Written evidence submitted by Guardian Media Group [CT 17]

 

  1. In late 2012 Edward Snowden was working as an analyst for Dell inside a US military base in Japan. In the three months before May 2013 Snowden had moved to work for the US government contractor, Booz Allen Hamilton, at a signals intelligence operations centre in Hawaii. The US signals intelligence service is known as the National Security Agency or “NSA”. It operates under the jurisdiction of the US Defense Department.

 

  1. Edward Snowden was one of a huge number of people with US Government clearance to access large quantities of electronic data about NSA surveillance activities as well as the activities of the UK’s GCHQ.

 

  1. Snowden gave documents to Glenn Greenwald, then a Guardian columnist based in Rio, in late May 2013. Snowden also gave material to Laura Poitras, and Academy Award-nominated independent filmmaker based in Berlin, who has specialised in intelligence matters, and Bart Gellman, a Pulitzer prize winning journalist at the Washington Post.  The Guardian’s veteran former diplomatic editor, Ewen Macaskill, met Snowden in Hong Kong along with Greenwald and Poitras.

 

  1. Using less than 1% of the documents it was given by Snowden, the Guardian has published stories about the changing nature of intelligence and how technology is leading to routine mass collection and analysis of phone, email, social media and text message data. We have revealed the close relationship between intelligence services and technology or telecom companies and examined how, in the opinions of some, technologies have moved ahead of the law. And we have disclosed how the intelligence agencies have, some believe, worked to undermine the security standards upon which the internet, commerce, financial institutions and individuals rely.

 

  1. The Guardian was not alone in publishing these stories.  Many other publications across the world including the New York Times, the Washington Post, Le Monde, Der Spiegel, El Mundo, Globo, the Hindu, Suddeutsche Zeitung and El Pais have also published stories based on the Snowden material.  In each case the relevant editor independently took the view that these were matters of considerable public importance.

 

  1. These stories have prompted vigorous debate in parliaments across the world, led to calls for legal reform in the US and Europe, and a number of legal challenges. The President of the US, the German Chancellor and the UK Prime Minister have set up or encouraged reviews of intelligence and/or oversight mechanisms.  Numerous academics, business leaders and technology experts have testified as to the public importance of the issues raised.  On November 26 The United Nations moved a step closer to calling for an end to excessive surveillance in a resolution that reaffirmed the “human right to privacy” and called for the UN’s human rights commissioner to conduct an inquiry into the impact of mass digital snooping.

 

  1. We now briefly outline the nine stories published by the Guardian since June that demonstrate the Guardian’s contribution to this global debate.

 

Verizon - NSA collecting phone records of millions of Verizon customers daily

 

  1. On 6th June, the Guardian published its first story as a result of having access to the files provided by Edward Snowden.  That story, entitled “Verizon - NSA collecting phone records of millions of Verizon customers daily” outlined that the NSA has been collecting telephone records of US Verizon customers under a top secret court order issued in April 2013 for a three month period until 19 July 2013.

 

  1. The order requires Verizon to give the NSA all call records in its systems daily (between the US and abroad and wholly within the US).  These details include the numbers of both parties, location data, time, call duration, unique identifiers, originating and terminating call, telephone calling card numbers, trunk identifiers, International Mobile Subscriber number, and comprehensive communication routing information.  The data can include cell site location data.  The NSA Court order explicitly bars Verizon from disclosing to the public either the existence of the FBI’s requests for its customers’ records or the court order itself.

 

  1. The coverage has prompted a significant number of cross party US Government reviews initiated from the President through to members in both Houses including: Fourth Amendment Restoration Act, Surveillance State Repeal Act and legislation to reform domestic surveillance laws.  Documents released in November 2013 showed the NSA’s searches of a database containing the phone records of nearly all Americans violated privacy protections for three years by failing to meet a court-ordered standard. The newly declassified documents showed the violations continued until a judge ordered an overhaul of the program in 2009. The revelations called into question the public statements of Top U.S. officials, including the NSA’s Gen. Alexander, who have repeatedly reassured lawmakers that the phone-records programme was “well-overseen” and carefully executed under oversight from the secret national security court. 

 

  1. As a direct result of the revelations in this first story, On 22nd November 2013, the American Civil Liberties Union was in court in its case ACLU v Clapper[1] to argue that this mass data collection violates Americans' constitutional rights of privacy, free speech, and association, and that it goes far beyond what Section 215 of the Patriot Act envisaged.  On 29th October, Republican Senator and author of the Patriot Act Jim Sensenbrenner wrote that “whatever our differences may have been in the past, we strongly agree that the dragnet collection of millions of Americans’ phone records every day — whether they have any connection at all to terrorism — goes far beyond what Congress envisioned or intended to authorize. More important, we agree it must stop.”[2]

 

NSA Prism program taps in to user data of Apple, Google and others & GCHQ had been gathering intelligence from internet companies under the Prism program

 

  1. On 6th & 7th June, the Guardian published two stories: “NSA Prism program taps in to user data of Apple, Google and others”, and “GCHQ had been gathering intelligence from internet companies under the Prism program.”  These stories examined how since 2007 the NSA has been running a programme called Prism which enables the NSA to have direct access to the servers of some of the largest technology firms in the world including Google, Apple and Facebook. 

 

  1. In doing so, the NSA is able to covertly acquire and store the search history, email content, file transfers and live chats of any users of those websites without the knowledge of users.  The second story demonstrated GCHQ’s close involvement in the NSA collection of data, outlining how GCHQ has been accessing the Prism programme since June 2010 to gather intelligence on UK citizens.  This story raised significant questions about the legal framework under which GCHQ was accessing vast amounts of personal data about UK citizens.

 

  1. On 7th June, as a result of the Guardian coverage, the Chairman of the Intelligence & Security Committee, Sir Malcolm Rifkind issued a statement saying that “the ISC will be receiving a full report from GCHQ very shortly and will decide what further action needs to be taken as soon as it receives that information.”[3] In its subsequent report published on 17th July, the ISC stated that it was satisfied that the activities outlined by the Guardian “conformed with GCHQ’s statutory duties”, but went on to say it would consider further whether the “current statutory framework governing access to private communications remains adequate.”[4]  On 31st October 2013, in a Westminster Hall debate on oversight of the intelligence services, ISC member George Howarth MP confirmed that the Committee was only made aware of the existence of the Tempora programme after they read the article in the Guardian.[5]

 

  1. As a result of the Guardian’s reporting on these stories, English PEN, Open Rights Group and Big Brother Watch are in the process of challenging the legality of PRISM and Tempora at the European Court of Human Rights[6].  Separately, the Government and telecoms companies face a separate legal challenge brought by Privacy International against the UK's Investigatory Powers Tribunal over Tempora.  Liberty Human Rights has made official complaint to IPT and asked for an investigation into whether Prism and Tempora systems breached Article 8 of the Human Rights Act in relation to regulation of access to personal information.

 

  1. On Monday 4th November, the Guardian published an interview with David Blunkett MP and former Home Secretary at the time that RIPA was passed in which he said “In government you are pressed by the security agencies. They come to you with very good information and they say 'you need to do something’… I think RIPA needs trimming back. It is being used for things for which it was never intended.”[7]

 

  1. The Guardian’s reporting for these first two stories was widely commended.  For instance, Strobe Talbott, President of the Brookings Institute in Washington and a former Ambassador at large for President Clinton, commented: “The Guardian us emerging as global source of old-fashioned journalism via new media: e.g., breaking data mining story. Good on them, good for us”. Former President Jimmy Carter said the revelations had been “helpful”, adding  "I think that the secrecy that has been surrounding this invasion of privacy has been excessive, so I think that the bringing of it to the public notice has probably been, in the long term, beneficial."[8]

 

GCHQ spied on foreign politicians at G20 summits

 

  1. On 17th June 2013, the Guardian published a story entitled, “GCHQ spied on foreign politicians at G20 summits”, which outlined how the UK Government led by Gordon Brown had worked through GCHQ to monitor the phones and emails from allies including Turkey and South Africa during the G20 meetings in London in 2009.  The interception of data enabled 45 analysts to monitor activity in real time, providing UK Ministers with intelligence on the positions of delegations attending the G20 event.

 

  1. While the G20 interception capability gave British Ministers and officials advance notice of what allies were likely to say at multilateral meetings, the value of the intelligence gathered was considered of limited advantage.  As such, the Guardian story prompted questions about whether spending significant budget on such activity was necessary given the economic pressures on Government budgets, and the central focus on counter-terrorism.  As a result of the coverage, the Governments of Turkey and South Africa issued denunciations of spying and demanded an apology.  Turkey called spying “scandalous” and the South African government demanded a full investigation. In October – after further revelations about the US and UK spying on diplomats and politicians from countries which would in other respects be regarded as allies – President Obama ordered the National Security Agency to stop eavesdropping on the headquarters of the International Monetary Fund and World Bank. [9]

 

How the NSA is still harvesting your online data

 

  1. On 27th June 2013, the Guardian published “How the NSA is still harvesting your online data”.  This story highlighted the disparity between public statements by the US President Barack Obama that practices put in place by President George W. Bush to intercept had ceased.  The White House had claimed that "the internet metadata collection program authorized by the FISA court was discontinued in 2011 for operational and resource reasons and has not been restarted."[10]  The story outlined that NSA metadata programs were ongoing after 2011, enabling the collection of one trillion records.  The story highlighted the fact that a substantial portion of internet data collected by the NSA comes from allied governments, including from GCHQ[11].

 

NSA leaks US bugging European allies

 

  1. On 30th June, the Guardian published “NSA leaks US bugging European allies” which outlined how US intelligence services have been spying on the EU mission in New York and its embassy in Washington through devices in mission fax machines, electronic bugs, collection of transmissions and copies of computer hard drives.  The story outlined how the US intelligence community has targeted the embassies and missions of 38 allied nations.

 

  1. This story demonstrates that the intelligence agencies are increasingly driven by economic considerations, alongside any considerations of counter terrorism or national security.  The fact that the US is bugging its allies led to the Spanish and German Governments summoning their respective US ambassadors to discuss the details of the story.  In November, the German Government summoned the UK ambassador to discuss the allegations.

 

Microsoft NSA collaboration over user data

 

  1. On 12th July, the Guardian published “Microsoft NSA collaboration over user data”, which outlined how the US technology firm Microsoft collaborated with US intelligence services to allow its users communications to be intercepted, including helping the NSA to deliberately circumvent the encryption protocols that millions of Outlook.com and Hotmail customers rely on to keep their data and communications private.  Microsoft also enabled the NSA’s Prism programme to have easy access to its cloud storage service which has more than 250 million users worldwide. The story also outlined the fact that 9 months after purchasing the online video calling application Skype (which has over 650 million registered users worldwide[12]) Microsoft had worked with the NSA to develop a new capability that had tripled the amount of Skype video calls being collected through the Prism programme.

 

  1. As a result of reporting by the Guardian, on 18th July, a group of digital and tech businesses petitioned the US Government, urging greater transparency around national security-related requests.  Several proposed Acts including the Government Surveillance Transparency Act, and the Surveillance Transparency Act followed.  On 30th August, Microsoft and Google began litigation against the US Government, seeking permission to tell the public how much surveillance information they have handed to the U.S. government.

 

  1. In a further Guardian article on 12th September, speaking at a conference in San Francisco, Mark Zuckerberg of Facebook said, "The government response was, 'Oh don't worry, we're not spying on any Americans.' Oh, wonderful: that's really helpful to companies’ trying to serve people around the world, and that's really going to inspire confidence in American internet companies”.  In reference to the tech companies actions to drive more transparency around data requests, Zuckerberg said, "We are not at the end of this. I wish that the government would be more proactive about communicating. We are not psyched that we had to sue in order to get this and we take it very seriously".  On being asked why the tech industry had not been clearer with consumers about what the US surveillance industry was up to, the CEO of Yahoo Marissa Mayer, said, "Releasing classified information is treason and you are incarcerated"[13]. 

 

  1. The Guardian’s publication of this story demonstrated the gap between the tech industry’s outward-facing attitude to consumer privacy and its actual cooperation with Government to supply access to vast amounts of data generated by users.  Without the Guardian’s publication of this story, given the classified nature of the material, it is likely that the tech industry would have remained silent, and that millions of innocent consumers would have been unaware of the intelligence agencies’ activities as a result.

 

  1. In response to a further Washington Post story Microsoft’s top lawyer called “disturbing” a new report saying the U.S. government may be eavesdropping on the company’s Web traffic overseas.  Brad Smith, Microsoft’s general counsel said: “If they are true these actions amount to hacking and seizure of private data and in our view are a breach of the protection guaranteed by the Fourth Amendment to the Constitution”. In common with other west coast tech companies – including Google and Yahoo – Microsoft moved to improve its encryption.[14]

 

NSA pays £100m in secret funding for GCHQ

 

  1. On 1st August, the Guardian published “NSA pays £100m in secret funding for GCHQ”, which outlined the fact that a weaker system of regulation governing the activities of the British intelligence agencies in relation to the collection and interrogation of data is being used as a 'a selling point' to the NSA who sub contract espionage activity to GCHQ for £100m paid over three years.  Through this contract, GCHQ supplies the NSA with personal data gathered from the mobile phones and digital applications to enable it to “exploit any phone, anywhere, any time".  As a result of this funding from the NSA, GCHQ is in a position where it must “pull its weight and be seen to pull its weight”[15]. 

 

  1. While it has been known for many years that the UK and US intelligence communities have a close relationship, before the publication of the article by the Guardian GCHQ supports the NSA in this way, acting to explicit or perceived service level agreements regarding output delivery.  It was also not known that the UK intelligence services explicitly use the weaker oversight regime in the UK as a key reason for conducting intelligence operations in Britain, saying “we are less constrained by NSA’s concerns about compliance.”[16]

 

Revealed: how US and UK spy agencies defeat internet privacy and security

 

  1. On 6th September, the Guardian published “Revealed: how US and UK spy agencies defeat internet privacy and security”.  The article detailed a 10 year, $250m-a-year NSA program which works covertly with tech companies to insert weaknesses into products. "For the past decade, NSA has lead [sic] an aggressive, multi-pronged effort to break widely used internet encryption technologies…Vast amounts of encrypted internet data which have up till now been discarded are now exploitable."[17]

 

  1. The document which sits at the heart of reporting the encryption story acknowledges the fact that there would likely be public interest if these revelations were ever revealed, stating that "Some exploitable products are used by the general public; some exploitable weaknesses are well known eg possibility of recovering poorly chosen passwords…Knowledge that GCHQ exploits these products and the scale of our capability would raise public awareness generating unwelcome publicity for us and our political masters."[18]

 

  1. Both the UK Government through the Cabinet Office, and the heads of the UK intelligence services acknowledge the dangers of weaknesses in cyber security to the UK economy.  A report published by the Cabinet Office undertaken by government technology supplier Detica, found that the cost of cyber crime to the UK economy is £27 billion per annum[19].  During the recent Intelligence and Security Committee open session with the intelligence chiefs, Director of GCHQ, Sir Iain Lobban, said that, “We are seeing threats to over 20 industrial sectors. Research and innovation being targeted, trade secrets, academic research, as I said. Industrial espionage on an industrial scale, stealing intellectual property. The response to that has to be a cross-Government one and actually a beyond Government one. We work very closely with the Centre for the Protection of National Infrastructure. We work with the Business, Innovation and Skills department. We will be working increasingly with the new National Crime Agency, who work with the Cabinet Office, of course. That is a team game. If we get that right, I believe that we can actually be world class in terms of cyber, the UK.”[20]

 

  1. Responding to revelations that UK and US intelligence agencies have been weakening the fabric of the internet, an Economist editorial read, “This is big news, if true… encryption of electronic data is an essential part of modern life. It secures the financial networks that link the world’s banks, protects credit cards, stops mobile-phone calls from being listened to, guards medical records and lawyers’ letters to their clients. Though cybercrime is a growing menace, reliable encryption remains the foundation on which the trillion-dollar edifice of e-commerce is built: without it, nobody would be able safely to make a payment online. For critics, sabotaging such codes is akin to a government secretly commanding lockmakers to make their products easier to pick—and to do so amid an epidemic of burglary.”[21]  The British creator of the World Wide Web, Sir Tim Berners-Lee, told the Guardian that the “agencies' decision to break the encryption software was appalling and foolish.”[22] An influential group of academic cryptographers wrote an open letter calling for the ISC to “investigate as a matter of urgency”.[23]

 

  1. Two leading US professors of computing wrote in Foreign Affairs, the journal of the US Council on Foreign Relations: "Of all of the revelations about the NSA that have come to light in recent months, two stand out as the most worrisome and surprising to cybersecurity experts. The first is that the NSA has worked to weaken the international cryptographic standards that define how computers secure communications and data. The second is that the NSA has deliberately introduced backdoors into security-critical software and hardware. If the NSA has indeed engaged in such activities, it has risked the computer security of the United States (and the world) as much as any malicious attacks have to date.  No one is surprised that the NSA breaks codes; the agency is famous for its cryptanalytic prowess. And, in general, the race between designers who try to build strong codes and cryptanalysts who try to break them ultimately benefits security. But surreptitiously implanting deliberate weaknesses or actively encouraging the public to use codes that have secretly been broken -- especially under the aegis of government authority -- is a dirty trick. It diminishes computer security for everyone and harms the United States’ national cyberdefense interests in a number of ways.”[24]

 

  1. On reviewing the Home Affairs Select Committee’s recent enquiry into e-crime, it appears that the Committee was not made aware of the intelligence agencies’ remit in this area, nor its activities in working with the tech community to alter encryption standards[25].  In publishing this story on encryption, the Guardian has brought to public attention the fact that digital products and services used by consumers and businesses across the world are potentially more vulnerable to attack as a result of intervention by our own intelligence agencies.

 

NSA and GCHQ target Tor network that protects anonymity of web users

 

  1. On 4th October, the Guardian published a story “NSA and GCHQ target Tor network that protects anonymity of web users”, which outlined the fact that the NSA had been targeting the encryption tool – originally designed and released by the US Navy to aid secure transfer of communications and still largely funded by the US State Department – by identifying users and attacking vulnerable software on their computers.  The Guardian article outlined a range of weaknesses that had historically been exploited by GCHQ and the NSA, all of which had been fixed voluntarily by the Tor community membership months before publication of the Guardian story.

 

  1. Tor has been the subject of attack by a range of repressive regimes in recent years.  According to a presentation by a Tor developer, the protocol has been under attack as a result of: DNS filtering of the Tor website in Thailand in 2006 and throttling of Tor traffic in Iran, Tunisia and China in 2009.[26]  At the height of the Arab Spring, the Tor project estimates that between 200,000 to 500,000 activists used Tor to communicate across Tunisia, Egypt, Syria and Iran in order to protect their anonymity.  It was this ability to communicate that inspired these societies to revolution and to communicate that revolution to the outside world.

 

  1. The centrality of Tor to both freedom of expression and its use by criminal elements has been recognised by the Coalition Government.  On 1st November 2011, the Foreign Secretary William Hague told a London conference on Cyberspace that, " Cultural differences are not an excuse to water down human rights, nor can the exploitation of digital networks by criminals or terrorists be a justification for states to censor their citizens.”[27]  More recently on 11th July 2013, 3 months before the Guardian published its story on Tor, the Prime Minister gave a speech at the NSPCC in which he said that in the law enforcement agency is already doing a good job in ‘disrupting the so called hidden internet” and that they would get more funding to “shine a light on this hidden internet”[28].  Just after the Guardian published its story on 10th October 2013, the head of the National Crime Agency said, “You may think that you can operate anonymously online and have the security of Tor to conduct your business but you can’t”[29].

 

  1. The Guardian’s story about the efforts of the NSA and GCHQ to exploit weaknesses in the Tor network related to historic - not live – events.  The weaknesses detailed by the Guardian and patches designed to fix those weaknesses have been openly discussed in forums used by Tor users for many months before the story was published.  The fact that UK law enforcement agencies are attacking hidden protocols such as Tor is, again, not news, having come from the Prime Minister’s mouth and being covered by many newspapers on Fleet Street in July this year.  However, as the Foreign Secretary said in 2011, the use of digital networks by terrorists and criminals should not be used as an excuse to close down debate about the activity of Government that potentially undermines freedom of expression online in the UK.

 

Guardian Media Group

27th November 2013

 


[1] https://www.aclu.org/blog/national-security/finally-day-court-challenge-mass-surveillance

[2] http://www.politico.com/story/2013/10/leahy-sensenbrenner-nsa-reform-98953.html

[3] http://isc.independent.gov.uk/news-archive/7june2013

[4] http://isc.independent.gov.uk/files/20130717_ISC_statement_GCHQ.pdf

[5] http://www.publications.parliament.uk/pa/cm201314/cmhansrd/cm131031/halltext/131031h0001.htm

[6] https://www.privacynotprism.org.uk/

[7] http://www.theguardian.com/world/2013/nov/04/david-blunkett-review-laws-security-services

[8] http://www.theregister.co.uk/2013/07/18/carter_warns_america_no_democracy_prism/

[9] http://www.reuters.com/article/2013/10/31/us-usa-security-imf-idUSBRE99U1EQ20131031

[10] http://www.theguardian.com/world/2013/jun/27/nsa-data-mining-authorised-obama

[11] http://www.theguardian.com/world/2013/jun/27/nsa-online-metadata-collection

[12] http://www.telecompaper.com/news/skype-grows-fy-revenues-20-reaches-663-mln-users--790254

[13] http://www.theguardian.com/technology/2013/sep/11/yahoo-ceo-mayer-jail-nsa-surveillance

[14] http://www.washingtonpost.com/business/technology/microsoft-suspecting-nsa-spying-to-ramp-up-efforts-to-encrypt-its-internet-traffic/2013/11/26/44236b48-56a9-11e3-8304-caf30787c0a9_story_1.html

[15] http://www.theguardian.com/uk-news/2013/aug/01/nsa-paid-gchq-spying-edward-snowden

[16] http://www.theguardian.com/uk-news/2013/aug/01/nsa-paid-gchq-spying-edward-snowden

[17] http://www.theguardian.com/world/2013/sep/05/nsa-gchq-encryption-codes-security

[18] http://www.theguardian.com/world/2013/sep/05/nsa-gchq-encryption-codes-security

[19] https://www.gov.uk/government/publications/the-cost-of-cyber-crime-joint-government-and-industry-report

[20] http://isc.independent.gov.uk/files/20131107_ISC_uncorrected_transcript.pdf

[21] http://www.economist.com/news/international/21586296-be-safe-internet-needs-reliable-encryption-standards-software-and

[22] http://www.theguardian.com/world/2013/nov/06/tim-berners-lee-encryption-spy-agencies

[23] http://bristolcrypto.blogspot.co.uk/2013/09/open-letter-from-uk-security-researchers.html

[24] http://www.foreignaffairs.com/articles/140214/nadia-heninger-and-j-alex-halderman/tales-from-the-crypto-community?cid=soc-twitter-in-snapshots-tales_From_the_crypto_community-103013

[25] http://www.publications.parliament.uk/pa/cm201314/cmselect/cmhaff/70/70.pdf

[26] http://internet-science.eu/sites/internet-science.eu/files/RunaSandvikEINSsummerschool%5B1%5D_0.pdf

[27] https://www.gov.uk/government/speeches/foreign-secretary-opens-the-london-conference-on-cyberspace

[28] https://www.gov.uk/government/speeches/the-internet-and-pornography-prime-minister-calls-for-action

[29] http://www.telegraph.co.uk/technology/internet-security/10369880/National-Crime-Agency-wages-war-on-Tor-darknet-anonymity.html