Showing posts with label democracy. Show all posts
Showing posts with label democracy. Show all posts

Extraordinary Rendition and the Secret Role of Metadata

Thursday, 28 August 2014

On Monday, I had a new story out at The Intercept revealing a secret search engine that the National Security Agency built to share a massive amount of data with other US government agencies, including domestic law enforcement. There are many new and important details scattered through the piece. But there is one in particular I would like to take a minute to focus on here, because it is a fact that strikes at the heart of the debate about government surveillance and deserves some more attention.

In one of the classified documents that we published with the story, dated from 2005, the NSA outlined some of the "successes" of a data-sharing project called CRISSCROSS that was led by the Central Intelligence Agency. The document shows that metadata collected about communications was integral to the CIA's extraordinary rendition program during the Bush Administration, which involved kidnapping terror suspects and taking them to secret "black site" jails where they would be brutally interrogated and sometimes tortured. The NSA document says:

Since 9/11, the contributions to the GWOT [global war on terror] due to our increased collection of signaling metadata are innumerable and significant. It is safe to say that it has been a contribution to virtually every successful rendition of suspects and often, the deciding factor.

This is an incredible detail. Remember, metadata is not the audio content of a phone call or the words contained within the body of an email message. It is merely information showing who you have contacted and when. Governments have often sought to defend the mass-scale collection of metadata by insisting that it is not information that is sensitive or very private. In June last year, President Obama tried to dismiss concerns about metadata collection in the United States by claiming that "nobody is listening to your telephone calls." But, clearly, the government doesn't need to be listening to your calls to deem you a threat. That metadata has been the deciding factor in targeting people for extraordinary rendition is a profound illustration of that — and it shows that metadata collection has real-world ramifications: it is not just some benign activity.

You might think, "well, I'm not a terror suspect so what do I care?" But this is not only about the Bad Guys — there are much wider consequences at play here. During the height of the extraordinary rendition program, for instance, some of the people targeted were victims of what was called "erroneous rendition." In other words, the CIA would kidnap the wrong person. (Yes, seriously.) In 2005, it was reported by the Washington Post that the CIA's inspector general was investigating a "growing number" of erroneous renditions, with some anonymous government officials saying that they believed there were as many as 30 instances of it having taken place.

Much is still unknown about these cocked-up renditions because the information has been kept secret. But now that we know metadata played a key role in targeting people — in some cases even being the "deciding factor" — questions must surely be asked about whether this method was ever to blame. From a legal and human rights perspective, it is disturbing enough that the CIA was secretly kidnapping, imprisoning, and then torturing people. But the possibility of innocent individuals being targeted on the basis of their metadata trail clearly adds a chilling extra dimension. It is a policy of guilt by association that bears all the hallmarks of a kind of terrible and flawed style of totalitarian policing.

Today, the practice of extraordinary rendition appears to have been largely phased out by President Obama. But the concerns raised by the use of metadata to target people are still highly pertinent. Indeed, as The Intercept reported back in February, metadata is actively being used to target and kill terror suspects in drone strikes in countries like Yemen, Pakistan and Somalia. One military source said that the method can result in the "wrong people" being bombed. And if you think that sounds far-fetched — that the US would not launch missiles at people because of their metadata — you don't need to take my word for it. Just go and listen to what former CIA and NSA chief Michael Hayden has to say. As he boasted in April: "We kill people based on metadata."

Canada's WiFi Surveillance and CSEC's Non-Denial Denials

Saturday, 1 February 2014

On Thursday, a report I worked on with Glenn Greenwald and Greg Weston was published in Canada, revealing how the country's spy agency CSEC secretly developed a program to monitor WiFi users in a major Canadian airport.

The piece, based on documents leaked by the former US National Security Agency contractor Edward Snowden, has led to CSEC being accused of acting unlawfully and has triggered calls for better oversight of the agency.

But one of the most intriguing aspects of the fallout from the story has been the Canadian government's response — which merits some scrutiny and analysis.

First, some context.

Back in November, Greenwald, Weston and I reported separate revelations about Canada's role in an NSA operation to spy at the G8 and G20 summits in Canada in 2010. In response, CSEC's chief John Forster claimed in response to reporters' questions:

What I can tell you is that CSEC, under its legislation, cannot target Canadians anywhere in the world or anyone in Canada, including visitors to Canada.

During a speech in October, Forster had made a similar statement:

I can tell you that we do not target Canadians at home or abroad in our foreign intelligence activities, nor do we target anyone in Canada. In fact, it's prohibited by law. Protecting the privacy of Canadians is our most important principle.

And again, in January, he repeated this assertion in a letter to a Canadian newspaper:

Under the law, CSE’s foreign intelligence mandate specifically dictates that our activities be directed only at foreign entities, and not at Canadians or anyone in Canada. That is the law and we fully respect that.

Having analysed Canadian documents in the Snowden material, these statements struck me as quite astonishing.

Why? Because one of the top-secret Snowden documents revealed that, in 2012, CSEC had set up a program that involved monitoring WiFi usage at a large Canadian airport. The secret files showed how CSEC was able to use a huge amount of data about the WiFi connections to follow users "backward and forward in recent time" — identifying visits to hotels, other airports, Internet cafes, coffee shops, and a library.

The tactic is described by CSEC in the files as "IP profiling" — a surveillance method that can be used to track users' movements over time. In one case, as we reported at CBC on Thursday, the spy agency says that it performed a sweep of an entire "modest-sized" city and identified 300,000 user IDs:

The "mission impact" of the tactic, according to the document, is that it can alert spies to "target country location changes" and "webmail logins with time-limited cookies":

The full document [pdf] speaks for itself. It illustrates a secret surveillance operation was conducted on Canadian soil — sweeping up metadata on the WiFi usage of thousands of people not suspected of any crime. Equally significant, the revelation contradicts CSEC chief Forster's repeated assertion that "we do not target Canadians at home or abroad in our foreign intelligence activities, nor do we target anyone in Canada."

After we reported the airports story, it got more interesting.

CSEC issued a statement that was notable for three reasons. First, the agency did not repeat its previous mantra claiming not to "target anyone in Canada." Second, it appeared to make an admission that it is sweeping up metadata within Canada, saying that it was "legally authorized" to "collect and analyze" this information. And third, it issued a fresh denial, saying that "no Canadian or foreign travellers were tracked. No Canadian communications were, or are, targeted, collected or used."

Shortly afterwards, on Friday, a similar denial was made by the Canadian prime minister's parliamentary secretary, who launched a bizarre personal attack on Greenwald while claiming that the "facts" were that "nothing in the stolen documents showed that Canadians' communications were targeted, collected, or used, nor that travellers' movements were tracked."

But these denials are hollow.

It's a straw man to claim that the revelations were about communications being "targeted, collected, or used." That is not what our story was about. The issue at hand is how CSEC initiated a program to sweep up information showing when people are connecting to WiFi networks and using this information to build "profiles" of their movements back and forward in time.

And that brings us to the more important point. CSEC and the prime minister's secretary claimed that "no Canadian or foreign travellers were tracked." However, what they did not say was how they were defining the word "tracked."

The documents quite clearly show how the agency used user "IP profiles" to monitor WiFi users' movements over time, with this capability enabling it to generate "alerts" when a person relocates to another country.

The dictionary definition of "tracking" says that it means "the act or process of following something or someone." CSEC's IP profiling is exactly that — monitoring users' location and keeping tabs on where they are. Indeed, the document says as much, outlining how CSEC uses this tactic to "follow IDs backward and forward in recent time." The documents also mention how CSEC used tools called "Quova" and "Atlas database" — which are technologies used to pinpoint the geolocation of an IP address.

CSEC's denial that it "tracked" Canadians or foreign travellers, I think, hinges upon a narrowly defined interpretation of the word. The US Department of Defence, for instance, uses "tracking" as a specific technical term meaning the "precise and continuous position-finding of targets by radar, optical, or other means." CSEC's IP profiling definitely fits the dictionary definition of "tracking" as it is understood by most people — but does it fit the narrower military definition? Perhaps CSEC believes that IP profiling does not constitute "precise and continuous" tracking. But if so, it should be explaining this — as otherwise its denial is highly misleading.

Spy agencies are professionals in the art of deception, and sometimes that seems to be reflected in their public relations strategy. Afterall, we have seen misleading denials issued repeatedly by the National Security Agency and its Five Eyes counterparts about various surveillance revelations in recent months. Again and again, officials have used narrowly defined words or jargon terms in a carefully crafted way in order to issue non-denial denials in which they appear to refute an allegation but on closer reading do not really refute it at all.

The ultimate point here is that the tactics being used by CSEC and the Canadian government to deflect criticism of their secret surveillance programs merit as much attention as the revelations themselves. That is especially clear when, in response to disclosures about their secret programs, senior government officials launch childish character assassination attempts against the journalists who reported the information. In a democratic society, surely a higher standard is required. It is not enough for governments and spy agencies to spit out a few indignant statements and denials with the expectation that people should just blindly trust that they are telling the truth.

Also, no matter how "tracking" is being defined, what is clear is that CSEC was (and our sources say still is) running a large-scale surveillance operation on domestic soil, seriously calling into question spy chief Forster's previous statements that "our activities" are not directed "at Canadians or anyone in Canada." The CSEC boss is due to appear before a Senate committee hearing on Monday. Hopefully Canada's lawmakers will take the opportunity to ask some probing questions.


UPDATE, 7 February 2014: Since the story was published last week, there have been several developments. There have been more calls for an independent review of CSEC's activities, while spy chief Forster was forced to publicly defend the surveillance in Monday's Senate hearing.

There have also been some interesting analyses of the leaked documents worth responding to.

First, the surveillance blog Electrospaces claimed that the secret documents seemed to have been "incorrectly interpreted" in our CBC report. The blog published an anonymous analysis from someone who says that CSEC's surveillance project was "was not surveillance of Canadian citizens per se but just a small research project." The second analysis came from Bruce Schneier, who claimed that it was "not really true" that CSEC used "airport Wi-Fi information to track travellers."

First of all, it is a mischaracterization to claim that the CSEC project was just a small research project that didn't implicate Canadians "per se." It was part of a pilot initiative that involved sweeping up data on hundreds of thousands of people — many of whom would have been Canadian citizens. Our sources for the story told us that the pliot had since gone live — i.e. that it had gone from being a "proof-of-concept" to an operationally active domestic program. This is about much more than a "small research project."

Second, it is absolutely the case that CSEC tracked travellers' movements based on the Internet activity by using IP and ID data and honing in on a major Canadian airport's WiFi system.

It may be about more than that — and I agree with Schneier when he says that it is "actually far more interesting than simply eavesdropping on airport Wi-Fi sessions" because of the wider ramifications of this kind of 'big data' analysis.

But this particular initiative was focused on pulling out a huge trove of user ID and IP data and following users "backward and forward in recent time" to and from a Canadian airport to see if it would be possible to keep tabs movements and trigger alerts based on those movements.

What we reported was accurate and remains so: "Canada's electronic spy agency used information from the free internet service at a major Canadian airport to track the wireless devices of thousands of ordinary airline passengers for days after they left the terminal."

Even CSEC chief Forster has since come out and admitted that a kind of tracking was going on (though he says it didn't occur in "real time," which is not something we actually claimed):

Forster said the agency used metadata to develop a model that showed they could track an internet user's network activity "around a public access mode," and that the tracking didn't happen in real time.

Some of the more insightful analysis on the CSEC affair has come from Bill Robinson, a Canadian surveillance expert described by the Toronto Star as "Canada's authority on CSEC."

Robinson makes some interesting points on the meaning of "tracking" in this context and CSEC's initial denial that it had tracked people — and I think he could be hitting the nail on the head here:

While normal human beings might conclude that both Canadian and foreign travellers were indeed tracked, CSEC's claim may be that only devices were tracked in the specific tests reported in the document. Since no device was tracked specifically on account of the fact that it belongs to a particular person, and the analysis itself (as far as I know) did not seek to associate particular individuals with particular devices (although it may well have utilized information associated or associatable with specific individuals), CSEC may feel it is justified in stating that no individuals were tracked. The same or similar logic seems to underlie the agency's claim that it can collect metadata related to thousands or even millions of Canadians and persons in Canada for foreign intelligence purposes while at the same time stating that its foreign intelligence operations do not "target" any Canadians or persons in Canada.

In a separate blog post after spy chief Forster's testimony before the Canadian Senate committee on Monday, Robinson wrote:

In essence, the government's position is that the metadata project reported by the CBC did take place, that its purpose was to develop targeting and analysis techniques that are in fact now being used operationally by CSEC, and that the collection, analysis, use, and retention of Canadian metadata is a normal part of CSEC's operations, necessary to those operations, and entirely legal. Officials also insist, however, that CSEC does not use the data to target Canadians for foreign intelligence purposes.
To have CSEC now appearing to admit (under pressure) that it is using metadata to conduct domestic monitoring on a mass scale is revelatory — and that is where the focus should be. As I wrote here previously, how "tracking" is being defined as a word should not be the most central point in the debate. The attention should be on CSEC conducting a large-scale surveillance operation on Canadian soil and misleading Canadian citizens about it in a series of public statements. Robinson asks the right questions in his earlier blog post:

If real-world operations are now being conducted using the techniques described in the document, or similar kinds of techniques, those operations will indeed involve the tracking of specific individuals who are either known before the tracking began or identified subsequent to their being singled out by analysis of the data.

Will the government state that no Canadian or foreign travellers have ever been tracked (or, if it prefers, detected in a number of different locations over time) in Canada, either by CSEC or by any other Canadian or allied agency, under any mandate, using these or similar metadata-based techniques?

The EU Parliamentary Inquiry's Report on Mass Surveillance

Saturday, 11 January 2014

After about five months of hearings and investigating, the European Parliament's civil liberties committee has published its report on the revelations about mass surveillance leaked by the American former National Security Agency contractor Edward Snowden.

The comprehensive 52-page report, published Wednesday in draft form [pdf], contains a large number of important findings and recommendations — some of which I think it's worth highlighing here.

The report accuses spy agencies — particularly in the US (NSA) and the UK (GCHQ) — of operating dragnet snooping programs that appear to involve illegal actions. It says that the UK government has on at least two occasions breached the European Convention on Human Rights and the EU Charter in how it has tried to crack down on reporting of the Snowden leaks (examples cited are the detention of former Guardian journalist Glenn Greenwald's partner and the destruction of Guardian computers). In addition, the committee calls for the European Parliament to suspend data sharing deals with the US government, and it says new legal protections are necessary for journalists and whistleblowers.

Crucially, the report does not shy away from attempting to address some of the larger issues — such as the profound and unprecedented existential questions new mass surveillance technologies raise for modern democracies. It calls on US authorities and EU member states to "prohibit blanket mass surveillance activities and bulk processing of personal data," adding:

[The committee] sees the surveillance programmes as yet another step towards the establishment of a fully fledged preventive state, changing the established paradigm of criminal law in democratic societies, promoting instead a mix of law enforcement and intelligence activities with blurred legal safeguards, often not in line with democratic checks and balances and fundamental rights, especially the presumption of innocence. [Emphasis added.]

This kind of policing, it warns, is leading to "every citizen being treated as a suspect." For that reason, the report notes that the committee

condemns in the strongest possible terms the vast, systemic, blanket collection of the personal data of innocent people, often comprising intimate personal information; emphasises that the systems of mass, indiscriminate surveillance by intelligence services constitute a serious interference with the fundamental rights of citizens; stresses that privacy is not a luxury right, but that it is the foundation stone of a free and democratic society; points out, furthermore, that mass surveillance has potentially severe effects on the freedom of press, thought and speech as well as a significant potential for abuse of the information gathered against political adversaries; emphasises that these mass surveillance activities appear also to entail illegal actions by intelligence services and raise questions regarding extraterritoriality of national law.

UK surveillance laws are singled out for criticism, with the inquiry concluding that the UK's legal framework is in need of an overhaul because it is outdated. But the finger is not pointed solely at the spooks in the UK and the US. The report accuses countries including France, Germany, and Sweden of running their own mass surveillance programs, too. It also rightly blasts the general incompetence of oversight committees — both in Europe and the US — that are supposed to be tasked with holding spy agencies accountable:

despite the fact that oversight of intelligence services’ activities should be based on both democratic legitimacy (strong legal framework, ex ante authorisation and ex post verification) and an adequate technical capability and expertise, the majority of current EU and US oversight bodies dramatically lack both, in particular the technical capabilities. [Emphasis added.]

Moreover, it calls on the European Commission — the EU's executive body — to evaluate the possibility of introducing legal liabilities that could be used to punish technology companies for not fixing known vulnerabilities in their software or for installing secret backdoors for spying. It wants the European Parliament to consider only procuring software that is open source, so that the software code can be reviewed to ensure it is secure and free from backdoors inserted for spying. And it also urges European Union member states to initiate investigations into "possible cybercrimes and cyber attacks committed by governments or private actors in the course of the activities under scrutiny."

"Trust has been profoundly shaken," the report says. "Trust between the two transatlantic partners, trust among EU Member States, trust between citizens and their governments, trust in the respect of the rule of law, and trust in the security of IT services...in order to rebuild trust in all these dimensions a comprehensive plan is urgently needed."

It's worth a read if you have the time. The full report is here [pdf].

GCHQ's Dubious Role in The 'Quantum' Hacking Spy Tactic

Thursday, 12 December 2013

I've not posted here for a while, but I've got a good excuse. For the last month or so I've been out in Brazil working on a series of stories with the American journalist and former Guardian columnist Glenn Greenwald. We've been reporting a series of revelations about government surveillance based on the trove of files leaked by former NSA contractor Edward Snowden.

I've had some time to take a breather tonight and I want to draw attention to something important in one of the latest stories we worked on with a team of excellent Swedish journalists from Uppdrag Granskning — an investigative unit that operates as part of Sweden's national public broadcaster SVT.

We worked on several stories with Uppdrag Granskning in the lead up to an hour-long documentary, aired Wednesday, about Sweden's major role in the global surveillance nexus that is led by the United States, the United Kingdom, and the other members of the so-called Five Eyes group — Australia, Canada, and New Zealand.

As we reported, the documents reveal how Sweden has become a key partner for the US and the UK, and top-secret agreements have been made in the last decade that bolster Sweden's spying role like never before.

But aside from these crucial details, which are hugely important for Swedish citizens to be informed about, I'd like to highlight here one smaller piece of information that we reported that I think is highly notable.

Earlier this year, it was disclosed that UK spy agency GCHQ was involved in hacking into the Belgian telecom company Belgacom's computer systems in order to covertly gather intelligence on unknown targets. But what is interesting is that, despite being involved in using these hacking methods, GCHQ has been worrying behind the scenes about their legality.

One of the Snowden documents we revealed on the Uppdrag Granskning documentary — dated circa April 2013 — shows the NSA describing a so-called 'Quantum' hacking initative that GCHQ was involved in at a "proof-of-concept" level. However, the document notes:
Continued GCHQ involvement may be in jeopardy due to British legal/policy restrictions, and in fact NSA’s goal all along has been to transition this effort to a bilat with the Swedish partner. [Emphasis added.]
This struck me because, last year, I uncovered a document showing something similar. In obscure technical standards meetings with telecom companies about implementing new surveillance capabilities, GCHQ representatives from a little-known unit of the agency called the National Techical Assistance Centre were voicing the same concerns about hacking techniques.

At meetings held between 2010 and 2011 in Estonia and Italy, at which a GCHQ representative was present, the UK was said to be anxious about the legality of performing a so-called 'man-in-the-middle' attack to covertly hack and eavesdrop on communications:
An additional concern in the UK is that performing an active attack, such as the Man-in-the-Middle attack proposed in the Lawful Interception solution...may be illegal. The UK Computer Misuse Act 1990 provides legislative protection against unauthorised access to and modification of computer material. The act makes specific provisions for law enforcement agencies to access computer material under powers of inspection, search or seizure. However, the act makes no such provision for modification of computer material. A Man-in-the-Middle attack causes modification to computer data and will impact the reliability of the data.
This could not be clearer. The UK's position was that it might be unlawful for authorities to hack a computer in order to monitor communications and/or exfiltrate data. That was the position in 2010/11, and I think the same concern is what is being referenced in the 2013 NSA document when UK "legal/policy restrictions" are mentioned.

Yet despite this concern — and this is perhaps the most important point — GCHQ has marched ahead with its participation in clandestine surveillance operations that involve hacking. The Belgacom case is a specific example, but the NSA documents on Sweden illustrate that Belgacom was not an isolated case. GCHQ was (and likely continues to be) involved in a program called WINTERLIGHT that explicitly involves trying to infect hundreds of targeted computers with so-called 'implants' of malware. GCHQ even operates a covert computer server that it uses to help infect targets with the malware, likely by masquerading as legitimate websites such as LinkedIn, as previous reports have suggested. These covert servers are mentioned in one of the NSA documents on Sweden, dated April 2013, revealed by Uppdrag Granskning:
Last month, we received a message from our Swedish partner that GCHQ received FRA [Swedish spy agency] QUANTUM tips that led to 100 shots, five of which were successfully redirected to the GCHQ server.
So, the question here is: how can this be legal? If GCHQ was previously concerned that performing active hacking attacks may be unlawful under the UK's Computer Misuse Act, then how has that situation been resolved? Has the agency been granted immunity to perform these operations? If so, who granted the immunity? Alternatively, has the UK government, with zero public debate and under cover of total secrecy, produced a classified interpretation of the law aimed at justifying and rendering lawful the use of this clandestine hacking technique?

Another very intriguing theory I have considered is that GCHQ lets one of the other agencies do the "dirty work" — the part of the hack that would illegal under UK law. The NSA may deploy the malware, for instance, while GCHQ plays a lesser role by merely facilitating the attack by hosting the server — but still reaping the benefits (i.e. it gets access to the intercepted data). Having spent countless hours now looking at the Snowden documents, it certainly appears to me that this is something that occurs — that the spy agencies circumvent their domestic laws by allowing partner agencies to do things that they could not do themselves.

Either way, GCHQ's clear and undeniable role in Quantum hacking attacks raises hugely significant legal questions and it is remarkable to me — but perhaps not totally surprising — that the blundering British parlimentarians who are supposed to hold the agency to account have thus far failed to raise any of these key issues.

The Torture & Rendition Report the UK Government Hasn't Published

Thursday, 7 November 2013

Last year, the UK government was presented with a preliminary report about an inquiry into British security services' alleged role in the extraordinary rendition and torture of terror suspects. The government said at the time that it would make the report public — but it has never surfaced.

The report was produced as part of the so-called 'Detainee Inquiry', set up by prime minister David Cameron in 2010 to investigate allegations of British security agencies' involvement in the mistreatment of individuals accused of terror offences. Spy agency MI6, for instance, has been blamed for helping to facilitate the abduction and subsequent alleged torture of a Libyan Islamist and his pregnant wife, who were covertly 'rendered' from Bangkok and reportedly taken to a Libyan prison run by the Gaddafi regime in 2004.

Headed by retired judge Sir Peter Gibson, the Detainee Inquiry was supposed to look into these allegations and others. It was scrapped in 2012 amid controversy because the government said that it clashed with ongoing police investigations into some of the same cases. But a preliminary report was produced by the inquiry and sent to the prime minister on 27 June 2012. At the time, the government issued a statement saying that the report focused on "preparatory work to date, highlighting particular themes or issues which might be the subject of further examination." Justice Secretary Ken Clarke said that the government was committed to publishing "as much of this interim report as possible."

Almost 18 months on, however, where is the preliminary report? That is exactly what I have been trying to find out. And the UK government is not returning my emails.

In September, I sent a Freedom of Information Act request seeking a copy of the report to the government's Cabinet Office. Under the FOIA, the government has 20 working days to issue a response. 31 working days have now passed and I have sent three separate emails related to the request. I have received nothing in response — not even an acknowledgement informing me that my request has been received. This means that the government is violating its legal obligations, according to an official I consulted at the Information Commissioner's Office, the public body that enforces access to information legislation in the UK.

I submit quite a lot of FOI requests, and I can't think of another occasion when a government department has flat-out ignored a request in this way. It is very unusual. Normally, the procedure is that you will receive an acknowledgement within a few days. And a couple of weeks later the respective department will either send you the information or refuse to release it, usually citing some flimsy national security secrecy exemption.

Notably, the chap who runs the website Spy Blog has also previously attempted to obtain a copy of the preliminary report. His efforts have so far been stonewalled. But unlike me, Spy Blog has at least been privileged enough to receive responses from the Cabinet Office, most recently in July. The Cabinet refused to disclose the report to the website, claiming that officials were busy "clearing the report for publication" and adding that they expected that it could be published "in the autumn, although no date has been set."

It is not clear why the Cabinet Office has needed almost a year and a half to "clear" a report for public consumption. At best, it looks to me like a case of incompetence and bureaucratic inefficiency; at worst, it is a red herring being deployed to delay the release of controversial information for political convenience. Either way, the delay suggests that there could be some interesting details contained in the report. And the government is running out of excuses to postpone publication. Indeed, under section 22 of the Freedom of Information Act, the government can decline to disclose information requested if it is already intended for future release. However, Ministry of Justice guidance on the Section 22 exemption explicitly states that:

These qualifications recognise that sometimes there will be an overriding public interest in the information being released prior to the intended publication date. Public authorities should not be able to avoid putting information in the public domain by adopting unreasonable publication timetables or an 'intention' to publish where there is little prospect of that happening within a reasonable timescale.

Given the seriousness of the allegations about UK security agencies' role in facilitating extraordinary rendition and torture, there is evidently a very strong public interest case for this preliminary report to be immediately released under the Freedom of Information Act. That is especially true given the inexplicably lengthy delay that we have already had to endure.

It's worth also pointing out that despite the sort of behaviour detailed above, the government continues to audaciously insist it is committed to transparency. Just last week the Cabinet Office was proclaiming "wide-ranging new commitments to bring more of the benefits of transparency into people’s everyday lives." Cabinet minister Francis Maude was quoted as saying that "transparency is an idea whose time has come."

Unfortunately, the section of Maude's own department responsible for implementing transparency does not appear to have received the memo — and is currently flouting the Freedom of Information Act in a case involving the withholding of important information that the public clearly has a right to know.

I have lodged a formal complaint about the Cabinet Office's conduct with the Information Commissioner's Office — so watch this space.

UPDATE, 4 December 2013: Late last month, the Information Commissioner's Office replied to the complaint I filed about the UK government's non-response to my request that it release the rendition/torture report. An official from the ICO said he had contacted the government's Cabinet Office to confirm that my request had been received and to give the government a 10-day deadline to contact me. The ICO reminded the government of its obligations under the Freedom of Information Act and noted that it "may consider taking enforcement action" should similar complaints arise (read the ICO's correspondence here).

However, despite this light reprimand from the ICO, incredibly I've still received no response from the government about the rendition report. The 10-day deadline expired yesterday and I've heard nothing — I've not yet so much as received an acknowlegement that my initial request is being dealt with, even though it was submitted more than two months ago (the government is supposed to respond within 20 working days; it's now been more than 50). This means that the Cabinet Office, which likes to tout its transparency credentials, is not only actively flouting its obligations under the Freedom of Information Act — it has also now failed to act on a formal request made by the authority that enforces the FOIA law, the ICO. Before the end of the week, I'll be following up my complaint with the ICO in the hope that more serious action can be taken. Of course, I'll post further updates here with any new developments in this strange case as and when they arise.

UPDATE, 29 December 2013: The government has released the Detainee Report today; the Guardian reports that it reveals how "MI6 officers were under no obligation to report breaches of the Geneva conventions and turned a 'blind eye' to the torture of detainees in foreign jails, according to the report into Britain's involvement in the rendition of terror suspects." I am still pursuing my complaint against the Cabinet Office for its handling of my FOIA request.

UPDATE, 26 March 2014: In response to my complaint, the Information Commissioner's Office issued a "decision notice" stating that the Cabinet Office breached section 10 of the Freedom of Information Act in ignoring my request. More details here.

Prism D Notice

Tuesday, 18 June 2013

Following disclosures by the Guardian earlier this month about a US National Security Agency internet surveillance program called Prism, it has emerged that UK government officials issued a so-called "D notice" in a bid to censor coverage of spy tactics.

The D notice following the NSA leaks was reportedly issued to news organisations including the BBC on 7 June, the day after the Prism story broke. Prism is a system used by the NSA to monitor emails, file transfers, photos, videos, chats, and other data. Intelligence gleaned from the system has been passed to GCHQ, the UK's version of the NSA.

The notice to the media organisations was marked "Private and Confidential: Not for publication, broadcast or use on social media," according to Jeff Stein at And Magazine. It added:

There have been a number of articles recently in connection with some of the ways in which the UK Intelligence Services obtain information from foreign sources.

Although none of these recent articles has contravened any of the guidelines contained within the Defence Advisory Notice System, the intelligence services are concerned that further developments of this same theme may begin to jeopardize both national security and possibly UK personnel.

It particularly warned against reporting on:

specific covert operations, sources and methods of the security services, SIS and GCHQ, Defence Intelligence Units, Special Forces and those involved with them, the application of those methods, including the interception of communications and their targets; the same applies to those engaged on counter-terrorist operations.

The D-notice system was first set up in 1912 and operates in accordance with a voluntary code — providing "advice and guidance to the media about defence and counter-terrorist information the publication of which would be damaging to national security." In 2010, for instance, a D notice was reportedly issued prior to WikiLeaks' release of thousands of US government diplomatic cables. A D notice has no formal legal authority, but defying it can make journalists vulnerable to prosecution under the UK's Official Secrets Act.

Snowden's Fate

Monday, 17 June 2013

On Democracy Now today there was an insightful interview with Hong Kong legislator Charles Mok on the potential next steps for US National Security Agency whistleblower Edward Snowden.

Snowden is currently believed to be in Hong Kong after passing a batch of NSA documents revealing top-secret surveillance programs to the Guardian, the Washington Post, and the South China Morning Post. US authorities have initiated a criminal investigation over the leaks and will probably pursue Snowden's extradition in the weeks and months ahead.

Mok talks about what that process could entail, and says that though Hong Kong enjoys independence from mainland China on many issues, the international magnitude of the Snowden case means the final decision that will determine his fate is ultimately likely to be made by central government in Beijing:

Please understand that at least we have a one-country, two-system system in Hong Kong and between Hong Kong and the mainland. So our laws are different from the laws in China. And we do have a border and so on. We do have different governments, even though as a regional government, we do report to the central government.

So I think what we want locally is to make sure that we can protect [Snowden] and make sure that we can live up to our core values and make sure that we treat this person according to all the rights that he should be getting under Hong Kong law. And... exactly what I don’t want to see, is that this sort of political influence to be interfering into the justice process, the judicial process that Mr. Snowden may end up having to get in Hong Kong. If, for example, the US starts by contacting the Hong Kong government to try to initiate an extradition, and if Mr. Snowden decides to try to get asylum or apply for refugee status here in Hong Kong, he — if he chose to do that, if the process comes to that point, he should be getting all the rights. [...]

If the US started to initiate a process [to] say that we want to arrest this person and start an extradition process, then Mr. Snowden could apply in Hong Kong for refugee status. And then there would be at least two tests: first by the United Nations High Commission on Refugees to determine whether or not, for example, that he will face torture at home and whether or not this is political persecution and so on, and second, also by the Hong Kong court. [...]

He will be accorded rights to appeal all the way up to our highest court in Hong Kong. So, assuming that money and financial issues — because you do need to get lawyers and so on — assuming those are not an issue, these processes in the past could have taken quite a bit of time. But... if [Snowden] isn’t successful and there has to be a final decision to be made about the extradition, our chief executive in Hong Kong, which is pretty much [like] our president... he will have to make the final decision. But because this case very likely will involve foreign relations, then he has to consult the central government. So, in the end, it means that the process can be a pretty prolonged process, and, second, Beijing will probably come into the equation to make a final decision in the end.

You can watch the full interview here.

Lady Liberty's Watching You: The Full Correspondence

Monday, 6 May 2013

Below is the full bizarre correspondence between myself and two companies, Cognitec and Total Recall Corporation, which was the subject of a recent article I wrote for Slate magazine called "Lady Liberty's Watching You."

As you will see, it started out with me following up a tip about new face recognition technology being piloted at the Statue of Liberty, and ended with me getting sent legal threats warning me not to write about it. A number of outlets followed up the story, including BoingBoing, the Village Voice, and Techdirt.

The correspondence — which consists of both phone interviews and emails listed in chronological order — has not been edited apart from a couple of typo fixes and the removal of email introductions and signatures ("hi there," "best regards," etc.) to avoid unnecessary repetition. I am publishing the correspondence in full not only because doing so is in the interest of transparency, but because I feel that it can serve as an educational example — helping inform about the sort of crass, outrageous intimidation attempts journalists occasionally face when attempting to go about their work. Receiving crude threats is unfortunately sometimes part of the job, but never should we back down.

*****
PHONE CALL
Ryan Gallagher
Elke Oberg [Cognitec]
19 March 2013 13:36pm
Contemporaneous note

I ask for more information about pilot of Cognitec face recognition at Statue of Liberty.

Oberg says: "We were doing this through an integrator [Total Recall Corporation]. So what usually happens is our software, we give it to a company that actually integrates it into a real-world application. I am not really the best person to tell you about what's happening with this project, because that's really more [for] the company that is doing the actual project. I mean, yes, they are going to try out our technology there. But as to the status, and how it's going, I am not the best person to answer those questions for you."

She adds: "I knew this project was going on but hadn't really checked up on it."

She describes what the technology can be used for: "facial analysis to determine how many people have gone through the checkpoints, how many are male, how many are female... we do have ethnicity detection as well but obviously not that accurate for person of mixed ethnicity. But you can also use it for people flow if you see a certain entrance or certain choke point there are too many people gathering you can open another entrance put more staff on etc. It can give a rough estimate of age... age ranges within five years of actual birth date, it is quite accurate.

She says the demographics capability was relevant to the Statue of Liberty pilot: "I'm certain that they are interested in that part."

*****

From: Ryan Gallagher
To: [Total Recall Corp. secretary] Viktoriya

19 March 2013 15:31

I spoke to you on the phone a moment ago. I am a journalist with Slate.com.

I'm doing a story on facial recognition technology in New York and was hoping you could give me an update on the status of a pilot I understand Total Recall is running at the Statue of Liberty with software made by a company called Cognitec.

Is the pilot still going ahead once the Statue of Liberty reopens? How long is the pilot expected to last?

If you could send me some information on this asap it'd be greatly appreciated.

*****

From: Ryan Gallagher
To: [Total Recall Corp. secretary] Viktoriya

20 March 2013 13:18

Hi Viktoriya, just wondering if you have managed to get me answers to my questions?

Thanks

*****

From: [Total Recall Corp. director of business development] Peter Millius
To: Ryan Gallagher
20 March 2013 14:06

Ryan,

Where did you get this information?

Please call me to discuss

*****

From: Ryan Gallagher
To: Peter Millius

20 March 2013 14:10

Hi Peter, calling now.

*****

PHONE CALL
Ryan Gallagher
Peter Millius
20 March 2013 14:19
Contemporaneous note

Millius asks where I heard about the pilot. I explain that I received a tip, had read about it in a police magazine, and that I had also spoken with Cognitec about it.

He says: "At this time there is not going to be a pilot project of the facial recognition at the Statue of Liberty although if it was it would be with Cognitec. We do work with Cognitec but right now because of what happened with [Hurricane] Sandy it put a lot of different pilots that we are doing on hold.

"There are no plans put something in right now. There are a lot of other things that need to get fixed. And they said that once we get all that stuff up we can start talking about that again. But nothing to talk about right now.

"Total recall is doing a security program at the Statue of Liberty. However, if you'd like to do a story about it I could talk to you about it more in detail when we want to do a full press release and so on and so forth.

"It's still months away and the facial recognition right now is not going to be part of this phase.

"We're in the middle of trying to work out what's going to get installed and what's not going to get installed.

"The timing is just premature."

[Millius then puts me on hold. He returns a minute or two later and puts me on speakerphone. One of his colleagues joins the call but does not introduce himself.]

Millius now says that the company had "discussed the possibility of it [a face recognition pilot] and it's been completely vetoed."

I ask, vetoed by who? He says the "Park Police."

I ask why it was vetoed and he says I should contact the Park Police. He declines to answer specific further questions and adds that I am "not authorized" to write about any use of face recognition at the statue.

*****

From: Ryan Gallagher
To: Elke Oberg [Cognitec]

20 March 2013 15:20

I have a couple more questions for you regarding the Statue of Liberty project. Do you think you could put me in touch with the person at Cognetic who knows most about this contract? Thanks.

*****

From: Elke Oberg
To: Ryan Gallagher

20 March 2013 15:23

LETTER ATTACHED.

Please consider this a written confirmation that you are to refrain from publishing any information about the use of face recognition at the Statue of Liberty. As you learned from Total Recall, the project was cancelled and you have false information.

If you decide to publish the information, we will need to take legal action to demand an official correction statement.

We appreciate your professionalism and integrity.

*****

From: Ryan Gallagher
To: Elke Oberg

20 March 2013 15:28

This is quite confusing. You told me yesterday that they were going to be trying out the Cognitec software at the statue. When and why was the project cancelled?

*****

From: Elke Oberg
To: Ryan Gallagher

20 March 2013 15:33

I asked you that I did not have any current information and that you need to talk to Total Recall about the status of this project. They told you and confirmed to me that the project is not happening. The City of New York has not approved it.

*****

From: Ryan Gallagher
To: Elke Oberg

20 March 2013 15:35

So the software is not going to be used because the City of New York has not given it approval?

You said yesterday, and I quote: "Yes, they are going to try out our technology there."

*****

From: Elke Oberg
To: Ryan Gallagher

20 March 2013 15:40

Again, I do not have any exact information about this. I thought you spoke to Total Recall about it?

*****

From: Ryan Gallagher
To: Elke Oberg

20 March 2013 15:42

I have spoken with Total Recall, yes, but I am trying to verify what they are saying. It is all very confusing and I have been provided contradictory information from different sources.

*****

From: Elke Oberg
To: Ryan Gallagher

20 March 2013 15:51

There seems enough confusion to leave the subject out of your article.

*****

From: Elke Oberg
To: Ryan Gallagher

20 March 2013 15:51

Quite the contrary, the confusion and people threatening me with legal action only encourages me to keep digging and establish the facts.

*****

From: Ryan Gallagher
To: Peter Millius

20 March 2013 16:52

Hi Peter,

A follow-up question for you. I have been back in touch with Cognitec and they are now saying that the facial recognition pilot project at the Statue of Liberty was "cancelled" because "the City of New York has not approved it."

Is that correct?

*****

From: Peter Millius
To: Ryan Gallagher

20 March 2013 17:04

LETTER ATTACHED.

Please consider this a written confirmation that you are to refrain from publishing any information about Total Recall and the Statue of Liberty or the use of face recognition at the Statue of Liberty. As you learned from Total Recall, the project was cancelled and you have false information.

If you decide to publish the information, we will need to take legal action to demand an official correction statement.

*****

From: Ryan Gallagher
To: Peter Millius

20 March 2013 17:10

Thanks for the interesting note, Peter. Who was the project cancelled by? You mentioned in our phone call that it had been "vetoed" by the Park Police, and Cognitec told me that "the City of New York has not approved it." Which of these statements is correct? If you could help clarify it'd be much appreciated.

*****

From: Peter Millius
To: Ryan Gallagher
CC: Attorney from Greenberg Traurig law firm.

20 March 2013 18:01

As I have previously told you- I have no comment and please be advised that we will take legal action against you personally and your company if you continue to harass me or chose to publish anything

*****

From: Ryan Gallagher
To: Peter Millius

20 March 2013 18:09

I am merely asking questions, Peter, legitimate questions. That is my job. I am a journalist. But If you have no further comment then I shall send no more inquiries. Thanks for your time.

*****

PHONE CALL
Ryan Gallagher
Elke Oberg [Cognitec]
22 March 2013 2:26pm
Contemporaneous note; summary of call

RG: I'm just trying to establish some of the details around why the project was cancelled, as you're saying.

Oberg: "I have no idea, Ryan, I really don't know. All I know is it's cancelled and that's the end of it... I have no information on it."

You did say the other day that they were 'going to try out our technology there.' So I'm just trying to establish what changed and why.

"Yes, not on that particular project, though, that particular project I don't know anything about. They informed us it was cancelled and I don't know any more than that."

You said you were aware it was going ahead at the statue.

"No, I did not say that. I don't know if it was scheduled."

Why did you tell me then, 'yes they're going to try out our technology there'?

"I don't think I said that."

Yes, you did.

"Then I must have made a mistake. I don't know anything about this project."

So you've never had any knowledge of this being tested at the Statue of Liberty, is that true?

"No, I don't. As I said, you need to ask the contractor."

*****

From: Ryan Gallagher
To: Peter Millius

28 March 2013 18:03

Mr. Millius,

I'm hoping you might have had a chance to reflect since our correspondence last week. I thought I would give you a final opportunity to talk with me — on record or off — about the reasons for the cancellation of the face recognition project at the Statue of Liberty. I am going to be writing about it based on information from a variety of sources. As things stand, your attempt to prevent me from reporting on the project will be a central focus of the story. But, of course, it doesn't have to be that way, and if you would like to discuss the project and the reasons for its cancellation then I would be happy to make time at your convenience for a phone call.

*****

Millius never responded to my final attempt to clarify details around the claimed cancellation of the Statue of Liberty face recognition project. The full article based on the above correspondence can be found at Slate.

Jack Straw, MI6, and Extraordinary Rendition

Thursday, 14 March 2013

There was a very interesting interview aired this evening on Channel 4 News with former UK foreign secretary Jack Straw, which touched on the British government's role in the Iraq War and alleged complicity in kidnappings and torture.

First, some important context.

In 2004, a Libyan Islamist militant anti-Gaddafi fighter Abdel Hakim Belhadj and his pregnant wife were abducted at a Bangkok airport and "rendered" to Libya by American agents. Belhadj was taken to one of Gaddafi's prisons and says he was subjected to torture.

At the time, British government officials were publicly denying any role in so-called "extraordinary rendition" — the practice used frequently by the United States under the George W. Bush administration involving kidnapping terror suspects and taking them to secret locations in third countries where they were sometimes brutally interrogated. But amid the revolution in Libya in 2011, a trove of classifed documents were found during the raid of a government office revealing British spy agency MI6 had in fact played a role in rendition — providing crucial intelligence that resulted in Belhadj being handed over to Gaddafi.

MI6 did not deny involvement when the documents were discovered: instead, UK government sources insisted the agency's actions were part of "ministerially authorised government policy." Then, in April last year, the Sunday Times reported that Jack Straw — foreign secretary between 2001 and 2006 — had been forced by MI6 to admit he had signed off on the secret rendition of Belhadj.

A few days after the Sunday Times report, Belhadj, who is now a military commander in the new Libya, launched legal action against Straw for alleged complicity in illegal rendition and torture.

Now, to the interview.

Tonight, on Channel 4 News, Straw made some eyebrow-raising statements to reporter Alex Thomson in light of the above. Previously he has declined to comment on the Belhadj case, and he told Channel 4 that he wouldn't discuss specifics. But he did make several short remarks that seem significant:

Thomson: It seems extraordinary to have to ask this question... but is the kidnapping and torturing of people by nation states wrong?

Straw: Of course it's wrong and we had no part in that.

Thomson: Are you sure we had no part in it?

Straw: Absolutely. It is wrong. It is absolutely wrong for any of that to have happened.

Thomson: And you are sure that the UK government had no part in it, that's what you just said?

Straw: Well, I'm absolutely sure that I had no part in this, let's just be clear about this OK, and there is going to be a full-scale judicial-led inquiry on the wider issues.

So Straw was clear. "I'm absolutely sure that I had no part in this," he said. Here is what the Sunday Times reported last year:

JACK STRAW, the former Labour foreign secretary, admitted that he had approved the secret rendition of a terrorist suspect to Libya after MI6 showed him evidence proving he had signed off the operation, well placed sources say.

Straw, who faces questioning by police over claims by Abdel Hakim Belhadj that he was tortured in a Libyan prison after being seized in 2004, was confronted by Secret Intelligence Service (MI6) officers after publicly appearing to deny he had authorised rendition.

Asked about Britain’s rendition policy during an interview on BBC Radio 4 last autumn, Straw said: “The position of successive foreign secretaries, including me, is that we were opposed to unlawful rendition, opposed to torture or similar methods and not only did we not agree with it, we were not complicit in it, nor did we turn a blind eye to it."

According to well-placed sources, within days of those comments MI6 officers met Straw. “They reminded him [Straw] that he had signed off on it. He was shown evidence and [then] he did accept that he had signed off on the rendition," said one insider.

Straw has repeatedly declined to comment publicly on the Belhadj case. This weekend a spokesman for him said: “I think that you will readily understand that while an investigation is pending, it is not appropriate for Mr Straw to respond to queries like yours."

And here is a timeline of the key events:

6-8 March 2004: Abdel Hakim Belhadj and his wife Fatima Bouchar are abducted at a Bangkok airport and flown to one of Gaddafi's prisons in Libya.

13 December 2005: Jack Straw, then foreign secretary, tells MPs in response to concerns about rendition: "Unless we all start to believe in conspiracy theories and that the officials are lying, that I am lying, that behind this there is some kind of secret state which is in league with some dark forces in the United States, and also let me say, we believe that Secretary Rice is lying, there simply is no truth in the claims that the United Kingdom has been involved in rendition full stop, because we have not been."

4 September 2011: Documents are found by Human Rights Watch inside the abandoned office Gaddafi's former intelligence chief, Moussa Koussa. One file contained hundreds of secret letters and faxes that UK spy agency MI6 and US spy agency the CIA had sent to Koussa, some revealing "evidence that British intelligence agencies mounted their own 'rendition' operation in collaboration with Muammar Gaddafi's security services." One document showed MI6 counter-terror chief Mark Allen boasting to Koussa about helping render Belhadj in 2004. “The intelligence was British," Allen wrote, adding that assisting in rendering Belhaj by providing information about his movements was “the least we could do for you and for Libya."

5 September 2011: Straw tells BBC Radio 4 in response to the discovery of the documents: “The position of successive foreign secretaries, including me, is that we were opposed to unlawful rendition, opposed to torture or similar methods and not only did we not agree with it, we were not complicit in it, nor did we turn a blind eye to it."

8 April 2012: Extensive details on the rendition of Belhadj and his wife emerge in a special report published by the Guardian. It opens: "Just when Fatima Bouchar thought it couldn't get any worse, the Americans forced her to lie on a stretcher and began wrapping tape around her feet. They moved upwards, she says, along her legs, winding the tape around and around, binding her to the stretcher. They taped her stomach, her arms and then her chest. She was bound tight, unable to move."

15 April 2012: The Sunday Times reports that following Straw's Radio 4 appearance in September 2011, officers from MI6 met with him. A source told the newspaper: "They reminded him [Straw] that he had signed off on it [the rendition of Belhadj]. He was shown evidence and [then] he did accept that he had signed off on the rendition."

18 April 2012: Belhadj launches legal action against Straw over alleged complicity in illegal rendition and torture.

14 March 2013: Straw claims in an interview aired by Channel 4 News that he is "absolutely sure that I had no part in this [extraordinary rendition and torture]."

*****

It doesn't take a genius to see that something does not add up here. There are clear inconsistencies between statements made publicly by Straw and the secret documents, and Straw's Channel 4 interview today contradicted both the secret documents and the claims published by the Sunday Times. The long-delayed judge-led inquiry into the UK's involvement in rendition cannot begin soon enough.

*****

UPDATE, 4 April 2013: It is reported that Straw and former MI6 spy chief Mark Allen say "they cannot respond to allegations of conspiracy in the torture of a prominent Libyan dissident [Hakim Belhadj], pleading the need to protect official secrets." Court documents seen by the Guardian show the former foreign secretary is arguing that the law means he "can neither confirm or deny [MI6] operations," claiming he cannot plead in the case without "causing real harm to the public interest."

However, Straw does explicitly deny misleading parliament in 2005 with his statement that Britain had not "been involved in rendition full stop." Straw claims, according to the Guardian's report, that:

it was 'readily apparent' ... that the committee at the time was discussing 'extraordinary rendition' — that is, rendition specifically carried out for the purposes of torture.

This denial strikes me as tenuous in the extreme, because when you read Straw's full 2005 statement to the parliamentary committee it is not at all clear that when he is talking about rendition he is only talking about rendition in the context of torture. Indeed, he even says at one point that "rendition is a term of art which covers a variety of activities," before going on to add: "there simply is no truth in the claims that the United Kingdom has been involved in rendition full stop, because we have not been." Of course, we now know that the UK was involved in rendition, at the time when Straw was the foreign secretary and thus the responsible minister.

*****

UPDATE II, 22 December 2013: A long-delayed UK government report on British spy agencies' complicity in rendition and torture is finally released on 19 December. The report finds that MI6 turned a "blind eye" to the torture of detainees and was not under any obligation to report breaches of the Geneva Convention. In response to the publication of the report, Jack Straw issues yet another denial, saying in a statement to parliament:

as Foreign Secretary, I acted at all times in a manner that was fully consistent with my legal duties and with national and international law, and that I was never in any way complicit in the unlawful rendition or detention of individuals by the United States or any other state.

The following day, on 20 December, the UK High Court rejects Abdel Hakim Belhadj's rendition and torture case against the government, which Straw was reported to have signed off on. Astonishingly, the judge says that while Belhadj appears to have a "potentially well-founded claim that the UK authorities were directly implicated in the extraordinary rendition," the case cannot proceed because pursuing it would "jeopardise national security." Belhadj is now trying to appeal against the decision.

*****

UPDATE III, 12 November 2015: Citing ongoing Supreme Court proceedings, The Guardian reports that Straw and former MI6 spy Sir Mark Allen "could avoid prosecution over complicity in the rendition and torture" of Belhadj and his wife by claiming immunity in the case.

Spy Trojan Seller on Ethics, Authoritarians, & 'Bad Guys' vs. 'Good Guys'

Monday, 11 March 2013

Headquartered out of a modern industrial estate in Andover, England, Gamma Group sells controversial advanced surveillance technologies to intelligence and law enforcement agencies in countries across the world. The company has been the source of widespread news coverage over the last couple of years due to its spy trojan tools — designed to secretly infiltrate computers, monitor communications and siphon data from hard drives — which security researchers say they believe are being used by authorities in a host of countries with poor human rights records, including: Bahrain, Brunei, Ethiopia, Indonesia, Mongolia, Singapore, Turkmenistan, and the United Arab Emirates.

Recently, I had an interesting and at times revealing back-and-forth email exchange with Gamma's Germany-based spokesman, Martin J. Muench. It is significant enough that I feel it is worth reproducing here, mainly because it offers an unusual level of insight into Muench's — and ultimately Gamma's — thinking.

The exchange began when I sent Muench a query regarding a prospective story I was working on — a follow-up to a Netzpolitik article detailing documents showing German federal police's plans to use Gamma's "Finfisher" (a.k.a "FinSpy") computer surveillance software. I also wanted to ask Muench about a "code of conduct" his company is apparently looking to implement in response to concerns about complicity in human rights violations.

However, the exchange, all on the record, eventually became a broader discussion about selling surveillance technologies, with Muench telling me that "we don’t necessarily agree with each other as far as the definition of what is ethical" and adding that he thought journalists had kicked up a "fuss" about Finfisher because they themselves were "guilty of the most appalling breaches."

It makes for quite a thought-provoking read, I think, especially toward the end. The content of the correspondence has not been edited, though I have removed email signatures and greetings ("Hi Ryan," "best regards," etc.) to cut out unnecessary repetition.

*****

From: Ryan Gallagher
To: Martin J. Muench

22 January 2013 12:52

I was reading this report on netzpolitik.org about the German Bundeskriminalamt acquiring Finspy: https://netzpolitik.org/2013/secret-government-document-reveals-german-federal-police-plans-to-use-gamma-finfisher-spyware/

I wanted to confirm with you:

1. is this an accurate report? Have the Bundeskriminalamt purchased Finspy or are they just testing it?

2. I note that the Netzpolitik report says you are in talks with NGOs with regards introducing a code of conduct for companies like yours. Which organizations are involved in the discussions? Can you share any information about what the code of conduct might include? And are any other companies involved?

*****

From: Martin J. Muench
To: Ryan Gallagher

22 January 2013 13:15

1. is this an accurate report? Have the Bundeskriminalamt purchased Finspy or are they just testing it?

As you can imagine this article and others relating to it have stimulated a great deal of interest...

However, I am afraid I have to tell you that Gamma simply does not discuss its client base, its exports, or any of the operations which its clients may or may not be undertaking. This is because there is usually a contractual term of confidentiality, and because naming a client can prejudice criminal or counter terror investigations and compromise the security of the members of the police or security services involved. Neither will Gamma name any countries which have not purchased its products thereby enabling customer countries to be identified by a process of elimination.

2. I note that the Netzpolitik report says you are in talks with NGOs with regards introducing a code of conduct for companies like yours. Which organizations are involved in the discussions? Can you share any information about what the code of conduct might include? And are any other companies involved?

We are currently having discussions with several groups. I don’t wish to elaborate further at the moment as some of these groups are our most vociferous public critics but who are quite prepared to discuss our ideas with us in private. In fact we have drafted a proposed Code of Conduct for the industry which goes far beyond the current ECAs.

*****

From: Ryan Gallagher
To: Martin J. Muench

22 January 2013 14:04

Regarding the code of conduct: is there any way you can send me a copy of the draft so I can get an idea of what it includes? Will it be made available publicly?

I note that Privacy International were previously reported to have turned down an invitation to discuss the code of conduct: http://www.guardian.co.uk/technology/2012/dec/26/british-company-gamma-international

Why did Privacy International refuse to engage? Do you think the code will have credibility if groups like Privacy International say they won't meet you to discuss it?

*****

From: Martin J. Muench
To: Ryan Gallagher

22 January 2013 14:16

I would honestly appreciate not putting too much focus on it at this point as I firstly would like to finish it and most of all also implement everything that has been and will be defined in there before promoting it publicly. Once it's done and we began the implementation we will definately make it public.

PI was offered numerous times a visit to our offices, a full product demonstration and open discussions about various topics. They mentioned that they're discussing internally a few month ago but did not respond to any follow-up emails. No reasons were given on why the offer was ignored.

I can only guess or better wonder why Eric King of PI does not want a personal meeting and also see the other side of the stories especially as he is spending so much time and energy on them without having the full picture; but I don't think that one organisation like PI not being interested in also giving constructive criticism will affect the credibility of such a code on a global level.

*****

From: Ryan Gallagher
To: Martin J. Muench

22 January 2013 15:05

If you have not yet implemented the code of conduct, doesn't that mean you are acknowledging that thus far you have not been adhering to appropriate ethical standards? What exactly is it that you need to implement? It would be great if you could show me a draft of the code, even on a background basis, to help me understand the context of the thing.

*****

From: Martin J. Muench
To: Ryan Gallagher

22 January 2013 21:56

Firstly, let me correct you. I am not acknowledging that Gamma has not adhered to ethical standards at all. One problem with ethical standards is that we all have them and we don’t necessarily agree with each other as far as the definition of what is ethical. Who decides? You have your views, I have mine and others have theirs’. That’s not to say we all disagree on everything. It simply means that we don’t all have the same views and for very different reasons.

Our position is this; we believe in the right to privacy but we don’t believe it takes precedence over or supersedes the right to life. We believe that nation states have the right to defend themselves against terrorists and we believe in the right to fight organised crime. We sell FinFisher to governments and law enforcement agencies to do this. We don’t sell a mass-monitoring tool. We sell a highly sophisticated piece of target specific software capable of providing evidential quality reports.

Another problem, of course, is that today’s ‘good guy’ may be tomorrow’s ‘bad guy’ and vice versa. If we imposed a moral code based on our intuition as to who might become a bad guy in the future we could end up spending a lot of time thinking about it and doing very little else. So, until we can get a code of conduct up and running that will actually work, rather than pay lip service to ‘ethics’, we have decided to let the export controls authorities act as our ‘moral compass’, for want of a better expression. After all, they are best placed to know who the ‘bad guys’ are and who the likely future ‘bad guys’ will be. We follow their lead and comply with the law.

Of course one of the reasons that some of the media have picked up on FinFisher products and make such a fuss is that some of them have become the subject of law enforcement inquiries themselves by electronic means and have been shown in the past to be by their own admission guilty of the most appalling breaches. The Leveson Inquiry shows a good example of this.

*****

From: Ryan Gallagher
To: Martin J. Muench

23 January 2013 03:30

Your last email raises many questions for me.

One problem with ethical standards is that we all have them and we don’t necessarily agree with each other as far as the definition of what is ethical.

Ethical standards can sometimes be highly subjective but they are often also relative to basic standards of right and wrong. Would it be ethical for me to sell a gun to a man I knew had a history of violence and might subsequently use it to murder an innocent person? I think the answer to that question is obvious. And I think the same kind of hypotheticals can be used in the realm of surveillance technologies. Would it be ethical for me to sell a sophisticated spy technology to a notoriously brutal state security agency operating in a country ruled by a despot with a well documented record of cracking down on, beating and jailing people engaging in legitimate democratic activities?

So, until we can get a code of conduct up and running that will actually work, rather than pay lip service to ‘ethics’, we have decided to let the export controls authorities act as our ‘moral compass’, for want of a better expression.

By this I assume you mean European export controls? Or are you also including United Nations and United States sanctions?

I should point out that just because a company is not on an export control list doesn't mean it is a place where human rights violations are not rife. For instance, countries such as Turkmenistan, Kazakhstan, Uzbekistan, Morocco and Thailand are ruled by authoritarian regimes with little (if any) limitations on the use of sophisticated spy technologies to monitor innocent individuals participating in legitimate democratic activities (journalism, activism, etc.). It is a given that these countries also have serious criminals whom they wish to monitor. But they may also have a disposition towards abusing surveillance technology to stifle dissent, track dissidents, target journalists, etc.

Have you never considered conducting an analysis of each country's respective social and polititical conditions before you do business with it? This is in line with the "know your customer" program recommended by the United States and the UN Guiding Principles on Business and Human Rights, which outlines how companies should "act with due diligence to avoid infringing on human rights and address adverse impacts."

It doesn't strike me as due diligence for you to say that you will sell to any country so long as they are not on a sanctions list.

Of course one of the reasons that some of the media have picked up on FinFisher products and make such a fuss is that some of them have become the subject of law enforcement inquiries themselves by electronic means have been shown in the past to be by their own admission guilty of the most appalling breaches. The Leveson Inquiry shows a good example of this.

I find this to be a bit of an inaccurate comparison. The "phone hacking" scandal involved (unethical) tabloid journalists listening to the voicemails of individuals by entering a default PIN code into their mailbox to gain access. I don't think that it is comparable to providing authoritarian regimes with a sophisticated spy trojan that can be used to secretly take over targeted computers, intercept communications and steal data from hard disks. The scale is different, the technology is different, and, perhaps most crucially, the potential harms are different.

*****

From: Martin J. Muench
To: Ryan Gallagher

23 January 2013 08:51

Thanks for your email. It’s a fascinating debate and one in which we could engage for some time. I see you have strong views and clearly have made your own judgments but I am afraid that I am going to have to end it here.

Would it be ethical for me to sell a sophisticated spy technology to a notoriously brutal state security agency operating in a country ruled by a despot with a well documented record of cracking down on, beating and jailing people engaging in legitimate democratic activities?

This may well be a view held by some of; the UK (Northern Ireland), the USA (Guantanamo Bay) or Germany – and we are a little sensitive of our past. However, many people in the West might not view those counties that way…..

Debate aside and let’s be clear, we co-operate with the export controls agencies of Germany, the UK and the USA. Gamma simply does not discuss its client base, its exports, or any of the operations which its clients may or may not be undertaking. This is because there is usually a contractual term of confidentiality, and because naming a client can prejudice criminal or counter terror investigations and compromise the security of the members of the police or security services involved. Neither will Gamma name any countries which have not purchased its products thereby enabling customer countries to be identified by a process of elimination.

Lastly, may I suggest you have a closer look at the Leveson Inquiry — you may find it illuminating — at least in the definition of a tabloid (David Leigh of The Guardian admits to hacking an arms dealer?)

*****

From: Ryan Gallagher
To: Martin J. Muench

23 January 2013 13:33

Yes, it's an interesting discussion. I was particularly keen to hear your response to my question about due diligence and the UN Guiding Principles on Business and Human Rights, which I note that you did not answer directly.

we are a little sensitive of our past. However, many people in the West might not view those counties that way…..

What do you mean?

may I suggest you have a closer look at the Leveson Inquiry – you may find it illuminating — at least in the definition of a tabloid (David Leigh of The Guardian admits to hacking an arms dealer?)

Yes, that's right. There were a few cases included in the Leveson inquiry that focused on journalists outside the tabloids, though it was certainly a tabloid-orientated inquiry. The Leigh case is interesting because it reveals the extent to which investigative journalists will sometimes break the law in order to expose corruption — which can be deemed permissible under UK law if there is a substantial "public interest" defence. In 2006, well before Leveson, Leigh admitted to listening to voicemails of an arms dealer in order to help reveal corrupt payments. If you followed the case you would know that the UK's Crown Prosecution Service looked into Leigh's activities and advised that he not be prosecuted because on balance it was decided his actions were in the public interest: http://www.guardian.co.uk/media/2012/jun/14/police-guardian-journalist-phone-hacking

I understand why you raise the example. But ultimately it is unrelated to what we are discussing — that is, export controls and surveillance technologies. It's false equivalence for you to bring up Leveson in the context of selling spy trojans to authoritarian regimes. As I wrote in my previous message, the scale is different, the technology is different, and, perhaps most crucially, the potential harms are different.

*****

From: Martin J. Muench
To: Ryan Gallagher

23 January 2013 14:37

Thank you for your email. I do not wish to add anything at this point. You have my answers.