Showing posts with label NSL. Show all posts
Showing posts with label NSL. Show all posts

20151130

The National Security Letter spy tool has been uncloaked, and it’s bad

by David Kravets - Nov 30, 2015 11:25am PST

...The National Security Letter (NSL) is a potent surveillance tool that allows the government to acquire a wide swath of private information—all without a warrant. Federal investigators issue tens of thousands of them each year to banks, ISPs, car dealers, insurance companies, doctors, and you name it. The letters don't need a judge's signature and come with a gag to the recipient, forbidding the disclosure of the NSL to the public or the target.

For the first time, as part of a First Amendment lawsuit, a federal judge ordered the release of what the FBI was seeking from a small ISP as part of an NSL. Among other things, the FBI was demanding a target's complete Web browsing history, IP addresses of everyone a person has corresponded with, and records of all online purchases, according to a court documentunveiled Monday. All that's required is an agent's signature denoting that the information is relevant to an investigation.

"The FBI has interpreted its NSL authority to encompass the websites we read, the Web searches we conduct, the people we contact, and the places we go. This kind of data reveals the most intimate details of our lives, including our political activities, religious affiliations, private relationships, and even our private thoughts and beliefs," said Nicholas Merrill, who was president of Calyx Internet Access in New York when he received the NSL targeting one of his customers in 2004.

The FBI subsequently dropped demands for the information on one of Merrill's customers, but he fought the gag order in what turned out to be an 11-year legal odyssey just to expose what the FBI was seeking. He declined to reveal the FBI's target.

The NSL got a major boost in the wake of the 2001 terror attacks, as it became part of the USA Patriot Act. Between 2003 and 2005, the FBI issued 143,074 NSLs according to a Justice Department inspector general report...

http://arstechnica.com/tech-policy/2015/11/the-national-security-letter-spy-tool-has-been-uncloaked-and-its-bad/

20150914

Federal Court Invalidates 11-Year-old FBI gag order on National Security Letter recipient Nicholas Merrill

Court Rules There Is “No Good Reason” To Prohibit Merrill from Describing the Array of Private Information that the FBI Sweeps Up Using NSLs

NEW HAVEN, CT – A federal district court has ordered the FBI to lift an eleven-year- old gag order imposed on Nicholas Merrill forbidding him from speaking about a National Security Letter (“NSL”) that the FBI served on him in 2004. The ruling marks the first time that an NSL gag order has been lifted in full since the PATRIOT Act vastly expanded the scope of the FBI’s NSL authority in 2001. Mr. Merrill, the executive director of the Calyx Institute, is represented by law students and supervising attorneys of the Media Freedom and Information Access Clinic, a program of Yale Law School’s Abrams Institute for Freedom of Expression and Information Society Project.

For more than a decade, the government has refused to allow Mr. Merrill and other NSL recipients to tell the public just how broadly the FBI has interpreted its authority to surveil individuals’ digital lives in secret using NSLs. Tens of thousands of NSLs are issued by FBI officers every year without a warrant or judicial oversight of any kind.

The letters demand disclosure of user information and are almost always accompanied by complete gag orders. Today’s decision will finally allow Mr. Merrill to speak about all aspects of the NSL and, specifically, to inform the public about the categories of personal information that the FBI believes it can obtain using an NSL...

20140525

Secrets, lies and Snowden's email: why I was forced to shut down Lavabit

My legal saga started last summer with a knock at the door, behind which stood two federal agents ready to to serve me with a court order requiring the installation of surveillance equipment on my company's network.

My company, Lavabit, provided email services to 410,000 people –including Edward Snowden, according to news reports – and thrived by offering features specifically designed to protect the privacy and security of its customers. I had no choice but to consent to the installation of their device, which would hand the US government access to all of the messages – to and from all of my customers – as they travelled between their email accounts other providers on the Internet.

But that wasn't enough. The federal agents then claimed that their court order required me to surrender my company's private encryption keys, and I balked. What they said they needed were customer passwords – which were sent securely – so that they could access the plain-text versions of messages from customers using my company's encrypted storage feature. (The government would later claim they only made this demand because of my "noncompliance".)


Bothered by what the agents were saying, I informed them that I would first need to read the order they had just delivered – and then consult with an attorney. The feds seemed surprised by my hesitation...

http://www.theguardian.com/commentisfree/2014/may/20/why-did-lavabit-shut-down-snowden-email