Spy, or pay up: FBI-backed bill would fine US firms for refusing wiretaps
RT | April 29, 2013
A US government task force is drafting FBI-backed legislation that would penalize companies like Google and Facebook for refusing to comply with wiretap orders, media report.
In the new legislation being drafted by US law enforcement officials, refusal to cooperate with the FBI could cost a tech company tens of thousands of dollars in fines, the Washington Post quoted anonymous sources as saying.
The fined company would be given 90 days to comply with wiretap orders. If the organization is unable or unwilling to turn over the communications requested by the wiretap, the penalty sum would double every day.
“We don’t have the ability to go to court and say, ‘We need a court order to effectuate the intercept.’ Other countries have that. Most people assume that’s what you’re getting when you go to a court,” FBI general counsel Andrew Weissmann told the Washington Post.
If passed in Congress and signed by President Obama, the bill could become a provision of the 1968 Wiretap Act, which require companies to develop mechanisms for obtaining information requested by government investigators.
However, many companies maintain that their resistance to this and similar measures has nothing to do with an unwillingness to help investigators. Google began encrypting its email service following a major hacking attack in 2010; developing wiretap technology could make it and other companies vulnerable, creating “a way for someone to silently go in and activate a wiretap,” said Susan Landau, a former engineer at Sun Microsystems.
The proposed expansion of wiretaps into the digital frontier is the latest in a series of US government efforts to monitor online communications.
The recent Boston Marathon bombings were used by some members of Congress as a reason to push through the highly controversial Cyber Intelligence Sharing and Protect Act (CISPA), which was passed by the lower house. If CISPA is signed into law, telecommunication companies will be encouraged to share Internet data with the Departments of Homeland Security and Justice concerning national security purposes.
Tech companies, including giants like Facebook and Microsoft, have objected fiercely to the bill, citing customers’ privacy concerns. The bill is currently shelved in the Senate following President Obama’s threat to veto CISPA due to a lack of personal privacy provisions.
Earlier in April, the FBI requested an additional $41 million from the federal government for the recording and analysis of Internet communication.
The Electronic Privacy Information Center also recently obtained over 1,000 pages of documents proving that the Pentagon has secretly eavesdropped on Internet traffic for several years.
“Senior Obama administration officials have secretly authorized the interception of communications carried on portions of networks operated by AT&T and other Internet service providers, a practice that might otherwise be illegal under federal wiretapping laws,” CNET reporter Declan McCullagh wrote.
Related article
- Obama administration bypasses CISPA by secretly allowing Internet surveillance (alethonews.wordpress.com)
Obama Expands Wiretap Authority to Cover Finance, Healthcare and Other Industries
By Matt Bewig | AllGov | April 29, 2013
When one conspires to violate federal law, it helps to have a government agency or two as one’s co-conspirators when law enforcement comes poking around, as telecom giant AT&T and others learned recently when the Defense Department (DOD) and the Department of Homeland Security (DHS) successfully pressured the Justice Department (DOJ) to agree secretly not to prosecute blatantly illegal wiretaps conducted by AT&T and other Internet service providers at the request of the agencies.
Although some press reports have termed this an authorization of activity that would otherwise be illegal, this is a misnomer. The executive branch lacks the power to retroactively declare criminal conduct to be lawful, but it can choose to ignore it by waiving prosecution pursuant to “prosecutorial discretion.”
Although the secret DOJ prosecution waiver initially applied to a cyber-security pilot project—the DIB Cyber Pilot—that allowed the military to monitor defense contractors’ Internet links, the program has since been renamed Enhanced Cybersecurity Services and is being expanded by President Obama to allow the government to snoop on the private networks of all companies operating in “critical infrastructure sectors,” including energy, healthcare, and finance starting June 12.
“The Justice Department is helping private companies evade federal wiretap laws,” warned Marc Rotenberg, executive director of the Electronic Privacy Information Center, which obtained more than 1,000 pages of government documents relating to the issue via a Freedom of Information Act request. “Alarm bells should be going off.”
The wiretap law referenced by Rotenberg is the Wiretap Act, codified at 18 USC 2511, which makes it a crime for a network operator to intercept communications carried on its networks unless the monitoring is a “necessary incident” to providing the service or it occurs with a user’s “lawful consent.” Since neither of those exceptions applied, DOD and DHS pressed DOJ attorneys to agree not to prosecute what were clearly prosecutable offenses by issuing an unknown number of “2511 letters,” which are normally used by DOJ to tell a company that its conduct fit within one of the lawful exceptions to the Act.
The purported “retroactive authorization” is similar to the “retroactive immunity” given the telecoms by Congress for their participation in illegal wiretapping and eavesdropping between 2001 and 2006. Likewise, former DHS official Paul Rosenzweig compared the case of the “2511 letters” to the CIA asking the Justice Department for legal memos justifying torture a decade ago. “If you think of it poorly, it’s a CYA [“cover your ass] function,” Rosenzweig says. “If you think well of it, it’s an effort to secure advance authorization for an action that may not be clearly legal.” Or may be clearly illegal.
In any event, Obama’s own expansion by mid-June of the snooping “to all critical infrastructure sectors,” defined as companies providing services whose disruption would harm national economic security or “national public health or safety” will proceed.
Related articles
- Obama administration bypasses CISPA by secretly allowing Internet surveillance (alethonews.wordpress.com)
- To Ease Internet Snooping, Feds Promise To Ignore Privacy Violations (reason.com)
EFF Fights to Protect Electronic Reserves at College Libraries
By Corynne McSherry | EFF | April 25, 2013
When college professors want students to read a small part of a book, they put that book on reserve at the library, so everyone can get access to the bit of information they need without having to buy the entire expensive work. Advances in technology have made this even easier for students: librarians have created electronic reserves, allowing online access to a digital version of the excerpt. But the publishing world has come down hard on these electronic reserves in a lawsuit aimed at Georgia State University (GSU), insisting that libraries must pay fees for excerpts they make available digitally to students. In an amicus brief filed on behalf of several national library associations today, EFF argues that electronic reserves must be protected to serve the public interest and preserve librarians’ and students’ fair-use rights.
This case started back in 2008, when the Association of American Publishers (AAP) recruited three plaintiffs to sue GSU for copyright infringement in their electronic reserves. GSU promptly updated its procedures to conform to fair use guidelines the AAP itself had helped draft for other universities. But instead of declaring victory, the plaintiffs continued to pursue this case, even taking it up on appeal when their claims were rejected by a federal district court.
In the amicus brief filed today, EFF urges the appeals court to see what the district court saw: the vast majority of uses at issue were protected fair uses. Moreover, as a practical matter, the licensing market the publishers say they want to create for e-reserves will never emerge—not least because libraries can’t afford to participate in it. Even assuming that libraries could pay such fees, requiring this would thwart the purpose of copyright by undermining the overall market for scholarship. Given libraries’ stagnant or shrinking budgets, any new spending for licenses must be reallocated from existing expenditures, and the most likely source of reallocated funds is the budget for collections. An excerpt license requirement thus will harm the market for new scholarly works, as the works assigned for student reading are likely to be more established pieces written by well-known academics. Libraries’ total investment in scholarship will be the same but resources will be diverted away from new works to redundant payments for existing ones, in direct contradiction of copyright’s purpose of “promot[ing] progress.”
A win for the publishers here would be a Pyrrhic victory at best for them, and a significant loss for the public interest. We hope the appellate court agrees that copyright law does not require forcing libraries to make reading a handful of pages either extraordinarily expensive or inordinately difficult for college students.
Files
georgiastateamicibriefconformed.pdf
Related articles
- EFF To Represent Bloggers Against Copyright Troll (eff.org)
- LCA Files Brief on Behalf of Georgia State (districtdispatch.org)
Obama administration bypasses CISPA by secretly allowing Internet surveillance
RT | April 24, 2013
Scared that CISPA might pass? The federal government is already using a secretive cybersecurity program to monitor online traffic and enforce CISPA-like data sharing between Internet service providers and the Department of Defense.
The Electronic Privacy Information Center has obtained over 1,000 pages of documents pertaining to the United States government’s use of a cybersecurity program after filing a Freedom of Information Act request, and CNET reporter Declan McCullagh says those pages show how the Pentagon has secretly helped push for increased Internet surveillance.
“Senior Obama administration officials have secretly authorized the interception of communications carried on portions of networks operated by AT&T and other Internet service providers, a practice that might otherwise be illegal under federal wiretapping laws,” McCullagh writes.
That practice, McCullagh recalls, was first revealed when Deputy Secretary of Defense William Lynn disclosed the existence of the Defense Industrial Base (DIB) Cyber Pilot in June 2011. At the time, the Pentagon said the program would allow the government to help the defense industry safeguard the information on their computer systems by sharing classified threat information between the Department of Defense, the Department of Homeland Security and the Internet service providers (ISP) that keep government contractors online.
“Our defense industrial base is critical to our military effectiveness. Their networks hold valuable information about our weapons systems and their capabilities,” Lynn said. “The theft of design data and engineering information from within these networks greatly undermines the technological edge we hold over potential adversaries.”
Just last week the US House of Representatives voted in favor of the Cyber Intelligence Sharing and Protection Act, or CISPA — a legislation that would allow ISPs and private Internet companies across the country like Facebook and Google to share similar threat data with the federal government without being held liable for violating their customers’ privacy. As it turns out, however, the DIB Cyber Pilot has expanded exponentially in recent months, suggesting that a significant chunk of Internet traffic is already subjected to governmental monitoring.
In May 2012 less than a year after the pilot was first unveiled, the Defense Department announced the expansion of the DIB program. Then this past January, McCullagh says it was renamed the Enhanced Cybersecurity Services (ECS) and opened up to a larger number of companies — not just DoD contractors. An executive order signed by US President Barack Obama earlier this year will let all critical infrastructure companies to sign-on to ECS this June, likely in turn bringing on board entities in energy, healthcare, communication and finance.
Although the 1,000-plus pages obtained in the FOIA request haven’t been posted in full on the Web just yet, a sampling of that trove published by EPIC on Wednesday starts to show just exactly how severe the Pentagon’s efforts to eavesdrop on Web traffic has been.
In one document, a December 2011 slideshow on the legal policies and practices regarding the monitoring of Web traffic on DIB-linked systems, the Pentagon instructs the administrators of those third-party computer networks on how to implement the program and, as a result, erode their customers’ expectation of privacy.
In one slide, the Pentagon explains to ISPs and other system administrators how to be clear in letting their customers know that their traffic was being fed to the government. Key elements to keep in mind, wrote the Defense Department, was that DIB “expressly covers monitoring of data and communications in transit rather than just accessing data at rest.”
“[T]hat information transiting or stored on the system may be disclosed for any purpose, including to the government,” it continued. Companies participating in the pilot program were told to let users know that monitoring would exist “for any purpose,” and that users have no expectation of privacy regarding communications or data stored on the system.
According to the 2011 press released on the DIB Cyber Pilot, “the government will not monitor, intercept or store any private-sector communications through the program.” In a privacy impact assessment of the ECS program that was published in January by the DHS though, it’s revealed that not only is information monitored, but among the data collected by investigators could be personally identifiable information, including the header info from suspicious emails. That would mean the government sees and stores who you communicate with and what kind of subject lines are used during correspondence.
The DHS says that personally identifiable information could be retained if “analytically relevant to understanding the cyber threat” in question.
Meanwhile, the lawmakers in Congress that overwhelmingly approved CISPA just last week could arguably use a refresher in what constitutes a cyberthreat. Rep. Michael McCaul (R-Texas) told his colleagues on the Hill that “Recent events in Boston demonstrate that we have to come together as Republicans and Democrats to get this done,” and Rep. Dan Maffei (D-New York) made unfounded claims during Thursday’s debate that the whistleblowing website WikiLeaks is pursuing efforts to “hack into our nation’s power grid.”
Should CISPA be signed into law, telecommunication companies will be encouraged to share Internet data with the DHS and Department of Justice for so-called national security purposes. But even if the president pursues a veto as his advisers have suggested, McCullagh says few will be safe from this secretive cybersecurity operation already in place.
The tome of FOIA pages, McCullagh says, shows that the Justice Department has actively assisted telecoms as of late by letting them off the hook for Wiretap Act violations. Since the sharing of data between ISPs and the government under the DIB program and now ECS violates federal statute, the Justice Department has reportedly issued an undeterminable number of “2511 letters” to telecoms: essentially written approval to ignore provisions of the Wiretap Act in exchange for immunity.
“The Justice Department is helping private companies evade federal wiretap laws,” EPIC Executive Director Marc Rotenberg tells CNET. “Alarm bells should be going off.”
In an internal Justice Department email cited by McCullagh, Associate Deputy Attorney General James Baker is alleged to write that ISPs will likely request 2511 letters and the ECS-participating companies “would be required to change their banners to reference government monitoring.”
“These agencies are clearly seeking authority to receive a large amount of information, including personal information, from private Internet networks,” EPIC staff attorney Amie Stepanovich adds to CNET. “If this program was broadly deployed, it would raise serious questions about government cybersecurity practices.”
Related articles
- To Ease Internet Snooping, Feds Promise To Ignore Privacy Violations (reason.com)
- Congressman evokes Boston bombings as reason to pass CISPA (rt.com)
- U.S. gives big, secret push to Internet surveillance (philosophers-stone.co.uk)
Britons’ phone calls spied on routinely by UK police: Report
Press TV – April 20, 2013
British police forces are making as many as 250,000 requests to snoop on people’s email and phone call details every year, a new report reveals.
According to a survey, which was carried out by civil liberties and privacy campaign group Big Brother Watch, 25 police forces across Britain made 506,720 requests for people’s “communications data” over the past three years, The Telegraph reported.
The survey released under the freedom of information laws found that the number of requests for Britons’ phone or email records has risen from 158,677 in 2009-10 to 178,985 in 2011-12. However, the figure could be increased to up to 250,000 including estimates for the forces that failed to reply to the research.
This comes as the UK government is seeking more snooping powers through the controversial Communications Data Bill, which is due to be published in the summer.
The draft bill is dubbed as the Snooper’s Charter, because it is considered as a significant threat to British citizens’ privacy.
The measures mark a serious increase in the powers the British government has to order any communications provider to collect, store and provide access to information about emails, online conversations and texts.
Former British shadow home secretary David Davis said, “It is frankly not good enough that the government is considering introducing a snoopers’ charter without even being able to tell us what they have used communications data for in the past.”
Israeli police head to US to aid in Boston Marathon bombing investigation
RT | April 17, 2013
The investigation into Monday’s deadly bombing at the Boston Marathon has officially gone international: law enforcement officials from Israel have been sent to the United States to assist in the probe.
Israel Police Chief Yohanan Danino says he has dispatched officials to Boston, Massachusetts, where they will meet with Federal Bureau of Investigation agents and other authorities, the Times of Israel reports.
Citing an earlier report published by the newspaper Maariv, Times of Israel writes that Danino has dispatched police officers to participate in discussions that “will center on the Boston Marathon bombings and deepening professional cooperation between the law enforcement agencies of both countries.”
The paper reports that Israeli law enforcement planned the trip before the deadly pair of bombings on Monday that has so far claimed three lives, but the discussions will now shift focus in order to see how help from abroad can expand the investigation.
In an address made Tuesday, Israel President Shimon Peres said that tragedies such as this week’s incident in Boston, sadly, bring people together from across the world.
“When it comes to events like this, all of us are one family. We feel a part of the people who paid such a high price. God bless them,” Peres said. “Today the real problem is terror, and terror is not an extension of policy: Their policy is terror, their policy is to threaten. Terrorists divide people, they kill innocent people.”
Around 20 hours after two bombs detonated near the finish line of the annual race, United States President Barack Obama went on record to condemn the tragedy as a terrorist attack.
“This was a heinous and cowardly act,” said Obama from the White House, “and given what we now know the FBI is investigating it as an act of terrorism.”
But even as officials come to assist from as far away as Israel, authorities are still in the dark as far as finding any leads in the case. Pres. Obama has directed the FBI and US Department of Homeland Security to assist in the investigation, but no agencies have identified suspects or motives at this time.
Pres. Obama has also said that his administration has been directed to implement “appropriate security measures to protect the American people,” but details as to what that could mean remain scarce. Meanwhile, at least one leading lawmaker is asking for the US to respond to the terrorist attack by increasing the scope of the ever-expanding surveillance program already growing across the United States.
“I do think we need more cameras,” Rep. Peter King (R-New York) told MSNBC after Monday’s attacks. “We have to stay ahead of the terrorists and I do know in New York, the Manhattan Security Initiative, which is based on cameras, the outstanding work that results from that. So yes, I do favor more cameras. They’re a great law enforcement device. And again, it keeps us ahead of the terrorists, who are constantly trying to kill us.”
New York Mayor Michael Bloomberg has also confirmed that he has dispatched law enforcement officers from the Big Apple to assist in the investigation by meeting with agents at a Boston fusion center, one of the DHS-funded data facilities that collects surveillance camera footage and other evidence in order to analyze events like Monday’s attack.
“We are certainly engaged in the information flow with the FBI through our Joint Terrorism Task Force. We have two New York City police officers, police sergeants, who are in the Boston Regional Intelligence Center,” Bloomberg said on Tuesday. “They’re up there, they’ve been up there since last evening.”
But in a study conducted last year by the Senate’s bipartisan Permanent Subcommittee on Investigations, lawmakers found that those fusion centers have been more or less unhelpful in assisting with terrorism probes.
The Department of Homeland Security’s work with state and local fusion centers, the subcommittee wrote, “has not produced useful intelligence to support federal counterterrorism efforts.” Instead, they added, so-called “intelligence” shared between facilities consisted of tidbits of shoddy quality that was often outdated and “sometimes endangering [to] citizen‘s civil liberties and Privacy Act protections.”
“More often than not,” the panel added, information collected and shared at DHS fusion centers was “unrelated to terrorism.”
Related video
Related articles
EPIC Appeals FOIA Decisions Concerning Body Scanner Information
Electronic Privacy Information Center – April 16, 2013
EPIC has filed appeals in two Freedom of Information Act cases seeking documents related to airport body scanners from the Department of Homeland Security and the Transportation Security Administration.
EPIC filed FOIA requests with the agencies seeking records related to radiation risks from body scanners and the threat detection software the machines use.
The TSA is currently developing formal rules for the use of body scanners in response to a court order in one of EPIC’s previous cases.
Body scanners allow routine digital strip searches of individuals who are not suspected of any crime.
For more information, see EPIC: Radiation Risks lawsuit and EPIC: ATR lawsuit, and EPIC: Suspension of Body Scanner Program.
Related articles
- Judge: DHS Must Release Body Scanner Safety Reports (reason.com)
- Letter From a Screener: So We Found a Suicide Bomber With The Full Body Scanner: Now What? (takingsenseaway.wordpress.com)
IRS Says It Will Respect 4th Amendment With Regard to Email, But Questions Remain
By Nathan Freed Wessler | ACLU | April 16, 2013
With tax day behind us, taxpayers may soon have something else to celebrate from the IRS. In testimony before the Senate Finance Committee today, IRS Acting Commissioner Steven Miller was questioned aggressively about documents released by the ACLU last week that indicate that the IRS does not think it needs a warrant to read all emails and other electronic communications during criminal investigations. Under pressure from senators, Miller agreed to update IRS policy documents within 30 days to state that a warrant is required for access to all emails, regardless of their age.
Two senators from opposite sides of the aisle, Senator Grassley (R-IA) and Senator Wyden (D-OR), pressed Miller about whether the IRS has sought or obtained emails without a warrant since a federal appeals court ruled in 2010 that a warrant is required for all emails. (You can watch the hearing here. Sen. Grassley’s questions start at 1:25:00 and Sen. Wyden’s questions start at 1:31:10.) They asked why the IRS seems to be ignoring that 2010 decision—United States v. Warshak—in most of the country, and advising its criminal investigative agents that emails stored on a server for more than 180 days can be obtained without a warrant. Surprisingly, Miller answered that the IRS follows Warshak across the country. That’s not what internal IRS documents and its public policy manual show, but if true it is welcome news. Importantly, Miller committed to clarify written IRS policy within 30 days to state that a warrant is always required.
Miller’s testimony leaves several important questions unanswered, however:
- Although Miller stated that the IRS Criminal Investigation unit obtains warrants for all emails, he did not discuss other forms of electronic communication such as text messages, instant messages, and direct messages on social media. Under the Fourth Amendment, a warrant should be required for those private communications as well.
- Miller stated that, to his knowledge, the IRS has not obtained electronic communications without a warrant in the past. But an internal IRS Chief Counsel Advice memorandum from 2011 reveals that, months after Warshak, IRS investigative agents requested emails from an internet service provider without a warrant at least once. The IRS should explain when it started following Warshak nationally, and whether it has sought or obtained emails without a warrant in the past.
We applaud Senators Grassley and Wyden for quickly taking up this important issue and getting an answer from the IRS, less than a week after the ACLU released the IRS documents. But while the IRS’s apparent change of policy is a step in the right direction, there is more for Congress to do. The current IRS policy manual relies on the outdated Electronic Communications Privacy Act (ECPA), which only requires a warrant for some emails and other electronic communications. In order to uniformly protect the privacy of Americans’ private communications, lawmakers must update ECPA to require a warrant for the contents of all electronic communications, regardless of age or other factors. Strong reform legislation has been introduced by a bipartisan group of sponsors, and is starting to make its way through the legislative process. Follow this link to urge Congress to modernize our electronic privacy law and close the loophole that’s letting the government access email and other electronic communications without a warrant.
Related article
- New Documents Suggest IRS Reads Emails Without a Warrant (alethonews.wordpress.com)
