:en:National Security Agency
{{short description|U.S. signals intelligence organization}}
{{Other uses}}
{{redirect-distinguish-text|NSA|NSC or NASA. For other uses, see NSA (disambiguation)}}
{{Infobox government agency
| agency_name = National Security Agency
| nativename_a =
| nativename_r =
| picture = National Security Agency headquarters, Fort Meade, Maryland.jpg
| picture_width =
| picture_caption = NSA headquarters building in Fort Meade, Maryland, {{Circa|1986}}
| logo = Flag of the U.S. National Security Agency.svg
| logo_width = 200
| logo_caption = Flag of the National Security Agency
| seal = National Security Agency.svg
| seal_width = 175
| seal_caption = Seal of the National Security Agency
| preceding1 = Armed Forces Security Agency
| preceding2 =
| dissolved =
| parent_agency = Department of Defense
| jurisdiction =
| headquarters = Fort Meade, Maryland, U.S. ({{Coord|39|6|32|N|76|46|17|W|type:landmark_region:US-MD|display=inline}})
| employees = Classified (est. 30,000–40,000){{cite web|title=60 Years of Defending Our Nation|publisher=National Security Agency|year=2012|url=https://www.nsa.gov/about/cryptologic_heritage/60th/book/NSA_60th_Anniversary.pdf|access-date=July 6, 2013|page=3|archive-url=https://web.archive.org/web/20130614022314/http://www.nsa.gov/about/cryptologic_heritage/60th/book/NSA_60th_Anniversary.pdf|archive-date=2013-06-14|url-status=dead|quote=On November 4, 2012, the National Security Agency (NSA) celebrates its 60th anniversary of providing critical information to U.S. decision makers and Armed Forces personnel in defense of our Nation. NSA has evolved from a staff of approximately 7,600 military and civilian employees housed in 1952 in a vacated school in Arlington, VA, into a workforce of more than 30,000 demographically diverse men and women located at NSA headquarters in Ft. Meade, MD, in four national Cryptologic Centers, and at sites throughout the world.}}{{cite news |title=NSA growth fueled by the need to target terrorists |url=https://www.washingtonpost.com/world/national-security/nsa-growth-fueled-by-need-to-target-terrorists/2013/07/21/24c93cf4-f0b1-11e2-bed3-b9b6fe264871_story.html |newspaper=The Washington Post |first=Dana |last=Priest |date=July 21, 2013 |access-date=July 22, 2013 |quote=Since the attacks of Sept. 11, 2001, its civilian and military workforce has grown by one-third, to about 33,000, according to the NSA. Its budget has roughly doubled. |archive-date=February 16, 2014 |archive-url=https://web.archive.org/web/20140216143545/http://www.washingtonpost.com/world/national-security/nsa-growth-fueled-by-need-to-target-terrorists/2013/07/21/24c93cf4-f0b1-11e2-bed3-b9b6fe264871_story.html |url-status=live }}
| motto = "Defending Our Nation. Securing the Future."
| budget = Classified (est. $10.8 billion, 2013){{cite news |url=https://www.washingtonpost.com/world/national-security/black-budget-summary-details-us-spy-networks-successes-failures-and-objectives/2013/08/29/7e57bb78-10ab-11e3-8cdd-bcdc09410972_story.html |page=3 |date=August 29, 2013 |access-date=August 29, 2013 |first1=Barton |last1=Gellman |author2=Greg Miller |newspaper=The Washington Post |title=U.S. spy network's successes, failures and objectives detailed in 'black budget' summary |archive-date=September 1, 2013 |archive-url=https://web.archive.org/web/20130901013422/http://www.washingtonpost.com/world/national-security/black-budget-summary-details-us-spy-networks-successes-failures-and-objectives/2013/08/29/7e57bb78-10ab-11e3-8cdd-bcdc09410972_story.html |url-status=live }}{{cite news |url=https://www.nytimes.com/2013/08/30/us/politics/leaked-document-outlines-us-spending-on-intelligence.html |date=August 29, 2013 |access-date=August 29, 2013 |first=Scott |last=Shane |work=The New York Times |title=New Leaked Document Outlines U.S. Spending on Intelligence Agencies |archive-date=August 30, 2013 |archive-url=https://web.archive.org/web/20130830013202/http://www.nytimes.com/2013/08/30/us/politics/leaked-document-outlines-us-spending-on-intelligence.html |url-status=live }}
| chief1_name = LTG William J. Hartman (acting){{cite news|last1=Nakashima|first1=Ellen|last2=Strobel|first2=Warren|url=https://www.washingtonpost.com/national-security/2025/04/03/nsa-director-fired-tim-haugh/|title=National Security Agency and Cyber Command chief Gen. Timothy Haugh ousted|date=2025-04-04|archive-url=https://archive.today/20250404032313/https://www.washingtonpost.com/national-security/2025/04/03/nsa-director-fired-tim-haugh/|archive-date=2025-04-04|newspaper=The Washington Post}}
| chief1_position = Director
| chief2_name = Sheila Thomas (acting)
| chief2_position = Deputy Director
| website = {{URL|https://www.nsa.gov|nsa.gov}}
}}
{{NSA surveillance|1|2|3}}
{{United States Armed Forces sidebar}}
The National Security Agency (NSA) is an intelligence agency of the United States Department of Defense, under the authority of the director of national intelligence (DNI). The NSA is responsible for global monitoring, collection, and processing of information and data for global intelligence and counterintelligence purposes, specializing in a discipline known as signals intelligence (SIGINT). The NSA is also tasked with the protection of U.S. communications networks and information systems.{{cite web |title=About NSA: Mission |publisher=National Security Agency |url=https://www.nsa.gov/about/mission/index.shtml |access-date=September 14, 2014 |archive-date=September 18, 2014 |archive-url=https://web.archive.org/web/20140918003311/https://www.nsa.gov/about/mission/index.shtml |url-status=live }} The NSA relies on a variety of measures to accomplish its mission, the majority of which are clandestine.Executive Order 13470 – [http://www.gpo.gov/fdsys/pkg/WCPD-2008-08-04/pdf/WCPD-2008-08-04-Pg1064.pdf 2008 Amendments to Executive Order 12333] {{Webarchive|url=https://web.archive.org/web/20181113014752/https://www.gpo.gov/fdsys/pkg/WCPD-2008-08-04/pdf/WCPD-2008-08-04-Pg1064.pdf |date=2018-11-13 }}, United States Intelligence Activities, July 30, 2008 (PDF) The NSA has roughly 32,000 employees.{{cite news |url=https://www.npr.org/templates/story/story.php?storyId=5176847&t=1631649030521 |date=January 29, 2006 |access-date=September 15, 2021 |first1=Daniel |last1=Schorr |work=NPR |title=A Brief History of the NSA |archive-date=September 15, 2021 |archive-url=https://web.archive.org/web/20210915132002/https://www.npr.org/templates/story/story.php?storyId=5176847&t=1631649030521 |url-status=live }}
Originating as a unit to decipher coded communications in World War II, it was officially formed as the NSA by President Harry S. Truman in 1952. Between then and the end of the Cold War, it became the largest of the U.S. intelligence organizations in terms of personnel and budget. Still, information available as of 2013 indicates that the Central Intelligence Agency (CIA) pulled ahead in this regard, with a budget of $14.7 billion.Bamford, James. Body of Secrets: Anatomy of the Ultra-Secret National Security Agency, Random House Digital, Inc., December 18, 2007 The NSA currently conducts worldwide mass data collection and has been known to physically bug electronic systems as one method to this end.Malkin, Bonnie. "NSA surveillance: US bugged EU offices". The Daily Telegraph, June 30, 2013. The NSA is also alleged to have been behind such attack software as Stuxnet, which severely damaged Iran's nuclear program.Ngak, Chenda. [https://www.cbsnews.com/news/nsa-leaker-snowden-claimed-us-and-israel-co-wrote-stuxnet-virus/ "NSA leaker Snowden claimed U.S. and Israel co-wrote Stuxnet virus"] {{Webarchive|url=https://web.archive.org/web/20240512124937/https://www.cbsnews.com/news/nsa-leaker-snowden-claimed-us-and-israel-co-wrote-stuxnet-virus/ |date=2024-05-12 }}, CBS, July 9, 2013{{cite magazine |last=Bamford|first=James|url=https://www.wired.com/threatlevel/?p=58188|title=The Secret War |archive-url=https://web.archive.org/web/20140125144725/http://www.wired.com/threatlevel/?p=58188|magazine=Wired |date=June 12, 2013|archive-date=January 25, 2014}} The NSA, alongside the CIA, maintains a physical presence in many countries across the globe; the CIA/NSA joint Special Collection Service (a highly classified intelligence team) inserts eavesdropping devices in high-value targets (such as presidential palaces or embassies). SCS collection tactics allegedly encompass "close surveillance, burglary, wiretapping, [and] breaking".{{cite news |last=Lichtblau |first=Eric |author-link=Eric Lichtblau |title=Spy Suspect May Have Revealed U.S. Bugging; Espionage: Hanssen left signs that he told Russia where top-secret overseas eavesdropping devices are placed, officials say |newspaper=Los Angeles Times |date=February 28, 2001 |page=A1 |url=http://www.latimes.com/news/nation/updates2/lat_spy010228.htm |archive-date=April 17, 2001 |url-status=dead |archive-url=https://web.archive.org/web/20010417230720/http://www.latimes.com/news/nation/updates2/lat_spy010228.htm |access-date=April 1, 2015 }}
Unlike the CIA and the Defense Intelligence Agency (DIA), both of which specialize primarily in foreign human espionage, the NSA does not publicly conduct human intelligence gathering. The NSA is entrusted with assisting with and coordinating, SIGINT elements for other government organizations—which Executive Order prevents from engaging in such activities on their own.Executive Order 13470 – [http://www.gpo.gov/fdsys/pkg/WCPD-2008-08-04/pdf/WCPD-2008-08-04-Pg1064.pdf 2008 Amendments to Executive Order 12333] {{Webarchive|url=https://web.archive.org/web/20181113014752/https://www.gpo.gov/fdsys/pkg/WCPD-2008-08-04/pdf/WCPD-2008-08-04-Pg1064.pdf |date=2018-11-13 }}, United States Intelligence Activities, Section C.2, July 30, 2008 As part of these responsibilities, the agency has a co-located organization called the Central Security Service (CSS), which facilitates cooperation between the NSA and other U.S. defense cryptanalysis components. To further ensure streamlined communication between the signals intelligence community divisions, the NSA Director simultaneously serves as the Commander of the United States Cyber Command and as Chief of the Central Security Service.
The NSA's actions have been a matter of political controversy on several occasions, including its role in providing intelligence during the Gulf of Tonkin incident, which contributed to the escalation of U.S. involvement in the Vietnam War.{{Cite news |last=Shane |first=Scott |date=2005-10-31 |title=Vietnam Study, CastingDoubts, Remains Secret |url=https://www.nytimes.com/2005/10/31/politics/vietnam-study-castingdoubts-remains-secret.html |access-date=2025-02-02 |work=The New York Times |language=en-US |issn=0362-4331}} Declassified documents later revealed that the NSA misinterpreted or overstated signals intelligence, leading to reports of a second North Vietnamese attack that likely never occurred.{{Cite news |date=2018-08-29 |title=Matthew M. Aid, independent researcher who wrote a history of the NSA, dies at 60 |url=https://www.washingtonpost.com/local/obituaries/matthew-m-aid-independent-researcher-who-wrote-a-history-of-the-nsa-dies-at-60/2018/08/28/31f99e98-aad6-11e8-b1da-ff7faa680710_story.html |access-date=2025-02-02 |newspaper=The Washington Post}} The agency has also received scrutiny for spying on anti–Vietnam War leaders and the agency's participation in economic espionage. In 2013, the NSA had many of its secret surveillance programs revealed to the public by Edward Snowden, a former NSA contractor. According to the leaked documents, the NSA intercepts and stores the communications of over a billion people worldwide, including United States citizens. The documents also revealed that the NSA tracks hundreds of millions of people's movements using cell phones metadata. Internationally, research has pointed to the NSA's ability to surveil the domestic Internet traffic of foreign countries through "boomerang routing".{{cite conference |last1=Obar |first1=Jonathan A. |last2=Clement |first2=Andrew |title=Internet Surveillance and Boomerang Routing: A Call for Canadian Network Sovereignty |editor1-last=Ross |editor1-first=P. |editor2-last=Shtern |editor2-first=J. |conference=TEM 2013: Proceedings of the Technology & Emerging Media Track – Annual Conference of the Canadian Communication Association |location=Victoria, British Columbia |orig-year=June 5–7, 2012 |date=July 1, 2013 |ssrn=2311792 |doi=10.2139/ssrn.2311792}}
History
= Formation =
The origins of the National Security Agency can be traced back to April 28, 1917, three weeks after the U.S. Congress declared war on Germany in World War I. A code and cipher decryption unit was established as the Cable and Telegraph Section, which was also known as the Cipher Bureau.{{cite web |date=2021-08-20 |title=The Black Chamber |url=https://www.nsa.gov/History/Cryptologic-History/Historical-Events/Article-View/Article/2740622/the-black-chamber/ |access-date=23 February 2018 |website=nsa.gov |archive-date=2021-11-04 |archive-url=https://web.archive.org/web/20211104224840/https://www.nsa.gov/History/Cryptologic-History/Historical-Events/Article-View/Article/2740622/the-black-chamber/ |url-status=live }} It was headquartered in Washington, D.C., and was part of the war effort under the executive branch without direct congressional authorization. During the war, it was relocated in the army's organizational chart several times. On July 5, 1917, Herbert O. Yardley was assigned to head the unit. At that point, the unit consisted of Yardley and two civilian clerks. It absorbed the Navy's cryptanalysis functions in July 1918. World War I ended on November 11, 1918, and the army cryptographic section of Military Intelligence (MI-8) moved to New York City on May 20, 1919, where it continued intelligence activities as the Code Compilation Company under the direction of Yardley.{{cite web |title=Records of the National Security Agency/Central Security Service [NSA/CSS] |url=https://www.archives.gov/research/guide-fed-records/groups/457.html |access-date=November 22, 2013 |website=National Archives |archive-date=October 14, 2006 |archive-url=https://web.archive.org/web/20061014140149/http://www.archives.gov/research/guide-fed-records/groups/457.html |url-status=live }}{{cite web|url=https://www.nsa.gov/news-features/declassified-documents/cryptologic-spectrum/assets/files/many_lives.pdf|title=The Many Lives of Herbert O. Yardley|access-date=May 26, 2016|archive-date=July 1, 2016|archive-url=https://web.archive.org/web/20160701195112/https://www.nsa.gov/news-features/declassified-documents/cryptologic-spectrum/assets/files/many_lives.pdf|url-status=live}}
= The Black Chamber =
{{Main|Black Chamber}}
After the disbandment of the U.S. Army cryptographic section of military intelligence known as MI-8, the U.S. government created the Cipher Bureau, also known as Black Chamber, in 1919. The Black Chamber was the United States' first peacetime cryptanalytic organization.{{cite book |last=Yardley |first=Herbert O. |title=The American Black Chamber |publisher=Naval Institute Press |year=1931 |isbn=978-1-59114-989-7 |location=Annapolis, MD}} Jointly funded by the Army and the State Department, the Cipher Bureau was disguised as a New York City commercial code company; it produced and sold such codes for business use. Its true mission, however, was to break the communications (chiefly diplomatic) of other nations. At the Washington Naval Conference, it aided American negotiators by providing them with the decrypted traffic of many of the conference delegations, including the Japanese. The Black Chamber successfully persuaded Western Union, the largest U.S. telegram company at the time, as well as several other communications companies, to illegally give the Black Chamber access to cable traffic of foreign embassies and consulates.{{cite news|last=James Bamford|title=Building America's secret surveillance state|url=http://blogs.reuters.com/great-debate/2013/06/10/building-americas-secret-surveillance-state/|archive-url=https://web.archive.org/web/20130613121507/http://blogs.reuters.com/great-debate/2013/06/10/building-americas-secret-surveillance-state/|url-status=dead|archive-date=June 13, 2013|work=Reuters|access-date=November 9, 2013}} Soon, these companies publicly discontinued their collaboration. Despite the Chamber's initial successes, it was shut down in 1929 by U.S. Secretary of State Henry L. Stimson, who defended his decision by stating, "Gentlemen do not read each other's mail."{{cite book|last1=Hastedt|first1=Glenn P.|title=Spies, wiretaps, and secret operations: An encyclopedia of American espionage|year=2009|publisher=ABC-CLIO|isbn=978-1-85109-807-1|page=32|author2=Guerrier, Steven W.}}
= World War II and its aftermath =
During World War II, the Signal Intelligence Service (SIS) was created to intercept and decipher the communications of the Axis powers.{{cite web |title=Army Security Agency Established, 15 September 1945 |url=https://www.army.mil/article/110544/ |author=USAICoE History Office |website=army.mil |date=6 September 2013 |publisher=United States Army |access-date=November 9, 2013 |url-status=live |archive-url=https://web.archive.org/web/20200716133448/https://www.army.mil/article/110544/ |archive-date=July 16, 2020}} When the war ended, the SIS was reorganized as the Army Security Agency (ASA), and it was placed under the leadership of the Director of Military Intelligence.
On May 20, 1949, all cryptologic activities were centralized under a national organization called the Armed Forces Security Agency (AFSA). This organization was originally established within the U.S. Department of Defense under the command of the Joint Chiefs of Staff.{{cite web |title=The Origins of the National Security Agency 1940–1952 (U)|last=Burns |first=Thomas L. |publisher=National Security Agency |url=https://nsarchive2.gwu.edu/NSAEBB/NSAEBB278/02.PDF |website=gwu.edu |access-date=November 28, 2020 |page=60 |url-status=live |archive-url=https://web.archive.org/web/20201129024035/https://nsarchive2.gwu.edu/NSAEBB/NSAEBB278/02.PDF |archive-date=November 29, 2020}} The AFSA was tasked with directing the Department of Defense communications and electronic intelligence activities, except those of U.S. military intelligence units. However, the AFSA was unable to centralize communications intelligence and failed to coordinate with civilian agencies that shared its interests, such as the Department of State, the Central Intelligence Agency (CIA) and the Federal Bureau of Investigation (FBI). In December 1951, President Harry S. Truman ordered a panel to investigate how AFSA had failed to achieve its goals. The results of the investigation led to improvements and its redesignation as the National Security Agency.{{cite web |title=The Creation of NSA – Part 2 of 3: The Brownell Committee |url=https://www.nsa.gov/public_info/_files/crypto_almanac_50th/The_Creation_of_NSA_Part_3.pdf |website=nsa.gov |publisher=National Security Agency |access-date=July 2, 2013 |url-status=dead |archive-url=https://web.archive.org/web/20130918015612/http://www.nsa.gov/public_info/_files/crypto_almanac_50th/The_Creation_of_NSA_Part_3.pdf |archive-date=September 18, 2013 }}
The National Security Council issued a memorandum of October 24, 1952, that revised National Security Council Intelligence Directive (NSCID) 9. On the same day, Truman issued a second memorandum that called for the establishment of the NSA.{{cite web |title=Memorandum |author=Truman, Harry S. |url=https://www.nsa.gov/public_info/_files/truman/truman_memo.pdf |website=nsa.gov |publisher=National Security Agency |date=October 24, 1952 |access-date=July 2, 2013 |url-status=dead |archive-url=https://web.archive.org/web/20130821073605/http://www.nsa.gov/public_info/_files/truman/truman_memo.pdf |archive-date=August 21, 2013 }} The actual establishment of the NSA was done by a November 4 memo by Robert A. Lovett, the Secretary of Defense, changing the name of the AFSA to the NSA, and making the new agency responsible for all communications intelligence.{{cite web |first=Thomas L. |last=Burns |url=https://www.nsa.gov/public_info/_files/cryptologic_histories/origins_of_nsa.pdf |title=The Origins of the National Security Agency |year=1990 |publisher=National Security Agency |series=United States Cryptologic History |volume=1 |pages=107–08 |url-status=dead |archive-url=https://web.archive.org/web/20160322122158/https://www.nsa.gov/public_info/_files/cryptologic_histories/origins_of_nsa.pdf |archive-date=2016-03-22 |df=mdy-all |access-date=2016-08-23 }} Since President Truman's memo was a classified document, the existence of the NSA was not known to the public at that time. Due to its ultra-secrecy, the U.S. intelligence community referred to the NSA as "No Such Agency".{{cite news|url=https://www.washingtonpost.com/world/national-security/no-such-agency-spies-on-the-communications-of-the-world/2013/06/06/5bcd46a6-ceb9-11e2-8845-d970ccb04497_story.html|title='No Such Agency' spies on the communications of the world|last=Anne Gearan|date=June 7, 2013|access-date=November 9, 2013|newspaper=The Washington Post|archive-date=December 25, 2013|archive-url=https://web.archive.org/web/20131225234416/http://www.washingtonpost.com/world/national-security/no-such-agency-spies-on-the-communications-of-the-world/2013/06/06/5bcd46a6-ceb9-11e2-8845-d970ccb04497_story.html|url-status=live}}
= Vietnam War =
{{Main|Project MINARET|NESTOR (encryption)}}
In the 1960s, the NSA played a key role in expanding American commitment to the Vietnam War by providing evidence of a North Vietnamese attack on the American Naval destroyer {{USS|Maddox|DD-731|6}} during the Gulf of Tonkin incident.{{cite news |first=Scott |last=Shane |title=Vietnam Study, Casting Doubts, Remains Secret |url=https://www.nytimes.com/2005/10/31/politics/31war.html |newspaper=The New York Times |date=October 31, 2005 |quote=The National Security Agency has kept secret since 2001 a finding by an agency historian that during the Tonkin Gulf episode, which helped precipitate the Vietnam War |access-date=June 7, 2024 |archive-date=March 28, 2015 |archive-url=https://web.archive.org/web/20150328104601/http://www.nytimes.com/2005/10/31/politics/31war.html |url-status=live }} A secret operation, code-named "MINARET", was set up by the NSA to monitor the phone communications of Senators Frank Church and Howard Baker, as well as key leaders of the civil rights movement, including Martin Luther King Jr., and prominent U.S. journalists and athletes who criticized the Vietnam War.[https://www.theguardian.com/world/2013/sep/26/nsa-surveillance-anti-vietnam-muhammad-ali-mlk "Declassified NSA Files Show Agency Spied on Muhammad Ali and MLK Operation Minaret Set Up in the 1960s to Monitor Anti-Vietnam Critics, Branded 'Disreputable If Not Outright Illegal' by NSA Itself"] {{Webarchive|url=https://web.archive.org/web/20130926154853/http://www.theguardian.com/world/2013/sep/26/nsa-surveillance-anti-vietnam-muhammad-ali-mlk |date=2013-09-26 }} The Guardian, September 26, 2013 However, the project turned out to be controversial, and an internal review by the NSA concluded that its Minaret program was "disreputable if not outright illegal".
The NSA has mounted a major effort to secure tactical communications among U.S. armed forces during the war with mixed success. The NESTOR family of compatible secure voice systems it developed was widely deployed during the Vietnam War, with about 30,000 NESTOR sets produced. However, a variety of technical and operational problems limited their use, allowing the North Vietnamese to exploit and intercept U.S. communications.{{Cite book|last=Boak|first=David G.|title=A History of U.S. Communications Security; the David G. Boak Lectures, Vol. 1|orig-year=1966|url=https://www.governmentattic.org/18docs/Hist_US_COMSEC_Boak_NSA_1973u.pdf|access-date=2017-04-23|edition=2015 partial declassification|date=July 1973|publisher=U.S. National Security Agency|location=Ft. George G. Meade, MD|archive-date=2017-05-25|archive-url=https://web.archive.org/web/20170525181251/https://www.governmentattic.org/18docs/Hist_US_COMSEC_Boak_NSA_1973u.pdf|url-status=live}}
{{rp|Vol I, p.79}}
= Church Committee hearings =
{{Further|Church Committee|Watergate scandal}}
In the aftermath of the Watergate scandal, a congressional hearing in 1975 led by Senator Frank Church{{cite web|url=https://www.pbs.org/wgbh/pages/frontline/homefront/preemption/telecoms.html|title=Pre-Emption – The Nsa And The Telecoms – Spying On The Home Front – FRONTLINE – PBS|work=pbs.org|access-date=2024-06-07|archive-date=2007-05-18|archive-url=https://web.archive.org/web/20070518115305/https://www.pbs.org/wgbh/pages/frontline/homefront/preemption/telecoms.html|url-status=live}} revealed that the NSA, in collaboration with Britain's SIGINT intelligence agency, Government Communications Headquarters (GCHQ), had routinely intercepted the international communications of prominent anti-Vietnam war leaders such as Jane Fonda and Dr. Benjamin Spock.{{cite book |last=Cohen |first=Martin |title=No Holiday: 80 Places You Don't Want to Visit |location=New York |publisher=Disinformation Company Ltd |isbn=978-1-932857-29-0 |url=https://books.google.com/books?id=Pj1_-1a79kkC&q=9781932857290 |access-date=March 14, 2014|year=2006 }} The NSA tracked these individuals in a secret filing system that was destroyed in 1974.{{cite web|title=National Security Agency Tracking of U.S. Citizens – "Questionable Practices" from 1960s & 1970s|editor=William Burr|publisher=National Security Archive|url=https://nsarchive.gwu.edu/briefing-book/cybervault-intelligence-nuclear-vault/2017-09-25/national-security-agency-tracking-us|access-date=August 2, 2018|date=September 25, 2017|archive-date=January 3, 2020|archive-url=https://web.archive.org/web/20200103044145/https://nsarchive.gwu.edu/briefing-book/cybervault-intelligence-nuclear-vault/2017-09-25/national-security-agency-tracking-us|url-status=live}} Following the resignation of President Richard Nixon, there were several investigations into suspected misuse of FBI, CIA and NSA facilities. Senator Frank Church uncovered previously unknown activity, such as a CIA plot (ordered by the administration of President John F. Kennedy) to assassinate Fidel Castro.{{cite web|url=http://www.intelligence.senate.gov/pdfs94th/94755_IV.pdf|title=Book IV, Supplementary Detailed Staff Reports on Foreign and Military Intelligence (94th Congress, Senate report 94-755)|date=April 23, 1976|publisher=United States Senate Select Committee on Intelligence|access-date=June 28, 2013|page=67 (72)|url-status=dead|archive-url=https://web.archive.org/web/20130922044847/http://www.intelligence.senate.gov/pdfs94th/94755_IV.pdf|archive-date=September 22, 2013}} The investigation also uncovered NSA's wiretaps on targeted U.S. citizens.{{cite web|url=http://www.intelligence.senate.gov/pdfs94th/94755_II.pdf|title=Book II, Intelligence Activities and the Rights of Americans (94th Congress, Senate report 94-755)|date=April 26, 1976|publisher=United States Senate Select Committee on Intelligence|access-date=June 28, 2013|page=124 (108)|url-status=dead|archive-url=https://web.archive.org/web/20130521200703/https://www.intelligence.senate.gov/pdfs94th/94755_II.pdf|archive-date=May 21, 2013}} After the Church Committee hearings, the Foreign Intelligence Surveillance Act of 1978 was passed. This was designed to limit the practice of mass surveillance in the United States.{{cite web|url=https://www.pbs.org/moyers/journal/10262007/profile2.html|title=The Church Committee and FISA|date=October 26, 2007|author=Bill Moyers Journal|publisher=Public Affairs Television|access-date=June 28, 2013|archive-date=June 16, 2013|archive-url=https://web.archive.org/web/20130616003831/http://www.pbs.org/moyers/journal/10262007/profile2.html|url-status=live}}
= 1980s to 1990s =
In 1986, the NSA intercepted the communications of the Libyan government during the immediate aftermath of the Berlin discotheque bombing. The White House asserted that the NSA interception had provided "irrefutable" evidence that Libya was behind the bombing, which U.S. President Ronald Reagan cited as a justification for the 1986 United States bombing of Libya.{{cite news|last=Seymour M. Hersh|title=Target Qaddafi|url=https://www.nytimes.com/1987/02/22/magazine/target-qaddafi.html?pagewanted=all|work=The New York Times|access-date=January 12, 2014|date=February 22, 1987|archive-date=January 24, 2014|archive-url=https://web.archive.org/web/20140124070854/http://www.nytimes.com/1987/02/22/magazine/target-qaddafi.html?pagewanted=all|url-status=live}}{{cite news|last=David Wise|title=Espionage Case Pits CIA Against News Media|url=https://www.latimes.com/archives/la-xpm-1986-05-18-op-21101-story.html|work=The Los Angeles Times|access-date=January 12, 2014|date=May 18, 1986|quote=the President took an unprecedented step in discussing the content of the Libyan cables. He was, by implication, revealing that the NSA had broken the Libyan code.|archive-date=January 13, 2014|archive-url=https://web.archive.org/web/20140113125722/http://articles.latimes.com/1986-05-18/opinion/op-21101_1_news-media/2|url-status=live}}
In 1999, a multi-year investigation by the European Parliament highlighted the NSA's role in economic espionage in a report entitled 'Development of Surveillance Technology and Risk of Abuse of Economic Information'.{{cite report |author=Peggy Becker |date=October 1999 |title=Development of Surveillance Technology and Risk of Abuse of Economic Information |url=http://www.europarl.europa.eu/stoa/cms/cache/offonce/home/publications/studies?page=12 |publisher=STOA, European Parliament |page=12 |access-date=November 3, 2013 |archive-date=January 25, 2014 |archive-url=https://web.archive.org/web/20140125141702/http://www.europarl.europa.eu/stoa/cms/cache/offonce/home/publications/studies?page=12 |url-status=dead }} That year, the NSA founded the NSA Hall of Honor, a memorial at the National Cryptologic Museum in Fort Meade, Maryland. The memorial is a, "tribute to the pioneers and heroes who have made significant and long-lasting contributions to American cryptology". NSA employees must be retired for more than fifteen years to qualify for the memorial.{{cite news|author=Staff|title=NSA honors 4 in the science of codes|url=https://www.baltimoresun.com/2003/06/13/nsa-honors-4-in-the-science-of-codes/|date=June 13, 2003|work=The Baltimore Sun|publisher=Tribune Company|access-date=June 11, 2013|archive-date=June 14, 2013|archive-url=https://web.archive.org/web/20130614020759/http://articles.baltimoresun.com/2003-06-13/news/0306130156_1_cryptology-hall-of-honor-pioneers|url-status=live}}
NSA's infrastructure deteriorated in the 1990s as defense budget cuts resulted in maintenance deferrals. On January 24, 2000, NSA headquarters suffered a total network outage for three days caused by an overloaded network. Incoming traffic was successfully stored on agency servers, but it could not be directed and processed. The agency carried out emergency repairs for $3 million to get the system running again (some incoming traffic was also directed instead to Britain's GCHQ for the time being). Director Michael Hayden called the outage a "wake-up call" for the need to invest in the agency's infrastructure.{{cite book|title=Body of Secrets: Anatomy of the Ultra-Secret National Security Agency|author=James Bamford|page=454 |url=https://books.google.com/books?id=VqY4Wr3T5K4C&pg=PA454|publisher=Knopf Doubleday Publishing Group|date=2007|isbn=978-0-307-42505-8}}
In the 1990s the defensive arm of the NSA—the Information Assurance Directorate (IAD)—started working more openly; the first public technical talk by an NSA scientist at a major cryptography conference was J. Solinas' presentation on efficient Elliptic Curve Cryptography algorithms at Crypto 1997.{{cite book|last=Koblitz|first=Neal|title=Random Curves: Journeys of a Mathematician|publisher=Springer-Verlag|year=2008|page=312|isbn=9783540740773}} The IAD's cooperative approach to academia and industry culminated in its support for a transparent process for replacing the outdated Data Encryption Standard (DES) by an Advanced Encryption Standard (AES). Cybersecurity policy expert Susan Landau attributes the NSA's harmonious collaboration with industry and academia in the selection of the AES in 2000—and the Agency's support for the choice of a strong encryption algorithm designed by Europeans rather than by Americans—to Brian Snow, who was the Technical Director of IAD and represented the NSA as cochairman of the Technical Working Group for the AES competition, and Michael Jacobs, who headed IAD at the time.{{citation|last=Landau|first=Susan|title=NSA and Dual EC_DRBG: Déjà Vu All Over Again?|journal=The Mathematical Intelligencer|volume=37|issue=4|year=2015|pages=72–83|doi=10.1007/s00283-015-9543-z|s2cid=124392006}}{{rp|75}}
After the terrorist attacks of September 11, 2001, the NSA believed that it had public support for a dramatic expansion of its surveillance activities.{{cite news|last=Curtis|first=Sophie|title=Ex-NSA technical chief: How 9/11 created the surveillance state|work=The Daily Telegraph|date=13 November 2014|url=https://www.telegraph.co.uk/technology/internet-security/11221287/Ex-NSA-technical-chief-How-911-created-the-surveillance-state.html |archive-url=https://ghostarchive.org/archive/20220111/https://www.telegraph.co.uk/technology/internet-security/11221287/Ex-NSA-technical-chief-How-911-created-the-surveillance-state.html |archive-date=2022-01-11 |url-access=subscription |url-status=live}}{{cbignore}} According to Neal Koblitz and Alfred Menezes, the period when the NSA was a trusted partner with academia and industry in the development of cryptographic standards started to come to an end when, as part of the change in the NSA in the post-September 11 era, Snow was replaced as Technical Director, Jacobs retired, and IAD could no longer effectively oppose proposed actions by the offensive arm of the NSA."In 2002 Brian Snow was moved from the technical directorship of IAD to a different position within the NSA that had high status but little influence, particularly about actions that were being proposed by SIGINT; Mike Jacobs retired from the NSA the same year." {{citation|last1=Koblitz|first1=Neal|last2=Menezes|first2=Alfred J.|title=A riddle wrapped in an enigma|journal=IEEE Security & Privacy|volume=14|issue=6|year=2016|pages=34–42|doi=10.1109/MSP.2016.120|s2cid=2310733}} Footnote 9 in the full version, see {{cite web|title=A riddle wrapped in an enigma|url=https://eprint.iacr.org/2015/1018.pdf|access-date=12 April 2018|archive-date=3 December 2017|archive-url=https://web.archive.org/web/20171203040151/https://eprint.iacr.org/2015/1018.pdf|url-status=live}}
= War on Terror =
In the aftermath of the September 11 attacks, the NSA created new IT systems to deal with the flood of information from new technologies like the Internet and cell phones. ThinThread contained advanced data mining capabilities. It also had a "privacy mechanism"; surveillance was stored encrypted; decryption required a warrant. The research done under this program may have contributed to the technology used in later systems. ThinThread was canceled when Michael Hayden chose Trailblazer, which did not include ThinThread's privacy system.{{cite news|first=Siobhan|last=Gorman|title=NSA killed system that sifted phone data legally|url=http://www.baltimoresun.com/news/nationworld/bal-te.nsa18may18,1,5386811.story|work=The Baltimore Sun|publisher=Tribune Company (Chicago, IL)|date=May 17, 2006|access-date=March 7, 2008|quote=The privacy protections offered by ThinThread were also abandoned in the post–September 11 push by the president for a faster response to terrorism.|archive-url=https://web.archive.org/web/20070927193047/http://www.baltimoresun.com/news/nationworld/bal-te.nsa18may18%2C1%2C5386811.story?ctrack=1&cset=true|archive-date=September 27, 2007|url-status=dead}}
Trailblazer Project ramped up in 2002 and was worked on by Science Applications International Corporation (SAIC), Boeing, Computer Sciences Corporation, IBM, and Litton Industries. Some NSA whistleblowers complained internally about major problems surrounding Trailblazer. This led to investigations by Congress and the NSA and DoD Inspectors General. The project was canceled in early 2004. Turbulence started in 2005. It was developed in small, inexpensive "test" pieces, rather than one grand plan like Trailblazer. It also included offensive cyber-warfare capabilities, like injecting malware into remote computers. Congress criticized Turbulence in 2007 for having similar bureaucratic problems as Trailblazer.Bamford, Shadow Factory, pp. 325–340. It was to be a realization of information processing at higher speeds in cyberspace.{{cite web|url=http://www.baltimoresun.com/news/nation-world/bal-nsa050607,0,1517618.story|title=Management shortcomings seen at NSA|author=Baltimore Sun|date=May 6, 2007|work=baltimoresun.com|access-date=January 31, 2013|archive-date=April 22, 2013|archive-url=https://web.archive.org/web/20130422092946/http://www.baltimoresun.com/news/nation-world/bal-nsa050607,0,1517618.story|url-status=dead}}
= Global surveillance program disclosures =
{{Main|Global surveillance disclosures (2013–present)|l2=|selfref=}}
The massive extent of the NSA's spying, both foreign and domestic, was revealed to the public in a series of detailed disclosures of internal NSA documents beginning in June 2013. Most of the disclosures were leaked by former NSA contractor Edward Snowden. On 4 September 2020, the NSA's surveillance program was ruled unlawful by the US Court of Appeals. The court also added that the US intelligence leaders, who publicly defended it, were not telling the truth.{{cite news|url=https://www.bbc.com/news/technology-54013527|title=NSA surveillance exposed by Snowden ruled unlawful|work=BBC News|date=3 September 2020|access-date=4 September 2020|archive-date=3 September 2020|archive-url=https://web.archive.org/web/20200903213041/https://www.bbc.com/news/technology-54013527|url-status=live}}
Mission
{{Global surveillance}}
NSA's eavesdropping mission includes radio broadcasting, both from various organizations and individuals, the Internet, telephone calls, and other intercepted forms of communication. Its secure communications mission includes military, diplomatic, and all other sensitive, confidential, or secret government communications.{{cite news|author=Bamford, James|title=The Agency That Could Be Big Brother|date=December 25, 2005|url=https://www.nytimes.com/2005/12/25/weekinreview/25bamford.html|work=The New York Times|access-date=September 11, 2005|archive-date=February 3, 2012|archive-url=https://web.archive.org/web/20120203174620/http://www.nytimes.com/2005/12/25/weekinreview/25bamford.html|url-status=live}}
According to a 2010 article in The Washington Post, "every day, collection systems at the National Security Agency intercept and store 1.7 billion e-mails, phone calls and other types of communications. The NSA sorts a fraction of those into 70 separate databases."{{cite news|author=Dana Priest, William Arkin|author-link=Dana Priest|url=http://projects.washingtonpost.com/top-secret-america/articles/a-hidden-world-growing-beyond-control/print/|title=A hidden world, growing beyond control|newspaper=The Washington Post|date=July 19, 2010|access-date=April 12, 2015|archive-date=May 15, 2013|archive-url=https://web.archive.org/web/20130515105106/http://projects.washingtonpost.com/top-secret-america/articles/a-hidden-world-growing-beyond-control/print/|url-status=dead}}
Because of its listening task, NSA/CSS has been heavily involved in cryptanalytic research, continuing the work of predecessor agencies which had broken many World War II codes and ciphers (see, for instance, Purple, Venona project, and JN-25). In 2004, NSA Central Security Service and the National Cyber Security Division of the Department of Homeland Security (DHS) agreed to expand the NSA Centers of Academic Excellence in Information Assurance Education Program.{{cite press release|title=National Security Agency and the U.S. Department of Homeland Security Form New Partnership to Increase National Focus on Cyber Security Education|url=https://www.nsa.gov/public_info/press_room/2004/nsa_dhs_new_partnership.shtml|publisher=NSA Public and Media Affairs|access-date=July 4, 2008|date=April 22, 2004|archive-url=https://web.archive.org/web/20090117020321/http://www.nsa.gov/public_info/press_room/2004/nsa_dhs_new_partnership.shtml|archive-date=2009-01-17|url-status=dead}}
As part of the National Security Presidential Directive 54/Homeland Security Presidential Directive 23 (NSPD 54), signed on January 8, 2008, by President Bush, the NSA became the lead agency to monitor and protect all of the federal government's computer networks from cyber-terrorism.{{cite news|url=https://www.washingtonpost.com/wp-dyn/content/article/2008/01/25/AR2008012503261_pf.html|title=Bush Order Expands Network Monitoring: Intelligence Agencies to Track Intrusions|author=Ellen Nakashima|newspaper=The Washington Post|date=January 26, 2008|access-date=February 9, 2008|archive-date=June 24, 2017|archive-url=https://web.archive.org/web/20170624233529/http://www.washingtonpost.com/wp-dyn/content/article/2008/01/25/AR2008012503261_pf.html|url-status=live}} A part of the NSA's mission is to serve as a combat support agency for the Department of Defense.{{cite web |url=https://www.nsa.gov/About/Mission-Combat-Support/ |title=Mission & Combat Support |website=www.nsa.gov |access-date=2022-01-21 |archive-date=2022-01-19 |archive-url=https://web.archive.org/web/20220119205828/https://www.nsa.gov/About/Mission-Combat-Support/ |url-status=live }}
Operations
Operations by the National Security Agency can be divided into three types:
- Collection overseas, which falls under the responsibility of the Global Access Operations (GAO) division.
- Domestic collection, which falls under the responsibility of the Special Source Operations (SSO) division.
- Hacking operations, which fall under the responsibility of the Tailored Access Operations (TAO) division.
= Collection overseas =
== Echelon ==
{{Main|ECHELON}}
"Echelon" was created in the incubator of the Cold War.{{cite book|publisher=Craig Potton Publishing|title=Secret Power: New Zealand's Role in the International Spy Network|last=Hager|first=Nicky|year=1996|page=55|isbn=978-0-908802-35-7}} Today it is a legacy system, and several NSA stations are closing. NSA/CSS, in combination with the equivalent agencies in the United Kingdom (Government Communications Headquarters), Canada (Communications Security Establishment), Australia (Australian Signals Directorate), and New Zealand (Government Communications Security Bureau), otherwise known as the UKUSA group,Richelson, Jeffrey T.; Ball, Desmond (1985). The Ties That Bind: Intelligence Cooperation Between the UKUSA Countries. London: Allen & Unwin. {{ISBN|0-04-327092-1}} was reported to be in command of the operation of the so-called ECHELON system. Its capabilities were suspected to include the ability to monitor a large proportion of the world's transmitted civilian telephone, fax, and data traffic.Patrick S. Poole, Echelon: America's Secret Global Surveillance Network (Washington, D.C.: Free Congress Foundation, October 1998)
During the early 1970s, the first of what became more than eight large satellite communications dishes were installed at Menwith Hill.[http://www.cbsnews.com/news/ex-snoop-confirms-echelon-network/ Echelon"] {{Webarchive|url=https://web.archive.org/web/20140120020809/http://www.cbsnews.com/news/ex-snoop-confirms-echelon-network/ |date=2014-01-20 }}, 60 Minutes, February 27, 2000 Investigative journalist Duncan Campbell reported in 1988 on the "ECHELON" surveillance program, an extension of the UKUSA Agreement on global signals intelligence SIGINT, and detailed how the eavesdropping operations worked.{{Cite news|last=Campbell|first=Duncan|author-link=Duncan Campbell (journalist)|title=They've Got It Taped|newspaper=New Statesman via duncancampbell.org|date=August 12, 1988|url=http://www.duncancampbell.org/menu/journalism/newstatesman/newstatesman-1988/They%27ve%20got%20it%20taped.pdf|access-date=June 19, 2007|archive-url=https://web.archive.org/web/20130614020755/http://www.duncancampbell.org/menu/journalism/newstatesman/newstatesman-1988/They%27ve%20got%20it%20taped.pdf|archive-date=June 14, 2013|url-status=dead}} On November 3, 1999, the BBC reported that they had confirmation from the Australian Government of the existence of a powerful "global spying network" code-named Echelon, that could "eavesdrop on every single phone call, fax or e-mail, anywhere on the planet" with Britain and the United States as the chief protagonists. They confirmed that Menwith Hill was "linked directly to the headquarters of the US National Security Agency (NSA) at Fort Meade in Maryland".{{cite news|first=Andrew|last=Bomford|date=November 3, 1999|title=Echelon spy network revealed|publisher=BBC|url=http://news.bbc.co.uk/2/hi/503224.stm|access-date=June 7, 2013|archive-date=June 14, 2013|archive-url=https://web.archive.org/web/20130614020758/http://news.bbc.co.uk/2/hi/503224.stm|url-status=live}} NSA's United States Signals Intelligence Directive 18 (USSID 18) strictly prohibited the interception or collection of information about "... U.S. persons, entities, corporations or organizations...." without explicit written legal permission from the United States Attorney General when the subject is located abroad, or the Foreign Intelligence Surveillance Court when within U.S. borders. Alleged Echelon-related activities, including its use for motives other than national security, including political and industrial espionage, received criticism from countries outside the UKUSA alliance.{{cite web|url=https://fas.org/irp/program/process/rapport_echelon_en.pdf|title=European Parliament Report on Echelon|date=July 2001|access-date=July 4, 2008|archive-date=June 28, 2019|archive-url=https://web.archive.org/web/20190628043116/https://fas.org/irp/program/process/rapport_echelon_en.pdf|url-status=live}}
File:Berlin 2013 PRISM Demo.jpg wearing Chelsea Manning and Edward Snowden masks]]
== Other SIGINT overseas operations ==
The NSA was also involved in planning to blackmail people with "SEXINT", intelligence gained about a potential target's sexual activity and preferences. Those targeted had not committed any apparent crime nor were they charged with one.{{cite news|title=Top-Secret Documents Reveal NSA Spied on Porn Habits as Part of Plan to Discredit 'Radicalizers'|url=http://www.huffingtonpost.com/2013/11/26/nsa-porn-muslims_n_4346128.html?1385526024|access-date=May 6, 2014|newspaper=The Huffington Post|date=November 26, 2013|author=Glenn Greenwald|location=London|archive-date=July 4, 2014|archive-url=https://web.archive.org/web/20140704223727/http://www.huffingtonpost.com/2013/11/26/nsa-porn-muslims_n_4346128.html?1385526024|url-status=live}} To support its facial recognition program, the NSA is intercepting "millions of images per day".{{cite news|author1=James Risen|author2=Laura Poitras|title=N.S.A. Collecting Millions of Faces From Web Images|url=https://www.nytimes.com/2014/06/01/us/nsa-collecting-millions-of-faces-from-web-images.html|access-date=June 1, 2014|newspaper=The New York Times|date=May 31, 2014|archive-date=June 1, 2014|archive-url=https://web.archive.org/web/20140601084735/http://www.nytimes.com/2014/06/01/us/nsa-collecting-millions-of-faces-from-web-images.html|url-status=live}} The Real Time Regional Gateway is a data collection program introduced in 2005 in Iraq by the NSA during the Iraq War that consisted of gathering all electronic communication, storing it, then searching and otherwise analyzing it. It was effective in providing information about Iraqi insurgents who had eluded less comprehensive techniques.{{cite news|title=For NSA chief, terrorist threat drives passion to 'collect it all,' observers say|url=https://www.washingtonpost.com/world/national-security/for-nsa-chief-terrorist-threat-drives-passion-to-collect-it-all/2013/07/14/3d26ef80-ea49-11e2-a301-ea5a8116d211_story.html|access-date=July 15, 2013|newspaper=The Washington Post|date=July 14, 2013|author=Ellen Nakashima|author2=Joby Warrick|quote=Collect it all, tag it, store it. . . . And whatever it is you want, you go searching for it.|archive-date=March 1, 2017|archive-url=https://web.archive.org/web/20170301114727/https://www.washingtonpost.com/world/national-security/for-nsa-chief-terrorist-threat-drives-passion-to-collect-it-all/2013/07/14/3d26ef80-ea49-11e2-a301-ea5a8116d211_story.html|url-status=live}} This "collect it all" strategy introduced by NSA director, Keith B. Alexander, is believed by Glenn Greenwald of The Guardian to be the model for the comprehensive worldwide mass archiving of communications which NSA is engaged in as of 2013.{{cite news|title=The crux of the NSA story in one phrase: 'collect it all': The actual story that matters is not hard to see: the NSA is attempting to collect, monitor, and store all forms of human communication|url=https://www.theguardian.com/commentisfree/2013/jul/15/crux-nsa-collect-it-all|access-date=July 16, 2013|newspaper=The Guardian|date=July 15, 2013|author=Glenn Greenwald|archive-date=March 10, 2017|archive-url=https://web.archive.org/web/20170310132541/https://www.theguardian.com/commentisfree/2013/jul/15/crux-nsa-collect-it-all|url-status=live}}
A dedicated unit of the NSA locates targets for the CIA for extrajudicial assassination in the Middle East.Greg Miller and Julie Tate, October 17, 2013, "[https://www.washingtonpost.com/world/national-security/documents-reveal-nsas-extensive-involvement-in-targeted-killing-program/2013/10/16/29775278-3674-11e3-8a0e-4e2cf80831fc_story.html Documents reveal NSA's extensive involvement in targeted killing program] {{Webarchive|url=https://web.archive.org/web/20170823063930/https://www.washingtonpost.com/world/national-security/documents-reveal-nsas-extensive-involvement-in-targeted-killing-program/2013/10/16/29775278-3674-11e3-8a0e-4e2cf80831fc_story.html |date=2017-08-23 }}", The Washington Post. Retrieved October 18, 2013. The NSA has also spied extensively on the European Union, the United Nations, and numerous governments including allies and trading partners in Europe, South America, and Asia.Laura Poitras, Marcel Rosenbach, Fidelius Schmid und Holger Stark. "[http://www.spiegel.de/netzwelt/netzpolitik/nsa-hat-wanzen-in-eu-gebaeuden-installiert-a-908515.html Geheimdokumente: NSA horcht EU-Vertretungen mit Wanzen aus] {{Webarchive|url=https://web.archive.org/web/20240518182038/https://www.spiegel.de/netzwelt/netzpolitik/nsa-hat-wanzen-in-eu-gebaeuden-installiert-a-908515.html |date=2024-05-18 }}". Der Spiegel (in German). Retrieved June 29, 2013."[http://www.spiegel.de/politik/ausland/nsa-hoerte-zentrale-der-vereinte-nationen-in-new-york-ab-a-918421.html US-Geheimdienst hörte Zentrale der Vereinten Nationen ab] {{Webarchive|url=https://web.archive.org/web/20240512130608/https://www.spiegel.de/politik/ausland/nsa-hoerte-zentrale-der-vereinte-nationen-in-new-york-ab-a-918421.html |date=2024-05-12 }}". Der Spiegel (in German). Retrieved August 25, 2013. In June 2015, WikiLeaks published documents showing that NSA spied on French companies.[http://www.spiegel.de/politik/ausland/wikileaks-enthuellung-nsa-soll-auch-franzoesische-wirtschaft-bespitzelt-haben-a-1041268.html Spiegel.de: Wikileaks-Enthüllung, NSA soll auch französische Wirtschaft bespizelt haben (German)] {{Webarchive|url=https://web.archive.org/web/20160919202253/http://www.spiegel.de/politik/ausland/wikileaks-enthuellung-nsa-soll-auch-franzoesische-wirtschaft-bespitzelt-haben-a-1041268.html |date=2016-09-19 }}, June 2015 WikiLeaks also published documents showing that NSA spied on federal German ministries since the 1990s.{{cite web|url=https://www.handelsblatt.com/politik/deutschland/wikileaks-und-taeglich-gruesst-die-nsa/12034888.html|title=Wikileaks: Und täglich grüßt die NSA|author=|date=July 9, 2015|website=Handelsblatt.com|access-date=March 10, 2017|archive-date=October 18, 2017|archive-url=https://web.archive.org/web/20171018075016/https://www.handelsblatt.com/politik/deutschland/wikileaks-und-taeglich-gruesst-die-nsa/12034888.html|url-status=dead}}{{Cite web|url=https://www.sueddeutsche.de/politik/nsa-skanal-us-spionage-ist-eine-demuetigung-fuer-deutschland-1.2558131|title=US-Spionage ist eine Demütigung für Deutschland|first=Tanjev|last=Schultz|website=Süddeutsche.de|date=9 July 2015|access-date=23 February 2022|archive-date=23 February 2022|archive-url=https://web.archive.org/web/20220223192449/https://www.sueddeutsche.de/politik/nsa-skanal-us-spionage-ist-eine-demuetigung-fuer-deutschland-1.2558131|url-status=live}} Even Germany's Chancellor Angela Merkel's cellphones and phones of her predecessors had been intercepted.{{cite news|url=https://www.theguardian.com/us-news/2015/jul/08/nsa-tapped-german-chancellery-decades-wikileaks-claims-merkel|title=NSA tapped German Chancellery for decades, WikiLeaks claims|agency=Reuters|date=8 July 2015 |work=The Guardian}}
== Boundless Informant ==
In June 2013, Edward Snowden revealed that between 8th February and 8th March 2013, the NSA collected about 124.8 billion telephone data items and 97.1 billion computer data items throughout the world, as was displayed in charts from an internal NSA tool codenamed Boundless Informant. Initially, it was reported that some of these data reflected eavesdropping on citizens in countries like Germany, Spain, and France,[http://www.lemonde.fr/technologies/article/2013/10/21/france-in-the-nsa-s-crosshair-phone-networks-under-surveillance_3499741_651865.html France in the NSA's crosshair: phone networks under surveillance] {{Webarchive|url=https://web.archive.org/web/20240512131834/https://www.lemonde.fr/technologies/article/2013/10/21/france-in-the-nsa-s-crosshair-phone-networks-under-surveillance_3499741_651865.html |date=2024-05-12 }} Le Monde October 21, 2013 but later on, it became clear that those data were collected by European agencies during military missions abroad and were subsequently shared with NSA.
== Bypassing encryption ==
In 2013, reporters uncovered a secret memo that claims the NSA created and pushed for the adoption of the Dual EC DRBG encryption standard that contained built-in vulnerabilities in 2006 to the United States National Institute of Standards and Technology (NIST), and the International Organization for Standardization (aka ISO).{{cite news |first=Nicole |last=Perlroth |url=http://bits.blogs.nytimes.com/2013/09/10/government-announces-steps-to-restore-confidence-on-encryption-standards/ |title=Government Announces Steps to Restore Confidence on Encryption Standards |website=The New York Times |type=Bits blog |date=September 10, 2013 |access-date=June 7, 2024 |archive-date=July 12, 2014 |archive-url=https://web.archive.org/web/20140712084931/http://bits.blogs.nytimes.com/2013/09/10/government-announces-steps-to-restore-confidence-on-encryption-standards/ |url-status=live }} This memo appears to give credence to previous speculation by cryptographers at Microsoft Research.{{cite web |url=https://www.schneier.com/blog/archives/2007/11/the_strange_sto.html |title=Schneier on Security: The Strange Story of Dual_EC_DRBG |publisher=Schneier.com |date=November 15, 2007 |access-date=October 9, 2013 |archive-date=April 23, 2019 |archive-url=https://web.archive.org/web/20190423212823/https://www.schneier.com/blog/archives/2007/11/the_strange_sto.html |url-status=live }} Edward Snowden claims that the NSA often bypasses the encryption process altogether by lifting information before encryption or after decryption.{{cite news|url=https://www.propublica.org/article/the-nsas-secret-campaign-to-crack-undermine-internet-encryption|title=The NSA's Secret Campaign to Crack, Undermine Internet Security|date=September 5, 2013|publisher=ProPublica|author=Perlroth, Nicole, Larson, Jeff, and Shane, Scott|quote=This story has been reported in partnership between The New York Times, the Guardian and ProPublica based on documents obtained by The Guardian. For the Guardian: James Ball, Julian Borger, Glenn Greenwald; For the New York Times: Nicole Perlroth, Scott Shane; For ProPublica: Jeff Larson|access-date=June 7, 2024|archive-date=February 21, 2020|archive-url=https://web.archive.org/web/20200221043243/https://www.propublica.org/article/the-nsas-secret-campaign-to-crack-undermine-internet-encryption|url-status=live}}
XKeyscore rules (as specified in a file xkeyscorerules100.txt, sourced by German TV stations NDR and WDR, who claim to have excerpts from its source code) reveal that the NSA tracks users of privacy-enhancing software tools, including Tor; an anonymous email service provided by the MIT Computer Science and Artificial Intelligence Laboratory (CSAIL) in Cambridge, Massachusetts; and readers of the Linux Journal.{{cite news |author1=J. Appelbaum |author2=A. Gibson |author3=J. Goetz |author4=V. Kabisch |author5=L. Kampf |author6=L. Ryge |title=NSA targets the privacy-conscious |url=http://daserste.ndr.de/panorama/aktuell/nsa230_page-1.html |access-date=July 4, 2014 |work=Panorama |publisher=Norddeutscher Rundfunk |date=July 3, 2014 |archive-date=July 3, 2014 |archive-url=https://web.archive.org/web/20140703215350/http://daserste.ndr.de/panorama/aktuell/nsa230_page-1.html |url-status=live }}{{cite news |author1=Lena Kampf, Jacob Appelbaum |author2=John Goetz, Norddeutscher Rundfunk |name-list-style=amp |url=https://www.tagesschau.de/inland/nsa-xkeyscore-100.html |title=Deutsche im Visier des US-Geheimdienstes: Von der NSA als Extremist brandmark |date=July 3, 2014 |publisher=ARD |language=de |access-date=June 7, 2024 |archive-date=July 3, 2014 |archive-url=https://web.archive.org/web/20140703074652/http://www.tagesschau.de/inland/nsa-xkeyscore-100.html |url-status=live }}
== Software backdoors ==
Linus Torvalds, the founder of Linux kernel, joked during a LinuxCon keynote on September 18, 2013, that the NSA, who is the founder of SELinux, wanted a backdoor in the kernel.{{cite web|url=http://www.linuxfoundation.org/news-media/news/2013/09/techweekeurope-linus-torvalds-jokes-nsa-wanted-backdoor-linux|title=TechWeekEurope: Linus Torvalds Jokes The NSA Wanted A Backdoor In Linux|work=linuxfoundation.org|url-status=dead|archive-url=https://web.archive.org/web/20150916142701/http://www.linuxfoundation.org/news-media/news/2013/09/techweekeurope-linus-torvalds-jokes-nsa-wanted-backdoor-linux|archive-date=2015-09-16|access-date=2014-05-23}} However, later, Linus' father, a Member of the European Parliament (MEP), revealed that the NSA actually did this.{{cite web|url=http://falkvinge.net/2013/11/17/nsa-asked-linus-torvalds-to-install-backdoors-into-gnulinux/|title=NSA Asked Linus Torvalds To Install Backdoors Into GNU/Linux|work=falkvinge.net|date=17 November 2013|access-date=7 June 2024|archive-date=19 May 2024|archive-url=https://web.archive.org/web/20240519085005/http://falkvinge.net/2013/11/17/nsa-asked-linus-torvalds-to-install-backdoors-into-gnulinux/|url-status=live}}
{{blockquote|When my oldest son was asked the same question: "Has he been approached by the NSA about backdoors?" he said "No", but at the same time he nodded. Then he was sort of in the legal free. He had given the right answer, everybody understood that the NSA had approached him.|Nils Torvalds|LIBE Committee Inquiry on Electronic Mass Surveillance of EU Citizens – 11th Hearing, 11 November 2013{{cite web|url=http://www.europarl.europa.eu/committees/en/libe/events.html|title=Civil Liberties, Justice and Home Affairs – Hearings|work=europa.eu|access-date=2024-06-07|archive-date=2016-09-16|archive-url=https://web.archive.org/web/20160916144242/http://www.europarl.europa.eu/committees/en/libe/events.html|url-status=live}}}} IBM Notes was the first widely adopted software product to use public key cryptography for client-server and server–server authentication and encryption of data. Until US laws regulating encryption were changed in 2000, IBM and Lotus were prohibited from exporting versions of Notes that supported symmetric encryption keys that were longer than 40 bits. In 1997, Lotus negotiated an agreement with the NSA that allowed the export of a version that supported stronger keys with 64 bits, but 24 of the bits were encrypted with a special key and included in the message to provide a "workload reduction factor" for the NSA. This strengthened the protection for users of Notes outside the US against private-sector industrial espionage, but not against spying by the US government."The Swedes discover Lotus Notes has key escrow!" The Risks Digest, Volume 19, Issue 52, December 24, 1997,Only NSA can listen, so that's OK Heise, 1999.
== Boomerang routing ==
While it is assumed that foreign transmissions terminating in the U.S. (such as a non-U.S. citizen accessing a U.S. website) subject non-U.S. citizens to NSA surveillance, recent research into boomerang routing has raised new concerns about the NSA's ability to surveil the domestic Internet traffic of foreign countries. Boomerang routing occurs when an Internet transmission that originates and terminates in a single country transits another. Research at the University of Toronto has suggested that approximately 25% of Canadian domestic traffic may be subject to NSA surveillance activities as a result of the boomerang routing of Canadian Internet service providers.
== Implanting hardware equipment ==
{{Multiple image|image1 = NSA implanting station.jpg|image2 = NSA interception.jpg|caption1 = Intercepted packages are opened carefully by NSA employees|caption2 = A "load station" implanting a beacon}}
A document included in the NSA files released with Glenn Greenwald's book No Place to Hide details how the agency's Tailored Access Operations (TAO) and other NSA units gained access to hardware equipment. They intercepted routers, servers, and other network hardware equipment being shipped to organizations targeted for surveillance and installing covert implant firmware onto them before they are delivered. This was described by an NSA manager as "some of the most productive operations in TAO because they preposition access points into hard target networks around the world."{{cite web|url=https://arstechnica.com/tech-policy/2014/05/photos-of-an-nsa-upgrade-factory-show-cisco-router-getting-implant|title=Photos of an NSA "upgrade" factory show Cisco router getting implant|last=Gallagher|first=Sean|date=May 14, 2014|website=Ars Technica|access-date=June 7, 2024|archive-date=June 4, 2024|archive-url=https://web.archive.org/web/20240604094912/https://arstechnica.com/tech-policy/2014/05/photos-of-an-nsa-upgrade-factory-show-cisco-router-getting-implant/|url-status=live}}
Computers that were seized by the NSA due to interdiction are often modified with a physical device known as Cottonmouth.{{cite web|last=Whitwam|first=Ryan|url=http://www.extremetech.com/computing/173721-the-nsa-regularly-intercepts-laptop-shipments-to-implant-malware-report-says/|title=The NSA regularly intercepts laptop shipments to implant malware report says|work=extremetech.com|date=December 30, 2013|access-date=June 7, 2024|archive-date=December 5, 2022|archive-url=https://web.archive.org/web/20221205081243/https://www.extremetech.com/computing/173721-the-nsa-regularly-intercepts-laptop-shipments-to-implant-malware-report-says|url-status=live}} It is a device that can be inserted at the USB port of a computer to establish remote access to the targeted machine. According to the NSA's Tailored Access Operations (TAO) group implant catalog, after implanting Cottonmouth, the NSA can establish a network bridge "that allows the NSA to load exploit software onto modified computers as well as allowing the NSA to relay commands and data between hardware and software implants."{{Cite web |url=http://www.spiegel.de/static/happ/netzwelt/2014/na/v1/pub/img/USB/S3223_COTTONMOUTH-I.jpg |title=Archived copy |access-date=2015-03-10 |archive-date=2015-03-10 |archive-url=https://web.archive.org/web/20150310094750/http://www.spiegel.de/static/happ/netzwelt/2014/na/v1/pub/img/USB/S3223_COTTONMOUTH-I.jpg |url-status=dead }}
= Domestic collection =
{{Further|Mass surveillance in the United States}}
NSA's mission, as outlined in Executive Order 12333 in 1981, is to collect information that constitutes "foreign intelligence or counterintelligence" while not "acquiring information concerning the domestic activities of United States persons". NSA has declared that it relies on the FBI to collect information on foreign intelligence activities within the borders of the United States while confining its activities within the United States to the embassies and missions of foreign nations.[https://www.nsa.gov/public_info/_files/speeches_testimonies/2013_08_09_the_nsa_story.pdf nsa.gov: The NSA story] {{webarchive|url=https://web.archive.org/web/20141209113543/https://www.nsa.gov/public_info/_files/speeches_testimonies/2013_08_09_the_nsa_story.pdf |date=2014-12-09 }}, Retrieved January 19, 2015 – Page 3: 'NSA ... will work with the FBI and other agencies to connect the dots between foreign-based actors and their activities in the U.S.'
The appearance of a 'Domestic Surveillance Directorate' of the NSA was soon exposed as a hoax in 2013.[https://nsa.gov1.info/ Domestic Surveillance Directorate website] {{Webarchive|url=https://web.archive.org/web/20240528223651/https://nsa.gov1.info/ |date=2024-05-28 }}, Nsa.gov1.info, Retrieved January 19, 2015[https://www.forbes.com/sites/kashmirhill/2013/08/29/the-definitive-nsa-parody-site-is-actually-informative/ The Definitive NSA Parody Site Is Actually Informative] {{Webarchive|url=https://web.archive.org/web/20240512125453/https://www.forbes.com/sites/kashmirhill/2013/08/29/the-definitive-nsa-parody-site-is-actually-informative/ |date=2024-05-12 }}, Forbes.com, Retrieved January 19, 2015 NSA's domestic surveillance activities are limited by the requirements imposed by the Fourth Amendment to the U.S. Constitution. The Foreign Intelligence Surveillance Court for example held in October 2011, citing multiple Supreme Court precedents, that the Fourth Amendment prohibitions against unreasonable searches and seizures apply to the contents of all communications, whatever the means, because "a person's private communications are akin to personal papers."{{cite web|url=https://www.eff.org/sites/default/files/filenode/fisc_opinion_-_unconstitutional_surveillance_0.pdf|pages=73–74|date=October 3, 2011|author=John D Bates|title=[redacted]|access-date=June 7, 2024|archive-date=August 24, 2013|archive-url=https://web.archive.org/web/20130824171345/https://www.eff.org/sites/default/files/filenode/fisc_opinion_-_unconstitutional_surveillance_0.pdf|url-status=live}} However, these protections do not apply to non-U.S. persons located outside of U.S. borders, so the NSA's foreign surveillance efforts are subject to far fewer limitations under U.S. law.David Alan Jordan. [https://iilj.org/documents/Jordan-47_BC_L_Rev_000.pdf Decrypting the Fourth Amendment: Warrantless NSA Surveillance and the Enhanced Expectation of Privacy Provided by Encrypted Voice over Internet Protocol] {{webarchive|url=https://web.archive.org/web/20071030095250/http://www.ss8.com/pdfs/Ready_Guide_Download_Version.pdf |date=2007-10-30 }}. Boston College Law Review. May 2006. Last access date January 23, 2007, The specific requirements for domestic surveillance operations are contained in the Foreign Intelligence Surveillance Act of 1978 (FISA), which does not extend protection to non-U.S. citizens located outside of U.S. territory.
== President's Surveillance Program ==
{{See also|NSA warrantless surveillance (2001–2007)}}
George W. Bush, president during the 9/11 terrorist attacks, approved the Patriot Act shortly after the attacks to take anti-terrorist security measures. Titles 1, 2, and 9 specifically authorized measures that would be taken by the NSA. These titles granted enhanced domestic security against terrorism, surveillance procedures, and improved intelligence, respectively. On March 10, 2004, there was a debate between President Bush and White House Counsel Alberto Gonzales, Attorney General John Ashcroft, and Acting Attorney General James Comey. The Attorneys General were unsure if the NSA's programs could be considered constitutional. They threatened to resign over the matter, but ultimately the NSA's programs continued.{{cite book|title=President George W. Bush's Influence Over Bureaucracy and Policy|last=Provost|first=Colin|publisher=Palgrave Macmillan|year=2009|isbn=978-0-230-60954-9|pages=[https://archive.org/details/presidentgeorgew0000unse/page/94 94–99]|url=https://archive.org/details/presidentgeorgew0000unse/page/94}} On March 11, 2004, President Bush signed a new authorization for mass surveillance of Internet records, in addition to the surveillance of phone records. This allowed the president to be able to override laws such as the Foreign Intelligence Surveillance Act, which protected civilians from mass surveillance. In addition to this, President Bush also signed that the measures of mass surveillance were also retroactively in place.James Risen & Eric Lichtblau (December 16, 2005), [https://www.nytimes.com/2005/12/16/politics/16program.html Bush Lets U.S. Spy on Callers Without Courts] {{Webarchive|url=https://web.archive.org/web/20150524040621/http://www.nytimes.com/2005/12/16/politics/16program.html |date=2015-05-24 }}, The New York Times
One such surveillance program, authorized by the U.S. Signals Intelligence Directive 18 of President George Bush, was the Highlander Project undertaken for the National Security Agency by the U.S. Army 513th Military Intelligence Brigade. NSA relayed telephone (including cell phone) conversations obtained from ground, airborne, and satellite monitoring stations to various U.S. Army Signal Intelligence Officers, including the 201st Military Intelligence Battalion. Conversations of citizens of the U.S. were intercepted, along with those of other nations.{{cite web |url=http://www.gwu.edu/~nsarchiv/NSAEBB/NSAEBB23/index2.html |title=Gwu.edu |publisher=Gwu.edu |access-date=October 9, 2013 |archive-date=June 2, 2010 |archive-url=https://web.archive.org/web/20100602002703/http://www.gwu.edu/~nsarchiv/NSAEBB/NSAEBB23/index2.html |url-status=live }} Proponents of the surveillance program claim that the President has executive authority to order such action{{citation needed|date=January 2022}}, arguing that laws such as FISA are overridden by the President's Constitutional powers. In addition, some argued that FISA was implicitly overridden by a subsequent statute, the Authorization for Use of Military Force, although the Supreme Court's ruling in Hamdan v. Rumsfeld deprecates this view.{{Cite journal |title=Hamdan v. Rumsfeld, Secretary of Defense, Et Al. Certiorari to the United States Court of Appeals for the District of Columbia Circuit |url=https://www.supremecourt.gov/opinions/05pdf/05-184.pdf |journal=Supreme Court of the United States |access-date=2022-03-12 |archive-date=2020-12-07 |archive-url=https://web.archive.org/web/20201207022617/https://www.supremecourt.gov/opinions/05pdf/05-184.pdf |url-status=dead }}
== The PRISM program ==
File: Prism-slide-8.jpg surveillance programs under which the NSA collects large amounts of user data from companies such as Facebook and Microsoft.]] Under the PRISM program, which started in 2007,{{cite news |url=https://www.washingtonpost.com/investigations/us-intelligence-mining-data-from-nine-us-internet-companies-in-broad-secret-program/2013/06/06/3a0c0da8-cebf-11e2-8845-d970ccb04497_story.html?hpid=z1 |title=U.S. intelligence mining data from nine U.S. Internet companies in broad secret program |newspaper=The Washington Post |date=June 7, 2013 |access-date=June 6, 2013 |first1=Barton |last1=Gellman |first2=Laura |last2=Poitras |archive-date=June 15, 2013 |archive-url=https://archive.today/20130615061900/http://www.washingtonpost.com/investigations/us-intelligence-mining-data-from-nine-us-internet-companies-in-broad-secret-program/2013/06/06/3a0c0da8-cebf-11e2-8845-d970ccb04497_story.html?hpid=z1 |url-status=live }}{{cite news|last=Greenwald|first=Glenn|title=NSA taps in to internet giants' systems to mine user data, secret files reveal|work=The Guardian|url=https://www.theguardian.com/world/2013/jun/06/us-tech-giants-nsa-data|access-date=June 6, 2013|date=June 6, 2013|location=London|archive-date=August 18, 2006|archive-url=https://web.archive.org/web/20060818114650/http://www.guardian.co.uk/world/2013/jun/06/us-tech-giants-nsa-data|url-status=live}} NSA gathers Internet communications from foreign targets from nine major U.S. Internet-based communication service providers: Microsoft,{{cite news|title=Microsoft handed the NSA access to encrypted messages|work=The Guardian|url=https://www.theguardian.com/world/2013/jul/11/microsoft-nsa-collaboration-user-data|access-date=September 7, 2013|date=July 12, 2013|archive-date=November 19, 2015|archive-url=https://web.archive.org/web/20151119014627/http://www.theguardian.com/world/2013/jul/11/microsoft-nsa-collaboration-user-data|url-status=live}} Yahoo, Google, Facebook, PalTalk, AOL, Skype, YouTube and Apple. Data gathered include email, videos, photos, VoIP chats such as Skype, and file transfers.
Former NSA director General Keith Alexander claimed that in September 2009 the NSA prevented Najibullah Zazi and his friends from carrying out a terrorist attack.{{cite book |last=Angwin |first=Julia |author-link=Julia Angwin |title=Dragnet Nation: A Quest for Privacy, Security, and Freedom in a World of Relentless Surveillance |url=https://archive.org/details/dragnetnationque0000angw|url-access=registration |year=2014 |publisher=Times Books / Henry Holt and Company |isbn=978-0-8050-9807-5 |page=[https://archive.org/details/dragnetnationque0000angw/page/47 47]}} However, no evidence has been presented demonstrating that the NSA has ever been instrumental in preventing a terrorist attack.{{cite web| url = https://www.propublica.org/article/claim-on-attacks-thwarted-by-nsa-spreads-despite-lack-of-evidence| title = Elliott, Justin and Meyer, Theodoric ProPublica. Retrieved October 7, 2016.| date = 23 October 2013| access-date = 7 June 2024| archive-date = 7 June 2024| archive-url = https://web.archive.org/web/20240607064024/https://www.propublica.org/article/claim-on-attacks-thwarted-by-nsa-spreads-despite-lack-of-evidence| url-status = live}}{{cite web|url=http://bigstory.ap.org/article/nyc-bomb-plot-details-settle-little-nsa-debate|title=Goldman, Adam and Apuzzo, Matt Associated Press. Retrieved October 7, 2016.|access-date=October 7, 2016|archive-date=July 3, 2015|archive-url=https://web.archive.org/web/20150703231925/http://bigstory.ap.org/article/nyc-bomb-plot-details-settle-little-nsa-debate|url-status=dead}}{{cite web|url=https://www.nbcnews.com/news/world/nsa-program-stopped-no-terror-attacks-says-white-house-panel-flna2D11783588|title=NSA program stopped no terror attacks, says White House panel member|website=NBC News|date=20 December 2013|access-date=7 June 2024|archive-date=21 December 2013|archive-url=https://web.archive.org/web/20131221133023/http://investigations.nbcnews.com/_news/2013/12/19/21975158-nsa-program-stopped-no-terror-attacks-says-white-house-panel-member?lite|url-status=live}}{{Cite news|url=https://www.techdirt.com/articles/20131220/11312025653/judge-intelligence-task-force-both-seem-stunned-nsa-couldnt-provide-single-example-data-collection-stopping-terrorism.shtml|title=Judge And Intelligence Task Force Both Seem Stunned By Lack Of Evidence That Bulk Phone Collection Program Stops Terrorists|last=Masnick|first=Mike|date=December 23, 2013|work=Techdirt.|access-date=2017-10-10|archive-url=https://web.archive.org/web/20161010010635/https://www.techdirt.com/articles/20131220/11312025653/judge-intelligence-task-force-both-seem-stunned-nsa-couldnt-provide-single-example-data-collection-stopping-terrorism.shtml|archive-date=October 10, 2016|url-status=dead}}
== The FASCIA database ==
FASCIA is a database created and used by the U.S. National Security Agency that contains trillions of device-location records that are collected from a variety of sources.{{cite news |author=Narayan Lakshman |date=2013-12-05 |title=NSA tracking millions of cellphones globally |url=http://www.thehindu.com/sci-tech/technology/nsa-tracking-millions-of-cellphones-globally/article5424401.ece |url-status=live |archive-url=https://web.archive.org/web/20140424062040/http://www.thehindu.com/sci-tech/technology/nsa-tracking-millions-of-cellphones-globally/article5424401.ece |archive-date=2014-04-24 |access-date=2014-03-23 |work=The Hindu }} Its existence was revealed during the 2013 global surveillance disclosure by Edward Snowden.{{cite news |author=The Washington Post |date=2013-12-04 |title=FASCIA: The NSA's huge trove of location records |url=https://apps.washingtonpost.com/g/page/world/fascia-the-nsas-huge-trove-of-location-records/637/ |url-status=live |archive-url=https://web.archive.org/web/20141101195543/http://apps.washingtonpost.com/g/page/world/fascia-the-nsas-huge-trove-of-location-records/637/ |archive-date=2014-11-01 |access-date=2014-03-23 |newspaper=The Washington Post |format=2 slides}}
The FASCIA database stores various types of information, including Location Area Codes (LACs), Cell Tower IDs (CeLLIDs), Visitor Location Registers (VLRs), International Mobile Station Equipment Identity (IMEIs) and MSISDNs (Mobile Subscriber Integrated Services Digital Network-Numbers). Over about seven months, more than 27 terabytes of location data were collected and stored in the database.{{cite news |author=The Washington Post |date=2013-12-04 |title=GHOSTMACHINE: The NSA's cloud analytics platform |url=https://apps.washingtonpost.com/g/page/world/ghostmachine-the-nsas-cloud-analytics-platform/644/ |url-status=live |archive-url=https://web.archive.org/web/20171120013152/https://apps.washingtonpost.com/g/page/world/ghostmachine-the-nsas-cloud-analytics-platform/644/ |archive-date=2017-11-20 |access-date=2014-03-23 |newspaper=The Washington Post |format=4 slides}}
= Hacking operations =
Besides the more traditional ways of eavesdropping to collect signals intelligence, the NSA is also engaged in hacking computers, smartphones, and their networks. A division that conducts such operations is the Tailored Access Operations (TAO) division, which has been active since at least circa 1998.{{cite journal|last=Aid|first=Matthew M.|title=Inside the NSA's Ultra-Secret China Hacking Group|journal=Foreign Policy|date=10 June 2013|url=https://foreignpolicy.com/2013/06/10/inside-the-nsas-ultra-secret-china-hacking-group/|access-date=11 June 2013|archive-date=12 February 2022|archive-url=https://web.archive.org/web/20220212231030/https://foreignpolicy.com/2013/06/10/inside-the-nsas-ultra-secret-china-hacking-group/|url-status=live}}
According to the Foreign Policy magazine, "... the Office of Tailored Access Operations, or TAO, has successfully penetrated Chinese computer and telecommunications systems for almost 15 years, generating some of the best and most reliable intelligence information about what is going on inside the People's Republic of China.""[http://www.businessinsider.com/us-nsa-unit-tao-hacking-china-for-years-2013-6 U.S. NSA Unit 'TAO' Hacking China For Years] {{Webarchive|url=https://web.archive.org/web/20240512132004/https://www.businessinsider.com/us-nsa-unit-tao-hacking-china-for-years-2013-6 |date=2024-05-12 }}". Business Insider. June 11, 2013"[http://www.computerworld.com/article/2473609/cybercrime-hacking/secret-nsa-hackers-from-tao-office-have-been-pwning-china-for-nearly-15-years.html Secret NSA hackers from TAO Office have been pwning China for nearly 15 years] {{Webarchive|url=https://web.archive.org/web/20180207010751/https://www.computerworld.com/article/2473609/cybercrime-hacking/secret-nsa-hackers-from-tao-office-have-been-pwning-china-for-nearly-15-years.html |date=2018-02-07 }}". Computerworld. June 11, 2013. In an interview with Wired magazine, Edward Snowden said the Tailored Access Operations division accidentally caused Syria's internet blackout in 2012."[http://www.ibtimes.com/flubbed-nsa-hack-caused-massive-2012-syrian-internet-blackout-snowden-says-1657886 Flubbed NSA Hack Caused Massive 2012 Syrian Internet Blackout, Snowden Says] {{Webarchive|url=https://web.archive.org/web/20240512123802/https://www.ibtimes.com/flubbed-nsa-hack-caused-massive-2012-syrian-internet-blackout-snowden-says-1657886 |date=2024-05-12 }}". International Business Times. August 13, 2013.
Organizational structure
File:LTG William J. Hartman (2).jpg, the acting director of the NSA]]
The NSA is led by the Director of the National Security Agency (DIRNSA), who also serves as Chief of the Central Security Service (CHCSS) and Commander of the United States Cyber Command (USCYBERCOM) and is the highest-ranking military official of these organizations. He is assisted by a Deputy Director, who is the highest-ranking civilian within the NSA/CSS. NSA also has an Inspector General, head of the Office of the Inspector General (OIG);{{Cite web |url=https://oig.nsa.gov/ |title=National Security Agency Office of the Inspector General |access-date=2024-06-07 |archive-date=2024-06-03 |archive-url=https://web.archive.org/web/20240603195905/https://oig.nsa.gov/ |url-status=live }} a General Counsel, head of the Office of the General Counsel (OGC); and a Director of Compliance, who is head of the Office of the Director of Compliance (ODOC).These offices are for example mentioned in a [http://www.dni.gov/files/documents/PrimaryOrder_Collection_215.pdf FISA court order] {{Webarchive|url=https://web.archive.org/web/20240512123342/https://www.dni.gov/files/documents/PrimaryOrder_Collection_215.pdf |date=2024-05-12 }} from 2011. The National Security Agency Office of Inspector General has worked on cases in collaboration with the United States Department of Justice and the Central Intelligence Agency Office of Inspector General.{{cite web | url=https://www.justice.gov/opa/pr/six-charged-scheme-defraud-federal-government | title=Office of Public Affairs | Six Charged in Scheme to Defraud the Federal Government | United States Department of Justice | date=29 October 2024 }} Unlike other intelligence organizations such as the CIA or DIA, the NSA has always been particularly reticent concerning its internal organizational structure.{{citation needed|date=May 2024}}
As of the mid-1990s, the National Security Agency was organized into five Directorates:
- The Operations Directorate, which was responsible for SIGINT collection and processing.
- The Technology and Systems Directorate, which develops new technologies for SIGINT collection and processing.
- The Information Systems Security Directorate, which was responsible for NSA's communications and information security missions.
- The Plans, Policy, and Programs Directorate, which provided staff support and general direction for the Agency.
- The Support Services Directorate, which provided logistical and administrative support activities.{{cite web |url=https://fas.org/irp/nsa/oldind.html |title=National Security Agency |publisher=fas.org |access-date=October 9, 2013 |archive-date=November 6, 2012 |archive-url=https://web.archive.org/web/20121106042740/https://fas.org/irp/nsa/oldind.html |url-status=live }}
Each of these directorates consisted of several groups or elements, designated by a letter. There were for example the A Group, which was responsible for all SIGINT operations against the Soviet Union and Eastern Europe, and the G Group, which was responsible for SIGINT related to all non-communist countries. These groups were divided into units designated by an additional number, like unit A5 for breaking Soviet codes, and G6, being the office for the Middle East, North Africa, Cuba, and Central and South America.Matthew M. Aid, The Secret Sentry, New York, 2009, pp. 130, 138, 156–158.See also the information about the historical structure of NSA that is archived at [https://fas.org/irp/nsa/oldind.html#organizations FAS.org] {{Webarchive|url=https://web.archive.org/web/20121106042740/https://fas.org/irp/nsa/oldind.html#organizations |date=2012-11-06 }}
= Directorates =
{{as of|2013}}, NSA has about a dozen directorates, which are designated by a letter, although not all of them are publicly known.TheWeek.com: [http://theweek.com/article/index/249658/the-nsas-secret-org-chart The NSA's secret org chart] {{Webarchive|url=https://web.archive.org/web/20150111074801/http://theweek.com/article/index/249658/the-nsas-secret-org-chart |date=2015-01-11 }}, September 15, 2013
In the year 2000, a leadership team was formed consisting of the director, the deputy director, and the directors of the Signals Intelligence (SID), the Information Assurance (IAD) and the Technical Directorate (TD). The chiefs of other main NSA divisions became associate directors of the senior leadership team.[https://www.nsa.gov/about/cryptologic_heritage/60th/book/NSA_60th_Anniversary.pdf National Security Agency – 60 Years of Defending Our Nation] {{Webarchive|url=https://web.archive.org/web/20180623141614/https://www.nsa.gov/about/cryptologic_heritage/60th/book/NSA_60th_Anniversary.pdf |date=2018-06-23 }}, Anniversary booklet, 2012, p. 96. After President George W. Bush initiated the President's Surveillance Program (PSP) in 2001, the NSA created a 24-hour Metadata Analysis Center (MAC), followed in 2004 by the Advanced Analysis Division (AAD), with the mission of analyzing content, Internet metadata and telephone metadata. Both units were part of the Signals Intelligence Directorate.Marc Ambinder, [http://theweek.com/article/index/246277/3008-selectors 3008 Selectors] {{Webarchive|url=https://web.archive.org/web/20150111073647/http://theweek.com/article/index/246277/3008-selectors |date=2015-01-11 }}, June 27, 2013.
In 2016, a proposal combined the Signals Intelligence Directorate with the Information Assurance Directorate into a Directorate of Operations.Ellen Nakashima. [https://www.washingtonpost.com/world/national-security/national-security-agency-plans-major-reorganization/2016/02/02/2a66555e-c960-11e5-a7b2-5a2f824b02c9_story.html National Security Agency plans major reorganization] {{Webarchive|url=https://web.archive.org/web/20230526120632/https://www.washingtonpost.com/world/national-security/national-security-agency-plans-major-reorganization/2016/02/02/2a66555e-c960-11e5-a7b2-5a2f824b02c9_story.html |date=2023-05-26 }}. The Washington Post, 2 Feb 2016.
= NSANet =
File:Intel GreenDoor.jpg, GWAN, NSANet, and JWICS]]
NSANet stands for National Security Agency Network and is the official NSA intranet.{{cite web|url=https://www.nsaarc.net/docs/arc_registration_guide.pdf|author=National Security Agency|title=ARC Registration|year=2009|access-date=April 13, 2011|publisher=NSA ARC|archive-url=https://web.archive.org/web/20120118224340/https://www.nsaarc.net/docs/arc_registration_guide.pdf|archive-date=January 18, 2012|url-status=dead}} It is a classified network,{{cite web |url=http://www.dni.gov/reports/IC_Consumers_Guide_2009.pdf|archive-url=https://web.archive.org/web/20120524093812/http://www.dni.gov/reports/IC_Consumers_Guide_2009.pdf|title=2009 National Intelligence Consumer's Guide|author=DNI|year=2009|access-date=April 13, 2011 |archive-date=May 24, 2012|publisher=Director of National Intelligence}} for information up to the level of TS/SCI{{cite web|url=http://portal.dean.usma.edu/departments/se/nrcd/PDFs/FM%203-93%20(Final%20Draft,%20Jul%2010).pdf|title=Theater Army Operations, Field Manual No. 3-93 (100–7)|author=US Army|access-date=April 13, 2011|url-status=dead|archive-url=https://web.archive.org/web/20110824235523/http://portal.dean.usma.edu/departments/se/nrcd/PDFs/FM%203-93%20(Final%20Draft,%20Jul%2010).pdf|archive-date=August 24, 2011}} to support the use and sharing of intelligence data between NSA and the signals intelligence agencies of the four other nations of the Five Eyes partnership. The management of NSANet has been delegated to the Central Security Service Texas (CSSTEXAS).[http://static.e-publishing.af.mil/production/1/67nww/publication/67nwwi33-1160/67nwwi33-1160.pdf Lackland Security Hill Enterprise Infrastructure and Computer Systems Management] {{webarchive|url=https://web.archive.org/web/20140204013239/http://static.e-publishing.af.mil/production/1/67nww/publication/67nwwi33-1160/67nwwi33-1160.pdf |date=2014-02-04 }}, October 1, 2010, p. 2.
NSANet is a highly secured computer network consisting of fiber-optic and satellite communication channels that are almost completely separated from the public Internet. The network allows NSA personnel and civilian and military intelligence analysts anywhere in the world to have access to the agency's systems and databases. This access is tightly controlled and monitored. For example, every keystroke is logged, activities are audited at random, and downloading and printing of documents from NSANet are recorded.Marc Ambinder, [http://theweek.com/article/index/245408/how-a-single-it-tech-could-spy-on-the-world How a single IT tech could spy on the world] {{Webarchive|url=https://web.archive.org/web/20150111073523/http://theweek.com/article/index/245408/how-a-single-it-tech-could-spy-on-the-world |date=2015-01-11 }}, June 10, 2013. In 1998, NSANet, along with NIPRNet and SIPRNet, had "significant problems with poor search capabilities, unorganized data, and old information".{{cite web |url=http://edocs.nps.edu/npspubs/scholarly/theses/1998/Sep/98Sep_Misiewicz.pdf |title=Thesis; Modeling and Simulation of a Global Reachback Architecture ... |date=September 1998 |access-date=April 13, 2011 |author=Misiewicz |url-status=dead |archive-url=https://web.archive.org/web/20110812153842/http://edocs.nps.edu/npspubs/scholarly/theses/1998/Sep/98Sep_Misiewicz.pdf |archive-date=August 12, 2011 }} In 2004, the network was reported to have used over twenty commercial off-the-shelf operating systems.{{cite web|url=http://www.sei.cmu.edu/library/assets/jarzombek.pdf|title=Systems, Network, and Information Integration Context for Software Assurance|author=Joe Jarzombek|year=2004|access-date=April 13, 2011|publisher=Carnegie Mellon University|archive-date=October 28, 2011|archive-url=https://web.archive.org/web/20111028095526/http://www.sei.cmu.edu/library/assets/jarzombek.pdf|url-status=live}} Some universities that do highly sensitive research are allowed to connect to it.{{cite web|url=http://www.exportcontrols.msu.edu/FBI_2010/Dr_Christopher_Griffin_Applied_Research_Laboratories_Penn_State_University_10_20_2010.pdf|title=Dealing with Sensitive Data at Penn State's Applied Research Laboratory: Approach and Examples|author= Christopher Griffin|year=2010|access-date=April 13, 2011|publisher=msu.edu}}{{dead link|date=March 2015}} The thousands of Top Secret internal NSA documents that were taken by Edward Snowden in 2013 were stored in "a file-sharing location on the NSA's intranet site"; so, they could easily be read online by NSA personnel. Everyone with a TS/SCI clearance had access to these documents. As a system administrator, Snowden was responsible for moving accidentally misplaced highly sensitive documents to safer storage locations.NPR.org: [https://www.npr.org/2013/09/18/223523622/officials-edward-snowdens-leaks-were-masked-by-job-duties Officials: Edward Snowden's Leaks Were Masked By Job Duties] {{Webarchive|url=https://web.archive.org/web/20240512123903/https://www.npr.org/2013/09/18/223523622/officials-edward-snowdens-leaks-were-masked-by-job-duties |date=2024-05-12 }}, September 18, 2013.
= Watch centers =
The NSA maintains at least two watch centers:
- National Security Operations Center (NSOC), which is the NSA's current operations center and focal point for time-sensitive SIGINT reporting for the United States SIGINT System (USSS). This center was established in 1968 as the National SIGINT Watch Center (NSWC) and was renamed into National SIGINT Operations Center (NSOC) in 1973. This "nerve center of the NSA" got its current name in 1996.{{citation needed|date=June 2022}}
- NSA/CSS Threat Operations Center (NTOC), which is the primary NSA/CSS partner for Department of Homeland Security response to cyber incidents. The NTOC establishes real-time network awareness and threat characterization capabilities to forecast, alert, and attribute malicious activity and enable the coordination of Computer Network Operations. The NTOC was established in 2004 as a joint Information Assurance and Signals Intelligence project.[https://www.nsa.gov/about/cryptologic_heritage/60th/book/NSA_60th_Anniversary.pdf National Security Agency – 60 Years of Defending Our Nation] {{Webarchive|url=https://web.archive.org/web/20180623141614/https://www.nsa.gov/about/cryptologic_heritage/60th/book/NSA_60th_Anniversary.pdf |date=2018-06-23}}, Anniversary booklet, 2012, p. 102.
=NSA Police=
The NSA has its law enforcement team, known as the NSA Police (and formerly as NSA Security Protective Force) which provides law enforcement services, emergency response, and physical security to its officials and properties.{{cite web |url=https://www.nsa.gov/News-Features/Feature-Stories/Article-View/Article/2604199/making-a-difference-over-30-years-with-the-nsa-police/ |title=Making a Difference over 30 Years with the NSA Police > National Security Agency Central Security Service > Article View |access-date=2021-06-18 |archive-date=2021-06-24 |archive-url=https://web.archive.org/web/20210624201455/https://www.nsa.gov/News-Features/Feature-Stories/Article-View/Article/2604199/making-a-difference-over-30-years-with-the-nsa-police/ |url-status=dead }}
NSA Police are armed federal officers. NSA Police has a K9 division, which generally conducts explosive detection screening of mail, vehicles, and cargo entering NSA grounds.{{cite web |url=https://www.nsa.gov/News-Features/Feature-Stories/Article-View/Article/1581793/nsa-police-k-9-unit-celebrates-140-dog-years/ |title=NSA Police K-9 Unit Celebrates 140 Dog Years! > National Security Agency Central Security Service > Article View |access-date=2021-06-18 |archive-date=2021-06-24 |archive-url=https://web.archive.org/web/20210624200154/https://www.nsa.gov/News-Features/Feature-Stories/Article-View/Article/1581793/nsa-police-k-9-unit-celebrates-140-dog-years/ |url-status=dead }} They use marked vehicles to carry out patrols. {{cite web|url=https://washington.cbslocal.com/wp-content/uploads/sites/15909891/2015/06/gettyimages-76864184-e1435148637500.jpg?w=1024&h=576&crop=1|format=JPG|title=Photographic image of vehicle|website=Washington.cbslocal.com|access-date=2022-02-23|archive-date=2021-06-24|archive-url=https://web.archive.org/web/20210624200950/https://washington.cbslocal.com/wp-content/uploads/sites/15909891/2015/06/gettyimages-76864184-e1435148637500.jpg?w=1024&h=576&crop=1|url-status=live}}
Employees
The number of NSA employees is officially classified{{Cite web |last=Tuutti |first=Camille |date=2012-04-16 |title=Introverted? Then the NSA wants you. |url=http://fcw.com/blogs/circuit/2012/04/fedsmc-chris-inglis-federal-workforce.aspx |url-status=dead |archive-url=https://web.archive.org/web/20201106044444/https://fcw.com/blogs/circuit/2012/04/fedsmc-chris-inglis-federal-workforce.aspx |archive-date=2020-11-06 |access-date=2013-07-01 |website=Florida Championship Wrestling}} but there are several sources providing estimates.
In 1961, the NSA had 59,000 military and civilian employees, which grew to 93,067 in 1969, of which 19,300 worked at the headquarters at Fort Meade. In the early 1980s, NSA had roughly 50,000 military and civilian personnel. By 1989 this number had grown again to 75,000, of which 25,000 worked at the NSA headquarters. Between 1990 and 1995 the NSA's budget and workforce were cut by one-third, which led to a substantial loss of experience.Matthew M. Aid, The Secret Sentry, New York, 2009, pp. 128, 148, 190, and 198.
In 2012, the NSA said more than 30,000 employees worked at Fort Meade and other facilities. In 2012, John C. Inglis, the deputy director, said that the total number of NSA employees is "somewhere between 37,000 and one billion" as a joke, and stated that the agency is "probably the biggest employer of introverts." In 2013 Der Spiegel stated that the NSA had 40,000 employees.{{cite news |url=http://www.spiegel.de/international/world/prism-leak-inside-the-controversial-us-data-surveillance-program-a-904761.html |title=Prism Exposed: Data Surveillance with Global Implications |page=2 |publisher=Spiegel Online International |date=June 10, 2013 |newspaper=Spiegel Online |last1=Rosenbach |first1=Marcel |last2=Stark |first2=Holger |last3=Stock |first3=Jonathan |access-date=June 13, 2013 |archive-date=June 13, 2013 |archive-url=https://web.archive.org/web/20130613165423/http://www.spiegel.de/international/world/prism-leak-inside-the-controversial-us-data-surveillance-program-a-904761.html |url-status=live }} "How can an intelligence agency, even one as large and well-staffed as the NSA with its 40,000 employees, work meaningfully with such a flood of information?" More widely, it has been described as the world's largest single employer of mathematicians.{{cite speech |title=Statement for the Record |author=Harvey A. Davis |date=March 12, 2002 |location=342 Dirksen Senate Office Building, Washington, D.C. |url=https://www.nsa.gov/public_info/speeches_testimonies/12mar02.shtml |access-date=November 24, 2009 |url-status=dead |archive-url=https://web.archive.org/web/20090619013425/http://www.nsa.gov/public_info/speeches_testimonies/12mar02.shtml |archive-date=June 19, 2009 }} Some NSA employees form part of the workforce of the National Reconnaissance Office (NRO), the agency that provides the NSA with satellite signals intelligence. As of 2013 about 1,000 system administrators work for the NSA.
= Personnel security =
The NSA received criticism early on in 1960 after two agents had defected to the Soviet Union. Investigations by the House Un-American Activities Committee and a special subcommittee of the United States House Committee on Armed Services revealed severe cases of ignorance of personnel security regulations, prompting the former personnel director and the director of security to step down and leading to the adoption of stricter security practices.David Kahn, The Codebreakers, Scribner Press, 1967, chapter 19, pp. 672–733. Nonetheless, security breaches reoccurred only a year later when in an issue of Izvestia of July 23, 1963, a former NSA employee published several cryptologic secrets. The very same day, an NSA clerk-messenger committed suicide as ongoing investigations disclosed that he had sold secret information to the Soviets regularly. The reluctance of congressional houses to look into these affairs prompted a journalist to write, "If a similar series of tragic blunders occurred in any ordinary agency of Government an aroused public would insist that those responsible be officially censured, demoted, or fired." David Kahn criticized the NSA's tactics of concealing its doings as smug and the Congress' blind faith in the agency's right-doing as shortsighted and pointed out the necessity of surveillance by the Congress to prevent abuse of power.
Edward Snowden's leaking of the existence of PRISM in 2013 caused the NSA to institute a "two-man rule", where two system administrators are required to be present when one accesses certain sensitive information.{{cite news|author1=Drew, Christopher|author2=Somini Sengupta|name-list-style=amp|url=https://www.nytimes.com/2013/06/24/technology/nsa-leak-puts-focus-on-system-administrators.html|title=N.S.A. Leak Puts Focus on System Administrators|work=The New York Times|date=June 24, 2013|access-date=June 25, 2013|archive-date=June 25, 2013|archive-url=https://web.archive.org/web/20130625074056/http://www.nytimes.com/2013/06/24/technology/nsa-leak-puts-focus-on-system-administrators.html|url-status=live}} Snowden claims he suggested such a rule in 2009.{{cite news|url=https://www.washingtonpost.com/world/national-security/edward-snowden-after-months-of-nsa-revelations-says-his-missions-accomplished/2013/12/23/49fc36de-6c1c-11e3-a523-fe73f0ff6b8d_story.html|title=Edward Snowden, after months of NSA revelations, says his mission's accomplished|author=Barton Gellman|newspaper=The Washington Post|date=December 25, 2013|access-date=June 7, 2024|archive-date=December 1, 2015|archive-url=https://web.archive.org/web/20151201015330/https://www.washingtonpost.com/world/national-security/edward-snowden-after-months-of-nsa-revelations-says-his-missions-accomplished/2013/12/23/49fc36de-6c1c-11e3-a523-fe73f0ff6b8d_story.html|url-status=live}}
== Polygraphing ==
File:DOD polygraph brochure.pdf (DSS) polygraph brochure given to NSA applicants]]
The NSA conducts polygraph tests of employees. For new employees, the tests are meant to discover enemy spies who are applying to the NSA and to uncover any information that could make an applicant pliant to coercion.{{cite book |url=https://books.google.com/books?id=EBkEGAOlCDsC&pg=PA359|author=Bauer, Craig P.|title=Secret History: The Story of Cryptology |publisher=CRC Press|isbn=978-1-4665-6186-1|year=2013|page=359}} As part of the latter, historically EPQs or "embarrassing personal questions" about sexual behavior had been included in the NSA polygraph. The NSA also conducts five-year periodic reinvestigation polygraphs of employees, focusing on counterintelligence programs. In addition, the NSA conducts periodic polygraph investigations to find spies and leakers; those who refuse to take them may receive "termination of employment", according to a 1982 memorandum from the director of the NSA.{{cite book|author=Bamford|title=Body of Secrets|chapter=page 538 |chapter-url=https://books.google.com/books?id=VqY4Wr3T5K4C&pg=PA538 |author-link=James Bamford|title-link=Body of Secrets|date=18 December 2007|publisher=Knopf Doubleday Publishing |isbn=9780307425058}}
There are also "special access examination" polygraphs for employees who wish to work in highly sensitive areas, and those polygraphs cover counterintelligence questions and some questions about behavior. NSA's brochure states that the average test length is between two and four hours.{{cite web|title=Your Polygraph Examination: An Important Appointment to Keep|url=https://www.nsa.gov/careers/_files/poly_brochure_final2.pdf|publisher=National Security Agency|access-date=June 17, 2013|archive-url=https://web.archive.org/web/20130903162514/http://www.nsa.gov/careers/_files/poly_brochure_final2.pdf|archive-date=2013-09-03|url-status=dead}} A 1983 report of the Office of Technology Assessment stated that "It appears that the NSA [National Security Agency] (and possibly CIA) use the polygraph not to determine deception or truthfulness per se, but as a technique of interrogation to encourage admissions."{{cite news|author=McCarthy, Susan|title=The truth about the polygraph|url=http://www.salon.com/2000/03/02/polygraph/|work=Salon|access-date=July 5, 2013|archive-date=August 16, 2013|archive-url=https://web.archive.org/web/20130816012934/http://www.salon.com/2000/03/02/polygraph/|url-status=live}} Sometimes applicants in the polygraph process confess to committing felonies such as murder, rape, and selling of illegal drugs. Between 1974 and 1979, of the 20,511 job applicants who took polygraph tests, 695 (3.4%) confessed to previous felony crimes; almost all of those crimes had been undetected.
In 2010 the NSA produced a video explaining its polygraph process.{{cite news|author=Nagesh, Gautham|url=https://thehill.com/policy/technology/163354-nsa-video-tries-to-dispel-fear-about-polygraph-use-during-job-interviews/|title=NSA video tries to dispel fear about polygraph use during job interviews|work=The Hill|date=June 14, 2010|access-date=June 15, 2013|archive-date=April 1, 2023|archive-url=https://web.archive.org/web/20230401085433/https://thehill.com/policy/technology/163354-nsa-video-tries-to-dispel-fear-about-polygraph-use-during-job-interviews/|url-status=live}} The video, ten minutes long, is titled "The Truth About the Polygraph" and was posted to the Web site of the Defense Security Service. Jeff Stein of The Washington Post said that the video portrays "various applicants, or actors playing them—it's not clear—describing everything bad they had heard about the test, the implication being that none of it is true."Stein, Jeff. "[http://voices.washingtonpost.com/spy-talk/2010/06/facing_nsas_lie_detector_relax.html NSA lie detectors no sweat, video says] {{Webarchive|url=https://web.archive.org/web/20131029200708/http://voices.washingtonpost.com/spy-talk/2010/06/facing_nsas_lie_detector_relax.html |date=2013-10-29 }}." The Washington Post. June 14, 2010. Retrieved July 5, 2013. AntiPolygraph.org argues that the NSA-produced video omits some information about the polygraph process; it produced a video responding to the NSA video.{{cite web|last=Maschke|first=George|date=13 June 2010|title=The Truth About the Polygraph (According to the NSA)|url=https://www.youtube.com/watch?v=93_FDeMENN4 |archive-url=https://ghostarchive.org/varchive/youtube/20211211/93_FDeMENN4| archive-date=2021-12-11 |url-status=live|access-date=15 July 2020|website=Youtube}}{{cbignore}} George Maschke, the founder of the Web site, accused the NSA polygraph video of being "Orwellian".
In 2013, an article indicated that after Edward Snowden revealed his identity in 2013, the NSA began requiring polygraphing of employees once per quarter.Drezner, Daniel. "[https://foreignpolicy.com/articles/2013/12/16/tone_deaf_at_the_listening_post_my_day_at_the_NSA Tone-Deaf at the Listening Post] {{Webarchive|url=https://web.archive.org/web/20140825152001/http://www.foreignpolicy.com/articles/2013/12/16/tone_deaf_at_the_listening_post_my_day_at_the_NSA |date=2014-08-25 }}." Foreign Policy. December 16, 2013. Retrieved March 1, 2014. "Snowden has also changed the way the NSA is doing business. Analysts have gone from being polygraphed once every five years to once every quarter."
= Arbitrary firing =
The number of exemptions from legal requirements has been criticized. When in 1964 Congress was hearing a bill giving the director of the NSA the power to fire at will any employee, The Washington Post wrote: "This is the very definition of arbitrariness. It means that an employee could be discharged and disgraced based on anonymous allegations without the slightest opportunity to defend himself." Yet, the bill was accepted by an overwhelming majority. Also, every person hired to a job in the US after 2007, at any private organization, state or federal government agency, must be reported to the New Hire Registry, ostensibly to look for child support evaders, except that employees of an intelligence agency may be excluded from reporting if the director deems it necessary for national security reasons.{{cite web |url=https://dc-newhire.com/faqs#faq:4 |title=Is anyone exempt from this law? {{!}} District of Columbia New Hire Registry FAQ |website=dc-newhire.com |accessdate=18 November 2021 |archive-date=18 November 2021 |archive-url=https://web.archive.org/web/20211118125006/https://dc-newhire.com/faqs#faq:4 |url-status=live }}
Facilities
= Headquarters =
== History of headquarters ==
File:NSA-Fort Meade-1950.png circa 1950s]]
When the agency was first established, its headquarters and cryptographic center were in the Naval Security Station in Washington, D.C. The COMINT functions were located in Arlington Hall in Northern Virginia, which served as the headquarters of the U.S. Army's cryptographic operations.{{cite web|title=60 Years of Defending Our Nation|publisher=National Security Agency|year=2012|url=https://www.nsa.gov/about/cryptologic_heritage/60th/book/NSA_60th_Anniversary.pdf|access-date=July 6, 2013|page=15|archive-url=https://web.archive.org/web/20130614022314/http://www.nsa.gov/about/cryptologic_heritage/60th/book/NSA_60th_Anniversary.pdf|archive-date=2013-06-14|url-status=dead}} Because the Soviet Union had detonated a nuclear bomb and because the facilities were crowded, the federal government wanted to move several agencies, including the AFSA/NSA. A planning committee considered Fort Knox, but Fort Meade, Maryland, was ultimately chosen as NSA headquarters because it was far enough away from Washington, D.C. in case of a nuclear strike and was close enough so its employees would not have to move their families.
Construction of additional buildings began after the agency occupied buildings at Fort Meade in the late 1950s, which they soon outgrew.{{cite web|title=60 Years of Defending Our Nation|publisher=National Security Agency|year=2012|url=https://www.nsa.gov/about/cryptologic_heritage/60th/book/NSA_60th_Anniversary.pdf|access-date=July 6, 2013|page=10|archive-url=https://web.archive.org/web/20130614022314/http://www.nsa.gov/about/cryptologic_heritage/60th/book/NSA_60th_Anniversary.pdf|archive-date=2013-06-14|url-status=dead}} In 1963 the new headquarters building, nine stories tall, opened. NSA workers referred to the building as the "Headquarters Building" and since the NSA management occupied the top floor, workers used "Ninth Floor" to refer to their leaders.{{cite web|title=60 Years of Defending Our Nation|publisher=National Security Agency|year=2012|url=https://www.nsa.gov/about/cryptologic_heritage/60th/book/NSA_60th_Anniversary.pdf|access-date=July 6, 2013|page=23|archive-url=https://web.archive.org/web/20130614022314/http://www.nsa.gov/about/cryptologic_heritage/60th/book/NSA_60th_Anniversary.pdf|archive-date=2013-06-14|url-status=dead}} COMSEC remained in Washington, D.C., until its new building was completed in 1968. In September 1986, the Operations 2A and 2B buildings, both copper-shielded to prevent eavesdropping, opened with a dedication by President Ronald Reagan. The four NSA buildings became known as the "Big Four." The NSA director moved to 2B when it opened.{{cite web|title=60 Years of Defending Our Nation|publisher=National Security Agency|year=2012|url=https://www.nsa.gov/about/cryptologic_heritage/60th/book/NSA_60th_Anniversary.pdf|access-date=July 6, 2013|page=39|archive-url=https://web.archive.org/web/20130614022314/http://www.nsa.gov/about/cryptologic_heritage/60th/book/NSA_60th_Anniversary.pdf|archive-date=2013-06-14|url-status=dead}}
File:National Security Agency, 2013.jpg
Headquarters for the National Security Agency is located at {{Coord|39|6|32|N|76|46|17|W|display=inline}} in Fort George G. Meade, Maryland, although it is separate from other compounds and agencies that are based within this same military installation. Fort Meade is about {{convert|20|mi|km|abbr=on}} southwest of Baltimore,{{cite web|url=http://www.hqmc.marines.mil/intelligence/Units/MarineCryptologicSupportBattalion/NewJoins.aspx|title=Marine Cryptologic Support Battalion: Intelligence Department: Fort Meade, MD: New Joins|publisher=United States Marine Corps|access-date=June 11, 2013|archive-date=June 14, 2013|archive-url=https://web.archive.org/web/20130614020759/http://www.hqmc.marines.mil/intelligence/Units/MarineCryptologicSupportBattalion/NewJoins.aspx|url-status=live}} and {{convert|25|mi|km|abbr=on}} northeast of Washington, D.C."Just off the Baltimore-Washington Parkway, about 25 miles northeast of Washington, is a secret city. Fort Meade, in suburban Maryland, is home to the National Security Agency—the NSA, sometimes wryly referred to as No Such Agency or Never Say Anything." "It contains almost 70 miles of roads, 1,300 buildings, each identified by a number, and 18,000 parking spaces as well as a shopping center, golf courses, chain restaurants and every other accouterment of Anywhere, USA." in {{cite news |url=http://www.thesundaytimes.co.uk/sto/news/world_news/Americas/article1271197.ece |archive-url=https://web.archive.org/web/20130614020751/http://www.thesundaytimes.co.uk/sto/news/world_news/Americas/article1271197.ece |url-status=dead |archive-date=June 14, 2013 |title=Free introduction to Who's reading your emails? |work=The Sunday Times |date=June 9, 2013 |access-date=June 11, 2013 }}{{subscription required}} The NSA has two dedicated exits off Baltimore–Washington Parkway. The Eastbound exit from the Parkway (heading toward Baltimore) is open to the public and provides employee access to its main campus and public access to the National Cryptology Museum. The Westbound side exit, (heading toward Washington) is labeled "NSA Employees Only".Sernovitz, Daniel J. "[http://www.bizjournals.com/baltimore/stories/2010/08/23/daily33.html?page=all NSA opens doors for local businesses] {{Webarchive|url=https://web.archive.org/web/20130614020853/http://www.bizjournals.com/baltimore/stories/2010/08/23/daily33.html?page=all |date=2013-06-14 }}." Baltimore Business Journal. August 26, 2010. Updated August 27, 2010. Retrieved June 11, 2013. "But for many more, the event was the first time attendees got the chance to take the "NSA Employees Only" exit off the Baltimore-Washington Parkway beyond the restricted gates of the agency's headquarters."Weiland and Wilsey, p. [https://books.google.com/books?id=BywaW1f4iQ4C&pg=PA208 208]. "[...]housing integration has invalidated Montpelier's Ivory Pass and the National Security Agency has posted an exit ramp off the Baltimore-Washington Parkway that reads NSA." The exit may only be used by people with the proper clearances, and security vehicles parked along the road guard the entrance.Grier, Peter, and Harry Bruinius. "[http://www.csmonitor.com/USA/DC-Decoder/2013/0618/In-the-end-NSA-might-not-need-to-snoop-so-secretly In the end, NSA might not need to snoop so secretly] {{Webarchive|url=https://web.archive.org/web/20130626224500/http://www.csmonitor.com/USA/DC-Decoder/2013/0618/In-the-end-NSA-might-not-need-to-snoop-so-secretly |date=2013-06-26 }}." The Christian Science Monitor. June 18, 2013. Retrieved July 1, 2013.
NSA is the largest employer in the state of Maryland, and two-thirds of its personnel work at Fort Meade. Built on {{convert|350|acre|ha sqmi|lk=off}}{{cite news|author=Gorman, Siobhan|title=NSA risking electrical overload|url=https://www.baltimoresun.com/2006/08/06/nsa-risking-electrical-overload/|date=August 6, 2006|work=The Baltimore Sun|publisher=Tribune Company|access-date=June 10, 2013|archive-date=June 14, 2013|archive-url=https://web.archive.org/web/20130614020806/http://articles.baltimoresun.com/2006-08-06/news/0608060158_1_agency-power-surges-nsa|url-status=live}} of Fort Meade's {{convert|5000|acre|ha sqmi|adj=off}},{{cite news|author=Dozier, Kimberly|date=June 9, 2013|title=NSA claims know-how to ensure no illegal spying|url=http://bigstory.ap.org/article/nsa-finder-and-keeper-countless-us-secrets|agency=Associated Press|access-date=June 12, 2013|archive-date=June 14, 2013|archive-url=https://web.archive.org/web/20130614020805/http://bigstory.ap.org/article/nsa-finder-and-keeper-countless-us-secrets|url-status=dead}} the site has 1,300 buildings and an estimated 18,000 parking spaces.{{cite web|url=https://www.baltimoresun.com/2010/01/13/geeks-r-us/|date=January 13, 2010|title=Geeks 'R' us|work=The Baltimore Sun|publisher=Tribune Company|access-date=June 11, 2013|archive-url=https://web.archive.org/web/20130614020802/http://articles.baltimoresun.com/2010-01-13/news/bal-ed.cybersecurity13jan13_1_cyber-security-cyber-command-national-security-agency|archive-date=June 14, 2013|url-status=live}}
{{multiple image
| align = right
| image1 = National Security Agency headquarters, Fort Meade, Maryland.jpg
| width1 = 190
| alt1 =
| caption1 =
| image2 = NSOC-2012.jpg
| width2 = 222
| alt2 =
| caption2 =
| footer = NSA headquarters building in Fort Meade (left), NSOC (right)
}}
The main NSA headquarters and operations building is what James Bamford, author of Body of Secrets, describes as "a modern boxy structure" that appears similar to "any stylish office building."Bamford, Body of Secrets: Anatomy of the Ultra-Secret National Security Agency, [https://books.google.com/books?id=VqY4Wr3T5K4C&pg=PA488 p. 488]. "At the heart of the invisible city is NSA's massive Headquarters/Operations Building. With more than sixty-eight acres of floor space,[...]" and "Entrance is first made through the two-story Visitor Control Center, one[...]" The building is covered with one-way dark glass, which is lined with copper shielding to prevent espionage by trapping in signals and sounds. It contains {{convert|3000000|sqft|sqm}}, or more than {{convert|68|acre|ha}}, of floor space; Bamford said that the U.S. Capitol "could easily fit inside it four times over."
The facility has over 100 watchposts,Bamford, Body of Secrets: Anatomy of the Ultra-Secret National Security Agency, p. [https://books.google.com/books?id=VqY4Wr3T5K4C&pg=PA488 488]–489. "[...]one of more than 100 fixed watch posts within the secret city manned by the armed NSA police. It is here that clearances are checked and visitor badges are issued." one of them being the visitor control center, a two-story area that serves as the entrance. At the entrance, a white pentagonal structure,Bamford, Body of Secrets: Anatomy of the Ultra-Secret National Security Agency, p. 490. "And then there is the red badge—[...]and is normally worn by people working in the "Red Corridor"—the drugstore and other concession areas[...]Those with a red badge are forbidden to go anywhere near classified information and are restricted to a few corridors and administrative areas—the bank, the barbershop, the cafeteria, the credit union, the airline and entertainment ticket counters." and "Once inside the white, pentagonal Visitor Control Center, employees are greeted by a six-foot painting of the NSA seal[...]" visitor badges are issued to visitors and security clearances of employees are checked.Bamford, Body of Secrets: Anatomy of the Ultra-Secret National Security Agency, p. 489. "It is here that clearances are checked and visitor badges are issued." The visitor center includes a painting of the NSA seal.
The OPS2A building, the tallest building in the NSA complex and the location of much of the agency's operations directorate is accessible from the visitor center. Bamford described it as a "dark glass Rubik's Cube".Bamford, Body of Secrets: Anatomy of the Ultra-Secret National Security Agency, p. 491. "From the Visitor Control Center, one enters the eleven-story, million OPS2A, the tallest building in the City. Shaped like a dark glass Rubik's Cube, the building houses much of NSA's Operations Directorate, which is responsible for processing the ocean of intercepts and prying open the complex cipher systems." The facility's "red corridor" houses non-security operations such as concessions and the drug store. The name refers to the "red badge" which is worn by someone without a security clearance. The NSA headquarters includes a cafeteria, a credit union, ticket counters for airlines and entertainment, a barbershop, and a bank. NSA headquarters has its own post office, fire department, and police force.{{cite web |url=https://www.nsa.gov/careers/career_fields/others.shtml |title=Career Fields/Other Opportunities/NSA Police Officers section of the NSA website |publisher=Nsa.gov |access-date=October 9, 2013 |archive-date=October 11, 2013 |archive-url=https://web.archive.org/web/20131011133816/http://www.nsa.gov/careers/career_fields/others.shtml |url-status=live }}{{cite web|author1=T.C. Carrington|author2=Debra L.Z. Potts|url=https://www.nsa.gov/public_info/_files/newsletters/Newsletter_Sept_1999.pdf|title=National Security Agency Newsletter, Protective Services-More Than Meets the Eye. An Overview of NSA's Protective Services Volume XLVII, No. 9|date=September 1999|pages=8–10|work=nsa.gov|url-status=dead|archive-url=https://web.archive.org/web/20160318060528/https://www.nsa.gov/public_info/_files/newsletters/Newsletter_Sept_1999.pdf|archive-date=2016-03-18|access-date=2016-08-23}}
The employees at the NSA headquarters reside in various places in the Baltimore-Washington area, including Annapolis, Baltimore, and Columbia in Maryland and the District of Columbia, including the Georgetown community."[https://www.nsa.gov/careers/life_at_nsa/explore.shtml Explore NSA]." ([https://web.archive.org/web/20130614022301/http://www.nsa.gov/careers/life_at_nsa/explore.shtml Archive]) National Security Agency. Retrieved June 12, 2013. "Other Locations" and "Our employees live along the Colonial-era streets of Annapolis and Georgetown; in the suburban surroundings of Columbia; near the excitement of Baltimore's Inner Harbor; along rolling hills adjacent to working farms; near the shores of the Chesapeake Bay; and amid the monumental history of Washington, DC." The NSA maintains a shuttle service from the Odenton station of MARC to its Visitor Control Center and has done so since 2005.{{cite web|author=McCombs, Alan J.|url=https://www.army.mil/article/17291/Fort_Meade_launches_commuter_shuttle_service|title=Fort Meade launches commuter shuttle service|publisher=United States Army|date=2009-02-23|access-date=2017-06-25|archive-date=2017-06-25|archive-url=https://web.archive.org/web/20170625044518/https://www.army.mil/article/17291/Fort_Meade_launches_commuter_shuttle_service|url-status=live}}
== Energy consumption ==
File:NeverSleeps 071310.jpg, NSA is the largest electricity consumer in Maryland.]]
Following a major power outage in 2000, in 2003, and follow-ups through 2007, The Baltimore Sun reported that the NSA was at risk of electrical overload because of insufficient internal electrical infrastructure at Fort Meade to support the amount of equipment being installed. This problem was apparently recognized in the 1990s but not made a priority, and "now the agency's ability to keep its operations going is threatened."{{cite news|author=Sabar, Ariel|title=NSA still subject to electronic failure|url=https://www.baltimoresun.com/2003/01/02/nsa-still-subject-to-electronic-failure/|date=January 2, 2003|access-date=2013-06-11|archive-date=2013-06-14|archive-url=https://web.archive.org/web/20130614020814/http://articles.baltimoresun.com/2003-01-02/news/0301020300_1_outages-electrical-and-computer-agency|url-status=live}} and "Agency officials anticipated the problem nearly a decade ago as they looked ahead at the technology needs of the agency, sources said, but it was never made a priority, and now the agency's ability to keep its operations going is threatened." and "The NSA is Baltimore Gas & Electric's largest customer, using as much electricity as the city of Annapolis, according to James Bamford...." in {{cite news|url=https://www.baltimoresun.com/2006/08/06/nsa-risking-electrical-overload/|date=August 6, 2006|author=Gorman, Siobhan|title=NSA risking electrical overload|access-date=2013-06-11|archive-date=2013-06-14|archive-url=https://web.archive.org/web/20130614020806/http://articles.baltimoresun.com/2006-08-06/news/0608060158_1_agency-power-surges-nsa|url-status=live}} and {{cite news|author=Gorman, Siobhan|title=NSA electricity crisis gets Senate scrutiny|url=https://www.baltimoresun.com/2007/01/26/nsa-electricity-crisis-gets-senate-scrutiny/|date=January 26, 2007|access-date=2013-06-11|archive-date=2013-06-14|archive-url=https://web.archive.org/web/20130614020818/http://articles.baltimoresun.com/2007-01-26/news/0701260231_1_electricity-rockefeller-senate-intelligence-committee|url-status=live}} and {{cite news|author=Gorman, Siobhan|title=Power supply still a vexation for the NSA|date=June 24, 2007|url=https://www.baltimoresun.com/2007/06/24/power-supply-still-a-vexation-for-the-nsa/|work=The Baltimore Sun|publisher=Tribune Company|access-date=June 11, 2013|archive-date=June 14, 2013|archive-url=https://web.archive.org/web/20130614020755/http://articles.baltimoresun.com/2007-06-24/news/0706240110_1_national-security-agency-classified-electricity|url-status=live}}
On August 6, 2006, The Baltimore Sun reported that the NSA had completely maxed out the grid and that Baltimore Gas & Electric (BGE, now Constellation Energy) was unable to sell them any more power.{{cite web|url=https://www.baltimoresun.com/news/bs-xpm-2006-08-06-0608060158-story.html|title=NSA risking electrical overload|first=SIOBHAN|last=GORMAN|website=baltimoresun.com|access-date=2018-12-23|archive-date=2020-08-13|archive-url=https://web.archive.org/web/20200813231456/https://www.baltimoresun.com/news/bs-xpm-2006-08-06-0608060158-story.html|url-status=dead}} NSA decided to move some of its operations to a new satellite facility. BGE provided NSA with 65 to 75 megawatts at Fort Meade in 2007 and expected that an increase of 10 to 15 megawatts would be needed later that year."The NSA uses about 65 to 75 megawatt-hours of electricity, The Sun reported last week. Its needs are projected to grow by 10 to 15 megawatt-hours by next fall." in {{cite news|author=Staff|title=NSA electricity crisis gets Senate scrutiny|url=https://www.baltimoresun.com/2007/01/26/nsa-electricity-crisis-gets-senate-scrutiny/|date=January 26, 2007|work=The Baltimore Sun|publisher=Tribune Company|access-date=June 11, 2013|archive-date=June 14, 2013|archive-url=https://web.archive.org/web/20130614020818/http://articles.baltimoresun.com/2007-01-26/news/0701260231_1_electricity-rockefeller-senate-intelligence-committee|url-status=live}} In 2011, the NSA was Maryland's largest consumer of power.{{cite web|url=http://www.gbc.org/Committee%20pages/Small%20Business%20Brief%20April%202011.pdf|archive-url=https://web.archive.org/web/20130617050958/http://www.gbc.org/Committee%20pages/Small%20Business%20Brief%20April%202011.pdf|archive-date=June 17, 2013|url-status=dead|author=Barnett, Mark L.|date=April 26, 2011|title=Small Business Brief|publisher=Office of Small Business Programs, NSA, via The Greater Baltimore Committee|page=3|access-date=June 11, 2013}} In 2007, as BGE's largest customer, NSA bought as much electricity as Annapolis, the capital city of Maryland. One estimate put the potential for power consumption by the new Utah Data Center at {{US$}}40 million per year.
== Computing assets ==
In 1995, The Baltimore Sun reported that the NSA is the owner of the single largest group of supercomputers.{{cite news |url=http://articles.baltimoresun.com/1995-12-10/news/1995344001_1_crypto-ag-nsa-headquarters-swiss |title=No Such Agency Part Four – Rigging the Game |author=Scott Shane and Tom Bowman |newspaper=The Baltimore Sun |date=December 10, 1995 |access-date=October 3, 2015 |archive-date=August 27, 2011 |archive-url=https://web.archive.org/web/20110827112138/http://articles.baltimoresun.com/1995-12-10/news/1995344001_1_crypto-ag-nsa-headquarters-swiss |url-status=dead }} NSA held a groundbreaking ceremony at Fort Meade in May 2013 for its High-Performance Computing Center 2, expected to open in 2016.{{cite news|author=Brown, Matthew Hay|title=NSA plans new computing center for cyber threats|url=https://www.baltimoresun.com/2013/05/06/nsa-plans-new-computing-center-for-cyber-threats/|date=May 6, 2013|work=The Baltimore Sun|publisher=Tribune Company|access-date=June 11, 2013|archive-date=June 14, 2013|archive-url=https://web.archive.org/web/20130614020810/http://articles.baltimoresun.com/2013-05-06/news/bs-md-nsa-high-performance-computing-center-2-20130506_1_cyber-attacks-u-s-cyber-command-cyber-threats|url-status=live}} Called Site M, the center has a 150-megawatt power substation, 14 administrative buildings and 10 parking garages. It cost {{dollarsign|US}}3.2 billion and covers {{convert|227|acre|ha sqmi|adj=off}}. The center is {{convert|1800000|sqft|ha sqmi|adj=off}} and initially uses 60 megawatts of electricity.{{cite web|title=National Security Agency: FY 2014 Military Construction, Defense-Wide|url=http://comptroller.defense.gov/defbudget/fy2014/budget%5Fjustification/pdfs/07_Military_Construction/11-National_Security_Agency.pdf|archive-url=https://web.archive.org/web/20140125150402/http://comptroller.defense.gov/defbudget/fy2014/budget_justification/pdfs/07_Military_Construction/11-National_Security_Agency.pdf|pages=3–4|publisher=Office of the Under Secretary of Defense (Comptroller), USA.gov|access-date=June 13, 2013|archive-date=January 25, 2014|url-status=dead}} Increments II and III are expected to be completed by 2030 and would quadruple the space, covering {{convert|5800000|sqft|ha sqmi|adj=off}} with 60 buildings and 40 parking garages.{{cite magazine|author=Bamford, James|title=The Secret War|url=https://www.wired.com/threatlevel/2013/06/general-keith-alexander-cyberwar/all/|date=June 12, 2013|magazine=Wired|access-date=June 12, 2013|author-link=James Bamford|archive-date=August 2, 2013|archive-url=https://web.archive.org/web/20130802125656/http://www.wired.com/threatlevel/2013/06/general-keith-alexander-cyberwar/all|url-status=live}} Defense contractors are also establishing or expanding cybersecurity facilities near the NSA and around the Washington metropolitan area.
= National Computer Security Center =
The DoD Computer Security Center was founded in 1981 and renamed the National Computer Security Center (NCSC) in 1985. NCSC was responsible for computer security throughout the federal government."The DoD Computer Security Center (DoDCSC) was established in January 1981..." and "In 1985, DoDCSC's name was changed to the National Computer Security Center..." and "its responsibility for computer security throughout the federal government..." in {{cite web|url=http://csrc.nist.gov/publications/secpubs/rainbow/tg001.txt|title=A Guide to Understanding Audit in Trusted Systems|publisher=National Computer Security Center via National Institute of Standards and Technology CSRC|access-date=June 30, 2013|archive-url=https://web.archive.org/web/20121106123647/http://csrc.nist.gov/publications/secpubs/rainbow/tg001.txt|archive-date=2012-11-06|url-status=dead}} NCSC was part of NSA,"NSA and its National Computer Security Center (NCSC) have responsibility for..." in {{cite web|url=http://csrc.nist.gov/publications/nistbul/csl91-02.txt|title=Computer Systems Laboratory Bulletin|date=February 1991|publisher=National Institute of Standards and Technology CSRC|access-date=June 30, 2013|archive-url=https://web.archive.org/web/20130702193745/http://csrc.nist.gov/publications/nistbul/csl91-02.txt|archive-date=2013-07-02|url-status=dead}} and during the late 1980s and the 1990s, NSA and NCSC published Trusted Computer System Evaluation Criteria in a six-foot high Rainbow Series of books that detailed trusted computing and network platform specifications. The Rainbow books were replaced by the Common Criteria, however, in the early 2000s.{{cite web|url=https://fas.org/irp/nsa/rainbow.htm|title=NSA/NCSC Rainbow Series|publisher=Federation of American Scientists|access-date=June 30, 2013|archive-date=June 14, 2013|archive-url=https://web.archive.org/web/20130614021145/https://www.fas.org/irp/nsa/rainbow.htm|url-status=live}}
= Other facilities =
File:Buckley AFB.png in Colorado]]
File:Utah Data Center Panorama (cropped).jpg]]
NSA had facilities at Friendship Annex (FANX) in Linthicum, Maryland, which is a 20 to 25-minute drive from Fort Meade;{{cite web|title=Fort Meade|url=http://www.public.navy.mil/necc/ecrc/Pages/FortMeade.aspx|publisher=Expeditionary Combat Readiness Center, United States Navy|access-date=June 11, 2013|archive-date=June 14, 2013|archive-url=https://web.archive.org/web/20130614020751/http://www.public.navy.mil/necc/ecrc/Pages/FortMeade.aspx|url-status=dead}} the Aerospace Data Facility at Buckley Space Force Base in Aurora, Colorado; NSA Texas in the Texas Cryptology Center at Lackland Air Force Base in San Antonio, Texas; NSA Georgia, Georgia Cryptologic Center, Fort Gordon (now Fort Eisenhower), Augusta, Georgia; NSA Hawaii, Hawaii Cryptologic Center in Honolulu; the Multiprogram Research Facility in Oak Ridge, Tennessee, and elsewhere.
In 2009, to protect its assets and access more electricity, NSA sought to decentralize and expand its existing facilities in Fort Meade and Menwith Hill,{{cite news|title=New NSA center unveiled in budget documents|url=http://www.sltrib.com/news/ci_12744661|work=The Salt Lake Tribune|publisher=MediaNews Group|author=LaPlante, Matthew D.|date=July 2, 2009|access-date=June 9, 2013|archive-date=January 26, 2021|archive-url=https://web.archive.org/web/20210126055709/http://www.sltrib.com/news/ci_12744661/|url-status=live}} the latter expansion expected to be completed by 2015.{{cite news|author=Norton-Taylor, Richard|title=Menwith Hill eavesdropping base undergoes massive expansion|date=March 1, 2012|url=https://www.theguardian.com/world/2012/mar/01/menwith-hill-eavesdropping-base-expansion|work=The Guardian|publisher=Guardian News and Media|access-date=June 10, 2013|location=London|archive-date=January 26, 2014|archive-url=https://web.archive.org/web/20140126001413/http://www.theguardian.com/world/2012/mar/01/menwith-hill-eavesdropping-base-expansion|url-status=live}}
On January 6, 2011, a groundbreaking ceremony was held to begin construction on the NSA's first Comprehensive National Cyber-security Initiative (CNCI) Data Center, known as the "Utah Data Center" for short. The $1.5B data center is being built at Camp Williams, Utah, located {{convert|25|mi|km}} south of Salt Lake City, and will help support the agency's National Cyber-security Initiative.{{cite news|title=Utah's billion cyber-security center under way|author=Steve Fidel|url=http://www.deseretnews.com/article/705363940/Utahs-15-billion-cyber-security-center-under-way.html|newspaper=Deseret News|date=January 6, 2011|access-date=January 6, 2011|archive-date=January 9, 2011|archive-url=https://web.archive.org/web/20110109001921/http://www.deseretnews.com/article/705363940/Utahs-15-billion-cyber-security-center-under-way.html|url-status=dead}} It is expected to be operational by September 2013.{{cite news |url=https://www.wired.com/threatlevel/2012/03/ff_nsadatacenter/all/1 |title=The NSA Is Building the Country's Biggest Spy Center (Watch What You Say) |last=Bamford |first=James |magazine=Wired |publisher=Condé Nast |date=March 15, 2012 |access-date=February 26, 2013 |archive-date=April 4, 2012 |archive-url=https://web.archive.org/web/20120404172946/http://www.wired.com/threatlevel/2012/03/ff_nsadatacenter/all/1 |url-status=live }} Construction of Utah Data Center finished in May 2019.{{cite web|author=Office of the Under Secretary of Defense for Acquisition, Technology, and Logistics|date=September 17, 2014|title=MilCon Status Report – August 2014 – Under Secretary of Defense for AT&L|url=http://www.acq.osd.mil/ie/fim/library/milcon/MILCON_EOM-AUG_Report_2014-09-17.xlsx|url-status=dead|archive-url=https://web.archive.org/web/20141210071515/http://www.acq.osd.mil/ie/fim/library/milcon/MILCON_EOM-AUG_Report_2014-09-17.xlsx|archive-date=December 10, 2014|access-date=April 16, 2015|df=mdy-all}}
In 2012, NSA collected intelligence from four geostationary satellites. Satellite receivers were at Roaring Creek Station in Catawissa, Pennsylvania and Salt Creek Station in Arbuckle, California. It operated ten to twenty taps on U.S. telecom switches. NSA had installations in several U.S. states and from them observed intercepts from Europe, the Middle East, North Africa, Latin America, and Asia. The Yakima Herald-Republic cited Bamford, saying that many of NSA's bases for its Echelon program were a legacy system, using outdated, 1990s technology."It's kind of a legacy system, this whole idea, the Echelon," Bamford said. "Communications have changed a great deal since they built it." in {{cite news|author=Muir, Pat|title=Secret Yakima facility may be outdated, expert says|date=May 27, 2013|url=http://www.yakimaherald.com/news/latestpoliticsnews/1142385-8/new-details-on-the-nsas-closure-of-its|archive-url=https://archive.today/20130616081534/http://www.yakimaherald.com/news/latestpoliticsnews/1142385-8/new-details-on-the-nsas-closure-of-its|url-status=dead|archive-date=June 16, 2013|publisher=Seattle Times|work=Yakima Herald-Republic|access-date=June 15, 2013}} In 2004, NSA closed its operations at Bad Aibling Station (Field Station 81) in Bad Aibling, Germany.{{cite news|author=Richelson, Jeffrey T.|title=Eavesdroppers in Disguise|date=August 2012|url=http://www.airforcemag.com/MagazineArchive/Pages/2012/August%202012/0812Eavesdroppers.aspx|work=Air Force Magazine|publisher=Air Force Association|access-date=June 10, 2013|archive-date=June 14, 2013|archive-url=https://web.archive.org/web/20130614022300/http://www.airforcemag.com/MagazineArchive/Pages/2012/August%202012/0812Eavesdroppers.aspx|url-status=live}} In 2012, NSA began to move some of its operations at Yakima Research Station, Yakima Training Center, in Washington state to Colorado, planning to leave Yakima closed.{{cite news|author=Troianello, Craig|title=NSA to close Yakima Training Center facility|date=April 4, 2013|url=http://www.yakimaherald.com/news/latestlocalnews/1006429-8/nsa-to-close-yakima-training-center-facility|archive-url=https://archive.today/20130616052825/http://www.yakimaherald.com/news/latestlocalnews/1006429-8/nsa-to-close-yakima-training-center-facility|url-status=dead|archive-date=June 16, 2013|publisher=Yakima Herald-Republic|access-date=June 15, 2013}} During 2013, NSA also intended to close operations at Sugar Grove, West Virginia.
= Global stations =
File:Menwith-hill-radomes.jpg has the largest NSA presence in the United Kingdom.]]
Following the {{cite web|title=UKUSA Agreement Release: 1940–1956|url=https://www.nsa.gov/public_info/declass/ukusa.shtml|publisher=National Security Agency|access-date=July 11, 2013|url-status=dead|archive-url=https://web.archive.org/web/20130702172840/http://www.nsa.gov/public_info/declass/ukusa.shtml|archive-date=July 2, 2013}} UKUSA Agreement between the Five Eyes that cooperated on signals intelligence and ECHELON,{{cite news |url=https://www.theguardian.com/uk/2002/sep/14/privacy|author=Bamford, James|date=September 13, 2002|title=What big ears you have |work=The Guardian|access-date=July 11, 2013|location=London}} NSA stations were built at GCHQ Bude in Morwenstow, United Kingdom; Geraldton, Pine Gap and Shoal Bay, Australia; Leitrim and Ottawa, Ontario, Canada; Misawa, Japan; and Waihopai and Tangimoana,Tangimoana listed in: {{cite web|title=Government Communications Security Bureau [GCSB]|url=https://fas.org/irp/world/new_zealand/gcsb/index.html|publisher=Federation of American Scientists|access-date=July 11, 2013|archive-date=September 11, 2013|archive-url=https://web.archive.org/web/20130911055711/http://www.fas.org/irp/world/new_zealand/gcsb/index.html|url-status=live}} New Zealand.{{cite web|url=http://world-information.org/wio/infostructure/100437611746/100438659207/?ic=100446325241|title=ECHELON Main Stations|publisher=World-Information.org|access-date=July 11, 2013|archive-url=https://web.archive.org/web/20131022081511/http://world-information.org/wio/infostructure/100437611746/100438659207/?ic=100446325241|archive-date=October 22, 2013|url-status=dead}}
NSA operates RAF Menwith Hill in North Yorkshire, United Kingdom, which was, according to BBC News in 2007, the largest electronic monitoring station in the world.{{cite news|url=http://news.bbc.co.uk/1/hi/uk_politics/6916262.stm|work=BBC News|title=UK agrees missile defense request|date=July 25, 2007|access-date=June 10, 2013|archive-date=December 8, 2019|archive-url=https://web.archive.org/web/20191208052826/http://news.bbc.co.uk/1/hi/uk_politics/6916262.stm|url-status=live}} Planned in 1954, and opened in 1960, the base covered {{convert|562|acre|ha sqmi}} in 1999.{{cite news|author=Campbell, Duncan|date=December 6, 1999|url=http://www.newstatesman.com/node/136356|title=1980 – America's big ear on Europe|work=New Statesman|access-date=June 15, 2013|archive-date=June 2, 2013|archive-url=https://web.archive.org/web/20130602064705/http://www.newstatesman.com/node/136356|url-status=live}} The agency's European Cryptologic Center (ECC), with 240 employees in 2011, is headquartered at a US military compound in Griesheim, near Frankfurt in Germany. A 2011 NSA report indicates that the ECC is responsible for the "largest analysis and productivity in Europe" and focuses on various priorities, including Africa, Europe, the Middle East, and counterterrorism operations.Laura Poitras, Marcel Rosenbach and Holger Stark, [http://www.spiegel.de/international/world/germany-is-a-both-a-partner-to-and-a-target-of-nsa-surveillance-a-916029.html Ally and Target: US Intelligence Watches Germany Closely]{{Webarchive|url=https://web.archive.org/web/20130820142333/http://www.spiegel.de/international/world/germany-is-a-both-a-partner-to-and-a-target-of-nsa-surveillance-a-916029.html |date=2013-08-20 }}, August 12, 2013.
In 2013, a new Consolidated Intelligence Center, also to be used by NSA, is being built at the headquarters of the United States Army Europe in Wiesbaden, Germany.{{cite news|url=http://www.spiegel.de/international/world/edward-snowden-accuses-germany-of-aiding-nsa-in-spying-efforts-a-909847.html|publisher=Spiegel International|title=Snowden Interview: NSA and the Germans 'In Bed Together'|date=July 7, 2013|access-date=July 8, 2013|archive-date=July 8, 2013|archive-url=https://web.archive.org/web/20130708095136/http://www.spiegel.de/international/world/edward-snowden-accuses-germany-of-aiding-nsa-in-spying-efforts-a-909847.html|url-status=live}} NSA's partnership with Bundesnachrichtendienst (BND), the German foreign intelligence service, was confirmed by BND president Gerhard Schindler.
== Thailand ==
Thailand is a "3rd party partner" of the NSA along with nine other nations.{{cite web|last1=Campbell|first1=Duncan|title=Paper 1: Echelon and its role in COMINT|url=http://www.heise.de/tp/artikel/7/7747/1.html|website=heise online|date=27 May 2001|access-date=March 11, 2015|archive-date=16 August 2016|archive-url=https://web.archive.org/web/20160816215011/http://www.heise.de/tp/artikel/7/7747/1.html|url-status=live}} These are non-English-speaking countries that have made security agreements for the exchange of SIGINT raw material and end product reports. Thailand is the site of at least two US SIGINT collection stations. One is at the US Embassy in Bangkok, an NSA-CIA Joint Special Collection Service (JSCS) unit. It presumably eavesdrops on foreign consulates, embassies, governmental communications, and other targets of opportunity.{{cite web|title=NSA's global interception network|url=http://electrospaces.blogspot.com/2013/12/nsas-global-interception-network.html|website=electrospaces.net|access-date=March 11, 2015|date=July 17, 2014|archive-date=December 25, 2014|archive-url=https://web.archive.org/web/20141225132429/http://electrospaces.blogspot.com/2013/12/nsas-global-interception-network.html|url-status=live}}
The second installation is a FORNSAT (foreign satellite interception) station in the Thai city of Khon Kaen. It is codenamed INDRA, but has also been referred to as LEMONWOOD. The station is approximately {{convert|40|ha|acre}} in size and consists of a large 3,700–4,600 m2 (40,000–50,000 ft2) operations building on the west side of the ops compound and four radome-enclosed parabolic antennas. Possibly two of the radome-enclosed antennas are used for SATCOM intercept and two antennas are used for relaying the intercepted material back to the NSA. There is also a PUSHER-type circularly-disposed antenna array (CDAA) just north of the ops compound.{{cite web|title=NSA Satellite Communications SIGINT Station in Thailand Found|url=http://www.matthewaid.com/post/56608069320/nsa-satellite-communications-sigint-station-in|work=matthewaid.com/|access-date=March 11, 2015|date=July 27, 2013|archive-date=March 17, 2015|archive-url=https://web.archive.org/web/20150317075324/http://www.matthewaid.com/post/56608069320/nsa-satellite-communications-sigint-station-in|url-status=live}}{{cite web|title=Thai map|url=https://www.google.com/maps/@16.4755559,102.8442837,171m/data=!3m1!1e3?hl=en|website=Google Maps|access-date=March 11, 2015|archive-date=October 16, 2015|archive-url=https://web.archive.org/web/20151016020520/https://www.google.com/maps/@16.4755559,102.8442837,171m/data=!3m1!1e3?hl=en|url-status=live}} NSA activated Khon Kaen in October 1979. Its mission was to eavesdrop on the radio traffic of Chinese army and air force units in southern China, especially in and around the city of Kunming in Yunnan Province. In the late 1970s, the base consisted only of a small CDAA antenna array that was remote-controlled via satellite from the NSA listening post at Kunia, Hawaii, and a small force of civilian contractors from Bendix Field Engineering Corp. whose job it was to keep the antenna array and satellite relay facilities up and running 24/7. According to the papers of the late General William Odom, the INDRA facility was upgraded in 1986 with a new British-made PUSHER CDAA antenna as part of an overall upgrade of NSA and Thai SIGINT facilities whose objective was to spy on the neighboring communist nations of Vietnam, Laos, and Cambodia. The base fell into disrepair in the 1990s as China and Vietnam became more friendly towards the US, and by 2002 archived satellite imagery showed that the PUSHER CDAA antenna had been torn down, perhaps indicating that the base had been closed. At some point in the period since 9/11, the Khon Kaen base was reactivated and expanded to include a sizeable SATCOM intercept mission. It is likely that the NSA presence at Khon Kaen is relatively small, and that most of the work is done by civilian contractors.
Research and development
NSA has been involved in debates about public policy, both indirectly as a behind-the-scenes adviser to other departments, and directly during and after Vice Admiral Bobby Ray Inman's directorship. NSA was a major player in the debates of the 1990s regarding the export of cryptography in the United States. Restrictions on export were reduced but not eliminated in 1996. Its secure government communications work has involved the NSA in numerous technology areas, including the design of specialized communications hardware and software, production of dedicated semiconductors at the Ft. Meade chip fabrication plant), and advanced cryptography research. For 50 years, the NSA designed and built most of its in-house computer equipment, but from the 1990s until about 2003 (when the U.S. Congress curtailed the practice), the agency contracted with the private sector in the fields of research and equipment.{{cite news|title=Congress curbs NSA's power to contract with suppliers|author=Sabar, Ariel|date=July 20, 2013|url=https://www.baltimoresun.com/2003/07/20/congress-curbs-nsas-power-to-contract-with-suppliers/|work=Baltimore Sun|publisher=Tribune Company|access-date=June 17, 2013|archive-date=May 10, 2013|archive-url=https://web.archive.org/web/20130510235528/http://articles.baltimoresun.com/2003-07-20/news/0307200276_1_nsa-eavesdropping-agency|url-status=live}}
= Data Encryption Standard =
{{Main|Data Encryption Standard}}
File:Frostburg.jpg was the NSA's first supercomputer, used from 1991 to 1997]]
NSA was embroiled in some controversy concerning its involvement in the creation of the Data Encryption Standard (DES), a standard and public block cipher algorithm used by the U.S. government and banking community.{{cite web |url=https://cryptome.org/2021/04/Joseph-Meyer-IEEE-1977.pdf |title=The NSA Comes Out of the Closet: The Debate over Public Cryptography in the Inman Era (U) |work=Cryptologic Quarterly |publisher=U.S. National Security Agency |quote=Public cryptography issues were overwhelming Inman and the NSA. (p.12) |access-date=2024-06-07 |archive-date=2024-05-12 |archive-url=https://web.archive.org/web/20240512130341/https://cryptome.org/2021/04/Joseph-Meyer-IEEE-1977.pdf |url-status=live }} During the development of DES by IBM in the 1970s, NSA recommended changes to some details of the design. There was suspicion that these changes had weakened the algorithm sufficiently to enable the agency to eavesdrop if required, including speculation that a critical component—the so-called S-boxes—had been altered to insert a "backdoor" and that the reduction in key length might have made it feasible for NSA to discover DES keys using massive computing power. It has since been observed that the S-boxes in DES are particularly resilient against differential cryptanalysis, a technique that was not publicly discovered until the late 1980s but known to the IBM DES team.
= Advanced Encryption Standard =
{{Main|Advanced Encryption Standard}}
The involvement of the NSA in selecting a successor to the Data Encryption Standard (DES), the Advanced Encryption Standard (AES), was limited to hardware performance testing (see AES competition).{{cite web|title=Hardware Performance Simulations of Round 2 Advanced Encryption Standard Algorithms|author=Weeks, Bryan|url=http://csrc.nist.gov/archive/aes/round2/NSA-AESfinalreport.pdf|publisher=National Institute of Standards and Technology|access-date=June 29, 2013|display-authors=etal|archive-url=https://web.archive.org/web/20111024234406/http://csrc.nist.gov/archive/aes/round2/NSA-AESfinalreport.pdf|archive-date=2011-10-24|url-status=dead}} NSA has subsequently certified AES for protection of classified information when used in NSA-approved systems."the NIST standards that define Suite B..." in {{cite web|title=Suite B Cryptography / Cryptographic Interoperability|url=https://www.nsa.gov/ia/programs/suiteb_cryptography/|publisher=National Security Agency|access-date=June 29, 2013|archive-url=https://web.archive.org/web/20160101091229/https://www.nsa.gov/ia/programs/suiteb_cryptography/|archive-date=2016-01-01|url-status=dead}}
= NSA encryption systems =
File:STU-IIIphones.nsa.jpg secure telephones on display at the National Cryptologic Museum]]
{{Main|NSA encryption systems}}
The NSA is responsible for the encryption-related components in these legacy systems:
- FNBDT Future Narrow Band Digital Terminal{{cite book|title=C4ISR for Future Naval Strike Groups|author=Committee on C4ISR for Future Naval Strike Groups, National Research Council|isbn=978-0-309-09600-3|publisher=National Academies Press |year=2006|page=167 |url=https://books.google.com/books?id=NByKhCK3edkC&pg=PA167}}
- KL-7 ADONIS off-line rotor encryption machine (post-WWII – 1980s)"Adkins Family asked for a pic of the KL-7. Here you go!..." in {{cite web|url=https://www.facebook.com/NationalCryptologicMuseum|date=March 20, 2013|title=NSA – National Cryptologic Museum|publisher=Facebook|access-date=June 30, 2013|archive-date=June 5, 2013|archive-url=https://web.archive.org/web/20130605203039/https://www.facebook.com/NationalCryptologicMuseum|url-status=live}}{{cite web|title=Cryptographic Damage Assessment: DOCID: 3997687|year=1968|url=https://www.nsa.gov/public_info/_files/uss_pueblo/Section_V_Cryptographic_Damage_Assessment.pdf|publisher=National Security Agency|access-date=June 30, 2013|url-status=dead|archive-url=https://web.archive.org/web/20130918031554/http://www.nsa.gov/public_info/_files/uss_pueblo/Section_V_Cryptographic_Damage_Assessment.pdf|archive-date=September 18, 2013}}
- KW-26 ROMULUS electronic in-line teletypewriter encryptor (1960s–1980s){{cite web|title=Cryptologic Excellence: Yesterday, Today and Tomorrow|year=2002|url=https://www.nsa.gov/about/_files/cryptologic_heritage/publications/misc/50th_anniversary.pdf|publisher=National Security Agency|access-date=June 30, 2013|page=17|archive-url=https://web.archive.org/web/20130918014341/http://www.nsa.gov/about/_files/cryptologic_heritage/publications/misc/50th_anniversary.pdf|archive-date=2013-09-18|url-status=dead}}
- KW-37 JASON fleet broadcast encryptor (1960s–1990s)
- KY-57 VINSON tactical radio voice encryptor
- KG-84 Dedicated Data Encryption/Decryption
- STU-III secure telephone unit, phased out by the STE{{cite news|url=http://gcn.com/articles/2010/01/06/nsa-certifies-viper-for-classified-communications.aspx|author=Hickey, Kathleen|date=January 6, 2010|title=NSA certifies Sectera Viper phone for classified communications|publisher=1105 Media|work=GCN|access-date=June 30, 2013|archive-date=January 25, 2014|archive-url=https://web.archive.org/web/20140125092308/http://gcn.com/articles/2010/01/06/nsa-certifies-viper-for-classified-communications.aspx|url-status=dead}}
The NSA oversees encryption in the following systems that are in use today:
- EKMS Electronic Key Management System{{cite web|url=http://jitc.fhu.disa.mil/ekms/|title=JITC Networks, Transmissions, and Integration Division Electronic Key Management System (EKMS)|date=February 1991|publisher=U.S. Department of Defense: Defense Information Systems Agency: Joint Interoperability Certifier|access-date=June 30, 2013 |url-status=dead|archive-url=https://web.archive.org/web/20130515225818/http://jitc.fhu.disa.mil/ekms/|archive-date=May 15, 2013}}
- Fortezza encryption based on portable crypto token in PC Card format{{cite web|url=http://www.rsa.com/rsalabs/node.asp?id=2320|title=6.2.6 What is Fortezza?|publisher=RSA Laboratories, EMC Corporation|access-date=June 30, 2013|url-status=dead|archive-url=https://web.archive.org/web/20120715221703/http://www.rsa.com/rsalabs/node.asp?id=2320|archive-date=July 15, 2012}}
- SINCGARS tactical radio with cryptographically controlled frequency hopping{{cite web|url=http://www.raytheon.com/capabilities/products/arc231/|title=AN/ARC-231 Airborne Communication System|publisher=Raytheon|access-date=June 30, 2013|archive-date=December 25, 2012|archive-url=https://web.archive.org/web/20121225134947/http://www.raytheon.com/capabilities/products/arc231/|url-status=live}}
- STE secure terminal equipment
- TACLANE product line by General Dynamics C4 Systems{{cite news|url=http://www.upi.com/Business_News/Security-Industry/2007/10/24/NSA-approves-TACLANE-Router/UPI-47061193262728/|date=October 24, 2007|title=NSA approves TACLANE-Router|publisher=United Press International|access-date=June 30, 2013|archive-date=December 15, 2012|archive-url=https://web.archive.org/web/20121215022929/http://www.upi.com/Business_News/Security-Industry/2007/10/24/NSA-approves-TACLANE-Router/UPI-47061193262728/|url-status=live}}
The NSA has specified Suite A and Suite B cryptographic algorithm suites to be used in U.S. government systems; the Suite B algorithms are a subset of those previously specified by NIST and are expected to serve for most information protection purposes, while the Suite A algorithms are secret and are intended for especially high levels of protection.
= SHA =
The widely used SHA-1 and SHA-2 hash functions were designed by NSA. SHA-1 is a slight modification of the weaker SHA-0 algorithm, also designed by NSA in 1993. This small modification was suggested by the NSA two years later, with no justification other than the fact that it provides additional security. An attack for SHA-0 that does not apply to the revised algorithm was indeed found between 1998 and 2005 by academic cryptographers. Because of weaknesses and key length restrictions in SHA-1, NIST deprecates its use for digital signatures and approves only the newer SHA-2 algorithms for such applications from 2013 on.Draft NIST SP 800-131, June 2010.
A new hash standard, SHA-3, has recently been selected through the competition concluded on October 2, 2012, with the selection of Keccak as the algorithm. The process to select SHA-3 was similar to the one held in choosing the AES, but some doubts have been cast over it,{{cite web |last=Lorenzo |first=Joseph |url=https://www.cdt.org/blogs/joseph-lorenzo-hall/2409-nist-sha-3 |title=What the heck is going on with NIST's cryptographic standard, SHA-3? | Center for Democracy & Technology |publisher=Cdt.org |date=September 24, 2013 |access-date=October 9, 2013 |archive-date=January 25, 2014 |archive-url=https://web.archive.org/web/20140125143053/https://www.cdt.org/blogs/joseph-lorenzo-hall/2409-nist-sha-3 |url-status=live }}{{cite web |url=https://twitter.com/marshray/status/380800393367674880 |title=Twitter / marshray: Believe it or not, NIST is |publisher=Twitter.com |access-date=October 9, 2013 |archive-date=February 28, 2019 |archive-url=https://web.archive.org/web/20190228084249/https://twitter.com/marshray/status/380800393367674880 |url-status=live }} since fundamental modifications have been made to Keccak to turn it into a standard.{{cite web|url=https://docs.google.com/file/d/0BzRYQSHuuMYOQXdHWkRiZXlURVE/ |title=kelsey-invited-ches-0820.pdf – Google Drive |access-date=October 9, 2013}} These changes potentially undermine the cryptanalysis performed during the competition and reduce the security levels of the algorithm.
= Clipper chip =
{{Main|Clipper chip}}
Because of concerns that widespread use of strong cryptography would hamper government use of wiretaps, the NSA proposed the concept of key escrow in 1993 and introduced the Clipper chip that would offer stronger protection than DES but would allow access to encrypted data by authorized law enforcement officials.{{cite magazine|author=Baker, Stewart A.|title=Don't Worry Be Happy|url=https://www.wired.com/wired/archive/2.06/nsa.clipper_pr.html|magazine=Wired|volume=2|issue=6|access-date=June 28, 2013|archive-date=October 11, 2008|archive-url=https://web.archive.org/web/20081011095737/http://www.wired.com/wired/archive/2.06/nsa.clipper_pr.html|url-status=live}} The proposal was strongly opposed and key escrow requirements ultimately went nowhere.{{cite web|title=Key Escrow, Key Recovery, Trusted Third Parties & Govt. Access to Keys |url=http://w2.eff.org/Privacy/Key_escrow/|publisher=Electronic Frontier Foundation|access-date=June 28, 2013 |url-status=dead |archive-url=https://web.archive.org/web/20120429112956/http://w2.eff.org/Privacy/Key_escrow/|archive-date=April 29, 2012}} However, NSA's Fortezza hardware-based encryption cards, created for the Clipper project, are still used within government, and NSA ultimately declassified and published the design of the Skipjack cipher used on the cards.{{cite web|author=Schneier, Bruce|title=Declassifying Skipjack|url=http://www.schneier.com/crypto-gram-9807.html#skip|publisher=Crypto-Gram (schneier.com)|date=July 15, 1998|access-date=June 28, 2013|archive-date=June 23, 2013|archive-url=https://web.archive.org/web/20130623200937/http://www.schneier.com/crypto-gram-9807.html#skip|url-status=live}}{{cite web|title=SKIPJACK and KEA Algorithm Specifications|date=May 29, 1998|url=http://csrc.nist.gov/groups/ST/toolkit/documents/skipjack/skipjack.pdf|publisher=National Institute of Standards and Technology|access-date=June 28, 2013|archive-url=https://web.archive.org/web/20111021070535/http://csrc.nist.gov/groups/ST/toolkit/documents/skipjack/skipjack.pdf|archive-date=2011-10-21|url-status=dead}}
= Dual EC DRBG random number generator crypto trojan=
{{Main|Dual EC DRBG}}
NSA promoted the inclusion of a random number generator called Dual EC DRBG in the U.S. National Institute of Standards and Technology's 2007 guidelines. This led to speculation of a backdoor which would allow NSA access to data encrypted by systems using that pseudorandom number generator (PRNG).{{cite magazine |url=https://www.wired.com/politics/security/commentary/securitymatters/2007/11/securitymatters_1115|archive-url=https://web.archive.org/web/20121024090318/http://www.wired.com/politics/security/commentary/securitymatters/2007/11/securitymatters_1115 |archive-date=October 24, 2012 |url-status=live|title=Did NSA Put a Secret Backdoor in New Encryption Standard? |first=Bruce |last=Schneier |author-link=Bruce Schneier|magazine=Wired News|date=November 15, 2007|access-date=July 4, 2008}}
This is now deemed to be plausible based on the fact that output of next iterations of PRNG can provably be determined if relation between two internal Elliptic Curve points is known.{{cite web |author=Matthew Green |url=http://blog.cryptographyengineering.com/2013/09/the-many-flaws-of-dualecdrbg.html |title=A Few Thoughts on Cryptographic Engineering: The Many Flaws of Dual_EC_DRBG |publisher=Blog.cryptographyengineering.com |date=September 18, 2013 |access-date=October 9, 2013 |archive-date=August 20, 2016 |archive-url=https://web.archive.org/web/20160820174502/http://blog.cryptographyengineering.com/2013/09/the-many-flaws-of-dualecdrbg.html |url-status=live }}{{cite web|url=http://blog.0xbadc0de.be/archives/155|title=Dual_Ec_Drbg backdoor: a proof of concept at Aris' Blog – Computers, ssh and rock'n roll|work=0xbadc0de.be|date=31 December 2013|access-date=7 June 2024|archive-date=17 December 2014|archive-url=https://web.archive.org/web/20141217102434/http://blog.0xbadc0de.be/archives/155|url-status=live}} Both NIST and RSA are now officially recommending against the use of this PRNG.{{cite web |url=https://www.propublica.org/documents/item/785571-itlbul2013-09-supplemental#document/p2 |title=itlbul2013 09 Supplemental |publisher=ProPublica |access-date=October 9, 2013 |archive-url=https://web.archive.org/web/20131008170739/http://www.propublica.org/documents/item/785571-itlbul2013-09-supplemental#document/p2 |archive-date=October 8, 2013 |url-status=dead }}{{cite web |author=Matthew Green |url=http://blog.cryptographyengineering.com/2013/09/rsa-warns-developers-against-its-own.html |title=A Few Thoughts on Cryptographic Engineering: RSA warns developers not to use RSA products |publisher=Blog.cryptographyengineering.com |date=September 20, 2013 |access-date=October 9, 2013 |archive-date=October 10, 2013 |archive-url=https://web.archive.org/web/20131010085457/http://blog.cryptographyengineering.com/2013/09/rsa-warns-developers-against-its-own.html |url-status=live }}
= Perfect Citizen =
{{Main|Perfect Citizen}}
Perfect Citizen is a program to perform vulnerability assessment by the NSA in the American critical infrastructure.[https://www.wired.com/threatlevel/2010/07/nsa-perfect-citizen-denial/ NSA Denies It Will Spy on Utilities] {{Webarchive|url=https://web.archive.org/web/20140209204445/http://www.wired.com/threatlevel/2010/07/nsa-perfect-citizen-denial/ |date=2014-02-09 }}, Threat Level, Wired.com{{cite news|url=http://www.dailytech.com/NSAs+Perfect+Citizen+Program++Big+Brother+or+Cybersecurity+Savior/article18969.htm|title=DailyTech – NSA's "Perfect Citizen" Program: Big Brother or Cybersecurity Savior?|last=Mick|first=Jason|date=July 8, 2010|work=DailyTech|access-date=July 8, 2010|url-status=dead|archive-url=https://web.archive.org/web/20100711071346/http://www.dailytech.com/NSAs+Perfect+Citizen+Program++Big+Brother+or+Cybersecurity+Savior/article18969.htm|archive-date=July 11, 2010}} It was originally reported to be a program to develop a system of sensors to detect cyber attacks on critical infrastructure computer networks in both the private and public sector through a network monitoring system named Einstein.{{cite news|url=http://news.cnet.com/8301-1009_3-20009952-83.html|title=Report: NSA initiating program to detect cyberattacks|last=Whitney|first=Lance|date=July 8, 2010|work=CNET.com|access-date=July 8, 2010|archive-date=June 17, 2011|archive-url=https://web.archive.org/web/20110617035918/http://news.cnet.com/8301-1009_3-20009952-83.html|url-status=dead}}{{cite news |title=U.S. Program to Detect Cyber Attacks on Infrastructure |url=https://www.wsj.com/articles/SB10001424052748704545004575352983850463108?mod=WSJ_hpp_MIDDLETopStories |newspaper=The Wall Street Journal |date=July 7, 2010 |access-date=July 7, 2010 |first=Siobhan |last=Gorman |archive-date=May 7, 2018 |archive-url=https://web.archive.org/web/20180507085839/https://www.wsj.com/articles/SB10001424052748704545004575352983850463108?mod=WSJ_hpp_MIDDLETopStories |url-status=live }} It is funded by the Comprehensive National Cybersecurity Initiative and thus far Raytheon has received a contract for up to $100 million for the initial stage.
= Academic research =
The NSA has invested many millions of dollars in academic research under grant code prefix MDA904, resulting in over 3,000 papers {{as of|2007|10|11|lc=y|df=US|post=.}} The NSA publishes its documents through various publications.
- Cryptolog is published monthly by PI, Techniques, and Standards, for the Personnel of Operations. Declassified issues are available online.{{cite web |url=http://www.nsa.gov/public_info/declass/cryptologs.shtml |title=NSA Communicators - NSA/CSS |website=www.nsa.gov |url-status=dead |archive-url=https://web.archive.org/web/20120514003049/http://www.nsa.gov/public_info/declass/cryptologs.shtml |archive-date=2012-05-14}}
- The Cryptologic Almanac is a cryptology academic journal published internally by the NSA. It publishes short vignettes about NSA or NSA-related topics. A selection of articles published are available to the public online.
- Cryptologic Quarterly was the combined result of the merger of NSA Technical Journal and Cryptologic Spectrum in 1981. It expanded its coverage to cover a larger segment of NSA readership.
- Cryptologic Spectrum was a cryptology journal published internally by the NSA.{{cite magazine|title=Declassified NSA Document Reveals the Secret History of TEMPEST|last=Singel|first=Ryan|magazine=Wired|publisher=CondéNet, Inc.|url=http://blog.wired.com/27bstroke6/2008/04/nsa-releases-se.html|date=2008-04-29|accessdate=2008-05-01|archiveurl=https://archive.today/20120707123850/http://blog.wired.com/27bstroke6/2008/04/nsa-releases-se.html|archivedate=2012-07-07}} It was established in 1969, until consolidation with the NSA Technical Journal in 1981. A selection of articles published between 1969 and 1981 are available to the public online.{{cite web|url=http://www.nsa.gov/public_info/declass/cryptologic_spectrum.shtml|title=Cryptologic Spectrum Articles|work=Declassification Initiatives|publisher=National Security Agency|accessdate=2010-03-27|url-status=dead|archiveurl=https://web.archive.org/web/20160318090231/http://www.nsa.gov/public_info/declass/cryptologic_spectrum.shtml|archivedate=2016-03-18}} The journal had been classified until its tables of contents were published online in September 2006 following a Freedom of Information Act request in 2003.{{cite magazine|url=https://www.wired.com/politics/security/news/2006/09/71849|title=Peek at NSA's Secret Reading List|last=Singel|first=Ryan|magazine=Wired|publisher=CondéNet, Inc.|date=2006-09-27|accessdate=2008-05-01|archiveurl=https://web.archive.org/web/20070220232300/http://www.wired.com/news/technology/security/0,71849-0.html|archivedate=2007-02-20}}
- The NSA Technical Journal was established in 1954 by Ralph J. Canine to "foster the exchange of ideas and create an 'intellectual community' within the Agency".{{Cite web|url=https://www.nsa.gov/portals/75/documents/news-features/declassified-documents/crypto-almanac-50th/A_Peek_Behind_the_Scenes_Part_2.pdf|title=A Peek Behind the Scenes Part 2|website=National Security Agency|access-date=November 24, 2024}} In 1981, the publication was consolidated with Cryptologic Spectrum into a single publication, called Cryptologic Quarterly.
Despite this, the NSA/CSS has, at times, attempted to restrict the publication of academic research into cryptography; for example, the Khufu and Khafre block ciphers were voluntarily withheld in response to an NSA request to do so. In response to a FOIA lawsuit, in 2013 the NSA released the 643-page research paper titled, "Untangling the Web: A Guide to Internet Research",{{cite web |url=https://www.nsa.gov/public_info/_files/Untangling_the_Web.pdf |title=Untangling the Web: A Guide to Internet Research |author1=Robyn Winder |author2=Charlie Speight |name-list-style=amp |work=National Security Agency Public Information |date=April 19, 2013 |access-date=May 9, 2013 |url-status=dead |archive-url=https://web.archive.org/web/20130509043240/http://www.nsa.gov/public_info/_files/Untangling_the_Web.pdf |archive-date=May 9, 2013 }} written and compiled by NSA employees to assist other NSA workers in searching for information of interest to the agency on the public Internet.{{cite news |url=https://www.wired.com/threatlevel/2013/05/nsa-manual-on-hacking-internet/ |title=Use These Secret NSA Google Search Tips to Become Your Spy Agency |last=Zetter |first=Kim |work=Wired Magazine |date=May 9, 2013 |access-date=June 7, 2024 |archive-date=March 22, 2014 |archive-url=https://web.archive.org/web/20140322033915/http://www.wired.com/threatlevel/2013/05/nsa-manual-on-hacking-internet |url-status=live }}
= Patents =
NSA can file for a patent from the U.S. Patent and Trademark Office under gag order. Unlike normal patents, these are not revealed to the public and do not expire. However, if the Patent Office receives an application for an identical patent from a third party, they will reveal the NSA's patent and officially grant it to the NSA for the full term on that date.{{cite book |last=Schneier|first=Bruce|author-link=Bruce Schneier|title=Applied Cryptography, Second Edition|publisher=John Wiley & Sons |year=1996|pages=609–610|isbn=978-0-471-11709-4}}
One of NSA's published patents describes a method of geographically locating an individual computer site in an Internet-like network, based on the latency of multiple network connections.{{cite web|publisher=United States Patent and Trademark Office|title=United States Patent 6,947,978 – Method for geolocating logical network addresses|url=http://patft.uspto.gov/netacgi/nph-Parser?Sect2=PTO1&Sect2=HITOFF&p=1&u=%2Fnetahtml%2FPTO%2Fsearch-bool.html&r=1&f=G&l=50&d=PALL&RefSrch=yes&Query=PN%2F6947978|date=September 20, 2005|access-date=July 4, 2008|archive-date=September 4, 2015|archive-url=https://web.archive.org/web/20150904005823/http://patft.uspto.gov/netacgi/nph-Parser?Sect2=PTO1&Sect2=HITOFF&p=1&u=%2Fnetahtml%2FPTO%2Fsearch-bool.html&r=1&f=G&l=50&d=PALL&RefSrch=yes&Query=PN%2F6947978|url-status=dead}} Although no public patent exists, NSA is reported to have used a similar locating technology called trilateralization that allows real-time tracking of an individual's location, including altitude from ground level, using data obtained from cellphone towers.{{cite news |url=https://www.nytimes.com/2013/06/09/us/revelations-give-look-at-spy-agencys-wider-reach.html?pagewanted=all |title=How the U.S. Uses Technology to Mine More Data More Quickly |author=James Risen and Eric Lichtblau |newspaper=The New York Times |date=June 10, 2013 |access-date=June 13, 2013 |archive-date=June 13, 2013 |archive-url=https://web.archive.org/web/20130613004529/http://www.nytimes.com/2013/06/09/us/revelations-give-look-at-spy-agencys-wider-reach.html?pagewanted=all |url-status=live }}
Insignia and memorials
File:National Security Agency.svg
The heraldic insignia of NSA consists of an eagle inside a circle, grasping a key in its talons. The eagle represents the agency's national mission. Its breast features a shield with bands of red and white, taken from the Great Seal of the United States and representing Congress. The key is taken from the emblem of Saint Peter and represents security.{{cite web|url=https://www.nsa.gov/about/faqs/about_nsa.shtml#about9|title=Frequently Asked Questions About NSA: 9. Can you explain the NSA and CSS seals?|publisher=National Security Agency|access-date=July 18, 2013|archive-date=July 25, 2013|archive-url=https://web.archive.org/web/20130725003854/http://www.nsa.gov/about/faqs/about_nsa.shtml#about9|url-status=live}}
When the NSA was created, the agency had no emblem and used that of the Department of Defense.{{cite web|url=https://www.nsa.gov/about/cryptologic_heritage/center_crypt_history/insignia/index.shtml|title=History of The Insignia|publisher=National Security Agency|access-date=July 18, 2013|archive-date=July 8, 2013|archive-url=https://web.archive.org/web/20130708163433/http://www.nsa.gov/about/cryptologic_heritage/center_crypt_history/insignia/index.shtml|url-status=live}} The agency adopted its first of two emblems in 1963. The current NSA insignia has been in use since 1965, when then-Director, LTG Marshall S. Carter (USA) ordered the creation of a device to represent the agency.{{cite web|title=The National Security Agency Insignia|publisher=National Security Agency via Internet Archive|url=https://www.nsa.gov/history/histo00018.cfm|archive-url=https://web.archive.org/web/20080413063307/http://www.nsa.gov/history/histo00018.cfm|archive-date=April 13, 2008|access-date=July 18, 2013|url-status=dead}} The NSA's flag consists of the agency's seal on a light blue background.
File:They Served In Silence - National Cryptologic Museum - DSC07636.JPG
Crews associated with NSA missions have been involved in several dangerous and deadly situations. The USS Liberty incident in 1967 and USS Pueblo incident in 1968 are examples of the losses endured during the Cold War.{{cite web|title=A Dangerous Business: The U.S. Navy and National Reconnaissance During the Cold War|url=https://www.nsa.gov/about/_files/cryptologic_heritage/publications/coldwar/dangerous_business.pdf|publisher=National Security Agency|access-date=June 13, 2013|archive-url=https://web.archive.org/web/20130918005012/http://www.nsa.gov/about/_files/cryptologic_heritage/publications/coldwar/dangerous_business.pdf|archive-date=2013-09-18|url-status=dead}} The National Security Agency/Central Security Service Cryptologic Memorial honors and remembers the fallen personnel, both military and civilian, of these intelligence missions. It is made of black granite, and has 171 names carved into it, {{As of|2013|lc=on|post=.}} It is located at NSA headquarters. A tradition of declassifying the stories of the fallen was begun in 2001.{{cite web|url=https://www.nsa.gov/about/cryptologic_heritage/memorial_wall/memorial_wall_list.shtml|title=National Cryptologic Memorial (List of Names) – NSA/CSS|publisher=NSA.gov|access-date=June 13, 2013|archive-date=June 14, 2013|archive-url=https://web.archive.org/web/20130614022304/http://www.nsa.gov/about/cryptologic_heritage/memorial_wall/memorial_wall_list.shtml|url-status=live}}
Constitutionality, legality, and privacy concerning operations
{{See also|Mass surveillance in the United States}}
In the United States, at least since 2001,[http://scholarship.law.duke.edu/cgi/viewcontent.cgi?article=1113&context=dlj Echelon and the Legal Restraints on Signals Intelligence: A Need For Reevalualtion] {{Webarchive|url=https://web.archive.org/web/20240606064111/https://scholarship.law.duke.edu/cgi/viewcontent.cgi?article=1113&context=dlj |date=2024-06-06 }} by Lawrence D. Sloan on April 30, 2001 there has been legal controversy over what signal intelligence can be used for and how much freedom the National Security Agency has to use signal intelligence.Liu, Edward C. et al. (May 21, 2015) [https://fas.org/sgp/crs/intel/R43459.pdf Overview of Constitutional Challenges to NSA Collection Activities] {{Webarchive|url=https://web.archive.org/web/20210308123629/https://fas.org/sgp/crs/intel/R43459.pdf |date=2021-03-08 }}. Washington, DC: Congressional Research Service. In 2015, the government made slight changes in how it uses and collects certain types of data,{{cite news|url=https://www.nytimes.com/2015/02/03/world/president-tweaks-the-rules-on-data-collection.html|title=Obama's changes to NSA data collection published on February 5, 2015, by Christina Murray quoting David E. Sanger of The New York Times|newspaper=The New York Times|date=3 February 2015|last1=Sanger|first1=David E.|access-date=7 June 2024|archive-date=12 May 2024|archive-url=https://web.archive.org/web/20240512124423/https://www.nytimes.com/2015/02/03/world/president-tweaks-the-rules-on-data-collection.html|url-status=live}} specifically phone records. The government was not analyzing the phone records as of early 2019.{{Cite news|url=https://www.nytimes.com/2019/03/04/us/politics/nsa-phone-records-program-shut-down.html|title=Disputed N.S.A. Phone Program Is Shut Down, Aide Says|last=Savage|first=Charlie|date=2019-03-04|work=The New York Times|access-date=2019-03-06|language=en-US|issn=0362-4331|archive-date=2019-03-06|archive-url=https://web.archive.org/web/20190306005802/https://www.nytimes.com/2019/03/04/us/politics/nsa-phone-records-program-shut-down.html|url-status=live}} The surveillance programs were deemed unlawful in September 2020 in a court of appeals case.
=Warrantless surveillance=
{{See also|NSA warrantless surveillance (2001–2007)}}
On December 16, 2005, The New York Times reported that under White House pressure and with an executive order from President George W. Bush, the National Security Agency, in an attempt to thwart terrorism, had been tapping phone calls made to persons outside the country, without obtaining warrants from the United States Foreign Intelligence Surveillance Court, a secret court created for that purpose under the Foreign Intelligence Surveillance Act (FISA).
=[[Edward Snowden]]=
Edward Snowden is a former American intelligence contractor who revealed in 2013 the existence of secret wide-ranging information-gathering programs conducted by the National Security Agency (NSA).{{cite web |title=Edward Snowden |url=https://www.britannica.com/biography/Edward-Snowden |access-date=February 6, 2022 |archive-date=February 2, 2022 |archive-url=https://web.archive.org/web/20220202130452/https://www.britannica.com/biography/Edward-Snowden |url-status=live }} More specifically, Snowden released information that demonstrated how the United States government was gathering immense amounts of personal communications, emails, phone locations, web histories and more of American citizens without their knowledge.{{cite web
| title= Why Edward Snowden should be pardoned
| url= https://www.amnesty.org.uk/edward-snowden-nsa-whistleblower-pardon
| access-date= February 6, 2022
| archive-date= February 7, 2022
| archive-url= https://web.archive.org/web/20220207014116/https://www.amnesty.org.uk/edward-snowden-nsa-whistleblower-pardon
| url-status= live
}} One of Snowden's primary motivators for releasing this information was fear of a surveillance state developing as a result of the infrastructure being created by the NSA. As Snowden recounts, "I believe that, at this point in history, the greatest danger to our freedom and way of life comes from the reasonable fear of omniscient State powers kept in check by nothing more than policy documents... It is not that I do not value intelligence, but that I oppose . . . omniscient, automatic, mass surveillance. . . . That seems to me a greater threat to the institutions of free society than missed intelligence reports, and unworthy of the costs."{{cite web
| title= Why NSA IT Guy Edward Snowden Leaked Top Secret Documents
| website= Forbes
| url= https://www.forbes.com/sites/kashmirhill/2013/06/10/why-nsa-it-guy-edward-snowden-leaked-top-secret-documents/?sh=6e3f2e755673
| date= June 10, 2013
| access-date= June 7, 2024
| archive-date= May 12, 2024
| archive-url= https://web.archive.org/web/20240512132008/https://www.forbes.com/sites/kashmirhill/2013/06/10/why-nsa-it-guy-edward-snowden-leaked-top-secret-documents/?sh=6e3f2e755673
| url-status= live
}}
In March 2014, Army General Martin Dempsey, Chairman of the Joint Chiefs of Staff, told the House Armed Services Committee, "The vast majority of the documents that Snowden ... exfiltrated from our highest levels of security ... had nothing to do with exposing government oversight of domestic activities. The vast majority of those were related to our military capabilities, operations, tactics, techniques, and procedures."{{Cite news |last=Capra |first=Tony |date=March 6, 2014 |title=Snowden Leaks Could Cost Military Billions: Pentagon |work=NBC News |url=https://www.nbcnews.com/news/investigations/snowden-leaks-could-cost-military-billions-pentagon-n46426 |access-date=April 11, 2015 |archive-date=April 10, 2015 |archive-url=https://web.archive.org/web/20150410091944/http://www.nbcnews.com/news/investigations/snowden-leaks-could-cost-military-billions-pentagon-n46426 |url-status=live }} When asked in a May 2014 interview to quantify the number of documents Snowden stole, retired NSA director Keith Alexander said there was no accurate way of counting what he took, but Snowden may have downloaded more than a million documents.{{Cite web |title=Interview transcript: former head of the NSA and commander of the US cyber command, General Keith Alexander |url=http://www.afr.com/p/technology/interview_transcript_former_head_51yP0Cu1AQGUCs7WAC9ZVN |archive-url=https://web.archive.org/web/20141006113815/http://www.afr.com/p/technology/interview_transcript_former_head_51yP0Cu1AQGUCs7WAC9ZVN |archive-date=October 6, 2014 |access-date=May 30, 2014 |website=Australian Financial Review}}
=Other surveillance programs=
On January 17, 2006, the Center for Constitutional Rights filed a lawsuit, CCR v. Bush, against the George W. Bush presidency. The lawsuit challenged the National Security Agency's (NSA's) surveillance of people within the U.S., including the interception of CCR emails without securing a warrant first.{{cite news |url=http://jurist.law.pitt.edu/paperchase/2007/05/ex-guantanamo-lawyers-sue-for.php |date=May 19, 2007 |title=Ex-Guantanamo lawyers sue for recordings of client meetings |author=Mike Rosen-Molina |publisher=The Jurist |access-date=May 22, 2007 |url-status=dead |archive-url=https://web.archive.org/web/20080502051556/http://jurist.law.pitt.edu/paperchase/2007/05/ex-guantanamo-lawyers-sue-for.php |archive-date=May 2, 2008 }}{{cite web|url=http://ccrjustice.org/ourcases/current-cases/ccr-v.-bush|title=CCR v. Bush|publisher=Center for Constitutional Rights|access-date=June 15, 2009|archive-date=June 17, 2009|archive-url=https://web.archive.org/web/20090617195549/http://ccrjustice.org/ourcases/current-cases/ccr-v.-bush|url-status=live}}
In the August 2006 case ACLU v. NSA, U.S. District Court Judge Anna Diggs Taylor concluded that NSA's warrantless surveillance program was both illegal and unconstitutional. On July 6, 2007, the 6th Circuit Court of Appeals vacated the decision because the ACLU lacked standing to bring the suit.{{cite web |url=http://fl1.findlaw.com/news.findlaw.com/nytimes/docs/nsa/aclunsa70607opn.pdf |title=6th Circuit Court of Appeals Decision |access-date=October 9, 2013 |archive-url=https://web.archive.org/web/20130117053024/http://fl1.findlaw.com/news.findlaw.com/nytimes/docs/nsa/aclunsa70607opn.pdf |archive-date=January 17, 2013 |url-status=dead |df=mdy-all }}
In September 2008, the Electronic Frontier Foundation (EFF) filed a class action lawsuit against the NSA and several high-ranking officials of the Bush administration,{{cite news|url=http://www.digitaljournal.com/article/260075|title=Jewel Vs. NSA Aims To Stop Illegal Surveillance|author=KJ Mullins|date=September 20, 2008|work=Digital Journal|access-date=December 30, 2011|archive-date=January 25, 2014|archive-url=https://web.archive.org/web/20140125120448/http://www.digitaljournal.com/article/260075|url-status=live}} charging an "illegal and unconstitutional program of dragnet communications surveillance,"[https://www.eff.org/files/filenode/jewel/jewel.complaint.pdf Jewel v. NSA (complaint)] {{Webarchive|url=https://web.archive.org/web/20180528044116/https://www.eff.org/files/filenode/jewel/jewel.complaint.pdf |date=2018-05-28 }}. September 18, 2008. Electronic Frontier Foundation. Retrieved December 30, 2011. based on documentation provided by former AT&T technician Mark Klein.{{cite magazine|url=https://www.wired.com/threatlevel/2009/07/jewel/|title=Obama Claims Immunity, As New Spy Case Takes Center Stage|first=David|last=Kravets|date=July 15, 2009|magazine=Wired|access-date=December 30, 2011|archive-date=December 31, 2011|archive-url=https://web.archive.org/web/20111231090151/http://www.wired.com/threatlevel/2009/07/jewel/|url-status=live}}
As a result of the USA Freedom Act passed by Congress in June 2015, the NSA had to shut down its bulk phone surveillance program on November 29 of the same year. The USA Freedom Act forbids the NSA to collect metadata and content of phone calls unless it has a warrant for terrorism investigation. In that case, the agency must ask the telecom companies for the record, which will only be kept for six months. The NSA's use of large telecom companies to assist it with its surveillance efforts has caused several privacy concerns.{{Cite journal|last=Van Loo|first=Rory|date=2019-10-01|title=The Missing Regulatory State: Monitoring Businesses in an Age of Surveillance|url=https://scholarship.law.bu.edu/faculty_scholarship/678|journal=Vanderbilt Law Review|volume=72|issue=5|page=1563|access-date=2024-06-07|archive-date=2024-05-12|archive-url=https://web.archive.org/web/20240512124224/https://scholarship.law.bu.edu/faculty_scholarship/678/|url-status=live}}{{rp|1568–69}}
= AT&T Internet monitoring =
{{Further|Hepting v. AT&T|Jewel v. NSA|Mark Klein|NSA warrantless surveillance (2001–2007)}}
In May 2008, Mark Klein, a former AT&T employee, alleged that his company had cooperated with NSA in installing Narus hardware to replace the FBI Carnivore program, to monitor network communications including traffic between U.S. citizens.{{cite journal|date=February 16, 2007|title=For Your Eyes Only?|journal=NOW|url=https://www.pbs.org/now/shows/307/index.html|access-date=June 7, 2024|archive-date=April 9, 2014|archive-url=https://web.archive.org/web/20140409130359/http://www.pbs.org/now/shows/307/index.html|url-status=live}} on PBS
= Data mining =
NSA was reported in 2008 to use its computing capability to analyze "transactional" data that it regularly acquires from other government agencies, which gather it under their jurisdictional authorities.{{cite news |url=https://www.wsj.com/articles/SB120511973377523845 |archive-url=https://web.archive.org/web/20090124141023/http://online.wsj.com/public/article_print/SB120511973377523845.html |archive-date=January 24, 2009 |title=NSA's Domestic Spying Grows As Agency Sweeps Up Data |first=Siobahn|last=Gorman|publisher=The Wall Street Journal Online|date=March 10, 2008 |url-status=dead |access-date=March 14, 2014}}
A 2013 advisory group for the Obama administration, seeking to reform NSA spying programs following the revelations of documents released by Edward J. Snowden,[https://obamawhitehouse.archives.gov/sites/default/files/docs/2013-12-12_rg_final_report.pdf Liberty and Security in a Changing World] {{webarchive|url=https://web.archive.org/web/20170124173532/https://obamawhitehouse.archives.gov/sites/default/files/docs/2013-12-12_rg_final_report.pdf |date=2017-01-24 }} – Report and Recommendations of The President's Review Group on Intelligence and Communications Technologies, December 12, 2013, 308 pages mentioned in 'Recommendation 30' on page 37, "...that the National Security Council staff should manage an interagency process to review regularly the activities of the US Government regarding attacks that exploit a previously unknown vulnerability in a computer application." Retired cybersecurity expert Richard A. Clarke was a group member and stated on April 11, 2014, that NSA had no advance knowledge of Heartbleed.{{cite news|title=White House, spy agencies deny NSA exploited 'Heartbleed' bug|url=https://www.reuters.com/article/us-cybersecurity-internet-bug-nsa-idUSBREA3A1XD20140411|access-date=April 16, 2014|newspaper=Reuters|date=April 11, 2014|author=Mark Hosenball|author2=Will Dunham|archive-date=April 15, 2014|archive-url=https://web.archive.org/web/20140415175914/http://www.reuters.com/article/2014/04/11/us-cybersecurity-internet-bug-nsa-idUSBREA3A1XD20140411|url-status=live}}
= Illegally obtained evidence =
{{Further|Parallel construction#Parallel construction in the United States Drug Enforcement Administration}}
In August 2013 it was revealed that a 2005 IRS training document showed that NSA intelligence intercepts and wiretaps, both foreign and domestic, were being supplied to the Drug Enforcement Administration (DEA) and Internal Revenue Service (IRS) and were illegally used to launch criminal investigations of US citizens. Law enforcement agents were directed to conceal how the investigations began and recreate a legal investigative trail by re-obtaining the same evidence by other means.John Shiffman and Kristina Cooke (August 5, 2013) [https://www.reuters.com/article/us-dea-sod-idUSBRE97409R20130805 Exclusive: U.S. directs agents to cover up program used to investigate Americans] {{Webarchive|url=https://web.archive.org/web/20130814032628/http://www.reuters.com/article/2013/08/05/us-dea-sod-idUSBRE97409R20130805 |date=2013-08-14 }}. Reuters. Retrieved August 12, 2013.John Shiffman and David Ingram (August 7, 2013) [http://uk.reuters.com/article/uk-dea-irs-idUKBRE9761B620130807 Exclusive: IRS manual detailed DEA's use of hidden intel evidence] {{Webarchive|url=https://web.archive.org/web/20200719175938/https://uk.reuters.com/article/uk-dea-irs-idUKBRE9761B620130807 |date=2020-07-19 }}. Reuters. Retrieved August 12, 2013.
= Obama administration =
In the months leading to April 2009, the NSA intercepted the communications of U.S. citizens, including a congressman, although the Justice Department believed that the interception was unintentional. The Justice Department then took action to correct the issues and bring the program into compliance with existing laws.{{cite news |author1=Lichtblau, Eric |author2=Risen, James |name-list-style=amp |date=April 15, 2009 |title=N.S.A.'s Intercepts Exceed Limits Set by Congress |url=https://www.nytimes.com/2009/04/16/us/16nsa.html |work=The New York Times |access-date=April 15, 2009 |archive-date=September 2, 2012 |archive-url=https://web.archive.org/web/20120902055056/http://www.nytimes.com/2009/04/16/us/16nsa.html |url-status=live }} United States Attorney General Eric Holder resumed the program according to his understanding of the Foreign Intelligence Surveillance Act amendment of 2008, without explaining what had occurred.{{cite news|author=Ackerman, Spencer |title=NSA Revelations Spark Push to Restore FISA |url=http://washingtonindependent.com/39153/nsa-revelations-spark-movement-to-restore-fisa |date=April 16, 2009 |work=The Washington Independent |publisher=Center for Independent Media |access-date=April 19, 2009 |url-status=dead |archive-url=https://web.archive.org/web/20090418170843/http://washingtonindependent.com/39153/nsa-revelations-spark-movement-to-restore-fisa |archive-date=April 18, 2009 }}
Polls conducted in June 2013 found divided results among Americans regarding NSA's secret data collection.{{cite web|url=http://www.statista.com/statistics/260140/opinion-of-americans-on-whether-the-nsas-secret-data-collection-is-acceptable/|title=Statistics on whether the NSA's Secret Data Collection is Acceptable|publisher=Statista|access-date=July 19, 2013|archive-date=November 4, 2013|archive-url=https://web.archive.org/web/20131104214811/http://www.statista.com/statistics/260140/opinion-of-americans-on-whether-the-nsas-secret-data-collection-is-acceptable/|url-status=live}} Rasmussen Reports found that 59% of Americans disapprove,{{cite web|title=59% Oppose Government's Secret Collecting of Phone Records|date=June 9, 2013|url=http://www.rasmussenreports.com/public_content/politics/general_politics/june_2013/59_oppose_government_s_secret_collecting_of_phone_records|publisher=Rasmussen Reports|access-date=July 19, 2013|archive-date=July 17, 2013|archive-url=https://web.archive.org/web/20130717104309/http://www.rasmussenreports.com/public_content/politics/general_politics/june_2013/59_oppose_government_s_secret_collecting_of_phone_records|url-status=live}} Gallup found that 53% disapprove,{{cite web|title=Americans Disapprove of Government Surveillance Programs|url=http://www.gallup.com/poll/163043/americans-disapprove-government-surveillance-programs.aspx|date=June 12, 2013|author=Newport, Frank|publisher=Gallup|access-date=July 19, 2013|archive-date=July 29, 2013|archive-url=https://web.archive.org/web/20130729153218/http://www.gallup.com/poll/163043/americans-disapprove-government-surveillance-programs.aspx|url-status=live}} and Pew found that 56% are in favor of NSA data collection.{{cite web|url=http://www.people-press.org/2013/06/10/majority-views-nsa-phone-tracking-as-acceptable-anti-terror-tactic/|title=Majority Views NSA Phone Tracking as Acceptable Anti-terror Tactic|date=June 10, 2013|publisher=Pew Research Center|access-date=July 19, 2013|archive-date=July 14, 2013|archive-url=https://web.archive.org/web/20130714195016/http://www.people-press.org/2013/06/10/majority-views-nsa-phone-tracking-as-acceptable-anti-terror-tactic/|url-status=live}}
= Section 215 metadata collection =
On April 25, 2013, the NSA obtained a court order requiring Verizon's Business Network Services to provide metadata on all calls in its system to the NSA "on an ongoing daily basis" for three months, as reported by The Guardian on June 6, 2013. This information includes "the numbers of both parties on a call ... location data, call duration, unique identifiers, and the time and duration of all calls" but not "[t]he contents of the conversation itself". The order relies on the so-called "business records" provision of the Patriot Act.{{cite news|author=Glenn Greenwald|title=Revealed: NSA collecting phone records of millions of Americans daily|url=https://www.theguardian.com/world/2013/jun/06/nsa-phone-records-verizon-court-order|access-date=June 6, 2013|location=London|work=The Guardian|date=June 6, 2013|author-link=Glenn Greenwald|archive-date=October 12, 2019|archive-url=https://web.archive.org/web/20191012153115/https://www.theguardian.com/world/2013/jun/06/nsa-phone-records-verizon-court-order|url-status=live}}{{cite news| url = https://www.nytimes.com/2013/06/06/us/us-secretly-collecting-logs-of-business-calls.html| title = U.S. Is Secretly Collecting Records of Verizon Calls| newspaper = The New York Times| date = 2013-06-05| author = Charlie Savage, Edward Wyatt| access-date = 2024-06-07| archive-date = 2024-05-12| archive-url = https://web.archive.org/web/20240512131030/https://www.nytimes.com/2013/06/06/us/us-secretly-collecting-logs-of-business-calls.html| url-status = live}}
In August 2013, following the Snowden leaks, new details about the NSA's data mining activity were revealed. Reportedly, the majority of emails into or out of the United States are captured at "selected communications links" and automatically analyzed for keywords or other "selectors". Emails that do not match are deleted.{{cite news|url=https://www.nytimes.com/2013/08/08/us/broader-sifting-of-data-abroad-is-seen-by-nsa.html|title=N.S.A. Said to Search Content of Messages to and From U.S|author=Savage, Charlie|date=August 8, 2013|access-date=August 13, 2013|work=The New York Times|author-link=Charlie Savage (author)|archive-date=August 13, 2013|archive-url=https://web.archive.org/web/20130813023342/https://www.nytimes.com/2013/08/08/us/broader-sifting-of-data-abroad-is-seen-by-nsa.html|url-status=live}} The utility of such a massive metadata collection in preventing terrorist attacks is disputed. Many studies reveal the dragnet-like system to be ineffective. One such report, released by the New America Foundation concluded that after an analysis of 225 terrorism cases, the NSA "had no discernible impact on preventing acts of terrorism."Nakashima, Ellen. [https://web.archive.org/web/20140113192921/http://www.washingtonpost.com/world/national-security/nsa-phone-record-collection-does-little-to-prevent-terrorist-attacks-group-says/2014/01/12/8aa860aa-77dd-11e3-8963-b4b654bcc9b2_story.html "NSA phone record collection does little to prevent terrorist attacks, the group says"], The Washington Post, January 12, 2014
Defenders of the program said that while metadata alone cannot provide all the information necessary to prevent an attack, it assures the ability to "connect the dots"Nakashima, Ellen. [https://www.washingtonpost.com/world/national-security/nsa-chief-defends-collecting-americans-data/2013/09/25/5db2583c-25f1-11e3-b75d-5b7f66349852_story.html / "NSA chief defends collecting Americans' data"] {{Webarchive|url=https://web.archive.org/web/20230326034532/https://www.washingtonpost.com/world/national-security/nsa-chief-defends-collecting-americans-data/2013/09/25/5db2583c-25f1-11e3-b75d-5b7f66349852_story.html |date=2023-03-26 }}, The Washington Post, September 25, 2013 between suspect foreign numbers and domestic numbers with a speed only the NSA's software is capable of. One benefit of this is quickly being able to determine the difference between suspicious activity and real threats.{{Cite book|url=https://www.nap.edu/read/11896/chapter/11|year=2007|doi=10.17226/11896|isbn=978-0-309-10392-3|language=en|title=Engaging Privacy and Information Technology in a Digital Age|access-date=2024-06-07|archive-date=2022-03-27|archive-url=https://web.archive.org/web/20220327084941/https://www.nap.edu/read/11896/chapter/11|url-status=live}} As an example, NSA director General Keith B. Alexander mentioned at the annual Cybersecurity Summit in 2013, that metadata analysis of domestic phone call records after the Boston Marathon bombing helped determine that rumors of a follow-up attack in New York were baseless. In addition to doubts about its effectiveness, many people argue that the collection of metadata is an unconstitutional invasion of privacy. {{As of|2015}}, the collection process remained legal and grounded in the ruling from Smith v. Maryland (1979). A prominent opponent of the data collection and its legality is U.S. District Judge Richard J. Leon, who issued a report in 2013[https://apps.washingtonpost.com/g/page/world/federal-judge-rules-nsa-program-is-likely-unconstitutional/668/ Federal judge rules NSA program is likely unconstitutional] {{Webarchive|url=https://web.archive.org/web/20170830105413/https://apps.washingtonpost.com/g/page/world/federal-judge-rules-nsa-program-is-likely-unconstitutional/668/ |date=2017-08-30 }}, The Washington Post, December 16, 2013 in which he stated: "I cannot imagine a more 'indiscriminate' and 'arbitrary invasion' than this systematic and high tech collection and retention of personal data on virtually every single citizen for purposes of querying and analyzing it without prior judicial approval...Surely, such a program infringes on 'that degree of privacy' that the founders enshrined in the Fourth Amendment".
As of May 7, 2015, the United States Court of Appeals for the Second Circuit ruled that the interpretation of Section 215 of the Patriot Act was wrong and that the NSA program that has been collecting Americans' phone records in bulk is illegal.[https://www.washingtonpost.com/opinions/the-nsa-went-too-far/2015/05/10/02635924-f5aa-11e4-b2f3-af5479e6bbdd_story.html New Rules for the National Security Agency] {{Webarchive|url=https://web.archive.org/web/20230326034649/https://www.washingtonpost.com/opinions/the-nsa-went-too-far/2015/05/10/02635924-f5aa-11e4-b2f3-af5479e6bbdd_story.html |date=2023-03-26 }} by the editorial board on May 10, 2015 It stated that Section 215 cannot be interpreted to allow government to collect national phone data and, as a result, expired on June 1, 2015. This ruling "is the first time a higher-level court in the regular judicial system has reviewed the NSA phone records program."{{cite news| url = https://www.nytimes.com/2015/05/08/us/nsa-phone-records-collection-ruled-illegal-by-appeals-court.html| title = N.S.A. Collection of Bulk Call Data is Ruled Illegal| newspaper = The New York Times| date = 2015-05-07| author = Charlie Savage, Jonathan Weisman| access-date = 2024-06-07| archive-date = 2024-05-18| archive-url = https://web.archive.org/web/20240518131549/https://www.nytimes.com/2015/05/08/us/nsa-phone-records-collection-ruled-illegal-by-appeals-court.html| url-status = live}} The replacement law known as the USA Freedom Act, which will enable the NSA to continue to have bulk access to citizens' metadata but with the stipulation that the data will now be stored by the companies themselves. This change will not have any effect on other Agency procedures—outside of metadata collection—which have purportedly challenged Americans' Fourth Amendment rights,{{cite web|title=Rand Paul vs. Washington DC on the USA Freedom Act|url=http://hotair.com/standing-athwarth-history-yelling-stop/2015/05/31/rand-paul-vs-washington-dc-on-the-usa-freedom-act/|website=HotAir|access-date=2015-06-02|archive-url=https://web.archive.org/web/20150602001207/http://hotair.com/standing-athwarth-history-yelling-stop/2015/05/31/rand-paul-vs-washington-dc-on-the-usa-freedom-act/|archive-date=2015-06-02|url-status=dead}} including Upstream collection, a mass of techniques used by the Agency to collect and store American's data/communications directly from the Internet backbone.Top Level Telecommunications, [http://electrospaces.blogspot.com/2014/01/slides-about-nsas-upstream-collection.html Slides about NSA's Upstream collection] {{Webarchive|url=https://web.archive.org/web/20191108055615/https://electrospaces.blogspot.com/2014/01/slides-about-nsas-upstream-collection.html |date=2019-11-08 }}, January 17, 2014
Under the Upstream collection program, the NSA paid telecommunications companies hundreds of millions of dollars in order to collect data from them.[https://www.washingtonpost.com/world/national-security/nsa-paying-us-companies-for-access-to-communications-networks/2013/08/29/5641a4b6-10c2-11e3-bdf6-e4fc677d94a1_story.html NSA paying U.S. companies for access to communications networks] {{Webarchive|url=https://web.archive.org/web/20140328125616/http://www.washingtonpost.com/world/national-security/nsa-paying-us-companies-for-access-to-communications-networks/2013/08/29/5641a4b6-10c2-11e3-bdf6-e4fc677d94a1_story.html |date=2014-03-28 }} by Craig Timberg and Barton Gellman on August 29, 2013 While companies such as Google and Yahoo! claim that they do not provide "direct access" from their servers to the NSA unless under a court order,[http://www.digitalspy.com/tech/news/a487943/nsa-prism-controversy-apple-facebook-google-more-deny-knowledge.html#~pbKCS2AUgt8krC NSA PRISM Controversy: Apple, Facebook, Google, more deny knowledge] {{Webarchive|url=https://web.archive.org/web/20151016020520/http://www.digitalspy.com/tech/news/a487943/nsa-prism-controversy-apple-facebook-google-more-deny-knowledge.html#~pbKCS2AUgt8krC |date=2015-10-16 }} by Digital Spy on June 6, 2013 the NSA had access to emails, phone calls, and cellular data users.[https://www.theguardian.com/world/2014/feb/03/microsoft-facebook-google-yahoo-fisa-surveillance-requests Microsoft, Facebook, Google and Yahoo release US surveillance requests] {{Webarchive|url=https://web.archive.org/web/20170106175615/https://www.theguardian.com/world/2014/feb/03/microsoft-facebook-google-yahoo-fisa-surveillance-requests |date=2017-01-06 }} by Spencer Ackerman and Dominic Rushe on February 3, 2014 Under this new ruling, telecommunications companies maintain bulk user metadata on their servers for at least 18 months, to be provided upon request to the NSA. This ruling made the mass storage of specific phone records at NSA datacenters illegal, but it did not rule on Section 215's constitutionality.
= Fourth Amendment encroachment =
In a declassified document it was revealed that 17,835 phone lines were on an improperly permitted "alert list" from 2006 to 2009 in breach of compliance, which tagged these phone lines for daily monitoring.{{cite book|title=Memorandum of the United States in Response to the Court's Order Dated January 28, 2009|date=January 28, 2009|publisher=Foreign Intelligence Surveillance Court Washington DC|location=Washington DC|page=11|url=http://www.dni.gov/files/documents/section/pub_Feb%2012%202009%20Memorandum%20of%20US.pdf|access-date=June 7, 2024|archive-date=May 12, 2024|archive-url=https://web.archive.org/web/20240512131445/https://www.dni.gov/files/documents/section/pub_Feb%2012%202009%20Memorandum%20of%20US.pdf|url-status=live}}{{cite magazine|last=Greenberg|first=Andy|title=NSA Secretly Admitted Illegally Tracking Thousands Of 'Alert List' Phone Numbers For Years|url=https://www.forbes.com/sites/andygreenberg/2013/09/10/nsa-secretly-admitted-illegally-tracking-thousands-of-alert-list-phone-numbers-for-years/|magazine=Forbes|access-date=February 25, 2014|archive-date=March 1, 2014|archive-url=https://web.archive.org/web/20140301012831/http://www.forbes.com/sites/andygreenberg/2013/09/10/nsa-secretly-admitted-illegally-tracking-thousands-of-alert-list-phone-numbers-for-years/|url-status=live}}{{cite web|last=Brandon|first=Russel|title=NSA illegally searched 15,000 suspects' phone records, according to declassified report|url=https://www.theverge.com/2013/9/10/4716642/nsa-illegally-searched-15000-suspects-phone-records-according-to|website=The Verge|date=10 September 2013|access-date=February 25, 2014|archive-date=28 February 2014|archive-url=https://web.archive.org/web/20140228122003/http://www.theverge.com/2013/9/10/4716642/nsa-illegally-searched-15000-suspects-phone-records-according-to|url-status=live}} Eleven percent of these monitored phone lines met the agency's legal standard for "reasonably articulable suspicion" (RAS).{{cite web|last=Timm|first=Trevor|title=Government Releases NSA Surveillance Docs and Previously Secret FISA Court Opinions in Response to EFF Lawsuit|date=10 September 2013|url=https://www.eff.org/deeplinks/2013/09/government-releases-nsa-surveillance-docs-and-previously-secret-fisa-court|publisher=Electronic Frontier Foundation|access-date=February 25, 2014|archive-date=9 February 2014|archive-url=https://web.archive.org/web/20140209033231/https://www.eff.org/deeplinks/2013/09/government-releases-nsa-surveillance-docs-and-previously-secret-fisa-court|url-status=live}}
The NSA tracks the locations of hundreds of millions of cell phones per day, allowing it to map people's movements and relationships in detail.Barton Gellman and Ashton Solanti, December 5, 2013, [https://www.washingtonpost.com/world/national-security/nsa-tracking-cellphone-locations-worldwide-snowden-documents-show/2013/12/04/5492873a-5cf2-11e3-bc56-c6ca94801fac_story.html?hpid=z1 "NSA tracking cellphone locations worldwide, Snowden documents show"] {{Webarchive|url=https://web.archive.org/web/20170719034402/https://www.washingtonpost.com/world/national-security/nsa-tracking-cellphone-locations-worldwide-snowden-documents-show/2013/12/04/5492873a-5cf2-11e3-bc56-c6ca94801fac_story.html?hpid=z1 |date=2017-07-19 }}, The Washington Post. Retrieved December 7, 2013. The NSA has been reported to have access to all communications made via Google, Microsoft, Facebook, Yahoo, YouTube, AOL, Skype, Apple and Paltalk,Greenwald, Glenn; MacAskill, Ewen (June 6, 2013). "[https://www.theguardian.com/world/2013/jun/06/us-tech-giants-nsa-data NSA Prism program taps in to user data of Apple, Google and others] {{Webarchive|url=https://web.archive.org/web/20060818114650/http://www.guardian.co.uk/world/2013/jun/06/us-tech-giants-nsa-data |date=2006-08-18 }}". The Guardian. Retrieved June 15, 2013. and collects hundreds of millions of contact lists from personal email and instant messaging accounts each year.Gellman and Soltani, October 15, 2013 "[https://www.washingtonpost.com/world/national-security/nsa-collects-millions-of-e-mail-address-books-globally/2013/10/14/8e58b5be-34f9-11e3-80c6-7e6dd8d22d8f_story.html NSA collects millions of e-mail address books globally] {{Webarchive|url=https://web.archive.org/web/20140127122752/http://www.washingtonpost.com/world/national-security/nsa-collects-millions-of-e-mail-address-books-globally/2013/10/14/8e58b5be-34f9-11e3-80c6-7e6dd8d22d8f_story.html |date=2014-01-27 }}", The Washington Post. Retrieved October 16, 2013. It has also managed to weaken much of the encryption used on the Internet (by collaborating with, coercing, or otherwise infiltrating numerous technology companies to leave "backdoors" into their systems) so that the majority of encryption is inadvertently vulnerable to different forms of attack.Perlroth, Larson and Shane, "[https://www.nytimes.com/2013/09/06/us/nsa-foils-much-internet-encryption.html N.S.A. Able to Foil Basic Safeguards of Privacy on Web] {{Webarchive|url=https://web.archive.org/web/20240522175823/https://www.nytimes.com/2013/09/06/us/nsa-foils-much-internet-encryption.html |date=2024-05-22 }}", The New York Times September 5, 2013. Retrieved September 23, 2013.Arthur, Charles "[https://www.theguardian.com/technology/2013/sep/16/nsa-gchq-undermine-internet-security Academics criticise NSA and GCHQ for weakening online encryption]", The Guardian September 16, 2013. Retrieved September 23, 2013.
Domestically, the NSA has been proven to collect and store metadata records of phone calls,{{cite news|title=Senators: Limit NSA snooping into US phone records|url=http://bigstory.ap.org/article/senators-limit-nsa-snooping-us-phone-records|agency=Associated Press|access-date=October 15, 2013|quote=" Is it the goal of the NSA to collect the phone records of all Americans?" Udall asked at Thursday's hearing. "Yes, I believe it is in the nation's best interest to put all the phone records into a lockbox that we could search when the nation needs to do it. Yes," Alexander replied.|archive-date=October 29, 2013|archive-url=https://web.archive.org/web/20131029003314/http://bigstory.ap.org/article/senators-limit-nsa-snooping-us-phone-records|url-status=dead}} including over 120 million US Verizon subscribers,Glenn Greenwald (June 6, 2013). "[https://www.theguardian.com/world/2013/jun/06/nsa-phone-records-verizon-court-order NSA collecting phone records of millions of Verizon customers daily] {{Webarchive|url=https://web.archive.org/web/20191012153115/https://www.theguardian.com/world/2013/jun/06/nsa-phone-records-verizon-court-order |date=2019-10-12 }}". The Guardian. Retrieved September 16, 2013. as well as intercept vast amounts of communications via the internet (Upstream). The government's legal standing had been to rely on a secret interpretation of the Patriot Act whereby the entirety of US communications may be considered "relevant" to a terrorism investigation if it is expected that even a tiny minority may relate to terrorism.[http://www.techdirt.com/articles/20130917/13395324556/court-reveals-secret-interpretation-patriot-act-allowing-nsa-to-collect-all-phone-call-data.shtml Court Reveals 'Secret Interpretation' Of The Patriot Act, Allowing NSA To Collect All Phone Call Data] {{Webarchive|url=https://web.archive.org/web/20220224094759/https://www.techdirt.com/articles/20130917/13395324556/court-reveals-secret-interpretation-patriot-act-allowing-nsa-to-collect-all-phone-call-data.shtml |date=2022-02-24 }}, September 17, 2013. Retrieved September 19, 2013. The NSA also supplies foreign intercepts to the DEA, IRS and other law enforcement agencies, who use these to initiate criminal investigations. Federal agents are then instructed to "recreate" the investigative trail via parallel construction.{{cite news|title=Exclusive: U.S. directs agents to cover up program used to investigate Americans|url=https://www.reuters.com/article/us-dea-sod-idUSBRE97409R20130805|work=Reuters|access-date=August 14, 2013|date=August 5, 2013|archive-date=August 14, 2013|archive-url=https://web.archive.org/web/20130814032628/http://www.reuters.com/article/2013/08/05/us-dea-sod-idUSBRE97409R20130805|url-status=live}}
The NSA also spies on influential Muslim societies to obtain information that could be used to discredit them, such as their use of pornography. The targets, both domestic and abroad, are not suspected of any crime but hold religious or political views deemed "radical" by the NSA.Glenn Greenwald, Ryan Gallagher & Ryan Grim, November 26, 2013, "[https://www.huffingtonpost.com/2013/11/26/nsa-porn-muslims_n_4346128.html Top-Secret Document Reveals NSA Spied On Porn Habits As Part Of Plan To Discredit 'Radicalizers'] {{Webarchive|url=https://web.archive.org/web/20131127144711/https://www.huffingtonpost.com/2013/11/26/nsa-porn-muslims_n_4346128.html |date=2013-11-27 }}", Huffington Post. Retrieved November 28, 2013. According to a report in The Washington Post in July 2014, relying on information provided by Snowden, 90% of those placed under surveillance in the U.S. are ordinary Americans and are not the intended targets. The newspaper said it had examined documents including emails, text messages, and online accounts that support the claim.{{cite news|title=Vast majority of NSA spy targets are mistakenly monitored|url=https://www.philadelphianews.net/index.php/sid/223558101/scat/c08dd24cec417021/ht/Vast-majority-of-NSA-spy-targets-are-mistakenly-monitored|access-date=July 7, 2014|publisher=Philadelphia News.Net|archive-url=https://web.archive.org/web/20140714180053/http://www.philadelphianews.net/index.php/sid/223558101/scat/c08dd24cec417021/ht/Vast-majority-of-NSA-spy-targets-are-mistakenly-monitored|archive-date=2014-07-14|url-status=dead}}
= Congressional oversight =
File:Ron Wyden and James Clapper - 6 June 2013.webm The Intelligence Committees of the US House and Senate exercise primary oversight over the NSA; other members of Congress have been denied access to materials and information regarding the agency and its activities.Greenwald, Glen, "[https://www.theguardian.com/commentisfree/2013/aug/04/congress-nsa-denied-access Members of Congress denied access to basic information about NSA]", The Guardian, August 4, 2013. Retrieved September 23, 2013. The United States Foreign Intelligence Surveillance Court, the secret court charged with regulating the NSA's activities is, according to its chief judge, incapable of investigating or verifying how often the NSA breaks even its own secret rules.Loennig, C., "[https://www.washingtonpost.com/politics/court-ability-to-police-us-spying-program-limited/2013/08/15/4a8c8c44-05cd-11e3-a07f-49ddc7417125_story.html Court: Ability to police U.S. spying program limited] {{Webarchive|url=https://web.archive.org/web/20231008052647/https://www.washingtonpost.com/politics/court-ability-to-police-us-spying-program-limited/2013/08/15/4a8c8c44-05cd-11e3-a07f-49ddc7417125_story.html |date=2023-10-08 }}", The Washington Post, August 16, 2013. Retrieved September 23, 2013. It has since been reported that the NSA violated its own rules on data access thousands of times a year, many of these violations involving large-scale data interceptions.Gellman, B. [https://www.washingtonpost.com/world/national-security/nsa-broke-privacy-rules-thousands-of-times-per-year-audit-finds/2013/08/15/3310e554-05ca-11e3-a07f-49ddc7417125_story.html NSA broke privacy rules thousands of times per year, audit finds], The Washington Post, August 15, 2013. Retrieved September 23, 2013. NSA officers have even used data intercepts to spy on love interests;Gorman, S. [https://blogs.wsj.com/washwire/2013/08/23/nsa-officers-sometimes-spy-on-love-interests/ NSA Officers Spy on Love Interests] {{Webarchive|url=https://web.archive.org/web/20140401212529/http://blogs.wsj.com/washwire/2013/08/23/nsa-officers-sometimes-spy-on-love-interests/ |date=2014-04-01 }}, Wall St Journal, August 23, 2013. Retrieved September 23, 2013. "most of the NSA violations were self-reported, and each instance resulted in administrative action of termination."Andrea Peterson, [https://www.washingtonpost.com/news/the-switch/wp/2013/08/24/loveint-when-nsa-officers-use-their-spying-power-on-love-interests/ LOVEINT: When NSA officers use their spying power on love interests] {{Webarchive|url=https://web.archive.org/web/20230924092154/https://www.washingtonpost.com/news/the-switch/wp/2013/08/24/loveint-when-nsa-officers-use-their-spying-power-on-love-interests/ |date=2023-09-24 }}, The Washington Post (August 24, 2013).{{Attribution needed|date=July 2020}}
The NSA has "generally disregarded the special rules for disseminating United States person information" by illegally sharing its intercepts with other law enforcement agencies.Spencer Ackerman, November 19, 2013, "[https://www.theguardian.com/world/2013/nov/19/fisa-court-documents-nsa-violations-privacy Fisa court documents reveal extent of NSA disregard for privacy restrictions]", The Guardian. Retrieved November 21, 2013. A March 2009 FISA Court opinion, which the court released, states that protocols restricting data queries had been "so frequently and systemically violated that it can be fairly said that this critical element of the overall ... regime has never functioned effectively."John D Bates (October 3, 2011). "[https://www.eff.org/sites/default/files/filenode/fisc_opinion_-_unconstitutional_surveillance_0.pdf [redacted]] {{Webarchive|url=https://web.archive.org/web/20130824171345/https://www.eff.org/sites/default/files/filenode/fisc_opinion_-_unconstitutional_surveillance_0.pdf |date=2013-08-24 }}". p. 16.Ellen Nakashima, Julie Tate, and Carol Leonnig (September 10, 2013). "[https://www.washingtonpost.com/world/national-security/declassified-court-documents-highlight-nsa-violations/2013/09/10/60b5822c-1a4b-11e3-a628-7e6dde8f889d_story.html Declassified court documents highlight NSA violations in data collection for surveillance] {{Webarchive|url=https://web.archive.org/web/20220228045431/https://www.washingtonpost.com/world/national-security/declassified-court-documents-highlight-nsa-violations/2013/09/10/60b5822c-1a4b-11e3-a628-7e6dde8f889d_story.html |date=2022-02-28 }}". The Washington Post. Retrieved September 14, 2013. In 2011 the same court noted that the "volume and nature" of the NSA's bulk foreign Internet intercepts was "fundamentally different from what the court had been led to believe". Email contact lists (including those of US citizens) are collected at numerous foreign locations to work around the illegality of doing so on US soil.
Legal opinions on the NSA's bulk collection program have differed. In mid-December 2013, U.S. District Judge Richard Leon ruled that the "almost-Orwellian" program likely violates the Constitution, and wrote, "I cannot imagine a more 'indiscriminate' and 'arbitrary invasion' than this systematic and high-tech collection and retention of personal data on virtually every single citizen for purposes of querying and analyzing it without prior judicial approval. Surely, such a program infringes on 'that degree of privacy' that the Founders enshrined in the Fourth Amendment. Indeed, I have little doubt that the author of our Constitution, James Madison, who cautioned us to beware 'the abridgment of the freedom of the people by gradual and silent encroachments by those in power,' would be aghast."Richard Leon, December 16, 2013, [https://www.theguardian.com/world/interactive/2013/dec/16/nsa-collection-phone-metadata-district-court-ruling Memorandum Opinion, Klayman vs. Obama]. U.S. District Court for the District of Columbia. Reproduced on The Guardian website. Retrieved February 3, 2013.
Later that month, U.S. District Judge William Pauley ruled that the NSA's collection of telephone records is legal and valuable in the fight against terrorism. In his opinion, he wrote, "a bulk telephony metadata collection program [is] a wide net that could find and isolate gossamer contacts among suspected terrorists in an ocean of seemingly disconnected data" and noted that a similar collection of data before 9/11 might have prevented the attack.{{cite web |last=Bazzle |first=Steph |title=Judge Says NSA's Data Collection Is Legal |url=http://www.indyposted.com/227717/judge-says-nsas-data-collection-legal/ |publisher=Indyposted |access-date=December 28, 2013 |date=December 27, 2013 |url-status=dead |archive-url=https://web.archive.org/web/20131228162843/http://www.indyposted.com/227717/judge-says-nsas-data-collection-legal/ |archive-date=December 28, 2013 }}
= Official responses =
At a March 2013 Senate Intelligence Committee hearing, Senator Ron Wyden asked the Director of National Intelligence James Clapper, "Does the NSA collect any type of data at all on millions or hundreds of millions of Americans?" Clapper replied "No, sir. ... Not wittingly. There are cases where they could inadvertently perhaps collect, but not wittingly."Kessler, Glenn, [https://www.washingtonpost.com/blogs/fact-checker/post/james-clappers-least-untruthful-statement-to-the-senate/2013/06/11/e50677a8-d2d8-11e2-a73e-826d299ff459_blog.html James Clapper's 'least untruthful' statement to the Senate] {{Webarchive|url=https://web.archive.org/web/20230622170802/https://www.washingtonpost.com/blogs/fact-checker/post/james-clappers-least-untruthful-statement-to-the-senate/2013/06/11/e50677a8-d2d8-11e2-a73e-826d299ff459_blog.html |date=2023-06-22 }}, June 12, 2013. Retrieved September 23, 2013. This statement came under scrutiny months later, in June 2013, when details of the PRISM surveillance program were published, showing that "the NSA apparently can gain access to the servers of nine Internet companies for a wide range of digital data." Wyden said that Clapper had failed to give a "straight answer" in his testimony. Clapper, in response to criticism, said, "I responded in what I thought was the most truthful, or least untruthful manner." Clapper added, "There are honest differences on the semantics of what—when someone says 'collection' to me, that has a specific meaning, which may have a different meaning to him."
NSA whistle-blower Edward Snowden additionally revealed the existence of XKeyscore, a top-secret surveillance program that allows the N.S.A for searching vast databases of "the metadata as well as the content of emails and other internet activity, such as browser history," with the capability to search by "name, telephone number, IP address, keywords, the language in which the internet activity was conducted or the type of browser used."Glenn Greenwald, [https://www.theguardian.com/world/2013/jul/31/nsa-top-secret-program-online-data XKeyscore: NSA tool collects 'nearly everything a user does on the internet'] {{Webarchive|url=https://web.archive.org/web/20140320191519/http://www.theguardian.com/world/2013/jul/31/nsa-top-secret-program-online-data |date=2014-03-20 }}, The Guardian (July 31, 2013). XKeyscore "provides the technological capability, if not the legal authority, to target even US persons for extensive electronic surveillance without a warrant provided that some identifying information, such as their email or IP address, is known to the analyst."
Regarding the necessity of these NSA programs, Alexander stated on June 27, 2013, that the NSA's bulk phone and Internet intercepts had been instrumental in preventing 54 terrorist "events", including 13 in the US, and in all but one of these cases had provided the initial tip to "unravel the threat stream".Kube, C., June 27, 2013, [http://usnews.nbcnews.com/_news/2013/06/27/19175466-nsa-chief-says-surveillance-programs-helped-foil-54-plots?lite "NSA chief says surveillance programs helped foil 54 plots"] {{Webarchive|url=https://web.archive.org/web/20200921011201/http://usnews.nbcnews.com/_news/2013/06/27/19175466-nsa-chief-says-surveillance-programs-helped-foil-54-plots?lite |date=2020-09-21 }}, US News on nbcnews.com. Retrieved September 27, 2013. On July 31 NSA Deputy Director John Inglis conceded to the Senate that these intercepts had not been vital in stopping any terrorist attacks, but were "close" to vital in identifying and convicting four San Diego men for sending US$8,930 to Al-Shabaab, a militia that conducts terrorism in Somalia.{{cite web |url=http://www.democracynow.org/2013/8/1/nsa_confirms_dragnet_phone_records_collection |title=NSA Confirms Dragnet Phone Records Collection, But Admits It Was Key in Stopping Just 1 Terror Plot |archive-url=https://web.archive.org/web/20240512124446/https://www.democracynow.org/2013/8/1/nsa_confirms_dragnet_phone_records_collection |archive-date=2024-05-12 |website=Democracy Now |date=August 1, 2013 |access-date=September 27, 2013 }}[http://jnslp.files.wordpress.com/2010/11/moalin.pdf "Indictment: USA vs Basaaly Saeed Moalin, Mohamed Mohamed Mohamud and Issa Doreh"] {{Webarchive|url=https://web.archive.org/web/20231005065118/https://jnslp.files.wordpress.com/2010/11/moalin.pdf |date=2023-10-05 }}. Southern District of California July 2010 Grand Jury. Retrieved September 30, 2013.{{cite press release |publisher=The Permanent Select Committee on Intelligence |date=July 23, 2013 |url=http://democrats.intelligence.house.gov/press-release/54-attacks-20-countries-thwarted-nsa-collection |title=54 Attacks in 20 Countries Thwarted By NSA Collection |archive-url=https://web.archive.org/web/20131023153822/http://democrats.intelligence.house.gov/press-release/54-attacks-20-countries-thwarted-nsa-collection |archive-date=October 23, 2013 }} The U.S. government has aggressively sought to dismiss and challenge Fourth Amendment cases raised against it, and has granted retroactive immunity to ISPs and telecoms participating in domestic surveillance.{{cite web |url=https://arstechnica.com/security/2008/02/democrats-fail-to-block-telecom-immunity-provision/ |title=Senate caves, votes to give telecoms retroactive immunity |website=Ars Technica |date=February 13, 2008 |access-date=September 16, 2013 |archive-date=July 8, 2017 |archive-url=https://web.archive.org/web/20170708072335/https://arstechnica.com/security/2008/02/democrats-fail-to-block-telecom-immunity-provision/ |url-status=live }}{{cite web |url=http://progressive.org/mag/wx071008.html |title=Forget Retroactive Immunity, FISA Bill is also about Prospective Immunity |publisher=The Progressive |date=July 10, 2008 |access-date=September 16, 2013 |url-status=dead |archive-url=https://web.archive.org/web/20130918200841/http://progressive.org/mag/wx071008.html |archive-date=September 18, 2013 }}
The U.S. military has acknowledged blocking access to parts of The Guardian website for thousands of defense personnel across the country,[http://www.montereyherald.com/local/ci_23554739/restricted-web-access-guardian-is-army-wide-officials "Restricted Web access to the Guardian is Armywide, say officials"] {{Webarchive|url=https://web.archive.org/web/20141020150616/http://www.montereyherald.com/local/ci_23554739/restricted-web-access-guardian-is-army-wide-officials |date=2014-10-20 }}, Philipp Molnar, Monterey Herald, June 27, 2013. Retrieved October 15, 2014.Ackerman, Spencer; Roberts, Dan (June 28, 2013). [https://www.theguardian.com/world/2013/jun/28/us-army-blocks-guardian-website-access "US Army Blocks Access to Guardian Website to Preserve 'Network Hygiene'—Military Admits to Filtering Reports and Content Relating to Government Surveillance Programs for Thousands of Personnel"] {{Webarchive|url=https://web.archive.org/web/20170103143200/https://www.theguardian.com/world/2013/jun/28/us-army-blocks-guardian-website-access |date=2017-01-03 }}. The Guardian. Retrieved June 30, 2013. and blocking the entire Guardian website for personnel stationed throughout Afghanistan, the Middle East, and South Asia.{{cite news|last=Ackerman|first=Spencer|title=US military blocks entire Guardian website for troops stationed abroad|url=https://www.theguardian.com/world/2013/jul/01/us-military-blocks-guardian-troops|newspaper=The Guardian|date=July 1, 2013|access-date=June 7, 2024|archive-date=February 2, 2017|archive-url=https://web.archive.org/web/20170202141818/https://www.theguardian.com/world/2013/jul/01/us-military-blocks-guardian-troops|url-status=live}} In October 2014, the United Nations report condemned mass surveillance programs carried out by the U.S. intelligence communities and other nations as violating multiple global treaties and conventions that guaranteed core privacy rights.{{cite web|last=Greenwald|first=Glenn|title=UN Report Finds Mass Surveillance Violates International Treaties and Privacy Rights|url=https://firstlook.org/theintercept/2014/10/15/un-investigator-report-condemns-mass-surveillance/|date=October 16, 2014|access-date=October 23, 2014|archive-date=January 3, 2015|archive-url=https://web.archive.org/web/20150103001936/https://firstlook.org/theintercept/2014/10/15/un-investigator-report-condemns-mass-surveillance/|url-status=dead}}
= Responsibility for global ransomware attack =
An exploit dubbed EternalBlue, created by the NSA, was used in the WannaCry ransomware attack in May 2017.{{Cite news|url=https://www.washingtonpost.com/business/technology/nsa-officials-worried-about-the-day-its-potent-hacking-tool-would-get-loose-then-it-did/2017/05/16/50670b16-3978-11e7-a058-ddbb23c75d82_story.html|title=NSA officials worried about the day its potent hacking tool would get loose. Then it did.|last1=Nakashima|first1=Ellen|date=2017-05-16|newspaper=Washington Post|access-date=2017-12-19|last2=Timberg|first2=Craig|language=en-US|issn=0190-8286|archive-date=2022-09-01|archive-url=https://web.archive.org/web/20220901234448/https://www.washingtonpost.com/business/technology/nsa-officials-worried-about-the-day-its-potent-hacking-tool-would-get-loose-then-it-did/2017/05/16/50670b16-3978-11e7-a058-ddbb23c75d82_story.html|url-status=live}} The exploit had been leaked online by a hacking group, The Shadow Brokers, nearly a month before the attack. Several experts have pointed the finger at the NSA's non-disclosure of the underlying vulnerability, and their loss of control over the EternalBlue attack tool that exploited it. Edward Snowden said that if the NSA had "privately disclosed the flaw used to attack hospitals when they found it, not when they lost it, [the attack] might not have happened".{{cite web|url=https://www.theguardian.com/technology/2017/may/12/global-cyber-attack-ransomware-nsa-uk-nhs|title=Massive ransomware cyber-attack hits 74 countries around the world|first1=Julia Carrie|last1=Wong|author1-link=Julia Carrie Wong|first2=Olivia|last2=Solon|date=12 May 2017|access-date=12 May 2017|work=The Guardian|archive-date=21 May 2017|archive-url=https://web.archive.org/web/20170521030555/https://www.theguardian.com/technology/2017/may/12/global-cyber-attack-ransomware-nsa-uk-nhs|url-status=live}} Wikipedia co-founder, Jimmy Wales, stated that he joined "with Microsoft and the other leaders of the industry in saying this is a huge screw-up by the government ... the moment the NSA found it, they should have notified Microsoft so they could quietly issue a patch and really chivvy people along, long before it became a huge problem."{{cite news|last1=Kharpal|first1=Arjun|title=Cyberattack that hit 200,000 users was 'huge screw-up' by government, Wikipedia's Jimmy Wales says|url=https://www.cnbc.com/2017/05/19/wannacry-cyberattack-nsa-wikipedia-jimmy-wales.html|access-date=2 June 2017|publisher=CNBC|date=19 May 2017|archive-date=24 May 2017|archive-url=https://web.archive.org/web/20170524225959/http://www.cnbc.com/2017/05/19/wannacry-cyberattack-nsa-wikipedia-jimmy-wales.html|url-status=live}}
= Activities of previous employees =
Former employee David Evenden, who had left the NSA to work for US defense contractor Cyperpoint at a position in the United Arab Emirates, was tasked with hacking UAE neighbor Qatar in 2015 to determine if they were funding terrorist group Muslim Brotherhood. He quit the company after learning his team had hacked Qatari Sheikha Moza bint Nasser's email exchanges with Michelle Obama, just before she visited Doha.{{cite news|url=https://www.nytimes.com/2021/02/06/technology/cyber-hackers-usa.html |archive-url=https://ghostarchive.org/archive/20211228/https://www.nytimes.com/2021/02/06/technology/cyber-hackers-usa.html |archive-date=2021-12-28 |url-access=limited|title=How the United States Lost to Hackers|access-date=6 February 2021|website=The New York Times|date=6 February 2021|last1=Perlroth|first1=Nicole}}{{cbignore}} Upon Evenden's return to the US, he reported his experiences to the FBI. The incident highlights a growing trend of former NSA employees and contractors leaving the agency to start up their firms, and then hiring out to countries like Turkey, Sudan, and even Russia, a country involved in numerous cyberattacks against the US.
= 2021 Denmark-NSA collaborative surveillance =
{{Further|Operation Dunhammer}}
In May 2021, it was reported that the Danish Defence Intelligence Service collaborated with the NSA to wiretap on fellow EU members and leaders,{{cite news |title=Danish secret service helped US spy on Germany's Angela Merkel: report |url=https://www.dw.com/en/danish-secret-service-helped-us-spy-on-germanys-angela-merkel-report/a-57721901 |work=Deutsche Welle |date=30 May 2021 |access-date=7 June 2024 |archive-date=12 May 2024 |archive-url=https://web.archive.org/web/20240512122924/https://www.dw.com/en/danish-secret-service-helped-us-spy-on-germanys-angela-merkel-report/a-57721901 |url-status=live }}{{cite news |title=How Denmark became the NSA's listening post in Europe |url=https://www.france24.com/en/technology/20210601-how-denmark-became-the-nsa-s-listening-post-in-europe |work=France 24 |date=1 June 2021 |access-date=7 June 2024 |archive-date=12 May 2024 |archive-url=https://web.archive.org/web/20240512132041/https://www.france24.com/en/technology/20210601-how-denmark-became-the-nsa-s-listening-post-in-europe |url-status=live }} leading to wide backlash among EU countries and demands for explanation from Danish and American governments.{{cite news |title=NSA spying row: US and Denmark pressed over allegations |url=https://www.bbc.com/news/world-europe-57311441 |work=BBC News |date=31 May 2021 |access-date=7 June 2024 |archive-date=17 May 2024 |archive-url=https://web.archive.org/web/20240517041238/https://www.bbc.com/news/world-europe-57311441 |url-status=live }}
= Buying data without a warrant =
NSA director Paul Nakasone disclosed in a letter to Representative Ron Wyden that the NSA buys data without a warrant.{{Cite web |last=Whittaker |first=Zack |date=2024-01-26 |title=NSA is buying Americans' internet browsing records without a warrant |url=https://techcrunch.com/2024/01/26/national-security-agency-americans-internet-browsing-records-warrantless/ |access-date= |website=TechCrunch |language=en-US}}{{Cite web |date=January 25, 2024 |title=Wyden Releases Documents Confirming the NSA Buys Americans’ Internet Browsing Records; Calls on Intelligence Community to Stop Buying U.S. Data Obtained Unlawfully From Data Brokers, Violating Recent FTC Order |url=https://www.wyden.senate.gov/news/press-releases/wyden-releases-documents-confirming-the-nsa-buys-americans-internet-browsing-records-calls-on-intelligence-community-to-stop-buying-us-data-obtained-unlawfully-from-data-brokers-violating-recent-ftc-order |archive-url=https://archive.today/20240127094647/https://www.wyden.senate.gov/news/press-releases/wyden-releases-documents-confirming-the-nsa-buys-americans-internet-browsing-records-calls-on-intelligence-community-to-stop-buying-us-data-obtained-unlawfully-from-data-brokers-violating-recent-ftc-order |archive-date=27 January 2024 |access-date= |website=wyden.senate.gov |language=en}}
See also
{{Portal bar|United States}}
{{cmn|
- Australian Signals Directorate (ASD) – Australia
- Criticomm
- FAPSI – Russia (1991–2003)
- Garda National Surveillance Unit (NSU) – Ireland
- GCHQ – United Kingdom
- Ghidra (software)
- Internal Security Department (Singapore) (ISD) – Singapore
- Korean Air Lines Flight 007
- Harold T. Martin III
- Mass surveillance in the United Kingdom
- Ministry of State Security (Stasi) – former German Democratic Republic
- Ministry of State Security (China) (MSS) – China
- National Intelligence Priorities Framework
- National Technical Research Organisation (NTRO) – India
- Operation Ivy Bells
- Operation Eikonal
- Special Communications Service of Russia (Spetssvyaz) – Russia
- Unit 8200—Israel's equivalent to the NSA
- U.S. Department of Defense Strategy for Operating in Cyberspace
- Military Cryptanalytics
}}
Notes
{{Reflist|refs=
{{cite news| url = https://www.nytimes.com/2015/09/21/us/politics/george-w-bush-made-retroactive-nsa-fix-after-hospital-room-showdown.html?_r=1| title = George W. Bush Made Retroactive N.S.A. 'Fix' After Hospital Room Showdown| newspaper = The New York Times| date = 2015-09-20| author = Charlie Savage| author-link = Charlie Savage (author)| access-date = 2024-06-07| archive-date = 2024-05-12| archive-url = https://web.archive.org/web/20240512124131/https://www.nytimes.com/2015/09/21/us/politics/george-w-bush-made-retroactive-nsa-fix-after-hospital-room-showdown.html?_r=1| url-status = live}}
}}
References
- Bamford, James. Body of Secrets: Anatomy of the Ultra-Secret National Security Agency, Random House Digital, Inc., December 18, 2007. {{ISBN|0-307-42505-3}}. Previously published as Doubleday, 2001, {{ISBN|0-385-49907-8}}.
- Bauer, Craig P. Secret History: The Story of Cryptology (Volume 76 of Discrete Mathematics and Its Applications). CRC Press, 2013. {{ISBN|1-4665-6186-6}}.
- Weiland, Matt and Sean Wilsey. State by State. HarperCollins, October 19, 2010. {{ISBN|0-06-204357-9}}.
Further reading
{{Library resources box}}
- Adams, Sam, War of Numbers: An Intelligence Memoir Steerforth; new edition (June 1, 1998).
- Aid, Matthew, The Secret Sentry: The Untold History of the National Security Agency, 432 pages, {{ISBN|978-1-59691-515-2}}, Bloomsbury Press (June 9, 2009).
- [https://www.archives.gov/files/declassification/iscap/pdf/2013-114-doc1.pdf Mandatory Declassification Review] {{Webarchive|url=https://web.archive.org/web/20240512130150/https://www.archives.gov/files/declassification/iscap/pdf/2013-114-doc1.pdf |date=2024-05-12 }} – Interagency Security Classification Appeals Panel
- Bamford, James, The Puzzle Palace, Penguin Books, 1982, {{ISBN|0-14-006748-5}}.
- Bamford, James, "[https://www.nytimes.com/2005/12/25/weekinreview/25bamford.html The Agency That Could Be Big Brother] {{Webarchive|url=https://web.archive.org/web/20150302033537/http://www.nytimes.com/2005/12/25/weekinreview/25bamford.html |date=2015-03-02 }}", The New York Times, December 25, 2005.
- Bamford, James, The Shadow Factory, Anchor Books, 2009, {{ISBN|978-0-307-27939-2}}.
- Budiansky, Stephen (2017). Code Warriors: NSA's Codebreakers and the Secret Intelligence War Against the Soviet Union. {{ISBN|978-080-417-097-0}}.
- {{cite book|last=Hanyok|first=Robert J.|year=2002|url=https://fas.org/irp/nsa/spartans/index.html|title=Spartans in Darkness: American SIGINT and the Indochina War, 1945–1975|publisher=National Security Agency|access-date=November 16, 2008|archive-date=January 11, 2009|archive-url=https://web.archive.org/web/20090111205047/http://www.fas.org/irp/nsa/spartans/index.html|url-status=live}}
- {{cite news | url=https://www.usatoday.com/story/theoval/2013/06/18/obama-charlie-rose-program-nsa-surveillance/2433549/ | title=Obama: NSA surveillance programs are 'transparent' | newspaper=USA Today | date=June 18, 2013 | access-date=June 18, 2013 | author=Jackson, David | archive-date=June 18, 2013 | archive-url=https://web.archive.org/web/20130618124016/http://www.usatoday.com/story/theoval/2013/06/18/obama-charlie-rose-program-nsa-surveillance/2433549/ | url-status=live }}
- {{cite book|last=Johnson|first=Thomas R.|year=2008|url=http://www.gwu.edu/~nsarchiv/NSAEBB/NSAEBB260/|title=American Cryptology during the Cold War|publisher=National Security Agency: Center for Cryptological History|access-date=November 16, 2008|archive-date=December 24, 2008|archive-url=https://web.archive.org/web/20081224044110/http://www.gwu.edu/~nsarchiv/NSAEBB/NSAEBB260/|url-status=live}}
- Radden Keefe, Patrick, Chatter: Dispatches from the Secret World of Global Eavesdropping, Random House, {{ISBN|1-4000-6034-6}}.
- Kent, Sherman, Strategic Intelligence for American Public Policy.
- Kahn, David, The Codebreakers, 1181 pp., {{ISBN|0-684-83130-9}}. Look for the 1967 rather than the 1996 edition{{why|date=January 2024}}.
- Laqueur, Walter, A World of secrets.
- Liston, Robert A., The Pueblo Surrender: A Covert Action by the National Security Agency, {{ISBN|0-87131-554-8}}.
- Levy, Steven, Crypto: How the Code Rebels Beat the Government—Saving Privacy in the Digital Age, Penguin Books, {{ISBN|0-14-024432-8}}.
- Prados, John, The Soviet estimate: U.S. intelligence analysis & Russian military strength, hardcover, 367 pages, {{ISBN|0-385-27211-1}}, Dial Press (1982).
- Perro, Ralph J. "[https://www.fas.org/irp/eprint/nsa-interview.pdf Interviewing With an Intelligence Agency (or, A Funny Thing Happened on the Way to Fort Meade)]". ([https://web.archive.org/web/20130202180139/http://www.fas.org/irp/eprint/nsa-interview.pdf Archive]) Federation of American Scientists. November 2003. Updated January 2004. – About the experience of a candidate of an NSA job in pre-employment screening. "Ralph J. Perro" is a pseudonym that is a reference to Ralph J. Canine (perro is Spanish for "dog", and a dog is a type of canine)
- Shaker, Richard J. "[https://www.ams.org/profession/employment-services/emp-shaker The Agency That Came in from the Cold]." ([https://web.archive.org/web/20140125104431/http://www.ams.org/profession/employment-services/emp-shaker Archive] Notices. American Mathematical Society. May/June 1992 pp. 408–411.
- Tully, Andrew, The Super Spies: More Secret, More Powerful than the CIA, 1969, LC 71080912.
- Church Committee, Intelligence Activities and the Rights of Americans: 1976 US Senate Report on Illegal Wiretaps and Domestic Spying by the FBI, CIA and NSA, Red and Black Publishers (May 1, 2008).
- "[http://www.cnn.com/video/data/2.0/video/us/2013/06/07/lawrence-nsa-no-such-agency.cnn.html Just what is the NSA?] {{Webarchive|url=https://web.archive.org/web/20141022062022/http://www.cnn.com/video/data/2.0/video/us/2013/06/07/lawrence-nsa-no-such-agency.cnn.html |date=2014-10-22 }}" (video). CNN. June 7, 2013.
- {{cite news|url=https://www.theguardian.com/world/the-nsa-files|title=The NSA Files|newspaper=The Guardian|location=London|date=June 8, 2013|access-date=June 7, 2024|archive-date=October 3, 2014|archive-url=https://web.archive.org/web/20141003122712/http://www.theguardian.com/world/the-nsa-files|url-status=live}}
- "[http://www.gwu.edu/~nsarchiv/NSAEBB/NSAEBB260/ National Security Agency Releases History of Cold War Intelligence Activities] {{Webarchive|url=https://web.archive.org/web/20081224044110/http://www.gwu.edu/~nsarchiv/NSAEBB/NSAEBB260/ |date=2008-12-24 }}." George Washington University. National Security Archive Electronic Briefing Book No. 260. Posted November 14, 2008.
- {{cite web|url=https://theintercept.com/snowden-sidtoday/?orderBy=publishedTime&orderDirection=desc#archive|title=The Snowden Archive|website=The Intercept|location=London|date=June 8, 2013|access-date=June 7, 2024|archive-date=May 12, 2024|archive-url=https://web.archive.org/web/20240512131635/https://theintercept.com/snowden-sidtoday/?orderBy=publishedTime&orderDirection=desc#archive|url-status=live}}
External links
{{Commons category}}
- {{Official website}}
- [https://web.archive.org/web/20180623141614/https://www.nsa.gov/about/cryptologic_heritage/60th/book/NSA_60th_Anniversary.pdf National Security Agency – 60 Years of Defending Our Nation]
- [https://www.archives.gov/research/guide-fed-records/groups/457.html Records of the National Security Agency/Central Security Service] {{Webarchive|url=https://web.archive.org/web/20061014140149/http://www.archives.gov/research/guide-fed-records/groups/457.html |date=2006-10-14 }}
- [https://www.gwu.edu/~nsarchiv/ The National Security Archive at George Washington University] {{Webarchive|url=https://web.archive.org/web/20150319080441/http://www2.gwu.edu/~nsarchiv/ |date=2015-03-19 }}
- {{cite web|url=http://www.intelligence.gov/1-members_nsa.shtml |title=United States Intelligence Community: Who We Are / NSA section |archive-url=https://web.archive.org/web/20060925221125/http://www.intelligence.gov/1-members_nsa.shtml |archive-date=September 25, 2006}}
- [https://archive.org/details/nsa-archive National Security Agency (NSA) Archive] on the Internet Archive
- [https://web.archive.org/web/20150803025808/https://www.nsa.gov/public_info/declass/index.shtml Declassification and Transparency] page on the Internet Archive
{{National Security Agency}}
{{Navboxes
|list =
{{Harry S. Truman}}
{{United States Department of Defense}}
{{United States intelligence agencies}}
{{National intelligence agencies}}
{{Five Eyes}}
{{Federal law enforcement agencies of the United States}}
{{United States topics}}
}}
{{Authority control}}
Category:1952 establishments in the United States
Category:Articles containing video clips
Category:Computer security organizations
Category:Federal law enforcement agencies of the United States
Category:Government agencies established in 1952
Category:Intelligence analysis agencies
Category:Signals intelligence agencies