Showing posts with label Thomas Hogan. Show all posts
Showing posts with label Thomas Hogan. Show all posts

Tuesday, May 10, 2016

The US Person Back Door Search Number DOJ Could Publish Immediately

The Senate Judiciary Committee had a first public hearing on Section 702 today, about which I’ll have several posts.

One piece of good news, however, is that both some of the witnesses (Liza Goitein and David Medine; Ken Wainstein, Matt Olsen, and Rachel Brand were the other witnesses) and some of the Senators supported more transparency, including requiring the FBI to provide a count of how many US person queries of 702-collected data it does, as well as a count of how many US persons get sucked up by Section 702 more generally.

Liza Goitein presented a very reasonable view of the efforts the privacy community is making to work with the government to come up with reasonable counts.

But no one mentioned the very easy count of US person back door searches that FBI could provide today.

As I noted when this was released, as part of last year’s 702 Certification process, Judge Thomas Hogan required FBI to report every time FBI reviews data on a US person query of 702 data that doesn’t pertain to National Security.

[Hogan] imposed a requirement that FBI “submit in writing a report concerning each instance … in which FBI personnel receive and review Section 702-acquired information that the FBI identifies as concerning a United States person in response to a query that is not designed to find and extract foreign intelligence information.” Such reporting, if required indefinitely, is worthwhile — and should have been required by Congress under USA Freedom Act.

But FBI can and presumably will game this information in two ways. First, FBI’s querying system can be set such that, even if someone has access to 702 data, they can run a query that will flag a hit in 702 data but won’t actually show the data underlying that positive return. This provides one way for 702-cleared people to learn that such information is in such a collection and — if they want the data without having to report it — may be able to obtain it another way. It is distinctly possible that once NSA shares EO 12333 data directly with FBI, for example, the same data will be redundantly available from that in such a way that would not need to be reported to FISC. (NSA used this arbitrage method after the 2009 problems with PATRIOT-authorized database collections.)

Plus, such reporting depends on the meaning of foreign intelligence information as defined under the Attorney General Guidelines.

FOREIGN INTELLIGENCE: information relating to the capabilities, intentions, or activities of foreign governments or elements thereof, foreign organizations or foreign persons, or international terrorists.

It would be relatively easy for FBI to decide that any conversation with a foreign person constituted foreign intelligence, and in so doing count even queries on US persons to identify criminal evidence as foreign intelligence information and therefore exempt from the reporting guidance. Certainly, the kinds of queries that might lead the FBI to profile St. Paul’s Somali community could be considered a measure of Somali activities in that community. Similarly, FBI might claim the search for informants who know those in a mosque with close ties overseas could be treated as the pursuit of information on foreign activities in US mosques.

Hogan imposed a worthwhile new reporting requirement. But that’s still a very far cry from conducing a fair assessment of whether FBI’s back door searches are constitutional.

This requirement went into effect on December 4, 2015, and Hogan required updates on such reporting by January 27, 2016, so FBI is already reporting on this.

It would take minimal effort for ODNI to release how many of these notices got sent to FISC — it could do it quarterly so we didn’t learn too much from the process. Maybe there wouldn’t be any notices, though for a variety of reasons I doubt it. Maybe, as I note, the number is too fake to be useful.

But it is a number, one FBI is already required to report. So they should start reporting it.

Friday, April 29, 2016

Rosemary Collyer’s Worst FISA Decision

In addition to adding former National Security Division head David Kris as an amicus (I’ll have more to say on this) the FISA Court announced this week that Rosemary Collyer will become presiding judge — to serve for four years — on May 19.

Collyer was the obvious choice, being the next-in-line judge from DC. But I fear she will be a crummy presiding judge, making the FISC worse than it already is.

Collyer has a history of rulings, sometimes legally dubious, backing secrecy and executive power, some of which include,

2011: Protecting redactions in the Torture OPR Report

2014: Ruling the mosaic theory did not yet make the phone dragnet illegal (in this case she chose to release her opinion)

2014: Erroneously freelance researching the Awlaki execution to justify throwing out his family’s wrongful death suit

2015: Serially helping the Administration hide drone details, even after remand from the DC Circuit

I actually think her mosaic theory opinion from 2014 is one of her (and FISC’s) less bad opinions of this ilk.

The FISC opinion I consider her most troubling, though, is not a FISC decision at all, but rather a ruling from last year in an EFF FOIA. Either Collyer let the government hide something that didn’t need hidden, or it has exploited EFF’s confusion to hide the fact that the Internet dragnet and the Upstream content programs are conducted by the same technical means, a fact that would likely greatly help EFF’s effort to show all Americans were unlawfully spied on in its Jewell suit.

Back in August 2013, EFF’s Nate Cardozo FOIAed information on the opinion referred to in this footnote from John Bates’ October 3, 2011 opinion ruling that some of NSA’s upstream collected was illegal.

Screen Shot 2015-10-31 at 6.52.30 PM

Here’s how Cardozo described his FOIA request (these documents are all attached as appendices to this declaration).

Accordingly, EFF hereby requests the following records:

1. The “separate order” or orders, as described in footnote 15 of the October 3 Opinion quoted above, in which the Foreign Intelligence Surveillance Court “address[ed] Section 1809(a) and related issues”; and,

2. The case, order, or opinion whose citation was redacted in footnote 15 of the October 3 Opinion and described as “concluding that Section 1809(a)(2) precluded the Court from approving the government’s proposed use of, among other things, certain data acquired by NSA without statutory authority through its ‘upstream collection.’”

Request 2 was the only thing at issue in Collyer’s ruling. By my read, it would ask for the entire opinion the citation to which was redacted, or at least identification of the case.

EFF, of course, is particularly interested in upstream collection because it’s at the core of their many years long lawsuit in Jewell. To get an opinion that ruled upstream collection constituted unlawful collection sure would help in EFF’s lawsuit.

In her opinion, Collyer made a point of defining “upstream” surveillance by linking to the 2012 John Bates opinion resolving the 2011 upstream issues (as well as to Wikipedia!), rather than to the footnote he used to describe it in his October 3, 2011 opinion.

The opinion in question, referred to here as the Section 1809 Opinion, held that 50 U.S.C. § 1809(a)(2) precluded the FISC from approving the Government’s proposed use of certain data acquired by the National Security Agency (NSA) without statutory authority through “Upstream” collection. 3

3 “Upstream” collection refers to the acquisition of Internet communications as they transit the “internet backbone,” i.e., principal data routes via internet cables and switches of U.S. internet service providers. See [Caption Redacted], 2012 WL 9189263, *1 (FISC Aug. 24, 2012); see also http://ift.tt/1gfilxm (last visited Oct. 19, 2015); http://ift.tt/1i7zNoo (last visited Oct. 19, 2015).

That had the effect of excluding an entirely redacted sentence from the footnote Bates used to explain it, which in context may have described a little more about the underlying opinion.

Screen Shot 2016-04-28 at 11.38.32 AM

Having thus laid out the case, Collyer deferred to NSA declarant David Sherman’s judgment — without conducting a review of the document — that releasing the document would reveal details about the implementation of upstream surveillance.

Specifically, the release of the redacted information would disclose sensitive operational details associated with NSA’s “Upstream” collection capability. While certain information regarding NSA’s “Upstream” collection capability has been declassified and publicly disclosed, certain other information regarding the capability remains currently and properly classified. The redacted information would reveal specific details regarding the application and implementation of the “Upstream” collection capability that have not been publicly disclosed. Revealing the specific means and methodology by which certain types of SIGINT collections are accomplished could allow adversaries to develop countermeasures to frustrate NSA’s collection of information crucial to national security. Disclosure of this information could reasonably be expected to cause exceptionally grave damage to the national security.

[snip]

With respect to the FISC opinion withheld in full, it is my judgment that any information in the [Section 1809 Opinion] is classified in the context of this case because it can reasonably be expected to reveal classified national security information concerning particular intelligence methods, given the nature of the document and the information that has already been released. . . . In these circumstances, the disclosure of even seemingly mundane portions of this FISC opinion would reveal particular instances in which the “Upstream” collection program was used and could reasonably be expected to encourage sophisticated adversaries to adopt countermeasures that may deprive the United States of critical intelligence. [my emphasis]

Collyer found NSA had properly withheld the document as classified information the release of which would cause “grave damage to national security.”

Now, especially thanks to the November 6, 2015 Section 702 certification approval opinion released last week, we have a fair amount of detail about opinions addressing 50 U.S.C. §1809(a)(2) violations written before October 3, 2011 (this post and this post lay some of that out). These are the three possibilities to explain what that prior memo is.

One possibility is that the May 13, 2011 opinion titled “Opinion and Order Requiring Destruction of Information Obtained by Unauthorized Electronic Surveillance” (see page 57) is that opinion. NSA left unredacted Hogan’s description of a “Title I collection in a particular case,” and made it clear that in that individual case, NSA collected data it was not authorized to collect. Hogan did not identify the problem as an upstream violation, though it would be unremarkable for every individual electronic surveillance order to include upstream surveillance, to collect the online behavior of a target outside of PRISM producers, as it would be equally unremarkable to target jihadist forums and the like using upstream surveillance. An order using multiple methods to target the same identifier might explain why Bates described the opinion as relating to “among other things, certain data acquired by NSA without statutory authority through its ‘upstream collection.’” But the timing would be particularly curious, given that NSA submitted the first clarification letter revealing its upstream 702 violations on May 2, before the final opinion in the individual case got finalized.

If that’s the opinion that NSA said would cause grave damage to national security, it seems odd that less than a year after Collyer’s ruling, NSA decided they can now segregate information from the opinion (I assume they didn’t mean to leave the title of the opinion unredacted, but as far as I know NYC has not collapsed as a result).

Another possibility is that the redacted opinion is the July 2010 John Bates opinion that spends its last 18 pages (98-116) discussing the application of 50 USC §1809(a)(2) to NSA surveillance. A December 2010 opinion leading up to the May 13, 2011 one cites from it at length (57), and Hogan cited from it at length two times (73 fn 54, 76 fn 56). In 2013, I assumed that’s what Bates’ later reference was to, and I still think it most likely, as it has become clear that that July 2010 opinion is the base opinion laying out how FISC applies 50 USC §1809(a)(2) to NSA surveillance that has gotten a little bit out of hand. In any case, those 18 pages are what EFF was looking for in the first place, the opinion on how NSA applies this law; they just somehow missed it in a critical opinion on PRTT.

The counterargument that this is the opinion in question is two-fold. First, Bates says that the memo he was citing from pertains to upstream surveillance, and we’ve been led to think of the Internet dragnet as a simple pen register.

Except that we know it is a “pen register” applied to telecom switches. There are few explicit explanations of this in officially released NSA documents, but in places — such as when Bates explains his inconceivable approval to expand this collection after railing about 5 years of violations, he makes clear that “Acquisition of particular forms of metadata (described in Part II, supra) is authorized for all e-mail [redacted] communications traversing any of the communications facilities at the specified locations.” (81) It’s more clear that upstream surveillance expanded on this PRTT collection from application documents (see DOJ’s supplemental memorandum at PDF 93) to conduct upstream collection to replace Stellar Wind, which cite Colleen Kollar-Kotelly’s 2004 PRTT opinion finding telecom switches were a facility under the term of the FISA pen/trap and trace provision, though that reference seems to cite from this paragraph, which is redacted in the original.

Screen Shot 2016-04-29 at 9.53.18 AM

Bates even makes it clear this PRTT collection can involve the collection of content when he talks about criminal decisions on whether the government could collect and then delete Post Cut Through Direct Dial content from a Pen Register (though curiously he may not cite earlier 2009 FISC discussions about its own permission to collect then minimize such information).

Screen Shot 2016-04-28 at 12.05.10 PM

This discussion makes two things clear: first, PRTT is upstream collection; it’s what upstream content collection pointed to as precedent. But in its public releases, NSA has tried to hide the fact that is is. I’ll come back to that.

Another counterargument that this is the opinion is that it has already been released!!! The opinion was released in response to an EPIC FOIA in November 2013 and EFF started suing for it in May 2014 (it was “randomly” assigned to Collyer, who had been a FISC judge starting in March 2013, in June 2014).

It is not without precedent for the government to play funny games with FOIAs. I’ve noted how the NSC withheld the Memorandum of Notification underlying the war on terror without ACLU realizing, at first, that’s what they were arguing over. A more exact analogy is is how, in another ACLU FOIA, the government has pretended that the Special Procedures for Communications Metadata Analysis have not been released (though they were released again yesterday, along with some of the underlying language they’re trying to hide from ACLU) so as to avoid having to release the underlying memo.

Of potentially critical import, along the way (I believe in early 2015), EFF agreed not to ask for the docket information or date of the opinion.

Plaintiff narrowed its challenges here to exclude (1) docket numbers, certification numbers and the like, (2) all withholdings pursuant to exemption (b)(6), and (3) names or descriptions of surveillance targets, all that remains in dispute are withholdings of classified intelligence sources and methods and law-enforcement procedures and methods that are exempt under (b)(1), (b)(3), and (b)(7).

The government is, after all, hiding both the docket number and date of the July 2010 memo (significantly, they’re also hiding the dates of the 2009 PRTT violations that resulted in a shut-down of PRTT collection at moments that coincide in key ways with EFF’s challenges to the NSA program). The only thing they’ll tell us that it was shut down and (they claim, though even NSA’s IG couldn’t entirely verify this) purged all the data very quickly in the weeks after Bates ruled the upstream collection was unconstitutional. So there’s no way we can prove (except for basic analysis and the fact they accidentally released the July 2010 date to Charlie Savage in a FOIA) that the PRTT opinion, which is technically upstream collection, predates the October 3, 2011 one. And the government can avoid having to convince Collyer that these dates and dockets are a key operational detail (which they’re not) even while they withhold the few tidbits that would make it clear the July 2010 memo is the one responsive to EFF’s FOIA.

The final counterargument for why the July 2010 memo is not the one in question is that it would make Bates’ syntax about the “government’s proposed use of, among other things, certain data acquired by NSA without statutory authority through its ‘upstream collection’” rather curious. All the data he ruled against the use of was acquired from switches. Moreover, unless the category violations of Kollar-Kotelly’s 2004 order were far broader than what Bates approved in his July 2010 opinion, then he ultimately found they had the statutory authority, just not the authority granted by the court (effectively because Bates redefined Dialing, Routing, Addressing, or Signaling information more broadly in 2010).

Of course, there’s a third possibility, that the opinion in question is a third one, one we’ve never heard of yet. The biggest reason I think that unlikely is that July 2010 does appear to be the base discussion of 50 USC §1809(a)(2) (it doesn’t, for example, cite any earlier discussion). Which would mean any other 50 USC §1809(a)(2) opinion would come in the fairly narrow window between July 2010 and October 2011. That’d be a lot of opinions (along with the May 2011 one) finding that NSA was illegally wiretapping Americans. Moreover, I would think a third opinion ruling what is technically upstream collection illegal would get even more discussion in Bates’ 2011 opinion.

As I said, I think it’s most likely that the government — with Collyer’s assistance — is hiding the fact that that 2010 opinion is the one Bates cited in his 2011 opinion. Sherman’s explanation that the information was classified “in the context of this case … given the nature of the document and the information that has already been released” would support an understanding that NSA refused to tell EFF that the already released 2010 opinion is the one they were looking for all along so as to hide the fact that PRTT is nothing more than upstream collection.

But there is a very obvious reason why they’d want to do that. The government has argued in EFF’s suits that upstream 702 collection does not infringe on the rights of Americans because the telecoms sort it before they hand it over to NSA. The only things that get handed over are transactions including the selector in question, the selectors are by definition foreign, and the switches from which they collected are supposed to be foreign facing.

None of those things are true of PRTT collection. Even in 2004, when Kollar-Kotelly limited collection to switches that were more likely to include terrorism traffic, the collection was designed to include all the metadata of Americans’ international conversations from those switches. In 2010, Bates expanded the number of switches NSA collected from, affecting a far greater percentage of Americans. He also expanded what could be collected from a packet to include stuff that is technically content (though the violations revealed in 2009 make it clear NSA was always collecting content under the Internet dragnet). Furthermore, when NSA intakes bulk collected data — as distinct from when they intake content — they put everything into a table of relationships. The analysts will never see the majority of this data, but effectively, the first thing the techs did on intake of PRTT data was conduct a search of every single record they obtained (I strongly believe this is why NSA did not permit its IG to review the intake part of the PRTT process when they destroyed it all in 2011, because it might have revealed that they were effectively illegally surveilling content from all Americans as part of the intake process).

EFF may not win their argument that upstream content collection is an illegal search. But (perhaps counterintuitively) they should be more likely to make that argument for PRTT, not least because NSA shut it down entirely on two different occasions.

And that is why I believe NSA wants to avoid admitting that that 2010 PRTT opinion is technically about unlawful upstream collection: because it will make it far easier for EFF to win their lawsuits against the government. They were granted discovery in February, so hopefully they can get to this information in any case. But I strongly suspect the NSA withheld a document it had already released only to make it harder for EFF to prove that even after PRTT moved under FISA’s oversight, it continued to be illegal collection for 5 years and then one more year, even as determined by John Bates.

And NSA did all this with the cooperation of a FISA judge they happened to “randomly” pull for this case, one who should have known enough by the point she ruled to understand the stakes. That is why I think Collyer will be a crummy FISC judge. Even if this FOIA suit was about the May 2011 opinion, it clearly was improperly withheld. But if it was about the already released July 2010 one, then it suggests a real abuse of authority.

Two years ago, I noted that we effectively have gotten to the point where we have a one (wo)man national security court, because the presiding judge (and maybe one or two other DC-based judges) sit on the big programmatic cases. That’s particularly problematic when, as now, we have a particularly crummy judge from a constitutional perspective.

Tuesday, April 26, 2016

The Easy Section 702 Surveillance Number James Clapper Can Share

Last week, a bunch of House Judiciary Committee members set James Clapper a letter stating that before the Committee deals with Section 702 reauthorization next year, they’d like:

  • The number of telephone communications in which one caller is located in the United States
  • The number of Internet communications acquired through upstream collection that originate or terminate in the United States
  • The number of communications of or concerning U.S. persons that the NSA positively identifies as such in the routine course of its work

They asked for those numbers by May 6.

In response, Clapper is humming and hawing about “several options” for disclosing how many Americans get spied on under Section 702.

Clapper said that “any methodology we come up with will not be completely satisfactory to all parties.”

“If we could have made such an estimate and if such an estimate were easy to do — explainable without compromise — we would’ve done it a long time ago,” he said.

We just learned there is, however, one number that should be easy-peasy to make public (and one I’m frankly alarmed the HJC members didn’t mention, as they should have known about it for some time): the number of back door searches FBI conducts on Section 702 data for reasons other than national security.

As I noted the other day, in response to FISC amicus (and former Eric Holder counsel) Amy Jeffress’ argument that FBI’s back door searches of Section 702 are unconstitutional, Thomas Hogan required FBI “submit in writing a report concerning each instance … in which FBI personnel receive and review Section 702-acquired information that the FBI identifies as concerning a United States person in response to a query that is not designed to find and extract foreign intelligence information.” As I noted, that’s an easily gamed number — I’m sure FBI treats a lot of criminal matters as national security ones, and FBI has the ability to see if there is 702 data without looking at it, permitting it to see if the same data is available under another authority.

Nevertheless, DOJ must have an exact number of reports they’ve submitted in response to this reporting requirement, which has been in place for over four months.

That’s not to say HJC shouldn’t insist on getting estimates for all the other numbers they’re seeking. But they should also demand that this number — the number of times FBI is using a foreign intelligence exception for criminal prosecutions that should be subject to a probable cause standard — be made public.

Monday, April 25, 2016

NSA Failed to Fully Inform FISC Even After It Started Fact-Checking Itself

On Friday, I described how, for four years after the FISA Court ruled that NSA couldn’t keep otherwise unlawfully collected information from a single traditional FISA order, the NSA continued to do just that with data from 702 orders.

Hogan was [] surprised to learn NSA was doing the same thing — and had been! — with Section 702 data that had otherwise been purged, which the NSA confessed to Hogan in July of last year. That is, having stopped the practice with a single traditional FISA order, they kept doing it with programmatic 702 data.

In light of the May 2011 [redacted], the Court was very surprised to learn from the July 13, 2015 Notice that the NSA had not been deleting from [redacted] Section 702 records placed on the NSA’s Master Purge List (“MPL”).

[snip]

As the Court explained to the government at the October 8 Hearing, it expects the government to comply with its heightened duty of candor in ex parte proceedings at all times. Candor is fundamental to this Court’s effective operation in considering ex parte submissions from the government, particularly in matters involving large and complex operations such as the implementation of Section 702.

That’s pathetic, given the history of material misstatements to FISC.

All the more so given that it happened after NSA implemented an effort to make sure it started telling FISC the truth (the date is redacted, but it probably happened sometime between October 2011 and March 2013).

As laid out in a 2013 reissue of a 2012 NSA IG report (this report starts at PDF 55; Charlie Savage liberated this via FOIA), NSA implemented a fact-checking process on its own FISC submissions. (See PDF 101)

Screen Shot 2016-04-25 at 9.15.54 AM

NSA is hiding when they first started fact-checking themselves, but it happened by March 2013. Which means the 2013 and 2014 702 recertification submissions were fact-checked. “The [Verification of Accuracy] procedures require all factual statements within the declarations to be verified.” Yet neither told FISC that NSA continued to retain communications from selectors on the Master Purge List in a management database two and three years after the time (at that point) FISC had told NSA, in an order titled, “Opinion and Order Requiring Destruction of Information Obtained by Unauthorized Electronic Surveillance,” it could not do so, not even with data unlawfully obtained on a single targeted FISA order. It took another year before NSA confessed to FISC it was keeping 702 data that should have been purged.

Perhaps the continued discovery of three to four violations every time NSA submits its recertification process reflects the slow implementation of fact-checking. Or perhaps there are just too many databases in which willing NSA employees can stash information before it gets purged off all the other databases.

But if the VoA was supposed to “increase confidence” in what NSA says to courts and Congress, it’s not clear how continuing to miss things like ongoing retention of unlawfully collected information does that.

Related posts on the November 6, 2015 reauthorization opinion

The NSA Has Never Not Been Violating FISA Since It Moved Stellar Wind to FISA in 2004

The Government Admits 9 Defendants Spied On Under Section 702 Have Not Gotten FISA Notice

Former Top Holder Aide Says Back Door Searches Violate Fourth Amendment; FISC Judge Thomas Hogan Doesn’t Care

FBI’s Back Door Searches: Explicit Permission … and Before That
Last July, NSA and CIA Decided They Didn’t Have to Follow Minimization Procedures, and Judge Hogan Is Cool with That

Please consider a donation to support this work.

Sunday, April 24, 2016

The NSA Has Never Not Been Violating FISA Since It Moved Stellar Wind to FISA in 2004

Back in 2013, I noted that FISA Judge John Bates had written two posts finding NSA had violated 50 U.S.C. §1809(a)(2), which prohibits the “disclos[ure] or use[ of] information obtained under color of law by electronic surveillance, knowing or having reason to know that the information was obtained through electronic surveillance not authorized by” FISA. Each time he did it, Bates sort of waggled around the specter of law-breaking as a way of forcing NSA to destroy data they otherwise wanted to retain and use. I suspect that is why NSA moved so quickly to shut down its PRTT program in 2011 in the wake of his upstream opinion.

In his November 6, 2015 opinion reauthorizing Section 702, presiding judge Thomas Hogan described two more definite violations of 50 U.S.C. §1809(a)(2), and one potential one, bringing the list of times the FISC caught NSA illegally surveilling Americans to four, and potentially five, times.

  1. Fall 2009 confession/July 2010 opinion: Collection of categories of data under the bulk PRTT program not permitted by the FISC
  2. June 2010 confession/December 10 2010, May 13, 2011 opinions: Retention of overcollected data from a traditional FISA warrant in mission management systems ultimately not deemed necessary for collection avoidance
  3. May 2011 confession/October 3, 2011 opinion: Collection of entirely domestic communications on upstream surveillance MCTs
  4. July 13, 2015 confession/November 6, 2015 opinion: Retention of 702 communications that had been otherwise purged in mission management systems, even though FISC had ruled against such retention in 2011
  5. [Potential] July 13, 2015 confession/November 6, 2015 opinion: Retention of data that should have been purged or aged off in compliance databases

Hogan describes these incidents starting on 56.

Between June and August of 2010, the government filed some notices notices of violation in conjunction with a single electronic surveillance order (on page 58, he describes that as dealing “exclusively with Title I collection in a particular case.”) It’s unclear whether the scope of the surveillance extended beyond what had been authorized, or whether the government had conducted surveillance based on illegally collected data (Hogan refers to it both as overcollection but also as poison fruit). As part of its efforts to resolve the problem, the government argued it could keep some of this poisonous fruit in some kind of oversight database to prevent further collection. But it also argued that its minimization procedures “only applied to interceptions authorized by the Court and did not apply to the fruits of unlawful surveillance,” effectively arguing that if it broke the law the FISC could then not tell it what to do because it had broken the law. The government also argued 50 U.S.C. §1809(a)(2) “only prohibits use or disclosure of unlawfully obtained information for investigative or analytic purposes,” meaning it could keep illegal data for management purposes.

FISC didn’t buy this argument generally, but in a December 10, 2010 opinion did permit NSA to retain “the results of unauthorized surveillance [that] are needed to remedy past unauthorized surveillance or prevent similar unauthorized surveillance in the future.” In that opinion, FISC cited John Bates’ July 2010 PRTT opinion discussing the application of 50 U.S.C. §1809(a)(2).

After further review, on May 13, 2011, the court ruled that the specific data in question did not fall within that exception.

[C]ourts should not attempt “to restrict the unqualified language of a [criminal] statute to the particular evil that Congress was trying to remedy — even assuming that it is possible to identify that evil from something other than the text of the statute itself.” Brogan v United States, 522 U.S. 398, 403 (1998) … The exception recognized in the December 10, 2010 Opinion stands on narrower but firmer ground: that in limited circumstances, prohibiting use of disclosure of the results of unauthorized electronic surveillance would be “so ‘absurd or glaringly unjust’ … as to [call into] question whether Congress actual intended what the plain language of Section 1809(a)(2) “so clearly imports.”

That decision only related to one traditional FISA order — but it did lay out the principle that NSA couldn’t keep illegally collected data for vague management reasons.

Which is why Hogan was so surprised to learn NSA was doing the same thing — and had been! — with Section 702 data that had otherwise been purged, which the NSA confessed to Hogan in July of last year. That is, having stopped the practice with a single traditional FISA order, they kept doing it with programmatic 702 data.

In light of the May 2011 [redacted], the Court was very surprised to learn from the July 13, 2015 Notice that the NSA had not been deleting from [redacted] Section 702 records placed on the NSA’s Master Purge List (“MPL”).

[snip]

As the Court explained to the government at the October 8 Hearing, it expects the government to comply with its heightened duty of candor in ex parte proceedings at all times. Candor is fundamental to this Court’s effective operation in considering ex parte submissions from the government, particularly in matters involving large and complex operations such as the implementation of Section 702.

After the hearing, the government submitted several filings effectively saying it was purging the data, then admitting that the technical process it had implemented to effect the purge was only purging some of the selectors that had been illegally collected.

In any case, after 4 years of retaining 702 data that had to be purged, they were finally moving towards deleting it last year.

The second violation pertains to two tools (both names of which are redacted) that help determine whether a selector can be or has been properly tasked (on page 76, Hogan suggests “most Section 702 information [in these databases] that is otherwise subject to purge pertains to roamer communications.”

The first appears to be a pre-tasking tool to see whether it properly tasked. This tool has not aged off PRISM data within the required 5 years, nor upstream data within the required 2 years, though it has aged off pre-October 31, 2011 upstream data. NSA has not done so “because of the utility of these records for compliance and collection avoidance purposes.”  It also helps to respond to OSD and ODNI oversight questions.

The second is a post-tasking tool to identify whether a Section 702 target may be in the US. It doesn’t age off PRISM data within the required 5 years, though it does treat upstream data properly. In addition, it doesn’t purge items that have been added to the Master Purge List. Rather than purging, it just masks certain fields from most users.

In general, Hogan seemed to believe most of this data did fall within the narrow exception laid out in the December 2010 opinion permitting the retention of unauthorized data for the purposes of collection avoidance, though he asked for further briefing that would have taken place in January.

He did point to the inclusion in these two tools of other selectors that had been put on the purge list, however, which would raise additional questions:

Examples would be incidentally acquired communications of or concerning United States persons that are clearly not relevant to the authorized purpose of the acquisition or that do not contain evidence of a crime which may be disseminated under the minimization procedures … attorney-client communications that do not contain foreign intelligence information or evidence of a crime … and any instances in which the NSA discovers that a United Staes person or person not reasonably believed to be outside the United States at the time of targeting has been intentionally targeted under Section 702.

That is, Hogan raised the possibility that these tools included precisely the kind of information that should be deliberately avoided.

Ah well. He still reauthorized Section 702.

Consider what this means: between the five years between when, in fall 2004, NSA told Colleen Kollar-Kotelly it was violating her category restrictions until the time, in 2009, it admitted it continued to do so, between the non-disclosure of what NSA was really doing with upstream surveillance between 2008 and 2011, and the time it treated 702 data in a way it had just been told (in May 2011) it could not even with a single FISA order, NSA has always been in violation of 50 U.S.C. §1809(a)(2) since it moved Stellar Wind to FISA.

And that’s just the stuff they have admitted to.

Friday, April 22, 2016

The Government Admits 9 Defendants Spied On Under Section 702 Have Not Gotten FISA Notice

As I noted, in his opinion approving the Section 702 certifications from last year, Judge Thomas Hogan had a long section describing the 4 different kinds of violations the spooks had committed in the prior year.

One of those pertained to FBI agents not establishing an attorney-client review team for people who had been indicted, as mandated by the FBI’s minimization procedures.

In his section on attorney-client review team violations, Hogan describes violations in all four of the Quarterly Reports submitted since the previous 702 certification process: December 19, 2014, March 20, 2015, June 19, 2015, and September 18, 2015. He also cites three more Preliminary Compliance Reports that appear not to be covered in that September 18, 2015 report: one on September 9, 2015, one on October 5, 2015, and one on October 8, 2015. His further discussion describes the government claiming at a hearing on October 8 to discuss the issue that, thanks to a new system FBI had deployed to address the problem, “additional instances of non-compliance with the review team requirement were discovered by the time of the October 8 Hearing.”

But as Hogan notes in his November 2015 opinion, FBI discovered a lot of these issues because FBI had had a similar problem the previous year and he required them to review for it closely in his 2014 order. A July 30, 2014 letter submitted as part of the recertification process describes two instances in depth: one noticed in February 2014 and reported in the March Quarterly report, and one noticed in April and reported in the June 2014, each involving multiple accounts. A footnote to that discussion admits “there have been additional, subsequent instances of this type of compliance incident.”

Set aside, for the moment, the persistence with which FBI failed to set up review teams to make sure prosecutorial teams were not reading the attorney-client conversations of indicted defendants (who are the only ones who get such protection!!!). Set aside the excuses they gave, such as that they thought this requirement — part of the legally mandatory minimization procedures — didn’t apply for sealed indictments or with targets located outside the United States.

Conservatively, this significantly redacted discussion identifies 9 examples (2 reported in Compliance Reports in 2014, at least 1 reported each in each of four quarterly Compliance report between applications, plus 3 individual compliance reports submitted after the September Compliance report) when people who have been indicted had their communications collected under Section 702, whether they were the target of the 702 directives or not.

And yet, as Patrick Toomey wrote in December, not a single defendant has gotten a Section 702 notice during the period in question.

Up until 2013, no criminal defendant received notice of Section 702 surveillance, even though notice is required by statute. Then, after reports surfaced in the New York Times that the Justice Department had misled the Supreme Court and was evading its notice obligations, the government issued five such notices in criminal cases between October 2013 and April 2014. After that, the notices stopped — and for the last 20 months, crickets.

We know both Mohamed Osman Mohamud — who received a 702 notice personally — and Bakhtiyor Jumaev — who would have secondary 702 standing via Jamshid Muhtorov, with whom he got busted — had their attorney-client communications spied on. But that wasn’t (damn well better not have been!!) 702 spying, because both parties to all those conversations were in the US.

These are 9 different defendants who’ve not yet been told they were being spied on under 702.

Why not?

The answer is probably the one Toomey laid out: that even though members of a prosecutorial team were listening in on attorney-client conversations collected under 702, DOJ made sure nothing from those conversations (or anything else collected via 702) got used in another court filing, and thereby avoided the notice requirement.

Based on what can be gleaned from the public record, it seems likely that defendants are not getting notice because DOJ is interpreting a key term of art in Fourth Amendment law too narrowly — the phrase “derived from.” Under FISA itself, the government is obliged to give notice to a defendant when its evidence is “derived from” Section 702 surveillance of the defendant’s communications. There is good reason to think that DOJ has interpreted this phrase so narrowly that it can almost always get around its own rule, at least in new cases.

It is clear from public reporting and DOJ’s filings in the ACLU’s lawsuit that it has spent years developing a secret body of law interpreting the phrase “derived from.” Indeed, from 2008 to 2013, National Security Division lawyers apparently adopted a definition of “derived” that eliminated notice of Section 702 surveillance altogether. Then, after this policy became public, DOJ came up with something else, which produced a handful of notices in existing cases.

Savage reports in Power Wars that then-Deputy Attorney General James Cole decided that Section 702 information had to have been “material” or “critical” to trigger notice to a defendant. But the book doesn’t provide any details about the legal underpinnings for this rule or, crucially, how Cole’s directive was actually implemented within DOJ. The complete absence of Section 702 notices since April 2014 suggests DOJ may well have found new ways of short-circuiting the notice requirement.

One obvious way DOJ might have done so is by deeming evidence to be “derived from” Section 702 surveillance only when it has expressly relied on Section 702 information in a later court filing — for instance, in a subsequent FISA application or search warrant application. (Perhaps DOJ’s interpretation is slightly more generous than this, but probably not by much.) DOJ could then avoid giving notice to defendants simply by avoiding all references to Section 702 information in those court filings, citing information gleaned from other investigative sources instead — even if the information from those alternative sources would never have been obtained without Section 702.

So these 9 mystery defendants don’t tell us anything new. They just give us a number — 9 — of defendants the government now has officially admitted have been spied on under 702 who have not been told that.

As I noted, Judge Hogan did not include this persistent attorney-client problem among the things he invited Amy Jeffress to review as amicus. Whether or not she would have objected to the persistent violation of FBI’s minimization procedures, a review of them would also have given her evidence from which she might have questioned FBI’s compliance with another part of 702, that defendants get notice.

But DOJ seems pretty determined to flout that requirement going forward.

Former Top Holder Aide Says Back Door Searches Violate Fourth Amendment; FISC Judge Thomas Hogan Doesnt Care

My apologies to Amy Jeffress.

When I first realized that FISA Court Presiding Judge Thomas Hogan picked her to serve as amicus for the review of the yearly 702 certifications last year, I complained that she, not Marc Zwillinger, got selected (the pick was made in August, but Jeffress would later be picked as one of the standing amicus curiae, along with Zwillinger). After all, Zwillinger has already argued that PRISM (then authorized by Protect America Act) was unconstitutional when he represented Yahoo in its challenge of the program. He’s got experience making this precise argument. Plus, Jeffress not only is a long-time national security prosecutor and former top Eric Holder aide, but she has been involved in some actions designed to protect the Executive. I still think Zwillinger might have done a better job. But Jeffress nevertheless made what appears to be a vigorous, though unsuccessful, argument that FBI’s back door searches of US person data are unconstitutional.

A former top DOJ lawyer believes FBI’s back door queries are unconstitutional

But it says a lot that Jeffress — someone who narrowly missed being picked as Assistant Attorney General for National Security and who presumably got at least some visibility on back door searches when working with Holder — argued that FBI’s warrantless back door searches of communications collected under Section 702 is unconstitutional.

Sadly, Hogan didn’t care. Worse, his argument for not caring doesn’t make sense. As I’ll note, not only did Hogan pick a less than optimal person to make this argument, but he may have narrowly scoped her input, which may have prevented her from raising evidence in Hogan’s own opinion that his legal conclusion was problematic.

To be clear, Jeffress was no flaming hippie. She found no problem with the NSA and CIA practice of back door searches, concluding, “that the NSA and CIA minimization procedures are sufficient to ensure that the use of U.S. person identifiers for th[e] purpose of [querying Section 702-acquired information] complies with the statutory requirements of Section 702 and with the Fourth Amendment.” But she did find the FBI practice problematic.

Jeffress’ amicus brief included at least 10 pages of discussion of her concerns with the practice, though ODNI did not release her brief and Hogan cited very limited bits of it. She argued, “the FISA process cannot be used as a device to investigate wholly unrelated ordinary crimes” and said because the queries could do so they “go far beyond the purpose for which the Section 702-acquired information is collected in permitting queries that are unrelated to national security.”

To dismiss Jeffress’ arguments, Hogan does several things. He,

  • Notes the statute requires foreign intelligence just be “a significant purpose” of the collection, and points back to the 2002 In Re Sealed Case FISCR decision interpreting the “significant purpose” language added in the PATRIOT Act to permit the use of traditional FISA information for prosecutions
  • Cites the FISA minimization procedure language that “allow[s] for the retention and dissemination of information that is evidence of a crime which has been, is being, or is about to be committed”
  • Dismisses a former top DOJ official’s concerns about the use of FISA data for non-national security crimes as “hypothetical”
  • Doesn’t address — at all — language in the FBI minimization procedures that permits querying of data for assessments and other unspecific uses
  • Invests a lot of faith in FBI’s access and training requirements that later parts of his opinion undermine

There are several problems with his argument.

In Re Sealed Case ties “significant purpose” to the target of an interception

First, Hogan extends the scope of what the FISA Court of Review interpreted the term “significant purpose,” which got added to traditional FISA in the PATRIOT Act and then adopted in FISA Amendments Act.

Hogan cites the FISCR decision in In Re Sealed Case to suggest it authorized the use of information against non-targets of surveillance. He does so by putting the court’s ultimate decision after caveats it uses to modify that. “The Court of Review concluded that it would be an “anomalous reading” of the “significant purpose” language of 50 U.S.C. § 1804(a)(6)(B) to allow the use of electronic surveillance in such a case. See id. at 736. The Court nevertheless stressed, however, that “[s]o long as the government entertains a realistic option of dealing with the agent other than through criminal prosecution that it satisfies the significant purpose test.”

But that’s not what FISCR found. Here’s how that reads in the original, with Hogan’s citations emphasized.

On the one hand, Congress did not amend the definition of foreign intelligence information which, we have explained, includes evidence of foreign intelligence crimes. On the other hand, Congress accepted the dichotomy between foreign intelligence and law enforcement by adopting the significant purpose test. Nevertheless, it is our task to do our best to read the statute to honor congressional intent. The better reading, it seems to us, excludes from the purpose of gaining foreign intelligence information a sole objective of criminal prosecution. We therefore reject the government’s argument to the contrary. Yet this may not make much practical difference. Because, as the government points out, when it commences an electronic surveillance of a foreign agent, typically it will not have decided whether to prosecute the agent (whatever may be the subjective intent of the investigators or lawyers who initiate an investigation). So long as the government entertains a realistic option of dealing with the agent other than through criminal prosecution, it satisfies the significant purpose test.

The important point is–and here we agree with the government–the Patriot Act amendment, by using the word “significant,” eliminated any justification for the FISA court to balance the relative weight the government places on criminal prosecution as compared to other counterintelligence responses. If the certification of the application’s purpose articulates a broader objective than criminal prosecution–such as stopping an ongoing conspiracy–and includes other potential non-prosecutorial responses, the government meets the statutory test. Of course, if the court concluded that the government’s sole objective was merely to gain evidence of past criminal conduct–even foreign intelligence crimes–to punish the agent rather than halt ongoing espionage or terrorist activity, the application should be denied.

The government claims that even prosecutions of non-foreign intelligence crimes are consistent with a purpose of gaining foreign intelligence information so long as the government’s objective is to stop espionage or terrorism by putting an agent of a foreign power in prison. That interpretation transgresses the original FISA. It will be recalled that Congress intended section 1804(a)(7)(B) to prevent the government from targeting a foreign agent when its “true purpose” was to gain non-foreign intelligence information–such as evidence of ordinary crimes or scandals. See supra at p.14. (If the government inadvertently came upon evidence of ordinary crimes, FISA provided for the transmission of that evidence to the proper authority. 50 U.S.C. § 1801(h)(3).) It can be argued, however, that by providing that an application is to be granted if the government has only a “significant purpose” of gaining foreign intelligence information, the Patriot Act allows the government to have a primary objective of prosecuting an agent for a non-foreign intelligence crime. Yet we think that would be an anomalous reading of the amendment. For we see not the slightest indication that Congress meant to give that power to the Executive Branch. Accordingly, the manifestation of such a purpose, it seems to us, would continue to disqualify an application. That is not to deny that ordinary crimes might be inextricably intertwined with foreign intelligence crimes. For example, if a group of international terrorists were to engage in bank robberies in order to finance the manufacture of a bomb, evidence of the bank robbery should be treated just as evidence of the terrorist act itself. But the FISA process cannot be used as a device to investigate wholly unrelated ordinary crimes.

Hogan ignores three key parts of this passage. First, FISCR’s decision only envisions the use of evidence against the target of the surveillance, not against his interlocutors, to in some way neutralize him. Any US person information collected and retained under 702 is, by definition, not the targeted person (whereas he or she might be in a traditional FISA order). Furthermore, FBI’s queries of information collected under 702 will find and use information that has nothing to do with putting foreign agents in prison — that is, to “investigate wholly unrelated ordinary crimes,” which FISCR prohibited. Finally, by searching data that may be years old for evidence of a crime, FBI is, in effect, “gaining evidence of past criminal conduct” — itself prohibited by FISCR — of someone who isn’t even the target of the surveillance.

Hogan only treats querying for criminal purposes

Having, in my opinion, expanded on what FISCR authorized back in 2002, Hogan then ignores several parts of what FBI querying permits.

Here’s (some of) the language FBI added to its minimization procedures, at the suggestion of PCLOB, to finally, after 8 years, fully disclose what it was doing to the FISC.

It is a routine and encouraged practice for FBI to query databases containing lawfully acquired information, including FISA-acquired information, in furtherance of the FBI’s authorized intelligence and law enforcement activities, such as assessments, investigations and intelligence collection. Section III.D governs the conduct of such queries. Examples of such queries include, but are not limited to, queries reasonably designed to identify foreign intelligence information or evidence of a crime related to an ongoing authorized investigation or reasonably designed queries conducted by FBI personnel in making an initial decision to open an assessment concerning a threat to national security, the prevention or protection against a Federal crime, or the collection of foreign intelligence, as authorized by the Attorney General Guidelines. These examples are illustrative and neither expand nor restrict the scope of the queries authorized in the language above.

This language makes clear FBI may do back door searches for:

  • To identify foreign intelligence information
  • To identify evidence of a crime related to an ongoing investigation
  • To decide whether to open an assessment concerning a threat to national security, the prevention or protection against a Federal crime, or the collection of foreign intelligence
  • Other things, because FBI’s use of such queries “are not limited to” these uses

Given Hogan’s stingy citations from Jeffress’ brief, it’s unclear how much of these things she addressed (or whether she was permitted to introduce knowledge gained from having worked closely with Eric Holder when these back door searches were being formalized).

But he only treats her objection that FISC cannot be used “to investigate wholly unrelated ordinary crimes.”

And his treatment of that is pretty unconvincing. Indeed, at times Hogan’s rationalizations read like he’s trying to convince himself. He cites, without quoting, these two statements from the PCLOB 702 report (the first is from the report itself; the second is from Rachel Brand and Elisabeth Collins Cook’s separate statement).

Anecdotally, the FBI has advised the Board that it is extremely unlikely that an agent or analyst who is conducting an assessment of a non-national security crime would get a responsive result from the query against the Section 702–acquired data.

[snip]

We are unaware of any instance in which a database query in an investigation of a non–foreign intelligence crime resulted in a “hit” on 702 information, much less a situation in which such information was used to further such an investigation or prosecution.

Because FBI didn’t track these queries before this ruling, it actually doesn’t know whether any query has resulted in such a hit, and neither statement claims to be proof it never happened. From that absence of evidence, however, Hogan calls the risk “remote, if not entirely theoretical,” then treats it as a “hypothetical problem.”

Worse, Hogan presumably has reason to know the possibility is not remote at all. After all, Hogan himself authorized an expansion of FBI’s minimization procedures in 2014 permitting FBI to share 702 information with the National Center on Missing and Exploited Children, which is a pretty clear indication that FBI planned to use 702 data to investigate kiddie porn. Kiddie porn is a serious crime. But it is not, usually, a national security one (except insofar as the government now treats some Transnational Crime Organizations like it does terrorist groups. Nowhere in his discussion does Hogan explain why 702 information should be used to investigate kiddie porn, or what FBI’s clear intent to do so means for the Fourth Amendment analysis.

Hogan’s okay with what he calls a theoretical possibility, though, based on this equally theoretical example — offered by the government at the hearing — that FBI will stumble on a foreign terrorist tie when investigating some kind of common criminal plot.

A query designed to find and extract data regarding a [redacted] plot, for example, might reveal a previously unknown connection to persons believed to be funding terrorist operations on behalf of [redacted]

But what this suggestion means is that alleged terrorists with ties to a foreign organization may be investigated with information collected with less than a warrant standard. By contrast, if the FBI were to investigate, say, Robert Dear (the Colorado Springs Planned Parenthood killer, who long hailed the actions of other anti-choice terrorists and sometimes communicated with them) or the Malheur Refugee occupiers, with their ties to groups that have threatened the government, FBI would be less likely to find data showing such ties, because to actually have collected it in the past, FBI would have needed to reach a probable cause standard not required for FISA, much less 702. Yet there’s no reason to believe Islamic extremists here in the US are a bigger threat than other kinds of terrorists. Moreover, to treat white Christian terrorists with a probable cause standard while treating Muslim terrorists with a NSA targeting standard exposes is patently unequal treatment before the law.

Hogan ignores other potential queries under FBI’s minimization procedures

As noted, there are two other things clearly permitted in FBI’s new minimization procedures language on which Hogan is completely silent: to decide whether to open an assessment, or “other things” not laid out in the minimization procedures.

One of the known uses of such queries is tied quite closely to the question of whether 702 data should be used to investigate common crimes, and it’s one Hogan tacitly invokes when he invokes In Re Sealed case. As I have noted in the past, during the FISCR hearing in that case, then Solicitor General Ted Olson argued that if the government obtained evidence of rape using a FISA wiretap, they might then use such information to coerce the rapist in question to become an informant.

OLSON: And it seems to me, if anything, it illustrates the position that we’re taking about here. That, Judge Silberman, makes it clear that to the extent a FISA-approved surveillance uncovers information that’s totally unrelated — let’s say, that a person who is under surveillance has also engaged in some illegal conduct, cheating —

JUDGE LEAVY: Income tax.

SOLICITOR GENERAL OLSON: Income tax. What we keep going back to is practically all of this information might in some ways relate to the planning of a terrorist act or facilitation of it.

JUDGE SILBERMAN: Try rape. That’s unlikely to have a foreign intelligence component.

SOLICITOR GENERAL OLSON: It’s unlikely, but you could go to that individual and say we’ve got this information and we’re prosecuting and you might be able to help us. I don’t want to foreclose that.

JUDGE SILBERMAN: It’s a stretch.

SOLICITOR GENERAL OLSON: It is a stretch but it’s not impossible either. [my emphasis]

The FBI admits it uses assessments to find informants. Doing so might easily qualify under “the decision to open an assessment.” And, especially if the FBI were using something embarrassing but not illegal (say, evidence that an Imam were engaged in an extramarital affair) to coerce a person to spy, that would have enormous implications under the Fourth Amendment.

Similarly, FBI admits it uses assessments to engage in domestic profiling — such as to map out the Somali community in Saint Paul. I could see the FBI using communications between people writing from IP addresses in certain cities to targets of interest in Somalia to decide that such profiling — of entire communities! — was worthwhile. But Hogan doesn’t deal with FBI’s use of 702 queries for assessments at all. It’s a clear part of their minimization procedures, and he doesn’t include it, at all, in his Fourth Amendment analysis.

Which, of course, leaves that “such queries include, but are not limited to,” language in FBI’s minimization procedures (which reveals the practice is even more invasive than described in the PCLOB report). What is FBI doing with this data? And why, once again, is Hogan approving minimization procedures that don’t lay out how this domestic surveillance is being used?

After relying on protections in FBI’s minimization procedures to deem FBI’s queries constitutional, Hogan then lays out two ways FBI’s minimization procedures aren’t being followed

As noted, there’s one more thing Hogan relies on to find FBI’s querying process constitutional. He cites the restrictions in the FBI’s minimization procedures to suggest the protections are adequate. “With respect to the intrusiveness of the querying process, the FBI Minimization Procedures impose substantial restrictions on the use and dissemination of information derived from queries.”

In an few cases, Hogan cites what Jeffress found problematic — that even people without training in 702 data can access it on a one-time basis — as proof of its control. “In ‘very rare’ circumstances,” he cites the hearing, “FBI personnel who are not trained for and do not have access to Section 702-acquired information may view the results of a query solely to aid in the determination of whether the information constitutes foreign intelligence information or evidence of a crime.”

Yet the second half of Hogan’s opinion — dealing with 702 as implemented, including the numerous violations reported in the year leading up to these certifications — even further undermines Hogan claim that minimization procedures make the queries acceptable. Two of the violations Hogan describes pertain to FBI minimization procedures not being enforced. For example, in his description of the multiple cases — documented in 6 difference compliance reports over the previous year and what appear to be at least three more in 2014 — where FBI did not meet its own (wholly inadequate, given that protection is focused primarily on indicted defendants) minimization procedures designed to protect attorney-client communications, Hogan judged, “FBI case agents are generally aware of the requirement for a review team when a Section 702 target is charged with a federal crime, but they are confused about the specific requirements of the FBI Minimization Procedures.” He does so while describing a situation that, by asking agents whether a target might be indicted in the future, might encourage agents to delay indictment so as to delay the time when attorney-client communications would become subject to the taint team.

More troubling is an almost entirely redacted violation pertaining to failure of access controls to raw 702 data. Hogan introduces a two page, entirely redacted discussion about this problem by noting that FBI’s minimization procedures grant access to raw 702 data “‘permitting access … only by individuals who require access in order to perform their job duties'” and also “requires users with access to raw FISA-acquired information to receive training on the minimization procedures.” That introduction only makes sense if the redacted two pages explain that FBI is not meeting those procedures. And it comes a year after Hogan appears to have learned of similar problems with access controls on ad hoc FBI databases created from 702 data. Less than ten pages after having found FBI’s querying process constitutional because of access limits and training required to use this data, then, Hogan lays out how FBI access controls don’t work and agents remain “confused” even after being trained on the minimization procedures.

Plus, throughout the discussion of compliance problems (including more pertaining to NSA), there’s no mention of Jeffress’ involvement (although the attorney-client review team problems were discussed at a hearing that she also attended). It’s unclear whether Hogan permitted Jeffress to learn of these violations (he determines what she needs to do her job, after all), and if she didn’t have access to it, it would have prevented her from showing why the FBI’s minimization procedures aren’t adequate to protect Fourth Amendment rights.

Hogan’s easily gamed reporting requirement

Hogan doesn’t leave FBI’s querying process entirely untouched. He imposed a requirement that FBI “submit in writing a report concerning each instance … in which FBI personnel receive and review Section 702-acquired information that the FBI identifies as concerning a United States person in response to a query that is not designed to find and extract foreign intelligence information.” Such reporting, if required indefinitely, is worthwhile — and should have been required by Congress under USA Freedom Act.

But FBI can and presumably will game this information in two ways. First, FBI’s querying system can be set such that, even if someone has access to 702 data, they can run a query that will flag a hit in 702 data but won’t actually show the data underlying that positive return. This provides one way for 702-cleared people to learn that such information is in such a collection and — if they want the data without having to report it — may be able to obtain it another way. It is distinctly possible that once NSA shares EO 12333 data directly with FBI, for example, the same data will be redundantly available from that in such a way that would not need to be reported to FISC. (NSA used this arbitrage method after the 2009 problems with PATRIOT-authorized database collections.)

Plus, such reporting depends on the meaning of foreign intelligence information as defined under the Attorney General Guidelines.

FOREIGN INTELLIGENCE: information relating to the capabilities, intentions, or activities of foreign governments or elements thereof, foreign organizations or foreign persons, or international terrorists.

It would be relatively easy for FBI to decide that any conversation with a foreign person constituted foreign intelligence, and in so doing count even queries on US persons to identify criminal evidence as foreign intelligence information and therefore exempt from the reporting guidance. Certainly, the kinds of queries that might lead the FBI to profile St. Paul’s Somali community could be considered a measure of Somali activities in that community. Similarly, FBI might claim the search for informants who know those in a mosque with close ties overseas could be treated as the pursuit of information on foreign activities in US mosques.

Hogan imposed a worthwhile new reporting requirement. But that’s still a very far cry from conducing a fair assessment of whether FBI’s back door searches are constitutional.

 

Wednesday, April 20, 2016

FBIs Back Door Searches: Explicit Permission and Before That

I have written numerous times about the timing of authorization for FBI to do back door searches. There’s a passage of the November 6, 2015 FISC opinion finding those searches to be constitutional that some have taken to clearly date the authority. But I believe the (unredacted sections of the) passage are being misread.

As Judge Thomas Hogan describes, “Queries by FBI personnel of Section 702-acquired data…

Screen Shot 2016-04-20 at 8.53.44 PM

As the unredacted parts of the section make clear, queries for both foreign intelligence information or evidence of a crime “have been explicitly permitted by the FBI Minimization Procedures since 2009.” [my emphasis] The footnote goes onto describe how Minimization Procedures approved by Attorney General Mukasey on October 22, 2008 and submitted on some redacted date were approved by an opinion issued on April 7, 2009.

Already, that’s a curious set of details. If the minimization procedures were approved in October 2008, normally they’d be submitted close to right away, though it’s not clear that that happened. In any case, James Clapper’s censors want to hide what those dates were. One likely reason they might have done so would be to hide the dates from defendants, including a few of the ones challenging 702. Another would be to obscure how the approval process went after passage of FISA Amendments Act, specifically given that the FISA Court of Review finalized its Yahoo opinion in August of that year, in which it relied on DOJ’s promise that “there is no database” of incidentally collected US person information.

There Is No Database

But two other things suggest that’s not the end of the story. First, the use of “explicitly” suggests there may have been a period before FISC approved the minimization procedures when such a practice was approved but perhaps not explicitly. Perhaps that simply refers to that lag period, between the time Mukasey approved those minimization procedures and the time FISC approved them.

But then there’s that redacted paragraph (the next footnote, 25, starts after it). Hogan adds something to his discussion beyond his description of the explicit approval of those minimization procedures.

As I have pointed out, Mukasey (writing with then Director of National Intelligence Mike McConnell, who would also have to approve any PRISM minimization procedures) made it clear in response to a Russ Feingold amendment of FISA Amendments Act in February of 2008 that they intended to spy in Americans under PRISM.

So it sure seems likely the Administration at the very least had FBI back door searches planned, if not already in the works, well before FISC approved the minimization procedures in 2009. That’s probably what Hogan explained in that paragraph, but James Clapper apparently believes it would be legally inconvenient to mention that.

Last July NSA and CIA Decided They Didnt Have to Follow Minimization Procedures and Judge Hogan Is Cool with That

Yesterday, I Con the Record released three FISA Court opinions from last year. This November 6, 2015 opinion, authorizing last year’s Section 702 certifications, has attracted the most attention, both for its list of violations (including the NSA’s 3rd known instance of illegal surveillance) and for the court’s rejection of amicus Amy Jeffress’ argument that FBI’s back door searches are not constitutional. I’ll return to both issues.

I’m surprised, however, that this passage hasn’t generated more attention.

The NSA and CIA Minimization Procedures included as part of the July 15, 2015 Submission each contain new language stating that “[n]othing in these procedures shall prohibit the retention, processing, or dissemination of information reasonably necessary to comply with specific constitutional, judicial, or legislative mandates.” See NSA Minimization Procedures at 1; CIA Minimization Procedures at 4-5. These provisions were not included in the draft procedures that were submitted to the Court in June 2015, but appear to have been added by the government thereafter. They are not discussed in the July 15, 2015 Memorandum.

So basically, NSA and CIA just slipped in language suggesting that they can blow off minimization procedures mandated by Congress, without prior explanation (which is highly unusual in FISA process). The language reminds me of the language NSA used in Intelligence Oversight Board reports to cover up for Stellar Wind. Or the language John Yoo used in his letter to Colleen Kollar-Kotelly saying that FISC couldn’t bind the President.

Thomas Hogan was, to some degree, suitably shocked by this. After laying out how much detail goes into minimization procedures, he said,

A provision that would allow the NSA and CIA to deviate from any of these restrictions based un unspecified “mandates” could undermine the Court’s ability to find the procedures satisfy the above-described statutory requirement.

Ya think?!?!

Hogan then went on to suggest — based on what evidence, he doesn’t say — that the NSA and CIA will only use this language sparingly because the NCTC, which apparently has similar language in their minimization procedures, claimed they’d only use it sparingly.

It appears, however, that the government does not intend to apply these provisions as broadly as their language would arguably permit. In 2012, the government proposed a similar provision as part of minimization procedures to be applied by NCTC in handling certain unminimized terrorism-related information acquired by FBI pursuant to other provisions of FISA. In requesting approval of a provision that would allow NCTC personnel to deviate from other requirements of its minimization procedures when “reasonably necessary to comply with specific constitutional, judicial, or legislative mandates,” the government asserted that “Executive Branch orders or directives will not trigger this provision, nor will general Congressional directives that are not specific to information NCTC receives pursuant to this motion. [citation removed] The Court approved the NCTC minimization procedures with the understanding that this provision would be applied sparingly.The Court described the provision as permitting NCTC personnel to “retain, process or disseminate information when reasonably necessary to fulfill specific legal requirements” and compared it to a more narrowly-drafted provision of separate procedures that permits CIA to retain or disseminate information that is “required by law to be retained or disseminated.”

This language, which if I’m counting correctly, is now in everyone’s minimization procedures but FBI’s, is alarming enough in the NCTC context, which will only get counterterrorism information and that only via FBI.

But CIA and NSA get raw data. Shit-tons of it. Which makes the scale of such language pretty damned alarming.

Having thus assumed the NCTC example is decent precedent for the NSA and CIA adoption, Hogan then does something else amazing. He relies on “informal communications.”

The Court understands based on informal communications between Court staff and attorneys for the government that NSA and CIA intend to apply the similar provisions at issue here in the same narrow manner. In any case, to avoid a deficiency under the above-described definition of “minimization procedures” the Court must construe the phrase “specific constitutional, judicial, or legislative mandates” to include only those mandates containing language that clearly and specifically requires action in contravention of an otherwise-applicable provision of the requirement of the minimization procedures. Such clear and specific language, for instance, might be found in a court order requiring the government to preserve a particular target’s communications beyond the date when they would otherwise be subject to age-off under the minimization procedures. On the other hand, these provisions should not be interpreted as permitting an otherwise prohibited retention or use of information simply because that retention of use could assist the government in complying with a general statutory requirement, such as those stated at 50 U.S.C. § 1881a(b).

This is batshit insane! The court has for years, fought, often unsuccessfully, to keep NSA within the scope of the law as interpreted in minimization procedures. The government slipped in a provision basically saying, if we decide we don’t have to follow minimization procedures mandated by law, we won’t. And Hogan hasn’t required written explanation for why the agencies need this?!?!?!

Hogan does it again in a footnote suggesting the government “may” use this provision to share data with Congress.

The Court understands that the government may have added these new provisions to clarify that information acquired under Section 702 may be shared with Members of Congress or Congressional committees in connection with Congressional oversight of the program. If so, the Court would urge the government to consider replacing these broadly-worded provisions with language that is narrowly tailored to that purpose.

Hey Judge Hogan? The law requiring you approve these minimization procedures and NSA follow them? That law comes from Congress. If Congress needs NSA to start sharing raw data with it (!!!!), then it can change the law. At the very least, don’t you owe your independent branch of government — and the American people — more certainty than that this may explain this alarming provision?

But no. Hogan required nothing in writing. He did require reporting on how NSA and CIA use it. I’m not sure how that’ll be effective when President Trump decides he can pass an Executive Order requiring NSA to keep all the US person data it collects but not tell FISC about it, because the order they report on this to him is part of the minimization procedures they say they can blow off.

And note this is not one of the two areas that Hogan asked amicus Amy Jeffress to weigh in on. Apparently this is either not a “novel or significant interpretation of the law” requiring amicus review or Hogan didn’t include it because it didn’t get included in the June draft, which is when he decided this should have amicus review.

There’s a lot that’s troubling in this opinion. But the most troubling is that the presiding Judge of the FISC court just rubber-stamped NSA and CIA blowing off entirely the minimization procedures that are the core of the FISC’s leverage over the government.