Showing posts with label June 07. Show all posts
Showing posts with label June 07. Show all posts

Tuesday, June 7, 2016

Why Is the Government Poison-Pilling ECPA Reform?

Back in 2009, the Obama Administration had Jeff Sessions gut an effort by Dianne Feinstein to gut an effort by Patrick Leahy to gut an effort by Russ Feingold to halt the phone and Internet dragnet programs (as well as, probably, some Post Cut Through Dialed Digit collections we don’t yet know about).

See what Jeff Sesssions–I mean Barack Obama–did in complete secrecy and behind the cover of Jeff Sessions’ skirts the other night?

They absolutely gutted the minimization procedures tied to pen registers! Pen registers are almost certainly the means by which the government is conducting the data mining of American people (using the meta-data from their calls and emails to decide whether to tap them fully). And Jeff Sesssions–I mean Barack Obama–simply gutted any requirement that the government get rid of all this meta-data when they’re done with it. They gutted any prohibitions against sharing this information widely. In fact, they’ve specified that judges should only require minimization procedures in extraordinary circumstances. Otherwise, there is very little limiting what they can do with your data and mine once they’ve collected it. [no idea why I was spelling Sessions with 3 ses]

At each stage of this gutting process, Feingold’s effort to end bulk collection got watered down until, with Sessons’ amendments, the Internet dragnet was permitted to operate as it had been. Almost the very same time this happened, NSA’s General Counsel finally admitted that every single record the agency had collected under the dragnet program had violated the category restrictions set back in 2004. Probably 20 days later, Reggie Walton would shut down the dragnet until at least July 2010.

But before that happened, the Administration made what appears to be — now knowing all that we know now — an effort to legalize the illegal Internet dragnet that had replaced the prior illegal Internet dragnet.

I think that past history provides an instructive lens with which to review what may happen to ECPA reform on Thursday. A version of the bill, which would require the government to obtain a warrant for any data held on the cloud, passed the House unanimously. But several amendments have been added to the bill in the Senate Judiciary Committee that I think are designed to serve as poison pills to kill the bill.

The first is language that would let the FBI resume obtaining Electronic Communication Transaction Records with just a National Security Letter (similar language got added to the Intelligence Authorization; I’ll return to this issue, which I think has been curiously reported).

The second is language that would provide a vast emergency exception to the new warrant requirement, as described by Jennifer Daskal in this post.

[T]here has been relatively little attention to an equally, if not more, troubling emergency authorization provision being offered by Sen. Jeff Sessions. (An excellent post by Al Gidari and op-ed by a retired DC homicide detective are two examples to the contrary.)

The amendment would allow the government to bypass the warrant requirement in times of claimed emergency. Specifically, it would mandate that providers turn over sought-after data in response to a claimed emergency from federal, state, or local law enforcement officials. Under current law, companies are permitted, but not required, to comply with such emergency — and warrantless — requests for data.

There are two huge problems with this proposal. First, it appears to be responding to a problem that doesn’t exist. Companies already have discretion to make emergency disclosures to governmental officials, and proponents of the legislation have failed to identify a single instance in which providers failed to disclose sought-after information in response to an actual, life-threatening emergency. To the contrary, the data suggest that providers do in fact regularly cooperate in response to emergency requests. (See the discussion here.)

Second, and of particular concern, the emergency disclosure mandate operates with no judicial backstop. None. Whatsoever. This is in direct contrast with the provisions in both the Wiretap Act and Foreign Intelligence Surveillance Act (FISA) that require companies to comply with emergency disclosure orders, but then also require subsequent post-hoc review by a court. Under the Wiretap Act, an emergency order has to be followed up with an application for a court authorization within 48 hours (see 18 U.S.C. § 2518(7)). And under FISA, an emergency order has to be followed with an application to the court within 7 days (see 50 U.S.C. § 1805(5)). If the order isn’t filed or the court application denied, the collection has to cease.

The proposed Sessions amendment, by contrast, allows the government to claim emergency and compel production of emails, without any back-end review.

Albert Gidari notes that providers are already getting a ton of emergency requests, and a good number of them turn out to be unfounded.

For the last 15 years, providers have routinely assisted law enforcement in emergency cases by voluntarily disclosing stored content and transactional information as permitted by section 2702 (b)(8) and (c)(4) of Title 18. Providers recently began including data about emergency disclosures in their transparency reports and the data is illuminating. For example, for the period January to June 2015, Google reports that it received 236 requests affecting 351 user accounts and that it produced data in 69% of the cases. For July to December 2015, Microsoft reports that it received 146 requests affecting 226 users and that it produced content in 8% of the cases, transactional information in 54% of the cases and that it rejected about 20% of the requests. For the same period, Facebook reports that it received 855 requests affecting 1223 users and that it produced some data in response in 74% of the cases. Traditional residential and wireless phone companies receive orders of magnitude more emergency requests. AT&T, for example, reports receiving 56,359 requests affecting 62,829 users. Verizon reports getting approximately 50,000 requests from law enforcement each year.

[snip]

Remember, in an emergency, there is no court oversight or legal process in advance of the disclosure. For over 15 years, Congress correctly has relied on providers to make a good faith determination that there is an emergency that requires disclosure before legal process can be obtained. Providers have procedures and trained personnel to winnow out the non-emergency cases and to deal with some law enforcement agencies for whom the term “emergency” is an elastic concept and its definition expansive.

Part of the problem, and the temptation, is that there is no nunc pro tunc court order or oversight for emergency requests or disclosures. Law enforcement does not have to show a court after the fact that the disclosure was warranted at the time; indeed, no one may ever know about the request or disclosure at all if it doesn’t result in a criminal proceeding where the evidence is introduced at trial. In wiretaps and pen register emergencies, the law requires providers to cut off continued disclosure if law enforcement hasn’t applied for an order within 48 hours.  But if disclosure were mandatory for stored content, all of a user’s content would be out the door and no court would ever be the wiser. At least today, under the voluntary disclosure rules, providers stand in the way of excessive or non-emergency disclosures.

[snip]

A very common experience among providers when the factual basis of an emergency request is questioned is that the requesting agency simply withdraws the request, never to be heard from again. This suggests that to some, emergency requests are viewed as shortcuts or pretexts for expediting an investigation. In other cases when questioned, agents withdraw the emergency request and return with proper legal process in hand shortly thereafter, which suggests it was no emergency at all but rather an inconvenience to procure process. In still other cases, some agents refuse to reveal the circumstances giving rise to the putative emergency. This is why some providers require written certification of an emergency and a short statement of the facts so as to create a record of events — putting it in writing goes a long way to ensuring an emergency exists that requires disclosure. But when all is in place, providers respond promptly, often within an hour because most have a professional, well-trained team available 7×24.

In other words, what seems to happen now, is law enforcement use emergency requests to go on fishing expeditions, some of which are thwarted by provider gatekeeping. Jeff Sessions — the guy who 7 years ago helped the Obama Administration preserve the dragnets — now wants to make it so these fishing expeditions will have no oversight at all, a move that would make ECPA reform meaningless.

The effort to lard up ECPA reform with things that make surveillance worse (not to mention the government’s disinterest in reforming ECPA since 2007, when it first started identifying language it wanted to reform) has my spidey sense tingling. The FBI has claimed, repeatedly, in sworn testimony, that since the 2010 Warshak decision in the Sixth Circuit, it has adopted that ruling everywhere (meaning that it has obtained a warrant for stored email). If that’s true, it should have no objection to ECPA reform. And yet … it does.

I’m guessing these emergency requests are why. I suspect, too, that there are some providers that we haven’t even thought of that are even more permissive when turning over “emergency” content than the telecoms.

 

On Presidential Powers to Destabilize Entire Regions

In his latest installment on Trump and the powers of the American presidency, Ben Wittes manages to avoid calling his adversaries delusional while making delusional arguments himself, which makes for a much more intriguing post. In this one, he shifts his focus to the topics his adversaries had originally focused on, which Wittes calls “U.S. arms and war powers” but which for the moment I’ll call “national security.”

Wittes argues that the degree of authority granted the President in matters of war is scary, but less scary than not having such a powerful President.

It was a few years ago, on a panel at American University’s Washington College of Law, that I heard Brad Berenson—who served in the White House Counsel’s office under President Bush—make an arresting statement about the American Presidency.

The Presidency, Berenson argued, is an office of terrifying power. There is no legal question—at least as a matter of domestic constitutional law—that the president has the authority to order a preemptive nuclear strike on Tehran. Indeed, there is really only one thing, Berenson said, that is scarier than a president who has such power in his sole command: a president who does not have that power.

[snip]

“Energy in the Executive,” wrote Hamilton, “is a leading character in the definition of good government. It is essential to the protection of the community against foreign attacks. . . .” The reason? “A feeble Executive implies a feeble execution of the government. A feeble execution is but another phrase for a bad execution; and a government ill executed, whatever it may be in theory, must be, in practice, a bad government.” Translation: If you want government to do things, you have to have an executive capable of it.

Wittes admits that presidency doesn’t have to be this way — indeed, that Israel, which he describes as “another democratic country that has ongoing security issues and fights wars semi-regularly” doesn’t have it. Me, I’d call Israel a partially democratic country that faces far greater security issues, but which has nevertheless thrived for 70 years without it. Which is another way of saying, right in the middle of his post arguing for the necessity of a unitary presidency, Wittes provides a counterargument that suggests that, at least in some circumstances (Israel has had a lot of help, after all), it’s not actually necessary.

Nevertheless, Wittes likes what we’ve got because it gives us decisiveness and accountability.

The American system has a lot to recommend it. It generates not merely decisiveness of action, but also political accountability for that action—what Hamilton called “a due dependence on the people” and “a due responsibility.” Divide up the executive authority and nobody really knows who gets credit for success and who gets blame for failure. Nobody is responsible for anything in Israel, for example. Give all the responsibility to one president, and that is not really a problem. Nobody doubts who is responsible for Obamacare, for example, or for the Iraq war.

It’s definitely true we know who to hold responsible for Obamacare. Getting into the Iraq War, too — though there’s far less certainty among the public about who is responsible for the failure to negotiate a SOFA, which led to the withdrawal timeline, and (arguably) to the resurgence of what would become ISIS. Both Obama and Bush get blamed.

But it’s an interesting argument particularly in light of Wittes’ prior dismissal of Conor Friedersdorf and Jennifer Granick’s concerns about drones and surveillance, because on those issues and many more, the Executive is shielded from much political and all legal accountability. Presidents have authorized a vast range of covert action over the years that have led to a great deal of blowback that they by definition cannot be held accountable for. Hell, as recently as 2013, the Executive was stone-walling SSCI member Ron Wyden about what countries we were conducting lethal counterterrorism operations in, and it took years of requests, starting before the Anwar al-Awlaki killing and continuing for some time after it, before Wyden was permitted to see the authorization for that.

No one may doubt who is responsible for Obamacare, but even select oversight committees, and especially voters, simply don’t know all the things they might want to hold a president accountable for.

And on the issues that (I think) Wittes would lump under “national security,” such secrecy, such unilateral power, actually may lead to rash and often stupid decisions. Setting aside what you think about the need for the President to have authority to order preemptive nuclear strikes (the “Bomb Power” that Garry Wills argues created the necessity for such secrecy), with such authority also comes the ability to create significant harms to the US by a thousand cuts of stupid covert action. We helped to create modern Sunni terrorism via such secret authority, after all.

Add in the fact that the Intelligence Community now claims cyberattacks are the biggest threat to the US. That’s an area where there has been a distinct lack of accountability, even after catastrophic failures.

But one thing never happens in either of those worlds: accountability.

On the national security side, I have long noted that people like then Homeland Security Czar John Brennan or Director of National Security Keith Alexander never get held responsible when the US gets badly pawned. The Chinese were basically able to steal the better part of the F-35 program, yet we still don’t demand good cyber practices from defense contractors or question the approach the NSA used on cyber defense. A few people lost their job because of the OPM hack, but not the people who have a larger mandate for counterintelligence or cybersecurity. Indeed, the National Security Council apparently considers cyber a third category, in addition to public safety and national security.

As a result, whereas we assume (wrongly) that we should expect the NatSec establishment to prevent all terrorist attacks, no one thinks to hold our NatSec establishment responsible if China manages to steal databases of all our cleared personnel.

Finally, our supposedly nimble presidency has been distinctly unable to act decisively in two areas that have been a bigger threat to the US than Iran or terrorism of late: financial recklessness and crime, and climate change. The reasons for inaction are dramatically different (though both have a lot to do with the way big money dominates our elections), but the effect is that the President has a lot of power to kill Americans in secret, but doesn’t wield that same power to prevent systemic catastrophes of another sort.

Wittes ends his piece by blaming the electorate — a stance I’m not unsympathetic with.

I want to suggest, in closing, that the problem here is not a structural flaw in the executive branch. That we are contemplating our fears of a Trump presidency reflects, rather, a flaw in the electorate that would contemplate his election and in the political leadership of one of our major political parties—leadership that prefers to back him than repudiate him. In a democracy, the people, generally speaking, get the president they ask for. And if the populace asks for an abusive, erratic, proudly ignorant figure of no coherent policy vision, it’s going to get that.

But I’m far more struck by this passage, which seems a much better argument for reversing some of what even Wittes admits has been growing power of the presidency.

[I]n the ordinary course of business, nobody gets to remove from the hands of the president the vast powers that he lawfully wields: the power to destabilize regions, launch military adventures, abrogate agreements, and destroy alliances. These powers are inherent features of powers of the presidency, and they are inherent powers that we actively need.

Wittes argues we can’t impose any limits on the President (even ones that existed as recently as 15 years ago), because we need the ability to do stupid things with little oversight.

Given how damaging those powers have already been, in the hands of purportedly sane Presidents, why do we think we want to keep it that way?