> That said, "US selectors" shouldn't return the results that they do in the first place.
Determining if a "selector" is tied to a U.S. person is actually a very subtle and very hard problem.
Let's take a phone number +1 (212) 555-1234
Is this a US selector? It's a selector for a phone in the US, but that's not the same thing as a phone number tied to a US citizen. Let's say I'm following a senior North African pirate with a Maltese mobile +356 2010-1234 and he calls/is called by my number above?
- Should I follow it? Or is it absolutely off limits for me because it happens to be a U.S. number?
- How do I determine if it's tied to a U.S. person?
- What if it's a shared number between a group of associates, all of whom are not U.S. persons except for one?
- Is that number off limits now?
- If it is a U.S. person what should I do with it?
- Pretend it doesn't exist? Turn it over to U.S. Federal law enforcement? Who should I turn it over to? DEA? FBI? ATF? DHS? The Coast Guard? U.S. Customs and Border Patrol?
It's actually a significant intelligence task to figure this out.
Did the possibility ever cross your mind that the fake accounts and users are simply an attempt by a very small fringe group to bulk up their numbers and look like a more legitimate political concern?
Outside of magical unicorns, what kind of unicorn should guard things? I'm afraid automated systems don't offer either the coverage or the flexibility to provide what you think should be provided.
> Yes, but you don't copy all communications to try and find the astonishingly small number from the most closed-off country in the world.
What would your collection proposal be then?
You can't determine data of interest until you have sufficient data to determine if it's of interest in the first place. Even the NSA doesn't have an Oracle computer that can look into the future and figure out what vanishingly small percentage of communications are just the ones they should be interested in. If they did, they could also solve the halting problem and rewrite the history of computer science and time-travel.
Remember, the standard the NSA is held up to is that it should not only be following known bad people who are/might be doing bad things, but to ferret out the unknown bad people. Every time there's a Boston or similar, everybody goes and climbs all over the NSA for "not knowing about these guys"
You can't do that until you have a sufficiently large enough collection of unevaluated data to start looking through.
I'm not saying it's right or wrong, only that it's the reality of the task spy agencies have before them.
> He just bought it retail. There was a great interview of Kim Jong-Il's sushi chef awhile back, the way he gets ingredients is the chef makes trips abroad to foreign markets and buys whatever he needs from wherever, presumably paying cash. If you're willing to pay the price premium and take care of packing and shipping yourself, you can buy anything you want to, legally, without anyone else knowing.
Right. Most nefarious actors just buy most of their stuff retail. Figuring that out, from whom, what was purchased etc. and if it violates some sanctions regime is one of the things the NSA might participate in, handing off the findings to the State Department of the Commerce Department or whoever for action. The action being that participating companies would not be allowed to do business in the U.S. and would be monitored for further sanctions violations in case other U.S. involved companies want to do business with the retail outfit that sold the whiskey. No big deal if you're Mom & Pop liquor store in Italy with no U.S. involvement. But who knows? It could mean that your supplier is a U.S. based company and may not be allowed to supply you any more in the future.
In practice nobody gives a shit about a few cases of whiskey, but the same practice might be used for large shipments or for items that are undesirable for North Korea to obtain.
> Really? why should anyone trust in anything coming from the NSA when you are systematically lying again and again? why should we listen to anything you say when historically, part of your strategy is to try to influence the PoV of society || specifics groups?
OP is not the NSA. OP was an employee for a couple years and can only comment about what he specifically knows about, just like anybody. Take what he says with that context.
(ex-)Employees can write about anything, but if it involves IC related topics, they have to submit to a review before publication. All those various books about life in the Spy world or Special Forces etc. all went through similar reviews.
> There are articles suggesting this is happening many thousands of times per year - shouldn't each of these 'regular employees' be put on trial? They have committed serious crimes.
Quite often they are. The minimum penalty is loss of clearance and job (which is a career death sentence in the IC), and depending on what they did and if the agency feels like it's a good expenditure of resources, some kind of criminal prosecution may be involved.
e.g.
- Employee sees if his own cell phone number has been collected (violates rules regarding looking up U.S. persons): probably a firing, but not worth criminal prosecution
- Employee starts a side business and starts monitoring communications of his competitors to get a leg up, probably a firing + prison time.
> Thank you so much, kind American intelligence guy, for having the grace to not look at USA citizens emails, all the while not even mentioning foreigners, who should apparently just lie down and take it.
Foreigners don't just "take it", they have their own nation's intelligence apparatus collecting against their foreigners. Let me know when there are mass protests against foreign collection in the rest of the world and maybe then your complaint will make some kind of sense. Until then it's just bitter complaining about something you knew all along anyway. It's kind of the point of Intelligence.
> Why is a distinction made between US and non-US people?
Because, at least in the U.S., there's a distinction between IC and LE entities -- this is not a distinction shared by most countries. LE deals with domestic events and U.S. people, while IC deals with non-domestic actors and locations. There's a bit of overlap, for example, a U.S. citizen doing bad things in a foreign country gets a bit of both, or a foreign national in the U.S. But that's generally where the line is drawn. U.S. law doesn't apply outside of the U.S. and it shouldn't. Can you imagine the world if the U.S. suddenly decided that France had to apply by all U.S. laws including the U.S. Constitution? If people think New Zealand cooperating on
> What makes me a potential criminal, and Mr. Smith not?
The reverse is true of U.S. citizens w/r to other country's intelligence apparatus as well.
IC agencies generally aren't looking for criminals...meaning they aren't looking for people who broke U.S. law. They're basically looking for threats to U.S. soil, citizens and concerns. LE agencies look for law breakers. That's one of the reasons why the trials at GTMO are such a mess, guys were wrapped up and sent off to Cuba for interrogation based on "Intelligence" but not using information collected as part of a criminal prosecution. IC and LE really do operate under very different methods (at least in the U.S.).
> I am a foreign national, I and my company uses services provided by a US company (email etc.), and this gives right to you guys to collect and ready my emails?
Yes. Look at your question from a different angle, under what legal regime is the U.S. not allowed to do so? Or the contrapositive, what are you doing to prevent your country from spying on U.S. Citizens?
> If an employee had a contrarian opinion to the NSA would it be declassified like this one?
Yes. You can check Amazon yourself for books by former NSA employees who don't side with the Agency. Their books were all reviewed by the NSA for classified information, but not for dissenting opinions.
> Do you think Snowdon's revelations had any beneficial impact, or is your view of them entirely negative?
Disappointingly no. At least in my circles, Snowden is not mentioned in polite terms. The likely outcome will be no change in NSA collections or capabilities, but automation in system administration, better collection of auditable information on IC employees and more compartmentalizing of the activities even further.
> My question to the OP: even if you believe that at the moment abuses are rare and that your colleagues are trustworthy and law-abiding, does the capability and level of information concern you in terms of the potential for future abuse it enables?
I'll toss in my answer too. I think it is serious cause for concern. But the kind of work the IC does is hard and I'd say impossible to get right. Anybody who thinks the kinds of work that most of us do in our day-to-day businesses is hard have no idea how really difficult the industry is. In a normal business, if you get things wrong you might get sued or shut down. In the Spy industry? countries might fall, nukes might loose and people might die. Doing that kind of work in balance with people's rights, or at least not negatively impacting truly innocent people is among the hardest things to do in the world.
> "All that is necessary for the triumph of evil is that good men do nothing."
Doing nothing would be for the U.S. to not spy at all, which is a sentiment shared by many in this forum. And then bad things would certainly happen for the U.S. because no other country would do the same. Sometimes doing the right thing really involves doing hard things that don't feel good. I won't make any apologies for it and nor should the OP. The kind of work that the IC and the military does, make no mistake about it, is ugly ugly work. It is very important though that this public debate be held often, and constantly. The IC/Military construct is like a huge guard dog. You want it a bit mean and angry, but you don't want it to bite you, the mailman or the neighborhood kids...it's not so bad if it goes after the occasional solicitor or burgler. So it's very important that you keep a constant eye on it and keep it in check. Because it will dig up your yard, chew up the sofa and otherwise misbehave.
> Anyone who defends the NSA on the grounds that it only targets those who are worthy of targeting needs to convince me that another COINTELPRO will never happen. I would actually welcome such an argument, since it would make me feel a whole lot better about this.
You raise a very good point. I don't think there are many in the IC who would have a problem with more (and better) oversight...it helps them feel more legitimacy in what they're doing. All that being said, assume that there will be another COINTELPRO or similar. It sucks, but to be perfectly honest with you, you aren't important enough to convince one way or the other about it or about approving of the various collection programs the NSA is running. If half of the comments here are to be taken at face value, almost nobody on HN knows enough about the issues involved to be consulted or for their opinion to be considered. I'll draw a parallel here to the outcry over technology centered court cases or software patents, an opinion often given here is that engineers or software experts should be involved in deciding those cases because the layman doesn't know enough about it to have an informed opinion. It's just as true with IC issues. What's troubling is that oversight is via Congress, who until the last election were likely laypeople themselves. So the expertise to properly evaluate, oversee and monitor what's going on simply isn't there.
> This reads like it was penned by someone who's never heard of the Stanford Prison experiment or Milgram's research...
You bring up good points. One of the issues with the IC is one of internal monitoring (as we're all now seeing). Who watches the watchers? There's notionally a number of very serious laws, or committees and counter-X professionals who are supposed to be doing this, but to be honest. Once you're cleared and stuck on a project, there's really very little day-to-day oversight of any kind. I personally would welcome a higher level of scrutiny, but I think the equation of "spend manpower watching watchers" vs. "spend manpower looking for bad guys out in the world" has, and will continue to, balance on the later.
> If you'd never heard of parallel construction before today, that seems to powerfully undermine your credibility.
He only worked there for two years on a single program. I challenge anybody here who works for any organization larger than 3 people to have perfect knowledge of every single thing their organization is doing. Unless you work on the bits that interface with the LE community you'd probably never have had opportunity to know anything about it. I bet he also doesn't know the details of companies the NSA contracts to do their plumbing or handle their trash.
> The NSA has a history of sharing intelligence with LE, to state that the NSA is not a LE agency is extremely misleading, if not an outright lie.
I don't think you understand what a LE entity is, the powers and limitations that LE organizations operate under or how they differ from IC organizations. Saying the NSA is LE because they cooperate with LE is like saying the Department of Agriculture or Labor is an LE agency because they sometimes have to cooperate with LE.
> It's good to hear that many NSA employees take the police/military distinction seriously, but we know for a fact that some higher-ups don't...
This is true, and it's particularly vexing to work in the IC and have senior officials asking you to participate in outright illegal activities. It doesn't happen often, but I've seen both people ruin their careers saying no and those that want to keep their job and say yes. It's usually under the auspices of "helping out to stop bad things", and it's very hard to say no when activities are couched that way...despite very many of the people on here talking publicly about their very righteous and moral high ground, placed in the same position, the vast majority of HN users would want to stop bad things from happening even if it meant crossing the line a bit here or there. Because, honestly, if you choice is help stop innocents from getting killed vs. sit on your hands because of some futzy law someplace that ties your hands, most of us would feel like we'd rather take the immediate action to stop the bad guys. "Mission Expediency" is the word of the day when it comes to these matters.
> No offense to OP, but this reads like propaganda to me.
I can confirm that this represents the mindset of most of the people I've worked with in the IC. It does take a certain kind of personality to sign-up and go through all the hassles involved with getting employed in the IC and that self-selection seems to attract a certain kind of personality type.
> But I wouldn't be surprised if there was some sort of concerted effort by the NSA to encourage a dialogue with hackers on platforms like HN.
There really isn't, other than to not discuss classified information. Keeping track of what's classified and not when you spend near a third of your life and half of your waking hours dealing with only classified things is complex enough that most people just don't engage with the "unclean" public.
> What I'd be more interested in is how much this issue is being discussed internally. If these discussions are allowed, or even surreptitiously encouraged, then I'd take that as a possible internal propaganda push, subtle as it may be.
Discussions about these issues, in the way that they're being discussed here, are not terribly common. The milieu of working in the IC just doesn't lend itself to these kinds of topics, in these kinds of ways, as focuses of conversation. Mostly what's discussed is the lines you aren't supposed to cross and the penalties for crossing them. But more often then not, casual conversation is about anything other than IC topics. After a hard day of spying, you really want to just engage in something else.
Bizarrely, discussing Snowden might be tricky inside of the IC because you might discuss something that was leaked that you technically don't have a need-to-know for. So specific cases like this are not often serious topics of conversation.
There's lots of condemnation of the poster, and the NSA practices and some of the murkier parts of this article. I thought I'd tip in with some explanations as possible while staying outside of anything classified or naughty.
- "It's compartmentalized enough that the individual actors can justify their actions by the assumed competence and benevolence of the others."
It's compartmentalized a bit more than the OP lets on for mostly security/separation of concerns/need-to-know reasons. For example, a Air Force analyst who is cleared to view TS//SI material won't have access to the NSA systems directly. Some of the NSA systems have external (Intelligence Community (IC)) facing equivalents that omit quite a bit of the information that less scrutinized IC analysts shouldn't have access to. w/r to the information the NSA collects, NSA employees and contractors are held to stricter standards about how that material is used and treated. An analogy, a minor commits a crime and his record is sealed. The local court employees who handle the record, the judge etc. have really nothing that prevents them from leaking that information to an overzealous cop or lawyer or some such other than the standard to which their held for their job. It's more or less the same thing with the NSA.
> The mental leap here is subtle, but substantial. Since I have been told I can't use US selectors , I assume the system enforces this.
Actually, one of the higher standards the NSA employees are held to, and I believe they sign something to effect is that it's outright illegal for them to do so and even one misuse could result in loss of employment, clearance (a death sentence in IC heavy employment areas) and possibly time in prison as a felon. This is taken very seriously and I've never known an NSA employee to not treat this rule and US citizen data as radioactive to them.
> Definitely a bizarre mix, I thought it was a parody a couple of times. To combat the threat of nuclear war with the completely isolated totalitarian state of North Korea we must create and store copies of all global communication...
It's easy to generalize, and if the world worked as simply as the model you propose here, then things would be much better for everybody, but it simply doesn't. For example, to uphold various sanctions regimes, by law, the U.S. must know if a business has connections two hops out that are linked to any bad activity. For example, how did Kim Jong Il buy all his whiskey? It's outright illegal for a U.S. company to sell to the North Korean government. Okay, so they sell to an overseas distributor who then sells to the North Korean government. Turns out that's illegal as well and the government must take action to not allow the U.S. whiskey maker or the distributor to operate in the U.S. any longer. Okay, so the whiskey make checks out their distributors finds one who doesn't sell to NK, but one of their customers does. Same deal, it's illegal for anybody in that chain to operate in the U.S. After that, the chain becomes so long it's not worth looking into and Kim Jong Il was eventually able to get his whiskey.
Just talking whiskey and North Korea here, but you can guess it goes for all kinds of goods and countries under various sanction regimes. So how do you propose things should be collected? Collecting only on North Korea gets you nowhere, it's everybody else who may or may not be supplying whiskey to the Norks that makes things much harder and requires a much larger collection apparatus.
> It's helping diplomats illegally snoop on our allies.
Good! Our allies are most definitely snooping on us! Spying and espionage is sometimes called the second oldest profession for a reason. There's been no time in history that two countries aren't doing a bit of spying on each other, most especially at the diplomatic level.
> In fact, it's been known for months that the DEA receives intercepts from the NSA in such volume that they have an office devoted to handling them (the DEA's "Special Operations Division").
This is a problem. In general, the work the IC does in collection does not hold up to LE scrutiny. Having worked on both sides of the fence, LE is both more difficult in some cases and easier in others to work in. For example, you need a warrant to gather phone records in LE, but you can share those records more freely once you have them. In the IC the opposite is true, you can pretty much get whatever you need, but it's virtually useless if a criminal approach is taken. That's why it's often simpler to blow up the target then to arrest and try them. Parallel Construction is an investigative focusing approach that saves LE from getting collection warrants that go nowhere. The IC approach is to find the connections or whatever, then help LE figure out where to focus their warrant-based approach in doing the same collection from their side. Scrubbing U.S. Persons IC data and reusing it directly for LE is highly illegal for all of the participants involved.
> Well, following his explanations, you can fail the polygraph and just do it again. The cost of failure is zero, so really just keep trying.
Actually the penalty after enough tries is no clearance which means no job and a permanent record that you were denied a clearance...which pretty much deep sixes any attempt in the future to get one. In some parts of the country, like the Washington D.C. area, that's virtually a career death sentence.
> During the 70s and 80s my dad worked with Russian scientists
> So, how likely is it that my email is read, that my phone records are looked at, and so on? What are the chances that I'll have trouble the next time I cross a border or try to board a plane? One percent? Fifty percent?
Assume it is collected but probably not read, but not for the reasons you gave above. There's just simply not enough manpower to read everybody's email, and it's a useless thing to try to accomplish. Now suppose one of the guys you email also emails somebody who's "nefarious" in some way. Then yeah, maybe your email is read. And if all you talk about in your emails are things that don't involve an armed insurrection against the United States you'll probably be filed into the "don't give a shit" bucket and the analyst will move on.
A common thread here is that everybody who's worried about their email being read seems to assume that whatever they're doing is important enough for it to get read. Trust me, it isn't.
You actually can't handle classified data, or derive something from classified data, that doesn't automatically classify the derived work (a report, or some such) at at least the same level. To not do that risks releasing the information and you can actually end up in prison over it, or at the very least lose your job.
So in 99% of the cases it's not like you make a decision to "classify" something. It is by its nature classified.
Think of it this way. You have a friend that tells you via email a secret. This secret can only be known between you and your friend. For example, you are arranging a surprise party for a third friend.
Using this knowledge it is your job to get a birthday cake that has the person's name and age (and a decoration) on it. But the only baker in town is also friends with the birthday friend. You don't want to risk the baker leaking the surprise of the cake to your friend. So you decide to buy a blank cake, and decorate it yourself.
This cake is also classified at the same level of the original information (Classified//only between you and your friend). Because it is derived from the knowledge of the birthday party email).
Now your friend prints off decorations with some party specific information, say a sign or some streamers or something. Those are also classified at the same level.
Suppose there are some other odds and ends that are a result of this email and the party plans. Say a "making of video" for the party etc.
Now let's say you also hire a clown for the party. You only provide the clown the time and place to come and perform, not any other details. Because the clown isn't in on the original secret, the arrangements for the clown and the various transaction documents pertaining to it are at a lower classification level. You might still not want the birthday friend to know that somebody he knows hired a clown on his birthday (a convenient coincidence) so you swear the clown to secrecy.
Even if it gets out and the birthday friend asks the clown directly, the clown has plausible dependability and doesn't know why he was hired, only that he was. So it's not good that your friend finds out, but it doesn't entirely screw up the surprise.
I'm stretching the analogy a bit, but hopefully that makes it clear how knowledge of single piece of information (the email that established the surprise party) can end up producing so many classified documents and how that process happens.
I'm assuming you aren't actually asking me to prove a negative. If a reading of NISPOM doesn't clarify it for you, then there's really nothing more I can say that will persuade you from your conspiracy theory.
Army Grunts are required to have a clearance. General Infantry (18yo cannon fodder in your parlance) must have at least a Secret clearance. Army Cooks, may even be required to be cleared.
Think you can run around with 5th generation night vision goggles and state of the art body armor, talk on encrypted radio equipment, know troop movement information, chase after specific enemies and report back on activities on Secret level systems without a clearance? Think again.
Let's do a thought experiment. Let's say we can say there's a piece of information that is so dangerous, so important, that releasing that information could endanger the entire population of the planet. Say, the nuclear codes.
These are arguably the most sensitive information in the world. Why would there need to be a classification level above and beyond TS and the appropriate compartments and or SAP program to protect them? Some sort of Super Top Secret?
Or for fun, let's say Area-51 has alien tech there, or we have a secret military base on the moon, or a Stargate. Why wouldn't it just be protected under a SAP? A Super Top Secret doesn't buy you anything at all in terms of protecting that information. Nor does a Super Duper Top Secret. As somebody not in the SAP and not with a need to know, I wouldn't even know the SAP exists to protect the Stargate program, or the alien autopsy videos, or whatever. Only the people in the SAP and a handful of people managing the SAPs of the agency that created it even know of the SAPs existence and/or what it protects. SAPs can even have sub-compartments that provide even further protection.
Practically speaking this offers what can be perceived to be "high levels of clearance" but in fact are all just plain jane Top Secret.
You can get a clearance at 18, and people live into their 70s and 80s pretty regularly. The 4.2 million with a clearance are not the same ones that had a clearance 10, 20, 30, 40, 50, 60 etc. years ago.
We had a draft until the early 70s. Tens of Millions of people have been through the military system, and this doesn't even count civilian types, contractors, cleaning people, building facility people, secretaries, etc.
The Vietnam war saw about 9 million people in the military for example.
There's about 25 million vets in the U.S. right now.
It's pretty simple math to arrive at number well above the current number. Remember, just because you aren't in the club, doesn't mean it isn't big.
Let's look at what 10% means. There are ~300 million people in the U.S. 10% of that number is 30 million. Let's say that every single man and woman who is currently in the military or has previous served has a clearance (with no overlap). There are about 3 million active and reserve people right now in the military.
25 + 3 = 28 million. Now let's add in non-military government civilians with clearances, the CIA for example is a civilian agency with an estimated 20,000 people, DIA, 16,500, DTRA, 2,000, DOE: ~110,000, NGA 16,000, NRO, 3,000, NSA 20,000 (civilians only, 38,000 total), DHS, 216,000, DOJ, ~112,000, State, ~50,000, etc.
I'm not even including treasury. And we're up to almost 29 million people.
Now how many contractors do you think have Secret clearances?
Lockheed Martin employes over 100,000 people, Northrup Grumman, 120,000, General Dynamics, 91,200, SAIC, 46,000 etc. etc. etc.
And we rapidly go past 1:10.
Now obviously not every single person I've listed has (or has had) a Secret clearance. But until you start shaving off huge percentages out of each organization you're still between 1:10 and 1:15.
If you disagree with these numbers, the onus is on your to provide better ones.
You actually can't handle classified data, or derive something from classified data, that doesn't automatically classify the derived work (a report, or some such) at at least the same level. To not do that risks releasing the information and you can actually end up in prison over it, or at the very least lose your job.
So in 99% of the cases it's not like you make a decision to "classify" something. It is by its nature classified.
Think of it this way. You have a friend that tells you via email a secret. This secret can only be known between you and your friend. For example, you are arranging a surprise party for a third friend.
Using this knowledge it is your job to get a birthday cake that has the person's name and age (and a decoration) on it. But the only baker in town is also friends with the birthday friend. You don't want to risk the baker leaking the surprise of the cake to your friend. So you decide to buy a blank cake, and decorate it yourself.
This cake is also classified at the same level of the original information (Classified//only between you and your friend). Because it is derived from the knowledge of the birthday party email).
Now your friend prints off decorations with some party specific information, say a sign or some streamers or something. Those are also classified at the same level.
Suppose there are some other odds and ends that are a result of this email and the party plans. Say a "making of video" for the party etc.
Now let's say you also hire a clown for the party. You only provide the clown the time and place to come and perform, not any other details. Because the clown isn't in on the original secret, the arrangements for the clown and the various transaction documents pertaining to it are at a lower classification level. You might still not want the birthday friend to know that somebody he knows hired a clown on his birthday (a convenient coincidence) so you swear the clown to secrecy.
Even if it gets out and the birthday friend asks the clown directly, the clown has plausible dependability and doesn't know why he was hired, only that he was. So it's not good that your friend finds out, but it doesn't entirely screw up the surprise.
I'm stretching the analogy a bit, but hopefully that makes it clear how knowledge of single piece of information (the email that established the surprise party) can end up producing so many classified documents and how that process happens.
Yes, close personal contacts with people from unfriendly countries can be a problem. However, I do know people with clearances who are from several countries the U.S. is not particularly friendly with.
Quite often it could be that the investigator could not ascertain the relationships on the wife's side and/or they don't have a citizenship yet.
Let me know what country you can start an online service in that doesn't also have a foreign intelligence agency if that's your ethical standard.