U.S. looks at ways to prevent spying on its spying

WASHINGTON — The U.S. government is looking at ways to prevent anyone from spying on its own surveillance of Americans’ phone records.

As the Obama administration considers shifting the collection of those records from the National Security Agency to requiring that they be stored at phone companies or elsewhere, it’s quietly funding research to prevent phone company employees or eavesdroppers from seeing whom the U.S. is spying on, The Associated Press has learned.

The Office of the Director of National Intelligence has paid at least five research teams across the country to develop a system for high-volume, encrypted searches of electronic records kept outside the government’s possession. The project is among several ideas that would allow the government to discontinue storing Americans’ phone records, but still search them as needed.

Under the research, U.S. data mining would be shielded by secret coding that could conceal identifying details from outsiders and even the owners of the targeted databases, according to public documents obtained by The Associated Press and AP interviews with researchers, corporate executives and government officials.

In other developments Monday:

The Justice Department and leading Internet companies agreed to a compromise with the government that would allow the firms to reveal how often they are ordered to turn over information about their customers in national security investigations. The deal with Google Inc., Microsoft Corp., Yahoo Inc., Facebook Inc. and LinkedIn Corp. would provide public information in general terms. Other technology companies were also expected to participate.

Published reports said new documents leaked by former NSA contactor Edward Snowden suggest that popular mapping, gaming and social networking apps on smartphones can feed the NSA and Britain’s GCHQ eavesdropping agency with personal data, including location information and details such as political affiliation or sexual orientation. The reports, published by The New York Times, the Guardian and ProPublica, said the intelligence agencies get routine access to data generated by apps such as the Angry Birds game franchise or the Google Maps navigation service.

When the New York Times published a censored U.S. document on the smartphone surveillance program, computer experts said they were able to extract what appeared to be the name of an NSA employee, the Middle Eastern terror group the program was targeting and details about the types of computer files the NSA found especially useful. Since Snowden began leaking documents in June, his supporters have maintained they have been careful not to disclose any agent’s identity or operational details that would compromise ongoing surveillance. The employee did not return phone or email messages from the AP. A spokesman for the newspaper did not respond to emails from the AP. The NSA and DNI’s office declined to comment.

NBC News reported that British cyber spies demonstrated a pilot program to their U.S. partners in 2012 in which they were able to monitor YouTube in real time and collect addresses from the billions of videos watched daily, as well as some user information, for analysis. At the time the documents were printed, they were also able to spy on Facebook and Twitter. The network said the monitoring program was called “Squeaky Dolphin.”

Under pressure, the administration has provided only vague descriptions about changes it is considering to the NSA’s daily collection and storage of Americans’ phone records, which are presently kept in NSA databanks. To resolve legal, privacy and civil liberties concerns, President Barack Obama this month ordered the attorney general and senior intelligence officials to recommend changes by March 28 that would allow the U.S. to identify suspected terrorists’ phone calls without the government holding the phone records itself.

One federal review panel urged Obama to order phone companies or an unspecified third party to store the records; another panel said collecting the phone records was illegal and ineffective and urged Obama to abandon the program entirely.

Internal documents describing the Security and Privacy Assurance Research project do not cite the NSA or its phone surveillance program. But if the project were to prove successful, its encrypted search technology could pave the way for the government to shift storage of the records from NSA computers to either phone companies or a third-party organization.

A DNI spokesman, Michael Birmingham, confirmed that the research was relevant to the NSA’s phone records program. He cited “interest throughout the intelligence community” but cautioned that it may be some time before the technology is used.

The intelligence director’s office is by law exempt from disclosing detailed budget figures, so it’s unclear how much money the government has spent on the SPAR project, which is overseen by the DNI’s Intelligence Advanced Research Projects Activity office. Birmingham said the research is aimed for use in a “situation where a large sensitive data set is held by one party which another seeks to query, preserving privacy and enforcing access policies.”

A Columbia University computer sciences expert who heads one of the DNI-funded teams, Steven M. Bellovin, estimates the government could start conducting encrypted searches within the next year or two.

“If the NSA wanted to deploy something like this it would take one to two years to get the hardware and software in place to start collecting data this way either from phone companies or whatever other entity they decide on,” said Bellovin, who is also a former chief technologist for the Federal Trade Commission.

The NSA’s surveillance program collects millions of Americans’ daily calling records into a central agency database. When the agency wants to review telephone traffic associated with a suspected terrorist — the agency made 300 such queries in 2012 — it then searches that data bank and retrieves matching calling records and stores them separately for further analysis.

Using a “three-hop” method that allows the NSA to pull in records from three widening tiers of phone contacts, the agency could collect the phone records of up to 2.5 million Americans during each single query. Obama this month imposed a limit of “two hops,” or scrutinizing phone calls that are two steps removed from a number associated with a terrorist organization, instead of the current three.

An encrypted search system would permit the NSA to shift storage of phone records to either phone providers or a third party, and conduct secure searches remotely through their databases. The coding could shield both the extracted metadata and identities of those conducting the searches, Bellovin said. The government could use encrypted searches to ensure its analysts were not leaking information or abusing anyone’s privacy during their data searches. And the technique could also be used by the NSA to securely search out and retrieve Internet metadata, such as emails and other electronic records.

Some computer science experts are less sanguine about the prospects for encrypted search techniques. Searches could bog down because of the encryption computations needed, said Daniel Weitzner, principal research scientist at MIT’s Computer Science and Artificial Intelligence Laboratory and former deputy U.S. chief technology officer for the Obama administration.

“There’s no silver bullet that guarantees the intelligence community will only have access to the records they’re supposed to have access to,” Weitzner said. “We also need oversight of the actual use of the data.”

Intelligence officials worry that phone records stored outside the government could take longer to search and could be vulnerable to hackers or other security threats. The former NSA deputy director, John Inglis, told Congress last year that privacy — both for the agency and for Americans’ whose records were collected — is a prime consideration in the agency’s preference to store the phone data itself.

The encrypted search techniques could make it more difficult for hackers to access the phone records and could prevent phone companies from knowing which records the government was searching.

“It would remove one of the big objections to having the phone companies hold the data,” Bellovin said.

Similar research is underway by researchers at University of California at Irvine; a group from the University of Wisconsin-Madison and the University of Texas at Austin; another group from MIT, Yale and Rensselaer Polytechnic Institute; and a fourth from Stealth Software Technologies, a Los Angeles-based technology company.

Talk to us

> Give us your news tips.

> Send us a letter to the editor.

> More Herald contact information.

More in Local News

In this Jan. 4, 2019 photo, workers and other officials gather outside the Sky Valley Education Center school in Monroe, Wash., before going inside to collect samples for testing. The samples were tested for PCBs, or polychlorinated biphenyls, as well as dioxins and furans. A lawsuit filed on behalf of several families and teachers claims that officials failed to adequately respond to PCBs, or polychlorinated biphenyls, in the school. (AP Photo/Ted S. Warren)
Judge halves $784M for women exposed to Monsanto chemicals at Monroe school

Monsanto lawyers argued “arbitrary and excessive” damages in the Sky Valley Education Center case “cannot withstand constitutional scrutiny.”

Mukilteo Police Chief Andy Illyn and the graphic he created. He is currently attending the 10-week FBI National Academy in Quantico, Virginia. (Photo provided by Andy Illyn)
Help wanted: Unicorns for ‘pure magic’ career with Mukilteo police

“There’s a whole population who would be amazing police officers” but never considered it, the police chief said.

Alan Edward Dean, convicted of the 1993 murder of Melissa Lee, professes his innocence in the courtroom during his sentencing Wednesday, April 24, 2024, at Snohomish County Superior Court in Everett, Washington. (Ryan Berry / The Herald)
Bothell man gets 26 years in cold case murder of Melissa Lee, 15

“I’m innocent, not guilty. … They planted that DNA. I’ve been framed,” said Alan Edward Dean, as he was sentenced for the 1993 murder.

People hang up hearts with messages about saving the Clark Park gazebo during a “heart bomb” event hosted by Historic Everett on Saturday, Feb. 17, 2024 in Everett, Washington. (Olivia Vanni / The Herald)
Clark Park gazebo removal complicated by Everett historical group

Over a City Hall push, the city’s historical commission wants to find ways to keep the gazebo in place, alongside a proposed dog park.

Hawthorne Elementary students Kayden Smith, left, John Handall and Jace Debolt use their golden shovels to help plant a tree at Wiggums Hollow Park  in celebration of Washington’s Arbor Day on Wednesday, April 13, 2022 in Everett. (Olivia Vanni / The Herald)
Snohomish County to hold post-Earth Day recycling event in Monroe

Locals can bring hard-to-recycle items to Evergreen State Fair Park. Accepted items include Styrofoam, electronics and tires.

Everett
Everett baby dies amid string of child fentanyl overdoses

Firefighters have responded to three incidents of children under 2 who were exposed to fentanyl this week. Police were investigating.

Everett
Everett police arrest different man in fatal pellet gun shooting

After new evidence came to light, manslaughter charges were dropped against Alexander Moseid. Police arrested Aaron Trevino.

A Mukilteo Speedway sign hangs at an intersection along the road on Sunday, April 21, 2024, in Mukilteo, Washington. (Ryan Berry / The Herald)
What’s in a ‘speedway’? Mukilteo considers renaming main drag

“Why would anybody name their major road a speedway?” wondered Mayor Joe Marine. The city is considering a rebrand for its arterial route.

Edmonds City Council members answer questions during an Edmonds City Council Town Hall on Thursday, April 18, 2024 in Edmonds, Washington. (Olivia Vanni / The Herald)
Edmonds fire service faces expiration date, quandary about what’s next

South County Fire will end a contract with the city in late 2025, citing insufficient funds. Edmonds sees four options for its next step.

House Transportation Subcommittee Chairman Rep. Rick Larsen, D-Wash., speaks during a hearing on Capitol Hill in Washington, Wednesday, May 15, 2019, on the status of the Boeing 737 MAX aircraft.(AP Photo/Susan Walsh)
How Snohomish County lawmakers voted on TikTok ban, aid to Israel, Ukraine

The package includes a bill to ban TikTok if it stays in the hands of a Chinese company, which made one Everett lawmaker object.

FILE - In this May 26, 2020, file photo, a grizzly bear roams an exhibit at the Woodland Park Zoo, closed for nearly three months because of the coronavirus outbreak in Seattle. Grizzly bears once roamed the rugged landscape of the North Cascades in Washington state but few have been sighted in recent decades. The federal government is scrapping plans to reintroduce grizzly bears to the North Cascades ecosystem. (AP Photo/Elaine Thompson, File)
Grizzlies to return to North Cascades, feds confirm in controversial plan

Under a final plan announced Thursday, officials will release three to seven bears per year. They anticipate 200 in a century.s

ZeroAvia founder and CEO Val Mifthakof, left, shows Gov. Jay Inslee a hydrogen-powered motor during an event at ZeroAvia’s new Everett facility on Wednesday, April 24, 2024, near Paine Field in Everett, Washington. (Ryan Berry / The Herald)
ZeroAvia’s new Everett center ‘a huge step in decarbonizing’ aviation

The British-American company, which is developing hydrogen-electric powered aircraft, expects one day to employ hundreds at the site.

Support local journalism

If you value local news, make a gift now to support the trusted journalism you get in The Daily Herald. Donations processed in this system are not tax deductible.