Tuesday, December 31, 2013
App Smart: Basic Apps for Your New Smartphone or Tablet
Saturday, September 7, 2013
N.S.A. Able to Foil Basic Safeguards of Privacy on Web
This undated photo released by the United States government shows the National Security Agency campus in Fort Meade, Md. This article has been reported in partnership among The New York Times, The Guardian and ProPublica based on documents obtained by The Guardian. For The Guardian: James Ball, Julian Borger, Glenn Greenwald. For The New York Times: Nicole Perlroth, Scott Shane. For ProPublica: Jeff Larson.
CITING EFFORTS TO EXPLOIT WEB James R. Clapper Jr., the director of national intelligence. The agency has circumvented or cracked much of the encryption, or digital scrambling, that guards global commerce and banking systems, protects sensitive data like trade secrets and medical records, and automatically secures the e-mails, Web searches, Internet chats and phone calls of Americans and others around the world, the documents show. Many users assume — or have been assured by Internet companies — that their data is safe from prying eyes, including those of the government, and the N.S.A. wants to keep it that way. The agency treats its recent successes in deciphering protected information as among its most closely guarded secrets, restricted to those cleared for a highly classified program code-named Bullrun, according to the documents, provided by Edward J. Snowden, the former N.S.A. contractor. Beginning in 2000, as encryption tools were gradually blanketing the Web, the N.S.A. invested billions of dollars in a clandestine campaign to preserve its ability to eavesdrop. Having lost a public battle in the 1990s to insert its own “back door” in all encryption, it set out to accomplish the same goal by stealth. The agency, according to the documents and interviews with industry officials, deployed custom-built, superfast computers to break codes, and began collaborating with technology companies in the United States and abroad to build entry points into their products. The documents do not identify which companies have participated. The N.S.A. hacked into target computers to snare messages before they were encrypted. In some cases, companies say they were coerced by the government into handing over their master encryption keys or building in a back door. And the agency used its influence as the world’s most experienced code maker to covertly introduce weaknesses into the encryption standards followed by hardware and software developers around the world. “For the past decade, N.S.A. has led an aggressive, multipronged effort to break widely used Internet encryption technologies,” said a 2010 memo describing a briefing about N.S.A. accomplishments for employees of its British counterpart, Government Communications Headquarters, or GCHQ. “Cryptanalytic capabilities are now coming online. Vast amounts of encrypted Internet data which have up till now been discarded are now exploitable.” When the British analysts, who often work side by side with N.S.A. officers, were first told about the program, another memo said, “those not already briefed were gobsmacked!” An intelligence budget document makes clear that the effort is still going strong. “We are investing in groundbreaking cryptanalytic capabilities to defeat adversarial cryptography and exploit Internet traffic,” the director of national intelligence, James R. Clapper Jr., wrote in his budget request for the current year. In recent months, the documents disclosed by Mr. Snowden have described the N.S.A.’s reach in scooping up vast amounts of communications around the world. The encryption documents now show, in striking detail, how the agency works to ensure that it is actually able to read the information it collects. The agency’s success in defeating many of the privacy protections offered by encryption does not change the rules that prohibit the deliberate targeting of Americans’ e-mails or phone calls without a warrant. But it shows that the agency, which was sharply rebuked by a federal judge in 2011 for violating the rules and misleading the Foreign Intelligence Surveillance Court, cannot necessarily be restrained by privacy technology. N.S.A. rules permit the agency to store any encrypted communication, domestic or foreign, for as long as the agency is trying to decrypt it or analyze its technical features. The N.S.A., which has specialized in code-breaking since its creation in 1952, sees that task as essential to its mission. If it cannot decipher the messages of terrorists, foreign spies and other adversaries, the United States will be at serious risk, agency officials say. Just in recent weeks, the Obama administration has called on the intelligence agencies for details of communications by leaders of Al Qaeda about a terrorist plot and of Syrian officials’ messages about the chemical weapons attack outside Damascus. If such communications can be hidden by unbreakable encryption, N.S.A. officials say, the agency cannot do its work. John Markoff contributed reporting.
Sunday, June 16, 2013
Bits Blog: Facebook Discloses Basic Data on Law-Enforcement Requests
Jeff Chiu/Associated Press A sign outside of Facebook’s headquarters in Menlo Park, Calif. The company on Friday disclosed information about government requests for data, the vast majority of which did not pertain to national security matters.12:10 a.m. Saturday, June 15, 2013 | Updated Added Microsoft’s release of more data on Friday night.
Facebook on Friday disclosed for the first time how many requests for data about its 1.1 billion users it had gotten from law enforcement authorities in the United States.
The social networking company said that in the last six months of 2012, it had 9,000 to 10,000 requests for information about its users from local, state and federal agencies. Those requests covered 18,000 to 19,000 user accounts.
“These requests run the gamut — from things like a local sheriff trying to find a missing child, to a federal marshal tracking a fugitive, to a police department investigating an assault, to a national security official investigating a terrorist threat,” the company’s general counsel, Ted Ullyot, said in a blog post disclosing the data.
Facebook said it was legally prohibited from saying how many of the data requests were related to national security. But generally speaking, the vast majority of the law-enforcement data requests received by tech companies are for other matters, like local criminal cases.
Facebook’s disclosure comes after negotiations with the federal government that began after the first news reports a week ago about the National Security Agency’s secret Prism surveillance program. Those reports revealed that a number of American Internet companies, including Facebook, Google, Microsoft and Yahoo, had secretly provided data about foreigners to the United States government under the Foreign Intelligence Surveillance Act.
The tech companies have also secretly provided data to the F.B.I. under National Security Letters, which the government uses to gather information about Americans.
Under federal law, companies generally cannot disclose even the existence of national security data requests they receive. But in recent days, Facebook, Google and Microsoft have been pressing the government for permission to share more information.
“We’re pleased that as a result of our discussions, we can now include in a transparency report all U.S. national security-related requests (including FISA as well as National Security Letters) – which until now no company has been permitted to do,” Mr. Ullyot wrote. “As of today, the government will only authorize us to communicate about these numbers in aggregate, and as a range. This is progress, but we’re continuing to push for even more transparency.”
Google had previously published a transparency report that included N.S.L. but not FISA data requests. Microsoft’s recent transparency report similarly excluded FISA requests but included National Security Letters.
Late Friday, after Facebook’s data release, Microsoft provided similar information about requests for data that it had received from law enforcement at all levels of government.
For the six months ending Dec. 31, 2012, Microsoft received between 6,000 and 7,000 criminal and national security warrants, subpoenas and orders affecting between 31,000 and 32,000 consumer accounts from governmental entities in the United States, the company’s deputy general counsel, John Frank, said in a statement.
“We have not received any national security orders of the type that Verizon was reported to have received that required Verizon to provide business records about U.S. customers,” Mr. Frank said.
This post has been revised to reflect the following correction:
Correction: June 15, 2013
An earlier version of this article incorrectly described Microsoft's transparency report. It included National Security Letters requests, but excluded FISA requests. It did not exclude both types of national security requests.
Tuesday, April 23, 2013
Competition Designed to Spread Basic Technologies
This article has been revised to reflect the following correction:
Correction: April 20, 2013
An article on Friday about a World Bank competition aimed at solving sanitation problems in poor countries gave an incorrect operating base for John Kluge Jr., a venture capitalist who commented on the effort. He is based in New York, not in Silicon Valley.