Showing posts with label National Security Agency. Show all posts
Showing posts with label National Security Agency. Show all posts

UK Police Snowden Probe Declared "Inactive"

Friday, 20 December 2019

In 2013, London's Metropolitan Police began a criminal investigation focusing on journalists who reported stories from a trove of secret documents leaked by the National Security Agency whistleblower Edward Snowden. Now, after six years and no arrests or prosecutions, the Met has confirmed that the investigation has been shelved.

The Met told me in response to a recent Freedom of Information request that the investigation is "inactive pending further information being received." Since 2014, I've had several updates from the Met regarding the investigation, and this marks the first time that its status has changed from "ongoing." In November 2017, the Met stated that it was a "complex investigation and enquiries continue."

The investigation, which was given the code-name Operation Curable, had been led by the Met's Counter-Terrorism Command, under the direction of assistant commissioner Mark Rowley. In March 2018, Rowley retired from the Met -- and with his departure, it seems the Curable investigation went cold.

The majority of the documents in Snowden's leaked archive revealed classified American mass surveillance operations. But a significant portion of the files disclosed explosive information about electronic spying programs operated by the UK’s largest intelligence agency, Government Communications Headquarters, or GCHQ.

British authorities responded furiously to the Snowden revelations and tried to prevent The Guardian from publishing them. Infamously, representatives from GCHQ were sent to the newspaper's London offices at one stage to oversee the destruction of hard drives that contained the secret files.

The police went as far as to argue that publishing the Snowden files was itself a terrorist act, thereby explicitly conflating journalism with terrorism. In August 2013, a memo authored by the Met and domestic spy agency MI5 asserted that “the disclosure [of the Snowden documents], or threat of disclosure, is designed to influence a government and is made for the purpose of promoting a political or ideological cause. This therefore falls within the definition of terrorism.”

In December 2013, one of the London force’s most senior officers, Cressida Dick, was questioned about the case during a parliamentary hearing. She acknowledged that the force’s investigation was looking at whether reporters at The Guardian had committed criminal offences -- some carrying potential 10-year prison sentences -- for their role in revealing secret surveillance operations exposed in the documents. “We need to establish whether they have or haven’t [committed offences],” Dick said. “That involves a huge amount of scoping of material.”

It is unclear how much taxpayer money and police resources were invested in pursuing the Curable investigation. The Met has declined to provide any information about the amount of funds spent on the probe, or disclose the number of officers who worked on it; the force claims that it does not hold records of these details. It is also unclear whether the investigation may at some point resume. The Met said that the probe is inactive pending further information being received -- what that information may be, and whether it will ever actually materialise, is anyone's guess.

Extraordinary Rendition and the Secret Role of Metadata

Thursday, 28 August 2014

On Monday, I had a new story out at The Intercept revealing a secret search engine that the National Security Agency built to share a massive amount of data with other US government agencies, including domestic law enforcement. There are many new and important details scattered through the piece. But there is one in particular I would like to take a minute to focus on here, because it is a fact that strikes at the heart of the debate about government surveillance and deserves some more attention.

In one of the classified documents that we published with the story, dated from 2005, the NSA outlined some of the "successes" of a data-sharing project called CRISSCROSS that was led by the Central Intelligence Agency. The document shows that metadata collected about communications was integral to the CIA's extraordinary rendition program during the Bush Administration, which involved kidnapping terror suspects and taking them to secret "black site" jails where they would be brutally interrogated and sometimes tortured. The NSA document says:

Since 9/11, the contributions to the GWOT [global war on terror] due to our increased collection of signaling metadata are innumerable and significant. It is safe to say that it has been a contribution to virtually every successful rendition of suspects and often, the deciding factor.

This is an incredible detail. Remember, metadata is not the audio content of a phone call or the words contained within the body of an email message. It is merely information showing who you have contacted and when. Governments have often sought to defend the mass-scale collection of metadata by insisting that it is not information that is sensitive or very private. In June last year, President Obama tried to dismiss concerns about metadata collection in the United States by claiming that "nobody is listening to your telephone calls." But, clearly, the government doesn't need to be listening to your calls to deem you a threat. That metadata has been the deciding factor in targeting people for extraordinary rendition is a profound illustration of that — and it shows that metadata collection has real-world ramifications: it is not just some benign activity.

You might think, "well, I'm not a terror suspect so what do I care?" But this is not only about the Bad Guys — there are much wider consequences at play here. During the height of the extraordinary rendition program, for instance, some of the people targeted were victims of what was called "erroneous rendition." In other words, the CIA would kidnap the wrong person. (Yes, seriously.) In 2005, it was reported by the Washington Post that the CIA's inspector general was investigating a "growing number" of erroneous renditions, with some anonymous government officials saying that they believed there were as many as 30 instances of it having taken place.

Much is still unknown about these cocked-up renditions because the information has been kept secret. But now that we know metadata played a key role in targeting people — in some cases even being the "deciding factor" — questions must surely be asked about whether this method was ever to blame. From a legal and human rights perspective, it is disturbing enough that the CIA was secretly kidnapping, imprisoning, and then torturing people. But the possibility of innocent individuals being targeted on the basis of their metadata trail clearly adds a chilling extra dimension. It is a policy of guilt by association that bears all the hallmarks of a kind of terrible and flawed style of totalitarian policing.

Today, the practice of extraordinary rendition appears to have been largely phased out by President Obama. But the concerns raised by the use of metadata to target people are still highly pertinent. Indeed, as The Intercept reported back in February, metadata is actively being used to target and kill terror suspects in drone strikes in countries like Yemen, Pakistan and Somalia. One military source said that the method can result in the "wrong people" being bombed. And if you think that sounds far-fetched — that the US would not launch missiles at people because of their metadata — you don't need to take my word for it. Just go and listen to what former CIA and NSA chief Michael Hayden has to say. As he boasted in April: "We kill people based on metadata."

Canada's WiFi Surveillance and CSEC's Non-Denial Denials

Saturday, 1 February 2014

On Thursday, a report I worked on with Glenn Greenwald and Greg Weston was published in Canada, revealing how the country's spy agency CSEC secretly developed a program to monitor WiFi users in a major Canadian airport.

The piece, based on documents leaked by the former US National Security Agency contractor Edward Snowden, has led to CSEC being accused of acting unlawfully and has triggered calls for better oversight of the agency.

But one of the most intriguing aspects of the fallout from the story has been the Canadian government's response — which merits some scrutiny and analysis.

First, some context.

Back in November, Greenwald, Weston and I reported separate revelations about Canada's role in an NSA operation to spy at the G8 and G20 summits in Canada in 2010. In response, CSEC's chief John Forster claimed in response to reporters' questions:

What I can tell you is that CSEC, under its legislation, cannot target Canadians anywhere in the world or anyone in Canada, including visitors to Canada.

During a speech in October, Forster had made a similar statement:

I can tell you that we do not target Canadians at home or abroad in our foreign intelligence activities, nor do we target anyone in Canada. In fact, it's prohibited by law. Protecting the privacy of Canadians is our most important principle.

And again, in January, he repeated this assertion in a letter to a Canadian newspaper:

Under the law, CSE’s foreign intelligence mandate specifically dictates that our activities be directed only at foreign entities, and not at Canadians or anyone in Canada. That is the law and we fully respect that.

Having analysed Canadian documents in the Snowden material, these statements struck me as quite astonishing.

Why? Because one of the top-secret Snowden documents revealed that, in 2012, CSEC had set up a program that involved monitoring WiFi usage at a large Canadian airport. The secret files showed how CSEC was able to use a huge amount of data about the WiFi connections to follow users "backward and forward in recent time" — identifying visits to hotels, other airports, Internet cafes, coffee shops, and a library.

The tactic is described by CSEC in the files as "IP profiling" — a surveillance method that can be used to track users' movements over time. In one case, as we reported at CBC on Thursday, the spy agency says that it performed a sweep of an entire "modest-sized" city and identified 300,000 user IDs:

The "mission impact" of the tactic, according to the document, is that it can alert spies to "target country location changes" and "webmail logins with time-limited cookies":

The full document [pdf] speaks for itself. It illustrates a secret surveillance operation was conducted on Canadian soil — sweeping up metadata on the WiFi usage of thousands of people not suspected of any crime. Equally significant, the revelation contradicts CSEC chief Forster's repeated assertion that "we do not target Canadians at home or abroad in our foreign intelligence activities, nor do we target anyone in Canada."

After we reported the airports story, it got more interesting.

CSEC issued a statement that was notable for three reasons. First, the agency did not repeat its previous mantra claiming not to "target anyone in Canada." Second, it appeared to make an admission that it is sweeping up metadata within Canada, saying that it was "legally authorized" to "collect and analyze" this information. And third, it issued a fresh denial, saying that "no Canadian or foreign travellers were tracked. No Canadian communications were, or are, targeted, collected or used."

Shortly afterwards, on Friday, a similar denial was made by the Canadian prime minister's parliamentary secretary, who launched a bizarre personal attack on Greenwald while claiming that the "facts" were that "nothing in the stolen documents showed that Canadians' communications were targeted, collected, or used, nor that travellers' movements were tracked."

But these denials are hollow.

It's a straw man to claim that the revelations were about communications being "targeted, collected, or used." That is not what our story was about. The issue at hand is how CSEC initiated a program to sweep up information showing when people are connecting to WiFi networks and using this information to build "profiles" of their movements back and forward in time.

And that brings us to the more important point. CSEC and the prime minister's secretary claimed that "no Canadian or foreign travellers were tracked." However, what they did not say was how they were defining the word "tracked."

The documents quite clearly show how the agency used user "IP profiles" to monitor WiFi users' movements over time, with this capability enabling it to generate "alerts" when a person relocates to another country.

The dictionary definition of "tracking" says that it means "the act or process of following something or someone." CSEC's IP profiling is exactly that — monitoring users' location and keeping tabs on where they are. Indeed, the document says as much, outlining how CSEC uses this tactic to "follow IDs backward and forward in recent time." The documents also mention how CSEC used tools called "Quova" and "Atlas database" — which are technologies used to pinpoint the geolocation of an IP address.

CSEC's denial that it "tracked" Canadians or foreign travellers, I think, hinges upon a narrowly defined interpretation of the word. The US Department of Defence, for instance, uses "tracking" as a specific technical term meaning the "precise and continuous position-finding of targets by radar, optical, or other means." CSEC's IP profiling definitely fits the dictionary definition of "tracking" as it is understood by most people — but does it fit the narrower military definition? Perhaps CSEC believes that IP profiling does not constitute "precise and continuous" tracking. But if so, it should be explaining this — as otherwise its denial is highly misleading.

Spy agencies are professionals in the art of deception, and sometimes that seems to be reflected in their public relations strategy. Afterall, we have seen misleading denials issued repeatedly by the National Security Agency and its Five Eyes counterparts about various surveillance revelations in recent months. Again and again, officials have used narrowly defined words or jargon terms in a carefully crafted way in order to issue non-denial denials in which they appear to refute an allegation but on closer reading do not really refute it at all.

The ultimate point here is that the tactics being used by CSEC and the Canadian government to deflect criticism of their secret surveillance programs merit as much attention as the revelations themselves. That is especially clear when, in response to disclosures about their secret programs, senior government officials launch childish character assassination attempts against the journalists who reported the information. In a democratic society, surely a higher standard is required. It is not enough for governments and spy agencies to spit out a few indignant statements and denials with the expectation that people should just blindly trust that they are telling the truth.

Also, no matter how "tracking" is being defined, what is clear is that CSEC was (and our sources say still is) running a large-scale surveillance operation on domestic soil, seriously calling into question spy chief Forster's previous statements that "our activities" are not directed "at Canadians or anyone in Canada." The CSEC boss is due to appear before a Senate committee hearing on Monday. Hopefully Canada's lawmakers will take the opportunity to ask some probing questions.


UPDATE, 7 February 2014: Since the story was published last week, there have been several developments. There have been more calls for an independent review of CSEC's activities, while spy chief Forster was forced to publicly defend the surveillance in Monday's Senate hearing.

There have also been some interesting analyses of the leaked documents worth responding to.

First, the surveillance blog Electrospaces claimed that the secret documents seemed to have been "incorrectly interpreted" in our CBC report. The blog published an anonymous analysis from someone who says that CSEC's surveillance project was "was not surveillance of Canadian citizens per se but just a small research project." The second analysis came from Bruce Schneier, who claimed that it was "not really true" that CSEC used "airport Wi-Fi information to track travellers."

First of all, it is a mischaracterization to claim that the CSEC project was just a small research project that didn't implicate Canadians "per se." It was part of a pilot initiative that involved sweeping up data on hundreds of thousands of people — many of whom would have been Canadian citizens. Our sources for the story told us that the pliot had since gone live — i.e. that it had gone from being a "proof-of-concept" to an operationally active domestic program. This is about much more than a "small research project."

Second, it is absolutely the case that CSEC tracked travellers' movements based on the Internet activity by using IP and ID data and honing in on a major Canadian airport's WiFi system.

It may be about more than that — and I agree with Schneier when he says that it is "actually far more interesting than simply eavesdropping on airport Wi-Fi sessions" because of the wider ramifications of this kind of 'big data' analysis.

But this particular initiative was focused on pulling out a huge trove of user ID and IP data and following users "backward and forward in recent time" to and from a Canadian airport to see if it would be possible to keep tabs movements and trigger alerts based on those movements.

What we reported was accurate and remains so: "Canada's electronic spy agency used information from the free internet service at a major Canadian airport to track the wireless devices of thousands of ordinary airline passengers for days after they left the terminal."

Even CSEC chief Forster has since come out and admitted that a kind of tracking was going on (though he says it didn't occur in "real time," which is not something we actually claimed):

Forster said the agency used metadata to develop a model that showed they could track an internet user's network activity "around a public access mode," and that the tracking didn't happen in real time.

Some of the more insightful analysis on the CSEC affair has come from Bill Robinson, a Canadian surveillance expert described by the Toronto Star as "Canada's authority on CSEC."

Robinson makes some interesting points on the meaning of "tracking" in this context and CSEC's initial denial that it had tracked people — and I think he could be hitting the nail on the head here:

While normal human beings might conclude that both Canadian and foreign travellers were indeed tracked, CSEC's claim may be that only devices were tracked in the specific tests reported in the document. Since no device was tracked specifically on account of the fact that it belongs to a particular person, and the analysis itself (as far as I know) did not seek to associate particular individuals with particular devices (although it may well have utilized information associated or associatable with specific individuals), CSEC may feel it is justified in stating that no individuals were tracked. The same or similar logic seems to underlie the agency's claim that it can collect metadata related to thousands or even millions of Canadians and persons in Canada for foreign intelligence purposes while at the same time stating that its foreign intelligence operations do not "target" any Canadians or persons in Canada.

In a separate blog post after spy chief Forster's testimony before the Canadian Senate committee on Monday, Robinson wrote:

In essence, the government's position is that the metadata project reported by the CBC did take place, that its purpose was to develop targeting and analysis techniques that are in fact now being used operationally by CSEC, and that the collection, analysis, use, and retention of Canadian metadata is a normal part of CSEC's operations, necessary to those operations, and entirely legal. Officials also insist, however, that CSEC does not use the data to target Canadians for foreign intelligence purposes.
To have CSEC now appearing to admit (under pressure) that it is using metadata to conduct domestic monitoring on a mass scale is revelatory — and that is where the focus should be. As I wrote here previously, how "tracking" is being defined as a word should not be the most central point in the debate. The attention should be on CSEC conducting a large-scale surveillance operation on Canadian soil and misleading Canadian citizens about it in a series of public statements. Robinson asks the right questions in his earlier blog post:

If real-world operations are now being conducted using the techniques described in the document, or similar kinds of techniques, those operations will indeed involve the tracking of specific individuals who are either known before the tracking began or identified subsequent to their being singled out by analysis of the data.

Will the government state that no Canadian or foreign travellers have ever been tracked (or, if it prefers, detected in a number of different locations over time) in Canada, either by CSEC or by any other Canadian or allied agency, under any mandate, using these or similar metadata-based techniques?

The EU Parliamentary Inquiry's Report on Mass Surveillance

Saturday, 11 January 2014

After about five months of hearings and investigating, the European Parliament's civil liberties committee has published its report on the revelations about mass surveillance leaked by the American former National Security Agency contractor Edward Snowden.

The comprehensive 52-page report, published Wednesday in draft form [pdf], contains a large number of important findings and recommendations — some of which I think it's worth highlighing here.

The report accuses spy agencies — particularly in the US (NSA) and the UK (GCHQ) — of operating dragnet snooping programs that appear to involve illegal actions. It says that the UK government has on at least two occasions breached the European Convention on Human Rights and the EU Charter in how it has tried to crack down on reporting of the Snowden leaks (examples cited are the detention of former Guardian journalist Glenn Greenwald's partner and the destruction of Guardian computers). In addition, the committee calls for the European Parliament to suspend data sharing deals with the US government, and it says new legal protections are necessary for journalists and whistleblowers.

Crucially, the report does not shy away from attempting to address some of the larger issues — such as the profound and unprecedented existential questions new mass surveillance technologies raise for modern democracies. It calls on US authorities and EU member states to "prohibit blanket mass surveillance activities and bulk processing of personal data," adding:

[The committee] sees the surveillance programmes as yet another step towards the establishment of a fully fledged preventive state, changing the established paradigm of criminal law in democratic societies, promoting instead a mix of law enforcement and intelligence activities with blurred legal safeguards, often not in line with democratic checks and balances and fundamental rights, especially the presumption of innocence. [Emphasis added.]

This kind of policing, it warns, is leading to "every citizen being treated as a suspect." For that reason, the report notes that the committee

condemns in the strongest possible terms the vast, systemic, blanket collection of the personal data of innocent people, often comprising intimate personal information; emphasises that the systems of mass, indiscriminate surveillance by intelligence services constitute a serious interference with the fundamental rights of citizens; stresses that privacy is not a luxury right, but that it is the foundation stone of a free and democratic society; points out, furthermore, that mass surveillance has potentially severe effects on the freedom of press, thought and speech as well as a significant potential for abuse of the information gathered against political adversaries; emphasises that these mass surveillance activities appear also to entail illegal actions by intelligence services and raise questions regarding extraterritoriality of national law.

UK surveillance laws are singled out for criticism, with the inquiry concluding that the UK's legal framework is in need of an overhaul because it is outdated. But the finger is not pointed solely at the spooks in the UK and the US. The report accuses countries including France, Germany, and Sweden of running their own mass surveillance programs, too. It also rightly blasts the general incompetence of oversight committees — both in Europe and the US — that are supposed to be tasked with holding spy agencies accountable:

despite the fact that oversight of intelligence services’ activities should be based on both democratic legitimacy (strong legal framework, ex ante authorisation and ex post verification) and an adequate technical capability and expertise, the majority of current EU and US oversight bodies dramatically lack both, in particular the technical capabilities. [Emphasis added.]

Moreover, it calls on the European Commission — the EU's executive body — to evaluate the possibility of introducing legal liabilities that could be used to punish technology companies for not fixing known vulnerabilities in their software or for installing secret backdoors for spying. It wants the European Parliament to consider only procuring software that is open source, so that the software code can be reviewed to ensure it is secure and free from backdoors inserted for spying. And it also urges European Union member states to initiate investigations into "possible cybercrimes and cyber attacks committed by governments or private actors in the course of the activities under scrutiny."

"Trust has been profoundly shaken," the report says. "Trust between the two transatlantic partners, trust among EU Member States, trust between citizens and their governments, trust in the respect of the rule of law, and trust in the security of IT services...in order to rebuild trust in all these dimensions a comprehensive plan is urgently needed."

It's worth a read if you have the time. The full report is here [pdf].

Rights Groups on Snowden

Friday, 12 July 2013

Edward Snowden is the NSA whistleblower whose document leaks have in recent weeks cracked open the US and UK governments' secret surveillance programs to an unprecedented level of public scrutiny. The former Hawaii-based NSA contractor, 30, is currently holed up in Sheremetyevo airport in Moscow, Russia, as he attempts to seek asylum in a number of countries — fearing persecution if he returns to the United States.

But Snowden's options are limited. The US government has revoked his passport while exerting extraordinary pressure on countries across the world in order to prevent the whistleblower from gaining asylum. This has raised questions about the US government's commitment to international law and has led a number of human rights groups to weigh in with criticism of US officials' actions. Today, Snowden is said to have set up a meeting with groups including Amnesty International in order to discuss his next steps.

Below, I've compiled a quick list for my own reference of the various rights groups that have issued a statement on the Snowden case so far. There may be others that I've missed. If so, add a comment at the bottom or send me a link via Twitter and I'll update this post.

American Civil Liberties Union

"In addition to infringing on Mr. Snowden's right to asylum, [the US government's] actions also create the risk of providing cover for other countries to crack down on whistleblowers and deny asylum to individuals who have exposed illegal activity or human rights violations." (Statement, 11 July.)

Amnesty International

"The US authorities’ relentless campaign to hunt down and block whistleblower Edward Snowden’s attempts to seek asylum is deplorable and amounts to a gross violation of his human rights." (Statement, 2 July.)

Article 19

“The manhunt for Edward Snowden must be stopped. More energy is being spent on arresting one whistleblower that exposed human rights violations than has been spent on finding and arresting perpetrators of war crimes or crimes against humanity." (Statement, 5 July.)

Government Accountability Project (US)

"Snowden disclosed information about a secret program that he reasonably believed to be illegal. Consequently, he meets the legal definition of a whistleblower, despite statements to the contrary made by numerous government officials and security pundits." (Statement, 14 June.)

Human Rights Watch

"[The US government] should not apply a double standard by working against other governments that might extend asylum in this case." (Statement, 3 July.)

“Edward Snowden has a serious asylum claim that should be considered fairly by Russia or any other country where he may apply. He should be allowed at least to make that claim and have it heard... Washington’s actions appear to be aimed at preventing Snowden from gaining an opportunity to claim refuge, in violation of his right to seek asylum under international law.” (Statement, 12 July.)

Index on Censorship

"The mass surveillance of citizens’ private communications is unacceptable – it both invades privacy and threatens freedom of expression. The US government cannot use the excuse of national security to justify either surveillance on this scale or the extradition of Snowden for revealing it." (Statement, 24 June.)

Norwegian PEN

"The threat of criminal prosecution against whistleblower Edward Snowden on the charge of espionage is an allegation against an individual who has used his right to free speech in order to uncover serious abuse, not worthy of a country that abides by the rule of law. By going out with this information, Edward Snowden has questioned the democratic openness of US counter-terrorism strategy. The practice uncovered in the United States is in clear conflict with the principles of a democratic constitutional state." (Statement, 3 July.)

Reporters Without Borders

"Now that Edward Snowden, the young American who revealed the global monitoring system known as Prism, has requested asylum from 20 countries, the EU nations should extend a welcome, under whatever law or status seems most appropriate... [European Union] countries owe Snowden a debt of gratitude for his revelations, which were clearly in the public interest... American leaders should realize the glaring contradiction between their soaring odes to freedom and the realities of official actions, which damage the image of their country." (Statement, 3 July.)

Prism D Notice

Tuesday, 18 June 2013

Following disclosures by the Guardian earlier this month about a US National Security Agency internet surveillance program called Prism, it has emerged that UK government officials issued a so-called "D notice" in a bid to censor coverage of spy tactics.

The D notice following the NSA leaks was reportedly issued to news organisations including the BBC on 7 June, the day after the Prism story broke. Prism is a system used by the NSA to monitor emails, file transfers, photos, videos, chats, and other data. Intelligence gleaned from the system has been passed to GCHQ, the UK's version of the NSA.

The notice to the media organisations was marked "Private and Confidential: Not for publication, broadcast or use on social media," according to Jeff Stein at And Magazine. It added:

There have been a number of articles recently in connection with some of the ways in which the UK Intelligence Services obtain information from foreign sources.

Although none of these recent articles has contravened any of the guidelines contained within the Defence Advisory Notice System, the intelligence services are concerned that further developments of this same theme may begin to jeopardize both national security and possibly UK personnel.

It particularly warned against reporting on:

specific covert operations, sources and methods of the security services, SIS and GCHQ, Defence Intelligence Units, Special Forces and those involved with them, the application of those methods, including the interception of communications and their targets; the same applies to those engaged on counter-terrorist operations.

The D-notice system was first set up in 1912 and operates in accordance with a voluntary code — providing "advice and guidance to the media about defence and counter-terrorist information the publication of which would be damaging to national security." In 2010, for instance, a D notice was reportedly issued prior to WikiLeaks' release of thousands of US government diplomatic cables. A D notice has no formal legal authority, but defying it can make journalists vulnerable to prosecution under the UK's Official Secrets Act.

Snowden's Fate

Monday, 17 June 2013

On Democracy Now today there was an insightful interview with Hong Kong legislator Charles Mok on the potential next steps for US National Security Agency whistleblower Edward Snowden.

Snowden is currently believed to be in Hong Kong after passing a batch of NSA documents revealing top-secret surveillance programs to the Guardian, the Washington Post, and the South China Morning Post. US authorities have initiated a criminal investigation over the leaks and will probably pursue Snowden's extradition in the weeks and months ahead.

Mok talks about what that process could entail, and says that though Hong Kong enjoys independence from mainland China on many issues, the international magnitude of the Snowden case means the final decision that will determine his fate is ultimately likely to be made by central government in Beijing:

Please understand that at least we have a one-country, two-system system in Hong Kong and between Hong Kong and the mainland. So our laws are different from the laws in China. And we do have a border and so on. We do have different governments, even though as a regional government, we do report to the central government.

So I think what we want locally is to make sure that we can protect [Snowden] and make sure that we can live up to our core values and make sure that we treat this person according to all the rights that he should be getting under Hong Kong law. And... exactly what I don’t want to see, is that this sort of political influence to be interfering into the justice process, the judicial process that Mr. Snowden may end up having to get in Hong Kong. If, for example, the US starts by contacting the Hong Kong government to try to initiate an extradition, and if Mr. Snowden decides to try to get asylum or apply for refugee status here in Hong Kong, he — if he chose to do that, if the process comes to that point, he should be getting all the rights. [...]

If the US started to initiate a process [to] say that we want to arrest this person and start an extradition process, then Mr. Snowden could apply in Hong Kong for refugee status. And then there would be at least two tests: first by the United Nations High Commission on Refugees to determine whether or not, for example, that he will face torture at home and whether or not this is political persecution and so on, and second, also by the Hong Kong court. [...]

He will be accorded rights to appeal all the way up to our highest court in Hong Kong. So, assuming that money and financial issues — because you do need to get lawyers and so on — assuming those are not an issue, these processes in the past could have taken quite a bit of time. But... if [Snowden] isn’t successful and there has to be a final decision to be made about the extradition, our chief executive in Hong Kong, which is pretty much [like] our president... he will have to make the final decision. But because this case very likely will involve foreign relations, then he has to consult the central government. So, in the end, it means that the process can be a pretty prolonged process, and, second, Beijing will probably come into the equation to make a final decision in the end.

You can watch the full interview here.

NSA Chief Quizzed Over Legality of Phone Records Grab: Transcript

Thursday, 13 June 2013

General Keith Alexander, the chief of the US National Security Agency, today appeared before a Senate committee and was quizzed publicly for the first time on issues related to the agency's recently revealed surveillance programs.

Most of the questions Alexander faced concerned the secret mass retention of Americans' phone records, exposed by the Guardian last week, which the spy chief said is necessary to conduct retrospective surveillance of patterns of communication during counter-terrorism investigations — enabling the agency to go "back and time" to monitor who has called whom, when, and for how long.

Perhaps the most notable point in Alexander's appearance came during an exchange with Oregon Senator Jeff Merkley (Democrat), who asked a few specific, probing questions about the section of the Patriot Act (215) being used to justify storing the records. Merkley seemed to believe the NSA had exceeded its authority in mass retaining the records, and I think his comments pinpoint a crucial part of the legal debate about the scope of the surveillance that we will see more of in the weeks ahead. Merkley also pressed for secret interpretations of the law being used by the government to justify the surveillance to be declassified and published, a point that Alexander seemed to agree was necessary though said he couldn't guarantee it because he was "not the only decision maker in the administration."

See the relevant part of the exchange below:

Sen. Merkley: You referred to section 215 [of the Patriot Act] and 215 requires for an application for production of any tangible thing. It says in it that this application must have a statement of facts showing reasonable grounds that the tangible things sought are relevant to an authorised investigation. So we have several standards of law embedded in this application: A statement of facts, reasonable grounds, and tangible things that are relevant to an authorised investigation.

Now as it's been described in this conversation and in the press, the standard for collecting phone records on Americans is now all phone records, all the time, all across America. How do we get from the reasonable grounds, relevant authorised investigation, statement of facts, to all phone records, all the time, all locations? How do you make that transition and how has the standard of the law been met?

General Alexander: So this is what we have to deal with the court and I think that... we go through this court process... it's a very deliberate process where we meet all of those portions of the 215. We lay out for the court what we're going to do and to meet that portion we just said. The answer is we don't get to look at the data, we don't get to swim through the data....

Sen. Merkley: Let me stop you there, because these are requirements to acquire the data, not to analyze the data, to acquire the data ... this is the application to acquire the data. So here I have my Verizon phone, my cell phone, what authorized investigation gave you the grounds for acquiring my cellphone data?

General Alexander: On this part here, on the legal standards and stuff, on this part here I think we need to get Department of Justice and others because it is a complex area and you're asking a specific question. I don't want to shirk that but I want to make sure I get it exactly right. And so I do think part of what we should do is perhaps at the closed hearing tomorrow walk through that with the intent of taking what you've asked and seeing if we can get it declassified and out to the American people so they can see how exactly how we do it because I do think that should be answered.

Sen. Merkley: In between these two pieces, the FISA court gives an interpretation of the plain language of the law, their interpretation is what translates the standards of the law into what is governable in terms of what you can do. I had an amendment last December that said these findings of law that translate the requirements that are in the law into what is permissible needs to be declassified so we can have the debate. I believe that what you just said is that you want to have that information to be declassified that explains how you get from these standards of law to the conduct that has now been presented publicly. Did I catch that right and do you support the standards of law, the interpretations of the FISA court of the plain language to be set before the American people so we can have this debate?

General Alexander: I think that makes sense. I'm not the only decision maker in the administration on this process so there are two issues I'm not equivocating. I just want to make sure that I put this expectation exactly right and that is I don't want to jeopardize the security of Americans by making a mistake and saying yes we're going to do all that, but the intent is to get the transparency there.

So Senator I will work hard to do that, and if I can't do that I will come back to you and tell you why and we will have that discussion and run it out and I defer to the chair of the intelligence committee. But I think that's reasonable to get this out. Having said that I don't have the legal background that perhaps you have in this area.

I want this debate out there for a couple of reasons. I think that what we're doing to protect American citizens here is the right thing. Our agency takes great pride in protecting this nation and our civil liberties and privacy and doing it in partnership with this committee, with congress and the courts. We aren't trying to hide it we are trying to protect America so we need your help in doing that. [...]

Sen. Merkley: General I thank you for your statement of support. I also want to thank chair Feinstein who helped develop and send a letter expressing this concern about the secrecy of the interpretations of the FISA court ... I think it's time that [the FISA interpretations] become understandable and public because otherwise how in a democracy do you have a debate if you don't know what the plain language [of the law] means. I do have concerns about that translation and I will continue this conversation.

The NSA's Prism & its Capabilities

Saturday, 8 June 2013

It has been two days now since the Guardian and the Washington Post reported that the US National Security Agency has "obtained direct access to the systems of Google, Facebook, Apple and other US internet giants, according to a top secret document." As part of a surveillance program called Prism, the NSA and the FBI, the Post reported, are "extracting audio and video chats, photographs, e-mails, documents, and connection logs that enable analysts to track foreign targets."

But since the initial reports, the Internet companies have all denied this "direct access" claim [1], which prompted the Guardian on Saturday to publish the secret source document showing the NSA's description of Prism as program enabling "collection directly from the servers of these service providers: Microsoft, Yahoo, Google, Facebook, Paltalk, AOL, Skype, YouTube, Apple."

So what exactly is Prism and how does it work?

In my view, it is possible too much has been read into the NSA's description of Prism as enabling "collection directly from the servers." Taken in isolation, this statement does not necessarily mean that the NSA has direct and unrestricted access to these companies' central computers to sift through troves of private data whenever they feel like it, which is what the initial reporting seemed to imply. "Collection directly from the servers" could feasibly mean Prism is the codename the NSA uses for a "separate, secure portal" that is linked to or located within the servers of these companies. As the New York Times reported on Friday:

[I]nstead of adding a back door to their servers, the companies were essentially asked to erect a locked mailbox and give the government the key, people briefed on the negotiations said. Facebook, for instance, built such a system for requesting and sharing the information, they said. [...] In at least two cases, at Google and Facebook, one of the plans discussed [with the government] was to build separate, secure portals, like a digital version of the secure physical rooms that have long existed for classified information, in some instances on company servers. Through these online rooms, the government would request data, companies would deposit it and the government would retrieve it, people briefed on the discussions said.

This could still be understood as "collection directly from the servers," but the distinction is that it is not "open-ended access." Under this system, the NSA — or the FBI on behalf of the NSA — would obtain a court order under the Foreign Intelligence Surveillance Act and use it to demand the respective company turn over various data into its "separate, secure portal." The scale of the data grab, though somewhat limited in scope by the court order, could still be huge. As was separately disclosed earlier this week, for instance, a single FISA order can be used to obtain millions of phone records.

The confusing thing about this picture of Prism, however, is that it still conflicts a little bit with how the system was portrayed by the newspapers that reported on the secret documents. The description of a "separate, secure portal" like an "online room" where companies "deposit" data for the government suggests that the transaction happens in static, incremental stages: data is requested by the government, data is passed over by the company, then the government sifts through it. But the Washington Post's reporting suggests the transaction does not occur in static stages because it can involve real-time monitoring:

According to a separate “User’s Guide for PRISM Skype Collection,” that service can be monitored for audio when one end of the call is a conventional telephone and for any combination of “audio, video, chat, and file transfers” when Skype users connect by computer alone. Google’s offerings include Gmail, voice and video chat, Google Drive files, photo libraries, and live surveillance of search terms.

Additionally, the source who disclosed the document, described as a career intelligence officer, told the Post: “They quite literally can watch your ideas form as you type.”

So this means that if the companies are not providing "direct access" to their servers to mine data indiscriminately, then the "separate, secure portal" can also be used not just to "deposit" data, but also to obtain access to real-time communication flows, presumably authorized by a FISA order and implemented by the respective company that receives it (Google, Apple, Facebook, etc). Indeed, in a statement Sunday, the US director of national intelligence James Clapper said in a statement that Prism was authorized under Section 702 of FISA and he described the program as an "internal government computer system used to facilitate the government's statutorily authorized collection of foreign intelligence information from electronic communication service providers."

The question, then, is how sweeping the FISA orders are. The Post reported that "from inside a company’s data stream the NSA is capable of pulling out anything it likes" and also said that the NSA's spies use Prism through a "Web portal" that entails entering “'selectors,' or search terms, that are designed to produce at least 51 percent confidence in a target’s 'foreignness'." This suggests to me that we are talking about dragnet FISA orders that oblige the companies to turn over huge amounts of data, some in real time, handled by the NSA on a system codenamed Prism, which may involve the NSA having its own "secure portal" within or at least linked to company servers.

The companies would not know that they were participating in anything named "Prism" — that is just the NSA's internal codename for the program. From the companies' perspective, all they are doing is responding to court-authorized FISA orders. What I would like to hear each of the companies publicly explain is whether they have any kind of interface for facilitating government FISA orders built within or linked to their server infrastructure. (See this update below.)

I should note that all of the above is my own speculation based on an analysis of the available facts. Other theories I have heard proposed include that the NSA has essentially secretly "hacked" the respective companies' servers by spoofing encryption certificates. But I think that is far-fetched and that what I have suggested here is likely more in line with what is happening, though, again, I am only speculating. Without access to the full leaked source documents, it is difficult to comprehensively analyse the details. Only a fraction of the secret documents has been published so far, presumably for legal and/or editorial reasons. There are reportedly 41 top-secret leaked PowerPoint slides in total related to Prism but only about four or five have been made available by the Guardian and the Post. It is my hope that they will all surface eventually so we can get a better and more accurate understanding of what this controversial surveillance program entails.

*****

[1] Facebook said it does not "provide any government organization with direct access to Facebook servers." Apple said "we do not provide any government agency with direct access to our servers." Microsoft said "If the government has a broader voluntary national security program to gather customer data we don’t participate in it.” Yahoo said "We do not provide the government with direct access to our servers, systems, or network.” Paltalk said it "does not provide any government agency with direct access to its servers.” AOL said that it does not "provide any government agency with access to our servers.” And Google, too, said that it had "not joined any program that would give the U.S. government — or any other government — direct access to our servers."

*****

UPDATE, 9 June 2013: A new report from the Washington Post has some additional interesting details about Prism. The Post has spoken with anonymous executives at some of the companies linked to the program, who "acknowledged the system’s existence and said it was used to share information about foreign customers with the NSA and other parts of the nation’s intelligence community." The report adds:

According to slides describing the mechanics of the system, PRISM works as follows: NSA employees engage the system by typing queries from their desks. For queries involving stored communications, the queries pass first through the FBI’s electronic communications surveillance unit, which reviews the search terms to ensure there are no U.S. citizens named as targets.

That unit then sends the query to the FBI’s data intercept technology unit, which connects to equipment at the Internet company and passes the results to the NSA.

PRISM allows “collection managers [to send] content tasking instructions directly to equipment installed at company-controlled locations,” rather than directly to company servers. The companies cannot see the queries that are sent from the NSA to the systems installed on their premises, according to sources familiar with the PRISM process.

This seems in line with my theory above about the functionality of the system — that it is a "secure portal" within or at least linked to the companies' servers. What is particularly notable is the role of the FBI in reviewing the search terms, and the fact that the companies apparently do not see what the NSA is searching for. I think this hammers home the point regarding the sweeping scope of the FISA orders, which we need to know much more about. Even without any further information, however, it is clear to me that Prism has huge ramifications — in particular for all non-US citizens using services like Gmail, Skype, and Hotmail.

State Secrets Culture and Warrantless Wiretapping

Sunday, 30 September 2012

In the days following 11 September 2001, many things changed in the United States. The terrorist attacks that took place on that day quickly prompted tightened security and, crucially, heightened use of surveillance tactics.

It is now well documented how eavesdropping agency the National Security Agency (NSA) was given unprecedented authority to intercept communications flowing to and from the country after 9/11. As the New York Times reported in its 2005 exposé: "The international telephone calls and international e-mail messages of hundreds, perhaps thousands, of people inside the United States without warrants over the past three years in an effort to track possible 'dirty numbers' linked to al Qaeda."

This revelation led to a lawsuit (Jewel v. National Security Agency) which alleged the US government was engaged in "the biggest fishing expedition ever devised, scanning millions of ordinary Americans' phone calls and emails for 'suspicious' patterns." The lawsuit was originally dismissed back in 2010 on the grounds that it didn't sufficiently allege "personal injury" was caused by the warrantless snooping. However, this decision was later reversed and now an appeals court is taking another look at the case.

As it has done previously, the US government is asserting its state secrets privilege as part of an attempt to stop the case moving forward. In a motion to dismiss submitted to the appeals court earlier this month, the government said that invoking the privilege was necessary "in order to prevent exceptionally grave damage to national security." It denied the allegation that it had "indiscriminately collected the content of millions of communications sent or received by people inside the United States." But added that it could not prove this before a court because doing so would "risk or require the disclosure of highly classified NSA intelligence sources and methods."

Such claims from the NSA are not new. The agency has a track record of arguing it is entitled to avoid public scrutiny because doing so would pose some sort of grand danger. Back in 1998, for instance, the agency admitted it had spied on Princess Diana and was holding more than a thousand pages of documents in a "Diana file." But the NSA declined to disclose the information held about the Princess because it would reveal — you guessed it — "sources and methods."

The problem with the NSA's position is that it is questionable. The NSA seems to think that disclosing even the slightest detail about what it is doing would aid people who are engaged in plotting against the US. But organised terror groups or oppositional foreign government agents will already presume that every phone call they make and email they send can be intercepted by agencies like the NSA. And besides this, many of the NSA's clandestine methods can be learned by anyone with access to Google because of details made public by whistleblowers. A sworn 2006 declaration by a former engineer for the AT&T telecom firm, for example, stated the NSA was routing AT&T communications through a secret "secure room" where they could be intercepted. This, a former NSA employee said earlier this year in his own sworn declaration, involved the use of a "Semantic Traffic Analyser," which would allow the NSA to mine "addresses, locations, countries, and phone numbers, as well as watch-listed names, keywords, and phrases" from within the data flowing through communication networks.

So given that such detailed information is already in the public domain about the NSA's snooping activities, the "sources and methods" justification for secrecy seems at best naive, at worst disingenuous.

The knee-jerk reaction of governments and groups with power is often to resort to secrecy in order to avoid controversy, to protect reputations, and to ultimately avoid accountability. That's why the use of state secrets to protect the NSA's wiretapping program from public scrutiny in a court looks suspect — particularly as the US government has form abusing official secrecy to conceal scandals.

As was revealed by the British politician David Davis during an astonishing speech in the UK parliament in March this year, the very same state secrets privilege currently being put forward to protect the NSA from court was previously used as part of an extraordinary cover-up involving US intelligence agencies (including the NSA).

In the late 1990s, as part of a covert effort called Operation Foxden, the FBI, the NSA and the US Central Intelligence Agency (CIA) were working with three businessmen — one Afghan-American citizen, two British — to introduce telecommunications infrastructure into Afghanistan. They planned to rig it with extra circuits in order to listen live to every landline and mobile phone call across the whole of the country. But there was a turf war between the three US agencies, which led to Operation Foxden being delayed some 20 months. It is believed, had it been introduced earlier, it may have helped gather intelligence about the 9/11 terror plot — possibly preventing it from ever happening.

The businessmen involved in helping set up the Afghan network later had a dispute over money, which in 2002 ended up being taken to a court in New York. A year later, the case was suddenly shut down by a judge who cited the state secrets privilege. It turned out that the two British men involved in the deal — Stuart Bentham and Michael Cecil — were being defrauded by the Afghan-American, Ehsanollah Bayat. But they were not allowed to have their case heard in court because the US government did not want its secrets laid bare — in this case showing that a dispute between the intelligence agencies had delayed a massive spy project that might have helped prevent a catastrophic terrorist attack.

Last year, a Vanity Fair writer found out some details about Operation Foxden and approached the CIA for comment about it. Surprisingly, given the previous iron-fisted attempt to keep the story secret and out of courts, the CIA made no attempt to suppress Vanity Fair's report. Why? According to a US source quoted by David Davis in his speech to the British parliament on the subject: "Ten years have passed since 9/11, and the culpable people have moved on, so it’s no longer embarrassing."

The short remark was as shocking as it was revealing. As Davis noted:
This demonstrates only too clearly that although the aim of the American state secrets privilege is to protect national security, in practice it is often used to eliminate embarrassment — political, bureaucratic, organisational or individual embarrassment at past failures ... It also shows how giving a government agency an absolute right to secrecy encourages bad behaviour. The American agencies could easily have stopped the defrauding of British citizens without the matter going to court, given their enormous leverage in the matter. Instead, they chose to suppress justice.

Could the current attempt to stop the case against the NSA over the domestic surveillance programme be a similar bid to "suppress justice" and protect reputations? It is not a far-fetched possibility. One key figure in the warrantless wiretapping saga has even openly gloated about how he is pleased state secrets privilege is being used to shield him. General Michael Hayden, who was the director of the NSA between 1999 and 2005, said with a smirk a few weeks ago that he was "personally grateful to Obama for using the state secrets argument to stop some of these court proceedings — because I am personally named in some of these courts."

Perhaps most alarming, though, is the bigger picture at play here. When any democratic government repeatedly resorts to secrecy to protect the disclosure of information the public has a right to know, it has lost its way. It is broken, existentially fractured. In my own experience as a journalist, the US has a stronger culture of freedom of information than the UK does, but at the highest echelons of power there remains a definite absence of transparency and accountability. The ongoing surveillance case, and the aggressive bid to suppress it, is only the latest example.

Ex-US Spy Chief On Surveillance, Rendition, and Targeted Killings

Sunday, 9 September 2012

Secret black sites, illegal surveillance of American citizens' communications, waterboarding — General Michael Hayden overseen it all, and he doesn't have a single regret.

Between 1999–2005 Hayden was director of US eavesdropping agency the NSA, and between 2006-2009 he was director of US spy agency the CIA. He served under the presidencies of Bill Clinton, George W. Bush, and Barack Obama.

On Friday, Hayden, who is now retired, gave a speech at the Gerald R. Ford School of Public Policy in the state of Michigan. Over the course of about 60 minutes, he reflected at length on everything from extrajudicial killings of suspected terrorists to extraordinary renditions (or kidnapping) of suspected al-Qaeda members. It was an unapologetic speech that occasionally verged into sociopathic territory. It was also, at times, revelatory.

Here are a few highlights:

  • Approximately two hours after the first terror attack on New York in September 2001, Hayden used his authority as chief of the NSA to "dial things up" and get more "aggressive" with communications interception. This prompted a colleague at the CIA to tell him, jokingly, that he was "going to jail," and in turn led President George W. Bush to authorise the domestic wiretapping program that permitted the NSA to spy on emails and phone calls of Americans without a warrant.
  • Hayden is "personally grateful" to President Barack Obama for protecting him from being held to account in a court of law by invoking state secrets privilege.
  • A 2008 amendment to the Foreign Intelligence and Surveillance Act "legitimated" everything president Bush had authorised the NSA to do regarding the domestic wiretapping of communications and "gave the NSA a great deal more authority to do these kinds of things."
  • Hayden says there has been "powerful continuity" between the counter-terror tactics used by President Bush and President Obama, including on extraordinary rendition. However, he said one area of discontinuity is that Obama has a preference for killing terror suspects as opposed to capturing them — because it is now considered "so politically dangerous and so legally difficult" to capture.
  • On 11 September 2001, the day of the Twin Towers attacks, Hayden explained how he stood behind blacked out curtains at an NSA building in Washington and thought to himself, "things are going to be different around here tomorrow. We have entered into an entirely new era."

    Within about two hours of the first plane striking the first World Trade Center tower that morning, Hayden said he had used his authority to "dial things up a little bit" at the NSA in order to give the agency "a higher probability we would intercept those kind of messages that would tell us about the next attack." Hayden didn't elaborate exactly on what it means to "dial things up," but I think it's safe to assume it means intercepting a much larger volume of communications. (Hayden said that because he had "dialed things up" then-CIA director George Tenet a few days later joked to him that he was "going to jail" but President Bush and Vice-President Dick Cheney said it was alright because they would "bail him out.")

    In the weeks ahead, President Bush gave Hayden more powers. This led to the domestic wiretapping scandal revealed by the New York Times in 2005, which exposed how the NSA had been granted authority to spy on "the international telephone calls and international e-mail messages of hundreds, perhaps thousands, of people inside the United States without warrants over the past three years in an effort to track possible 'dirty numbers' linked to al Qaeda."

    But that was just the start. And despite the controversy around the domestic wiretapping exposed by the New York Times, as Hayden said in his speech, a 2008 amendment to the Foreign Intelligence and Surveillance Act "not only legitimated almost everything President Bush had told me to do under his article two authorities as commander in chief but in fact gave the NSA a great deal more authority to do these kinds of things."

    Aside from the surveillance, Hayden also overseen a variety of other ghoulish new tactics brought in amid the terror fears. There was the kidnapping, or extraordinary rendition, of suspects from one country to the other — often to countries where they were allegedly subject to torture, like Egypt and Libya. There was also the secret black sites — hidden prisons in locations such as Poland and Thailand — where terror suspects were subjected to a variety of so-called 'enhanced interrogation techniques' like waterboarding, which makes a person feel like they are drowning. Not to mention the Guantanamo Bay prison, the indefinate detention of accused terrorists, and the birth of remote-controlled drone strikes as a method of 'targeted killing' or extrajudicial assassination — however you want to term it.

    None of this Hayden has any reservations about. In his speech he explained it was all about how America had to "take the fight to the enemy" wherever he (or she) may be. He even recounted a meeting in Germany during the spring of 2007, where he gave a speech to a room of about two dozen people including representatives from every country in the European Union. He spoke about extraordinary rendition and America's tactics in the War on Terror. Not one person present in the room, he said, agreed with any of the justifications he gave for the use of such tactics. But this didn't dissuade him. His essential position could be summarised as, "how could we possibly be wrong?" Perhaps a mindset that can be attributed to American exceptionalism, the belief that the US has a unique mission in the world to spread its ideals.

    Hayden was evidently not preoccupied at all with minor irritations like human rights obligations and international law. Rather, he explained how his main concern was in early 2009, when Barack Obama was sworn in to the White House. He was worried that Obama, a Democrat who had voiced strong criticism of George W. Bush's counter-terror policies, might seek to scale back efforts in the War on Terror. Hayden had at this point moved to the CIA, where he was director. But his fears about Obama being a soft touch were quickly alleviated.

    Obama continued almost all of Bush's policies, Hayden explained, because he realised "we are at war" with al-Qaeda and its affiliates. In the end, there was a "powerful continuity" between Bush and Obama, Hayden said.

    "Targeted killings have continued, in fact if you look at the statistics targeted killings have increased under Obama" ... "renditions, that's the extrajudicial movement of suspected terrorists from place A to place B — our policy is the same under President Obama as it was under President Bush and President Clinton."

    He went on: Obama "didn't shut Guantanamo" and he also took the same position as Bush on "indefinite detention and state secrets" ... "I am personally grateful to Obama for using the state secrets argument to stop some of these court proceedings — because I am personally named in some of these courts."

    Perhaps most revealing, the one discontinuity between Bush and Obama from a counter-terror perspective, Hayden said, was (and is) the difference between the presidents when it comes to killing or capturing terror suspects. Under Bush many suspected insurgents were captured, incarcerated and interrogated. Under Obama, according to Hayden, just one person has been held outside of Iraq and Afghanistan since January 2009. Obama has been accused of preferring to kill than capture, though this is something he has denied. He said in a recent interview that "our preference has always been to capture when we can because we can gather intelligence" but that it’s sometimes "very difficult to capture them."

    According to Hayden, however, the kill rather than capture policy is a political decision.

    "We have made it so politically dangerous and so legally difficult that we don't capture anyone anymore. We take another option. We kill them," he said. And in a thinly veiled criticism of Obama's aggressive killing policy, Hayden added: "We're losing the opportunity to interrogate and to learn about our enemy."

    When you weigh up Hayden's comments, the essence of what he is saying is quite extraordinary. This is a man who openly admits has has no qualms whatsoever about some of the most brutal and contentious tactics that have been used by the United States over the last decade or so. The wiretapping, the renditions that contravene international law, the interrogation techniques widely considered to constitute torture, the extrajudicial killings in countries like Pakistan, Yemen and Somalia, where there has been no formal declaration of war. And here he is applauding Barack Obama, a president elected on a platform oppositional to many of these tactics, for keeping up a "powerful continuity." In fact, his only criticism of Obama is that he is doing too much killing.

    The other thing that struck me about Hayden in this speech was his general demenour. The way he was making quips and smirking about how he was thankful Obama was protecting him from being held to account in American courts over the actions of the agencies he was in charge of. There was an arrogance about his comments, an air of impunity. Hayden came off as a man with an almost sociopathic disdain for the basic rule of law.

    His justification for the controversial tactics was simple: al-Qaeda and its affiliates constitute a "new threat to old institutions." Terror groups have no regard for laws like the Geneva Convention and blur the distinction between civilian and combatant. Therefore, and this is the core logic underpinning Hayden's remarks, America's security apparatus has to do the same. It has to evolve (or, rather, regress) and "take the fight to the enemy" using whatever means necessary.

    The problem is that there is no conclusive evidence anywhere to suggest that this is a successful method of combating the threat in the first place. Killing people and indefinitely detaining them, implementing secret systems of mass surveillance — these are things that have lowered America's standing in the world. If you flout the rule of law, if you sink to a level of legal nihilism, you immediately lose the moral high-ground. You also make more enemies than friends. As we are seeing with US drone strikes in Yemen, where many civilians have been killed by American missiles, the US may only be inspiring a new generation of Jihadists by spreading fear across entire regions of countries while pursuing small handfuls of men who have been deemed a threat through a process that is itself contentious and conceivably highly flawed. Hayden seems convinced that what he presided over at the NSA and CIA was right, just, and absolutley necessary to protect America. But he has not won the argument and I don't think he ever will.

    He told the audience at one point that they, as Americans, in reference to the CIA, were "blessed as a people with the talent and the morality of the folks who are in your chief espionage service." I couldn't help recall at this point the case of a Muslim cleric known as Abu Omar. He was accused of plotting terrorism and snatched by CIA agents from a street in Milan, Italy in broad daylight on 17 February, 2003. Omar was taken to Egypt where he was imprisoned in Tura, 20 miles south of Cairo, and handed over to Egyptian security services. He said he was twice raped, suffered electroshock treatment and lost the hearing in his left ear due to repeated beatings. He was eventually released by the Egyptian government in 2007, after a state security court ruled that his detention was unfounded. There are many cases similar to this. All of them call into question the morality of those involved, and that includes General Michael Hayden and the staff he commanded.