Showing posts with label gchq. Show all posts
Showing posts with label gchq. Show all posts

UK Police Snowden Probe Declared "Inactive"

Friday, 20 December 2019

In 2013, London's Metropolitan Police began a criminal investigation focusing on journalists who reported stories from a trove of secret documents leaked by the National Security Agency whistleblower Edward Snowden. Now, after six years and no arrests or prosecutions, the Met has confirmed that the investigation has been shelved.

The Met told me in response to a recent Freedom of Information request that the investigation is "inactive pending further information being received." Since 2014, I've had several updates from the Met regarding the investigation, and this marks the first time that its status has changed from "ongoing." In November 2017, the Met stated that it was a "complex investigation and enquiries continue."

The investigation, which was given the code-name Operation Curable, had been led by the Met's Counter-Terrorism Command, under the direction of assistant commissioner Mark Rowley. In March 2018, Rowley retired from the Met -- and with his departure, it seems the Curable investigation went cold.

The majority of the documents in Snowden's leaked archive revealed classified American mass surveillance operations. But a significant portion of the files disclosed explosive information about electronic spying programs operated by the UK’s largest intelligence agency, Government Communications Headquarters, or GCHQ.

British authorities responded furiously to the Snowden revelations and tried to prevent The Guardian from publishing them. Infamously, representatives from GCHQ were sent to the newspaper's London offices at one stage to oversee the destruction of hard drives that contained the secret files.

The police went as far as to argue that publishing the Snowden files was itself a terrorist act, thereby explicitly conflating journalism with terrorism. In August 2013, a memo authored by the Met and domestic spy agency MI5 asserted that “the disclosure [of the Snowden documents], or threat of disclosure, is designed to influence a government and is made for the purpose of promoting a political or ideological cause. This therefore falls within the definition of terrorism.”

In December 2013, one of the London force’s most senior officers, Cressida Dick, was questioned about the case during a parliamentary hearing. She acknowledged that the force’s investigation was looking at whether reporters at The Guardian had committed criminal offences -- some carrying potential 10-year prison sentences -- for their role in revealing secret surveillance operations exposed in the documents. “We need to establish whether they have or haven’t [committed offences],” Dick said. “That involves a huge amount of scoping of material.”

It is unclear how much taxpayer money and police resources were invested in pursuing the Curable investigation. The Met has declined to provide any information about the amount of funds spent on the probe, or disclose the number of officers who worked on it; the force claims that it does not hold records of these details. It is also unclear whether the investigation may at some point resume. The Met said that the probe is inactive pending further information being received -- what that information may be, and whether it will ever actually materialise, is anyone's guess.

UK Police Spying Expert Heading Probe into Snowden Leak Journalists

Wednesday, 28 October 2015

Back in July, London's Metropolitan Police admitted that it was still conducting a criminal investigation it launched two years ago into journalists who have reported on Edward Snowden's leaked documents.

Since then, I have been trying to find out more details about the investigation through the Freedom of Information Act. The Met is refusing to disclose virtually anything about the probe, but recently it did provide me with one new detail:
Specialist Operations under the direction of AC Mark Rowley is the MPS [Metropolitan Police Service] unit involved in the investigation related to the Snowden documents.
Rowley (pictured below) has taken over the Snowden investigation from Cressida Dick, the Met's former head of Specialist Operations, who quit the force in December last year to take up a secret new job at the Foreign Office. The Met confirmed this in an emailed letter it sent me late last month (I'd have written about it sooner but have been a bit swamped with other projects).

Rowley is an expert in covert surveillance methods and pioneered the development of new police spying techniques across the UK while working as a detective superintendent in the 1990s with the National Criminal Intelligence Service. Notably, he recently made clear he has no qualms about monitoring journalists' communications if he deems it necessary to “chase down criminals." He has also boasted about the London police being at the “cutting edge” of covert surveillance through the use of “specialist hardware and software.” (These specialist tools include powerful portable spying devices the Met uses to monitor mobile phone communications across targeted areas of London, as I reported back in 2011.)

The Met first announced it had launched an investigation related to the Snowden documents in August 2013, saying the criminal probe was being headed by its Counter Terrorism Command, which is a division of the Specialist Operations department. In December 2013, Rowley's predecessor Cressida Dick acknowledged during a parliamentary hearing that the investigation was looking at whether reporters at The Guardian had committed criminal offenses for their role in revealing secret surveillance operations exposed in the Snowden documents.

For almost seven months earlier this year, the Met refused to confirm or deny whether the investigation remained ongoing, repeatedly claiming doing so would be “detrimental to national security.” But the force performed a sudden volte-face on its position in late July following an intervention from the Information Commissioner’s Office, the public body that enforces the UK’s freedom of information laws.

I'm currently seeking more information about the investigation, such as details about how much money it has cost the taxpayer to date and the names of outside agencies or contractors that have assisted. The Met has so far refused to release this information — again spuriously claiming that doing so could somehow jeopardise national security — but I have lodged an appeal in an effort to have this decision reversed. Will post updates as and when I have them.

Questions About The Sunday Times Snowden Story

Sunday, 14 June 2015

The Sunday Times has a front page story out today claiming that the Chinese and Russian governments have somehow managed to obtain National Security Agency whistleblower Edward Snowden's trove of documents. The story is sourced from anonymous UK government officials who make a series of significant allegations, unfortunately backed up with zero evidence. It's worth going through some of the key points of the story to cast some critical scrutiny on the central claims and to raise a few questions about them:
1) "RUSSIA and China have cracked the top-secret cache of files stolen by the fugitive US whistleblower Edward Snowden...according to senior officials in Downing Street, the Home Office and the security services."
Is the claim here that a full archive of encrypted files was "cracked" by some sort of brute-force decryption attack? If so, how did these "senior officials" establish that? How did the Russians and Chinese allegedly obtain the encrypted material in the first place?
2) "forcing MI6 to pull agents out of live operations in hostile countries."
This was a surprise to me because I've reviewed the Snowden documents and I've never seen anything in there naming active MI6 agents. Were the agents pulled out as a precautionary measure? Keeping in mind that the UK government does not actually know exactly what Snowden leaked, how do these officials know there were documents in there that implicated MI6 operatives and live operations in the first place?
3) "Moscow gained access to more than 1m classified files held by the former American security contractor"
Snowden has said repeatedly that he did not carry any files with him when he left Hong Kong for Moscow. Is this article alleging that he is lying? If so, where's the evidence to support that? Moreover, I've seen nothing in the region of 1m documents in the Snowden archive, so I don't know where that number has come from. Oh, wait:
4) "Snowden, a former contractor at the CIA and National Security Agency (NSA), downloaded 1.7m secret documents"
This 1.7m figure was invented by US officials and since then it has been regurgitated repeatedly and unquestioningly by various media outlets. I've seen the trove of documents; the claim or insinuation that he leaked 1.7m is not true.
5) "A senior Downing Street source said: 'It is the case that Russians and Chinese have information'."
Of course they do: the same information that the rest of the world has access to in public news reports and documents published as part of those. If the claim here is that the Russians and Chinese have access to every single document in the entire archive (i.e. all the unpublished material), where is the evidence to support that? How do the officials know? Are they speculating? These are serious claims — and serious claims demand serious evidence. Which is unfortunately not provided here.
6) “Why do you think Snowden ended up in Russia?” said a senior Home Office source. “Putin didn’t give him asylum for nothing."
I thought this one had long since been debunked by now, but apparently not. The reality is that Snowden never intended to stay in Russia. He was trying to get to Latin America and only ended up in Russia because his passport was revoked by the US government while he was transiting through.
7) Senior Home Office source: "His documents were encrypted but they weren’t completely secure and we have now seen our agents and assets being targeted.”
So the UK Home Office is alleging Snowden lied about taking documents to Moscow? How has it established that? And the "targeted" assets — how does the source know this has happened as a direct consequence of the Snowden leaks? There are many other factors at play here, and correlation does not imply causation. Especially with regard to Russia, given that anonymous UK "security sources" claimed months ago — again in the Sunday Times — that they are engaged in a "new Cold War" against Kremlin spies due to the broader issue of Vladimir Putin's heightened military posturing.
8) "A British intelligence source said: 'We know Russia and China have access to Snowden’s material'."
As I noted above: the Russians and Chinese have access to documents published with public news reports, sure, that's obvious and true. But is the claim here that they have access to material beyond that? If so, where's the evidence? How does this source "know" and what does he "know," exactly? Why the vague statement? Let's hear what it is the source knows and how so we can properly assess and scrutinise the merit of the allegation.
9) "It is not clear whether Russia and China stole Snowden’s data, or whether he voluntarily handed over his secret documents in order to remain at liberty in Hong Kong and Moscow."
If it's not clear then why does the top line of the story say the Chinese and Russians "cracked" the documents? If Snowden just handed them over, why would they need to "crack" them? And if the Russians and Chinese somehow stole the documents in encrypted form, how did they a) manage to obtain them in the first place (especially given Snowden says he didn't carry the files with him into Russia), and then b) break the encryption?
10) "David Miranda, the boyfriend of the Guardian journalist Glenn Greenwald, was seized at Heathrow in 2013 in possession of 58,000 'highly classified' intelligence documents after visiting Snowden in Moscow."
This is wrong. Miranda was detained at Heathrow after visiting Laura Poitras in Berlin. He wasn't visiting Snowden in Moscow and I think this is the first time I've ever seen this asserted. It's false.

*****

All in all, for me the Sunday Times story raises more questions than it answers, and more importantly it contains some pretty dubious claims, contradictions, and inaccuracies. The most astonishing thing about it is the total lack of scepticism it shows for these grand government assertions, made behind a veil of anonymity. This sort of credulous regurgitation of government statements is antithetical to good journalism.

The government has an obvious vested interest in portraying Snowden as a terrible person who's helped "the enemy" — it has been badly stung by his surveillance revelations and the political fallout that has ensued as a result of them. For that reason alone its claims should be treated with caution and not repeated unchallenged. Evidence should be necessary for allegations of this magnitude, which have such big ramifications. The Sunday Times has a long and commendable history of holding the government to account with great investigative journalism. But in this case, sadly, it has allowed itself to be used by faceless officials as a mouthpiece.

UPDATE, 14 June 2015, 19:30 BST: My colleague Glenn Greenwald has a post up at The Intercept dissecting the Sunday Times report, which he blasts as "pure stenography of the worst kind." Greenwald writes that "the exact kinds of accusations laundered in the Sunday Times today are made — and then disproven — in every case where someone leaks unflattering information about government officials." He says the story is "as shoddy and unreliable as it gets. Worse, its key accusations depend on retraction-level lies."

The Guardian has a good piece from Ewen MacAskill with five pertinent questions for the British government about the claims. "Anonymous sources are an unavoidable part of reporting, but neither Downing Street nor the Home Office should be allowed to hide behind anonymity in this case," writes MacAskill, who travelled with Greenwald and Laura Poitras to meet Snowden in Hong Kong back in 2013. "Where is the evidence?" he asks.

In another interesting development, the Sunday Times quietly deleted the false assertion I noted above (see #10) about David Miranda having documents on his possession "after visiting Snowden in Moscow." This has been removed from the online version of the story with no correction or note, but it can still be found in the paper version, which I got a copy of. The inaccuracy was significant as it underpinned the central dubious narrative of the story — that the documents were "held" by Snowden in Moscow, the insinuation being that this was how the Kremlin was supposed to have gotten hold of them, a claim presented in the story as unquestionable fact because nameless officials "confirmed" it (without offering any evidence).

UPDATE II, 15 June 2015, 19:00 BST: The lead reporter on the Sunday Times article, Tom Harper, has given an interview with CNN that has to be seen to be believed. In it, Harper is quizzed by host George Howell about the piece — and his answers highlight the many problems with the story's central allegations and how they were sourced. Here's a transcript of the important bits; I'll dissect some key points below.

Howell: How do senior officials at 10 Downing Street know that these files were breached?

Harper: Well, uhh, I don't know the answer to that George. All we know is that this is effectively the official position of the British government ... we picked up on it a while ago and we've been working on it and trying to stand it up through multiple sources, and when we approached the government late last week with our evidence, they confirmed effectively what you read today in the Sunday Times, so it's obviously allegations at the moment from our point of view and it's really for the British government to defend it.

How do they know what was in them [the files], if they were encrypted? Has the British government also gotten into these files?

Well, the files came from America and the UK, so they may already have known for some time what Snowden took — uhh, again, that's not something we're clear on ... we don't go into that level of detail in the story we just publish what we believe to be the position of the British government at the moment.

Your article asserts that it is not clear if the files were hacked or if he just gave these files over when he was in Hong Kong or Russia, so which is it?


Well again sorry to just repeat myself George, but we don't know so we haven't written that in the paper. It could be either, it could be another scenario ... when you're dealing with the world of intelligence there are so many unknowns and possibilities it's difficult to state anything with certainty and so we've been very careful to just stick to what we are able to substantiate.

The article mentions these MI6 agents ... were they directly under threat as a result of the information leaked or was this a precautionary measure?

Uhh, again, I'm afraid to disappoint you, we don't know ... there was a suggestion some of them may have been under threat but the statement from senior Downing Street sources suggests that no one has come to any harm, which is obviously a positive thing from the point of view of the West.

So essentially you are reporting what the government is saying, but as far as the evidence to substantiate it, you're not really able to comment or explain that at this point?

No. We picked up on the story a while back from an extremely well placed source in the Home Office. and picked up on trying to substantiate through various sources in various agencies throughout Britain, and finally presented the story to the government, and they effectively confirmed what you read in today's Sunday Times. But obviously when you're dealing with intelligence it's the toughest nut to crack and unless you have leaked documents like Snowden had, it's difficult to say anything with certainty.

So, in summary: How were the files breached? "I don't know." Were the files hacked or did Snowden hand them over? "We don't know." Were MI6 agents directly under threat? "We don't know." How did the government know what was in the files? "That's not something we're clear on." Can you substantiate the claims? "No."

The interview is quite extraordinary because it makes absolutely clear that not only was this entire dubious story based solely on claims made anonymously by government officials, the reporters who regurgitated the claims did not even seek to question the veracity of the information. They just credulously accepted the allegations and then printed them unquestioningly. That really is the definition of stenography journalism — it's shameful.

It's also worth noting that in Harper's interview he admits he has no idea how the Chinese and Russian governments supposedly obtained the files, yet the whole story was based on a bombshell claim that the trove of files was somehow "cracked" by Chinese and Russian government operatives (i.e. that the encryption on them was broken). As I noted above in point #9, if Snowden just handed over the files, why would these governments then need to "crack" them, unless the claim is that he handed over a set of encrypted documents? Either way, Harper says he has no idea how the files were obtained, so how does he know they were "cracked"? This central allegation seems to have been invented completely out of thin air, at worst a fabrication by technologically inept reporters who don't understand what terminology like "cracked" means, at best derived from evidence-free conjecture from spineless government officials too afraid to put their names to the claims.

It is also very telling to note that Harper cites "an extremely well placed source in the Home Office" as the initial person who tipped him off about the story. That's presumably the same "senior Home Office source" quoted in the story insinuating that Snowden chose to go to Russia and hand over documents in return for asylum. That absurd allegation, as I noted in point #6 above, contradicts the fact that Snowden only ended up in Moscow because the US government foolishly revoked his passport and stranded him there while he was passing through on route to Latin America; moreover, Snowden has said repeatedly that he didn't take any documents to Russia. Any reporter familiar with the story knows this. An assertion from an official claiming Snowden went there to hand over documents should surely have set off alarm bells about the credibility of his claims, and should have at least prompted a demand for evidence to back them up, given their magnitude.

But no alarm bells were triggered in our boy Harper's head. Sounding more like a government press officer than a journalist, he told CNN: "we just publish what we believe to be the position of the British government at the moment."

And that brings me to my final point on this. Harper claimed in his CNN interview that his story was "effectively the official position of the British government." If that's the case, then why will no one in the government come out and say so publicly? As the well-sourced BBC security correspondent Gordon Corera noted in a measured analysis on Sunday: "No one in government today is confirming that they are sure that the Russians and Chinese have got full access — that remains in the realm of 'no comment'."

Year in Review

Monday, 5 January 2015

Well, 2014 turned out to be quite a year. For me, it was a really productive one, and I was lucky enough to get the opportunity to work on some great projects. Below are a few personal highlights that I've put together as a sort of 'year in review', along with a list of notable stories and developments in the realm of surveillance and national security, some 'ones to watch' for 2015, and a few awards that I've decided to hand out for dishonourable government conduct, just because there was so much of it over the last twelve months, and the worst offenders deserve some recognition...

(I meant to post this last week, but I've been on a remote Spanish island on holiday with no internet connection... so here it is, better late than never...)
 
January to March

In January I worked with Canadian broadcaster CBC to reveal details about domestic surveillance in the Canada. In February, The Intercept launched, and I contributed to a story that revealed some new details about US and UK government efforts to target WikiLeaks. In March, I had a report out shining a light on how the US National Security Agency has worked alongside its UK partner Government Communication Headquarters to infect large numbers of computers across the world with malware. I also worked on a story exposing the NSA's targeting of innocent system administrators as part of its covert attempts to hack into communication networks.

April to June

In March, I worked with German news magazine Der Spiegel on a story revealing new details about the NSA's surveillance of world leaders. In April, I reported on British spies' attempts to get broad unsupervised access into NSA troves of surveillance data. And in June, I worked with some great reporters at Danish newspaper Dagbladet Information to reveal new information showing how the NSA forms secret partnerships with countries across the world in order to help significantly expand its surveillance reach.

July to September

In August, the US military banned its personnel from reading The Intercept, and a few days later we published one of the most important stories I've worked on to date, exposing a vast US surveillance search system used to share huge troves of private data among dozens of US government agencies, including domestic law enforcement. The story revealed the decades-long history of US agencies' use of masses of metadata to monitor people's behaviour, and exposed how the CIA was using metadata to aid its efforts to secretly kidnap terror suspects (a practice that often resulted in the suspects — some of whom were totally innocent — being brutally tortured).

In September, we began reporting details at The Intercept about the scope of surveillance in New Zealand, and shined a light on deceptive statements made by the government there about its spying efforts; meanwhile, police raided and ransacked the home of the excellent investigative reporter that we were (and are) working with on Snowden revelations related to New Zealand.

October to December

In November, I worked on a story revealing how one of the most sophisticated pieces of malware ever discovered — dubbed "Regin" by security experts — was linked to cyberattacks perpetrated by British spies against Belgian telecommunications company Belgacom and European Union offices. This piece was an interesting one to work on in that it combined both news reportage with malware analysis — something that's never been done before in journalism, I think — and was published alongside downloadable samples of the Regin malware.

In December, I had a new report out revealing a secret NSA program that involves spying on emails sent among hundreds of mobile phone companies around the world, a practice that helps the agency hack into phone networks. The story exposed how the NSA targeted a London-headquartered trade group that represents tech giants like Microsoft and Facebook, and provided evidence that NSA had been working to insert security vulnerabilities into global telecommunications infrastructure so that they can be exploited for surveillance.

Also in December, I reported new details about the GCHQ hack of Belgian telecommunications company Belgacom as part of a reporting collaboration with newspapers in Belgium and the Netherlands. This particular story is one that I am especially proud of; it was the culmination of about six months of work, and took a huge amount of cooperation with different teams operating out of four separate countries simultaneously. We were able to tell the full story of the British hack on Belgacom, a hugely significant incident representing an unprecedented cyberattack by one EU member state on another. The story included new 'smoking gun' evidence showing that the Regin malware samples contained code-names that also appeared in secret GCHQ documents obtained from whistleblower Edward Snowden.

Vital stories

Here a list of some reports and developments that stood out to me in 2014:

NSA collects millions of text messages daily in 'untargeted' global sweep, The Guardian, 16 January.

Snowden docs show UK spies attacked Anonymous, hackers, NBC News, 4 February.

The NSA’s secret role in the US assassination program, The Intercept, 10 February.

Optic Nerve: millions of Yahoo webcam images intercepted by GCHQ, The Guardian, 27 February.

NSA surveillance program reaches ‘into the past’ to retrieve, replay phone calls, Washington Post, 18 March.

Top EU court rejects EU-wide data retention law, BBC News, 8 April.

Death from above: how American drone strikes are devastating Yemen, Rolling Stone, 14 April.

Turkish president approves law widening secret service's powers, Reuters, 24 April.

The NSA is recording every cell phone call in the Bahamas, The Intercept, 19 May.

Germany arrests man suspected of spying for US, BBC News, 4 June.

NSA: Inside the five-eyed vampire squid of the Internet, The Register, 5 June.

Vodafone reveals existence of secret wires that allow state surveillance, The Guardian, 6 June.

US officials scrambled to nab Snowden, hoping he would take a wrong step. He didn’t, Washington Post, 14 June.

GCHQ sanctions spying on every Facebook, Google and Twitter user, The Telegraph, 17 June.

In NSA-intercepted data, those not targeted far outnumber the foreigners who are, Washington Post, 5 July.

Germany to spy on US for first time since 1945 after ‘double agent’ scandal, The Independent, 7 July.

Meet the Muslim-American leaders the FBI and NSA have been spying on, The Intercept, 9 July.

Hacking online polls and other ways British spies seek to control the Internet, The Intercept, 14 July.

The secret government rulebook for labeling you a terrorist, The Intercept, 23 July.

CIA Admits improperly hacked into Senate computers, Washington Times, 31 July.

Barack Obama’s secret terrorist-tracking system, by the numbers, The Intercept, 5 August.

The Islamic State (documentary), Vice, 7 August.

German spy company helped Bahrain hack Arab Spring protesters, The Intercept, 8 August.

Photos of alleged 9/11 '20th hijacker' can stay classified: court, Reuters, 2 September.

MRAPs and bayonets: what we know about the Pentagon's 1033 program, NPR, 2 September.

The NSA and GCHQ campaign against German satellite companies, The Intercept, 14 September.

Israel's NSA scandal, New York Times, 16 September.

Wikileaks releases FinFisher files to highlight government malware abuse, The Guardian, 16 September.

The NSA and me, The Intercept, 2 October.

Citizen Four (documentary), 10 October.

Why was the NSA chief playing the market? Foreign Policy, 22 October.

MI5 spied on leading British historians for decades, secret files reveal, The Guardian, 24 October.

In Cold War, US spy agencies used 1,000 Nazis, New York Times, 26 October.

Secret manuals show the spyware sold to despots and cops worldwide, The Intercept, 30 October.

Brazil is keeping its promise to avoid the US Internet, Gizmodo, 30 October.

Disguised as climate negotiators, Dagbladet Information, 1 November.

UK intelligence agencies spying on lawyers in sensitive security cases, The Guardian, 7 November.

FBI says it impersonated AP reporter in 2007 case, AP, 7 November.

Americans’ cellphones targeted in secret US spy program, Wall Street Journal, 14 November.

WhatsApp now provides end-to-end encryption for your messages, Gizmodo, 18 November.

Before Snowden, a debate inside NSA, AP, 19 November.

US firms accused of enabling surveillance in despotic Central Asian regimes, The Intercept, 20 November.

How Vodafone-subsidiary Cable & Wireless aided GCHQ’s spying efforts, Süddeutsche Zeitung, 25 November.

CIA torture report, 9 December.

WikiLeaks CIA leaks, 18 & 21 December.

Inside the NSA's war on internet security, Der Spiegel, 27 December.

The Sabu Files, Vice/Daily Dot.

Save our sources campaign, The Press Gazette.

Ones to watch in 2015

Some things worth keeping an eye on...

A new US cybersecurity unit that will advise agencies on surveillance operations.

Details about a secret database being used by federal agents in the US, the existence of which has become the subject of dispute in an ongoing court case.

Information about documents being shredded en masse in a UK police anti-corruption investigation.

Developments in the US government's ongoing criminal investigation into WikiLeaks, which may have involved the use of a prominent informant.

The long-overdue publication of a government-commissioned post-Snowden review of UK surveillance operations.

The US government using state secrecy powers to block the release of files from anti-Iran group.

Renewed 'crypto wars' as law enforcement agencies in the US push for more powers to combat privacy-protecting encryption technologies.

More details about the CIA's hacking of Senate computers.

A continuing government effort to introduce new laws bolstering surveillance powers in the US, UK, Australia, Canada, and New Zealand.

Many more stories from the Snowden documents related to secret spying conducted by the US, UK, Australia, Canada, New Zealand, and other countries.

Now for a few awards...

Because I feel like handing out some dubious accolades:

Bullshit statement of the year

Winner: Recently retired GCHQ spy chief Sir Iain Lobban for his claim in October that the agency doesn't engage in "anything remotely resembling mass surveillance." A completely false statement that could not be further from the truth.

Runner-up: UK home secretary Theresa May for "collection of bulk data is not mass surveillance."

3rd prize: former US vice-president Dick Cheney for "we were very careful to stop short of torture."

Dishonourable mentions: former NSA and CIA chief Michael Hayden for "I didn’t do anything wrong"; New GCHQ spy chief Robert Hannigan for "GCHQ is happy to be part of a mature debate on privacy in the digital age."

Orwellian euphemism of the year

New Zealand's prime minister John Key tries and fails to make mass surveillance palatable to the public in September by re-branding it "mass protection."

Outrageous admission of the year

Former NSA and CIA chief Michael Hayden tells an audience at Johns Hopkins University in April: "We kill people based on metadata."

Understatement of the year

President Barack Obama, in August, on the CIA's brutal human rights abuses post 9/11: "We tortured some folks."

Gaffe of the year

UK foreign secretary Philip Hammond, who is responsible for signing off on GCHQ surveillance operations, illustrates that he doesn't have a clue what he's been approving during a parliamentary hearing in October.

Hypocrite of the year

Michael Hayden, the CIA chief who overseen the agency's secret extrajudicial kidnapping operations that involved imprisoning and torturing terrorism suspects, some of whom were entirely innocentcomplains in December that a Senate report criticising CIA torture methods was like being "tried and convicted in absentia. We were not given an opportunity to mount a defense."

Most bizarre mass surveillance justification of the year

UK prime minister David Cameron explains to British lawmakers in January that fictional TV crime dramas demonstrate the need for new dragnet spying powers.

Most absurd response to surveillance revelations of the year

A special joint award that goes to the Canadian prime minister's parliamentary secretary, Paul Calandra, and John Key, New Zealand's prime minister. Instead of addressing the substance of revelations about secret government spying in 2014 (that I was involved in reporting), Calandra and Key both resorted to weird and childish petty insults, calling my colleague Glenn Greenwald a "porn spy" (Calandra) and a "loser" (Key).

Villain of the year

UK police and security agencies for establishing a precedent that means journalism — the mere publication of facts and opinions — can now be considered terrorism; for working to secretly identify journalists' confidential sources; and for eavesdropping on lawyers' privileged communications.

The EU Parliamentary Inquiry's Report on Mass Surveillance

Saturday, 11 January 2014

After about five months of hearings and investigating, the European Parliament's civil liberties committee has published its report on the revelations about mass surveillance leaked by the American former National Security Agency contractor Edward Snowden.

The comprehensive 52-page report, published Wednesday in draft form [pdf], contains a large number of important findings and recommendations — some of which I think it's worth highlighing here.

The report accuses spy agencies — particularly in the US (NSA) and the UK (GCHQ) — of operating dragnet snooping programs that appear to involve illegal actions. It says that the UK government has on at least two occasions breached the European Convention on Human Rights and the EU Charter in how it has tried to crack down on reporting of the Snowden leaks (examples cited are the detention of former Guardian journalist Glenn Greenwald's partner and the destruction of Guardian computers). In addition, the committee calls for the European Parliament to suspend data sharing deals with the US government, and it says new legal protections are necessary for journalists and whistleblowers.

Crucially, the report does not shy away from attempting to address some of the larger issues — such as the profound and unprecedented existential questions new mass surveillance technologies raise for modern democracies. It calls on US authorities and EU member states to "prohibit blanket mass surveillance activities and bulk processing of personal data," adding:

[The committee] sees the surveillance programmes as yet another step towards the establishment of a fully fledged preventive state, changing the established paradigm of criminal law in democratic societies, promoting instead a mix of law enforcement and intelligence activities with blurred legal safeguards, often not in line with democratic checks and balances and fundamental rights, especially the presumption of innocence. [Emphasis added.]

This kind of policing, it warns, is leading to "every citizen being treated as a suspect." For that reason, the report notes that the committee

condemns in the strongest possible terms the vast, systemic, blanket collection of the personal data of innocent people, often comprising intimate personal information; emphasises that the systems of mass, indiscriminate surveillance by intelligence services constitute a serious interference with the fundamental rights of citizens; stresses that privacy is not a luxury right, but that it is the foundation stone of a free and democratic society; points out, furthermore, that mass surveillance has potentially severe effects on the freedom of press, thought and speech as well as a significant potential for abuse of the information gathered against political adversaries; emphasises that these mass surveillance activities appear also to entail illegal actions by intelligence services and raise questions regarding extraterritoriality of national law.

UK surveillance laws are singled out for criticism, with the inquiry concluding that the UK's legal framework is in need of an overhaul because it is outdated. But the finger is not pointed solely at the spooks in the UK and the US. The report accuses countries including France, Germany, and Sweden of running their own mass surveillance programs, too. It also rightly blasts the general incompetence of oversight committees — both in Europe and the US — that are supposed to be tasked with holding spy agencies accountable:

despite the fact that oversight of intelligence services’ activities should be based on both democratic legitimacy (strong legal framework, ex ante authorisation and ex post verification) and an adequate technical capability and expertise, the majority of current EU and US oversight bodies dramatically lack both, in particular the technical capabilities. [Emphasis added.]

Moreover, it calls on the European Commission — the EU's executive body — to evaluate the possibility of introducing legal liabilities that could be used to punish technology companies for not fixing known vulnerabilities in their software or for installing secret backdoors for spying. It wants the European Parliament to consider only procuring software that is open source, so that the software code can be reviewed to ensure it is secure and free from backdoors inserted for spying. And it also urges European Union member states to initiate investigations into "possible cybercrimes and cyber attacks committed by governments or private actors in the course of the activities under scrutiny."

"Trust has been profoundly shaken," the report says. "Trust between the two transatlantic partners, trust among EU Member States, trust between citizens and their governments, trust in the respect of the rule of law, and trust in the security of IT services...in order to rebuild trust in all these dimensions a comprehensive plan is urgently needed."

It's worth a read if you have the time. The full report is here [pdf].

GCHQ's Dubious Role in The 'Quantum' Hacking Spy Tactic

Thursday, 12 December 2013

I've not posted here for a while, but I've got a good excuse. For the last month or so I've been out in Brazil working on a series of stories with the American journalist and former Guardian columnist Glenn Greenwald. We've been reporting a series of revelations about government surveillance based on the trove of files leaked by former NSA contractor Edward Snowden.

I've had some time to take a breather tonight and I want to draw attention to something important in one of the latest stories we worked on with a team of excellent Swedish journalists from Uppdrag Granskning — an investigative unit that operates as part of Sweden's national public broadcaster SVT.

We worked on several stories with Uppdrag Granskning in the lead up to an hour-long documentary, aired Wednesday, about Sweden's major role in the global surveillance nexus that is led by the United States, the United Kingdom, and the other members of the so-called Five Eyes group — Australia, Canada, and New Zealand.

As we reported, the documents reveal how Sweden has become a key partner for the US and the UK, and top-secret agreements have been made in the last decade that bolster Sweden's spying role like never before.

But aside from these crucial details, which are hugely important for Swedish citizens to be informed about, I'd like to highlight here one smaller piece of information that we reported that I think is highly notable.

Earlier this year, it was disclosed that UK spy agency GCHQ was involved in hacking into the Belgian telecom company Belgacom's computer systems in order to covertly gather intelligence on unknown targets. But what is interesting is that, despite being involved in using these hacking methods, GCHQ has been worrying behind the scenes about their legality.

One of the Snowden documents we revealed on the Uppdrag Granskning documentary — dated circa April 2013 — shows the NSA describing a so-called 'Quantum' hacking initative that GCHQ was involved in at a "proof-of-concept" level. However, the document notes:
Continued GCHQ involvement may be in jeopardy due to British legal/policy restrictions, and in fact NSA’s goal all along has been to transition this effort to a bilat with the Swedish partner. [Emphasis added.]
This struck me because, last year, I uncovered a document showing something similar. In obscure technical standards meetings with telecom companies about implementing new surveillance capabilities, GCHQ representatives from a little-known unit of the agency called the National Techical Assistance Centre were voicing the same concerns about hacking techniques.

At meetings held between 2010 and 2011 in Estonia and Italy, at which a GCHQ representative was present, the UK was said to be anxious about the legality of performing a so-called 'man-in-the-middle' attack to covertly hack and eavesdrop on communications:
An additional concern in the UK is that performing an active attack, such as the Man-in-the-Middle attack proposed in the Lawful Interception solution...may be illegal. The UK Computer Misuse Act 1990 provides legislative protection against unauthorised access to and modification of computer material. The act makes specific provisions for law enforcement agencies to access computer material under powers of inspection, search or seizure. However, the act makes no such provision for modification of computer material. A Man-in-the-Middle attack causes modification to computer data and will impact the reliability of the data.
This could not be clearer. The UK's position was that it might be unlawful for authorities to hack a computer in order to monitor communications and/or exfiltrate data. That was the position in 2010/11, and I think the same concern is what is being referenced in the 2013 NSA document when UK "legal/policy restrictions" are mentioned.

Yet despite this concern — and this is perhaps the most important point — GCHQ has marched ahead with its participation in clandestine surveillance operations that involve hacking. The Belgacom case is a specific example, but the NSA documents on Sweden illustrate that Belgacom was not an isolated case. GCHQ was (and likely continues to be) involved in a program called WINTERLIGHT that explicitly involves trying to infect hundreds of targeted computers with so-called 'implants' of malware. GCHQ even operates a covert computer server that it uses to help infect targets with the malware, likely by masquerading as legitimate websites such as LinkedIn, as previous reports have suggested. These covert servers are mentioned in one of the NSA documents on Sweden, dated April 2013, revealed by Uppdrag Granskning:
Last month, we received a message from our Swedish partner that GCHQ received FRA [Swedish spy agency] QUANTUM tips that led to 100 shots, five of which were successfully redirected to the GCHQ server.
So, the question here is: how can this be legal? If GCHQ was previously concerned that performing active hacking attacks may be unlawful under the UK's Computer Misuse Act, then how has that situation been resolved? Has the agency been granted immunity to perform these operations? If so, who granted the immunity? Alternatively, has the UK government, with zero public debate and under cover of total secrecy, produced a classified interpretation of the law aimed at justifying and rendering lawful the use of this clandestine hacking technique?

Another very intriguing theory I have considered is that GCHQ lets one of the other agencies do the "dirty work" — the part of the hack that would illegal under UK law. The NSA may deploy the malware, for instance, while GCHQ plays a lesser role by merely facilitating the attack by hosting the server — but still reaping the benefits (i.e. it gets access to the intercepted data). Having spent countless hours now looking at the Snowden documents, it certainly appears to me that this is something that occurs — that the spy agencies circumvent their domestic laws by allowing partner agencies to do things that they could not do themselves.

Either way, GCHQ's clear and undeniable role in Quantum hacking attacks raises hugely significant legal questions and it is remarkable to me — but perhaps not totally surprising — that the blundering British parlimentarians who are supposed to hold the agency to account have thus far failed to raise any of these key issues.

How UK Surveillance is on the Rise

Saturday, 20 July 2013

Earlier this week, the UK's official communications interception commissioner published his annual report. The commissioner releases statistics every year that offer an insight into the levels of surveillance being conducted by UK authorities, including police, security and intelligence agencies.

The latest report provides more evidence that the trend in recent years has been towards a general increase in surveillance of communications. In 2012, the report shows, there were a record 570,135 authorisations for police and other agencies to obtain so-called "communications data." This can include subscriber information about suspects' phone and email accounts, as well as call and email records showing who a suspect is phoning/emailing and when. It does not include the actual content of the communication.

Notably, the 570,135 figure is a 15 percent increase on the figure for 2011 and amounts to about an average 1,562 communications data authorisations every day. In addition, the commissioner noted in his report that "979 communications data errors" were made by authorities in cases involving the wrongful collection of data from innocent individuals. The botched surveillance had serious ramifications, with six members of the public "wrongly detained / accused of crimes" as a consequence.

Here's a quick graph I've knocked up showing how, with the exception of a unusual drop in authorisations in 2011, UK authorities have been increasingly obtaining communications data as part of investigations in recent years:

The same trend is reflected in the latest statistics on the interception of communications. Interception is when the authorities obtain a warrant, signed off by the secretary of state, enabling them to secretly eavesdrop on phone calls or read emails and texts. There were 3,372 interception warrants authorised in 2012, which represents a 16 percent increase on the figure for 2011. It is crucial to note that a single interception warrant can encompass large groups of individuals. It is not known exactly how many people were swept up in the 3,372 warrants because these figures are, unfortunately, not published.

Here's a graph that illustrates the steady increase in interceptions since 2008:

While surveillance is on the rise, as the above graphs show, the UK government has been arguing that it does not have enough digital spying capabilities and needs more surveillance powers.

The government's case may have recently been damaged, however, by leaked secret documents, published by the Guardian in June, that revealed how UK spy agency GCHQ was tapping into internet cables and reportedly monitoring some 600 million "telephone events" every day. The exposed extent of GCHQ's spying offered a rare and startling insight into the sweeping scope of surveillance already being conducted by the UK government, and seemed to affirm what the UN's special rapporteur on free expression, Frank La Rue, warned about in an unprecedented report published just weeks before the leaks.

"Technological advancements," La Rue wrote, "mean that the state’s effectiveness in conducting surveillance is no longer limited by scale or duration."

Rights Groups on Snowden

Friday, 12 July 2013

Edward Snowden is the NSA whistleblower whose document leaks have in recent weeks cracked open the US and UK governments' secret surveillance programs to an unprecedented level of public scrutiny. The former Hawaii-based NSA contractor, 30, is currently holed up in Sheremetyevo airport in Moscow, Russia, as he attempts to seek asylum in a number of countries — fearing persecution if he returns to the United States.

But Snowden's options are limited. The US government has revoked his passport while exerting extraordinary pressure on countries across the world in order to prevent the whistleblower from gaining asylum. This has raised questions about the US government's commitment to international law and has led a number of human rights groups to weigh in with criticism of US officials' actions. Today, Snowden is said to have set up a meeting with groups including Amnesty International in order to discuss his next steps.

Below, I've compiled a quick list for my own reference of the various rights groups that have issued a statement on the Snowden case so far. There may be others that I've missed. If so, add a comment at the bottom or send me a link via Twitter and I'll update this post.

American Civil Liberties Union

"In addition to infringing on Mr. Snowden's right to asylum, [the US government's] actions also create the risk of providing cover for other countries to crack down on whistleblowers and deny asylum to individuals who have exposed illegal activity or human rights violations." (Statement, 11 July.)

Amnesty International

"The US authorities’ relentless campaign to hunt down and block whistleblower Edward Snowden’s attempts to seek asylum is deplorable and amounts to a gross violation of his human rights." (Statement, 2 July.)

Article 19

“The manhunt for Edward Snowden must be stopped. More energy is being spent on arresting one whistleblower that exposed human rights violations than has been spent on finding and arresting perpetrators of war crimes or crimes against humanity." (Statement, 5 July.)

Government Accountability Project (US)

"Snowden disclosed information about a secret program that he reasonably believed to be illegal. Consequently, he meets the legal definition of a whistleblower, despite statements to the contrary made by numerous government officials and security pundits." (Statement, 14 June.)

Human Rights Watch

"[The US government] should not apply a double standard by working against other governments that might extend asylum in this case." (Statement, 3 July.)

“Edward Snowden has a serious asylum claim that should be considered fairly by Russia or any other country where he may apply. He should be allowed at least to make that claim and have it heard... Washington’s actions appear to be aimed at preventing Snowden from gaining an opportunity to claim refuge, in violation of his right to seek asylum under international law.” (Statement, 12 July.)

Index on Censorship

"The mass surveillance of citizens’ private communications is unacceptable – it both invades privacy and threatens freedom of expression. The US government cannot use the excuse of national security to justify either surveillance on this scale or the extradition of Snowden for revealing it." (Statement, 24 June.)

Norwegian PEN

"The threat of criminal prosecution against whistleblower Edward Snowden on the charge of espionage is an allegation against an individual who has used his right to free speech in order to uncover serious abuse, not worthy of a country that abides by the rule of law. By going out with this information, Edward Snowden has questioned the democratic openness of US counter-terrorism strategy. The practice uncovered in the United States is in clear conflict with the principles of a democratic constitutional state." (Statement, 3 July.)

Reporters Without Borders

"Now that Edward Snowden, the young American who revealed the global monitoring system known as Prism, has requested asylum from 20 countries, the EU nations should extend a welcome, under whatever law or status seems most appropriate... [European Union] countries owe Snowden a debt of gratitude for his revelations, which were clearly in the public interest... American leaders should realize the glaring contradiction between their soaring odes to freedom and the realities of official actions, which damage the image of their country." (Statement, 3 July.)

Prism D Notice

Tuesday, 18 June 2013

Following disclosures by the Guardian earlier this month about a US National Security Agency internet surveillance program called Prism, it has emerged that UK government officials issued a so-called "D notice" in a bid to censor coverage of spy tactics.

The D notice following the NSA leaks was reportedly issued to news organisations including the BBC on 7 June, the day after the Prism story broke. Prism is a system used by the NSA to monitor emails, file transfers, photos, videos, chats, and other data. Intelligence gleaned from the system has been passed to GCHQ, the UK's version of the NSA.

The notice to the media organisations was marked "Private and Confidential: Not for publication, broadcast or use on social media," according to Jeff Stein at And Magazine. It added:

There have been a number of articles recently in connection with some of the ways in which the UK Intelligence Services obtain information from foreign sources.

Although none of these recent articles has contravened any of the guidelines contained within the Defence Advisory Notice System, the intelligence services are concerned that further developments of this same theme may begin to jeopardize both national security and possibly UK personnel.

It particularly warned against reporting on:

specific covert operations, sources and methods of the security services, SIS and GCHQ, Defence Intelligence Units, Special Forces and those involved with them, the application of those methods, including the interception of communications and their targets; the same applies to those engaged on counter-terrorist operations.

The D-notice system was first set up in 1912 and operates in accordance with a voluntary code — providing "advice and guidance to the media about defence and counter-terrorist information the publication of which would be damaging to national security." In 2010, for instance, a D notice was reportedly issued prior to WikiLeaks' release of thousands of US government diplomatic cables. A D notice has no formal legal authority, but defying it can make journalists vulnerable to prosecution under the UK's Official Secrets Act.

Surveillance, Britain's Secret Agencies, and Drowning in Data

Thursday, 25 October 2012

I was speaking to someone today about this, and it occurred to me that it is a piece of information that is not widely known but should be.

Every year in Britain, there is an official report that comes out detailing the activities of the UK's spy agencies — MI5, MI6 and GCHQ. It is authored by a group of politicians who function as a kind of oversight authority, under the name the Intelligence and Security Committee.

In this year's report, published in July, I noticed a section of particular interest in light of new proposals for more surveillance powers in the UK. The second paragraph is what is important here — it is a comment made by Jonathan Evans, chief of domestic security agency MI5.

The Security Service is undertaking a number of major projects covering estates, business continuity, core IT systems and improving its digital investigative capabilities. A notable success during the reporting period was the completion of the Digital Intelligence (DIGINT) programme, which aimed to improve systems for the collection and analysis of intelligence material gathered electronically. The Director General explained:

"One of the things that really drove us on the investment of DIGINT was a discussion where the relevant directors explained that actually, of all the material that we’ve caught, over half was not being processed. Now, as an intelligence organisation, that’s a nightmare. I mean, quite frankly, I would rather not have the intelligence at all and miss something than have the intelligence and not actually having processed it… We have made real progress on that, and I’m very proud on DIGINT." (Emphasis added)

What this comment suggests, for the sake of clarity, is that the UK's spy agencies in recent years have been mining and storing quantities of electronic data — or "digital intelligence" — so large that they have not been able to analyse it. The data, most of it I would expect is mined from the internet, has probably been gathered and then left to sit and gather digital dust in a secret storeroom somewhere. The claim from Evans in the above quote is that MI5 has worked to address the problem as part of a new programme, which presumably involves a great deal of automated analysis. But the statement also illustrates how new surveillance powers currently being proposed in the UK could pose problems for the UK if the security services are already near a point where they are drowning in data.

There tends to be two main schools of thought within the intelligence community. Some believe that targeted surveillance of specific individuals and groups is the best method, because it provides information that can be dissected and acted upon fairly quickly by human analysts. The other school of thought, and the one which seems to be prevailing, is that a kind of dragnet surveillance is superior. What this entails is gathering huge quantities of data based on key words, locations, phrases, and then mining through it to find anything useful. From a rights and civil liberties perspective, targeted surveillance is clearly more attractive because it is likely to involve much less intrusion of innocent individuals' communications. But rights and civil liberties do not appear to be high on the agenda at our secret agencies, and so what we get is something closer to the dragnet option.

I should add that surveillance in the UK is not without regulation. To intercept domestic communications, police and security services require ministerial authorisation, and must show that any interception is in the interests of national security, safeguarding economic well being, or to prevent and detect serious crime. That said, these justifications are fairly broad, and there were 2,911 interception warrants granted in 2011 — but any one warrant can cover countless individuals, so we actually have little idea how many people had their communications snooped on. (Also, to monitor content posted on social networks and other "open source" websites, there are no laws or restrictions at all. So websites like Facebook, Twitter and Foursquare are all fair game for the likes of MI5's "DIGINT" team to gather data from.)