Translate

显示标签为“棱镜门”的博文。显示所有博文
显示标签为“棱镜门”的博文。显示所有博文

2013年7月1日星期一

NSA最新幻灯片曝光:详解棱镜项目工作流程

北京时间6月30日上午消息,《华盛顿邮报》昨天独家披露了美国国家安全局(NSA)“棱镜”(PRISM)项目的四张幻灯片。这些文件详细揭示了 整个项目的工作流程,包括NSA和美国联邦调查局(FBI)的审查和监管权限。另外,它们还显示了该项目与所涉九家互联网公司的互动方式。
  1. 获取新目标的数据
1
  这张幻灯片描述了NSA分析员在PRISM系统中建立新监控目标的流程。建立新目标的请求会自动发送到审查搜索关键词的主管。主管必须批准分析员的“合理意见”,即收集数据时指定目标为海外的外籍人士。
外国情报监视法庭不审批任何个人数据收集请求外国情报监视法庭不审批任何个人数据收集请求
  左:FBI使用装在私人公司(例如微软、雅虎)的政府设备检索匹配的信息,不经进一步审查便交给NSA。
  中:外国情报监视法庭不审批任何个人数据收集请求
  右1:对于存储的通信记录(非实时监控),FBI会查询其数据库,确保筛选器不会匹配任何知名美国人。
  右2:数据从此处进入NSA系统。
  2. 分析从私人公司收集到的信息
2
  获取通信信息后,由专门的系统处理语音、文字、视频以及地理位置、监控目标的设备特征等“数字网络信息”。
  左:FBI装在私人公司的截获设备将信息传递给NSA、CIA或FBI。
  3. 每个目标分配一个案例代号
3
  PRISM案例代号格式反映了实时监控和存储内容的可用情况。
  每当监控目标登录或发送电子邮件时,NSA可收到实时通知,另外还可实时监控语音通话和文字消息,具体情况视PRISM数据提供方而定。
  4. 搜索PRISM数据库
4
  这张幻灯片显示,4月5日PRISM的反恐数据库中由11.7675万活跃的监控目标。它未显示监控这些目标的过程中“无意”收集了多少其他互联网用户以及多少美国人的通信信息。

文章来源: http://goo.gl/03kw2
附原文:

NSA slides explain the PRISM data-collection program

The top-secret PRISM program allows the U.S. intelligence community to gain access from nine Internet companies to a wide range of digital information, including e-mails and stored data, on foreign targets operating outside the United States. The program is court-approved but does not require individual warrants. Instead, it operates under a broader authorization from federal judges who oversee the use of the Foreign Intelligence Surveillance Act (FISA). Some documents describing the program were first released by The Washington Post on June 6. The newly released documents below give additional details about how the program operates, including the levels of review and supervisory control at the NSA and FBI. The documents also show how the program interacts with the Internet companies. These slides, annotated by The Post, represent a selection from the overall document, and certain portions are redacted. Read related article.
New slides published June 29

Acquiring data from a new target

This slide describes what happens when an NSA analyst "tasks" the PRISM system for information about a new surveillance target. The request to add a new target is passed automatically to a supervisor who reviews the "selectors," or search terms. The supervisor must endorse the analyst's "reasonable belief," defined as 51 percent confidence, that the specified target is a foreign national who is overseas at the time of collection.
The FBI uses government equipment on private company property to retrieve matching information from a participating company, such as Microsoft or Yahoo and pass it without further review to the NSA.
For stored communications, but not for live surveillance, the FBI consults its own databases to make sure the selectors do not match known Americans.
This is where data enters NSA systems, described more fully on the next slide.
The Foreign Intelligence Surveillance Court does not review any individual collection request.

Analyzing information collected from private companies

After communications information is acquired, the data are processed and analyzed by specialized systems that handle voice, text, video and "digital network information" that includes the locations and unique device signatures of targets.
From the FBI's interception unit on the premises of private companies, the information is passed to one or more "customers" at the NSA, CIA or FBI.
PRINTAURA automates the traffic flow. SCISSORS and Protocol Exploitation sort data types for analysis in NUCLEON (voice), PINWALE (video), MAINWAY (call records) and MARINA (Internet records).
The systems identified as FALLOUT and CONVEYANCE appear to be a final layer of filtering to reduce the intake of information about Americans.

Each target is assigned a case notation

The PRISM case notation format reflects the availability, confirmed by The Post's reporting, of real-time surveillance as well as stored content.
Depending on the provider, the NSA may receive live notifications when a target logs on or sends an e-mail, or may monitor a voice, text or voice chat as it happens (noted on the first slide as "Surveillance").

Searching the PRISM database

On April 5, according to this slide, there were 117,675 active surveillance targets in PRISM's counterterrorism database. The slide does not show how many other Internet users, and among them how many Americans, have their communications collected "incidentally" during surveillance of those targets.
Original slides published June 6

Introducing the program

A slide briefing analysts at the National Security Agency about the program touts its effectiveness and features the logos of the companies involved.
The program is called PRISM, after the prisms used to split light, which is used to carry information on fiber-optic cables.
This note indicates that the program is the number one source of raw intelligence used for NSA analytic reports.
The seal of
Special Source Operations, the NSA term for alliances with trusted U.S. companies.

Monitoring a target's communication

This diagram shows how the bulk of the world’s electronic communications move through companies based in the United States.

Providers and data

The PRISM program collects a wide range of data from the nine companies, although the details vary by provider.

Participating providers

This slide shows when each company joined the program, with Microsoft being the first, on Sept. 11, 2007, and Apple the most recent, in October 2012.

 

2013年6月25日星期二

从民主理论角度看棱镜事件–政府秘密机构与民主政治

删节版以“美情报机构如何成为‘民主盲区’?”为题发表于6月23日《新京报》。
本文受到Rahul Sagar (2007), “On Combating the Abuse of State Secrecy,” The Journal of Political Philosophy 15(4): 404-427的启发。
日前美国“棱镜(PRISM)”项目的曝光,引发了广泛争议。“棱镜”的前身是911以后国家安全局秘密启动的“恐怖分子监控计划 (Terrorist Surveillance Program)”。2005年,国家安全局情报分析员罗素·泰斯(Russell Tice)爆料称,该计划完全绕开了“外国情报监控法院(Foreign Intelligence Surveillance Court,以下简称‘情报法院’)”的审查,在未获法庭许可证的情况下非法窃听美国公民,一时舆论哗然。碍于物议,小布什先后要求国会通过了《保护美国 法案》(Protect America Act of 2007)与《〈外国情报监控法案〉修正案》(FISA Amendments Act of 2008),正式授权国家安全局在经过情报法院批准后对涉外信息进行监控,同时规定网络运营商必须与国家安全局合作,提交怀疑对象的电子邮件、社交网站信 息等数据。相应地,改头换面之后的“棱镜”,监控范围除了传统的账单与电话外,还扩及互联网上的各种涉外活动。
由于得到了立法、司法部门的授权,因此单从法律程序上说,“棱镜”项目是毫无问题的。争议的焦点集中在法理以及更深入的理论层面上,比如个人隐私与 国家安全之间的平衡、信息技术进步对隐私权立法的影响等等。而在这些理论问题中,迄今甚少得到讨论的一个是:国安、情报部门等等就其性质而言必然隐于幕后 的政府机构,及其种种秘密活动,如何能够恰当地纳入民主政治的框架之中?
这一问题并非无的放矢,相反恰恰指向民主理论的一个内在困境。在自由民主社会中,民众的授权与问责是政府统治正当性的必要条件,而这种授权与问责的 实现至少要求存在周期性的普选。但选举授权只有在公众具备获得充分信息的渠道、能够有效地对政府行为做出判断的条件下才有实质意义。显然,政府秘密机构的 存在与民主政治对公共信息的要求是相抵牾的,在一般情况下,公众不可能接触到诸如“棱镜”之类项目的机密资料,甚至根本无从得知这些项目的存在,自然也无 从判断这些项目带来的利益与风险,无从判断政府是否僭越了既有授权、应当受到选票的支持还是惩罚。另一方面,国家安全离不开机密部门的存在与运作,又是不 能不承认的政治事实。因此,民主正当性条件与国家机密部门必要性之间的张力,便成为一个亟待解决的问题。
知情问责
面对这一矛盾,一种简单的解决思路认为,民主政府必须尽可能地向公众开放涉及秘密活动的信息。譬如“棱镜”事件发作后,《经济学人》(The Economists)的一篇评论认为:“在民主制中从事监视活动,其正当性依赖于知情同意,而非盲目信任。”根据这种观点,国家安全局在制定“棱镜”计 划前,应当将意图与草案公之于众,经过媒体充分讨论之后再做决定。但问题在于,监控的效力极大地依赖于其保密程度。倘若恐怖分子明知国安部门将会监控电邮 与社交网站,自然要改弦更张转向别的通讯方式,或者使用暗语联络等等。这样一来,监控项目也就失去其意义了。
正是出于同样的考虑,1976年的《阳光政府法案》(Government in the Sunshine Act)在规定政府机构的会议必须开放公众旁听、以提高政府工作透明度的同时,也列出了十种例外的情况,其中就包括涉及国家安全信息的会议。
有人或许认为,秘密机构活动的正当性并不依赖于公众对其细节的完全了解,而只需要知道个大概——譬如这些机构正在进行若干涉及监控的反恐项目、这些 项目能够保障国家安全——即可。但这样粗浅的了解恐怕不足以对行政部门的滥用权力构成任何制约或问责。2006年,时任司法部长的阿尔贝托·冈萨雷斯 (Alberto Gonzales)在为“恐怖分子监控计划”辩护时,声称该计划在保护美国免受恐怖袭击上发挥了及其巨大的作用,但当记者请他略举一例以说明该计划如何发 挥作用时,冈萨雷斯的回应却是:事关国家机密,无可奉告。类似地,日前国家安全局长凯思·亚历山大(Keith Alexander)在为“棱镜”项目辩护时,声称该项目迄今至少阻止了50次恐怖袭击。哪50次?对不起,无可奉告。当然,没有证据表明亚历山大是信口 开河,但同样也没有证据表明他的说法值得公众信赖——因为所有能够作为证据和问责基础的资料,都锁在公众遥不可及的机密档案柜里。
从理论上说,公众并不是没有可能获得这些信息。根据《信息自由法案》(Freedom of Information Act of 1966)及其修正案,普通公民可以提请法院对某项政府机密进行审查,以决定其是否能够公开。但在实践中,法院往往会听从行政部门的意见,但凡后者认为其 公开有碍国家安全的,法院便判其继续保密。这倒不是说司法部门屈从于行政部门的威压,只是因为法官们自感无力对涉及国家安全的问题做出合格的判断。最高法 院在1985年“中央情报局诉希姆斯(CIA v. Sims)”一案中的判词很有代表性:“中央情报局的局长对‘全盘局势’当然是熟悉的,而法官们对此当然是不熟悉的,因此,考虑到国家安全涉及的重大利益 与潜在风险,中央情报局局长的决定理当得到我们的高度尊重。”
公众了解秘密机构活动的另一途径是等待相关信息的解密。但等待解密毕竟过于被动,依赖其作为问责的基础存在两大问题。首先,倘若即将解密的资料中包 含了非法活动的证据,秘密机构的相关人员完全具备狗急跳墙破坏证据的便利条件。1972年,在联邦调查局长交椅上一坐三十多年的埃德加·胡佛(Edgar Hoover)去世时,其秘书海伦·甘迪(Helen Gandy)便连夜将联邦调查局的过往重要档案全部销毁。“伊朗门”丑闻爆发后,里根政府的官员同样迅速销毁了关键文件,使得国会的调查无以为继。
其次,即便档案得到完整保存,但越是机密的文档保密年限越长,等到解密时早已沧海桑田物是人非,公众想要问责也无从问起了。由于文件机密规格的归类 权主要掌握在行政机构手中,行政首长便可以利用这一点拖延事后的问责。小布什上任时,正值里根任内的总统文件即将公开之际,而这些文件很可能涉及里根、老 布什、以及小布什内阁中诸多共和党大员在伊朗门事件中扮演的角色。于是小布什通过第13233号行政令宣布,现任总统有权任意延长过往总统文件的保密时 间。两年后他又颁发了第13292号行政令,将更广泛的保密权揽到行政部门手中。尽管奥巴马上任后,分别通过第13489、13526号行政令撤销了这两 道命令,并对秘密部门档案的解密程序作了系统性的规范,但是除非国会对此通过新的立法,否则未来的总统同样随时可以撤销奥巴马的政令。
分权制衡
公众无法对政府秘密机构的活动及时知情,完全依赖事后的解密来追加问责又过于被动延沓。自然而然地,我们会想到是否可以利用权力之间的分立与制衡,通过立法、司法部门对秘密材料的审查来约束行政部门下属的秘密机构,并间接地为其存在赋予民主正当性。
在某些特定时候,国会的介入确实能够对秘密机构的滥权构成约束。1975年,受到海伦·甘迪销毁联邦调查局文件一事与水门事件丑闻的连续刺激,参议 院成立了丘奇委员会(Church Committee),对国家安全局、联邦调查局、中央情报局的所作所为进行了集中调查,叫停了若干非法秘密项目,并促成了《阳光政府法案》、《外国情报 监控法案》(Foreign Intelligence Surveillance Act of 1978)等一系列立法的出台。此后丘奇委员会演变为常设的参议院情报特别委员会(Senate Select Committee on Intelligence),旨在对情报系统进行持久的监督。
但缺少了重大丑闻的刺激,这种监督的效力便变得可疑。由于行政部门控制着秘密机构的日常工作,其很容易对国会议员接触到的信息加以筛选和操纵。共和 党参议员苏珊·柯林斯(Susan Collins)曾是参议院国土安全与政府事务委员会(Senate Committee on Homeland Security and Governmental Affairs)主席、现任参议院情报特别委员会委员,然而她在“棱镜”项目曝光后接受采访时却表示,自己虽然每个月都会收到一份来自情报部门的国家安全 威胁简报,但是这些简报并不包含任何涉及具体项目的信息,所以她和普通人一样,根本不知道存在“棱镜”这样一个监控电话与网络记录的项目。这种现象并非偶 然,几年前情报特别委员会的成员们同样对“恐怖分子监控计划”一无所知,以至于在媒体曝光该计划的非法窃听后,委员会里的民主党参议员荣·怀登(Ron Wyden)对前来采访的记者半开玩笑半感叹道:“我哪里知道什么?我只不过是情报委员会的成员而已。”
当然从理论上说,国会议员有权随时查看相关项目的详细机密报告——但首先你总得知道这些项目和报告的存在吧。其次,议员在查看浩如烟海的机密报告 时,不得随身携带任何通讯工具、可以现场作笔记但不得将笔记带走、事后也不得向助手谈起这些报告的内容(因为助手的机密级别不够)。结果大部分议员在投票 表决对涉及国家安全的法律时其实都是糊里糊涂,并没有真正意识到自己授权的是怎样性质的项目。
司法部门的监督审查也好不到哪里去。前面提到,非专业的法官往往倾向于听从行政部门的意见。因此国会在1978年制定了《外国情报监控法案》,成立 专门的情报法院,希望其能够独立而专业地审查国家安全局与联邦调查局在国内的监听监视活动。但自其成立以来,在国安、情报部门提交的数以万计的监控申请 中,该法院对绝大多数都颁发了许可令,只拒绝了其中的区区11例。而2005年罗素·泰斯出面揭发国家安全局非法窃听美国公民时,也曾说道,情报法院向来 不过是“手拿橡皮图章的袋鼠法院”。
当然,颁发监控许可令的比例并不足以作为判断情报法院审查效力的依据。由于其涉及事项的敏感性,这个法院同样是一个秘密机构,其庭审不对公众开放, 法庭记录也被列为机密文件,只公布提交与批准的监控申请数。所以公众无从得知法院对绝大多数监控申请的批准,究竟是理由充分,还是敷衍塞责。
这意味着我们又绕回到了一开始的困境上来:公众之所以能够信赖权力制衡的效果,将立法、司法部门对行政部门秘密机构的审查视为后者民主正当性的间接 来源,是因为前者本身直接暴露于公共审视之下。但如果仅仅由一个秘密委员会或者秘密法庭来审查秘密行政机构,而公众对前者的工作细节仍然毫不知情,又怎么 保证不是换汤不换药、保证两者不会同流合污呢?
爆料检举
看来制度上的各种安排,无论是政府透明度的提高、档案解密后的追责、还是国会与司法部门的监督审查,都无法完全有效地化解民主政治与政府秘密机构活 动之间的张力。因此,制度外的公众知情途径,对于两者之间的兼容平衡是不可或缺的。换言之,民主政治的运作,从逻辑上蕴含了秘密机构内部人士不定时的爆料 检举。
从历史上看,公众(甚至国会)对政府秘密机构活动的了解也确实绝大多数来自各式各样的爆料。最著名的莫过于1971年的“五角大楼文件”事件,丹尼 尔·艾尔斯伯格(Daniel Ellsberg)将政府在越南问题上犯下一连串政策失误并长期欺骗国会与公众的证据泄露给《纽约时报》等媒体,促成了越战的终结。而仅在最近几年,就有 罗素·泰斯对“恐怖分子监控计划”非法窃听的检举,布拉德利·曼宁(Bradley Manning)将大量外交机密档案泄露给“维基解密”,以及本次爱德华·斯诺登(Edward Snowden)对“棱镜”的曝光,等等。
但内部人员对秘密档案的爆料,本身又与国家安全的考量相冲突,因此也并非毫无争议。在这一点上,爆料行为与一般的“公民不服从(civil disobedience)”有所不同:后者通过对恶法的公开抵制来表达自身政治立场,自愿为此付出法律代价,却并不牵累其它公众;而前者对国家机密的曝 光却有可能造成政府在外交、反恐等方面的失败,从而间接损害到公共利益。另一方面,对秘密机构的爆料也与一般的检举政府不当行为的做法有所不同:在后一种 情况中,各方证据有案可查,容易判断谁是谁非;而在前一种情况中,由于除非爆料者能够出示大量而切实的材料,否则公众很难判断其是否夸大其辞、或是通过有 选择地剪裁材料来诱导公众。
出于这两方面的原因,秘密机构的爆料人基本无望在法律上得到与其它检举人一样的保护。1989年《检举人保护法案》(Whistleblower Protection Act)规定,联邦政府机构不得对检举政府不当行为的雇员在人事安排上施行打击报复。但该法案同时规定,国家安全局、中央情报局、联邦调查局、国防情报局 这些秘密机构的工作人员并不在保护范围之内(当然,本次“棱镜”事件的爆料人爱德华·斯诺登只是外包公司的员工,并非联邦政府本身的雇员,本来也无权享受 该法案的保护)。反过来,秘密机构的爆料人往往会面临相当严重的刑事指控。譬如对“维基解密”爆料人布拉德利·曼宁的审判,目前就在进行之中。
民主政治中国家机密部门存在的必要性所导致的张力无法单靠制度来消除(当然这并不意味着制度上的约束毫无意义),需要内部人士偶尔的爆料引发公共关 注与问责方能得到平衡。然而爆料人本身面临着巨大的道德风险与高昂的法律代价,并且这些风险与代价同样来自制度上的要求,因为政府无法在不陷入自相矛盾的 前提下鼓励来自秘密机构内部的爆料行为。既然如此,一个完备的民主理论就必须说明,如何能够在制度之外为爆料人提供合理的动机资源去面对潜在风险和代价, 使得通过内部爆料来平衡秘密机构权力的做法成为民主生活中一种可持续的机制。
这就意味着完备的民主理论不但需要关心民主政治的制度建设,还需要重视民主生活中作为动机资源的公民美德与公共文化。民主社会中对公民美德——比如 荣誉感、合理慎思的能力、对自由的重视与对权力滥用的警惕——的强调,并不是说任何人、任何时候都需要具备这些美德,也不是说在做任何判断或决定时,这些 美德都应该成为首要的动机,而只是说这些美德在若干时候、若干个体身上能够获得若干程度的呈现,对于民主政治的良好运作是不可或缺的。
另一方面,这些公民美德的持续存在与呈现,离不开民主生活中公共文化的支持。以对秘密机构的内部爆料为例,只有当公众清晰地意识到秘密机构滥权的巨 大威胁与爆料者所面临的困难抉择,并对后者体现出充分的理解与声援(这并不意味着公众必须赞同后者的观点)时,公权力对个体的威压才能得到一定的抗衡,而 未来可能的爆料者也不会因为前车之鉴而噤若寒蝉。理解这点之后便很容易看出,保守派评论员戴维·布鲁克斯(David Brooks)在《纽约时报》专栏文章〈孤独的泄密者〉(“The Solitary Leaker”)中对斯诺登“背叛基本的信任合作”、“破坏社会纽带”的种种指控,实在是本末倒置,荒谬至极。
附:以下是漫画家赫尔伯特·布洛克(Herbert Block)50年代为《华盛顿邮报》创作的两幅关于“国家机密”的插画。版权属于赫尔·布洛克基金会(Herb Block Foundation)。
(1956年7月25日)“你知不知道——你忘了给这份打字机带的订购单加盖‘机密’戳?”
1
(1957年3月13日)“唉呀,我们肯定把这事儿搞砸了。现在给它盖个什么戳比较好——‘机密’还是‘顶级机密’?”
2


文章来源:http://goo.gl/C1ZLL

2013年6月15日星期六

彭博社:美情报局与数千公司互通数据 棱镜仅为冰山一角

national-security-agency-seal_610x407
彭博社今天发表署名迈克尔·莱利(Michael Riley)的文章称,美国NSA、CIA和FBI等情报机构与美国数千家私有企业保持着紧密的合作关系,它们会从这些企业获得敏感情报,同时也会向合作企业提供机密信息。以下是文章全文:
据四位熟悉内幕的消息人士称,成千上万家科技、金融和制造领域的公司与美国国家安全机构合作紧密,它们向后者提供敏感信息,作为回报它们会获得后者提供的机密情报。
这 些项目的参与公司都是可信赖的合作伙伴,它们的所作所为远远超出在美国国家安全局(NSA)从事电脑技术员工作的爱德华·斯诺登(Edward Snowden)所披露出来的那些内容。自从斯诺登本月披露NSA收集数百万美国居民的电话记录以及与谷歌等互联网企业合作监控外国人的计算机通信信息以 来,那些涉事的私有企业受到了公众密切的关注。
上述四位消息人士称,除了用户的私人通信信息外,许多互联网和通信公司自觉自愿地为美国情报组织提供额外的数据,例如设备规格。
软硬件制造商、银行、互联网安全服务商、卫星通信公司以及其它许多公司也参与了美国政府的这些项目。某些时候,这些项目所收集的信息不仅仅是出于自我保护,还被用来作为攻击手段,侵入竞争对手的计算机系统。
据上述四位消息人士中一位曾在美国政府及其合作企业都工作过的人透露,除NSA外,美国中央情报局(CIA)、联邦调查局(FBI)以及美国军方的情报机构也与上述公司保持合作,收集那些普通人看起来无害,但在美国情报人员或网络战部队看来非常有用的信息。
微软漏洞
据两位熟悉内幕的人士称,世界上最大的软件公司微软会向情报机构提前提供操作系统的漏洞信息,之后再发布修复补丁。这些信息可被用来保护美国政府的计算机,以及用来访问恐怖分子或军事对手的电脑系统。
据两位美国官员透露,微软等软件公司、互联网和安全企业提前提供的这些信息可以帮助政府好好利用这些出售到海外的软件的脆弱性。这两位不愿具名的消息人士表示,微软没有问、也不可能被告知政府将如何使用这些信息。
微软一位发言人弗兰克·肖(Frank Shaw)表示,微软会向多个合作机构提前提供漏洞信息,目的是让政府能够“尽早启动”风险评估和减少灾难带来的损失。
乐意合作
上 述四位消息人士之一透露,一些美国通信公司非常愿意向情报机构提供访问海外基础设施和通信数据的权利。而在美国本土,这样事情必须得到法官的批准才能进 行。在美国“外国情报监视法”(Foreign Intelligence Surveillance Act)的庇佑下,美国的通信公司可以不经监管,自愿地向情报机构提供信息。
情报机构和私有企业之间展开的这类广泛合作是非法的,它存在于 人们生活的方方面面,但只有很少一部分律师、企业主和间谍人员才会审慎地看待这个问题。一位熟悉情报机构和公司间协议内容的消息人士称,私有企业的高管们 乐于与政府合作,博得协助国防的美名,同时公司本身也会从中获益。
一位熟悉流程的人士表示,大多数协议都属于高度机密,公司只有少数高层能够访问这些信息。很多时候,这样的机密信息只有企业的CEO和间谍机构的负责人知晓,其他人根本无从得知。
“感谢他们”
曾 先后担任NSA和CIA一把手的迈克尔·海登(Michael Hayden)这样描述与合作公司间的关系:“如果我是情报机构负责与合作企业接洽的主管,当我的伙伴向我提供了对公共防卫非常有价值的信息时,我要以我 的方式感谢他们,让他们意识到自己的所作所为的必要性和有用性。”
海登补充道:“作为公司负责人你有义务做这样的事,很少有人会置身事外。”
根 据斯诺登披露的一张幻灯片显示,美国互联网公司与NSA“特别来源行动”(Special Source Operations)小组之间有一个命名为Prism(棱镜)的秘密计划,该计划专门收集海外侦查目标的电子邮件、视频以及其它数据信息。每家互联网企 业监控的数据不同,具体类别由一个秘密的评委会决定。
由于全球的信息呈现爆炸式增长,以及更多地通过由美国公司提供的交换机/路由器、线缆及其它网络设备传输,美国情报机构越来越依赖与私有企业间的这种合作关系。
设备规格
除了私人通信外,支撑互联网运行的设备的规格信息也在美国政府及其合作企业的收集之列。理论上,这些设备规格信息与私人通信信息之间没多大联系,不属于情报机构关心的范畴。但是,这些信息对企业、美国执法官员和军方很重要。
接洽官员
如果必要,与情报机构合作的公司高管,会被授予可以免除因转移数据而遭受的民事诉讼的豁免权。情报机构还会定期向公司接洽人更新他们将如何使用收集到的数据信息。
上述四位熟悉内幕的消息人士之一称,英特尔旗下从事互联网安全软件业务的McAfee部门,会定期与NSA、FBI以及CIA合作。McAfee是美国情报机构一个非常有价值的合作伙伴,因为它生产的互联网软件可以掌握大量的恶意互联网流量,包括来自外国的间谍行动等。
该 消息人士表示,美国情报机构与McAfee的合作过程可能是:先与McAfee CEO接洽,后者会指派特别的员工来负责向调查员提供数据。他还表示,美国公众如果得知政府居然要寻求这么多帮助,一定会大吃一惊。McAfee的防火墙 可以收集使用正版服务器从事间谍活动的数据,从而找出攻击发起的位置。此外,McAfee还熟知全球信息网络的体系结构,这些信息对合作情报机构非常有 用。
企业高管获关照
McAfee全球首席技术执行官迈克尔·菲(Michael Fey)表示,McAfee的数据和相关分析并不涉及个人信息。他在一份声明中写道:“我们不与政府机构合作伙伴分享任何类型的个人信息。McAfee的 任务是向政府机构提供安全技术、教育信息和威胁情报。这种情报包括有关新威胁、网络攻击模式、矢量活动的趋势数据,以及对软件系统漏洞和黑客组织活动真实 性的分析。”
上述知情人士透露,作为交换,美国安全机构会给予合作企业高管特别关照和相关信息,以维持这种合作关系。有时候,合作企业还会提前获得相关威胁的警告,这些威胁可能会影响他们的营收,如大规模网络攻击以及幕后操纵者等信息。
据 一位熟悉美国政府调查的知情人士透露,2010年,在谷歌遭受中国黑客攻击后,谷歌联合创始人塞吉·布林(Sergey Brin)获得了一份高度机密的政府情报,称此次攻击的主使是中国军方下属秘密机构。根据斯诺登透露的信息,作为全球第一大搜索引擎,谷歌当时已经参与 “棱镜”计划一年有余。
谷歌CEO拉里·佩奇(Larry Page)本月7日在一份博文中写道,在斯诺登曝料之前,他从未听说过“棱镜”计划,而谷歌并不允许美国政府直接接入其服务器,或是数据中心的“后门”系 统。佩奇称,谷歌只有在不违反法律的情况下,才向政府提供用户数据。谷歌发言人莱斯利·米勒(Leslie Miller)暂未对这一报道发表评论。
搜集设备元数据
斯诺登提供的信息还曝光了一个名为的“Blarney”秘密计划。根据《华盛顿邮报》对“Blarney”计划的描述,美国安全机构会搜集一些电脑和设备的元数据(Metadata),这些电脑和设备被用于通过主数据线路发送电子邮件,浏览互联网信息。
全 球数以百万计的设备都在使用元数据,而美国情报机构则可以利用此类信息,向这些电脑或手机进行渗透,对用户实施监控。元数据还包括操作系统、浏览器和 Java软件版本。澳大利亚大型电信运营商Telstra Corp前首席信息官格伦·奇斯霍尔姆(Glenn Chisholm)说:“这是一种具有高度进攻性的数据”。他这样讲,其实是在与保护而非渗透电脑的防御性信息做对比。
据《华盛顿邮报》报道,斯诺登称“Blarney”计划的目标是“接入和获取外国情报”。目前尚不清楚美国互联网服务提供商是否按照“Blarney”计划,向NSA提供了用户信息,如果确有此事,他们是否得到了法官批准。
NSA前法律总顾问斯图尔特·贝克(Stewart Baker)表示,如果元数据涉及两台碰巧穿越美国光缆的境外电脑之间的通讯,“那么相比正在逐一筛查的通信,前者并不需要太多的法律监督就可以获取。”
跟不上科技潮流
雅 各布·奥尔库特(Jacob Olcott)表示,负责监督美国情报机关的议员们,或许并不清楚NSA所搜集的部分元数据的重要性。奥尔库特是美国参议院商业委员会主席约翰·洛克菲勒 (John D. Rockefeller IV)的前任网络安全顾问,现为安全风险管理公司Good Harbor Security Risk Management高层。
他说:“这使得议员对此类问题的监察变得非常困难。现如今,科技和技术政策瞬息万变,大多数民选议员及其助手的 背景和专长已经无法跟上这种潮流。”知情人士透露,虽然美国情报机构会向合作企业提供颇具吸引力的奖励,但许多高管参与此类计划主要是出于爱国情操,或是 觉得他们是在保护国家安全。
美国电信运营商、互联网公司、电力公司和其他企业,向美国情报机构提供了他们系统的基础架构或相关设备的细节,以便情报机构可以分析潜在漏洞。美国加州数据安全公司Cylance首席安全官奇斯霍尔姆说:“政府想要知道国家重要基础设施的情况,这是自然而然的举动。”
不承担法律责任
即 便是一些高度防御性系统,也会给用户隐私带来预想不到的后果。“Einstein 3”是最早由NSA制订的一个投入巨大的计划,旨在保护政府系统免遭黑客攻击。目前,该项目已经公诸于众,目前正处于安装阶段,它将会对每年发送至政府电 脑的数十亿封电子邮件进行仔细分析,以确定它们是否包含间谍工具或恶意软件。据知情人士透露,在某些情况下,“Einstein 3”计划还可能使电子邮件的私密内容曝光。
据悉,在AT&T、Verizon Communications、Sprint Nextel、Level 3 Communications、CenturyLink等美国五家知名互联网同意在其网络中安装“Einstein 3”系统之前,有几家还要求政府必须保证,他们不会因违反美国反窃听法律而承担责任,结果他们收到了一封有美国总检察长亲笔签名的书信,信中称曝光此类信 息并不符合美国法律对窃听的定义,同时给予这些公司以民事诉讼的豁免权。
AT&T发言人马克·西格尔(Mark Siegel)和Verizon发言人爱德华·麦克法登(Edward McFadden)均对这一报道不愿置评,而Sprint发言人斯科特·斯洛特(Scott Sloat)和Level 3发言人莫妮卡·马丁尼斯(Monica Martinez)则暂未对此发表评论。
Centurylink发言人琳达·约翰逊(Linda Johnson)表示,该公司参与了“网络安全增强服务”(Enhanced Cybersecurity Services)和“入侵预防安全服务”(Intrusion Prevention Security Services)等两个计划,后者还包括“Einstein 3”项目。这两个计划都由美国国土安全部直接负责。她说,除此之外,“Centurylink不会对国家安全相关事宜发表评论。”
————-
U.S. Agencies Said to Swap Data With Thousands of Firms
By Michael Riley – Jun 15, 2013 12:01 PM CT
Thousands of technology, finance and manufacturing companies are working closely with U.S. national security agencies, providing sensitive information and in return receiving benefits that include access to classified intelligence, four people familiar with the process said.
These programs, whose participants are known as trusted partners, extend far beyond what was revealed by Edward Snowden, a computer technician who did work for the National Security Agency. The role of private companies has come under intense scrutiny since his disclosure this month that the NSA is collecting millions of U.S. residents’ telephone records and the computer communications of foreigners from Google Inc (GOOG). and other Internet companies under court order.
Many of these same Internet and telecommunications companies voluntarily provide U.S. intelligence organizations with additional data, such as equipment specifications, that don’t involve private communications of their customers, the four people said.
Makers of hardware and software, banks, Internet security providers, satellite telecommunications companies and many other companies also participate in the government programs. In some cases, the information gathered may be used not just to defend the nation but to help infiltrate computers of its adversaries.
Along with the NSA, the Central Intelligence Agency (0112917D), the Federal Bureau of Investigation and branches of the U.S. military have agreements with such companies to gather data that might seem innocuous but could be highly useful in the hands of U.S. intelligence or cyber warfare units, according to the people, who have either worked for the government or are in companies that have these accords.
Microsoft Bugs
Microsoft Corp. (MSFT), the world’s largest software company, provides intelligence agencies with information about bugs in its popular software before it publicly releases a fix, according to two people familiar with the process. That information can be used to protect government computers and to access the computers of terrorists or military foes.
Redmond, Washington-based Microsoft (MSFT) and other software or Internet security companies have been aware that this type of early alert allowed the U.S. to exploit vulnerabilities in software sold to foreign governments, according to two U.S. officials. Microsoft doesn’t ask and can’t be told how the government uses such tip-offs, said the officials, who asked not to be identified because the matter is confidential.
Frank Shaw, a spokesman for Microsoft, said those releases occur in cooperation with multiple agencies and are designed to give government “an early start” on risk assessment and mitigation.
In an e-mailed statement, Shaw said there are “several programs” through which such information is passed to the government, and named two which are public, run by Microsoft and for defensive purposes.
Willing Cooperation
Some U.S. telecommunications companies willingly provide intelligence agencies with access to facilities and data offshore that would require a judge’s order if it were done in the U.S., one of the four people said.
In these cases, no oversight is necessary under the Foreign Intelligence Surveillance Act, and companies are providing the information voluntarily.
The extensive cooperation between commercial companies and intelligence agencies is legal and reaches deeply into many aspects of everyday life, though little of it is scrutinized by more than a small number of lawyers, company leaders and spies. Company executives are motivated by a desire to help the national defense as well as to help their own companies, said the people, who are familiar with the agreements.
Most of the arrangements are so sensitive that only a handful of people in a company know of them, and they are sometimes brokered directly between chief executive officers and the heads of the U.S.’s major spy agencies, the people familiar with those programs said.
‘Thank Them’
Michael Hayden, who formerly directed the National Security Agency and the CIA, described the attention paid to important company partners: “If I were the director and had a relationship with a company who was doing things that were not just directed by law but were also valuable to the defense of the Republic, I would go out of my way to thank them and give them a sense as to why this is necessary and useful.”
“You would keep it closely held within the company and there would be very few cleared individuals,” Hayden said.
Cooperation between nine U.S. Internet companies and the NSA’s Special Source Operations unit came to light along with a secret program called Prism. According to a slide deck provided by Snowden, the program gathers e-mails, videos, and other private data of foreign surveillance targets through arrangements that vary by company, overseen by a secret panel of judges.
U.S. intelligence agencies have grown far more dependent on such arrangements as the flow of much of the world’s information has grown exponentially through switches, cables and other network equipment maintained by U.S. companies.
Equipment Specs
In addition to private communications, information about equipment specifications and data needed for the Internet to work — much of which isn’t subject to oversight because it doesn’t involve private communications — is valuable to intelligence, U.S. law-enforcement officials and the military.
Typically, a key executive at a company and a small number of technical people cooperate with different agencies and sometimes multiple units within an agency, according to the four people who described the arrangements.
Committing Officer
If necessary, a company executive, known as a “committing officer,” is given documents that guarantee immunity from civil actions resulting from the transfer of data. The companies are provided with regular updates, which may include the broad parameters of how that information is used.
Intel Corp. (INTC)’s McAfee unit, which makes Internet security software, regularly cooperates with the NSA, FBI and the CIA, for example, and is a valuable partner because of its broad view of malicious Internet traffic, including espionage operations by foreign powers, according to one of the four people, who is familiar with the arrangement.
Such a relationship would start with an approach to McAfee’s chief executive, who would then clear specific individuals to work with investigators or provide the requested data, the person said. The public would be surprised at how much help the government seeks, the person said.
McAfee firewalls collect information on hackers who use legitimate servers to do their work, and the company data can be used to pinpoint where attacks begin. The company also has knowledge of the architecture of information networks worldwide, which may be useful to spy agencies who tap into them, the person said.
McAfee’s Data
McAfee (MFE)’s data and analysis doesn’t include information on individuals, said Michael Fey, the company’s worldwide chief technology officer.
“We do not share any type of personal information with our government agency partners,” Fey said in an e-mailed statement. “McAfee’s function is to provide security technology, education, and threat intelligence to governments. This threat intelligence includes trending data on emerging new threats, cyber-attack patterns and vector activity, as well as analysis on the integrity of software, system vulnerabilities, and hacker group activity.”
In exchange, leaders of companies are showered with attention and information by the agencies to help maintain the relationship, the person said.
In other cases, companies are given quick warnings about threats that could affect their bottom line, including serious Internet attacks and who is behind them.
China’s Military
Following an attack on his company by Chinese hackers in 2010, Sergey Brin, Google’s co-founder, was provided with highly sensitive government intelligence linking the attack to a specific unit of the People’s Liberation Army, China’s military, according to one of the people, who is familiar with the government’s investigation. Brin was given a temporary classified clearance to sit in on the briefing, the person said.
According to information provided by Snowden, Google, owner of the world’s most popular search engine, had at that point been a Prism participant for more than a year.
Google CEO Larry Page said in a blog posting June 7 that he hadn’t heard of a program called Prism until after Snowden’s disclosures and that the Mountain View, California-based company didn’t allow the U.S. government direct access to its servers or some back-door to its data centers. He said Google provides user data to governments “only in accordance with the law.”
Leslie Miller, a spokeswoman for Google, didn’t provide an immediate response June 13.
The information provided by Snowden also exposed a secret NSA program known as Blarney. As the program was described in the Washington Post (WPO), the agency gathers metadata on computers and devices that are used to send e-mails or browse the Internet through principal data routes, known as a backbone.
Metadata
That metadata includes which version of the operating system, browser and Java software are being used on millions of devices around the world, information that U.S. spy agencies could use to infiltrate those computers or phones and spy on their users.
“It’s highly offensive information,” said Glenn Chisholm, the former chief information officer for Telstra Corp (TLS)., one of Australia’s largest telecommunications companies, contrasting it to defensive information used to protect computers rather than infiltrate them.
According to Snowden’s information, Blarney’s purpose is “to gain access and exploit foreign intelligence,” the Post said.
It’s unclear whether U.S. Internet service providers gave information to the NSA as part of Blarney, and if so, whether the transfer of that data required a judge’s order.
Less Scrutiny
Stewart Baker, former general counsel for the NSA, said if metadata involved communications between two foreign computers that just happened to be crossing a U.S. fiber optic cable “then the likelihood is it would demand less legal scrutiny than when communications are being extracted one by one.”
Lawmakers who oversee U.S. intelligence agencies may not understand the significance of some of the metadata being collected, said Jacob Olcott, a former cybersecurity assistant for Senator John D. Rockefeller IV of West Virginia, the Democratic chairman of the Senate Commerce Committee.
“That’s what makes this issue of oversight so challenging,” said Olcott, now a principal at Good Harbor Security Risk Management in Washington. “You have a situation where the technology and technical policy is far outpacing the background and expertise of most elected members of Congress or their staffs.”
While companies are offered powerful inducements to cooperate with U.S. intelligence, many executives are motivated by patriotism or a sense they are defending national security, the people familiar with the trusted partner programs said.
Einstein 3
U.S telecommunications, Internet, power companies and others provide U.S. intelligence agencies with details of their systems’ architecture or equipment schematics so the agencies can analyze potential vulnerabilities.
“It’s natural behavior for governments to want to know about the country’s critical infrastructure,” said Chisholm, chief security officer at Irvine, California-based Cylance Inc.
Even strictly defensive systems can have unintended consequences for privacy. Einstein 3, a costly program originally developed by the NSA, is meant to protect government systems from hackers. The program, which has been made public and is being installed, will closely analyze the billions of e-mails sent to government computers every year to see if they contain spy tools or malicious software.
Einstein 3 could also expose the private content of the e-mails under certain circumstances, according to a person familiar with the system, who asked not to be named because he wasn’t authorized to discuss the matter.
AT&T, Verizon
Before they agreed to install the system on their networks, some of the five major Internet companies — AT&T Inc. (T), Verizon Communications Inc (VZ)., Sprint Nextel Corp. (S), Level 3 Communications Inc (LVLT). and CenturyLink Inc (CTL). — asked for guarantees that they wouldn’t be held liable under U.S. wiretap laws. Those companies that asked received a letter signed by the U.S. attorney general indicating such exposure didn’t meet the legal definition of a wiretap and granting them immunity from civil lawsuits, the person said.
Mark Siegel, a spokesman for Dallas-based AT&T, the nation’s biggest phone carrier, declined to comment. Edward McFadden, a spokesman for New York-based Verizon, the second-largest phone company, declined to comment.
Scott Sloat, a spokesman for Overland Park, Kansas-based Sprint, and Monica Martinez, a spokeswoman for Broomfield, Colorado-based Level 3, didn’t immediately respond to requests for comment.
Linda Johnson, a spokeswoman for Centurylink, formerly Qwest Corp., said her Monroe, Louisiana-based company participates in the Enhanced Cybersecurity Services program and the Intrusion Prevention Security Services program, which includes Einstein 3. Both programs are managed by the U.S. Department of Homeland Security.
Beyond that, she said, “CenturyLink does not comment on matters pertaining to national security.”
To contact the reporter on this story: Michael Riley in Washington at michaelriley@bloomberg.net
To contact the editor responsible for this story: Michael Hytha at mhytha@bloomberg.net

http://goo.gl/UlBgd