Showing posts with label Benjamin Wittes. Show all posts
Showing posts with label Benjamin Wittes. Show all posts

Sunday, 5 March 2017

Ten More Questions for President Trump

Yesterday, I posed ten questions for President Trump in response to his bizarre Twitter temper tantrum accusing his predecessor of wiretapping Trump Tower in the days before the election.

In the hours after I did so, a variety of media organizations began reporting—unsurprisingly, I suppose—that the President’s tweets were not based on any information that came from within the executive branch—indeed, that the White House was now scrambling to find some evidence to substantiate the president’s statements. Here’s how the New York Times characterized it:

His aides declined to clarify on Saturday whether the president’s allegations were based on briefings from intelligence or law enforcement officials — which could mean that Mr. Trump was revealing previously unknown details about the investigation — or on something else, like a news report.

But a senior White House official said that Donald F. McGahn II, the president’s chief counsel, was working to secure access to what Mr. McGahn believed to be an order issued by the Foreign Intelligence Surveillance Court authorizing some form of surveillance related to Mr. Trump and his associates.

The official offered no evidence to support the notion that such an order exists. It would be a highly unusual breach of the Justice Department’s traditional independence on law enforcement matters for the White House to order it to turn over such an investigative document.

Any request for information from a top White House official about a continuing investigation would be a stunning departure from protocols intended to insulate the F.B.I. from political pressure. It would be even more surprising for the White House to seek information about a case directly involving the president or his advisers, as does the case involving the Russia contacts.

After the White House received heavy criticism for the suggestion that Mr. McGahn would breach Justice Department independence, a different administration official said that the earlier statements about his efforts had been overstated. The official said the counsel’s office was looking at whether there was any legal possibility of gleaning information without impeding or interfering with an investigation. The counsel’s office does not know whether an investigation exists, the official said.

If you are finding Lawfare useful in these times, please consider making a contribution to support what we do.

Also yesterday, the estimable Julian Sanchez writing on Just Security, penned this excellent explainer piece about what he thinks is really going on. I find entirely plausible Sanchez’s suspicion that Trump is really just channeling and garbling accounts in news stories about surveillance around the campaign that have been kicking around for some time.

All that said, Sanchez's account is speculative. And we thus still have on our hands a definitive presidential statement that his phones were “wiretapped” by his predecessory. Unless and until the President retracts those statements or amends them to comport with Julian’s sense (which I share) of what the reality probably is, I think we all have an obligation to take the words of the President of the United States seriously.

So in that spirit, here are ten more questions for President Trump on the subject of his tweetstorm yesterday:

  1. To the extent any wiretap you revealed yesterday was previously classified, your tweets have declassified the fact of its existence. Do you agree that the FBI, DOJ, and the FISA Court are now at liberty to confirm the existence of any FISA surveillance that may have been taking place at Trump Tower or against its occupants?
  2. Do you agree that, to whatever extent no such surveillance was taking place, the fact of its absence—which is to say the fact that you were either lying or making up facts or repeating allegations published in Breitbart with no idea of their accuracy—is also not classified?
  3. Will you similarly declassify any material the underlying FISA application may contain so that the public can understand the basis or lawlessness of the alleged Obama surveillance of your campaign and business?
  4. You say that there was “Nothing found” in the wiretapping of Trump Tower. Are you thereby declassifying the fruits of any surveillance that may have taken place? Will you?
  5. You say that the surveillance was “Turned down by court earlier.” Are you thereby declassying the fact of and waiving any privacy interests in any earlier application to the FISA Court or to any federal district court under Title III—and in any rulings that any court may have made on the subject?
  6. To whatever extent you have revealed FISA surveillance in a series of tweets, with which agencies, if any, did you consult before declassifying presumably sensitive material about a foreign counterintelligence investigation that is by most accounts still ongoing?
  7. To whatever extent you have revealed FISA surveillance in a series of tweets, was your National Security Adviser, Gen. H.R. McMaster, aware that you intended to declassify sensitive material about a foreign counterintelligence investigation  that is by most accounts still ongoing?
  8. You say that you “bet a good lawyer could make a great case out of the fact that President Obama was tapping my phones in October, just prior to Election!” Are you planning to bring suit against Obama or anyone else under either 50 U.S.C. § 1810—which provides for civil remedies for “[a]n aggrieved person, other than a foreign power or an agent of a foreign power . . . who has been subjected to an electronic surveillance”—or under 18 U.S.C. § 2520—which provides that “any person whose wire, oral, or electronic communication is intercepted . . . in violation of [criminal wiretap law] may in a civil action recover from the person or entity, other than the United States, which engaged in that violation”?
  9. To the extent no such surveillance took place or you have grossly mischaracterized it, do you have any concerns that you might have imputed grave misconduct to your predecessor—in the language of New York Times v. Sullivan—with “‘actual malice’—that is, with knowledge that it was false or with reckless disregard of whether it was false or not”?
  10. If so, have you or your counsel considered the question of whether a tweet from the @realDonaldTrump Twitter account that contains a slander or a libel is an official presidential act for which you are immune from liability under Nixon v. Fitzgerald or whether it is personal conduct for which you might be subject to suit under Clinton v. Jones?


from Ten More Questions for President Trump

Saturday, 4 March 2017

Ten Questions for President Trump

This morning, the country awoke to a bizarre tweetstorm from the President of the United States, about which I have ten questions.

First off, here's what Trump tweeted:

Donald Trump's Morning Tweet Storm

Here are my questions, about all of which I am, I want to stress, entirely serious:

If you are finding Lawfare useful in these times, please consider making a contribution to support what we do.

  1. Are you making the allegation that President Obama conducted electronic surveillance of Trump Tower in your capacity as President of the United States based on intelligence or law enforcement information available to you in that capacity? 
  2. If so—that is, if you have executive branch information validating that either a FISA wiretap or a Title III wiretap took place—have you reviewed the applications for the surveillance and have you or your lawyers concluded that they lack merit?
  3. If you know that a FISA wiretap took place, are you or were you at the time of the application, an agent of a foreign power within the meaning of FISA? 
  4. Was anyone else working in Trump Tower an agent of a foreign power within the meaning of FISA?
  5. If you know that a Title III wiretap took place, are you or were you at the time of the application engaged in criminal activity that would support a Title III wiretap or might you have previously engaged in criminal activity that might legitimately be the subject of a Title III wiretap?
  6. Was anyone else working in Trump Tower engaged in criminal activity that would support a Title III wiretap or might another person have previously engaged in criminal activity that might legitimately be the subject of a Title III wiretap?
  7. If you were tweeting not based on knowledge received as chief executive of the United States, were you tweeting in your capacity as a reader of Breitbart or a listener of Mark Levin's radio show?
  8. If so, on what basis are you confident the stories and allegations in these august outlets are true and accurate vis a vis the activity of the government you, in fact, now head?
  9. If you learned of this alleged surveillance from media outlets, did you or anyone on your staff check with any responsible law enforcement or intelligence officials or agencies before making public allegations against your own government?
  10. What exactly does any of this have to do with Arnold Schwarzenegger?

Author's Note: This tweetstorm episode is an excellent illustration of some of the points Quinta Jurecic and I made yesterday in a lengthy article on the presidential oath of office. I commend it to you.



from Ten Questions for President Trump

Friday, 13 January 2017

Empirical Data on the Privacy Paradox

The contemporary debate about the effects of new technology on individual privacy centers on the idea that privacy is an eroding value. The erosion is ongoing and takes place because of the government and big corporations that collect data on us all: In the consumer space, technology and the companies that create it erode privacy, as consumers trade away their solitude either unknowingly or in exchange for convenience and efficiency.

Today, we released a Brookings paper that challenges this idea. Entitled, “The Privacy Paradox II: Measuring the Privacy Benefits of Privacy Threats,” we try to measure the extent to which this focus ignores the significant privacy benefits of the technologies that concern privacy advocates. And we conclude that quantifiable effects in consumer behavior strongly support the reality of these benefits.   

In 2015, one of us, writing with Jodie Liu, laid out the basic idea last year in a paper published by Brookings called “The Privacy Paradox: the Privacy Benefits of Privacy Threats.” (The title, incidentally, became the name of Lawfare’s privacy-oriented subsidiary page.) Individuals, we argued, might be more concerned with keeping private information from specific people—friends, neighbors, parents, or even store clerks—than from large, remote corporations, and they might actively prefer to give information remote corporations by way of shielding it from those immediately around them. By failing to associate this concern with the concept of privacy, academic and public debates tends to ignore countervailing privacy benefits associated with privacy threats, and thereby keeps score in a way biased toward the threats side of the ledger.

To cite a few examples, an individual may choose to use a Kindle e-reader to read Fifty Shades of Grey precisely because she values the privacy benefit of hiding her book choice from the eyes of people on the bus or the store clerk at the book store, rather than for reasons of mere convenience. This privacy benefit, for many consumers, can outweigh the privacy concern presented by Amazon’s data mining. At the very least, the privacy benefits of the Kindle should enter into the discussion.

In this paper, we tried to begin the task for measuring the effect and reasoning that supported the thesis in the “Privacy Paradox” using Google Surveys, an online survey tool.

In order to isolate the effects of perceived privacy benefits from those of convenience, efficiency, or economic concerns, we asked pairs of questions about consumer behavior. In each pair, one question concerned an item that would be likely to trigger privacy concerns (for example, condoms), while the other involved a much more mundane item (for example, dental floss). The results indicate a measurable difference in reported behavior about sensitive behaviors as compared to non-sensitive ones.  

First, we tested the hypothesis that readers of Fifty Shades of Grey would prefer to do so on an e-reader than would readers of a substantially less titillating novel, Hunger Games. A full three-quarters of respondents who read Hunger Games did so in paper copy (Figure 5), while only 58.7 percent of Fifty Shades readers reported having read a paper copy of the salacious (and easily identifiable) novel (Figure 4).  

 

Figure 4: Results for Question #10

Screen Shot 2016-12-26 at 7.32.15 AM.png

 

Figure 5: Results for Question #11

Screen Shot 2016-12-26 at 8.02.23 AM.png

 

Second, we asked respondents about their shopping habits to address the proposition that factors other than privacy, such as convenience or price, might explain preferences for online shopping. Very few survey respondents preferred to buy general household items online, but almost double preferred to buy products of a sensitive personal nature online, despite presumably equal convenience or price benefits to online shopping for either type of product (Figure 6).

 

Figure 6: Results for Question #9

Screen Shot 2016-12-26 at 8.05.59 AM.png

 

This effect was also evident when we asked about purchasing a specific sensitive product—a “personal massager.” Women reported a preference for buying personal massagers online, but did not have the same preference for buying electric fans online rather than in a store (Figure 7).

 

Figure 7: Results for Question #1

Screen Shot 2016-12-26 at 8.20.55 AM.png

 

Finally, we tested the hypotheses that young men and women would rather use self-checkout to buy products like condoms and tampons for reasons beyond convenience and efficiency. Though many reported having no preference, more respondents in both groups reported a preference for a human cashier when buying dental floss than when buying products they might consider embarrassing (Figures 8 & 9).

 

Figure 8: Results for Questions #4 & #5

Screen Shot 2016-12-26 at 8.26.02 AM.png

Screen Shot 2016-12-26 at 8.32.15 AM.png

 

Figure 9: Results for Questions #6 & #7

Picture1.png

 

There’s a lot more in the underlying paper, including some amusing material our Google’s half-heartedly prudish censorship of Google Surveys—and our efforts to hack the rules. But you’ll have to download the paper for that. For present purposes, the key point is that the results clearly indicate that when privacy concerns are activated, consumers tend to favor methods of purchasing (or reading) that shield their behavior from those around them, while they are not shy about exposing the same information to tracking and storage by remote entities like Google or Amazon. In short, privacy from whom matters, and an understanding of privacy as a contextual value is really important to explaining the lived privacy choices of real people.



from Empirical Data on the Privacy Paradox

Tuesday, 10 January 2017

The Privacy Paradox II: An Event at Brookings on Friday

On Friday morning, I will be releasing a new Brookings paper that readers may find interesting. Stewart Baker of Steptoe & Johnson and Amie Stepanovich of Access Now will be discussants on the paper, which I wrote with Emma Kohse. 

Here's how Brookings is describing the event:

In the post-Snowden world, debates about privacy are ubiquitous. Some of the most heated debates center around consumer data collection by the government and large corporations, a practice that many advocates and watchdog groups seek to protect Americans from. But do Americans want or need such protection? A new Brookings paper illustrates how many of the technologies often considered to pose the greatest threats to data privacy actually offer consumers another kind of privacy that they value even more: the privacy to consume goods and media away from prying eyes.

On January 13, Governance Studies at Brookings will convene a panel of experts to discuss this “privacy paradox,” to challenge the common belief that consumers are simply willing to sacrifice privacy for convenience and cost-effectiveness when making purchasing decisions, and to determine whether it is time to redefine privacy with the consumer perspective in mind.

After the session, panelists will take audience questions.

The paper is a sequel to this one from last year, which was entitled "The Privacy Paradox: The Privacy Benefits of Privacy Threats." It argued that our privacy debate tends to measure privacy very badly and hypothesized that many of the companies we most fear on privacy grounds actually provide great privacy benefits to many consumers. 

In the new paper, Emma and I tried to measure those benefits. Specifically, we used Google Surveys to run a series of public opinion probes of consumer behavior with respect to various aspects of the Privacy Paradox thesis. As we discuss in the new paper, the results strongly support the notion that a great many people are less concerned about privacy from big remote data-collecting entities than they are about privacy from the people immediately  around them—indeed, that they will actively give data to such companies by way of buying more privacy in their immediate surroundings. 

We will post the paper on Lawfare on Friday, and I hope you'll join us for the event.



from The Privacy Paradox II: An Event at Brookings on Friday

Wednesday, 4 January 2017

Follow Buddies and Block Buddies: A Simple Proposal to Improve Civility, Control, and Privacy on Twitter

The 2016 election has put squarely on the public agenda a series of questions related to the norms of social media, everything from the proliferation of fake news on Facebook to the trolling culture of Twitter. These questions are not new. The culture of abuse online towards women, for example, is a matter about which one of us wrote a book. But over the last few months, the concerns—spurred in part by a president-elect and his followers who participate actively in Twitter abuse of opponents and critics—have vaulted into the mainstream.

The problems vary significantly by social media platform. On Twitter, the pressing issue is civility: values of free expression and individual user freedom often get pitted against norms of decency and the ability to participate online free of harassment and abuse.

Consider the attacks on journalists between August 2015 and July 2016. When neo-Nazi trolls attacked well-known writers on Twitter with anti-Semitic death threats and images of their (or their children’s) faces photoshopped into ovens, the goal was to terrorize and silence. Sometimes, the attacks succeeded. New York Times editor Jonathan Weisman suspended his Twitter account and switched to Facebook for a time after a cyber mob descended on his Twitter feed. The harrowing account of National Review writer David French’s experience of Twitter abuse as a result of his opposition to Trump is another example.

The obvious reason why Weisman switched to Facebook is that random strangers can’t contact users and attack them there without having gotten through an initial screening process. Non-friends cannot directly contact users on Facebook until the user has given the green light to interaction by accepting a friend request. That initial screening process substantially diminishes the possibility of drive-by attacks, though it also prevents unexpected, positive interactions with strangers.

By contrast, Twitter has no such speed bump to interactions. Anyone can engage with any user: Put an @ in front of someone’s user handle and you have their attention. That can be a very good thing. A diversity of interactions can yield rich discussions, unexpected insights, and pointed feedback. Yet it also allows angry cyber mobs to descend upon users with threats, defamation, privacy invasions, and intimidating slurs. Right now, on Twitter, each troll gets at least one free shot at each user and has to be blocked individually, which is both time consuming and onerous if multiple individuals are targeting individuals.

So the question is how can Twitter and similarly designed platforms help users harness the positive potential of networked interactions while diminishing its most destructive uses? How can platforms empower users to help themselves more efficiently and effectively, avoiding the need for their intervention, which can be hard to scale and raises concerns about private censorship?

We have a simple proposal for a technical mechanism to align the values of free expression, individual freedom, and civility. It would provide an easy and quick way of giving users more control over the material they see and read and give groups of users the ability to enforce their shared norms. Specifically, Twitter should expand its current system of letting users designate whom they “block” and “follow” to let users designate other users whose blocks and follows their accounts will replicate.

Third-party apps like Block Together have emerged with the express purpose of preventing abuse and harassment. Integrating “block together” and “follow together” functions on Twitter would make it easier for users to protect themselves and view the content that most interests them while reducing other apps’ access to users’ feeds and personal information. Integrating this sort of functionality into Twitter itself would also send a powerful message about Twitter’s desire to enhance civility, privacy, and user control.

A “block buddy” system, like Block Together, would crowd-source the process of blocking among like-minded people. In this system, if Ben block-buddies Danielle, he effectively instructs Twitter that if someone is behaving in a sufficiently uncivil fashion that Danielle doesn’t want to hear from that person any more, then Ben instructs the platform that he doesn’t want to hear from that person either.

If Danielle block-buddies the Southern Poverty Law Center, the Anti-Defamation League, or the National Association for the Advancement of Colored People, entities with the mission of fighting bigotry, she is saying that anyone that organization blocks should also be dead to her for Twitter purposes. Similarly, if people find Ben’s or Danielle’s tweets so offensive that they don’t want to hear from them, they can band together and block them as a group. Some individuals would use this system merely as a way of keeping away harassing users. Civil rights organizations like the SPLC, ADL, and the NAACP, whom many would be inclined to trust in their ability to identify Twitter accounts used to harass and silence, might use it as a way of identifying hate speech online that large numbers of people want to do without.

By implementing a block buddy system, Twitter would effectively allow people to delegate the blocking process to trusted others. Critically, it could do so without itself policing the content in question. Individual users could be as aggressive or reticent about this delegation as they choose: A person who doesn’t mind a certain amount of abuse and doesn’t want to delegate any blocking to anyone does not have to do so and can retain as much control as desired; a person more intimidated by the atmosphere, by contrast, can designate lots of people as block buddies and thus have a cleaner feed, albeit one with less chance of spontaneous positive interactions.

Twitter should also consider adopting a mirror-image “follow buddy” system, in which users can honor another user’s follows. If Danielle has designated Ben a “follow buddy,” she would automatically follow anyone he chooses to follow. This would allow a new user in a particular field or social setting to instantly acquire a Twitter feed based on the people her immediate friends have followed and follow in the future. It would create a default in which she follows her buddies’ follows unless she specifically unfollows them, rather than a default in which she has to choose to follow them individually in the first instance. Again, nobody would have to use this feature. It would simply be an option available to people who want to delegate some degree of control over their feeds to people or organizations whom they trust.

The result, we think, would be a free-speech-friendly and content-neutral means of giving users greater control over the substance and civility of their Twitter feeds.

Would this system cause more people to live in philosophical bubbles? It probably would. But it’s really only an extension of Twitter’s existing system. Currently, users designate those they want to hear from and block those they do not want to hear from. All we are suggesting here is extending these two principles to enhance user choice about whom we trust to act on our behalfs in those judgments without needing to resort to third party applications that may harvest users’ personal information.

This system is, we concede, prone to abuses of its own. For instance, a mischief-maker could include Ben in a block list not because he is engaged in anti-social activity but, say, to silence his views on surveillance or Guantanamo or to deprive him of the ability to engage with others on Twitter. If that mischief maker were a big organization with lots of block-buddies, the silencing effect could be substantial. Similarly, a mischief-maker could include a destructive individual in a follow list for anti-social ends, thus magnifying that person’s voice to lots of unsuspecting people. Worst of all would be if the mischief makers were government authorities bent on silencing and marginalizing dissenting voices.

Then there’s the potential mischief involving small, localized groups. Consider the implications of a social clique in a middle school who have all block-buddied one another and then were to en masse turn on the bullied kids who are on the outs and block them. All of a sudden, those kids are shut out from everyone.

The mischief in the public sphere may be easier to address than in the more intimate local setting of a school. For one thing, there’s the person maintaining the block or follow list. That person is presumably entrusted with the list for a good reason by each person who trusts him or her. The trust is earned, and it can be undone by bad management of a list. Thus, if the trustee falls down on the job of screening additional profiles for following and blocking, users will be less inclined to use that trustee’s list and may abandon it entirely. The beauty of Twitter is that word gets out quickly, so a trustee’s reputation can be revised and updated.

Moreover, the follow- and block-buddy system should not be mechanistic but one that merely changes the defaults. If Danielle block-buddies Ben and he blocks someone, she should still have the ability to unblock the person on an individual level. So even if she doesn’t lose faith in Ben’s blocking judgment in general and uncouple her blocking from his, she can still disagree with and undo any individual judgment he may make.

The problem at the local level may be more difficult to resolve. And it may be that improving the civility climate on Twitter at the political level will necessarily create opportunities for abuse and bullying at the local level—where people’s reasons for blocking one another may be more likely to be petty, highly personal, or downright mean. That is not to suggest that this problem is intractable. There may be algorithmic ways of ameliorating the highly-localized problem: for example, preventing small groups of people who all follow one another from mass blocking of a person deeply within that social web. If, say, ten people all follow one another, Twitter might disallow nine of them from mass-blocking the tenth, but have blocking in those situations automatically revert to only individualized actions. One could imagine, in other words, a block-buddy system that does not operate in certain environments in which it might be prone to abuse. The shunning of the out kids, of course, might still happen, but it would have to take place as a consequence of the individual actions of the nine users, rather than as an automated consequence of the block-buddy system. And that scenario is already possible today.

The broad point here is that there should be some way on Twitter to crowd-source both disgust with and interest in people and organizations about whom many users are likely to have similar reactions. There should be a way of collectively following and collectively turning our face from people who either enliven or diminish crucial online spaces for discourse, networking, and enlightenment. That mechanism should be entirely voluntary, and it should be designed so as to avoid implicating Twitter in any editorial or political judgments.

Crucially, a block- and follow-buddy system might help forestall some governmental pressure for platforms like Twitter to remove hateful and terroristic speech. That pressure should not be underestimated; the recent Code of Conduct agreement between Facebook, Microsoft, Twitter, YouTube, and the EU Commission on hate speech demonstrates as much.

One does not have to be a believer in the creation of “safe spaces” to believe that Twitter should experiment with tools that enable users to protect themselves from destructive abuse (and hence keep expressing themselves on the platform). A block- and follow-buddy system would succeed or fail on its own terms. It might end up as a niche tool, used only by a minority of users. But it is worth trying to avoid a far worse fate: the loss of talented voices (often but not always women, people of color, and religious minorities) as a consequence of the destructive online culture made needlessly easy to inflict on individuals as a consequence of the architectural choices of platforms like Twitter.  



from Follow Buddies and Block Buddies: A Simple Proposal to Improve Civility, Control, and Privacy on Twitter

Thursday, 6 October 2016

Holding Off on that Yahoo Email Story

I've gotten a few questions the last couple of days about why Lawfare has had nothing to say about that big story Reuters ran the other day on Yahoo, the intelligence community, and the scanning of all those email accounts.

I can't speak for other writers on this site, but here's why I haven't written about it: the stories in question contain too little information to usefully comment, and too much of the information is contradictory. I thus don't think I can say anything useful at this stage, other than to point out how much we don't know and to point out that nearly all of the other commentary is either the rankest of speculation or has already proven to be wrong. The better part of valor right now is to shut up and wait.

So as a reader service, I'm going to shut up and wait to draw any conclusions. But first, I'm going to list three things I'm waiting for, things we don't yet know that should be pivotal to figuring out how to evaluate what the government and Yahoo actually did here.

First, neither the original Reuters story nor the New York Times story that followed—and contradicted—it yesterday had access to any of the underlying documents. The Reuters story is sourced to "people familiar with the matter." The Times story is sourced to "several people familiar with the matter," "Two government officials who spoke on the condition of anonymity," and "a third person familiar with Yahoo’s response, who also spoke on the condition of anonymity."

There's nothing wrong with writing news stories based on anonymous sourcing when it's necessary to do so. There is something very wrong with doing a complex legal and factual analysis without access to either the facts or the legal thinking that went into the surveillance in the government, at the court, and at Yahoo. Sometimes, of course, we don't have access to the core materials because the government keeps things classified, so we are left to read tea leaves. We are never, however, forced to act like those tea leaves are sufficient to draw conclusions. A lot of people are doing that this week.

Second, the reporting here is actually very thin and do not, in fact, have enough tea leaves to draw even tentative conclusions. Without access to documents detailing what sort of order the government sought from the FISA court or what the court actually ordered Yahoo to do, both stories can give only the vaguest outline of the actual collection that took place.

Here's Reuters:

Yahoo Inc last year secretly built a custom software program to search all of its customers' incoming emails for specific information provided by U.S. intelligence officials, according to people familiar with the matter.

The company complied with a classified U.S. government demand, scanning hundreds of millions of Yahoo Mail accounts at the behest of the National Security Agency or FBI, said three former employees and a fourth person apprised of the events.

. . .

It is not known what information intelligence officials were looking for, only that they wanted Yahoo to search for a set of characters. That could mean a phrase in an email or an attachment, said the sources, who did not want to be identified.

Here's the Times:

Yahoo customized an existing scanning system for all incoming email traffic, which also looks for malware, according to one of the officials and to a third person familiar with Yahoo’s response, who also spoke on the condition of anonymity.

With some modifications, the system stored and made available to the Federal Bureau of Investigation a copy of any messages it found that contained the digital signature. The collection is no longer taking place, those two people said.

. . . 

Investigators had learned that agents of the foreign terrorist organization were communicating using Yahoo’s email service and with a method that involved a “highly unique” identifier or signature, but the investigators did not know which specific email accounts those agents were using, the officials said.

I don't fault any of the reporters for this. They only have access to the information to which they have access. But the dramatic rush on the part of lots of commentators to have opinions about the matter is irresponsible. There simply isn't enough information here to have an opinion about the propriety or legality of the activity in question. Nor is there enough information here to wax indignant that Yahoo did not fight the order. Reuters reports that Yahoo chieftain Marissa "Mayer and other executives ultimately decided to comply with the directive last year rather than fight it, in part because they thought they would lose, said the people familiar with the matter." The many self-described privacy advocates who are outraged that Yahoo didn't stand and fight are insisting, with virtually no information, that they know better how some law (they are not sure which law) would interact with some facts (they are not sure which facts) than did Mayer and her lawyers, who had access to both the law and the facts and to the actual court order to which they had to respond.

Third, the reports are not consistent with one another about the legal authority for the surveillance either—and the Reuters stories are not even internally consistent with themselves on the subject. In its initial report, Reuters did not specify under what authority the government had issued its demand, calling it only "a broad demand for real-time Web collection" and saying that "The request to search Yahoo Mail accounts came in the form of a classified edict sent to the company's legal team." For the record, "classified edict" is not a term of art.

The Times, however, yesterday clarified that the order was not broad, but narrow, coming from the FISA Court under what is called the "traditional" FISA authority:

Two government officials who spoke on the condition of anonymity said the Justice Department obtained an individualized order from a judge of the Foreign Intelligence Surveillance Court last year.

. . .

The two government officials familiar with the matter said the digital signature Yahoo was ordered to look for last year was individually approved in an order issued by a judge, who was persuaded that there was probable cause to believe that it was uniquely used by a foreign power.

. . .

According to the government officials, Yahoo was served with an individualized court order to look only for code uniquely used by the foreign terrorist organization. Two sources, including one of the officials, portrayed it as adapting the scanning systems that it already had in place to comply with that order rather than building a brand-new capability. The other official did not comment on the technology. The officials did not name the terrorist organization.

But then Reuters doubled down, and published another story insisting that the legal authority for the action was FISA 702: "Yahoo's request came under the Foreign Intelligence Surveillance Act, the sources said. The two sources said the request was issued under a provision of the law known as Section 702, which will expire on Dec. 31, 2017, unless lawmakers act to renew it." Except that elsewhere in the same story, the Reuters reporters described a process that sounds nothing at all like 702 but something like traditional FISA: "The collection in question was specifically authorized by a warrant issued by the secret Foreign Intelligence Surveillance Court, said the two government sources, who requested anonymity to speak freely." 

So in other words, we don't have the documents; we don't have the facts; and we don't even know what law we're talking about.

All we really know is that there was some kind of order, under some provision of FISA, that prompted Yahoo to scan all emails for a known signature and segregate the fruits of that scanning for FBI inspection. I can imagine situations and fact patterns in which that would bother me a lot. I can also imagine situations and fact patterns in which it would strike me as a perfectly reasonable thing. Right now, I have very little sense of what really happened here. So I'm going to wait to have an opinion until I actually know something.

So should everyone else.



from Holding Off on that Yahoo Email Story