Tag Archives: NSA

Facebook makes its first revised report on U.S. government’s secret requests for user data


By SB Anderson

Facebook on Monday became one of the latest companies since Justice Department reporting rules were relaxed late last month to release more details about the number and type of secret requests that U.S. authorities have made for user account information and content.

Facebook in a release said it had received up to 999 requests for content under the the Foreign Intelligence Surveillance Act in the first half of 2013, and those requests covered from 5,000 to 5,999 accounts. Another 0-999 FISA requests that didn’t involve content — but sought information such as a subscriber name — were received, involving an equal number of accounts. It also received up to 999 “National Security Letters” from the FBI director for user information.

Those numbers were little changed from the second half of 2012. The number of National Security Letters was in the same range in the second half of 2013. Data for the FISA requests cannot be released until after a six-month waiting period, so there is no data for the second half of 2013 for those yet.

The new relaxed reporting standards allowed the FISA data to be made public for the first time. Companies that choose to report the FISA requests and NSL requests combined can use ranges of 0–249; if data is separate, it must be reported in larger ranges — 0-999. Facebook chose the latter.

Apple, which reported its data last week, chose the former. Apple said it had received between 0 and 249 FISA and NSL requests in the first half of 2013, involving the same range of accounts.

In its original “transparency report” on 2013 first-half requests, Facebook said it received between 11,000 and 12,000 requests from all law enforcement agencies, affecting 20,000-21,000 accounts.

The Justice Department agreed to relax the reporting rules as part of settling a lawsuit by a number of companies — including Facebook, seeking latitude to be more transparent in their reporting.

“The new information we are releasing today marks a significant step forward,” Facebook said in its release. “As we have said before, we believe that while governments have an important responsibility to keep people safe, it is possible to do so while also being transparent.”

Facebook FISA and NSL

SOURCE: Facebook.

Apple first to report number of secret customer data requests under new reporting rules


By SB Anderson

Apple this week was the first tech company to take advantage of new slightly more lenient Justice Department rules about how many secret requests for customer information the federal government makes.

The new rules governing controversial “National Security Letters” from the FBI director and national security orders issued under the Foreign Intelligence Surveillance Act were part of a settlement of a lawsuit by technology companies seeking to be more transparent about the top secret demands for information. (Read the settlement order as well as a letter from the Justice Department)

Apple said it had received between 0 and 249 FISA and NSL requests in the first half of 2013, involving the same range of accounts.

Only basic customer information can be requested in an NSL; content, such as e-mails, cannot be sought. Content information can be sought under national security orders and the new regulations provide some latitude to report how many times that happens.

Previously, companies were prohibited from even acknowledging that they had received national security orders from the Foreign Intelligence Surveillance Court. They could report NSLs, but only in bands of 1,000 such as 0-999.

Apple in its release on Monday said it was “pleased” with the new rules, but made it clear that the number of secret orders at the end of the day was de minimis.

“The number of accounts involved in national security orders is infinitesimal relative to the hundreds of millions of customer accounts registered with Apple,” Apple said.

Companies now have two options for reporting data that is at least six months old, and only once every six months:

  1. Can report national security orders under FISA, and National Security Letters from the FBI, as a combined number in increments of 250, as well as the number of accounts affected, also in increments. This is what Apple chose to do. Companies can also release the type of order as well as whether it was for customer content.
  2. If they want to report security orders and NSLs separately, the must use the original bands of 1,000 (e.g., 0-999).

Below is our running tally of key transparency report data, updated with Apple’s new report. | Earlier stories on transparency reports.

Transparency Report Update

For Verizon, a solid grade on transparency reporting


By SB Anderson

Telecom behemoth Verizon released its first ever “Transparency Report” today on the number of requests for customer data it gets from government agencies — a whopping 900 A DAY almost. That was 320,000 total in 2013 in the U.S. alone.

Numbers aside for a moment, this report is one the clearest, most pithy documents on the topic that OTB has come across in the past two years of working with this data from Google, Apple, Microsoft et al. It’s like the lawyers were temporarily possessed by an angel of clarity and precision as they sat down at the keyboard.

verizon transparency data

      SOURCE: Verizon

Not only do you get a clear, simple explanation of the number of requests and types, and Verizon’s policies, but also a clear, simple explanation of the various laws and process that are involved.

One negative in the report is that it does not detail how often Verizon actually released data. While the numbers are typically small, other companies detail the times they’ve said no to requests for various reasons or didn’t have the data requested. Google, for example, did not release data in 17% of requests in the first half of 2013.

Verizon’s numbers are so large compared to even the largest companies such as Google and Microsoft that have released reports in the past that it said it only “relatively infrequently” was compelled to provide content such as text messages, email and photos. Infrequently in this case: 14,500 times via warrant. It received about twice that many warrants and orders for location information — 35,000 demands — and 3,200 requests for “cell tower dumps,” in which it provides an agency all phone numbers that communicated with a certain cell tower for a period of time.

“The number of warrants and orders for location information are increasing each year,” Verizon noted.

Verizon also received between 1,000 and 1,999 “National Security Letters” from the FBI Director. These controversial orders certify that “the information sought is relevant to an authorized investigation to protect against international terrorism or clandestine intelligence activities. . . .” Content data cannot be sought; requests must be for “name, address, length of service and toll billing records.”

It is illegal to disclose the exact number of letters received (individuals who receive them cannot even say they got one) or give details about what was sought. Only figures in ranges from 1-999 can be used to say how many were received.

NSA FOIA requests explode in months since Snowden leaks began


By SB Anderson

Freedom of Information Act requests filed with the National Security Agency have boomed since Edward Snowden began leaking top-secret documents in June.

An internal document released last week to MuckRock showed 3,382 FOIA requests between June 6 and Sept, 14 of this year — nearly 12 times the 293 filed in that same period a year ago.

The requests have leveled off somewhat from earlier in the summer when the first media leaks appeared, although they continue to be much higher than normal. For perspective, for all of FY12 we received only 1809 requests,” the NSA said in its memo.

Change in NSA FOIA Requests