going on.

Corporate Bedfellows

One major new element of the NSA's spying machinery is its ability to tap directly into the major communications switches, routing stations, or access points of the telecommunications system. For example, according to the New York Times , the NSA has worked with "the leading companies" in the telecommunications industry to collect communications patterns, and has gained access "to switches that act as gateways" at "some of the main arteries for moving voice and some Internet traffic into and out of the United States.

 

click for larger image or open pdf (500k)

This new level of direct access apparently includes both some of the gateways through which phone calls are routed, as well as other key nodes through which a large proportion of Internet traffic passes. This new program also recognizes that today's voice and Internet communications systems are increasingly converging, with a rising proportion of even voice phone calls moving to the Internet via VOIP, and parts of the old telephone transmission system being converted to fiber optic cable and used for both data and voice communications. While data and voice sometimes travel together and sometimes do not, and we do not know exactly which "switches" and other access points the NSA has tapped, what appears certain is that the NSA is looking at both.

And most significantly, access to these "switches" and other network hubs give the agency access to a direct feed of all the communications that pass through them, and the ability to filter, sift through, analyze, read, or share those communications as it sees fit.

Data Mining

The other major novelty in the NSA's activities appears to be the exploitation of a new concept in surveillance that has attracted a lot of attention in the past few years: what is commonly called "data mining." Unlike the agency's longstanding practice of spying on specific individuals and communications based upon some source of suspicion, data mining involves formula-based searches through mountains of data for individuals whose behavior or profile is in some way suspiciously different from the norm.

Data mining is a broad dragnet. Instead of targeting you because you once received a telephone call from a person who received a telephone call from a person who is a suspected terrorist, you might be targeted because the NSA's computers have analyzed your communications and have determined that they contain certain words or word combinations, addressing information, or other factors with a frequency that deviates from the average, and which they have decided might be an indication of suspiciousness. The NSA has no prior reason to suspect you, and you are in no way tied to any other suspicious individuals -- you have just been plucked out of the crowd by a computer algorithm's analysis of your behavior.

Use of these statistical fishing expeditions has been made possible by the access to communications streams granted by key corporations. The NSA may also be engaging in "geographic targeting," in which they listen in on communications between the United States and a particular foreign country or region. More broadly, data mining has been greatly facilitated by underlying changes in technology that have taken place in the past few years (see below).

This dragnet approach is not only bad for civil liberties -- it is also a bad use of our scarce security and law enforcement resources. In fact, the creation of large numbers of wasteful and distracting leads is one of the primary reasons that many security experts say data mining and other dragnet strategies are a poor way of preventing crime and terrorism. The New York Times confirmed that point, with its report that the NSA has sent the FBI a "flood" of tips generated by mass domestic eavesdropping and data mining, virtually all of which led to dead ends that wasted the FBI's resources. "We'd chase a number, find it's a schoolteacher with no indication they've ever been involved in international terrorism," one former FBI agent told the Times . "After you get a thousand numbers and not one is turning up anything, you get some frustration."

Combining Telecommunications and Other Private Data?

The NSA has historically been in the business of intercepting and analyzing communications data. One question is whether or not this communications data is being combined with other intimate details about our lives. A few years ago, the Pentagon began work on an breathtaking data mining program called Total Information Awareness, which envisioned programming computers to trawl through an extensive list of information on Americans (including, according to the program's own materials, "Financial, Education, Travel, Medical, Veterinary, Country Entry, Place/Event Entry, Transportation, Housing, Critical Resources, Government, Communications") in the hunt for "suspicious" patterns of activity. Congress decisively rejected this approach, voting to shut down the program, at least for domestic use -- but we know Congress allowed elements of the program to be moved undercover, into the bowels of the Pentagon, while supposedly being restricted to non-Americans. We also know that the NSA is sharing its information with other security services. What we do not know is whether any of information from TIA-like enterprises is being combined with the NSA's communications intercepts.

How the NSA searches for targets

There are a range of techniques that are probably used by the NSA to sift through the sea of communications it steals from the world's cables and airwaves:

  • Keywords. In this longstanding technique, the agency maintains a watch list or "dictionary" of key words, individuals, telephone numbers and presumably now computer IP addresses. It uses that list to pick out potentially relevant communications from all the data that it gathers. These keywords are often provided to the NSA by other security agencies, and the NSA passes the resulting intelligence "take" back to the other agencies or officials. According to the law, the NSA must strip out the names and other identifying information of Americans captured inadvertently, a process called "minimization." (According to published reports, those minimization procedures are not being properly observed.) In the 1990s, it was revealed that the NSA had used the word "Greenpeace" and "Amnesty" (as in the human rights group Amnesty International) as keywords as part of its "Echelon" program (see below).
  • Link analysis. It is believed that another manner in which individuals are now being added to the watch lists is through a process often called "link analysis." Link analysis can work like this: the CIA captures a terrorist's computer on the battlefield and finds a list of phone numbers, including some U.S. numbers. The NSA puts those numbers on their watch list. They add the people that are called from those numbers to their list. They could then in turn add the people called from those numbers to their list. How far they carry that process and what standards if any govern the process is unknown.
  • Other screening techniques. There may be other techniques that the NSA could be using to pluck out potential targets. One example is voice pattern analysis, in which computers listen for the sound of, say, Osama Bin Laden's voice. No one knows how accurate the NSA's computers may be at such tasks, but if commercial attempts at analogous activities such as face recognition are any guide, they would also be likely to generate enormous numbers of false hits.

A three-stage process

So how are all these new techniques and capabilities being put into practice? Presumably, "The Program" (as insiders reportedly refer to the illegal practices) continues to employ watch lists and dictionaries. We do not know how the newer and more sophisticated link analysis and statistical data mining techniques are being used.

But, a good guess is that the NSA is following a three-stage process for the broadest portion of its sweep through the communications infrastructure:

  1. The Dragnet: a search for targets. In this stage, the NSA sifts through the data coursing through the arteries of our telecom systems, making use of such factors as keyword searches, telephone number and IP address targeting, and techniques such as link analysis, and "data mining." At this stage, the communications of millions of people may be scrutinized.
  2. Human review: making the target list. Communications and individuals that are flagged by the system for one reason or another are presumably then subject to human review. An analyst looks at the origin, destination and content of the communication and makes a determination as to whether further eavesdropping or investigation is desired. We have absolutely no idea what kind of numbers are involved at this stage.
  3. The Microscope: targeting listed individuals. Finally, individuals determined to be suspicious in phase two are presumably placed on a target list so that they are placed under the full scrutiny of the NSA's giant surveillance microscope, with all their communications captured and analyzed.

Expanding surveillance as technology changes

Today's NSA spying is a response to, and has been made possible by, some of the fundamental technological changes that have taken place in recent years. Around the end of 1990s, the NSA began to complain privately -- and occasionally publicly -- that they were being overrun by technology as communications increasingly went digital. One change in particular was especially significant: electronic communications ranging from email to voice conversations were increasingly using the new and different protocols of the Internet.

The consequence of this change was that the NSA felt it was forced to change the points in the communications infrastructure that it targeted -- but having done that, it gained the ability to analyze vastly more and richer communications.

The Internet and technologies that rely upon it (such as electronic mail, web surfing and Internet-based telephones known as Voice over IP or VOIP) works by breaking information into small "packets." Each packet is then routed across the network of computers that make up the Internet according to the most efficient path at that moment, like a driver trying to avoid traffic jams as he makes his way across a city. Once all the packets -- which are labeled with their origin, destination and other "header" information -- have arrived, they are then reassembled.

An important result of this technology is that on the Internet, there is no longer a meaningful distinction between "domestic" and "international" routes of a communication. It was once relatively easy for the NSA, which by law is limited to "foreign intelligence," to aim its interception technologies at purely "foreign" communications. But now, an e-mail sent from London to Paris, for example, might well be routed through the west coast of the United States (when, for example, it is a busy mid-morning in Europe but the middle of the night in California) along the same path traveled by mail between Los Angeles and San Francisco.

That system makes the NSA all the more eager to get access to centralized Internet exchange points operated by a few telecommunications giants. But because of the way this technology works, eavesdropping on an IP communication is a completely different ballgame from using an old-fashioned "wiretap" on a single line. The packets of interest to the eavesdropper are mixed in with all the other traffic that crosses through that pathway -- domestic and international.

Echelon

Much of what we know about the NSA's spying prior to the recent revelations comes from the late 1990s, when a fair amount of information emerged about a system popularly referred to by the name "Echelon" -- a codename the NSA had used at least at one time (although their continued use of the term, if at all, is unknown). Echelon was a system for mass eavesdropping on communications around the world by the NSA and its allies among the intelligence agencies of other nations. The best source of information on Echelon was two reports commissioned by the European Parliament (in part due to suspicions among Europeans that the NSA was carrying out economic espionage on behalf of American corporations). Other bits of information were gleaned from documents obtained through the U.S. Freedom of Information Act, as well as statements by foreign governments that were partners in the program (the UK, Australia, Canada, and New Zealand).

As of the late 1990s/early 2000s, Echelon swept up global communications using two primary methods:

  • The interception of satellite and microwave signals. One way that telephone calls and other communications are sent from the United States to Europe and other destinations is via satellite and microwave transmissions. ECHELON was known to use numerous satellite receivers ("dishes") -- located on the east and west coasts of the United States, in England, Australia, Germany, and elsewhere around the globe -- to vacuum up the "spillover" broadcasts from these satellite transmissions.
  • Transoceanic cable tapping. ECHELON's other primary eavesdropping method was to tap into the transoceanic cables that also carry phone calls across the seas. According to published reports, American divers were able to install surveillance devices onto these cables. One of these taps was discovered in 1982, but other devices apparently continued to function undetected. It is more difficult to tap into fiber-optic cables (which unlike other cables do not "leak" radio signals that can be picked up by a device attached to the outside of the cable), but there is no reason to believe that that problem remained unsolved by the agency.

We do not know the extent to which these sources of data continue to be significant for the NSA, or the extent to which they have been superseded by the agency's new direct access to the infrastructure, including the Internet itself, over which both voice and data communications travel.

Unanswered questions

The bottom line is that the NSA appears to be capable not only of intercepting the international communications of a relatively small number of targeted Americans, but also of intercepting a sweeping amount of U.S. communications (through corporate-granted access to communications "pipes" and "boxes"), and of performing mass analysis on those communications (through data mining and other techniques).

Despite the fuzzy picture of "The Program" that we now possess, the current spying scandal has highlighted many unanswered questions about the NSA's current activities. They include:

  • Just what kinds of communications arteries has the NSA tapped into?
  • What kinds of filters or analysis is the NSA applying to the data that flows through those arteries? How are data mining and other new techniques are being used?
  • Which telecom providers are cooperating with the NSA?
  • How are subjects selected for targeted intercepts?
  • What kinds of information exchange are taking place between the NSA and other security agencies? We know they probably turn over to other agencies any data turned up by watch list entries submitted by those other agencies, and they are also apparently passing along data mining-generated "cold hits" to the FBI and perhaps other security agencies for further investigation. Does information flow the other way as well -- are other agencies giving data to the NSA for help in that second phase of deciding who gets put under the microscope?
  • Is data that NSA collects, under whatever rubric, being merged with other data, either by NSA or another agency? Is communications data being merged with other transactional information, such as credit card, travel, and financial data, in the fashion of the infamous "Total Information Awareness" data mining program? (TIA, while prohibited by Congress from engaging in "domestic" activities, still exists within the Pentagon -- and can be used for "foreign intelligence purposes.)
  • Just how many schoolteachers and other innocent Americans have been investigated as a result of "The Program"? And just how much privacy invasion are they subject to before the FBI can conclude they are not "involved in international terrorism"?

Rarely if ever in American history has a government agency possessed so much power subject to so little oversight. Given that situation, abuses were inevitable -- and any limits to those abuses a matter of mere good fortune. If our generation of leaders and citizens does not rise to the occasion, we will prove ourselves to be unworthy of the heritage that we have been so fortunate to inherit from our Founders.

Eric Lichtblau and James Risen, "Spy Agency Mined Vast Data Trove, Officials Report," New York Times , December 24, 2005; http://select.nytimes.com/search/restricted/article?res=FA0714F63E540C778EDDAB0994DD404482

Lowell Bergman, Eric Lichtblau, Scott Shane and Don Van Natta Jr., "Spy Agency Data After Sept. 11 Led F.B.I. to Dead Ends," New York Times , January 17, 2006; http://www.nytimes.com/2006/01/17/politics/17spy.html .

 

NSA Watch | Echelon FAQ

Answers to Frequently Asked Questions (FAQ) about Echelon

Q - What is Project ECHELON?

ECHELON is the term popularly used for an automated global interception and relay system operated by the intelligence agencies in five nations: the United States, the United Kingdom, Canada, Australia and New Zealand (it is believed that ECHELON is the code name for the portion of the system that intercepts satellite-based communications). While the United States National Security Agency (NSA) takes the lead, ECHELON works in conjunction with other intelligence agencies, including the Australian Defence Signals Directorate (DSD). It is believed that ECHELON also works with Britain's Government Communications Headquarters (GCHQ) and the agencies of other allies of the United States, pursuant to various treaties. (1)

These countries coordinate their activities pursuant to the UKUSA agreement, which dates back to 1947. The original ECHELON dates back to 1971. However, its capabilities and priorities have expanded greatly since its formation. According to reports, it is capable of intercepting and processing many types of transmissions, throughout the globe. In fact, it has been suggested that ECHELON may intercept as many as 3 billion communications everyday, including phone calls, e-mail messages, Internet downloads, satellite transmissions, and so on. (2) The ECHELON system gathers all of these transmissions indiscriminately, then distills the information that is most heavily desired through artificial intelligence programs. Some sources have claimed that ECHELON sifts through an estimated 90 percent of all traffic that flows through the Internet. (3)

However, the exact capabilities and goals of ECHELON remain unclear. For example, it is unknown whether ECHELON actually targets domestic communications. Also, it is apparently very difficult for ECHELON to intercept certain types of transmissions, particularly fiber communications.

Q - How does ECHELON work?

ECHELON apparently collects data in several ways. Reports suggest it has massive ground based radio antennae to intercept satellite transmissions. In addition, some sites reputedly are tasked with tapping surface traffic. These antennae reportedly are in the United States, Italy, England, Turkey, New Zealand, Canada, Australia, and several other places. (4)

Similarly, it is believed that ECHELON uses numerous satellites to catch "spillover" data from transmissions between cities. These satellites then beam the information down to processing centers on the ground. The main centers are in the United States (near Denver), England (Menwith Hill), Australia, and Germany. (5)

According to various sources, ECHELON also routinely intercepts Internet transmissions. The organization allegedly has installed numerous "sniffer" devices. These "sniffers" collect information from data packets as they traverse the Internet via several key junctions. It also uses search software to scan for web sites that may be of interest. (6)

Furthermore, it is believed that ECHELON has even used special underwater devices which tap into cables that carry phone calls across the seas. According to published reports, American divers were able to install surveillance devices on to the underwater cables. One of these taps was discovered in 1982, but other devices apparently continued to function undetected. (7)

It is not known at this point whether ECHELON has been able to tap fiber optic phone cables.

Finally, if the aforementioned methods fail to garner the desired information, there is another alternative. Apparently, the nations that are involved with ECHELON also train special agents to install a variety of special data collection devices. One of these devices is reputed to be an information processing kit that is the size of a suitcase. Another such item is a sophisticated radio receiver that is as small as a credit card. (8)

After capturing this raw data, ECHELON sifts through them using DICTIONARY. DICTIONARY is actually a special system of computers which finds pertinent information by searching for key words, addresses, etc. These search programs help pare down the voluminous quantity of transmissions which pass through the ECHELON network every day. These programs also seem to enable users to focus on any specific subject upon which information is desired. (9)

Q - If ECHELON is so powerful, why haven't I heard about it before?

The United States government has gone to extreme lengths to keep ECHELON a secret. To this day, the U.S. government refuses to admit that ECHELON even exists. We know it exists because both the governments of Australia (through its Defence Signals Directorate) and New Zealand have admitted to this fact. (10) However, even with this revelation, US officials have refused to comment.

This "wall of silence" is beginning to erode. The first report on ECHELON was published in 1988. (11) In addition, besides the revelations from Australia, the Scientific and Technical Options Assessment program office (STOA) of the European Parliament commissioned two reports which describe ECHELON's activities. These reports unearthed a startling amount of evidence, which suggests that Echelon's powers may have been underestimated. The first report, entitled "An Appraisal of Technologies of Political Control," suggested that ECHELON primarily targeted civilians.

This report found that:

The ECHELON system forms part of the UKUSA system but unlike many of the electronic spy systems developed during the cold war, ECHELON is designed for primarily non-military targets: governments, organisations and businesses in virtually every country. The ECHELON system works by indiscriminately intercepting very large quantities of communications and then siphoning out what is valuable using artificial intelligence aids like Memex to find key words. Five nations share the results with the US as the senior partner under the UKUSA agreement of 1947, Britain, Canada, New Zealand and Australia are very much acting as subordinate information servicers.

Each of the five centres supply "dictionaries" to the other four of keywords, phrases, people and places to "tag" and the tagged intercept is forwarded straight to the requesting country. Whilst there is much information gathered about potential terrorists, there is a lot of economic intelligence, notably intensive monitoring of all the countries participating in the GATT negotiations. But Hager found that by far the main priorities of this system continued to be military and political intelligence applicable to their wider interests. Hager quotes from a "highly placed intelligence operatives" who spoke to the Observer in London. "We feel we can no longer remain silent regarding that which we regard to be gross malpractice and negligence within the establishment in which we operate." They gave as examples. GCHQ interception of three charities, including Amnesty International and Christian Aid. "At any time GCHQ is able to home in on their communications for a routine target request," the GCHQ source said. In the case of phone taps the procedure is known as Mantis. With telexes its called Mayfly. By keying in a code relating to third world aid, the source was able to demonstrate telex "fixes" on the three organisations. With no system of accountability, it is difficult to discover what criteria determine who is not a target. (12)

A more recent report, known as Interception Capabilities 2000, describes ECHELON capabilities in even more elaborate detail. (13) The release of the report sparked accusations from the French government that the United States was using ECHELON to give American companies an advantage over rival firms. (14) In response, R. James Woolsey, the former head of the US Central Intelligence Agency (CIA), charged that the French government was using bribes to get lucrative deals around the world, and that US surveillance networks were used simply to level the playing field. (15) However, experts have pointed out that Woolsey missed several key points. For example, Woolsey neglected to mention alleged instances of economic espionage (cited in Intelligence Capabilities 2000) that did not involve bribery. Furthermore, many observers expressed alarm with Woolsey's apparent assertion that isolated incidents of bribery could justify the wholesale interception of the world's communications. (16)

The European Parliament formed a temporary Committee of Enquiry to investigate ECHELON abuses. (17) In May 2001, members of this committee visited the United States in an attempt to discover more details about ECHELON. However, officials from both the NSA and the US Central Intelligence Agency (CIA) canceled meetings that they had previously scheduled with the European panel. The committee's chairman, Carlos Coelho, said that his group was "very disappointed" with the apparent rebuffs; in protest, the Parliamentary representatives returned home a day early. (18)

Afterwards, the committee published a report stating that ECHELON does indeed exist and that individuals should strongly consider encrypting their emails and other Internet messages. (19) However, the panel was unable to confirm suspicions that ECHELON is used to conduct industrial espionage, due to a lack of evidence. (20) Ironically, the report also mentioned the idea that European government agents should be allowed greater powers to decrypt electronic communications, which was criticized by some observers (including several members of the committee) as giving further support to Europe's own ECHELON-type system. (21) The European Parliament approved the report, but despite the apparent need for further investigation, the committee was disbanded. (22) Nevertheless, the European Commission plans to draft a "roadmap" for data protection that will address many of the concerns aired by the EP panel. (23)

Meanwhile, after years of denying the existence of ECHELON, the Dutch government issued a letter that stated: "Although the Dutch government does not have official confirmation of the existence of Echelon by the governments related to this system, it thinks it is plausible this network exists. The government believes not only the governments associated with Echelon are able to intercept communication systems, but that it is an activity of the investigative authorities and intelligence services of many countries with governments of different political signature." (24)These revelations worried Dutch legislators, who had convened a special hearing on the subject. During the hearing, several experts argued that there must be tougher oversight of government surveillance activities. There was also considerable criticism of Dutch government efforts to protect individual privacy, particularly the fact that no information had been made available relating to Dutch intelligence service's investigation of possible ECHELON abuses.(25)

In addition, an Italian government official has begun to investigate Echelon's intelligence-gathering efforts, based on the belief that the organization may be spying on European citizens in violation of Italian or international law. (26)

Events in the United States have also indicated that the "wall of silence" might not last much longer. Exercising their Constitutionally created oversight authority, members of the House Select Committee on Intelligence started asking questions about the legal basis for NSA's ECHELON activities. In particular, the Committee wanted to know if the communications of Americans were being intercepted and under what authority, since US law severely limits the ability of the intelligence agencies to engage in domestic surveillance. When asked about its legal authority, NSA invoked the attorney-client privilege and refused to disclose the legal standards by which ECHELON might have conducted its activities. (27)

President Clinton then signed into law a funding bill which required the NSA to report on the legal basis for ECHELON and similar activities. (28) However, the subsequent report (entitled Legal Standards for the Intelligence Community in Conducting Electronic Surveillance) gave few details about Echelon's operations and legality. (29)

However, during these proceedings, Rep. Bob Barr (R-GA), who has taken the lead in Congressional efforts to ferret out the truth about ECHELON, stated that he had arranged for the House Government Reform and Oversight Committee to hold its own oversight hearings.(30)

Finally, the Electronic Privacy Information Center has sued the US Government, hoping to obtain documents which would describe the legal standards by which ECHELON operates.(31)

Q - What is being done with the information that ECHELON collects?

The original purpose of ECHELON was to protect national security. That purpose continues today. For example, we know that ECHELON is gathering information on North Korea. Sources from Australia's DSD have disclosed this much because Australian officials help operate the facilities there which scan through transmissions, looking for pertinent material. (32) Similarly, the Spanish government has apparently signed a deal with the United States to receive information collected using ECHELON. The consummation of this agreement was confirmed by Spanish Foreign Minister Josep Pique, who tried to justify this arrangement on security grounds. (33)

However, national security is not Echelon's only concern. Reports have indicated that industrial espionage has become a part of Echelon's activities. While present information seems to suggest that only high-ranking government officials have direct control over Echelon's tasks, the information that is gained may be passed along at the discretion of these very same officials. As a result, much of this information has been given to American companies, in apparent attempts to give these companies an edge over their less knowledgeable counterparts. (34)

In addition, there are concerns that Echelon's actions may be used to stifle political dissent. Many of these concerns were voiced in a report commissioned by the European Parliament. What is more, there are no known safeguards to prevent such abuses of power. (35)

Q - Is there any evidence that ECHELON is doing anything improper or illegal with the spying resources at its disposal?

ECHELON is a highly classified operation, which is conducted with little or no oversight by national parliaments or courts. Most of what is known comes from whistleblowers and classified documents. The simple truth is that there is no way to know precisely what ECHELON is being used for.

But there is evidence, much of which is circumstantial, that ECHELON (along with its British counterpart) has been engaged in significant invasions of privacy. These alleged violations include secret surveillance of political organizations, such as Amnesty International. (36) It has also been reported that ECHELON has engaged in industrial espionage on various private companies such as Airbus Industries and Panavia, then has passed along the information to their American competitors. (37) It is unclear just how far Echelon's activities have harmed private individuals.

However, the most sensational revelation was that Diana, Princess of Wales may have come under ECHELON surveillance before she died. As reported in the Washington Post, the NSA admitted that they possessed files on the Princess, partly composed of intercepted phone conversations. While one official from the NSA claimed that the Princess was never a direct target, this disclosure seems to indicates the intrusive, yet surreptitious manner by which ECHELON operates. (38)

What is even more disquieting is that, if these allegations are proven to be true, the NSA and its compatriot organizations may have circumvented countless laws in numerous countries. Many nations have laws in place to prevent such invasions of privacy. However, there are suspicions that ECHELON has engaged in subterfuge to avoid these legal restrictions. For example, it is rumored that nations would not use their own agents to spy on their own citizens, but assign the task to agents from other countries. (39) In addition, as mentioned earlier, it is unclear just what legal standards ECHELON follows, if any actually exist. Thus, it is difficult to say what could prevent ECHELON from abusing its remarkable capabilities.

Q - Is everyone else doing what ECHELON does?

Maybe not everyone else, but there are plenty of other countries that engage in the type of intelligence gathering that ECHELON performs. These countries apparently include Russia, France, Israel, India, Pakistan and many others. (40) Indeed, the excesses of these ECHELON-like operations are rumored to be similar in form to their American equivalents, including digging up information for private companies to give them a commercial advantage.

However, it is also known that ECHELON system is the largest of its kind. What is more, its considerable powers are enhanced through the efforts of America's allies, including the United Kingdom, Canada, Australia, and New Zealand. Other countries don't have the resources to engage in the massive garnering of information that the United States is carrying out.


Notes

1. Development of Surveillance Technology and Risk of Abuse of Economic Information (An appraisal of technologies for political control), Part 4/4: The state of the art in Communications Intelligence (COMINT) of automated processing for intelligence purposes of intercepted broadband multi-language leased or common carrier systems, and its applicability to COMINT targeting and selection, including speech recognition, Ch. 1, para. 5, PE 168.184 / Part 4/4 (April 1999). See Duncan Campbell, Interception Capabilities 2000 (April 1999) (http://www.iptvreports.mcmail.com/stoa_cover.htm).

2. Kevin Poulsen, Echelon Revealed, ZDTV (June 9, 1999).

3. Greg Lindsay, The Government Is Reading Your E-Mail, TIME DIGITAL DAILY (June 24, 1999).

4. PE 168.184 / Part 4/4, supra note 1, Ch. 2, para. 32-34, 45-46.

5. Id. Ch. 2, para. 42.

6. Id. Ch. 2, para. 60.

7. Id. Ch. 2, para. 50.

8. Id. Ch. 2, para. 62-63.

9. An Appraisal of Technologies for Political Control, at 20, PE 166.499 (January 6, 1998). See Steve Wright, An Appraisal of Technologies for Political Control (January 6, 1998) (http://cryptome.org/stoa-atpc.htm).

10.Letter from Martin Brady, Director, Defence Signals Directorate, to Ross Coulhart, Reporter, Nine Network Australia 2 (Mar. 16, 1999) (on file with the author); see also Calls for inquiry into spy bases, ONE NEWS New Zealand (Dec. 28, 1999).

11. Duncan Campbell, Somebody's listening, NEW STATESMAN, 12 August 1988, Cover, pages 10-12. See Duncan Campbell, ECHELON: NSA's Global Electronic Interception, (last visited October 12, 1999) (http://jya.com/echelon-dc.htm).>

12. PE 166.499, supra note 9, at 19-20.

13. PE 168.184 / Part 4/4, supra note 1.

14. David Ruppe, Snooping on Friends?, ABCNews.com (US) (Feb. 25, 2000) (http://abcnews.go.com/sections/world/dailynews/echelon000224.html).

15. R. James Woolsey, Why We Spy on Our Allies, WALL ST. J., March 17, 2000. See also CRYPTOME, Ex-CIA Head: Why We Spy on Our Allies (last visited April 11, 2000) (http://cryptome.org/echelon-cia2.htm).

16. Letter from Duncan Campbell to the Wall Street Journal (March 20, 2000) (on file with the author). See also Kevin Poulsen, Echelon Reporter answers Ex-CIA Chief, SecurityFocus.com (March 23, 2000) (http://www.securityfocus.com/news/6).>

17. Duncan Campbell, Flaw in Human Rights Uncovered, HEISE TELEPOLIS, April 8, 2000. See also HEISE ONLINE, Flaw in Human Rights Uncovered (April 8, 2000) (http://www.heise.de/tp/english/inhalt/co/6724/1.html).

18.Angus Roxburgh, EU investigators 'snubbed' in US, BBC News, May 11, 2001 (http://news.bbc.co.uk/hi/english/world/europe/newsid_1325000/1325186.stm).

19.Report on the existence of a global system for intercepting private and commercial communications (ECHELON interception system), PE 305.391 (July 11, 2001) (available in PDF or Word format at http://www2.europarl.eu.int). Draft Report on the existence of a global system for intercepting private and commercial communications (ECHELON interception system), PE 305.391 (May 18 2001).(http://www.europarl.eu.int/tempcom/echelon/pdf/prechelon_en.pdf or http://cryptome.org/echelon-ep.htm). -->

20. Id.; see also E-mail users warned over spy network, BBC News, May 29, 2001 (http://news.bbc.co.uk/hi/english/world/europe/newsid_1357000/1357264.stm).

21. Steve Kettman, Echelon Furor Ends in a Whimper, Wired News, July 3, 2001 (http://www.wired.com/news/print/0,1294,44984,00.html).

22. European Parliament resolution on the existence of a global system for the interception of private and commercial communications (ECHELON interception system) (2001/2098(INI)), A5-0264/2001, PE 305.391/DEF (Sept. 5, 2001) (available at http://www3.europarl.eu.int); Christiane Schulzki-Haddouti, Europa-Parlament verabsciedet Echelon-Bericht, Heise Telepolis, Sept. 5, 2001 (available at http://www.heise.de/tp/); Steve Kettman, Echelon Panel Calls It a Day, Wired News, June 21, 2001 (http://www.wired.com/news/print/0,1294,44721,00.html).

23. European Commission member Erkki Liikanen, Speech regarding European Parliament motion for a resolution on the Echelon interception system (Sept. 5, 2001) (transcript available at http://europa.eu.int).

24. Jelle van Buuren, Dutch Government Says Echelon Exists, Heise Telepolis, Jan. 20, 2001 (available at http://www.heise.de/tp/).

25. Jelle van Buuren, Hearing On Echelon In Dutch Parliament, Heise Telepolis, Jan. 23, 2001 (available at http://www.heise.de/tp/).

26. Nicholas Rufford, Spy Station F83, SUNDAY TIMES (London), May 31, 1998. See Nicholas Rufford, Spy Station F83 (May 31, 1998) (http://www.sunday-times.co.uk/news/pages/sti/98/05/31/stifocnws01003.html?999).

27. H. Rep. No. 106-130 (1999). See Intelligence Authorization Act for Fiscal Year 2000, Additional Views of Chairman Porter J. Goss (http://www.echelonwatch.org/goss.htm).

28. Intelligence Authorization Act for Fiscal Year 2000, Pub. L. 106-120, Section 309, 113 Stat. 1605, 1613 (1999). See H.R. 1555 Intelligence Authorization Act for Fiscal Year 2000 (Enrolled Bill (Sent to President)) http://www.echelonwatch.org/hr1555c.htm).

29. UNITED STATES NATIONAL SECURITY AGENCY, LEGAL STANDARDS FOR THE INTELLIGENCE COMMUNITY IN CONDUCTING ELECTRONIC SURVEILLANCE (2000) (http://www.fas.org/irp/nsa/standards.html).>

30. House Committee to Hold Privacy Hearings, (August 16, 1999) (http://www.house.gov/barr/p_081699.html).>

31. ELECTRONIC PRIVACY INFORMATION CENTER, PRESS RELEASE: LAWSUIT SEEKS MEMOS ON SURVEILLANCE OF AMERICANS; EPIC LAUNCHES STUDY OF NSA INTERCEPTION ACTIVITIES (1999). See also Electronic Privacy Information Center, EPIC Sues for NSA Surveillance Memos (last visited December 17, 1999) (http://www.epic.org/open_gov/foia/nsa_suit_12_99.html).>

32. Ross Coulhart, Echelon System: FAQs and website links, (May 23, 1999).

33. Isambard Wilkinson, US wins Spain's favour with offer to share spy network material, Sydney Morning Herald, June 18, 2001 (http://www.smh.com.au/news/0106/18/text/world11.html).

34. PE 168.184 / Part 4/4, supra note 1, Ch. 5, para. 101-103.

35. PE 166.499, supra note 9, at 20.

36. Id.

37. PE 168.184 / Part 4/4, supra note 1, Ch. 5, para. 101-102; Brian Dooks, EU vice-president to claim US site spies on European business, YORKSHIRE POST, Jan. 30, 2002 (available at http://yorkshirepost.co.uk).

38. Vernon Loeb, NSA Admits to Spying on Princess Diana, WASHINGTON POST, December 12, 1998, at A13. See Vernon Loeb, NSA Admits to Spying on Princess Diana, WASHINGTON POST, A13 (December 12, 1998) (http://www.washingtonpost.com/wp-srv/national/daily/dec98/diana12.htm).

39. Ross Coulhart, Big Brother is listening, (May 23, 1999).

40. PE 168.184 / Part 4/4, supra note 1, Ch. 1, para. 7.