Tuesday, June 15, 2010

DOJ's surveillance reporting failure

In both 2004, and 2009, the US Department of Justice provided Congress with a "document dump", covering 5 years of Pen Register and Trap & Trace surveillance reports. Although the law clearly requires the Attorney General to submit annual reports to Congress, DOJ has not done so, nor has it provided any reason for its repeated failure to submit the reports to Congress in a timely manner, as the law requires.

Professor Paul Schwartz, who first highlighted DOJ's pen register reporting deficiencies in a law review article, has argued that the lack of timely reporting creates "blank spaces on the map of telecommunications surveillance law."

In his 2008 article, Schwartz stated:
[T]he reports do not appear to have been made annually, but as one document dump with five years of reports in November 2004. The reports also fail to detail all of the information that the Pen Register Act requires to be shared with Congress.
The cover letter for the 2004 document dump to Congress can be seen embeded below and the yearly reports (later obtained through a FOIA by the Electronic Frontier Foundation) can be viewed here: 1999, 2000, 2001, 2002, 2003,



Unfortunately, it appears that after the 2004 document dump, DOJ went back to its old ways, and stopped providing the reports to Congress. As a result, in April 2009, the Electronic Privacy Information Center wrote a letter to Senator Leahy, to ask him to look into the issue.

There is no indication that the DOJ provided annual pen register reports to Congress for 2004, 2005, 2006, 2007, or 2008.19 This failure would demonstrate ongoing, repeated breaches of the DOJ's statutory obligations to inform the public and the Congress about the use of electronic surveillance authority....

We request that you ask the Attorney General to make public pen register and trap and trace reports from 2004 through the present, and to publicly disclose all future reports as a matter of course. This might be accomplished by requiring the DOJ to submit the annual pen register reports to the Administrative Office of the U.S. Courts, which has a proven track record of reliably collecting and publicly disseminating similar statistics regarding wiretap orders.

Earlier this year, I obtained (via a FOIA request) copies of the reports for the years 2004-2008. I also obtained the cover letter that DOJ sent to members of Congress in October of 2009, attached to the reports. The wording of the October 2009 letter is practically identical to the letter that accompanied the 2004 document dump, suggesting that DOJ failed to comply with the annual reporting requirements in 2005, 2006, 2007 and 2008.



Based on 10 years of repeated failures, it seems clear that the Department of Justice is unable to supply Congress with annual reports for pen register and trap & trace surveillance. As such, I think it is time for Congress to take a serious look at this problem, and consider shifting the responsibility for the reporting to the Administrative Office of the U.S. Courts, which has a proven track record of reliably collecting and publicly disseminating similar statistics regarding wiretap orders.

In a forthcoming law review article, I dig through the currently published surveillance statistics, and find many of them to be woefully lacking. I also propose several ways that Congress could overhaul the reporting requirements. Hopefully, if Congress does look into this issue, they will expand the scope of their inquiry to cover all surveillance reporting, and not just the pen register reports.

While my article is still in very rough shape, I've extracted the section on surveillance statistics, and included it here. I'd love feedback.

Tuesday, April 20, 2010

In Praise of Google

Regular readers of this blog will know that I have long been a vocal critic of Google. Today, in response to the news that the company has published stats on the number of requests it receives from governments for private user data, I have nothing but praise for the company.

Until this announcement, the privacy community in the United States had just four data points regarding the scale of government requests to Internet and telecommunications providers: A 2006 New York Times article revealing that AOL was getting 1000 requests regarding criminal and civil cases per month; a 2009 Newsweek article revealing that Facebook was getting 10-20 police requests per day; a 2009 letter from Verizon's general counsel in response to a FOIA request that I filed, revealing that the company gets "tens of thousands of requests for customer records and other customer information from law enforcement" per year; and Sprint's 2009 disclosure at a surveillance industry conference that it let law enforcement agencies initiate 8 million GPS pings as part of "thousands" of requests for its customers' location data.

Google's new Government Requests Tool quite simply blows away the competition, in terms sharing useful information about governments' ever growing appetite for individuals' private data, and in particular, per-country level transparency.

Just a few weeks ago, one of Microsoft's lawyers told Wired News that "We would like to see more transparency across the industry ... But no one company wants to stick its head up to talk about numbers."

It seems that at least one company has now bravely stuck its head up by disclosing these numbers. Hopefully, the other big Internet firms will see the positive press that Google received from this move, and voluntarily follow Google's lead.

What other data do we need

Hopefully, Google will share even more detailed data on government requests in the future. In particular, I'd like to know the following:
  1. How many requests from the government were under exigent or emergency circumstances, in which there was no accompanying subpoena,search warrant or other court order? In such situations, the company is permitted to voluntarily disclose data to the government, but is under no legal obligation to do so. Thus, it is also important to know how many times the company refused these requests.
  2. Of the government requests that Google received, how many were subpoenas, search warrants, 2703(d) orders, "hybrid" location requests, and electronic intercept/wiretap orders?
  3. For each of these categories of government requests, how many did the company comply, and how many did the company go to court to fight the request?
  4. For each of these categories of requests, how many (or a %) were by local, state or federal agencies?
  5. For each of these categories of requests, what kind of information was being asked for? (e.g. 15% of requests were for search records, 50% were for email, 20% for GPS location info, etc).
  6. What is the median and mean age of the customer information requested by and disclosed to law enforcement? (e.g. Are most requests for private user data that is a week old, or 200 days old?)
Making sense of the numbers

Let us imagine that over the next few months, Microsoft, Yahoo, Facebook, Apple, Skype, Comcast, AT&T, Verizon, Sprint and T-Mobile follow Google's lead and publish these stats. While this'll be a great source of information for researchers, for those in Congress who are considering an update to the Electronic Communications Privacy Act, and for concerned citizens wishing to observe the rate of transformation of this country into a surveillance state, these statistics won't actually be that useful to privacy conscious consumers wishing to make a wise choice in picking a service provider.

As a hypothetical example, if Yahoo receives 6000 requests for customer email data per year and Google receives 3000 requests, what does that mean? How should consumers interpret it if they wish to vote with their feet, and pick an ISP that will best protect their privacy?

Unfortunately, the number of requests a company receives doesn't really reveal how much the company values user privacy -- it merely reveals how often government agencies are willing to type up a subpoena and fax it off. Furthermore, while companies may be willing to fight unreasonable requests, if the request is lawful, even the most pro-privacy company can't do much to protect its customers.

At the end of the day, what matters most is the privacy enhancing technologies that companies build into their products -- such as minimal/no data retention and the use of encryption with a key only known to the user -- which effectively neutralize the ability of governments to compel service providers into violating their customers' privacy.

Transparency is great -- but meaningful competition on privacy will come through privacy enhancing technologies, baked into products, enabled by default.

Disclaimer: These are my own personal views, and do not reflect those of any other individual or organization with which I am affiliated.

Wednesday, March 24, 2010

New paper

My latest paper, co-authored with Sid Stamm, is now online:

Certified Lies: Detecting and Defeating Government Interception Attacks Against SSL

The abstract:
This paper introduces a new attack, the compelled certificate creation attack, in which government agencies compel a certificate authority to issue false SSL certificates that are then used by intelligence agencies to covertly intercept and hijack individuals' secure Web-based communications. We reveal alarming evidence that suggests that this attack is in active use. Finally, we introduce a lightweight browser add-on that detects and thwarts such attacks.

The first paragraph describing the threat:
A pro-democracy dissident in China connects to a secure web forum hosted on servers outside the country. Relying on the training she received from foreign human rights groups, she makes certain to look for the SSL encryption lock icon in her web browser, and only after determining that the connection is secure does she enter her login credentials and then begin to upload materials to be shared with her colleagues. However, unknown to the activist, the Chinese government is able to covertly intercept SSL encrypted connections. Agents from the state security apparatus soon arrive at her residence, leading to her arrest, detention and violent interrogation. While this scenario is fictitious, the vulnerability is not.


We are hoping to release the CertLock browser add-on described in the paper in the next few weeks. In the mean time, we welcome any feedback on our paper.

In general, the SSL/Certificate Authority system is horribly broken, and it needs to be fixed. However, broken SSL is still better than no SSL -- which is why the big name email providers, social networks and any other site that handles sensitive data needs to step up and protect their users.