Showing posts with label national security. Show all posts
Showing posts with label national security. Show all posts

Year in Review

Monday, 5 January 2015

Well, 2014 turned out to be quite a year. For me, it was a really productive one, and I was lucky enough to get the opportunity to work on some great projects. Below are a few personal highlights that I've put together as a sort of 'year in review', along with a list of notable stories and developments in the realm of surveillance and national security, some 'ones to watch' for 2015, and a few awards that I've decided to hand out for dishonourable government conduct, just because there was so much of it over the last twelve months, and the worst offenders deserve some recognition...

(I meant to post this last week, but I've been on a remote Spanish island on holiday with no internet connection... so here it is, better late than never...)
 
January to March

In January I worked with Canadian broadcaster CBC to reveal details about domestic surveillance in the Canada. In February, The Intercept launched, and I contributed to a story that revealed some new details about US and UK government efforts to target WikiLeaks. In March, I had a report out shining a light on how the US National Security Agency has worked alongside its UK partner Government Communication Headquarters to infect large numbers of computers across the world with malware. I also worked on a story exposing the NSA's targeting of innocent system administrators as part of its covert attempts to hack into communication networks.

April to June

In March, I worked with German news magazine Der Spiegel on a story revealing new details about the NSA's surveillance of world leaders. In April, I reported on British spies' attempts to get broad unsupervised access into NSA troves of surveillance data. And in June, I worked with some great reporters at Danish newspaper Dagbladet Information to reveal new information showing how the NSA forms secret partnerships with countries across the world in order to help significantly expand its surveillance reach.

July to September

In August, the US military banned its personnel from reading The Intercept, and a few days later we published one of the most important stories I've worked on to date, exposing a vast US surveillance search system used to share huge troves of private data among dozens of US government agencies, including domestic law enforcement. The story revealed the decades-long history of US agencies' use of masses of metadata to monitor people's behaviour, and exposed how the CIA was using metadata to aid its efforts to secretly kidnap terror suspects (a practice that often resulted in the suspects — some of whom were totally innocent — being brutally tortured).

In September, we began reporting details at The Intercept about the scope of surveillance in New Zealand, and shined a light on deceptive statements made by the government there about its spying efforts; meanwhile, police raided and ransacked the home of the excellent investigative reporter that we were (and are) working with on Snowden revelations related to New Zealand.

October to December

In November, I worked on a story revealing how one of the most sophisticated pieces of malware ever discovered — dubbed "Regin" by security experts — was linked to cyberattacks perpetrated by British spies against Belgian telecommunications company Belgacom and European Union offices. This piece was an interesting one to work on in that it combined both news reportage with malware analysis — something that's never been done before in journalism, I think — and was published alongside downloadable samples of the Regin malware.

In December, I had a new report out revealing a secret NSA program that involves spying on emails sent among hundreds of mobile phone companies around the world, a practice that helps the agency hack into phone networks. The story exposed how the NSA targeted a London-headquartered trade group that represents tech giants like Microsoft and Facebook, and provided evidence that NSA had been working to insert security vulnerabilities into global telecommunications infrastructure so that they can be exploited for surveillance.

Also in December, I reported new details about the GCHQ hack of Belgian telecommunications company Belgacom as part of a reporting collaboration with newspapers in Belgium and the Netherlands. This particular story is one that I am especially proud of; it was the culmination of about six months of work, and took a huge amount of cooperation with different teams operating out of four separate countries simultaneously. We were able to tell the full story of the British hack on Belgacom, a hugely significant incident representing an unprecedented cyberattack by one EU member state on another. The story included new 'smoking gun' evidence showing that the Regin malware samples contained code-names that also appeared in secret GCHQ documents obtained from whistleblower Edward Snowden.

Vital stories

Here a list of some reports and developments that stood out to me in 2014:

NSA collects millions of text messages daily in 'untargeted' global sweep, The Guardian, 16 January.

Snowden docs show UK spies attacked Anonymous, hackers, NBC News, 4 February.

The NSA’s secret role in the US assassination program, The Intercept, 10 February.

Optic Nerve: millions of Yahoo webcam images intercepted by GCHQ, The Guardian, 27 February.

NSA surveillance program reaches ‘into the past’ to retrieve, replay phone calls, Washington Post, 18 March.

Top EU court rejects EU-wide data retention law, BBC News, 8 April.

Death from above: how American drone strikes are devastating Yemen, Rolling Stone, 14 April.

Turkish president approves law widening secret service's powers, Reuters, 24 April.

The NSA is recording every cell phone call in the Bahamas, The Intercept, 19 May.

Germany arrests man suspected of spying for US, BBC News, 4 June.

NSA: Inside the five-eyed vampire squid of the Internet, The Register, 5 June.

Vodafone reveals existence of secret wires that allow state surveillance, The Guardian, 6 June.

US officials scrambled to nab Snowden, hoping he would take a wrong step. He didn’t, Washington Post, 14 June.

GCHQ sanctions spying on every Facebook, Google and Twitter user, The Telegraph, 17 June.

In NSA-intercepted data, those not targeted far outnumber the foreigners who are, Washington Post, 5 July.

Germany to spy on US for first time since 1945 after ‘double agent’ scandal, The Independent, 7 July.

Meet the Muslim-American leaders the FBI and NSA have been spying on, The Intercept, 9 July.

Hacking online polls and other ways British spies seek to control the Internet, The Intercept, 14 July.

The secret government rulebook for labeling you a terrorist, The Intercept, 23 July.

CIA Admits improperly hacked into Senate computers, Washington Times, 31 July.

Barack Obama’s secret terrorist-tracking system, by the numbers, The Intercept, 5 August.

The Islamic State (documentary), Vice, 7 August.

German spy company helped Bahrain hack Arab Spring protesters, The Intercept, 8 August.

Photos of alleged 9/11 '20th hijacker' can stay classified: court, Reuters, 2 September.

MRAPs and bayonets: what we know about the Pentagon's 1033 program, NPR, 2 September.

The NSA and GCHQ campaign against German satellite companies, The Intercept, 14 September.

Israel's NSA scandal, New York Times, 16 September.

Wikileaks releases FinFisher files to highlight government malware abuse, The Guardian, 16 September.

The NSA and me, The Intercept, 2 October.

Citizen Four (documentary), 10 October.

Why was the NSA chief playing the market? Foreign Policy, 22 October.

MI5 spied on leading British historians for decades, secret files reveal, The Guardian, 24 October.

In Cold War, US spy agencies used 1,000 Nazis, New York Times, 26 October.

Secret manuals show the spyware sold to despots and cops worldwide, The Intercept, 30 October.

Brazil is keeping its promise to avoid the US Internet, Gizmodo, 30 October.

Disguised as climate negotiators, Dagbladet Information, 1 November.

UK intelligence agencies spying on lawyers in sensitive security cases, The Guardian, 7 November.

FBI says it impersonated AP reporter in 2007 case, AP, 7 November.

Americans’ cellphones targeted in secret US spy program, Wall Street Journal, 14 November.

WhatsApp now provides end-to-end encryption for your messages, Gizmodo, 18 November.

Before Snowden, a debate inside NSA, AP, 19 November.

US firms accused of enabling surveillance in despotic Central Asian regimes, The Intercept, 20 November.

How Vodafone-subsidiary Cable & Wireless aided GCHQ’s spying efforts, Süddeutsche Zeitung, 25 November.

CIA torture report, 9 December.

WikiLeaks CIA leaks, 18 & 21 December.

Inside the NSA's war on internet security, Der Spiegel, 27 December.

The Sabu Files, Vice/Daily Dot.

Save our sources campaign, The Press Gazette.

Ones to watch in 2015

Some things worth keeping an eye on...

A new US cybersecurity unit that will advise agencies on surveillance operations.

Details about a secret database being used by federal agents in the US, the existence of which has become the subject of dispute in an ongoing court case.

Information about documents being shredded en masse in a UK police anti-corruption investigation.

Developments in the US government's ongoing criminal investigation into WikiLeaks, which may have involved the use of a prominent informant.

The long-overdue publication of a government-commissioned post-Snowden review of UK surveillance operations.

The US government using state secrecy powers to block the release of files from anti-Iran group.

Renewed 'crypto wars' as law enforcement agencies in the US push for more powers to combat privacy-protecting encryption technologies.

More details about the CIA's hacking of Senate computers.

A continuing government effort to introduce new laws bolstering surveillance powers in the US, UK, Australia, Canada, and New Zealand.

Many more stories from the Snowden documents related to secret spying conducted by the US, UK, Australia, Canada, New Zealand, and other countries.

Now for a few awards...

Because I feel like handing out some dubious accolades:

Bullshit statement of the year

Winner: Recently retired GCHQ spy chief Sir Iain Lobban for his claim in October that the agency doesn't engage in "anything remotely resembling mass surveillance." A completely false statement that could not be further from the truth.

Runner-up: UK home secretary Theresa May for "collection of bulk data is not mass surveillance."

3rd prize: former US vice-president Dick Cheney for "we were very careful to stop short of torture."

Dishonourable mentions: former NSA and CIA chief Michael Hayden for "I didn’t do anything wrong"; New GCHQ spy chief Robert Hannigan for "GCHQ is happy to be part of a mature debate on privacy in the digital age."

Orwellian euphemism of the year

New Zealand's prime minister John Key tries and fails to make mass surveillance palatable to the public in September by re-branding it "mass protection."

Outrageous admission of the year

Former NSA and CIA chief Michael Hayden tells an audience at Johns Hopkins University in April: "We kill people based on metadata."

Understatement of the year

President Barack Obama, in August, on the CIA's brutal human rights abuses post 9/11: "We tortured some folks."

Gaffe of the year

UK foreign secretary Philip Hammond, who is responsible for signing off on GCHQ surveillance operations, illustrates that he doesn't have a clue what he's been approving during a parliamentary hearing in October.

Hypocrite of the year

Michael Hayden, the CIA chief who overseen the agency's secret extrajudicial kidnapping operations that involved imprisoning and torturing terrorism suspects, some of whom were entirely innocentcomplains in December that a Senate report criticising CIA torture methods was like being "tried and convicted in absentia. We were not given an opportunity to mount a defense."

Most bizarre mass surveillance justification of the year

UK prime minister David Cameron explains to British lawmakers in January that fictional TV crime dramas demonstrate the need for new dragnet spying powers.

Most absurd response to surveillance revelations of the year

A special joint award that goes to the Canadian prime minister's parliamentary secretary, Paul Calandra, and John Key, New Zealand's prime minister. Instead of addressing the substance of revelations about secret government spying in 2014 (that I was involved in reporting), Calandra and Key both resorted to weird and childish petty insults, calling my colleague Glenn Greenwald a "porn spy" (Calandra) and a "loser" (Key).

Villain of the year

UK police and security agencies for establishing a precedent that means journalism — the mere publication of facts and opinions — can now be considered terrorism; for working to secretly identify journalists' confidential sources; and for eavesdropping on lawyers' privileged communications.

Extraordinary Rendition and the Secret Role of Metadata

Thursday, 28 August 2014

On Monday, I had a new story out at The Intercept revealing a secret search engine that the National Security Agency built to share a massive amount of data with other US government agencies, including domestic law enforcement. There are many new and important details scattered through the piece. But there is one in particular I would like to take a minute to focus on here, because it is a fact that strikes at the heart of the debate about government surveillance and deserves some more attention.

In one of the classified documents that we published with the story, dated from 2005, the NSA outlined some of the "successes" of a data-sharing project called CRISSCROSS that was led by the Central Intelligence Agency. The document shows that metadata collected about communications was integral to the CIA's extraordinary rendition program during the Bush Administration, which involved kidnapping terror suspects and taking them to secret "black site" jails where they would be brutally interrogated and sometimes tortured. The NSA document says:

Since 9/11, the contributions to the GWOT [global war on terror] due to our increased collection of signaling metadata are innumerable and significant. It is safe to say that it has been a contribution to virtually every successful rendition of suspects and often, the deciding factor.

This is an incredible detail. Remember, metadata is not the audio content of a phone call or the words contained within the body of an email message. It is merely information showing who you have contacted and when. Governments have often sought to defend the mass-scale collection of metadata by insisting that it is not information that is sensitive or very private. In June last year, President Obama tried to dismiss concerns about metadata collection in the United States by claiming that "nobody is listening to your telephone calls." But, clearly, the government doesn't need to be listening to your calls to deem you a threat. That metadata has been the deciding factor in targeting people for extraordinary rendition is a profound illustration of that — and it shows that metadata collection has real-world ramifications: it is not just some benign activity.

You might think, "well, I'm not a terror suspect so what do I care?" But this is not only about the Bad Guys — there are much wider consequences at play here. During the height of the extraordinary rendition program, for instance, some of the people targeted were victims of what was called "erroneous rendition." In other words, the CIA would kidnap the wrong person. (Yes, seriously.) In 2005, it was reported by the Washington Post that the CIA's inspector general was investigating a "growing number" of erroneous renditions, with some anonymous government officials saying that they believed there were as many as 30 instances of it having taken place.

Much is still unknown about these cocked-up renditions because the information has been kept secret. But now that we know metadata played a key role in targeting people — in some cases even being the "deciding factor" — questions must surely be asked about whether this method was ever to blame. From a legal and human rights perspective, it is disturbing enough that the CIA was secretly kidnapping, imprisoning, and then torturing people. But the possibility of innocent individuals being targeted on the basis of their metadata trail clearly adds a chilling extra dimension. It is a policy of guilt by association that bears all the hallmarks of a kind of terrible and flawed style of totalitarian policing.

Today, the practice of extraordinary rendition appears to have been largely phased out by President Obama. But the concerns raised by the use of metadata to target people are still highly pertinent. Indeed, as The Intercept reported back in February, metadata is actively being used to target and kill terror suspects in drone strikes in countries like Yemen, Pakistan and Somalia. One military source said that the method can result in the "wrong people" being bombed. And if you think that sounds far-fetched — that the US would not launch missiles at people because of their metadata — you don't need to take my word for it. Just go and listen to what former CIA and NSA chief Michael Hayden has to say. As he boasted in April: "We kill people based on metadata."

Canada's WiFi Surveillance and CSEC's Non-Denial Denials

Saturday, 1 February 2014

On Thursday, a report I worked on with Glenn Greenwald and Greg Weston was published in Canada, revealing how the country's spy agency CSEC secretly developed a program to monitor WiFi users in a major Canadian airport.

The piece, based on documents leaked by the former US National Security Agency contractor Edward Snowden, has led to CSEC being accused of acting unlawfully and has triggered calls for better oversight of the agency.

But one of the most intriguing aspects of the fallout from the story has been the Canadian government's response — which merits some scrutiny and analysis.

First, some context.

Back in November, Greenwald, Weston and I reported separate revelations about Canada's role in an NSA operation to spy at the G8 and G20 summits in Canada in 2010. In response, CSEC's chief John Forster claimed in response to reporters' questions:

What I can tell you is that CSEC, under its legislation, cannot target Canadians anywhere in the world or anyone in Canada, including visitors to Canada.

During a speech in October, Forster had made a similar statement:

I can tell you that we do not target Canadians at home or abroad in our foreign intelligence activities, nor do we target anyone in Canada. In fact, it's prohibited by law. Protecting the privacy of Canadians is our most important principle.

And again, in January, he repeated this assertion in a letter to a Canadian newspaper:

Under the law, CSE’s foreign intelligence mandate specifically dictates that our activities be directed only at foreign entities, and not at Canadians or anyone in Canada. That is the law and we fully respect that.

Having analysed Canadian documents in the Snowden material, these statements struck me as quite astonishing.

Why? Because one of the top-secret Snowden documents revealed that, in 2012, CSEC had set up a program that involved monitoring WiFi usage at a large Canadian airport. The secret files showed how CSEC was able to use a huge amount of data about the WiFi connections to follow users "backward and forward in recent time" — identifying visits to hotels, other airports, Internet cafes, coffee shops, and a library.

The tactic is described by CSEC in the files as "IP profiling" — a surveillance method that can be used to track users' movements over time. In one case, as we reported at CBC on Thursday, the spy agency says that it performed a sweep of an entire "modest-sized" city and identified 300,000 user IDs:

The "mission impact" of the tactic, according to the document, is that it can alert spies to "target country location changes" and "webmail logins with time-limited cookies":

The full document [pdf] speaks for itself. It illustrates a secret surveillance operation was conducted on Canadian soil — sweeping up metadata on the WiFi usage of thousands of people not suspected of any crime. Equally significant, the revelation contradicts CSEC chief Forster's repeated assertion that "we do not target Canadians at home or abroad in our foreign intelligence activities, nor do we target anyone in Canada."

After we reported the airports story, it got more interesting.

CSEC issued a statement that was notable for three reasons. First, the agency did not repeat its previous mantra claiming not to "target anyone in Canada." Second, it appeared to make an admission that it is sweeping up metadata within Canada, saying that it was "legally authorized" to "collect and analyze" this information. And third, it issued a fresh denial, saying that "no Canadian or foreign travellers were tracked. No Canadian communications were, or are, targeted, collected or used."

Shortly afterwards, on Friday, a similar denial was made by the Canadian prime minister's parliamentary secretary, who launched a bizarre personal attack on Greenwald while claiming that the "facts" were that "nothing in the stolen documents showed that Canadians' communications were targeted, collected, or used, nor that travellers' movements were tracked."

But these denials are hollow.

It's a straw man to claim that the revelations were about communications being "targeted, collected, or used." That is not what our story was about. The issue at hand is how CSEC initiated a program to sweep up information showing when people are connecting to WiFi networks and using this information to build "profiles" of their movements back and forward in time.

And that brings us to the more important point. CSEC and the prime minister's secretary claimed that "no Canadian or foreign travellers were tracked." However, what they did not say was how they were defining the word "tracked."

The documents quite clearly show how the agency used user "IP profiles" to monitor WiFi users' movements over time, with this capability enabling it to generate "alerts" when a person relocates to another country.

The dictionary definition of "tracking" says that it means "the act or process of following something or someone." CSEC's IP profiling is exactly that — monitoring users' location and keeping tabs on where they are. Indeed, the document says as much, outlining how CSEC uses this tactic to "follow IDs backward and forward in recent time." The documents also mention how CSEC used tools called "Quova" and "Atlas database" — which are technologies used to pinpoint the geolocation of an IP address.

CSEC's denial that it "tracked" Canadians or foreign travellers, I think, hinges upon a narrowly defined interpretation of the word. The US Department of Defence, for instance, uses "tracking" as a specific technical term meaning the "precise and continuous position-finding of targets by radar, optical, or other means." CSEC's IP profiling definitely fits the dictionary definition of "tracking" as it is understood by most people — but does it fit the narrower military definition? Perhaps CSEC believes that IP profiling does not constitute "precise and continuous" tracking. But if so, it should be explaining this — as otherwise its denial is highly misleading.

Spy agencies are professionals in the art of deception, and sometimes that seems to be reflected in their public relations strategy. Afterall, we have seen misleading denials issued repeatedly by the National Security Agency and its Five Eyes counterparts about various surveillance revelations in recent months. Again and again, officials have used narrowly defined words or jargon terms in a carefully crafted way in order to issue non-denial denials in which they appear to refute an allegation but on closer reading do not really refute it at all.

The ultimate point here is that the tactics being used by CSEC and the Canadian government to deflect criticism of their secret surveillance programs merit as much attention as the revelations themselves. That is especially clear when, in response to disclosures about their secret programs, senior government officials launch childish character assassination attempts against the journalists who reported the information. In a democratic society, surely a higher standard is required. It is not enough for governments and spy agencies to spit out a few indignant statements and denials with the expectation that people should just blindly trust that they are telling the truth.

Also, no matter how "tracking" is being defined, what is clear is that CSEC was (and our sources say still is) running a large-scale surveillance operation on domestic soil, seriously calling into question spy chief Forster's previous statements that "our activities" are not directed "at Canadians or anyone in Canada." The CSEC boss is due to appear before a Senate committee hearing on Monday. Hopefully Canada's lawmakers will take the opportunity to ask some probing questions.


UPDATE, 7 February 2014: Since the story was published last week, there have been several developments. There have been more calls for an independent review of CSEC's activities, while spy chief Forster was forced to publicly defend the surveillance in Monday's Senate hearing.

There have also been some interesting analyses of the leaked documents worth responding to.

First, the surveillance blog Electrospaces claimed that the secret documents seemed to have been "incorrectly interpreted" in our CBC report. The blog published an anonymous analysis from someone who says that CSEC's surveillance project was "was not surveillance of Canadian citizens per se but just a small research project." The second analysis came from Bruce Schneier, who claimed that it was "not really true" that CSEC used "airport Wi-Fi information to track travellers."

First of all, it is a mischaracterization to claim that the CSEC project was just a small research project that didn't implicate Canadians "per se." It was part of a pilot initiative that involved sweeping up data on hundreds of thousands of people — many of whom would have been Canadian citizens. Our sources for the story told us that the pliot had since gone live — i.e. that it had gone from being a "proof-of-concept" to an operationally active domestic program. This is about much more than a "small research project."

Second, it is absolutely the case that CSEC tracked travellers' movements based on the Internet activity by using IP and ID data and honing in on a major Canadian airport's WiFi system.

It may be about more than that — and I agree with Schneier when he says that it is "actually far more interesting than simply eavesdropping on airport Wi-Fi sessions" because of the wider ramifications of this kind of 'big data' analysis.

But this particular initiative was focused on pulling out a huge trove of user ID and IP data and following users "backward and forward in recent time" to and from a Canadian airport to see if it would be possible to keep tabs movements and trigger alerts based on those movements.

What we reported was accurate and remains so: "Canada's electronic spy agency used information from the free internet service at a major Canadian airport to track the wireless devices of thousands of ordinary airline passengers for days after they left the terminal."

Even CSEC chief Forster has since come out and admitted that a kind of tracking was going on (though he says it didn't occur in "real time," which is not something we actually claimed):

Forster said the agency used metadata to develop a model that showed they could track an internet user's network activity "around a public access mode," and that the tracking didn't happen in real time.

Some of the more insightful analysis on the CSEC affair has come from Bill Robinson, a Canadian surveillance expert described by the Toronto Star as "Canada's authority on CSEC."

Robinson makes some interesting points on the meaning of "tracking" in this context and CSEC's initial denial that it had tracked people — and I think he could be hitting the nail on the head here:

While normal human beings might conclude that both Canadian and foreign travellers were indeed tracked, CSEC's claim may be that only devices were tracked in the specific tests reported in the document. Since no device was tracked specifically on account of the fact that it belongs to a particular person, and the analysis itself (as far as I know) did not seek to associate particular individuals with particular devices (although it may well have utilized information associated or associatable with specific individuals), CSEC may feel it is justified in stating that no individuals were tracked. The same or similar logic seems to underlie the agency's claim that it can collect metadata related to thousands or even millions of Canadians and persons in Canada for foreign intelligence purposes while at the same time stating that its foreign intelligence operations do not "target" any Canadians or persons in Canada.

In a separate blog post after spy chief Forster's testimony before the Canadian Senate committee on Monday, Robinson wrote:

In essence, the government's position is that the metadata project reported by the CBC did take place, that its purpose was to develop targeting and analysis techniques that are in fact now being used operationally by CSEC, and that the collection, analysis, use, and retention of Canadian metadata is a normal part of CSEC's operations, necessary to those operations, and entirely legal. Officials also insist, however, that CSEC does not use the data to target Canadians for foreign intelligence purposes.
To have CSEC now appearing to admit (under pressure) that it is using metadata to conduct domestic monitoring on a mass scale is revelatory — and that is where the focus should be. As I wrote here previously, how "tracking" is being defined as a word should not be the most central point in the debate. The attention should be on CSEC conducting a large-scale surveillance operation on Canadian soil and misleading Canadian citizens about it in a series of public statements. Robinson asks the right questions in his earlier blog post:

If real-world operations are now being conducted using the techniques described in the document, or similar kinds of techniques, those operations will indeed involve the tracking of specific individuals who are either known before the tracking began or identified subsequent to their being singled out by analysis of the data.

Will the government state that no Canadian or foreign travellers have ever been tracked (or, if it prefers, detected in a number of different locations over time) in Canada, either by CSEC or by any other Canadian or allied agency, under any mandate, using these or similar metadata-based techniques?

The Torture & Rendition Report the UK Government Hasn't Published

Thursday, 7 November 2013

Last year, the UK government was presented with a preliminary report about an inquiry into British security services' alleged role in the extraordinary rendition and torture of terror suspects. The government said at the time that it would make the report public — but it has never surfaced.

The report was produced as part of the so-called 'Detainee Inquiry', set up by prime minister David Cameron in 2010 to investigate allegations of British security agencies' involvement in the mistreatment of individuals accused of terror offences. Spy agency MI6, for instance, has been blamed for helping to facilitate the abduction and subsequent alleged torture of a Libyan Islamist and his pregnant wife, who were covertly 'rendered' from Bangkok and reportedly taken to a Libyan prison run by the Gaddafi regime in 2004.

Headed by retired judge Sir Peter Gibson, the Detainee Inquiry was supposed to look into these allegations and others. It was scrapped in 2012 amid controversy because the government said that it clashed with ongoing police investigations into some of the same cases. But a preliminary report was produced by the inquiry and sent to the prime minister on 27 June 2012. At the time, the government issued a statement saying that the report focused on "preparatory work to date, highlighting particular themes or issues which might be the subject of further examination." Justice Secretary Ken Clarke said that the government was committed to publishing "as much of this interim report as possible."

Almost 18 months on, however, where is the preliminary report? That is exactly what I have been trying to find out. And the UK government is not returning my emails.

In September, I sent a Freedom of Information Act request seeking a copy of the report to the government's Cabinet Office. Under the FOIA, the government has 20 working days to issue a response. 31 working days have now passed and I have sent three separate emails related to the request. I have received nothing in response — not even an acknowledgement informing me that my request has been received. This means that the government is violating its legal obligations, according to an official I consulted at the Information Commissioner's Office, the public body that enforces access to information legislation in the UK.

I submit quite a lot of FOI requests, and I can't think of another occasion when a government department has flat-out ignored a request in this way. It is very unusual. Normally, the procedure is that you will receive an acknowledgement within a few days. And a couple of weeks later the respective department will either send you the information or refuse to release it, usually citing some flimsy national security secrecy exemption.

Notably, the chap who runs the website Spy Blog has also previously attempted to obtain a copy of the preliminary report. His efforts have so far been stonewalled. But unlike me, Spy Blog has at least been privileged enough to receive responses from the Cabinet Office, most recently in July. The Cabinet refused to disclose the report to the website, claiming that officials were busy "clearing the report for publication" and adding that they expected that it could be published "in the autumn, although no date has been set."

It is not clear why the Cabinet Office has needed almost a year and a half to "clear" a report for public consumption. At best, it looks to me like a case of incompetence and bureaucratic inefficiency; at worst, it is a red herring being deployed to delay the release of controversial information for political convenience. Either way, the delay suggests that there could be some interesting details contained in the report. And the government is running out of excuses to postpone publication. Indeed, under section 22 of the Freedom of Information Act, the government can decline to disclose information requested if it is already intended for future release. However, Ministry of Justice guidance on the Section 22 exemption explicitly states that:

These qualifications recognise that sometimes there will be an overriding public interest in the information being released prior to the intended publication date. Public authorities should not be able to avoid putting information in the public domain by adopting unreasonable publication timetables or an 'intention' to publish where there is little prospect of that happening within a reasonable timescale.

Given the seriousness of the allegations about UK security agencies' role in facilitating extraordinary rendition and torture, there is evidently a very strong public interest case for this preliminary report to be immediately released under the Freedom of Information Act. That is especially true given the inexplicably lengthy delay that we have already had to endure.

It's worth also pointing out that despite the sort of behaviour detailed above, the government continues to audaciously insist it is committed to transparency. Just last week the Cabinet Office was proclaiming "wide-ranging new commitments to bring more of the benefits of transparency into people’s everyday lives." Cabinet minister Francis Maude was quoted as saying that "transparency is an idea whose time has come."

Unfortunately, the section of Maude's own department responsible for implementing transparency does not appear to have received the memo — and is currently flouting the Freedom of Information Act in a case involving the withholding of important information that the public clearly has a right to know.

I have lodged a formal complaint about the Cabinet Office's conduct with the Information Commissioner's Office — so watch this space.

UPDATE, 4 December 2013: Late last month, the Information Commissioner's Office replied to the complaint I filed about the UK government's non-response to my request that it release the rendition/torture report. An official from the ICO said he had contacted the government's Cabinet Office to confirm that my request had been received and to give the government a 10-day deadline to contact me. The ICO reminded the government of its obligations under the Freedom of Information Act and noted that it "may consider taking enforcement action" should similar complaints arise (read the ICO's correspondence here).

However, despite this light reprimand from the ICO, incredibly I've still received no response from the government about the rendition report. The 10-day deadline expired yesterday and I've heard nothing — I've not yet so much as received an acknowlegement that my initial request is being dealt with, even though it was submitted more than two months ago (the government is supposed to respond within 20 working days; it's now been more than 50). This means that the Cabinet Office, which likes to tout its transparency credentials, is not only actively flouting its obligations under the Freedom of Information Act — it has also now failed to act on a formal request made by the authority that enforces the FOIA law, the ICO. Before the end of the week, I'll be following up my complaint with the ICO in the hope that more serious action can be taken. Of course, I'll post further updates here with any new developments in this strange case as and when they arise.

UPDATE, 29 December 2013: The government has released the Detainee Report today; the Guardian reports that it reveals how "MI6 officers were under no obligation to report breaches of the Geneva conventions and turned a 'blind eye' to the torture of detainees in foreign jails, according to the report into Britain's involvement in the rendition of terror suspects." I am still pursuing my complaint against the Cabinet Office for its handling of my FOIA request.

UPDATE, 26 March 2014: In response to my complaint, the Information Commissioner's Office issued a "decision notice" stating that the Cabinet Office breached section 10 of the Freedom of Information Act in ignoring my request. More details here.

Prism D Notice

Tuesday, 18 June 2013

Following disclosures by the Guardian earlier this month about a US National Security Agency internet surveillance program called Prism, it has emerged that UK government officials issued a so-called "D notice" in a bid to censor coverage of spy tactics.

The D notice following the NSA leaks was reportedly issued to news organisations including the BBC on 7 June, the day after the Prism story broke. Prism is a system used by the NSA to monitor emails, file transfers, photos, videos, chats, and other data. Intelligence gleaned from the system has been passed to GCHQ, the UK's version of the NSA.

The notice to the media organisations was marked "Private and Confidential: Not for publication, broadcast or use on social media," according to Jeff Stein at And Magazine. It added:

There have been a number of articles recently in connection with some of the ways in which the UK Intelligence Services obtain information from foreign sources.

Although none of these recent articles has contravened any of the guidelines contained within the Defence Advisory Notice System, the intelligence services are concerned that further developments of this same theme may begin to jeopardize both national security and possibly UK personnel.

It particularly warned against reporting on:

specific covert operations, sources and methods of the security services, SIS and GCHQ, Defence Intelligence Units, Special Forces and those involved with them, the application of those methods, including the interception of communications and their targets; the same applies to those engaged on counter-terrorist operations.

The D-notice system was first set up in 1912 and operates in accordance with a voluntary code — providing "advice and guidance to the media about defence and counter-terrorist information the publication of which would be damaging to national security." In 2010, for instance, a D notice was reportedly issued prior to WikiLeaks' release of thousands of US government diplomatic cables. A D notice has no formal legal authority, but defying it can make journalists vulnerable to prosecution under the UK's Official Secrets Act.

The WikiLeaks Grand Jury

Thursday, 28 March 2013

As Alexa O'Brien reported Tuesday, the US Department of Justice has provided the latest confirmation that the grand jury investigation into WikiLeaks remains currently ongoing. That means it has been actively investigating the whistleblower website now for at least about 26 months (the Guardian first reported back in January 2011 that a subpoena seeking data on WikiLeaks had "appear[ed] to confirm for the first time the existence of a secret grand jury" empanelled to investigate individuals associated with the organisation. Prior to that, in late November 2010, the White House confirmed that there was an "active, ongoing criminal investigation" into WikiLeaks. And in July 2010, the Department of Defence stated that it had requested that the FBI help with an investigation related to WikiLeaks disclosures and that it "go wherever it needs to go").

I've been doing a bit of reading on grand juries, and the time-frame is significant because they do not have an indefinite lifespan. US law states that:
The grand jury shall serve for a term of eighteen months unless an order for its discharge is entered earlier by the court upon a determination of the grand jury by majority vote that its business has been completed. If, at the end of such term or any extension thereof, the district court determines the business of the grand jury has not been completed, the court may enter an order extending such term for an additional period of six months. No special grand jury term so extended shall exceed thirty-six months, except as provided in subsection (e) of section 3333 of this chapter.

From subsection (e) section 3333:

A special grand jury term may be extended by the district court beyond thirty-six months in order that such additional testimony may be taken or the provisions of subsection (b) of this section may be met.

And this from the American Bar Association's riveting Handbook on Antitrust Grand Jury Investigations:

The district court may extend the term of the special grand jury to a total of 36 months... The special grand jury may continue even beyond 36 months if it issues a report, and if the district judge determines that additional testimony is necessary, or that the report needs to be rewritten to comply with the governing statute.

So this means that the WikiLeaks grand jury seems to have been granted at least one six month extension thus far, as it has definitely exceeded the 18 month period already. It also suggests that some time between July this year and January 2014 — about four to ten months from now — the grand jury will either have already wrapped up or it will be close to wrapping up as it reaches the somewhat flexible 36-month cut-off point (see an update on this below). Grand juries, for those unfamiliar with them, do not decide the guilt of a person or persons. What they do is take evidence and make a judgement on whether or not criminal charges can be brought (in the form of an indictment) — in this case against Julian Assange and others affiliated with WikiLeaks.

All things considered, I would expect that within the next year or so it will be crunch time for this long-drawn-out saga. It still seems as if it could swing either way at this point, but it is worth weighing up the influence the broader political climate may have. There is an atmosphere in the United States at the minute that seems to represent a growing fatigue with the punitive national security culture that became pervasive post 9/11. Recent court judgments have gone against the government on issues related to secret surveillance and covert drone strikes, and this makes me wonder whether the tides are changing — albeit only incrementally and to a small degree.

Choosing to prosecute Assange for his role as an editor in publishing classified documents, as if it needs to be said, would be an outrageous decision that would cause an almighty outcry from a cross-partisan range of organisations and in the process damage the standing of the United States globally. Even at the height of the Bush administration's jingoistic reign it would have been an extremely controversial call to make. So for Obama's Justice Department to pursue a prosecution in the months ahead, in an atmosphere that may be tangibly shifting against draconian policies, would be a doubly contentious act that could turn out to be politically kamikaze for Obama personally in terms of his lasting legacy. All of these things will surely factor into any final decision regarding a prosecution, which will no doubt be discussed at the very highest echelons of the administration. But first, of course, we will have to wait to see whether or not the grand jury determines that there are charges to pursue in the first place....

*****

UPDATE, 1 April 2013: Wired.com news editor Kevin Poulsen, who was himself once the subject of a grand jury investigation for hacking into computer systems, tells me: "When a grand jury is up, prosecutors can just roll the case into a new grand jury." Significantly, this means that the 36-month cut-off point is far more flexible than the law I cited above implies, because when the first grand jury runs out of time, a new, second grand jury can effectively take up the investigation and continue its work with a fresh timetable. Poulsen said this occurred in his own case ("I had two GJs in series. Prosecution had a law enforcement witness summarize all previous testimony for the incoming panel"). And the book Grand Jury Practice by Howard W. Goldstein suggests it is not an unusual occurrence. Goldstein notes that "given the increasing complexity of federal investigations, many are not finished before the grand jury's term expires," adding: "information developed in one grand jury may be relevant to another grand jury."

An additional point worth mentioning here is that, according to an analysis of grand jury statistics circulated by WikiLeaks:

it is extremely rare for a grand jury not to indict. In the year 2009, federal grand juries in the United States saw cases involving 69,245 suspects and voted to indict all but 20 of them. (This is denoted by "no true bill returned" in the document.) That is a approximately one in every three thousand five hundred suspects. These statistics are repeated year after year. Given that it is known that he is the target of a grand jury investigation, Julian Assange has in and around a 99.97% chance of being indicted.
Interestingly, the same statistics show that US attorneys declined to prosecute 29,780 suspects in 2009 for reasons such as "stale case," "weak evidence," "minimal federal interest," and "Department of Justice policy." These all sound like strong grounds to halt any future attempt to prosecute WikiLeaks staff for their publishing work — if and when an indictment eventually materialises.

India's BlackBerry Snooping

Friday, 22 February 2013

The Indian government, as I reported at Slate today, is keen to obtain data on millions of BlackBerry users across the world to help its spy agencies intercept and track messages sent in and out of the country.

I was able to obtain some revealing Indian government documents, signed and dated as recently as last month, which offer an unusual level of insight into how the authorities have been negotiating with BlackBerry to enable surveillance of communications. You can find a bunch of previously unpublished extracts from these documents below.

Why they are of particular interest is because they disclose the level of cooperation between BlackBerry and spy agencies. It is highly likely that BlackBerry has worked with other countries — not only India — to help them monitor communications sent via BlackBerry's unique "BBM" messaging service, which allows BlackBerry users to communicate for free with each other.

Authorities in the United Kingdom, for instance, struggled to intercept BlackBerry messages during the riots in 2011 due to the encryption the technology uses. However, BlackBerry later admitted that it had "engaged with the authorities to assist," presumably by providing the type of interception function that is currently being used in India. The Indian government document I obtained show the authorities there have been working with RIM to:
  • Enable interception of emails and email attachments sent using BlackBerry devices.
  • Enable monitoring of web browsing by people using BlackBerry handsets.
  • Enable eavesdropping on messages sent via BlackBerry messenger.
  • Enable the interception of "delivery reports" showing when a sent message has been received.
  • Obtain access to a trove of the unique PIN codes of all BlackBerry phones shipped to India. (These codes can be used to trace and intercept BlackBerry messenger communications. Indian authorities are seeking access to all PIN codes belonging to every BlackBerry handset across the world. They say this will enable them to track and monitor BlackBerry messages going from India to countries overseas.)

It also caught my eye that the US-based company Verint, which I recently reported is offering governments a mass surveillance system to help intercept "billions" of communications, was present while India's BlackBerry monitoring system was being tested.

You can read the specific details in the extracts indented below, taken from an Indian government department of telecommunication report, produced by its "security wing." There is quite a lot of telecom jargon in there, unfortunately, but if you can cut through the acronyms you will see that the content is significant. I've included a little glossary/acronym debunker at the bottom of this post which may help translate. I've also bolded some bits that stand out to me as particularly noteworthy.

Research in Motion (RIM), Canada, is providing the Blackberry services in India through the licensed Telecom Service Providers.

Since Blackberry services are not getting intercepted in a readable format while lawful interception and monitoring by Security agencies, RIM was asked to provide the solution for lawful interception and monitoring in a readable format.

Accordingly, RIM offered the Interception solution for testing on 19.07.2012. During the testing, some observations were made by the testing team which were forwarded to RIM for compliance vide this office even letter dated 27.07.2012.

We may ask all the TSPs [telecom service providers] to comply with the Blackberry Interception requirements by 31.12.2012.

...the initial testing of various Blackberry services offered in India by Research In Motion (RIM), Canada, was carried out on 19 July, 2012 at Mumbai. During the testing on 19 July, 2012, some observations were made and conveyed to RIM as well as Vodafone to comply, which are as follows:

  • (i) PIN resolution is required to identify the actual user behind Blackberry PIN.
  • (ii) Web-browsing services which are being offered under BIS [are] also required to be decrypted.
  • (iii) CRI [call related information] is required in the standard format as applicable for Non-Blackberry cases.
  • (iv) Correlation between attachment intercepted communication and its initial email communication is required.
  • (v) The correct direction has to be provided in the CRI as per actual case scenario.
  • (vi) In case of BES services, Enterprise server and its Public IP address should be made available.
  • (vii) The delivery & read acknowledgment communications/signaling messages are not getting intercepted.
For the compliance of the above observations, RIM offered the testing in the network of Vodafone for the verification of compliances against the observations made on 19 July 2012. Accordingly, the testing was conducted on 10 Dec 2012 at Vodafone Data Center, Sahas, Mumbai. Besides the representatives of RIM Canada, Verint & Vodafone...officers were present during the testing...

*****

The IMEI was populated in all the scenarios of BBM (incoming / outgoing) and PIN-to-PIN messages (incoming and outgoing) correctly along with the PIN details (and IMEI) details of both the target and the other communicated party. However, if the target/communicated party is international then correlation between Blackberry PIN and IMEI does not appear.

During interaction, it was clarified by RIM that database provided in the CRS [carrier routing system] is based on the information of the PINs which have been officially shipped to India and data pertaining to other countries have not been provided due to privacy and other legal provisions of those countries. However, if data for entire world is loaded in the CRS, it can correlate each & every PIN.

In OS5 — the Web browsing service is based on RIM proprietary protocol (IPPP). Presently, it cannot be intercepted in a readable format through the proposed solution. As per RIM, the solution for OS5 is still under development and will be deployed and tested by end of April 2013.

Correlation between attachment intercepted communication and its initial email communication is required. Email Attachments — In BIS Email service, attachments are not downloaded automatically for incoming mails. Attachment gets transmitted after email is delivered when the user initiates an event to download it. Thus, the attachment arrives in a later stage (after the Email product has already been marked and stored), the system shall mark an independent File Transfer product (like Email).

With respect to PIN to IMEI resolution, the tested solution is apparently satisfactory for all the handsets officially shipped to India. With regard to handsets shipped to other countries, RIM intimated that PIN to IMEI correlation in such cases can be obtained through Blackberry Public safety office (PSO). However, we may negotiate with RIM to provide the entire IMEI-PIN correlation data including other countries.

it is proposed that:

(i) We may initiate a process to take over the possession of RIM infrastructure created at Mumbai for which a suitable agreement may be entered between DOT [department of telecommunication] and RIM.

(ii) We may negotiate with RIM to provide the Blackberry PIN-IMEI Correlation data for all the Blackberry handsets.

(iii) RIM and Vodafone may be asked to demonstrate the final solution in respect in respect of [interception of delivery reports] by end of January 2013 and [email attachment monitoring and web browsing tracking/decryption] by end of April 2013.

Acronym debunker: PIN = Personal Identification Number (a unique code every BlackBerry is allocated, can be used to track and monitor communications and identify the sender); BBM = BlackBerry Messenger; IMEI = International Mobile Station Equipment Identity (another unique code used to identify a phone); OS5 = a BlackBerry operating system; BIS = BlackBerry Internet Service; CRI = Call Related Information (the who, where and when of a communication — like the time a call was made and the number of the caller and recipient); CRS = Carrier Routing System (network infrastructure through which communications travel).

Guantanamo's Anonymous Censor

Sunday, 3 February 2013

When a suspected terrorist mastermind goes on trial at the Guantanamo Bay military commission, strange things can happen.

Last week, midway through the pretrial hearings for five accused 9/11 plotters, an anonymous outside censor unilaterally blacked out an audiovisual feed that provides public access to journalists reporting on the proceedings. The incident frustrated the military judge, who is supposed to have total control over the courtroom, and in the process illustrated the acute tension between open justice and obsessive-compulsive national security secrecy.

Here's how it went down, according to Jason Leopold, a reporter for Truthout who was in attendance:

...the audio feed to the proceedings was interrupted Monday when defence attorney David Nevin, who represents [accused 9/11 planner Khalid Shaikh] Mohammed, discussed the title of an exhibit pertaining to the CIA's secret black site prisons, where the self-professed 9/11 mastermind and his alleged co-conspirators had been held prior to their transfer to Guantanamo.

When Nevin uttered the word "secret," a warning light, which is silent, positioned on the judge's dais, started to flash and the sound of white noise was fed through the audio feed. Moments later, the monitors inside the gallery went black. The outage lasted three minutes. (The courtroom is visible to members of the gallery but is separated by soundproof glass; the audio feed is delayed by 40 seconds).

The judge, Col. James Pohl, was not happy about the act of censorship because he had not approved it. "If some external body is turning the commission on or off based on their own views of what things ought to be, with no reasonable explanation ... then we’re going to have a little meeting about who turns that light on and off," he said, reported the Huffington Post.

The fascinating debacle raised a number of questions, most importantly: who was this mysterious outside censor, watching proceedings from outside the courtroom and able to hit a "white noise" button on a whim? Leopold's report offers the closest thing to an answer:

It was later revealed by the government that the third party monitoring the hearings who was responsible for the interruption ... was the "original classification authority," or OCA, likely a reference to the CIA since that is the agency that operated the black site prisons.

But the government refused to provide information about whether the censor had been monitoring proceedings from a room at Guantanamo or was in fact located somewhere in the United States (like, say, the CIA's headquarters at Langley, Virginia).

"Who is the invisible hand?" asked one of the defence attorneys, not content with the lack of clarity. "Who is the master of puppets?"

It's a question that's difficult to answer with 100 percent certainty, given the secrecy. But whoever was responsible, he or she is not likely to be hitting the blackout button again any time soon. On Thursday judge Pohl ordered the government to unplug any outside censors. “This is the last time that will happen,” he said. “No third party can unilaterally cut off the broadcast.”

A rare triumph for transparency, it seems.

[You can a detailed report about the case, United States v. Mohammed, et al., here, courtesy of the Public Record.]