Showing posts with label civil liberties. Show all posts
Showing posts with label civil liberties. Show all posts

Canada's WiFi Surveillance and CSEC's Non-Denial Denials

Saturday, 1 February 2014

On Thursday, a report I worked on with Glenn Greenwald and Greg Weston was published in Canada, revealing how the country's spy agency CSEC secretly developed a program to monitor WiFi users in a major Canadian airport.

The piece, based on documents leaked by the former US National Security Agency contractor Edward Snowden, has led to CSEC being accused of acting unlawfully and has triggered calls for better oversight of the agency.

But one of the most intriguing aspects of the fallout from the story has been the Canadian government's response — which merits some scrutiny and analysis.

First, some context.

Back in November, Greenwald, Weston and I reported separate revelations about Canada's role in an NSA operation to spy at the G8 and G20 summits in Canada in 2010. In response, CSEC's chief John Forster claimed in response to reporters' questions:

What I can tell you is that CSEC, under its legislation, cannot target Canadians anywhere in the world or anyone in Canada, including visitors to Canada.

During a speech in October, Forster had made a similar statement:

I can tell you that we do not target Canadians at home or abroad in our foreign intelligence activities, nor do we target anyone in Canada. In fact, it's prohibited by law. Protecting the privacy of Canadians is our most important principle.

And again, in January, he repeated this assertion in a letter to a Canadian newspaper:

Under the law, CSE’s foreign intelligence mandate specifically dictates that our activities be directed only at foreign entities, and not at Canadians or anyone in Canada. That is the law and we fully respect that.

Having analysed Canadian documents in the Snowden material, these statements struck me as quite astonishing.

Why? Because one of the top-secret Snowden documents revealed that, in 2012, CSEC had set up a program that involved monitoring WiFi usage at a large Canadian airport. The secret files showed how CSEC was able to use a huge amount of data about the WiFi connections to follow users "backward and forward in recent time" — identifying visits to hotels, other airports, Internet cafes, coffee shops, and a library.

The tactic is described by CSEC in the files as "IP profiling" — a surveillance method that can be used to track users' movements over time. In one case, as we reported at CBC on Thursday, the spy agency says that it performed a sweep of an entire "modest-sized" city and identified 300,000 user IDs:

The "mission impact" of the tactic, according to the document, is that it can alert spies to "target country location changes" and "webmail logins with time-limited cookies":

The full document [pdf] speaks for itself. It illustrates a secret surveillance operation was conducted on Canadian soil — sweeping up metadata on the WiFi usage of thousands of people not suspected of any crime. Equally significant, the revelation contradicts CSEC chief Forster's repeated assertion that "we do not target Canadians at home or abroad in our foreign intelligence activities, nor do we target anyone in Canada."

After we reported the airports story, it got more interesting.

CSEC issued a statement that was notable for three reasons. First, the agency did not repeat its previous mantra claiming not to "target anyone in Canada." Second, it appeared to make an admission that it is sweeping up metadata within Canada, saying that it was "legally authorized" to "collect and analyze" this information. And third, it issued a fresh denial, saying that "no Canadian or foreign travellers were tracked. No Canadian communications were, or are, targeted, collected or used."

Shortly afterwards, on Friday, a similar denial was made by the Canadian prime minister's parliamentary secretary, who launched a bizarre personal attack on Greenwald while claiming that the "facts" were that "nothing in the stolen documents showed that Canadians' communications were targeted, collected, or used, nor that travellers' movements were tracked."

But these denials are hollow.

It's a straw man to claim that the revelations were about communications being "targeted, collected, or used." That is not what our story was about. The issue at hand is how CSEC initiated a program to sweep up information showing when people are connecting to WiFi networks and using this information to build "profiles" of their movements back and forward in time.

And that brings us to the more important point. CSEC and the prime minister's secretary claimed that "no Canadian or foreign travellers were tracked." However, what they did not say was how they were defining the word "tracked."

The documents quite clearly show how the agency used user "IP profiles" to monitor WiFi users' movements over time, with this capability enabling it to generate "alerts" when a person relocates to another country.

The dictionary definition of "tracking" says that it means "the act or process of following something or someone." CSEC's IP profiling is exactly that — monitoring users' location and keeping tabs on where they are. Indeed, the document says as much, outlining how CSEC uses this tactic to "follow IDs backward and forward in recent time." The documents also mention how CSEC used tools called "Quova" and "Atlas database" — which are technologies used to pinpoint the geolocation of an IP address.

CSEC's denial that it "tracked" Canadians or foreign travellers, I think, hinges upon a narrowly defined interpretation of the word. The US Department of Defence, for instance, uses "tracking" as a specific technical term meaning the "precise and continuous position-finding of targets by radar, optical, or other means." CSEC's IP profiling definitely fits the dictionary definition of "tracking" as it is understood by most people — but does it fit the narrower military definition? Perhaps CSEC believes that IP profiling does not constitute "precise and continuous" tracking. But if so, it should be explaining this — as otherwise its denial is highly misleading.

Spy agencies are professionals in the art of deception, and sometimes that seems to be reflected in their public relations strategy. Afterall, we have seen misleading denials issued repeatedly by the National Security Agency and its Five Eyes counterparts about various surveillance revelations in recent months. Again and again, officials have used narrowly defined words or jargon terms in a carefully crafted way in order to issue non-denial denials in which they appear to refute an allegation but on closer reading do not really refute it at all.

The ultimate point here is that the tactics being used by CSEC and the Canadian government to deflect criticism of their secret surveillance programs merit as much attention as the revelations themselves. That is especially clear when, in response to disclosures about their secret programs, senior government officials launch childish character assassination attempts against the journalists who reported the information. In a democratic society, surely a higher standard is required. It is not enough for governments and spy agencies to spit out a few indignant statements and denials with the expectation that people should just blindly trust that they are telling the truth.

Also, no matter how "tracking" is being defined, what is clear is that CSEC was (and our sources say still is) running a large-scale surveillance operation on domestic soil, seriously calling into question spy chief Forster's previous statements that "our activities" are not directed "at Canadians or anyone in Canada." The CSEC boss is due to appear before a Senate committee hearing on Monday. Hopefully Canada's lawmakers will take the opportunity to ask some probing questions.


UPDATE, 7 February 2014: Since the story was published last week, there have been several developments. There have been more calls for an independent review of CSEC's activities, while spy chief Forster was forced to publicly defend the surveillance in Monday's Senate hearing.

There have also been some interesting analyses of the leaked documents worth responding to.

First, the surveillance blog Electrospaces claimed that the secret documents seemed to have been "incorrectly interpreted" in our CBC report. The blog published an anonymous analysis from someone who says that CSEC's surveillance project was "was not surveillance of Canadian citizens per se but just a small research project." The second analysis came from Bruce Schneier, who claimed that it was "not really true" that CSEC used "airport Wi-Fi information to track travellers."

First of all, it is a mischaracterization to claim that the CSEC project was just a small research project that didn't implicate Canadians "per se." It was part of a pilot initiative that involved sweeping up data on hundreds of thousands of people — many of whom would have been Canadian citizens. Our sources for the story told us that the pliot had since gone live — i.e. that it had gone from being a "proof-of-concept" to an operationally active domestic program. This is about much more than a "small research project."

Second, it is absolutely the case that CSEC tracked travellers' movements based on the Internet activity by using IP and ID data and honing in on a major Canadian airport's WiFi system.

It may be about more than that — and I agree with Schneier when he says that it is "actually far more interesting than simply eavesdropping on airport Wi-Fi sessions" because of the wider ramifications of this kind of 'big data' analysis.

But this particular initiative was focused on pulling out a huge trove of user ID and IP data and following users "backward and forward in recent time" to and from a Canadian airport to see if it would be possible to keep tabs movements and trigger alerts based on those movements.

What we reported was accurate and remains so: "Canada's electronic spy agency used information from the free internet service at a major Canadian airport to track the wireless devices of thousands of ordinary airline passengers for days after they left the terminal."

Even CSEC chief Forster has since come out and admitted that a kind of tracking was going on (though he says it didn't occur in "real time," which is not something we actually claimed):

Forster said the agency used metadata to develop a model that showed they could track an internet user's network activity "around a public access mode," and that the tracking didn't happen in real time.

Some of the more insightful analysis on the CSEC affair has come from Bill Robinson, a Canadian surveillance expert described by the Toronto Star as "Canada's authority on CSEC."

Robinson makes some interesting points on the meaning of "tracking" in this context and CSEC's initial denial that it had tracked people — and I think he could be hitting the nail on the head here:

While normal human beings might conclude that both Canadian and foreign travellers were indeed tracked, CSEC's claim may be that only devices were tracked in the specific tests reported in the document. Since no device was tracked specifically on account of the fact that it belongs to a particular person, and the analysis itself (as far as I know) did not seek to associate particular individuals with particular devices (although it may well have utilized information associated or associatable with specific individuals), CSEC may feel it is justified in stating that no individuals were tracked. The same or similar logic seems to underlie the agency's claim that it can collect metadata related to thousands or even millions of Canadians and persons in Canada for foreign intelligence purposes while at the same time stating that its foreign intelligence operations do not "target" any Canadians or persons in Canada.

In a separate blog post after spy chief Forster's testimony before the Canadian Senate committee on Monday, Robinson wrote:

In essence, the government's position is that the metadata project reported by the CBC did take place, that its purpose was to develop targeting and analysis techniques that are in fact now being used operationally by CSEC, and that the collection, analysis, use, and retention of Canadian metadata is a normal part of CSEC's operations, necessary to those operations, and entirely legal. Officials also insist, however, that CSEC does not use the data to target Canadians for foreign intelligence purposes.
To have CSEC now appearing to admit (under pressure) that it is using metadata to conduct domestic monitoring on a mass scale is revelatory — and that is where the focus should be. As I wrote here previously, how "tracking" is being defined as a word should not be the most central point in the debate. The attention should be on CSEC conducting a large-scale surveillance operation on Canadian soil and misleading Canadian citizens about it in a series of public statements. Robinson asks the right questions in his earlier blog post:

If real-world operations are now being conducted using the techniques described in the document, or similar kinds of techniques, those operations will indeed involve the tracking of specific individuals who are either known before the tracking began or identified subsequent to their being singled out by analysis of the data.

Will the government state that no Canadian or foreign travellers have ever been tracked (or, if it prefers, detected in a number of different locations over time) in Canada, either by CSEC or by any other Canadian or allied agency, under any mandate, using these or similar metadata-based techniques?

The EU Parliamentary Inquiry's Report on Mass Surveillance

Saturday, 11 January 2014

After about five months of hearings and investigating, the European Parliament's civil liberties committee has published its report on the revelations about mass surveillance leaked by the American former National Security Agency contractor Edward Snowden.

The comprehensive 52-page report, published Wednesday in draft form [pdf], contains a large number of important findings and recommendations — some of which I think it's worth highlighing here.

The report accuses spy agencies — particularly in the US (NSA) and the UK (GCHQ) — of operating dragnet snooping programs that appear to involve illegal actions. It says that the UK government has on at least two occasions breached the European Convention on Human Rights and the EU Charter in how it has tried to crack down on reporting of the Snowden leaks (examples cited are the detention of former Guardian journalist Glenn Greenwald's partner and the destruction of Guardian computers). In addition, the committee calls for the European Parliament to suspend data sharing deals with the US government, and it says new legal protections are necessary for journalists and whistleblowers.

Crucially, the report does not shy away from attempting to address some of the larger issues — such as the profound and unprecedented existential questions new mass surveillance technologies raise for modern democracies. It calls on US authorities and EU member states to "prohibit blanket mass surveillance activities and bulk processing of personal data," adding:

[The committee] sees the surveillance programmes as yet another step towards the establishment of a fully fledged preventive state, changing the established paradigm of criminal law in democratic societies, promoting instead a mix of law enforcement and intelligence activities with blurred legal safeguards, often not in line with democratic checks and balances and fundamental rights, especially the presumption of innocence. [Emphasis added.]

This kind of policing, it warns, is leading to "every citizen being treated as a suspect." For that reason, the report notes that the committee

condemns in the strongest possible terms the vast, systemic, blanket collection of the personal data of innocent people, often comprising intimate personal information; emphasises that the systems of mass, indiscriminate surveillance by intelligence services constitute a serious interference with the fundamental rights of citizens; stresses that privacy is not a luxury right, but that it is the foundation stone of a free and democratic society; points out, furthermore, that mass surveillance has potentially severe effects on the freedom of press, thought and speech as well as a significant potential for abuse of the information gathered against political adversaries; emphasises that these mass surveillance activities appear also to entail illegal actions by intelligence services and raise questions regarding extraterritoriality of national law.

UK surveillance laws are singled out for criticism, with the inquiry concluding that the UK's legal framework is in need of an overhaul because it is outdated. But the finger is not pointed solely at the spooks in the UK and the US. The report accuses countries including France, Germany, and Sweden of running their own mass surveillance programs, too. It also rightly blasts the general incompetence of oversight committees — both in Europe and the US — that are supposed to be tasked with holding spy agencies accountable:

despite the fact that oversight of intelligence services’ activities should be based on both democratic legitimacy (strong legal framework, ex ante authorisation and ex post verification) and an adequate technical capability and expertise, the majority of current EU and US oversight bodies dramatically lack both, in particular the technical capabilities. [Emphasis added.]

Moreover, it calls on the European Commission — the EU's executive body — to evaluate the possibility of introducing legal liabilities that could be used to punish technology companies for not fixing known vulnerabilities in their software or for installing secret backdoors for spying. It wants the European Parliament to consider only procuring software that is open source, so that the software code can be reviewed to ensure it is secure and free from backdoors inserted for spying. And it also urges European Union member states to initiate investigations into "possible cybercrimes and cyber attacks committed by governments or private actors in the course of the activities under scrutiny."

"Trust has been profoundly shaken," the report says. "Trust between the two transatlantic partners, trust among EU Member States, trust between citizens and their governments, trust in the respect of the rule of law, and trust in the security of IT services...in order to rebuild trust in all these dimensions a comprehensive plan is urgently needed."

It's worth a read if you have the time. The full report is here [pdf].

How UK Surveillance is on the Rise

Saturday, 20 July 2013

Earlier this week, the UK's official communications interception commissioner published his annual report. The commissioner releases statistics every year that offer an insight into the levels of surveillance being conducted by UK authorities, including police, security and intelligence agencies.

The latest report provides more evidence that the trend in recent years has been towards a general increase in surveillance of communications. In 2012, the report shows, there were a record 570,135 authorisations for police and other agencies to obtain so-called "communications data." This can include subscriber information about suspects' phone and email accounts, as well as call and email records showing who a suspect is phoning/emailing and when. It does not include the actual content of the communication.

Notably, the 570,135 figure is a 15 percent increase on the figure for 2011 and amounts to about an average 1,562 communications data authorisations every day. In addition, the commissioner noted in his report that "979 communications data errors" were made by authorities in cases involving the wrongful collection of data from innocent individuals. The botched surveillance had serious ramifications, with six members of the public "wrongly detained / accused of crimes" as a consequence.

Here's a quick graph I've knocked up showing how, with the exception of a unusual drop in authorisations in 2011, UK authorities have been increasingly obtaining communications data as part of investigations in recent years:

The same trend is reflected in the latest statistics on the interception of communications. Interception is when the authorities obtain a warrant, signed off by the secretary of state, enabling them to secretly eavesdrop on phone calls or read emails and texts. There were 3,372 interception warrants authorised in 2012, which represents a 16 percent increase on the figure for 2011. It is crucial to note that a single interception warrant can encompass large groups of individuals. It is not known exactly how many people were swept up in the 3,372 warrants because these figures are, unfortunately, not published.

Here's a graph that illustrates the steady increase in interceptions since 2008:

While surveillance is on the rise, as the above graphs show, the UK government has been arguing that it does not have enough digital spying capabilities and needs more surveillance powers.

The government's case may have recently been damaged, however, by leaked secret documents, published by the Guardian in June, that revealed how UK spy agency GCHQ was tapping into internet cables and reportedly monitoring some 600 million "telephone events" every day. The exposed extent of GCHQ's spying offered a rare and startling insight into the sweeping scope of surveillance already being conducted by the UK government, and seemed to affirm what the UN's special rapporteur on free expression, Frank La Rue, warned about in an unprecedented report published just weeks before the leaks.

"Technological advancements," La Rue wrote, "mean that the state’s effectiveness in conducting surveillance is no longer limited by scale or duration."

Surveillance and Human Rights? Teliasonera's Business Model

Friday, 16 November 2012

Back in April I reported at Slate on how a Swedish telecommunications firm was linked to spy agencies in Azerbaijan, Kazakhstan, Uzbekistan, Tajikistan, and Georgia, facilitating crackdowns on dissident politicians and independent journalists.

Teliasonera, headquartered in Stockholm, was uncovered by a brilliant team of Swedish reporters to have allowed “black box” probes to be fitted within their telecommunications networks, which enabled security services and police to monitor, in real-time, all communications passing through, including texts, internet traffic and phone calls. The mass surveillance had reportedly been used in several instances, without any judicial oversight, to help track down protesters and political opponents.

The company came under huge criticism and pressure following the report, and subsequently issued a statement saying that it was launching "an action programme for handling issues related to protection of privacy and freedom of expression in non-democratic countries."

I noticed yesterday Teliasonera published a post on its website covering a recent conference it participated in about internet governance, held in Azerbaijan. It's quite interesting to see, for a company that was accused of such serious complicity in the most grave of human rights abuses, how Teliasonera is now presenting itself:

For Teliasonera, of course, providing access to telecommunications including the internet is the business model. This business model includes freedom of expression, so that our subscribers can communicate, and protection of privacy, so that our users feel trust in our services. [...]

Human rights are an area which is constantly evolving, and any measures against individuals must be based on the rule of law. Companies need to abide by local legislation whilst respecting human rights.

These two aspects show, that telecoms and human rights at times are in conflict and require difficult tradeoffs, both democratic and economic terms. This means working out and establishing processes based on firm principles. The way forward is not easy, the challenges must be met jointly by the industry, and national as well as international organizations...

It's a positive sign that Teliasonera is recognising that telecommunications companies need to respect human rights, and that a company providing access to telecommunications must respect freedom of expression and protect privacy. But what I would like to hear more about is the action Teliasonera has taken to put these principles into practice. I would be interested to hear from citizens in countries such as Azerbaijan, Kazakhstan, and Uzbekistan about whether or not there are still situations in which they find themselves called in for interrogations after saying things critical about the ruling government on a phone call or in an email or text message.

I can't imagine that Teliasonera has had much success trying to convince secret police in Azerbaijan, for instance, that they should start respecting privacy and stop using the "black boxes" to sift through emails and identify dissidents. Ultimately, if Teliasonera is still operating in these countries, then on some level it seems realistic to suggest that it will remain complicit in human rights violations — violations that will almost inevitably occur as a result of authoritarian governments abusing the power that they hold to spy on people.

At the internet governance conference I mentioned above, Neelie Kroes, the vice president of the European Commission, gave a stern speech in which she condemned Azerbaijan's human rights record: "In this very country, we see many arbitrary restrictions on the media," she said. "And we see activists spied on online, violating the privacy of journalists and their sources." What happened after Kroes speech was telling and indicative of the scale of the problem in a country like Azerbaijan: members of her team had their computers reportedly hacked. "I'm presuming it was some kind of surveillance," one said.

[To reiterate: I'd be keen to hear from any activists, journalists, telecom engineers, politicians, anyone in this region with more information about the current state of surveillance in the former Soviet Republics. Info on Teliasonera's continuing role would be especially welcome.]

UPDATE, 17.11.12: A kind gentleman has emailed me a link (.doc) to a very interesting full transcript of a meeting at the recent internet governance conference in Azerbaijan, which representatives from Teliasonera participated in.

Here are some notable snippets from speakers who identified themselves as representatives of Teliasonera or its subsidiary in Azerbaijan, Azercell (emphasis added):

...as a telecom company we do not participate in the decisions on proportionality between national security and human rights. That's something which is done by legislator and authorities.

and:

...the frequencies in this country [Azerbaijan] have been owned by the government, and we just lease them, so we just own the infrastructure, and the lease for those contracts are like for 20, 25 years, we lease the frequencies from the country, and then those -- and the government has the right to interfere in accordance with the different legislations, so whenever those defined cases are, they can take the information even without the notification to the company in accordance with the whole legislation so whatever Teliasonora operate in the local market they do operate in accordance with the legislation.

and:
...because the frequencies have been owned by the government, we don't even have to have this [secret "black box"] room or whatsoever. Because it is the property of the government.

The Teliasonera representatives also said that the company is trying to improve transparency in relation to its human rights efforts by publishing information on its website, and is working to "improve processes when it comes to government demands" such as by "maybe seeking judicial review."

I had a quick scan through one of the key documents over at teliasonera.com, which is supposed to be an overview of Teliasonera's "action programme" related to telecommunications and human rights. One of the most striking passages, in a document (.pdf) headed "Freedom of expression and privacy – the international framework," is as follows (emphasis added):

The requirements generally imposed on a telecoms operator that are sensitive from the point of view of rights and freedoms are those allowing the police and national security services to intercept and monitor telecommunications traffic in secret, or to gain access to information on subscribers and historical information on telecommunications traffic and on the location of mobile phones. There may also be requirements to shut down all or part of a telecommunications network, block individual messages and block specific websites on the Internet.

One aspect that national regulations have in common is that the telecoms operators do not participate in public authorities' decisions to take a particular action. Local laws sometimes require decisions to be made by a court or by an individual public authority. The choice of decision-making body may be influenced by the nature or severity of the threat and how time-critical the measures are. One recurring feature of national regulations is that details concerning public authorities' decisions, requirements and work in these areas are strictly confidential and telecoms operators are not given any information on why a particular measure is to be adopted.

What these snippets illustrate is the deeply conflicted position Teliasonera has put itself in by doing business in countries such as Azerbaijan. The company says that it is committed to protecting human rights, freedom of expression and privacy, and yet in the same breath admits that it must adhere to "local laws" in these authoritarian countries and in some cases has no say in decisions about "proportionality between national security and human rights." It is definitely a good sign that Teliasonera has at least recognised that it must do more to address these problems, as I mentioned above. But any telecom company that chooses to continue operating in countries where crackdowns on activists and journalists are rife at the present time is still on some level taking a decision to put financial considerations first, while implicitly turning a blind eye to ongoing human rights violations facilitated with communications surveillance.