Showing posts with label NSA. Show all posts
Showing posts with label NSA. Show all posts

June 4, 2026

New details from the Snowden files found by the Libroot collective



More than 12 years after the start of the Snowden revelations in June 2013, there are still new details to be found in the ca. 1200 highly classified documents that have been released to the public.

The latest finds are the result of mostly technical analysis conducted by a collective called Libroot. Since December last year, they are publishing the results in a series of postings on their website.




The Libroot collective

The new results from analyzing the Snowden documents are published on the website Libroot.org, which is aimed at "spying back" at the NSA under the motto "surveillance in the crosshairs".

It's not known who are behind the Libroot website but they describe themselves as "a collective focused on exposing and resisting surveillance and oppressive digital infrastructures. We create tools, research, and archives that defend digital autonomy." Libroot works on various projects, some of which are published on their website.

One of their projects is called "Going Through Snowden Documents", for which the Libroot collective "systematically reviews each available document with particular attention to small details and information that has received little or no public attention since the initial 2013 disclosures."



Going Through Snowden Documents

So far, "Going Through Snowden Documents" resulted in seven postings, which are summarized below (when new postings appear, they will be added). The titles of these summaries link to the original postings on the Libroot website. Each of these postings is very detailed and interesting, so I highly recommend reading them in full.



Part 1: CNE analysis in XKEYSCORE (December 9, 2025)

In their first posting, the Libroot collective analyzed an NSA presentation titled CNE Analysis in XKEYSCORE from 2009. This presentation was part of a large set of slide decks about the XKEYSCORE system which were published by The Intercept in July 2015 but were never analyzed individually.

Libroot looked specifically at the screenshots shown in this presentation. This revealed evidence that the NSA hacked the computer network of the Chinese company Norinco or North Industries Corporation, which is one of the world's largest state-owned defense contractors.

Other targets of NSA hacking operations were the mail servers of the Mexican federal law enforcement agencies Secretaría de Seguridad Pública (SSP) and Policía Federal Preventiva (PFP).

Yet another screenshot included in the XKS presentation shows that NSA compromised a laptop that likely belonged to someone working in Iranian transportation or customs infrastructure.

Finally, the presentation includes some codewords which were not yet included in my extensive listing of NSA Nicknames and Codewords (but have been added now):

- GREENCHAOS: A collection source feeding CNE data into XKEYSCORE?
- SHADOWQUEST: A collection source feeding CNE data into XKEYSCORE?
- TUCKER: An exploitation framework comparable to UNITEDRAKE, with sub-projects including OLYMPUS, EXPANDINGPULLY and UNIX.
- TURBOCHASER: An NSA database for profiles and future tasking, appearing alongside MARINA.
- WAYTIDE: A collection source feeding CNE data into XKEYSCORE?



Part 2: Central and South American politics (December 11, 2025)

This analysis by the Libroot collective is about two NSA presentations about operations to intercept the communications of Brazilian president Dilma Rousseff and the Mexican presidential candidate Enrique Peña Nieto.

> See also on this weblog: An NSA eavesdropping case study

One of the slides from those presentations listed "Geopolitical Trends: Key Challenges" but was almost fully redacted when it was published. Libroot, however, was able to reconstruct the full content of that slide based upon screenshots from Brazilian television.

In this posting, Libroot also provides a full transcription of a letter from the US State Department to NSA director Keith Alexander. This letter was shown shortly on Brazilian television and only a small section had been published in Glenn Greenwald's book No Place to Hide from 2014.



Part 3: Compromised telecommunications providers (December 25, 2025)

The third analysis by Libroot is about the NSA's TREASURE MAP presentation, which was published by Der Spiegel in September 2014. The TREASURE MAP tool provides "a near real-time, interactive map of the global Internet".

Besides the networks that make up the internet, TREASURE MAP also shows in which networks NSA and GCHQ have access points. Der Spiegel had already identified some satellite and internet providers that had been compromised.

By close examination, Libroot found another 20 major telecommunications providers across three continents which appeared to have been compromised. A list of those providers is in the posting on the Libroot website.



Part 4: Intelligence facilities inside the US (January 10, 2026)

Libroot also found out that in two documents from the Snowden trove some entire sections had been deleted, presumably by people from Greenwald's media outlet The Intercept. In both cases, the deleted sections were about intelligence facilities inside the US, while information about similar facilities abroad was not redacted.

The first document is apparently from the Menwith Hill Satellite Classification Guide and was published by The Intercept in September 2016. Deleted from this document was text saying that "Classic Wizard Reporting and Testing Center" is an unclassified cover name for the Potomac Mission Ground Station (PMGS). This facility is located at the Naval Research Laboratory (NRL) in Washington DC and functions as a Mission Ground Station (MGS) for NRO surveillance satellites.

The second document is titled NRO SIGINT Guide Pine Gap and was published by The Intercept in collaboration with the Australian Broadcast Corporation (ABC) in August 2017. Deleted from this document was text saying that "Aerospace Data Facility" (ADF) is the unclassified cover name of the Consolidated Denver Mission Ground Station (CDMGS). This facility is located at Buckley Space Force Base in Aurora, Colorado, which is also home to one of the NSA's regional Cryptologic Centers.

> See also on this weblog: The NSA's regional Cryptologic Centers



Part 5: Various redaction failures (January 17, 2026)

In their fifth posting, Libroot presents some additional redaction failures which they stumbled upon by conducting forensic analysis on PDF files from the Snowden trove. These failures are not very significant or spectacular, as in general the journalists redacted the files they published quite professionally.

The redaction failures include a total of some 20 usernames of NSA employees, as well as IP and email addresses of foreign targets. The NSA usernames, or Security Identifiers (SIDs), all consist of two initials followed by the first four or five letters of someone's surname. For example, Snowden's username at the NSA was "ejsnowd".

> See also on this weblog: E-mails from inside the NSA bureaucracy



Part 6: UNAMI router configurations (April 17, 2026)

This posting is about some screenshots included in an NSA presentation titled VPN SigDev Basics, which was published by Der Spiegel in December 2014. These screenshots show the interface of the NSA's DISCOROUTE program, which is a "project to acquire, parse, database and display configuration files from network devices."

In these screenshots, Libroot noticed a search for crypto keys from routers used by the United Nations Assistance Mission for Iraq (UNAMI). According to Libroot, this strongly indicates that the NSA had collected the full configuration data of at least eleven network routers used by UNAMI.



Part 7: NSA presentation containing sensitive data (May 5, 2026)

The seventh posting by Libroot is about an NSA presentation from early or mid-2012 titled What Your Mother Never Told You About SIGDEV Analysis, which was published by Der Spiegel in December 2014 as part of a long story about internet encryption.

Libroot was able to undo almost every redaction in that presentation, which revealed the full names of at least 14 NSA employees, as well as IP addresses and names of companies and organizations that had been targeted by the agency (which Libroot didn't publish).

In the same NSA presentation is a screenshot which contains another screenshot, but so tiny that it was almost invisible. When restored to its original size, it appeared to be the NSA's internal WikiInfo page about TNS (Target Network Service).

The screenshots also contain some new NSA codewords:

- BLACKBEACH: (related to BLACKPEARL?)
- BLACKSAND: (related to BLACKPEARL?)
- DARKSUNRISE: VPN exploitation tool released in Fall 2012.
- POTLUCK: (internal NSA or IC search engine?)
- SHADOWNET: Tool for exploitation of VPN communications.*
- TROPICNET: ?



On their website, Libroot writes that their examination of all the published documents leaked by Edward Snowden "will hopefully be complete and made public in mid-to-late 2026."

Libroot logo


January 17, 2025

Interesting topics from the NSA's 2009 Presidential Transition Book

(Updated: April 8, 2025)

In the period between the election and the inauguration, a new US president prepares to take over the administration and gets briefed by numerous officials and agencies, including the National Security Agency (NSA).

Here I will present some interesting topics from the extensive 2009 Presidential Transition Book (pdf), which the NSA had prepared for Barack Obama after he had been elected president on November 4, 2008.




Context

The NSA's briefing book was published in May 2017 by the National Security Archive as part of its Cyber Vault. That collection contains 42 declassified documents about cyber issues and also includes a 42-page Transition 2001 briefing (pdf) which the NSA had prepared for incoming president George W. Bush.

The 2009 Presidential Transition Book (pdf) for Obama was declassified on April 13, 2016 and has no less than 289 pages from a binder. It combines various documents and briefing materials from 2006 to 2008, some of them quite highly classified and therefore still heavily redacted.

Despite the redacted portions, the book provides a good and detailed introduction to the NSA and its activities, but with its 289 pages it sometimes goes well beyond what the president and his staff had to know, like for example the highly detailed acquisition and procurement plans of the agency. (p. 154ff)



Mission

While on its public website it was said that the NSA had just two core missions, Information Assurance and Signals Intelligence, the Presidential Transition Book add a third one:

- Signals Intelligence (SIGINT), including codebreaking,

and

- Information Assurance (IA), including codemaking,

which together enable

- Computer Network Attack (CNA), which includes offensive operations against adversaries' information systems, but this had to be done in collaboration the JFCC-NW, which eventually merged into the US Cyber Command.



Communications monitoring

Another topic that seems not necessary for the president to know is about a hardly known NSA unit called the Joint COMSEC Monitoring Activity (JCMA), which was part of the NSA's former Information Assurance (IA) directorate.

The JCMA consists of a Headquarters Operations Centers at Fort Meade and six Regional COMSEC Monitoring Centers, located at Menwith Hill Station (MHS) in the UK, NSA/CSS Europe in Stuttgart in Germany, an undisclosed location, NSA/CSS Hawaii at Camp Smith in Hawaii, and NSA/CSS Georgia at Fort Gordon in Georgia. (p. 36)

These JCMA units monitor the unclassified communications of American military and government entities to determine if critical information has been disclosed or if other vulnerabilities exist that adversaries could exploit. (p. 36)

According to the Transition Book the "Attorney General-approved procedures (and Federal law) permit monitoring with consent, and NSA/CSS ensures that personnel are notified of the possibility of monitoring and that all required consents have been obtained before such monitoring can begin." (p. 49)


Label on an Integrated Services Telephone (IST) which can be
used for both classified and unclassified phone calls
(click to enlarge)


Declassifications

The 2009 Presidential Transition Book, which was declassified in April 2016, also reveals some details that can be compared to information from the Snowden documents:

For example, the Transition Book reveals the involvement of foreign partners in the NSA's RT-RG processing and analysis system:

"The Real Time Regional Gateway (RT-RG) [...] is bringing the full Signals Intelligence analysis, processing and exploitation power of NSA/CSS to deployed U.S. and governement agencies and military forces along with our 2nd and 3rd party partners in Theater through special agreements. RT-RG provides Signals Intelligence analysts near real-time access to [redacted]." (p. 19)

As part of the Snowden revelations this aspect was reported only three years later, in May 2019, by the online outlet The Intercept.


The Transition Book also mentions the multilateral group formed by the NSA's partners in the Pacific Region called SIGINT Seniors Pacific (SSPAC):

"In addition to bilateral partnerships, NSA/CSS continues to support a limited number of multilateral relationships such as SIGINT Seniors Europe (SSEUR) and SIGINT Seniors Pacific (SSPAC)." (p. 47)

The name of this group had already been revealed a year before, in March 2015, when The New Zealand Herald released a document from the Snowden trove (although a paper from 2012 had already mentioned a "Pacific version of the Five Eyes ‘plus’ grouping").



Cyber defense

Several parts of the 2009 Presidential Transition Book are about "Defending Vital Networks", which at that time already was a high priority issue.

The NSA saw a central role for itself, because "Insights and information gained from the Signals Intelligence mission, combined with the expertise and capabilities offered by the Information Assurance mission, make NSA/CSS a key player in defending vital networks against the threats of the Internet age." (p. 30)

Accordingly, the NSA was one of over 20 federal departments involved in the Comprehensive National Cybersecurity Initiative (CNCI), or simply the "Cyber Initiative", which was established by president George W. Bush in January 2008 and was continued by president Obama.

The CNCI "seeks to address current cybersecurity threats and anticipate future threats and technologies in order to prevent, deter, and protect the U.S. Federal government (.gov) domain against cyber intrusions. The strategy includes establishing shared situational awareness across the federal government." (p. 32)

The exact way in which the NSA contributes to the CNCI is redacted, but some of its unclassified contributions are:

- "Threat analysis provides a comprehensive understanding of the intentions, capabilities, and activities of the adversary."

- "Activity analysis allows for the discovery of unknown, significant intrusion activity, in-depth analysis of known intrusion sets, and trend analysis."

- "Network analysis and cyber target development efforts monitor, characterize, and report on foreign digital networks, organizations and personas in cyberspace." (p. 32-35)


An intriguing issue is that in other NSA documents the notorious Utah Data Center is called an "Intelligence Community Comprehensive National Cybersecurity Initiative Data Center", but the Transition Book doesn't contain a single unclassified reference to what the purpose of such a CNCI data center would be (neither do the Snowden documents).

However, the Transition Book does emphasize that "All of our responsibilities under the CNCI are within our existing authorities and missions, i.e., SIGINT, Information Assurance, enabling network warfare under JFCC-NW, and providing technical assistance to other federal agencies. The vast majority of our work under the CNCI is work we are already doing under our Transformation 3.0." (p. 100)



The NSA/CSS Threat Operations Center (NTOC), ca. 2006
(photo: NSA - click to enlarge)



Transformation 3.0

The 2009 Presidential Transition Book seems to be the first document that provides an elaboration of "Transformation 3.0" or T3.0. This appears to be a strategic technology plan meant to "distribute our processing capabilities throughout the global enterprise and to unify our missions."

This had to be done by "creating a cooperative and concerted real-time exploit-attack-defend capability [redacted]. T3.0 connects analysts, missions partners, clients, sensors, systems, and information on a global scale through a robust, secure, and distributed network." (p. 60)

(Upon request of The Black Vault, an Intellipedia page about Transformation 3.0 was declassified in 2018, but again most parts have been redacted)

Transformation 3.0 comes after two earlier Transformations of the NSA, which apparently took place in the 1990s and the early 2000s:

"T1.0 - Modernization
Following the cold war, T1.0 improved corporate business processes, shaped the workforce, modernized technlogy, and updated operations - better positioning the Agency to grapple with varied threats and emerging technology."

"T2.0 - Collaboration
Following 9/11/2001, T2.0 began to move NSA/CSS from a paradigm of "need to know" to "need to share", both within NSA and with our clients and partners. T2.0 began to merge the Signals Intelligence and Information Assurance missions together as one, providing on-site support and tailored services - which enabled NSA/CSS to fashing new relationships for the new world order, redrawing distinctions between national and tactical, producer and consumer, collector and operator."

T3.0 - [redacted]
Today, NSA/CSS is focused on the [redacted]. The intention is to create cooperative, interoperable, real-time Exploitation/Defense/attack-enabling (E/D/enA) capabilities [redacted]" (p. 123)


Transformation 3.0 was comprised of three parts: "(1) Mission Modernization, (2) Infrastructure Modernization (comprising significant improvement in Power, Space and Cooling (PS&C) and Information Technology (IT) Modernization efforts, both described earlier) and (3) Workforce Modernization." (p. 125)

T3.0 is briefly mentioned in some documents from the Snowden trove as well, for example this one that says that the initiative started in 2006, which means it came shortly after Transformation 2.0 which had just been launched in 2003. See about T2.0 also this newsletter. At GCHQ there was a counterpart program called SIGINT Modernisation.

Another document leaked by Snowden says that the objective of T3.0 was nothing less than "Global Network Dominance" and that a crucial piece for that was the Remote Operations Center (ROC), which manages and operates the NSA's rapidly growing array of hacking operations.

The 2009 Presidential Transition Book also includes a copy of an internal powerpoint presentation about the Transformation 3.0 plan, which is almost completely redacted. (p. 79ff)




This briefing slide from the Transition Book repeats that an important part of T3.0 was to "create cooperative, interoperable, real-time Exploitation, Defense and attack-enabling capabilities" which reminds us of the NSA's TURBULENCE program. This program was first reported on in 2007 and was the successor of the TRAILBLAZER project.

Update:
An internal NSA newsletter from October 2006 confirms that TURBULENCE is the actual implementation of the Transformation 3.0 initiative. Something similar can be read on page 293 of the National Defense Authorization Act (pdf) for the fiscal year 2008, which added that TURBULENCE was structured as a "series of loosely connected projects, not one of which met the threshold for designation as a major systems acquisition. This decision, while permitting the NSA to avoid external acquisition oversight, exacerbated the Agency’s weaknesses in systems engineering and systems integration."


TURBULENCE (abbreviated as TU) was/is an umbrella program with at least seven components, including TURMOIL for passive collection from fiber-optic cables and TUTELAGE, which detects and blocks cyberattacks directed against the computer networks of the US Defense Department.

Even more interesting is TURBINE, which uses identifiers from TURMOIL and TUTELAGE to initiate a semi-automated process in which an implant from the NSA's Computer Network Exploitation system QUANTUM is installed on a target's computer system.

With these three components, TURBULENCE integrates all three capabilities of Transformation 3.0: TURMOIL for exploitation, TUTELAGE for defense and TURBINE for attack-enabling.


Slide about the TURBULENCE program from the Snowden files
(click to enlarge)


Research program

Another interesting chapter in the 2009 Presidential Transition Book is about the efforts of the NSA's Research Directorate (RD):

"Since 2003, the NSA Research Program has been structured around four important mission thrusts which drive our advanced research efforts.

"Owning the Net.
This denotes our goal to dominate the global computing and communications network. Research will develop tools and techniques to access, at will, any networked device for offensive or defensive purposes."

"Coping with Information Overload.
We must turn the massive amount of information on the global network into a strategic asset, rather than an obstacle. Under this thrust, Research will develop capabilities to present the most valuable information, organized to make sense to analysts so that thy can perform their tasks in a more efficient and effective manner."

"Ubiquitous, Secure Collaboration.
The focus here is to provide the techniques and technology to allow diverse users - within the government and with our industrial and international partners - to work collaboratively and securely across multiple domains and different environments."

"Penetrate Hard Targets.
Penetrating hard targets provides the technological solutions to enable new access, collection and exploitation methodologies against the nation's toughest intelligence targets. The research Directorate provides foundational and advanced mathematics that contribute innovative solutions to all of the above mission thrusts." (p. 69)


The NSA's Research and Engineering (R&E) Building at Fort Meade
(click to enlarge)


NSA workforce

The exact number of people working at US intelligence agencies was always classified, but surprisingly, the 2009 Presidential Transition Book provides some very detailed figures.

It says that, probably in 2008, NSA/CSS employed 36,371 people worldwide, with 52% of them civilians (18,849) and 48% military and civilians from the armed services (17,522).

68.8% of the NSA's civilian workforce had a bachelor's degree or higher, 40.7% were women, 17.7% members of a minority and 3.8% were persons with disabilities. The average age of the civilian workforce was 43.6 years. (p. 58-59)

A separate chapter titled "NSA/CSS Footprint" provides detailed information charts about the NSA's four regional Cryptologic Centers, including the names of their commanders, partial organizational charts and numbers about their workforce, with actual numbers for 2008 and projected numbers for 2012 and 2015. Below are the actual numbers for 2008: (p. 185ff)

- NSA/CSS Georgia (codename SWEET TEA):
2930 employees: 368 civilians, 42 service civilians, 2173 military, 347 other (foreign or IC partner, contractor)

- NSA/CSS Hawaii:
3054 employees: 224 civilians, 121 service civilians, 2582 military, 127 others

- NSA/CSS Texas (codename BACONRIDGE):
2136 employees: 246 civilians, 56 service civilians, 1689 military, 145 other.

- NSA/CSS Colorado:
1324 employees: 233 civilians, 4 service civilians, 976 military, 115 contractors.


Finally, the 2009 Presidential Transition Book ends with the biographies of over 30(!) top officials of the NSA, all of which have been fully redacted, except for those of the director (Keith B. Alexander), the deputy director (John C. Inglis) and the chief of staff (Deborah A. Bonanni). (p. 243ff)





October 6, 2023

The NSA's new organizational designators

(Updated: September 20, 2025)

For decades, the organizational structure of the NSA was classified, but since 2013 the Snowden documents provided hundreds of designators of internal divisions, branches and units, which allowed me to reconstruct the agency's internal structure.

From 2016 to 2017, the NSA was reorganized so that many of those designators may have changed. Some recent documents, however, provide designators from the current situation, which allows to start a reconstruction of the new structure as well.


The Integrated Cyber Center (ICC) and other new buildings at the NSA's East Campus
(photo: Brendan Smialowski/Getty Images)



The reorganization of 2016

The organizational structure of the NSA as it emerged from the Snowden documents was established in the year 2000 under director Michael Hayden. In 2016, director Michael Rogers initiated a full reorganization under the name NSA21, in order to prepare the agency for the cyber challenges of the 21st century.

One of the most important (and controversial) changes was fusing the operational elements of the Signals Intelligence (SID) and Information Assurance (IAD) directorates into the new Directorate of Operations. The remaining information assurance activities were merged with the old Technology Directorate into the new Capabilities Directorate.

The hacking group Tailored Access Operations (TAO) was renamed into Computer Network Operations (CNO). The new structure as envisioned by NSA21 reached full operational capability in December 2017.


The new structure of the NSA as established by the NSA21 reorganization
(source: NSA - click to enlarge)


On October 1, 2019, an additional Cybersecurity Directorate (CSD) was established to unify the NSA's foreign intelligence and cyber defense missions and to prevent and eradicate threats to National Security Systems (NSS) and the Defense Industrial Base (DIB). The CSD pulled its workforce from several directorates, including the Operations Directorate and its Computer Network Operations group.



The new organizational structure

A number of new designators from the NSA's current structure can be found in the extensive NSA/CSS Policy 12-3 Annex C from June 2023. Some other documents and press reports provide additional information, which results in the partial chart below.

Update: The NSA/CSS Civil Liberties and Privacy Program from November 2021 provides the internal top-level designators for all the agency's current directorates. The organization chart and the remarks below have been updated accordingly:


A: Workforce Support Activities (WSA)

A1: ?

A2: National Cryptologic School (NCS)


B: Business Management and Acquisition (BM&A)


C: Cybersecurity Directorate (CSD)

C5: Cybersecurity Collaboration Center (CCC) *

C5.: Artificial Intelligence Security Center (AISC)


D: Office of the Director

DC: NSA/CSS Chief of Staff (CoS)
...
D2: Office of General Counsel (OGC)
...
D5: Civil Liberties, Privacy, and Transparancy (CLPT)

D6: Diversity, Equality, and Inclusion (DEI)
...
D9: Risk Management Office (RMO)


I: Office of the Inspector General (OIG)


P: Engagement and Policy (E&P)

P1: ?
P12: Office of Policy

P13: ?
P131: Information Security/Classification *
...
P6: Mission Engagement & Assessments (MERA)
P615: IBSSO Watch

P7: Office of Compliance/Compliance Group

P75: Office of Compliance for Cybersecurity and Operations


R: Research Directorate


X: Operations Directorate

X3: Information and Intelligence Analysis (IIA)

X30: ?
X303: Defense Special Missile & Aerospace Center (DEFSMAC)

X31: Eurasia & Western Hemisphere (EWH)
X311: Russia division
      X3112: Military force projection
         X31122: Strategic Forces
            X311223: Strategic Navy
               X3112231: Watch ops

X32: East Asia & Pacific (EAP)

X33: Near East, South & Central Asia and Africa (NESCAA)

X34: Counterterrorism (CT)

X35: Counter-intelligence & Cyber (CIC)

X36: Global Issues (GI)

X4: Collection, Exploitation and Cryptoanalysis Operations

X40: ?

X41: ?

X42: Sensor and Data Operations (SDO)
X42?: High Capacity Sensor Operations (HCSO)
X42?: Tailored Sensor Operations (TSO)
X42?: MUSKETEER
X42?: MINUTEMAN

X43: Computer Network Operations (CNO)

X44: Cryptoanalysis and Signals Analysis (CASA)

X??: Access Discovery and Analysis
X???: Radio Frequency Analysis Center (RFAC)
X???: FORNSAT Discovery and Development (FDD)
X???: Unidentified Signals and Support Branch

X??: Digital Communications Analysis and Techniques
X???: Advanced Protocol Analysis
X???: Cyber Discovery
X???: DRAGON RF Exploitation
X???: High Capacity Discovery and Analysis


Y: Capabilities Directorate
    - Chief Information Officer (CIO)

Y1: ?
Y1D: Collection and CNO Capabilities
Y1D5: Orchestration Solutions (OS)
      Y1D511: CNO Infrastructure Operations Center
      Y1D515: CNO Security Operation Center
         Y1D5313: Defense Platform Solutions

Y2: ?

Y3: ?

Y4: ?
Y4D: Enterprise Infrastructure Services
Y4D1: User Facing services
   Y4D12: Directory service
      Y4D121: Active directory
      Y4D122: Enterprise Defense services
   Y4D14: Desktop services
      Y4D142: Deployment services

Y4D2: Network services
   Y4D23: Special Expeditionary IT
      Y4D231: OCO Communication support service
      Y4D232: Tactical services
   Y4D24: ?
      Y4D242: IC Legacy Messaging Desk

Y4D3: ?

Y4D4: Data Center services
   Y4D43: System management services

Y4D5: Operations Support
   Y4D54: Capabilities Service Center Global Event Manager





Some additional remarks (updated)

If we compare these current designators with the structure before 2016, we see that:

- The Office of the Director is still designated as "D" and may not have changed much, except for the Office of the Inspector General, which now has its own top-level designator (I), and at least two parts (the Office of Policy and the information security units) which have been transferred to the newly created Engagement & Policy Directorate (P).

- For the Inspector General (IG) this reflects that since the FY2014 Intelligence Authorization Act this official is appointed by the President and confirmed by the Senate. Previously, the IG was appointed by the Director of the NSA, who could also remove him. The first presidentially appointed NSA IG was Rob Storch, who served from 2018 to 2022.

- The position of the Chief Information Officer (CIO) is different: in 2020, the IG criticised that the CIO wasn't included in the organization charts of the agency and primarily served as head of one of the NSA's directorates, first Technology and now Capabilities.

- Other new directorates also got a top-level designator that wasn't used before 2016: Workforce Support Activities (A), Business Management and Acquisition (B), Cybersecurity (C) and Capabilities (Y). The Research Directorate however kept the letter R.

- The new Operations Directorate is designated by the letter X, which was already used under the old structure, although we don't know for what kind of activity. Maybe the previous X division was just temporary or very small as the only source that mentions it is a document about cable installations at NSA headquarters from 2007.


> See also: The NSA's regional Cryptologic Centers




Links
- NextGov: A leadership vacuum and staff cuts threaten NSA morale, operational strength (November 4, 2025)

June 6, 2023

On the 10th anniversary of the Snowden revelations

(Updated: April 7, 2025)

To mark the 10-year anniversary of the start of the Snowden revelations I will look back at some of the most notable disclosures and how they developed, based upon the most recent books and the numerous blog posts I have written here. Still, it should be noted that this overview is not a complete coverage of this wide-ranging topic.







Books and archives

Between June 2013 and May 2019, the Snowden revelations resulted in over 200 press reports and more than 1200 classified documents published in full or in part. Additionally, The Intercept published 2148 editions of the NSA's internal newsletter SIDtoday. In total, that may be well over 5000 pages.

A collection that allows a useful visual recognition of the documents was found on the private website IC Off the Record, while text searches are possible at the Snowden Archive which is a collaboration between Canadian Journalists for Free Expression (CJFE) and the University of Toronto. A private collection of the documents is also available at GitHub.

Update: The Snowden documents are also available on the website of the Dutch transparancy organization Buro Jansen & Janssen: as a list of NSA files and with a search interface.

There are also at least 12 books about the Snowden revelations. Glenn Greenwald's No Place To Hide from 2014 reads like a pamphlet against perceived mass surveillance. A much more factual overview can be found in Der NSA Komplex, which is also published in 2014 and written by two journalists from Der Spiegel, but unfortunately only available in German.

Detailed insights into the political and legal background of the NSA's collection programs are provided in Timothy Edgar's Beyond Snowden from 2017, which is in contrast to Snowden's own memoir Permanent Record from 2019, which leaves more questions than answers.

Finally, there's also the long-awaited book Dark Mirror by Washington Post journalist Barton Gellman, which was published in 2020 and offers some important new angles to the initial stories told by Snowden and Greenwald.

> See also my review of Permanent Record: Part I: at the CIA - Part II: at the NSA





Incentives

Some people assume that Snowden is a spy who worked for Russian intelligence, but nowadays, requests for information come from transparency activists as well. Wikileaks' wiki-page titled The Most Wanted Leaks of 2009 may have inspired Manning to search for information on SIPRNet and to download hundreds of thousands of military and diplomatic reports.

Likewise, the incentive for Snowden may have come from the news program Democracy Now!, in which on April 20, 2012, former NSA crypto-mathematician Bill Binney, documentary filmmaker Laura Poitras and hacktivist Jacob Appelbaum were interviewed by Amy Goodman (a full transcript can be found here).

In the program, Binney claimed that after 9/11 "all the wraps came off for NSA, and they decided to eliminate the protections on U.S. citizens and collect on domestically".

Appelbaum repeated what he said at the HOPE conference in 2010: "I feel that people like Bill need to come forward to talk about what the U.S. government is doing, so that we can make informed choices as a democracy" - which is exactly what Snowden would do: leaking documents because "the public needs to decide whether these programs and policies are right or wrong."

Later that day, Binney and Appelbaum spoke at a "Surveillance Teach-In" in the Whitney Museum, where Appelbaum emphasized that disclosing secret information is also important for privacy and civil liberties organizations: because of a lack of hard evidence and concrete harm it was almost impossible for them to fight NSA surveillance in court.



Binney and Appelbaum at the Surveillance Teach-In on April 20, 2012


Whistleblowing?

Just a month earlier, Snowden had started a new job as a SharePoint systems administrator at the NSA's regional cryptologic center in the Kunia Tunnel complex in Hawaii. There, he began automating his tasks to free up time for something more interesting, which he describes in Permanent Record:

"I want to emphasize this: my active searching out of NSA abuses began not with the copying of documents, but with the reading of them. My initial intention was just to confirm the suspicions that I'd first had back in 2009 in Tokyo. Three years later I was determined to find out if an American system of mass surveillance existed and, if it did, how it functioned." *

With this, Snowden basically admits that he isn't a whistleblower: he wasn't confronted with illegal activities or significant abuses and subsequently secured evidence of that, but acted the other way around, by first gathering as much information he could get and then look whether there was something incriminating in it.

In his memoir, Snowden doesn't come up with concrete misconducts or other things that could have triggered his decision to hand the files over to journalists. He even omits almost all the disclosures made by the press, which makes that Permanent Record contains hardly anything that justifies his unprecedented data theft.



The tunnel entrance to the former Kunia Regional Security Operations Center
in Hawaii, where Snowden worked from March 2012 to March 2013
(photo: NSA - click to enlarge)



The documents

The actual number of documents which Snowden eventually exfiltrated from the NSA has never been clarified. According to the 2016 report from the US House Intelligence Committee, Snowden removed more than 1.5 million documents from NSANet and the JWICS intelligence network.

Glenn Greenwald repeatedly said that number was "pure fabrication" and he could probably agree with former NSA director Keith Alexander who in November 2013 estimated that Snowden had exposed only between 50,000 and 200,000 documents.*

According to Barton Gellman, Snowden provided him and Laura Poitras with an encrypted archive of documents called "Pandora" on May 21, 2013. This archive was 8 gigabytes and contained over 50,000 separate documents, all neatly organized in folders.*

Poitras gave Greenwald a copy of the Pandora archive just before they boarded their flight to Hong Kong on June 1. There, Snowden gave Ewen MacAskill from The Guardian some 50,000 documents about GCHQ and handed over all the remaining files to Greenwald and Poitras, who are the only ones with a complete set. Other media outlets only got partial sets of documents.

Greenwald's cache eventually ended up at The Intercept, the online news outlet he co-founded with Jeremy Scahill and Laura Poitras in 2014 to report about the Snowden documents. In March 2019, however, The Intercept closed its Snowden archive and reportedly destroyed it.




Screenshot from a Brazilian television report, showing some of the Snowden files
opened in a TrueCrypt window on the laptop of Glenn Greenwald.
(screenshot by koenrh - click to enlarge)



Non-Snowden leaks

In a message to Gellman, Snowden said that "he was not resigned to life in prison or worse. He wanted to show other whistleblowers that there could be a happy ending".* Later, whistleblower attorney Jesselyn Radack hoped that "courage is contagious, and we see more and more people from the NSA coming through our door after Snowden made these revelations."

And indeed, other sources started to leak documents to the press. The first one was a so-called tasking record showing that the NSA had targeted the non-secure cell phone of German chancellor Angela Merkel. This was revealed by Der Spiegel on October 23, 2013, which is less than five months after the start of Snowden's revelations.


The second leaked document that wasn't attributed to Snowden was just as spectacular: the ANT product catalog with a range of sophisticated spying gadgets from the NSA's hacking division TAO. This catalog was also published by Der Spiegel and discussed by Jacob Appelbaum during the CCC on December 30, 2013.

Initially, hardly anyone noticed that these documents didn't come from Snowden, and so a mysterious "second source" was able to publish files that were sometimes even more embarrassing and damaging than those from the Snowden trove, like intercepted conversations from foreign government leaders.

Later, other piggybackers who called themselves The Shadow Brokers leaked highly sensitive information about NSA hacking tools. The sources of these leaks have never been identified, although it's often assumed that Russian intelligence was behind it. Snowden never addressed these other leaks, nor distanced himself from them.




NSA report about an intercepted conversation of French president Hollande.
Leaked by an unknown source and published by Wikileaks in 2015
(click to enlarge)



The Section 215 program

The very first disclosure of a document that did come from Snowden was the Verizon order of the Foreign Intelligence Surveillance Court (FISC). This court convenes behind closed doors and is often, but injustly referred to as a "rubber stamp". The order was published by The Guardian on June 6, 2013.

The Verizon order showed that the NSA was collecting domestic telephone metadata under the so-called Section 215 program. In the US, this became the most controversial issue and initially it seemed to confirm cryptic public warnings by US senators Ron Wyden and Mark Udall, as well as the aforementioned claims by Bill Binney about domestic mass surveillance.

In reaction, Director of National Intelligence (DNI) James Clapper started an unprecedented declassification effort and released numerous FISC and NSA documents about the Section 215 program on a newly created Tumblr site called IC On the Record.


Misunderstanding

This was meant to clarify a central misunderstanding: the fact that the NSA collects data inside the US doesn't mean they are spying on Americans. The NSA is still focused on foreign targets, but because they are using American internet services, it proved to be fruitful to intercept their data not only abroad, but at telecoms and internet companies inside the US as well (the "home field advantage").

Accordingly, the purpose of the Section 215 program was to find out whether foreign terrorists were in contact with unknown conspirators inside the US, which was one of the failures that could have prevented the attacks of 9/11.

Therefore, the only thing the domestic telephone records were used for was simple contact chaining: NSA started with a phone number of a foreign terrorist and then the MAINWAY system presented the (foreign and domestic) phone numbers with which that initial number had been in contact with, as well as the numbers they, in their turn had been in contact with, the so-called "second hop":



In 2012, the NSA used 288 phone numbers as a "seed" for such a contact chaining query, resulting in 6000 phone numbers that analysts actually looked at. When this led to a suspicious American phone number, the NSA passed it on to the FBI for further investigation.

This true purpose of the domestic metadata collection was clearly laid out in a public report which the independent Privacy and Civil Liberties Oversight Board (PCLOB) published in January 2014. The PCLOB found "no instance in which the program directly contributed to the discovery of a previously unknown terrorist plot", but Section 215 was of some value as it offered additional leads and could show that foreign terrorist plots had no US nexus.

Although these domestic telephone records were not used to spy on Americans, and the FISC limited their retention to 5 years and prohibited the collection of location data, many people would not like to have them in an NSA database because of what Binney and Snowden called the possibility of a "turnkey tyranny".*

The publication of the Verizon order did not only make the general public aware of the Section 215 program, but also gave civil liberty organizations standing in court, which fulfilled Jacob Appelbaum's wish from the 2012 Surveillance Teach-In.

Meanwhile there have been two cases in which a Circuit Court of Appeals ruled about the Section 215 program. They both found that the bulk collection of metadata exceeded the scope of Section 215 of the Patriot Act (because the actual practice hadn't been foreseen by lawmakers, although they had been briefed about it later). The courts didn't decide on whether the program was constitutional or not.




The first page of the Verizon order from April 25, 2013
(click for the full document)



The PRISM program

One day after the publication of the Verizon order, The Guardian and The Washington Post revealed the PRISM program, which became synonymous for an all encompassing NSA spying system, just like ECHELON was before.

In his book Dark Mirror, Barton Gellman tells a different story than Greenwald did in No Place to Hide. Greenwald presented himself as the one who was chosen by Snowden to lead the revelations and claimed that he and Laura Poitras were working with Snowden since February 2013, while Gellman only got "some documents" and that Snowden was angry about the fear-driven approach of The Washington Post.*

According to Gellman, the opposite was the case: on January 31, 2013, Laura Poitras already asked him for advice and on May 7, they agreed to work together. She introduced Gellman to her source, who still called himself Verax, and they started encrypted chat conversations. On May 20, Snowden sent them the full PRISM presentation, after which they signed a contract with The Washington Post on May 24.*

But Snowden was under severe time pressure and urged Gellman to rapidly publish the full PRISM presentation, which he had signed with a digital signature associated with his Verax alter ego. Only gradually did Gellman realize the implications of this. Snowden's plan was to ask political asylum at a foreign diplomatic mission in Hong Kong, where he wanted to use the cryptographic signature to identify himself as the source of the PRISM document (and didn't rule out to "provide raw source material to a foreign government").*

As a journalist, Gellman protected the identity of his source, but publishing the digitally signed PRISM presentation would make him and The Washington Post complicit in Snowden's flight from American law. After consulting Poitras, Gellman decided not to do so. On May 27, Snowden withdrew the exclusive right for the Washington Post and turned to Greenwald, who until that moment didn't know who Snowden was, nor had seen any of the documents.*




When Greenwald finally managed to get PGP working, Snowden sent him a zip-file with some 25 documents, including the 41-slide PRISM presentation. Greenwald started writing his own story about PRISM, which was published by The Guardian on June 6, 2013.* Just one hour earlier, The Washington Post had released its own PRISM story.

The most controversial part of these stories was the claim that "the National Security Agency has obtained direct access to the systems of Google, Facebook, Apple and other US internet giants", which those companies vigorously denied.

That "direct access" was taken from one of the slides, but it's unclear why both Gellman and Greenwald stuck to the most simple interpretation of it. Fact is that they had access to the extensive accompanying speaker's notes, which clearly said: "PRISM access is 100% dependent on ISP provisioning".*

They also had all the other PRISM slides, including two that were published later on, which also show that the FBI is in between the NSA and the internet companies:

PRISM-slide published by Le Monde on October 22, 2013


In July 2014, the Privacy and Civil Liberties Oversight Board (PCLOB) published an extensive public report about PRISM as well, which confirms that individual selectors (like a target's e-mail address) are sent to internet companies, which are "compelled to give the communications sent to or from that selector to the government." According to the report, PRISM "has proven valuable in the government’s efforts to combat terrorism as well as in other areas of foreign intelligence."


In Dark Mirror, Gellman admits: "In retrospect, I do not love the way I wrote the [PRISM] story. I knew a lot less then than I learned later, with more time in the documents and many more interviews". A well-informed source told him that the systems of a company like Facebook are too complex to let the NSA plug in a cable. Only Facebook knows how to pull things out, which they can then hand over upon a valid request.* Google did that through secure FTP transfers and in person.

Another interesting addition provided by Gellman is about the date of the PRISM presentation, April 2013, which is less than one and a half months before Snowden left the NSA:

"Nothing Snowden had seen until now better suited his plan. He had been talking to Poitras for three months, but he still did not feel confident that his disclosures would seize attention from a public that had seldom responded strongly to privacy warnings. Most of the NSA programs that worried him were legally and technically intricate, not easy to explain. He needed examples that ordinary people would recognize. Along came [the PRISM] presentation, festooned at the top of every slide with iconic logos from the best-known Internet companies in the world. "PRISM hits close to people's hearts", he told me."*



Overcollection

While PRISM is no mass surveillance, but targeted collection against individual foreign targets, it still has a problematic aspect: overcollection. Snowden was eager to draw public attention to this issue and, according to Greenwald, took his last job at NSA Hawaii only in order to get access to the NSA's raw data repositories.* Snowden declined to repeat or explain that to Gellman though.*

He succeeded and was able to exfiltrate a cache of ca. 22,000 collection reports, containing 160,000 individual conversations (75% of which instant messages), which the NSA collected via the PRISM program between 2009 and 2012.*

Snowden handed them over to Barton Gellman who reported about these files in July 2014. Researchers at The Washington Post found that the intercepted communications contained valuable foreign intelligence information, but also that over 9 out of 10 accountholders were not the intended surveillance targets and that nearly half of the files contained US person identifiers.

It's probably technically impossible to prevent such overcollection, but instead of deleting irrelevant personal content, the NSA only "minimizes" it, which means that names of Americans are redacted before they are distributed. Gellman saw that NSA personnel takes these procedures seriously, but when he confronted former NSA deputy director Rick Ledgett with his unease, Ledgett's only reply was that the NSA really doesn't care about ordinary people.*




The Mission List

Ledgett's answer is confirmed by a comprehensive listing of the tasks of the NSA in the Strategic Mission List from January 2007. It was published by The New York Times in November 2013, but got hardly any attention, despite the fact that it clearly contradicts the claims by Snowden and Greenwald that the NSA has just one single goal: collect all digital communications from all over the world.

Equally less traction gained reports by Ewen MacAskill from The Guardian and Scott Shane from The New York Times, who tried to provide balance and nuance by showing that NSA and GCHQ also did many good things, like monitoring terrorists, the Taliban, hostage takers, human traffickers, and drug cartels.

The Mission List says that China, North-Korea, Iraq, Iran, Russia and Venezuela were "Enduring Targets", which means they are of long-term strategic importance and therefore require a holistic approach. Next there were 16 "Topical Missions", which are subject to some change, but can be considered legitimate targets for any large intelligence agency:

- Winning the Global War on Terrorism (GWOT)
- Protecting the US homeland
- Combating proliferation of Weapons of Mass Destruction (WMD)
- Protecting US military forces deployed overseas
- Providing warning of impending state instability
- Providing warning of a strategic nuclear missile attack
- Monitoring regional tensions that could escalate
- Preventing an attack on US critical information systems
- Early detection of critical foreign military developments
- Preventing technological surprise
- Ensuring diplomatic advantage for the US
- Ensuring a steady and reliable energy supply for the US
- Countering foreign intelligence threats
- Countering narcotics and transnational criminal networks
- Mapping foreign military and civil communications infrastructure

In 2013, terrorism was replaced by cyber attacks as top threat to American national security. Since then, cyber threats are increasing in frequency, scale, sophistication and severity of impact.



Screenshot of the BOUNDLESSINFORMANT tool showing where the NSA collected most data



Spying among friends

For its mission of "Ensuring Diplomatic Advantage for the U.S.", the NSA intercepts the communications of numerous foreign governments and government leaders. Based upon documents from the Snowden trove, media reported about eavesdropping operations against the Mexican candidate for the presidency, Enrique Peña Nieto, Brazilian president Dilma Rousseff, the Venezuelan oil company PdVSA and many others.


The NSA's interest in Germany's chancellor Angela Merkel had the most far-reaching consequences. Merkel herself made clear to president Obama that "spying on friends is not acceptable" (Ausspähen unter Freunden, das geht gar nicht) and the German parliament started an official investigation into the spying activities of the NSA (NSA-Untersuchungsausschuss or #NSAUA). This inquiry lasted from March 2014 to June 2017, but soon shifted its focus to Germany's own foreign intelligence agency BND.

Extensive hearings of BND employees resulted in unprecedented insights into the details of the cable tapping and satellite interception operations which the BND conducted in cooperation with the NSA. Eventually it became clear that the NSA wasn't spying on German citizens, but did try to collect communications from European governments and companies of interest - just like the BND itself, which was also targeting American and French foreign ministers, the interior departments of EU member states, and many others.



German chancellor Angela Merkel holding a secure BlackBerry Z10 in 2013
(photo: Nicki Demarco/The Fold/The Washington Post)



Backdoor tapping Google

A disclosure that caused outrage in Silicon Valley was about MUSCULAR, a collection program in which the NSA cooperates with its British counterpart GCHQ. In October 2013, The Washington Post reported that under this program, the NSA had secretly broken into the main communications links between Yahoo and Google data centers around the world.

A big question was: why would the NSA do that, given that they already had "front door" access to Google and Yahoo via the PRISM program? Gellman asked Snowden, who didn't come much further than "Because it could" and: "I'm speculating, but NSA doesn't ignore low-hanging fruit". Eventually Gellman realized that inside the US, the NSA had to specify individual targets, but abroad it was possible to acquire such data in bulk and to search and analyse it with XKEYSCORE.*

The Post didn't mention the XKEYSCORE system by name and it's also not explained in Gellman's book Dark Mirror. That's unfortunate, because while Greenwald and Snowden presented XKEYSCORE as a global mass surveillance tool, it's actually a smart system to find targets who are communicating anonymously and therefore cannot be traced in the traditional way, via identifiers like phone numbers and e-mail addresses.

It seems that hardly anyone realized that the disclosure of XKEYSCORE must have been really damaging for the NSA. In the 1990s, ECHELON made clear that the agency targeted phone numbers, so terrorists and other adversaries began avoiding individual identifiers and switched to anonymous ways to communicate. It must have been an eye-opener that with XKEYSCORE, the NSA found a way to trace those as well.

> More about XKEYSCORE


NSA slide showing where to intercept data from the Google cloud



BOUNDLESSINFORMANT

Where Section 215 was most controversial in the United States, but lesser-known in Europe, the opposite was the case with BOUNDLESSINFORMANT, which caused fury in Europe, but is hardly known across the ocean. BOUNDLESSINFORMANT isn't a system to collect data, but an internal visualization tool that counts metadata records to provide insights into the NSA's worldwide data collection.

The results are shown in heat maps and charts, like for individual countries and collection programs. Such charts for Germany and a few other countries were published on July 29, 2013 by Der Spiegel, but on August 5, the German foreign intelligence agency BND said that they collected these data during military operations abroad and subsequently shared them with the NSA.

Despite this statement, Glenn Greenwald interpreted these charts as evidence of American mass surveillance on European citizens and started publishing them in major European newspapers.



BOUNDLESSINFORMANT chart showing the numbers of
metadata which German BND shared with the NSA


On October 21, for example, the French paper Le Monde published a story saying that "telephone communications of French citizens are intercepted on a massive scale." After a similar story appeared in Spain, NSA director Keith Alexander came with a remarkable clarification, saying: "This is not information that we collected on European citizens. It represents information that we and our NATO allies have collected in defense of our countries and in support of military operations."

Greenwald continued his framing in Norwegian and Italian papers. Only in The Netherlands it was found out that the BOUNDLESSINFORMANT charts were not about content, but about metadata. Dutch interior minister Ronald Plasterk, however, still followed Greenwald's interpretation and assumed the Americans were spying on Dutch citizens. A court case forced the government to admit that Dutch military intelligence had collected the data during operations abroad.


Correction

It was only in May 2019 that The Intercept put the pieces together and set the record straight: the various BOUNDLESSINFORMANT charts showed cellphone metadata that had been collected by members of the Afghanistan SIGINT Coalition (AFSC, also known as the 9 Eyes) and fed them into the NSA's Real-Time Regional Gateway (RT-RG) big data analysis platform.

When The Intercept confronted Greenwald with this new research, he still tried to blame the NSA: "At the time, Der Spiegel had already reported this interpretation, the NSA wouldn’t answer our questions, and they wouldn’t give us any additional information. I am totally in favor of correcting the record if the reporting was inaccurate."

While Greenwald ignored the declaration by general Alexander, he was right when he said that the NSA's internal documentation about BOUNDLESSINFORMANT was somewhat confusing. Apparently, Greenwald had to rely on that documentation because Snowden was of little help, just like he was for various other programs that journalists did not fully understand.




Slide showing all the collection systems that fed the RT-RG platform
(click to enlarge)



Truth

Many of the documents that Snowden provided to the press have been misinterpreted or exaggerated, sometimes unintentional, but in other cases maybe deliberately. In Dark Mirror, Barton Gellman writes:

"There were signs that Snowden was capable of an instrumental approach to truth. In conversations about my work, when I got stuck on a hard reporting problem, he sometimes suggested that I provoke fresh disclosures from government officials by pretending to know more than I did."

"Another time he went further, proposing that I actually publish informed speculation as fact. If my story outran the evidence, he said, the government would be forced to respond and thereby reveal more. There would be a net gain for public information either way."

"He said misinformation from people like Mike Hayden, supporters of the intelligence establishment, pushed the terms of debate so far off center that only rhetorical counterforce could set the record straight."*

Gellman declined this approach because it would make his reporting unreliable and it undermines confidence in the press if it would turn out that certain things weren't true. However, claims made by Greenwald and Snowden himself showed that his "counterforce" method sometimes did work: the government came up with new facts - but those never got the same attention as the original story, which was already stuck in people's minds.



Conclusion

There's no doubt that the Snowden revelations provided unprecedented insight into modern-day signals intelligence as conducted by the NSA and its Five Eyes partners.

In part this was much needed to understand how the legal framework is implemented and where safeguards need improvement. That, however, requires a close examination of the documents, which shows the problems are smaller and more complex than the mythical "global mass surveillance" which Snowden and Greenwald tried to proof.

On the other hand, many things have been published that were merely sensational and weakened the US and its signals intelligence system. By revealing its workings and capacity, the Snowden revelations unintentionally set a new standard which other countries hurried to catch up with.



Links

- Der Spiegel: Das Internet ist heute anders unsicher (June 9, 2023)
- The Atlantic: Did the Snowden Revelations Change Anything? (June 7, 2023)
- The Guardian: Snowden, MI5 and me: how the leak of the century came to be published (June 7, 2023)
- The Guardian: What’s really changed 10 years after the Snowden revelations? (June 7, 2023)
- Schneier on Security: Snowden Ten Years Later (June 6, 2023)
- System Update: SNOWDEN REVELATIONS 10-Year Anniversary: Glenn Greenwald Speaks with Snowden & Laura Poitras on the Past, Present, & Future of Their Historic Reporting (June 6, 2023)
- neues deutschland: 10 Jahre Snowden-Leaks: Enthüllungen nicht mehr erwünscht (June 6, 2023)
- neues deutschland: Snowden-Leaks: Geheimdokumente belegen globale Massenüberwachung (June 6, 2023)
- Heise: Edward Snowden: Die Enthüllungen des NSA-Whistleblowers 10 Jahre später (June 5, 2023)
- Der Tagesspiegel: Edward Snowden und die Whistleblower-Frage Feiert die Verräter! (June 2023)
- Netkwesties: Barton Gellman herziet NSA-onthullingen (Dec. 7, 2020)
- See also: Timeline of Edward Snowden

- Documentary: Edward Snowden: Whistleblower or Spy?


Comments at Hacker News
Some older articles on this weblog that are of current interest:
In Dutch: Volg de actuele ontwikkelingen rond de Wet op de inlichtingen- en veiligheidsdiensten via het Dossier herziening Wiv 2017