Showing posts with label Requests. Show all posts
Showing posts with label Requests. Show all posts

Saturday, November 16, 2013

A Barrage of Data Requests

requests received by Apple between January and June 2013, affecting about 10,605-11,605 accounts or devices.

Source: Apple Report

Thursday, June 20, 2013

Bits Blog: Google Seeks Permission to Publish Data on Security Requests

Google's motion with the Foreign Intelligence Surveillance Court on Tuesday is the company's latest move to control the public relations crisis that has resulted from revelations of government Internet surveillance.Jeff Chiu/Associated Press Google’s motion with the Foreign Intelligence Surveillance Court on Tuesday is the company’s latest move to control the public relations crisis that has resulted from revelations of government Internet surveillance.

Google on Tuesday filed a motion with the secret Foreign Intelligence Surveillance Court, asking permission to publish data on national security requests that were made to it and authorized by the court.

The motion is the company’s latest move to control the public relations crisis that has resulted from revelations of government Internet surveillance. It is an escalation of Google’s efforts to publish the data. Last week, it sent a letter to the director of the F.B.I. and the director of national intelligence, asking for the same thing.

By law, recipients of national security requests are not allowed to acknowledge their existence. But with the permission of the government, Facebook, Yahoo, Microsoft and Apple have in the last few days published aggregate numbers of national security and criminal requests, including those authorized by the Foreign Intelligence Surveillance Act. Google has not, because it said that would be less transparent than what it had already published. Its transparency report has since 2010 broken out requests by type, and if it agreed to the same terms the other companies did, it would not be able to publish the report that way in the future.

In the motion, Google argued that it had a First Amendment right to publish a range of the total number of requests and the number of users or accounts they cover.

Google said that its executives had responded to allegations — that it cooperated with the government in Internet surveillance — as best they could, given the government’s restraints on discussing them. But the company said that it wanted to do more for the sake of its reputation, business and users, and for the sake of public debate.

“Google’s reputation and business has been harmed by the false or misleading reports in the media, and Google’s users are concerned by the allegations,” the motion said. “Google must respond to such claims with more than generalities.”

The tech companies have been pressing to be able to publish the number of government requests largely to prove that the requests cover a tiny fraction of users. Though the other companies said they were also pushing the government for permission to publish more detailed data, they said the aggregate numbers were useful to control speculation by setting a ceiling on the number of requests.

Other tech companies affected by the government’s surveillance program, called Prism, have considered going to the secret court, an option that is still on the table, according to two people briefed on the discussions. So far, the companies have been individually negotiating with the government instead of acting in concert.

Still, even if they are allowed to publish more detailed numbers, it would leave many questions unanswered, including details of how Prism works. Also, the number of people affected by FISA requests could be much larger than the number of requests, because once the government makes a broad request, it can add individuals and additional search queries for a year.

Google’s motion also revealed that two of its top lawyers, Kent Walker and Richard Salgado, have security clearance, which FISA requires for handling classified legal orders and materials. It was filed on behalf of the company by Albert Gidari, a partner at the law firm Perkins Coie who has earned a reputation in tech and legal circles as the go-to man on surveillance law.

Bits Blog: The Latest to Disclose Government Requests, Yahoo Reveals the Least

Marissa Mayer, Yahoo's chief executive, in May. She and the company's general counsel, Ron Bell, said in a statement Monday that Yahoo would issue its first global law enforcement transparency report later this summer.Emmanuel Dunand/Agence France-Presse — Getty Images Marissa Mayer, Yahoo’s chief executive, in May. She and the company’s general counsel, Ron Bell, said in a statement Monday that Yahoo would issue its first global law enforcement transparency report later this summer.

Following in the footsteps of Facebook, Microsoft and Apple, Yahoo disclosed late Monday some broad data about the number of requests that American law enforcement authorities had made for data about its users.

From Dec. 1, 2012, to May 31, 2013, the Internet company received between 12,000 and 13,000 requests from the government, related to everything from local crimes to terrorism investigations under the Foreign Intelligence Surveillance Act. “The most common of these requests concerned fraud, homicides, kidnappings, and other criminal investigations,” the company said in a post on Tumblr, the blogging platform it recently acquired.

Unlike the other companies, which have been criticized for disclosing too little information, Yahoo did not specify how many users were included in the 12,000 to 13,000 requests.

But like the other companies, Yahoo said that the government would not permit it to break out more specific data on the number of FISA data requests, which the government considers so secret that companies aren’t supposed to even acknowledge their existence.

Yahoo went to a secret intelligence court in 2008 and challenged the government’s requests under FISA as unconstitutional, but lost the case. It subsequently joined the government’s secret Prism surveillance program.

In its post, signed by its chief executive, Marissa Mayer, and its general counsel, Ron Bell, Yahoo said it would continue to press for more disclosure of FISA data.

Yahoo said it would also issue later this summer its first global law enforcement transparency report, which will cover the first half of the year, and will continue making similar reports every six months.

This post has been revised to reflect the following correction:

Correction: June 18, 2013

An earlier version of this article misstated when Yahoo disclosed information about the requests for user data it received from American government agencies. Yahoo disclosed the information on Monday, not Friday.

Monday, June 17, 2013

Bits Blog: Apple Releases Some Data on Government Requests

A sign outside of Apple's headquarters in Cupertino, Calif. The company said Sunday that it does not store data related to customers’ location, map searches or search requests “in any identifiable form,” meaning it likely stores the data without linking it to a named individual.Marcio Jose Sanchez/Associated Press A sign outside of Apple’s headquarters in Cupertino, Calif. The company said Sunday that it does not store data related to customers’ location, map searches or search requests “in any identifiable form,” meaning it likely stores the data without linking it to a named individual.

Amid reports that technology companies cooperated with the United States government’s surveillance efforts, Apple has maintained that it does not provide the government with unfettered access to its servers. On Monday, the company released some numbers and information about its online services to try to prove it.

In a statement on its Web site, Apple said that from December 2012 through May 2013, it received between 4,000 and 5,000 requests from American law enforcement agencies for customer data. Among those requests, government officials asked for information about roughly 10,000 accounts or devices, Apple said.

Apple said the requests came from federal, state and local authorities regarding both national security matters and criminal investigations. It said the most common types of request came from police investigations of robberies and other crimes, searches for missing children, attempts to prevent a suicide or searches for people with Alzheimer’s disease.

Apple also published details about its online communication services, iMessage and FaceTime. It said it chooses not to store the content of exchanges between customers on these services, and therefore it does not hand over this type of data to law enforcement agencies. Furthermore, it said, those conversations are encrypted, so nobody but the sender and the receiver can see them.

“Apple has always placed a priority on protecting our customers’ personal data, and we don’t collect or maintain a mountain of personal details about our customers in the first place,” the company said in the statement.

Apple said it also does not store data related to customers’ location, map searches or search requests “in any identifiable form,” meaning it likely stores the data without linking it to a named individual.

Sunday, June 16, 2013

Bits Blog: Facebook Discloses Basic Data on Law-Enforcement Requests

A sign outside of Facebook's headquarters in Menlo Park, Calif. The company on Friday disclosed information about government requests for data, the vast majority of which did not pertain to national security matters.Jeff Chiu/Associated Press A sign outside of Facebook’s headquarters in Menlo Park, Calif. The company on Friday disclosed information about government requests for data, the vast majority of which did not pertain to national security matters.

12:10 a.m. Saturday, June 15, 2013 | Updated Added Microsoft’s release of more data on Friday night.

Facebook on Friday disclosed for the first time how many requests for data about its 1.1 billion users it had gotten from law enforcement authorities in the United States.

The social networking company said that in the last six months of 2012, it had 9,000 to 10,000 requests for information about its users from local, state and federal agencies. Those requests covered 18,000 to 19,000 user accounts.

“These requests run the gamut — from things like a local sheriff trying to find a missing child, to a federal marshal tracking a fugitive, to a police department investigating an assault, to a national security official investigating a terrorist threat,” the company’s general counsel, Ted Ullyot, said in a blog post disclosing the data.

Facebook said it was legally prohibited from saying how many of the data requests were related to national security. But generally speaking, the vast majority of the law-enforcement data requests received by tech companies are for other matters, like local criminal cases.

Facebook’s disclosure comes after negotiations with the federal government that began after the first news reports a week ago about the National Security Agency’s secret Prism surveillance program. Those reports revealed that a number of American Internet companies, including Facebook, Google, Microsoft and Yahoo, had secretly provided data about foreigners to the United States government under the Foreign Intelligence Surveillance Act.

The tech companies have also secretly provided data to the F.B.I. under National Security Letters, which the government uses to gather information about Americans.

Under federal law, companies generally cannot disclose even the existence of national security data requests they receive. But in recent days, Facebook, Google and Microsoft have been pressing the government for permission to share more information.

“We’re pleased that as a result of our discussions, we can now include in a transparency report all U.S. national security-related requests (including FISA as well as National Security Letters) – which until now no company has been permitted to do,” Mr. Ullyot wrote. “As of today, the government will only authorize us to communicate about these numbers in aggregate, and as a range. This is progress, but we’re continuing to push for even more transparency.”

Google had previously published a transparency report that included N.S.L. but not FISA data requests. Microsoft’s recent transparency report similarly excluded FISA requests but included National Security Letters.

Late Friday, after Facebook’s data release, Microsoft provided similar information about requests for data that it had received from law enforcement at all levels of government.

For the six months ending Dec. 31, 2012, Microsoft received between 6,000 and 7,000 criminal and national security warrants, subpoenas and orders affecting between 31,000 and 32,000 consumer accounts from governmental entities in the United States, the company’s deputy general counsel, John Frank, said in a statement.

“We have not received any national security orders of the type that Verizon was reported to have received that required Verizon to provide business records about U.S. customers,” Mr. Frank said.

This post has been revised to reflect the following correction:

Correction: June 15, 2013

An earlier version of this article incorrectly described Microsoft's transparency report. It included National Security Letters requests, but excluded FISA requests. It did not exclude both types of national security requests.

Tuesday, June 11, 2013

Google Wants to Release Details on Classified Requests

SAN FRANCISCO — Google on Tuesday asked the government for permission to reveal details about the classified requests the technology company receives for the personal information of foreign users.

BitsNews from the technology industry, including start-ups, the Internet, enterprise and gadgets.
On Twitter: @nytimesbits.

It is the first time that Google has publicly acknowledged that it has received requests under the Foreign Intelligence Surveillance Act, which forbids companies from acknowledging the existence of requests or revealing any details about them. The technology company added that it complies with far fewer of these requests than it receives.

Google made the request after revelations of the National Security Agency’s secret surveillance program, known as Prism. The data the government collects as part of Prism – including email messages, telephone records and online chats -- is legally authorized by FISA.

Google made the request in a letter from David Drummond, Google’s chief legal officer, to Eric H. Holder, the attorney general, and Robert S. Mueller, the director of the F.B.I.

In the letter, Mr. Drummond expressed frustration that the company has been unable, because of a government gag order, to explain the details of how it shares user data with the government. He asked for permission to publish both the number of national security requests, including FISA disclosures, that Google receives, and their scope.

“Google’s numbers would clearly show that our compliance with these requests falls far short of the claims being made,” Mr. Drummond wrote. “Google has nothing to hide.”

Mr. Drummond was unavailable for an interview. In a statement, Leslie Miller, a Google spokeswoman, said that of Google’s hundreds of millions of users worldwide, “only a tiny fraction” are subject to government data requests each year.

“If we could publish those numbers openly, as we are asking, they would show that our compliance with these national security requests falls far short of the claims being made,” Ms. Miller said.

Sunday, March 24, 2013

Microsoft Report Discloses Law Enforcement Requests for Customer Data

The report, which Microsoft said it planned to update every six months, showed that law enforcement agencies in five countries — Britain, France, Germany, Turkey and the United States — accounted for 69 percent of the 70,665 requests the company received last year.

In 80 percent of requests, Microsoft provided elements of what is called noncontent data, like an account holder’s name, sex, e-mail address, I.P. address, country of residence, and dates and times of data traffic.

In 2.1 percent of requests, the company disclosed the actual content of a communication, like the subject heading of an e-mail, the contents of an e-mail or a picture stored on SkyDrive, its cloud computing service.

Microsoft said it disclosed the content of communications in 1,544 cases to law enforcement agencies in the United States, and in 14 cases to agents in Brazil, Canada, Ireland and New Zealand.

“Government requests for online data are like the dark matter of the Internet,” said Eva Galperin, a global policy analyst at the Electronic Frontier Foundation in San Francisco, which has campaigned for greater disclosure.

Ms. Galperin said that even with Microsoft’s disclosures, fewer than 10 companies published the extent of their cooperation with law enforcement agencies.

“Only a few companies report this, but they are only a very small percent of the online universe,” she said. “So any one company that joins the disclosure effort is good news. The faster this becomes a standard for all Web businesses, the better.”

The law enforcement requests concerned users of Microsoft services including Hotmail, Outlook.com, SkyDrive, Skype and Xbox Live, where people are typically asked to enter their personal details to obtain service.

Google was the first major Web business, in 2010, to report the number of legal requests it had received for information. Since then, Twitter, LinkedIn and some smaller companies have also begun reporting, but big businesses like Apple and Yahoo have not.

Microsoft also resisted at first. In January, a group of more than 100 Internet activists and digital rights groups signed a petition asking the company to disclose its data-handling practices for Skype, the Internet voice and video service it bought in 2011.

But Microsoft did provide two types of detail in its transparency report that rivals have not addressed in similar fashion.

It described the reasons it had rejected some requests, and it listed separately by country how it had responded to requests for the content of communications and for noncontent data.

It also published separate information for Skype, which is based in Luxembourg and is subject to national and European Union laws.

In 4,713 cases last year, Microsoft disclosed administrative details of Skype accounts — like a user’s Skype ID, name, e-mail address and billing information, as well as call detail records if a person subscribed to a Skype service that connects to a telephone number.

But Microsoft said it had released no content from Skype transmissions last year. It has said that the peer-to-peer nature of Skype’s Internet conversations means the company does not store and has no access to past conversations.

The countries that made the most requests and received information from Microsoft for Skype noncontent information last year, in descending order, were Britain, the United States, Germany, France and Taiwan, which together accounted for about 80 percent of the requests.

Microsoft did not disclose the total number of requests it had received for Skype information, but said it aimed to do so in its next report later this year.

Brad Smith, an executive vice president at Microsoft and the company’s general counsel, said that the number of requests Microsoft received last year covered only a tiny fraction of its huge customer base, which the company estimates is in the hundreds of millions.

Mr. Smith said in a blog post that the requests in 2012 had affected less than 0.02 percent of Microsoft account holders. He wrote that Microsoft, like all global businesses, must comply with requests from law enforcement, but that the company had set high standards for doing so.

Law enforcement agencies must present a subpoena or its foreign equivalent to obtain noncontent data about Microsoft users, Mr. Smith wrote. To obtain the contents of e-mails and other communications, the company requires agencies to submit a warrant, which is issued in the United States by a court judge and in Britain by the home secretary.

Microsoft rejected requests for data in 18 percent of cases last year, mostly because it could not find any information on the individuals named or because law enforcement officials had not demonstrated the proper legal justification for the requests, the company said.

It also said it had received a minuscule number of requests for data on businesses.

In 2012, Microsoft said, it received only 11 requests for information on business clients and complied in four instances, either after it had obtained consent from the business or when it already had in effect a contract permitting it to disclose the information.

“Like every company, we are obligated to comply with legally binding requests from law enforcement, and we respect and appreciate the role that law enforcement personnel play in so many countries to protect the public’s safety,” Mr. Smith wrote in his blog post. “As we continue to move forward, Microsoft is committed to respecting human rights, free expression and individual privacy.”

Wednesday, July 11, 2012

Cell Carriers See Rise in Requests to Aid Surveillance

The cellphone carriers’ reports, which come in response to a Congressional inquiry, document an explosion in cellphone surveillance in the last five years, with the companies turning over records thousands of times a day in response to police emergencies, court orders, law enforcement subpoenas and other requests.

The reports also reveal a sometimes uneasy partnership with law enforcement agencies, with the carriers frequently rejecting demands that they considered legally questionable or unjustified. At least one carrier even referred some inappropriate requests to the F.B.I.

The information represents the first time data have been collected nationally on the frequency of cell surveillance by law enforcement. The volume of the requests reported by the carriers — which most likely involve several million subscribers — surprised even some officials who have closely followed the growth of cell surveillance.

“I never expected it to be this massive,” said Representative Edward J. Markey, a Massachusetts Democrat who requested the reports from nine carriers, including AT&T, Sprint, T-Mobile and Verizon, in response to an article in April in The New York Times on law enforcement’s expanded use of cell tracking. Mr. Markey, who is the co-chairman of the Bipartisan Congressional Privacy Caucus, made the carriers’ responses available to The Times.

While the cell companies did not break down the types of law enforcement agencies collecting the data, they made clear that the widened cell surveillance cut across all levels of government — from run-of-the-mill street crimes handled by local police departments to financial crimes and intelligence investigations at the state and federal levels.

AT&T alone now responds to an average of more than 700 requests a day, with about 230 of them regarded as emergencies that do not require the normal court orders and subpoena. That is roughly triple the number it fielded in 2007, the company said. Law enforcement requests of all kinds have been rising among the other carriers as well, with annual increases of between 12 percent and 16 percent in the last five years. Sprint, which did not break down its figures in as much detail as other carriers, led all companies last year in reporting what amounted to at least 1,500 data requests on average a day.

With the rapid expansion of cell surveillance have come rising concerns — including among carriers — about what legal safeguards are in place to balance law enforcement agencies’ needs for quick data against the privacy rights of consumers.

Legal conflicts between those competing needs have flared before, but usually on national security matters. In 2006, phone companies that cooperated in the Bush administration’s secret program of eavesdropping on suspicious international communications without court warrants were sued, and ultimately were given immunity by Congress with the backing of the courts. The next year, the F.B.I. was widely criticized for improperly using emergency letters to the phone companies to gather records on thousands of phone numbers in counterterrorism investigations that did not involve emergencies.

Under federal law, the carriers said they generally required a search warrant, a court order or a formal subpoena to release information about a subscriber. But in cases that law enforcement officials deem an emergency, a less formal request is often enough. Moreover, rapid technological changes in cellphones have blurred the lines on what is legally required to get data — particularly the use of GPS systems to identify the location of phones.

As cell surveillance becomes a seemingly routine part of police work, Mr. Markey said in an interview that he worried that “digital dragnets” threatened to compromise the privacy of many customers. “There’s a real danger we’ve already crossed the line,” he said.

With the rising prevalence of cellphones, officials at all levels of law enforcement say cell tracking represents a powerful tool to find suspects, follow leads, identify associates and cull information on a wide range of crimes.

“At every crime scene, there’s some type of mobile device,” said Peter Modafferi, chief of detectives for the Rockland County district attorney’s office in New York, who also works on investigative policies and operations with the International Association of Chiefs of Police. The need for the police to exploit that technology “has grown tremendously, and it’s absolutely vital,” he said in an interview.

The surging use of cell surveillance was also reflected in the bills the wireless carriers reported sending to law enforcement agencies to cover their costs in some of the tracking operations. AT&T, for one, said it collected $8.3 million last year compared with $2.8 million in 2007, and other carriers reported similar increases in billings.