

SUBSCRIBE TO OUR FREE NEWSLETTER
Daily news & progressive opinion—funded by the people, not the corporations—delivered straight to your inbox.
5
#000000
#FFFFFF
To donate by check, phone, or other method, see our More Ways to Give page.


Daily news & progressive opinion—funded by the people, not the corporations—delivered straight to your inbox.
The retail giant was also ordered to pay more than $30 million last year after allegedly surveilling customers with its tech products.
Months after Amazon was fined more than $30 million for allegedly spying on customers in their homes, a French data watchdog on Monday announced it had ordered the retail giant to pay another $35 million for what it called "excessive" tracking of warehouse employees' activity.
France's National Commission on Informatics and Liberty (CNIL) informed Amazon France Logistique, which runs the U.S. company's warehouses in the country, of the fine late last month after investigating scanning devices used by employees.
Several features of the tools violate the European Union's General Data Protection Regulation (GDPR), according to the group.
The technology-focused news outlet The Register reported that all employees at Amazon's French warehouses are given scanners that document their tasks, including when they pick up an item or place it in a delivery box.
CNIL found that the "inactivity indicators" on the scanners were "too precise" and could lead "to the employee potentially having to justify each break or interruption."
Another feature used to measure the speed at which the scanner is used and one that stored data history for 31 days were also deemed "excessive" by the watchdog.
CNIL's investigation found that before April 2020, temporary employees at the warehouses weren't informed that their data would be collected by the scanning devices and that no workers were sufficiently told that the facilities were equipped with video surveillance systems.
In violation of Article 32 of the GDPR, said the watchdog, "access to the video surveillance software was not sufficiently secure, since the password was not sufficiently robust and the access account was shared between several users."
The group said it determined the amount of Amazon's penalty by taking into account "the fact that the processing of employees' data by means of scanners differed from the methods of monitoring of traditional activity because of the scale at which they were implemented, both in terms of their completeness and permanence, and led to a very tight and detailed monitoring of the work of employees."
The EUobserver, which reports on democracy within the bloc, noted that the fine was announced on the same day that Amazon refused to participate in a European Parliament hearing on working conditions in its warehouses.
The fine comes less than a year after the U.S. Federal Trade Commission (FTC) determined that an Amazon employee had used its Ring security cameras to spy on female customers for several months, prompting the company to agree to a settlement worth $5.8 million.
Amazon also agreed to a $25 million settlement after being accused to failing to delete audio when parents requested they be erased from Alexa speakers.
The company said Tuesday that it "might appeal" the CNIL's decision and that the watchdog's conclusions about its surveillance practices were "factually incorrect."
In the U.S., progressive law professor Zephyr Teachout called the fine "excellent" and expressed hope that policymakers will soon pass "clear American laws that recognize just how harmful extreme monitoring is."
"Contract law is not the key," said Teachout. "Basic dignity is."
Amazon's focus on closely monitoring employees' activities has led to numerous injuries among workers, according to a survey by the University of Illinois Chicago's Center for Urban Economic Development last October. The center found that out of 1,484 employees, 70% had been forced to take unpaid time off due to sprains, strains, and other injuries sustained while rushing to keep up with Amazon's demanding quotas.
"We see clear evidence in our data," said researchers, "that work intensity and monitoring contribute to negative health outcomes."
Artificial intelligence could supercharge threats to civil liberties, civil rights, and privacy.
Your friends aren’t the only ones seeing your tweets on social media. The F.B.I and the Department of Homeland Security (DHS), as well as police departments around the country, are reviewing and analyzing people’s online activity. These programs are only likely to grow as generative artificial intelligence (AI) promises to re-make our online world with better, faster, and more accurate analyses of data, as well as the ability to generate humanlike text, video, and audio.
While social media can help law enforcement investigate crimes, many of these monitoring efforts reach far more broadly even before bringing AI into the mix. Programs aimed at “situational awareness,” like those run by many parts of DHS or police departments preparing for public events, tend to have few safeguards. They often veer into monitoring social and political movements, particularly those involving minority communities. For instance, DHS’s National Operations Center issued multiple bulletins on the 2020 racial justice protests. The Boston Police Department tracked posts by Black Lives Matter protesters and labeled online speech related to Muslim religious and cultural practices as “extremist” without any evidence of violence or terrorism. Nor does law enforcement limit itself to scanning public posts. The Memphis police, for example, created a fake Facebook profile to befriend and gather information from Black Lives Matter activists.
The pervasiveness — and problems — of social media surveillance are almost certain to be exacerbated by new AI tools...
Internal government assessments cast serious doubt on the usefulness of broad social media monitoring. In 2021, after extensive reports of the department’s overreach in monitoring racial justice protestors, the DHS General Counsel’s office reviewed the activities of agents collecting social media and other open-source information to try to identify emerging threats. It found that agents gathered material on “a broad range of general threats,” ultimately yielding “information of limited value.” The Biden administration ordered a review of the Trump-era policy requiring nearly all visa applicants to submit their social media handles to the State Department, affecting some 15 million people annually, to help in immigration vetting — a practice that the Brennan Center has sought to challenge. While the review’s results have not been made public, intelligence officials charged with conducting it concluded that collecting social media handles added “no value” to the screening process. This is consistent with earlier findings. According to a 2016 brief prepared by the Department of Homeland Security for the incoming administration, in similar programs to vet refugees, account information “did not yield clear, articulable links to national security concerns, even for those applicants who were found to pose a potential national security threat based on other security screening results.” The following year, the DHS Inspector General released an audit of these programs, finding that the department had not measured their effectiveness and rendered them an insufficient basis for future initiatives. Despite failing to prove that monitoring programs actually bolster national security, the government continues to collect, use, and retain social media data.
The pervasiveness — and problems — of social media surveillance are almost certain to be exacerbated by new AI tools, including generative models, which agencies are racing to adopt.
Generative AI will enable law enforcement to more easily use covert accounts. In the physical world, undercover informants have long raised issues, especially when they have been used to trawl communities rather than target specific criminal activities. Online undercover accounts are far easier and cheaper to create and can be used to trick people into interacting and inadvertently sharing personal information such as the name of their friends and associations. New AI tools could generate fake accounts with a sufficient range of interests and connections to look real and autonomously interact with people online, saving officer time and effort. This will supercharge the problem of effortless surveillance, which the Supreme Court has recognized may “alter the relationship between citizen and government in a way that is inimical to democratic society.” These concerns are compounded by the fact that few police departments impose restrictions on undercover account use, with many allowing officers to monitor people online without a clear rationale, documentation or supervision. The same is true for federal agencies such as DHS.
Currently, despite the hype generated by their purveyors, social media surveillance tools seem to operate on a relatively rudimentary basis. While the companies that sell them tend to be secretive about how they work, the Brennan Center’s research suggest serious shortcomings. Some popular tools do not use scientific methods for identifying relevant datasets, much less test them for bias. They often use key words and phrases to identify potential threats, which blurs the context necessary to understand whether something is in fact a threat and not, for example, someone discussing a video game. It is possible that large language models, such as ChatGPT, will advance this capability — or at least be perceived and sold as doing so — and incentivize greater use of these tools.
At the same time, any such improvements may be offset by the fact that AI is widely expected to further pollute the unreliable information environment, exacerbating problems of provenance and reliability. Social media is already suffused with inaccurate and misleading information. According to a 2018 MIT study, false political news is 70 percent more likely to be re-tweeted than truthful content on X (formerly Twitter). Bots and fake accounts — which can already mimic human behavior — are also a challenge; during the COVID-19 pandemic, bots were found to proliferate misinformation about the disease, and could just as easily spread fake information generated by AI, deceiving platform users. Generative AI makes creating false news and fake identities easier, negatively contributing to an already-polluted online information environment. Moreover, AI has a tendency to “hallucinate,” or make up information — a seemingly unfixable problem that is ubiquitous among generative AI systems.
Generative AI also exacerbates longstanding problems. The promise of better analysis does nothing to ease First Amendment issues raised by social media monitoring. Bias in algorithmic tools has long been a concern, ranging from predictive policing programs that treat Black people as suspect to content moderation practices disfavoring Muslim speech. For example, Instagram users recently found that the label terrorist was addedto their English bios if their Arabic bios included the word “Palestinian,” the Palestinian flag emoji, and the common Arabic phrase “praise be to god.”
The need to address these risks is front and center in President Biden’s AI executive order and a draft memorandum from the Office of Management and Budget that sets out standards for federal agency use of AI. The OMB memo identifies social media monitoring as a use of AI that impacts individuals’ rights, and thus requires agencies using this technology to follow critical rules for transparency, testing efficacy and mitigating bias and other risks. Unfortunately, these sensible rules do not apply to national security and intelligence uses and do not affect police departments. But they should.
"Journalists must be able to freely report on government actions without fear the government will compel them to reveal their sources," said one campaigner.
Privacy and First Amendment advocates on Wednesday urged the U.S. House to pass legislation that would protect the United States' bedrock freedoms and a core tenet of journalism: the right of reporters to guard the identities of their sources.
The House Judiciary Committee advanced the Protect Reporters from Exploitative State Spying (PRESS) Act with bipartisan support, despite claims in recent months by Republican lawmakers such as Sen. Tom Cotton (R-Ark.) that the legislation would "immunize journalists and leakers alike from scrutiny and consequences for their actions."
The bill has been recognized by press freedom advocates as the most important piece of legislation in modern times regarding journalists' rights, as it would codify state protections at the federal level.
Forty-nine states already protect reporters from being compelled to reveal their confidential sources and federal abuse of subpoena power, and the PRESS Act would ensure all journalists have those protections regardless of where in the country they live and work.
"Journalists must be able to freely report on government actions without fear the government will compel them to reveal their sources. We commend the House Judiciary Committee for its bipartisan support of the PRESS Act," said Daniel Schuman, policy director at Demand Progress. "The Senate must act now to advance this important legislation."
The House previously advanced the bill with a voice vote last September, garnering support from all the Republicans in the chamber. Schuman pointed out late last year, as Cotton blocked the passage of the bill in the Senate, that the lower chamber included a number of exceptions in the law to satisfy the House GOP.
The bill includes exceptions for cases pertaining to information necessary to identify people accused of terrorist acts or involving the risk of imminent bodily harm or death, crimes unrelated to journalism, slander, libel, and defamation.
"The PRESS Act creates critical protections for the fearless journalists who act as government watchdogs and keep all of us informed," said Jenna Leventoff, senior policy counsel at the ACLU, which has long advocated for the bill. "While the majority of states already have shield laws in place that protect journalists from compelled disclosure of their sources, the PRESS Act provides uniform protections to journalists all across the country. We thank the House Judiciary Committee for protecting our constitutional right to a free press and urge the full House to swiftly pass this bipartisan legislation."
Although the U.S. Department of Justice adopted a policy in 2021 restricting subpoenas and seizures of journalists' technological devices and data, Gabriela Schneider noted at First Branch Forecast, Demand Progress Education Fund's newsletter, that the measure "could just as easily be suspended, ignored, or secretly altered."
"Importantly," Schneider wrote, "the PRESS Act would codify into law this prohibition, making it real and permanent."
"We trusted the government not to screw us," said Edward Snowden. "But they did. We trusted the tech companies not to take advantage of us. But they did. That is going to happen again, because that is the nature of power."
With this week marking 10 years since whistleblower Edward Snowden disclosed information to journalists about widespread government spying by United States and British agencies, the former National Security Agency contractor on Thursday joined other advocates in warning that the fight for privacy rights, while making several inroads in the past decade, has grown harder due to major changes in technology.
"If we think about what we saw in 2013 and the capabilities of governments today," Snowden told The Guardian, "2013 seems like child's play."
Snowden said that the advent of commercially available surveillance products such as Ring cameras, Pegasus spyware, and facial recognition technology has posed new dangers.
As Common Dreams has reported, the home security company Ring has faced legal challenges due to security concerns and its products' vulnerability to hacking, and has faced criticism from rights groups for partnering with more than 1,000 police departments—including some with histories of police violence—and leaving community members vulnerable to harassment or wrongful arrests.
Law enforcement agencies have also begun using facial recognition technology to identify crime suspects despite the fact that the software is known to frequently misidentify people of color—leading to the wrongful arrest and detention earlier this year of Randal Reid in Georgia, among other cases.
"Despite calls over the last few years for federal legislation to rein in Big Tech companies, we've seen nothing significant in limiting tech companies' ability to collect data."
Last month, journalists and civil society groups called for a global moratorium on the sale and transfer of spyware like Pegasus, which has been used to target dozens of journalists in at least 10 countries.
Protecting the public from surveillance "is an ongoing process," Snowden told The Guardian on Thursday. "And we will have to be working at it for the rest of our lives and our children's lives and beyond."
In 2013, Snowden revealed that the U.S. government was broadly monitoring the communications of citizens, sparking a debate over surveillance as well as sustained privacy rights campaigns from groups like Electronic Frontier Foundation (EFF) and Fight for the Future.
"Technology has grown to be enormously influential," Snowden told The Guardian on Thursday. "We trusted the government not to screw us. But they did. We trusted the tech companies not to take advantage of us. But they did. That is going to happen again, because that is the nature of power."
Last month ahead of the anniversary of Snowden's revelations, EFF noted that some improvements to privacy rights have been made in the past decade, including:
"Despite calls over the last few years for federal legislation to rein in Big Tech companies, we've seen nothing significant in limiting tech companies' ability to collect data... or regulate biometric surveillance, or close the backdoor that allows the government to buy personal information rather than get a warrant, much less create a new Church Committee to investigate the intelligence community's overreaches," wrote EFF senior policy analyst Matthew Guariglia, executive director Cindy Cohn, and assistant director Andrew Crocker. "It's why so many cities and states have had to take it upon themselves to ban face recognition or predictive policing, or pass laws to protect consumer privacy and stop biometric data collection without consent."
"It's been 10 years since the Snowden revelations," they added, "and Congress needs to wake up and finally pass some legislation that actually protects our privacy, from companies as well as from the NSA directly."
Newly leaked documents published by The Intercept expose how easy it is for the FBI to spy on journalists using so-called National Security Letters (NSLs).
The classified rules, which had previously been released only in heavily redacted form, "show that the FBI imposes few constraints on itself when it bypasses the requirement to go to court and obtain subpoenas or search warrants before accessing journalists' information," The Intercept's Cora Currier wrote on Thursday.
According to the reporting, an attempt to access journalists' call data with an NSL must be approved by the typical chain-of-command, the FBI's general counsel, and the executive assistant director of the agency's National Security Branch.
"Generally speaking, there are a variety of FBI officials, including the agents in charge of field offices, who can sign off that an NSL is 'relevant' to a national security investigation," Currier explained.
Trevor Timm of the Freedom of the Press Foundation, an advocacy group that had petitioned for the release of these documents, calls Thursday's revelations "quite disturbing since the Justice Department spent two years trying to convince the public that it updated its 'Media Guidelines' to create a very high and restrictive bar for when and how they could spy on journalists using regular subpoenas and court orders. These leaked rules prove that the FBI and [Department of Justice or DOJ] can completely circumvent the Media Guidelines and use an NSL in total secrecy."
The Intercept added: "Under the rules, There is an extra step if the NSL targets a journalist to' identify confidential news media sources.' In that case, the general counsel and the executive assistant director must first consult with the assistant attorney general for the Justice Department's National Security Division."
Of this low additional hurdle, Timm scoffs: "That's it! They don't even have to go through the motions to follow any of the several rules laid out in the DOJ [M]edia [G]uidelines: like getting the Attorney General to sign off, exhausting all other means of investigation, alerting and negotiating with the affected media organization, making sure what is being sought is essential to the investigation, etc."
Furthermore, the rules stipulate that if "the NSL is trying to identify a leaker by targeting the records of the potential source, and not the journalist, the Justice Department doesn't need to be involved."
And then there's the matter of transparency, Timm writes, comparing the information gleaned through the leak with what was previously made available by the DOJ:
The other major question here is: why are these rules secret in the first place? The information that has been redacted here by the Justice Department--and which they are fighting to keep secret in court--is incredibly mundane. The fact that the FBI has to get another person in the bureaucracy to sign off on a particular investigation should not be a state secret, nor would it remotely harm any ongoing investigation, nor would "tip off" any alleged criminals to how to evade surveillance.
In an effort to make the rules more transparent, the Freedom of the Press Foundation in 2015 filed a Freedom of Information Act (FOIA) lawsuit demanding the DOJ release the secret rules targeting journalists. Last month, a coalition of 37 news organizations--including the Associated Press, NPR, and Buzzfeed--filed a legal brief supporting that demand.
Just last week, the U.S. Senate failed to pass a bill that would have dramatically expanded the FBI's authority to use NSLs to obtain Electronic Communication Transaction Records (ECTR) such as email time stamps, senders, and recipients, as well as browsing metadata such as history and location--all without a warrant.
However, digital rights group Electronic Frontier Foundation warned at the time, Senate Majority Leader Mitch McConnell "switched his vote to 'No' at the last minute so that he may be able to bring up the amendment during future debate."
Billboards nationwide will soon begin spying on passers-by's behavior and selling that data to advertisers.
Clear Channel Outdoor Americas, which owns tens of thousands of billboards nationwide, is announcing plans to use people's cell phones to allow its billboards to track the behavior of everyone who walks or drives past the ads.
"People have no idea that they're being tracked and targeted," Jeffrey Chester, executive director of the Center for Digital Democracy, told the New York Times, which broke the news on Sunday. "It is incredibly creepy, and it's the most recent intrusion into our privacy."
The marketing behemoth is partnering with AT&T and other companies that track human behavior to collect data on viewers' activity, which advertisers could then use to create hyper-targeted ads--similar to how websites track visitors through their browsers and sell that data to online marketers.
Privacy advocates say the problem is that most people when out in public, have no idea that their every move is being recorded, analyzed, and sold for marketing purposes. When similar ads that used smartphones to track behavior were installed in phone booths in New York City in 2008, there was a loud public outcry, and the billboards were quickly removed after a Buzzfeed investigation.
Indeed, even Clear Channel Outdoor Americas' spokesman conceded to the New York Times that the company's new service "sounds a bit creepy."
Critics also note that using smartphone data to track the behavior of unsuspecting passers-by poses specific risks to children. Children are more susceptible to advertisements and use mobile phones at increasingly younger ages. A 2012 study found that 56 percent of children ages eight to 12 have cell phones.
Advertisers also increasingly use facial recognition technology to track behavior in public spaces, and many people remain unaware of it. The February 2016 issue of Consumer Reports drew attention to the growing phenomenon and listed a few examples of how the technology is being put to use:
In Germany, the Astra beer brand recently created an automated billboard that noted when women walked past. The billboard approximated the women's age, then played one of several prerecorded ads to match.
Retailers can use facial recognition systems to see how long people of a particular race or gender remain in the shop and adjust displays and the store layout to enhance sales.
Using related technology, some high-end retailers in the U.S. have experimented with "memory mirrors" that perform tricks such as storing images of what shoppers tried on so that they can be revisited or emailed directly to friends for feedback.
Public tracking techniques such as facial recognition are "largely unregulated," the magazine observed.
"People would be outraged if they knew how facial recognition" is being developed and promoted, Alvaro Bedoya, the executive director of Georgetown Law's Center on Privacy & Technology, told Consumer Reports. "Not only because they weren't told about it, but because there's nothing they can do about it."
You may have heard that Juniper Networks announced what amounts to a backdoor in its virtual private network products. Here's Kim Zetter's accessible intro of what security researchers have learned. And here's some technical background from Matthew Green.
As Zetter summarizes, the short story is that some used weaknesses encouraged by the NSA to backdoor the security product protecting many American businesses.
They did this by exploiting weaknesses the NSA allegedly placed in a government-approved encryption algorithm known as Dual_EC, a pseudo-random number generator that Juniper uses to encrypt traffic passing through the VPN in its NetScreen firewalls. But in addition to these inherent weaknesses, the attackers also relied on a mistake Juniper apparently made in configuring the VPN encryption scheme in its NetScreen devices, according to Weinmann and other cryptographers who examined the issue. This made it possible for the culprits to pull off their attack.
As Green describes, the key events probably happened as early as 2007 and 2012 (contrary to the presumption of surveillance hawk Stewart Baker, who is looking to scapegoat those calling for more security). This means this can't be a response to the Snowden document, which strongly suggests the NSA had pushed those weaknesses in Dual_EC.
I find that particularly interesting, because it suggests whoever did this either used public discussions about the weakness of Dual_EC, dating to 2007, to identify and exploit this weakness, or figured out what (it is presumed) the NSA was up to. That suggests two likely culprits for what has been assumed to be a state actor behind this: Israel (because it knows so much about NSA from having partnered on things like StuxNet) or Russia (which was getting records on the FiveEyes' SIGINT activities from its Canadian spy, Jeffrey Delisle). The UK would be another obvious guess, except an Intercept article describing how NSA helped UK backdoor Juniper suggests they used another method.
This leads me back to an interesting change I noted between CISA -- the bill passed by the Senate back in October -- and OmniCISA -- the version passed last week as part of the omnibus funding bill. OmniCISA still required the Intelligence Community to provide a report on the most dangerous hacking threats, especially state actors, to the Intelligence Committees. However, it eliminated a report for the Foreign Relations Committees on the same topic. I joked at the time that that was probably to protect Israel, because no one wants to admit that Israel spies and has greater ability to do so by hacking than other nation-states, especially because it surely learns our methods by partnering with us to hack Iran.
Whoever hacked Juniper, the whole incident offers a remarkable lesson in the dangers of backdoors. Even as the FBI demands a backdoor into Apple's products, it is investigating who used a prior US-sponsored backdoor to do their own spying.
Following several dedicated grassroots campaigns by consumer rights advocates, technology companies are opposing the Cybersecurity Information Sharing Act (CISA) as the controversial surveillance bill approaches a vote in the U.S. Senate.
Some industry titans now publicly opposing CISA are Google, Apple, and Twitter, among other well-known companies, while those who support the bill include Verizon, AT&T, and Cisco.
CISA would allow tech companies to share user data with the National Security Agency (NSA) and other intelligence offices in cases of "cybersecurity threats." Critics say the bill only expands government surveillance powers and guts consumer protections.
Apple publicly came out against CISA on Tuesday as the Senate began gearing up for the vote, citing concerns over privacy and users' rights.
"We don't support the current CISA proposal," Apple said. "The trust of our customers means everything to us, and we don't believe security should come at the expense of their privacy."
Apple's strong stance on the issue earned it a top spot on digital rights group Fight for the Future's "Digital Scorecard," which tracks where tech firms stand in the battle for privacy. Companies that have publicly supported reform for the Electronic Communications Privacy Act (ECPA) and opposed CISA and other legislation that would give governments a backdoor into encrypted devices were named "Team Internet."
Those who did any less were dubbed "Team NSA."
"People trust these companies with a staggering amount of personal information, and we need ways to hold them accountable to ensure they keep our data safe from both attackers and the government," said Fight for the Future's campaign director Evan Greer. "It's not enough for companies to employ basic security practices; they must actively fight for their users' basic rights when key policy questions arise. Politicians constantly claim the tech industry's support when attempting to undermine our privacy, so these companies have a responsibility to fight back."
As Freedom of the Press Foundation co-founder Trevor Timm wrote in an op-ed for the Guardian on Tuesday, CISA is nothing more than "a surveillance bill in disguise." That opposition is coming from the likes of Google and Amazon--no strangers to privacy scandals--shows how bad the bill really is, Timm wrote.
Also in the internet's corner is Dropbox, marking a significant shift for a company that recently added surveillance advocate Condoleezza Rice to its board of directors and which NSA whistleblower Edward Snowden once called "a wannabe PRISM partner" for its anti-privacy policies.
"While the public and private sector needs to share relevant data about emerging threats, that type of collaboration should not come at the expense of users' privacy," Amber Cottle, head of Dropbox global public policy and government affairs, said on Tuesday.
Some of the other firms that also got high marks on the Digital Scorecard, including Apple and Microsoft, reversed course after initially giving their support to CISA--which resulted in a massive email campaign, also organized by Fight for the Future, threatening to quit using their products, services, and platforms if the bill went through.
The digital rights group said the pressure is on Congress and offered a similar warning to lawmakers.
"It's outrageous that Congress is even considering passing a law that would further erode Internet users' privacy and security at a time when both are already so fragile," Greer said. "CISA's supporters have repeatedly claimed that the tech industry needs this legislation, but now nearly every major tech company has come out opposing it, not only because they know it won't stop cyber attacks, but also because it's supremely unpopular with their users."
"Congress should remember that those users are also voters," Greer said.
As new controversial metadata laws took effect in Australia on Tuesday, whistleblower Edward Snowden took to Twitter to warn the country's residents about the privacy violations accompanying the legislation.
The new laws require Australian telecommunications companies and internet service providers (ISPs) to store user metadata--like phone records and IP addresses--for two years. During this time, it may be accessed by law enforcement without a warrant. Civil liberties and internet freedom groups have criticized the laws as invasive and unconstitutional.
"Beginning today, if you are Australian, everything you do online has been tracked, stored, and retained for 2 years," Snowden wrote, linking to a campaign by the advocacy group GetUp! that gave instructions on how to circumvent the data retention scheme.
The laws are "costly, ineffective, and against the public interest," GetUp! wrote in its campaign.
According to (pdf) the Australian Privacy Foundation, an internet advocacy group and a subsidiary of Privacy International, the laws require telecoms to maintain, at a minimum:
After a similar metadata dragnet was attempted in Germany, it was deemed unconstitutional in 2010. Further, the German Parliament's Working Group on Data Retention published a study in 2011 that concluded that Germany's similar metadata dragnet, which had been found unconstitutional in 2010, had resulted in a .006 percent increase in crime clearance rates--a "marginal" boost that showed "the relationship between ends and means is disproportionate."
And yet, the Australian government, led by newly installed Prime Minister Malcolm Turnbull, "says it has taken into account suggestions made by courts overseas that have overturned the legislation," writes Sydney Morning Herald technology editor Ben Grubb.
To counter the invasive new laws, GetUp! and other civil liberties groups recommend that users install privacy software on their phones and computers, such as encrypted messaging apps, secure browsers like Tor, or a virtual private network (VPN).
"Go dark against data retention," the group states. "Absurdly, the flawed legislation leaves open numerous loopholes, which can be used to evade the data retention. This means the data retention dragnet will capture the data of innocent Australians and cost millions of dollars while allowing those who don't want to be caught to remain hidden."
The current debate about government surveillance has largely overlooked the CIA, possibly because we know little about the agency's activities within the United States. While the relevant legal authorities governing the CIA, including Executive Order 12333, set out the CIA's mandate, they do so in broad terms. Beyond the generalities in EO 12333 and other laws, the public has had few opportunities to examine the rules governing the CIA's activities.
The current debate about government surveillance has largely overlooked the CIA, possibly because we know little about the agency's activities within the United States. While the relevant legal authorities governing the CIA, including Executive Order 12333, set out the CIA's mandate, they do so in broad terms. Beyond the generalities in EO 12333 and other laws, the public has had few opportunities to examine the rules governing the CIA's activities.
But we know more today than we did a few weeks ago. In response to a Freedom of Information Act lawsuit filed by the ACLU and Yale Law School's Media Freedom and Information Access Clinic, the CIA has released a slew of documents concerning CIA surveillance under EO 12333. (The Justice Department has also recently released a set of documents related to the executive order.)
The national debate in the 1970s about the proper limits of U.S. government spying on its own citizens was, to a large extent, about the CIA. In the wake of the Watergate scandal and news stories about other illegal CIA activity, President Gerald Ford and Congress launched investigations into the full range of CIA misdeeds -- from domestic spying programs and infiltration of leftist organizations to experimentation on non-consenting human subjects and attempts to assassinate foreign leaders.
Although the CIA's legal authority to spy on Americans was very narrow, these investigative committees -- chaired by Sen. Frank Church, Vice President Nelson Rockefeller, and Rep. Otis Pike -- discovered that the CIA had engaged in a massive domestic spying project, "Operation CHAOS," which targeted anti-war activists and political dissenters. The committee reports also revealed that, for more than 20 years, the CIA had indiscriminately intercepted and opened hundreds of thousands of Americans' letters. In addition to documenting the intelligence agencies' extensive violations of the law, the Church Committee concluded that the constitutional system of checks and balances "has not adequately controlled intelligence activities."
The Church Committee's conclusion -- at core, an admonition -- still resonates today. While the documents that the CIA has released are heavily redacted, raising more questions than they answer, they strongly suggest that the agency's domestic activities are extensive.
Some highlights from the documents:
AR 2-2, which has never been publicly released before, includes rules governing a wide range of activities, including surveillance of U.S. persons, human experimentation, contracts with academic institutions, relations with journalists and staff of U.S. news media, and relations with clergy and missionaries.
Several annexes to AR 2-2 contain the agency's EO 12333 implementing procedures. For example, Annex A, "Guidance for CIA Activities Outside the United States," sets forth the procedures that apply to CIA activity directed toward U.S. citizens and permanent residents who are abroad. Much of the relevant information is redacted. Annex F, "Procedures Governing Conduct and Coordination by CIA and DEA of Narcotics Activities Abroad," is similarly redacted in key sections, including the section discussing the agencies' "Specific Agreement Concerning Electronic Surveillance."
Domestically, the CIA's spying is governed by Annex B to AR 2-2, "Guidance for CIA Activities Within the United States." This document explains:
Although EO 12333, AR 2-2, and Annex B prohibit the agency from engaging in electronic surveillance within the United States, the CIA can nevertheless ask the FBI to do its bidding:
Annex B and the CIA-FBI memorandum of understanding comport with past reporting that the Foreign Intelligence Surveillance Court authorized the FBI to work with the CIA to collect Americans' financial records in bulk under Patriot Act Section 215.
In addition, Annex B explains that the CIA may "use a monitoring device within the United States under circumstances in which a warrant would not be required for law enforcement purposes if the CIA General Counsel concurs."
But what qualifies as a "monitoring device"? And how exactly does monitoring differ from "electronic surveillance," which the CIA is prohibited from doing domestically? We don't know. In the newly released documents, the definition of "monitoring" (as distinct from "electronic surveillance") is redacted.
The CIA also turned over several years' worth of annual reports to Congress about the agency's activities under EO 12333. These reports begin by discussing "Intelligence Activities Conducted by CIA Within the United States." This header is followed by dozens of entirely redacted pages -- once again suggesting that the agency is engaged in a significant amount of intelligence activity here at home.
A 2002 report by the CIA inspector general, "Intelligence Activity Assessment: Compliance with Executive Order 12333: The Use of [redacted] Collection [redacted] from 1995-2000," observed "a general and widespread lack of understanding" within the CIA of the rules governing the retention and sharing of U.S. citizens' and permanent residents' information. In particular, the OIG found that few managers or other officers "could accurately state the appropriate procedures for retaining or disseminating U.S. person information," and it concluded that these rules were "not being applied consistently" by the agency.
* * *
The independent and bi-partisan Privacy and Civil Liberties Oversight Board is currently examining the intelligence community's counterterrorism-related activities under EO 12333. Notably, one of the topics the board plans to focus on is the CIA's collection of information within the United States. We hope that, when the board eventually issues its public report about the agencies' activities under EO 12333, it sheds a little more light on what exactly the CIA is doing here at home.