Showing posts with label Ted Lieu. Show all posts
Showing posts with label Ted Lieu. Show all posts

Saturday, May 14, 2016

You Can Get Clearance If You Always Believed in the Fourth Amendment, But Not if You’re a Fourth Amendment Convert

Screen Shot 2016-05-14 at 8.43.08 PMOn Thursday night at 11PM, in advance of an Oversight and Government Reform hearing scheduled at 9AM Friday, James Clapper’s office rolled out a new policy integrating the use of social media in security clearance reviews. Basically, the government can use public social media in making security clearance determinations, but can’t ask for your password, friend you to collect information, or access your non-public social media activity. They additionally claim, implausibly, they won’t keep anything unnecessary to make such determinations.

Even taking those caveats in good faith, the policy should not be regarded as a risk-free policy, because government bureaucrats don’t have a perfect record with attribution (something National Counterintelligence Director William Evanina admitted in the hearing) and they have a still worse one with irony. Plus, the history of FBI prosecutions of alleged terrorists for RTs suggests they will read certain actions in social media with a certain kind of intent that may not be true.

Worse, Evanina said two ridiculous things in the hearing that raises real questions about the policy and his ability to implement it fairly.

First, Thomas Massie asked Evanina whether political views would be considered. Massie, after having noted the committee notes suggested a social media search might have identified Snowden as a potential threat (Snowden did spend time online before his classified career, but nothing would have obviously flagged him), also noted their similar political contribution histories. “Do you take into account political support when you’re doing background research on social media?” After Evanina explained the background check would not review that, Massie asked specifically about whether a person supported a candidate who was strong on the Fourth Amendment.”Your belief in Fourth Amendment would not have any predication on whether you could hold or maintain a security clearance,” Evanina replied in response.

Breaking! You can believe in the Fourth Amendment and get a security clearance. 

Only, that’s not true if you’re a convert to the Fourth Amendment (as Snowden arguably was, given his online comments).

Barely mentioned at the hearing were the guidelines the Intelligence Authorization had laid out for this policy, which I wrote about here and here.

(C) publicly available information, whether electronic, printed, or other form, including relevant security or counterintelligence information about the covered individual or information that may suggest ill intent, vulnerability to blackmail, compulsive behavior, allegiance to another country, change in ideology, or that the covered individual lacks good judgment, reliability, or trustworthiness; [my emphasis]

One thing Congress explicitly wanted to measure was “change in ideology” (I believe this was always included, but it has a much different impact if one is reviewing everyone’s candid thoughts), the kind of thing when someone who once railed against leakers in public comments goes on to question whether surveillance has gotten out of hand, as Snowden did.

Or as a lot of other people did, when they considered the impact of their dragnets.

The other ridiculous thing Evanina said came in response to Ted Lieu’s concerns about the number of Asian Americans charged with spying charges that later collapsed (something that Judy Chu has also been hitting on). Lieu also mentioned that since the public reports of spying cases collapsing, he has heard from some people who believe they were denied security clearances because of their (presumably Chinese-American) ethnicity.

So Lieu asked Evanina if that’s ever a consideration.

Evanina not only claimed that it is not a consideration (in spite of the case of the man who was denied clearance because of the USAID-tied organization his wife worked for), but he offered up that in his 19 years at FBI, they had also never used ethnicity as a reason for investigation.

There’s one ginormous problem with that claim (which was sworn).

Evanina was at FBI when, in 2008, they changed the Domestic Investigations and Operations Guide (as noted above) to permit consideration of First Amendment protected activities, including religion, among the things FBI Agents may take into account during an investigation.

FBI employees may take appropriate cognizance of the role religion may play in the membership or motivation of a criminal or terrorism enterprise. If, for example, affiliation with a certain religious institution or a specific religious sect is a known requirement for inclusion in a violent organization that is the subject of an investigation, then whether a person of interest is a member of that institution or sect is a rational and permissible consideration. Similarly, if investigative experience and reliable intelligence reveal that members of a terrorist or criminal organization are known to commonly possess or exhibit a combination of religion-based characteristics or practices (e.g., group leaders state that acts of terrorism are based in religious doctrine), it is rational and lawful to consider such a combination in gathering intelligence about the group-even if any one of these, by itself, would constitute an impermissible consideration.

Worse, Evanina served in a policy role when, in 2011, they reinforced this permission in that year’s DIOG.

Admittedly, religion is not the same thing as ethnicity. But for a number of ethnicities, including Chinese and Muslim Arabs, religion can stand in for a kind of ethnicity.

It may be that Evanina was foolish enough to raise his FBI experience, which might be entirely unrelated to the practice of security clearance evaluations. But he did. And that raised some really good reasons (on top of the known record and explicit direction from Congress about what this social media approach should entail) to doubt his assurances to the committee about civil liberties problems with this policy.

I get that it makes sense to review someone’s social media to see if they can keep a secret. But it is also the case that the IC generally, the FBI in particular, and Evanina personally, are not credible on this point.

Wednesday, April 20, 2016

SS7 and NSAs Redundant Spying

SS7 countermeasuresOn Sunday, 60 Minutes brought attention to an issue first exposed by researchers some years back: the ease with which people can use the SS7 system that facilitates global mobile phone interoperability to spy on you.

Sharyn Alfonsi: If you just have somebody’s phone number, what could you do?

Karsten Nohl: Track their whereabouts, know where they go for work, which other people they meet when– You can spy on whom they call and what they say over the phone. And you can read their texts.

60 Minutes was smart in that they got Congressman Ted Lieu to agree to be targeted.

Congressman Lieu didn’t have to do anything to get attacked.

All Karsten Nohl’s team in Berlin needed to get into the congressman’s phone was the number. Remember SS7 –that little-known global phone network we told you about earlier?

Karsten Nohl: I’ve been tracking the congressman.

[snip]Sharyn Alfonsi: Are you able to track his movements even if he moves the location services and turns that off?

Karsten Nohl: Yes. The mobile network independent from the little GPS chip in your phone, knows where you are. So any choices that a congressman could’ve made, choosing a phone, choosing a pin number, installing or not installing certain apps, have no influence over what we are showing because this is targeting the mobile network. That of course, is not controlled by any one customer.

[snip]

Sharyn Alfonsi: What is your reaction to knowing that they were listening to all of your calls?

Rep. Ted Lieu: I have two. First, it’s really creepy. And second, it makes me angry.

Sharyn Alfonsi: Makes you angry, why?

Rep. Ted Lieu: They could hear any call of pretty much anyone who has a smartphone. It could be stock trades you want someone to execute. It could be calls with a bank.

Karsten Nohl’s team automatically logged the number of every phone that called Congressman Lieu — which means there’s a lot more damage that could be done than just intercepting that one phone call.

So now Lieu is furious — and pushing House Oversight Committee to conduct an investigation into SS7’s vulnerabilities.

Of course, it’s probably best to think of SS7’s vulnerabilities not as a “flaw,” as 60 Minutes describes it, but a feature. The countries that collectively aren’t demanding change are also using this vulnerability to spy on their subjects and adversaries.

But the fact that Lieu — who really is one of the smartest Members of Congress on surveillance issues — is only now copping onto the vulnerabilities with SS7 suggests how stunted our debate over dragnet surveillance was and is. For two years, we debated how to shut down the Section 215 dragnet, which collected a set of phone records that was significantly redundant with what we collected “overseas” — though in fact the telecoms’ production of such records was mixed together until 2009, suggesting for years Section 215 probably served primarily as legal cover, not the actual authorization for the collection method used. We had very credulous journalists talking about what a big gap in cell phone records NSA faced, in part because FISC frowned on letting NSA collect location data domestically. Yet all the while (as some smarter commenters here have said), NSA was surely exploiting SS7 to collect all the cell phone records it needed, including the location data. Members of Congress like Lieu — on neither the House Intelligence (which presumably has been briefed) or the House Judiciary Committees — would probably not get briefed on the degree to which our intelligence community thrives on using SS7’s vulnerabilities.

What I find perhaps most interesting about this new flurry of attention on SS7 is that the researchers behind it were hired by some “international telecoms” to find ways to improve security sometime in advance of December 2014 (when they first presented their work). The original CCC presentation on this vulnerability (see after 40:00) included a general discussion of what cell phone providers could do to increase the security of their users (see above). 60 Minutes noted that some US providers were doing more than others.

The NSA presumably could and did use entirely SS7 collection for cell phones — especially US based ones — until such time as domestic providers started making them less accessible (and once they were unaccessible overseas, then subject to legal process, though even some of the countermeasures would still leave a US user exposed to other US providers). That needs to be understood (should have been, before the passage of USA Freedom) to really understand the degree to which Congress has any influence over the NSA.

Thursday, March 24, 2016

On the Coming Showdown over Promiscuous Sharing of EO 12333 Data

A number of outlets are reporting that Ted Lieu and Blake Farenthold have written a letter to NSA Director Mike Rogers urging him not to implement the new data sharing effort reported by Charlie Savage back in February. While I'm happy they wrote the letter, they use a dubious strategy in it: they suggest their authority to intervene comes from Congress having "granted" NSA authority to conduct warrantless collection of data.
Congress granted the NSA extraordinary authority to conduct warrantless collection of communications and other data.2

2 See Foreign Intelligence Surveillance Act and the Patriot Act.
As an initial matter, they've sent this letter to a guy who's not in the chain of approval for the change. Defense Secretary Ash Carter and Attorney General Loretta Lynch will have to sign off on the procedures developed by Director of National Intelligence James Clapper; they might consult with Rogers (if he isn't the one driving the change), but he's out of the loop in terms of implementing the decision.

Furthermore, the Congressionally granted authority to conduct warrantless surveillance under FISA has nothing to do with the authority under which NSA collects this data, EO 12333. In his story, Savage makes clear that the change relies on the [what he called "little-noticed," which is how he often describes stuff reported here years earlier] changes Bush implemented in the wake of passage of FISA Amendments Act. As I noted in 2014,
Perhaps the most striking of those is that, even while the White House claimed “there were very, very few changes to Part 2 of the order” — the part that provides protections for US persons and imposes prohibitions on activities like assassinations — the EO actually replaced what had been a prohibition on the dissemination of SIGINT pertaining to US persons with permission to disseminate it with Attorney General approval.

The last paragraph of 2.3 — which describes what data on US persons may be collected — reads in the original,
In addition, agencies within the Intelligence Community may disseminate information, other than information derived from signals intelligence, to each appropriate agency within the Intelligence Community for purposes of allowing the recipient agency to determine whether the information is relevant to its responsibilities and can be retained by it.
The 2008 version requires AG and DNI approval for such dissemination, but it affirmatively permits it.
In addition, elements of the Intelligence Community may disseminate information to each appropriate element within the Intelligence Community for purposes of allowing the recipient element to determine whether the information is relevant to its responsibilities and can be retained by it, except that information derived from signals intelligence may only be disseminated or made available to Intelligence Community elements in accordance with procedures established by the Director in coordination with the Secretary of Defense and approved by the Attorney General.
Given that the DNI and AG certified the minimization procedures used with FAA, their approval for any dissemination under that program would be built in here; they have already approved it! The same is true of the SPCMA — the EO 12333 US person metadata analysis that had been approved by both Attorney General Mukasey and Defense Secretary Robert Gates earlier that year. Also included in FISA-specific dissemination, the FBI had either just been granted, or would be in the following months, permission — in minimization procedures approved by both the DNI and AG — to conduct back door searches on incidentally collected US person data.

In other words, at precisely the time when at least 3 different programs expanded the DNI and AG approved SIGINT collection and analysis of US person data, EO 12333 newly permitted the dissemination of that information.
What Bush did just as he finished moving most of Stellar Wind over to FISA authorities, was to make it permissible to share EO 12333 data with other intelligence agencies under the same kind of DNI/AG/DOD approval process already in place for surveillance. They've already been using this change (though as I note, in some ways the new version of EO 12333 made FAA sharing even more permissive than EO 12333 sharing). And Savage's article describes that they've intended to roll out this further expansion since Obama's first term.
Obama administration has been quietly developing a framework for how to carry it out since taking office in 2009.

[snip]

Intelligence officials began working in 2009 on how the technical system and rules would work, Mr. Litt said, eventually consulting the Defense and Justice Departments. This month, the administration briefed the Privacy and Civil Liberties Oversight Board, an independent five-member watchdog panel, seeking input. Before they go into effect, they must be approved by James R. Clapper, the intelligence director; Loretta E. Lynch, the attorney general; and Ashton B. Carter, the defense secretary.

“We would like it to be completed sooner rather than later,” Mr. Litt said. “Our expectation is months rather than weeks or years.”
All of which is to say that if Lieu and Farenthold want to stop this, they're going to have to buckle down and prepare for a fight over separation of powers, because Congress has had limited success (the most notable successes being imposition of FAA 703-705 and Section 309 of last year's intelligence authorization) in imposing limits on EO 12333 collection. Indeed, Section 309 is the weak protection Dianne Feinstein and Mark Udall were able to get for activities they thought should be covered under FAA.

Two more points. First, I suspect such expanded sharing is already going on between NSA and DEA. I've heard RUMINT that DEA has actually been getting far more data since shutting down their own dragnets in 2013. The sharing of "international" narcotics trade data has been baked into EO 12333 from the very start. So it would be unsurprising to have DEA replicate its dragnet using SPCMA. There's no sign, yet, that DEA has been included under FAA certifications (and there's not, as far as we know, an FAA narcotics certificate). But EO 12333 sharing with DEA would be easier to implement on the sly than FAA sharing. And once you've shared with DEA, you might as well share with everyone else.

Finally, this imminent change is why I was so insistent that SPCMA should have been in the Brennan Center's report on privacy implications of EO 12333 collection. What the government was doing, explicitly, in 2007 when they rolled that out was making the US person participants in internationally collected data visible. We've seen inklings of how NSA coaches analysts to target foreigners to get at that US person content. The implications of basing targeting off of SPCMA enabled analysis under PRISM (which we know they do because DOJ turned over the SPCMA document, but not the backup, to FISC during the Yahoo challenge), currently, are that US person data can get selected because US persons are involved and then handed over to FBI with no limits on its access. Doing so under EO 12333 will only expand the amount of data available -- and because of the structure of the Internet, a great deal of it is available.

Probably, the best way to combat this change is to vastly expand the language of FAA 703-705 to over US person data collected incidentally overseas during next year's FAA reauthorization. But it will take language like that, because simply pointing to FISA will not change the Executive's ability to change EO 12333 -- even secretly! -- at will.