May 24, 2014

NSA's largest cable tapping program: DANCINGOASIS

(Updated: February 18, 2025)

On May 13, Glenn Greenwald published his book 'No Place To Hide' about the Snowden-disclosures. It doesn't contain substantial new revelations, but from one of the original documents in it we can determine that NSA's largest cable tapping program is codenamed DANCINGOASIS, something which was not reported on earlier.

Here we will combine information from a number of other documents and sources to create a somewhat more complete picture of the DANCINGOASIS program.


Special Source Operations

In Greenwald's book and on his website, the following chart from NSA's BOUNDLESSINFORMANT tool was published. Although these charts are not always easy to interpret, we can rather safely assume that this one gives the overview for NSA's Special Source Operations (SSO) division, which is responsible for collecting data from major telephony and internet cables and switches.

During the one month period between December 10, 2012 and January 8, 2013, a total of more than 160 billion metadata records were counted, divided into 93 billion DNI (internet) data and 67 billion DNR (telephony) data:




In the "Most Volume" section we see that the program which collects most data is identified by the SIGINT Activity Designator (SIGAD) US-3171, a facility that is also known under the codename DANCINGOASIS, which is sometimes abbreviated as DGO. Its Producer Designator Digraph (PDDG) is T8.*

During the one month period covered by the chart, this program collected 57.7 billion data records, which is more than twice as much as the program that is second: US-3180, which is codenamed SPINNERET. Third is US-3145 or MOONLIGHTPATH and fourth DS-300 or INCENSER. This chart will be analysed in general in a separate article.



Numbers

Previously it seemed that it was INCENSER that collected the biggest number of data. A BOUNDLESSINFORMANT chart published in November 2013 said that this program gathered some 14 billion metadata a month. Now we know that DANCINGOASIS is collecting almost 4 times as much: more than 57 billion records each month, or 684 billion every year.

Comparing some numbers learns us that DANCINGOASIS (57 bln.) accounts for more than a third of everything the SSO division collects (160 bln.). It is also far more than what is collected under FAIRVIEW (6 bln.), which is one of the big domestic cable tapping programs that NSA operates in cooperation with US telecom providers.

Comparing DANCINGOASIS with the total number of data that is collected worldwide during one month early 2013 (221 bln.), as presented in the BOUNDLESSINFORMANT heat map, we see that DANCINGOASIS alone seems to account for almost a quarter of the entire NSA data collection.





Given this large share, it could be that DANCINGOASIS is an umbrella program which encompasses various smaller sub-programs. However, DANCINGOASIS is different from MYSTIC, which is an umbrella program containing facilities that monitor at least five entire countries, as was revealed recently by The Intercept. The part of MYSTIC that stores all phone calls of two countries, codenamed SOMALGET, processes only about 3 billion telephony metadata every month.



Whereabouts

Strangely enough we haven't (yet) read about DANCINGOASIS in media reports, nor in the book of Glenn Greenwald, and also we haven't seen any slides or documents that specifically deal with this program.
Update:
On July 9, 2014, Glenn Greenwald indicated on Reddit, that it was part of the agreement with Snowden not to publish anything about Afghanistan and other military operations, so this might be the reason why Greenwald didn't publish anything about DANCINGOASIS.

But in the book 'Der NSA Komplex' written by two journalists from the German magazine Der Spiegel, there's more information. It says that the DANCINGOASIS program started in May 2011 and monitors a fiber optic cable between Western Europe and the Far East.*

It is not clarified what kind of targets DANCINGOASIS collection is used for, but given the enormous amounts of data (57 billion), it has to be from top priority countries from the Middle East. According to the BOUNDLESSINFORMANT heat map, NSA collected more than 27 billion data a month from Pakistan, 24 billion from Afghanistan, 15 billion from Iran and 13 billion from Jordan - all countries that are along the fiber optic cables between Europe and the Far East.


Blocking address books

Such a huge collection of communications inevitably comes with data that are useless, like for example address books from e-mail accounts that are not related to target persons. Because the number of these address books grew steadily, NSA started to block these from being ingested by installing the SCISSORS selection system.

This is shown in slides published by The Washington Post on October 15, 2013. We see that SCISSORS was enabled for DANCINGOASIS (US-3171) on March 13, 2012:

 

The slide on the right shows two codes associated with content collected under DANCINGOASIS: DGOT and DGOD. Similar codes for metadata are written reverse: TOGD and DOGD respectively.


Processing

The systems which are used to process the data from DANCINGOASIS are listed in the "Top 5 Tech" section of the SSO chart. Of the four most important systems, three are used for processing internet data: XKEYSCORE (42 bln.), TURMOIL (23 bln.) and FALLOUT (12 bln.), with LOPERS (41 bln.) being a system for processing data derived from telephone networks.

This means that there are two options regarding what kind of data are collected under the DANCINGOASIS program:
- Either 100% derived from the internet and then being processed by a combination of the XKEYSCORE, TURMOIL and FALLOUT systems;

- Or a mix of internet and telephony data, which are processed partly by the internet processing systems and partly by LOPERS.

Clarity about this can only be provided by the yet unpublished BOUNDLESSINFORMANT chart about the DANCINGOASIS specifically, but the fact that data from this collection facility end up in two separate databases (see below) could indicate that one receives internet data and another telephone communications.


Data filtering

The cable intercepted by DANCINGOASIS transfers 25 petabyte of communications data each day. Between 3 and 6 petabyte of them are being scanned by NSA computers. These systems search the data for keywords that are determined by NSA's targeting offices and are derived from the topics in the Strategic Mission List (pdf) and the National Intelligence Priorities Framework, as approved by the White House.

Based upon an unpublished NSA presentation from March 22, 2013 titled "Cyber Threats and Special Sources Operations", the Spiegel book says that between 10 and 40 percent of the data (both content and metadata) collected under the DANCINGOASIS program are filtered out and stored in two databases: 43 gigabyte in one and 132 gigabyte in another database, every day.*

This means that 175 gigabyte of data is stored daily, which is 0,000007% of the 25 petabyte that is transmitted by the cable. The 175 gigabyte makes 5,2 terabyte a month and 63 terabyte a year. Whether the 57,7 billion records collected under DANCINGOASIS also equal 5,2 terabyte of digital storage space seems a bit questionable however.

The book doesn't provide the names of the databases, so probably it aren't the known ones like PINWALE, MAINWAY and MARINA. Therefore, the data from DANCINGOASIS might be stored in the NSA's new cloud systems, the names of which NSA likes to keep secret for some reason or another.

Because of similar capacity limits across a range of collection programs, the NSA is leaping forward with cloud-based collection systems and a huge new "mission data repository" in Utah.


Metadata processing

According to the excerpt of an NSA document published in the book of Glenn Greenwald, metadata records from DANCINGOASIS are processed by a system codenamed SHELLTRUMPET. This system "began as a near-real time metadata analyser in December 2007 for a CLASSIC collection system":


On December 21, 2012 SHELLTRUMPET had processed its 1 trillionth metadata record. Almost half of this volume was processed during 2012, and half of that volume, so one quarter of a trillion (250 billion) metadata records, came from DANCINGOASIS.*



Reporting

A system that collects a huge amount of data does not automatically contribute to equal numbers of intelligence reports. We can see this in a slide about results from NSA's Upstream collection during the fiscal year 2010/2011.

In the chart, US-3171, the SIGAD of DANCINGOASIS, ranks 6th with some 5452 so called "Serialized Product Reports". Data collected under section 702 FAA authority (PRISM and the domestic Upstream cable tapping) led to almost 4 times more reports:


With a blue bar, DANCINGOASIS is listed as a "SSO Non-Corporate Program", which means the collection is done without cooperation of a commercial telecommunications company. Although this does not exclude foreign government or foreign partner agency cooperation, it's remarkable that NSA is able to collect these huge amounts of data from a fiber optic cable without the help of the operating companies.

Update:
On June 4, 2015, the New York Times published a slide about SSO cyber operations, which indicates that DANCINGOASIS became operational in June 2011. The remark "Need I see more?" seems to confirm the importance of this very large cable access program:



May 6, 2014

Pictures from inside the German intelligence agency BND

(Updated: May 25, 2020)

The German foreign intelligence service Bundesnachrichtendienst (BND) is moving to a brand new headquarters in Berlin. Here we show some unique pictures from inside the former headquarters in the village of Pullach and also give an impression of what the new building looks like.

Unlike for example the United States and the United Kingdom, Germany has no separate agency for collecting Signals Intelligence (SIGINT) - this is done by the BND, and as such this agency is a 3rd Party partner of NSA since 1962 and also participates in the SIGINT Seniors Europe or 14-Eyes group.



The former Pullach headquarters

Since its formal creation in 1956, the Bundesnachrichtendienst had its headquarters at a 68-hectare compound in Pullach, a village near Munich in the southern province of Bavaria, which was initially build as a model village for staff members of the Nazi party in the years 1936-1938. On the eastern part of the compound there are nowadays also a number of modern office blocks:




As a farewell to this old headquarters, the German photographer Martin Schlüter was allowed to take pictures of almost every corner of the complex, but only at night, when there were no employees present. His pictures now available in a book called "Nachts schlafen die Spione" (at night the spies are sleeping), published by the Sieveking Verlag.

Pictures from the book were shown in the German television magazine TTT - Titel, Thesen, Temperamente, which made it possible to take the following screenshots of those that show some of the telecommunications equipment used by the BND (click the pictures to enlarge).


One picture shows a larger room which is used as an operations center with all the common stuff, like various computers, large video screens and teleconferencing equipment:




In the next picture we see a smaller operations center room with desks and a lot of computer screens:




We see that every monitor has its own keyboard and mouse, which seems not very practical. In the US for example, military and intelligence agencies use so-called KVM-switches, which allows users to work on multiple computers and/or terminals of physically separated networks with just one keyboard, video screen and mouse.


A close up of the previous picture gives a somewhat more detailed view of the equipment:




On the left there are computer screens which show content inside a red and with a blue border. This most likely indicates the classification level of the network they're connected to:
- Blue: VERSCHLUSSSACHE (which equals Confidential)
- Red: GEHEIM (Secret) or STRENG GEHEIM (Top Secret)
Content without such a border is apparently unclassified.

In the center we see two telephones: at the left a Cisco Unified IP Phone 7961 and at the right a rather common looking but yet unidentified office telephone, which can be seen in the other pictures too. The Cisco phone is for a Voice over IP (VoIP) network, where the other one is probably part of a traditional Private Branch eXchange (PBX) internal telephone system.

In these pictures we see no secure telephones, ones that are capable of encrypting calls by themself, like the ELCRODAT 5-4, made by the German manufacturer Rohde & Schwarz. Probably BND uses network encryptors to secure the calls before they leave the internal network.


That there's also some amount of crazyness, can be seen in this picture of an office room, used by a BND employee who cleary is a hardcore fan of Elvis Presley:





The new Berlin headquarters

The new BND headquarters is a huge office building at the Chausseestraße in the centre of Berlin. The construction started in 2006 and the overall costs for the building and moving the inventory of some 6000 employees are estimated at 1,3 billion Euro. The BND finally moved to its new headquarters in 2019.

The architecture expert Niklas Maak points to a striking difference between the former and the new headquarters: in the past, the enemy was known, the communists from the Warsaw Pact, it was known where they came from, and hence the intelligence agency was hidden in the Bavarian woods. Nowadays, enemies like terrorists and hackers are unvisible and could be everywhere, but the BND is now as visible as it can be, almost as to scare them off.



The new BND headquarters building in Berlin
(photo: DAPD/TAZ.de)


In the new building each employee has a desk with two computers and a telephone, as can be seen in this picture:


(photo: Franz Solms-Laubach/BZ-Berlin.de)


There are two wide-screen monitors, each one with its own keybord and mouse connected to a computer device. Apparently the BND still doesn't want to use KVM switches.
Update:
Initially, the computer devices looked like thin clients, which just create a virtual desktop environment. All files are stored at centralized servers, which also makes it more easy to control and limit the access to sensitive and secret documents. But later, a reader recognized them as being Fujitsu ESPRIMO Q910 mini PC's, which are small but fully equipped personal computers. They also have usb-ports, which would allow to connect thumb drives to them.

One of the thin clients mini PC's has a red and the other one a blue sticker, which probably once again denotes the classification level of the network to which it connects:
- Blue: VERSCHLUSSSACHE (which equals Confidential)
- Red: GEHEIM (Secret) or STRENG GEHEIM (Top Secret)

The telephone on the desk is a Alcatel-Lucent 4068 IP Phone or a similar model, which is a high end full-featured office telephone for Voice over IP networks. Alcatel was a major French telecommunications company which merged with the American telephone manufacturer Lucent Technologies in 2006.

It seems somewhat strange for an intelligence agency to use telephones that are made by a foreign company, as for example the German company Siemens manufactures telephony equipment for almost a century.



Links and sources
- Berlin erleben: Die neue BND-Zentrale in Berlin - imposant oder megaloman? Berlin erklärt
- Internal NSA presentation: Structure of the BND (pdf)
- More pictures of the Berlin headquarters: Eröffnung der BND-Zentrale
- A 2006 photobook about BND Standort Pullach
- Zeit.de: Der BND wird schlecht überwacht

April 23, 2014

What is known about NSA's PRISM program

(Updated: May 23, 2026)

In June last year the Snowden-leaks started with the disclosure of the PRISM-program. For many people it stands for NSA surveillance in general because they often have still no idea what PRISM is actually about.

Therefore, this article presents almost everything we know about the PRISM program, combining information from my earlier postings and from other media and government sources.

It shows that PRISM is not about bulk or mass surveillance, but for collecting communications of specifically identified foreign targets. NSA also has no "direct access" to the servers of companies like Microsoft, Facebook and Google - it's actually a unit of the FBI that picks up data related to specific identifiers.

In total, ca. 227 million internet communications are collected under the PRISM program each year, contributing to reports about counter-intelligence, terrorism and weapons proliferation. Anually, NSA analysts write more than 20.000 PRISM-based reports, which is ca. 15% of all intelligence reports the agency produces.




The PRISM presentation

Most of what we know about PRISM comes from an internal NSA presentation of 41 slides. Edward Snowden initially asked The Washington Post to publish the full slide deck, but the paper refused and so only 4 were subsequently published by The Guardian. Other slides were revealed later on.

Until now, a total of 19 slides have been published and another 4 were incidentally or partially shown on television. This means that a remaining 18 slides are still being withheld.

All known slides are shown here, in an order that probably comes closest to the original presentation. The slides (click to enlarge) have a number which is only for reference. If new slides of this PRISM presentation become available, they will be added here.


1. This slide was one of the first four revealed by The Guardian and The Washington Post on June 6, 2013, and shows the title of the presentation.

All slides are marked TOP SECRET//SI//ORCON/NOFORN, which means they are classified as Top Secret and protected by the control system for Special Intelligence (SI). The dissemination is strictly controlled by the originator, while it's generally prohibited to release them to foreign nationals.

The SIGINT Activity Designator (SIGAD) of the PRISM program is US-984XN, which indicates that PRISM is part of the BLARNEY-family and used for collecting data under the authority of the FISA Amendments Act.


The media have redacted the name of the person who is the PRISM collection manager, a title which is followed by S35333, which is NSA's internal organization designator for a unit of the Special Source Operations (SSO). The logo of this division is in the top left corner of each slide, with in the opposite corner a logo for the PRISM program itself.

Immediatly after the first slides of the presentation were published, some people thought it could be fake or photoshopped because of the not very professional looking design and the copy-paste elements. After more, and especially far more complex slides became available, we can now assume the presentation to be genuine.


This presentation about PRISM was given in April 2013, which is just a month before Edward Snowden left his job at NSA and therefore this seems to be one of the most recent documents he was able to download from the internal NSA network.



General aspects of PRISM

The following slides are about the workings of the PRISM program in general:


2. This slide was one of the first four revealed by The Guardian and The Washington Post on June 6, 2013, and shows a short introduction of the world's telecommunications backbone.

The diagram shows that the majority of international communications from Latin America, Europe and even from Asia flow through the United States, which makes it easy for NSA to intercept them on American soil.

Note that most of the communications from Africa (the continent where many jihadist groups from the Middle East went to in recent years) are going through Europe, which explains why NSA sometimes needs European partner agencies (like from the Netherlands) to access them.



3. This slide was one of the first four revealed by The Guardian and The Washington Post on June 6, 2013, and shows which internet companies are involved and what kind communications can be received by the NSA.

We see that under PRISM the NSA is able to collect e-mail, chat, video and voice messages, photo's, stored data and things like that. But there are also "Notifications of target activity - logins, etc". This was interpreted by The Washington Post as a function that gives NSA analysts live notifications "when a target logs on or sends an e-mail".

But as these notifications are clearly listed as collected data (see also slide 8 down below), it's more likely they refer to the notification messages you get when someone logs in at an internet chatroom or an instant messenger, or when you receive an e-mail through an e-mail client.

It is possible though that NSA analysts can get a notification when new communications from a target they are watching becomes available in NSA systems. Whether (near) real-time monitoring of a target's communications is possible, depends on the way these data are made available to NSA (see slide 5 below).



4. This slide was one of the first four revealed by The Guardian and The Washington Post on June 6, 2013, and shows the dates when PRISM collection began for each provider:
- Microsoft: September 11, 2007
- Yahoo: March 12, 2008
- Google: January 14, 2009
- Facebook: June 3, 2009
- PalTalk: December 7, 2009
- YouTube: September 24, 2010
- Skype: February 2, 2011
- AOL: March 31, 2011
- Apple: October 2012

According to the book 'Der NSA Komplex', which was published by Der Spiegel in March 2014, PRISM also gained access to Microsoft's cloud service SkyDrive (now called OneDrive) as of March 2013. This was realized after months of cooperation between FBI and Microsoft.*

The Washington Post reported that in the speaker's notes accompanying the presentation, it's said that "98 percent of PRISM production is based on Yahoo, Google and Microsoft; we need to make sure we don’t harm these sources". The Post also says that "PalTalk, although much smaller, has hosted traffic of substantial intelligence interest during the Arab Spring and in the ongoing Syrian civil war".

The program cost of 20 million dollar per year was initially interpreted as being the cost of the program itself, but later The Guardian revealed that NSA pays for expenses made by cooperating corporations, so it seems more likely that the 20 million is the total amount paid by NSA to the companies involved in the PRISM program.

Update:
In September 2014, the US Justice Department and the Director of National Intelligence declassified a range of documents showing that when Yahoo was asked to join the PRISM program in October 2007, the company refused, but was forced to comply by the Foreign Intelligence Surveillance Court of Review in May, 2008.


5. This slide was one of four disclosed by The Washington Post on June 29, 2013 and shows the PRISM tasking process, which means how the actual collection facilities are instructed about what data should be gathered.

The process starts with an NSA analyst entering selectors into the Unified Targeting Tool (UTT). In this case, selectors can be e-mail or IP addresses, but not keywords. According to an article in the French paper Le Monde, there are some 45.000 selectors involved in the PRISM collection.

Analysts can order data from two different sources:
- Surveillance, which means communications that will happen from the moment the target was selected (although the media interpreted this as the ability to real-time "monitor a voice, text or voice chat as it happens")
- Stored Comms, which are communications stored by the various providers dating from before the moment the target was selected

Edward Snowden vehemently accuses NSA for a lack of control and oversight mechanisms, which according to him, makes that analysts have unrestricted access to the communications of virtually everyone in the world. But the diagram in the slide clearly shows that there are multiple steps for approving every collection request:

1. For Surveillance a first review is done by an FAA Adjudicator in the analysts Product Line (S2) and for Stored Comms there's a review by the Special FISA Oversight and Processing unit (SV4).

2. A second and final review is done in both cases by the Targeting and Mission Management (S343) unit. Only after passing both stages, the request is released through the UTT and the PRINTAURA distribution managing system.

3. For Stored Comms the Electronic Communications Surveillance Unit (ECSU) of the FBI even does a third check against its own database to filter out known Americans.

Then it's the Data Intercept Technology Unit (DITU) of the FBI that goes to the various internet companies to pick up the requested data and then sends them back to NSA.

As indicated by companies like Google, they deliver the information to the FBI in different ways, like through a secure FTP transfer, an encrypted dropbox or even in person. According to a report by the journalist Declan McCullagh, the companies prefer installing their own monitoring capabilities to their networks and servers, instead of allowing the FBI to plug in government-controlled equipment.




6. This slide was published in Glenn Greenwald's book No Place To Hide and on his website on May 13, 2014. It shows a chart representing the number of unique selectors (like e-mail addresses) used for PRISM collection during the Fiscal Year (FY) 2012.

By September 2012, the communications of some 45.000 selectors were being monitored. The strongest growth was Skype (up 248%), Facebook (up 131%) and Google (up 61%).



7. This slide was one of three that were made available on the website of the German magazine Der Spiegel on June 18, 2014. It shows a table with numbers about requesting (tasking) the collection of internet communications (DNI) through the Unified Targeting Tool (UTT).

The table lists NSA units which are called Product Lines (click here for an explanation of the internal designations). For each unit it is shown how many DNI selectors, like e-mail and IP addresses, they are tasking in total and how many of those are directed to the PRISM program. We also see the percentages and the change compared to the previous year.

In absolute numbers, the top-5 units tasking most DNI requests for PRISM are:
- S2I: Counter-Terrorism Product Line (11.461 selectors)
- S2E: Middle East and Africa Product Line (6935 selectors)
- F6: NSA/CIA Special Collection Service (4007 selectors)
- S2D: Counter Foreign Intelligence Product Line (3796 selectors)
- F22: European Cryptologic Center (3523 selectors)

In total, all these NSA-units requested the communications of 175.126 internet addresses, of which 49.653 (or 28% of the total) were tasked to PRISM. It's not clear whether these numbers include double selectors, like ones tasked by multiple units.



8. This slide was shown on Brazilian television and seems also to be about PRISM Tasking, more specifically about a procedure for emergency tasking when lives are in danger. The slide was uploaded to Wikipedia, where there's also a transcript of the text:
[...] your targets meet FAA criteria, you should consider tasking to FAA.
Emergency tasking processes exist for [imminent/immediate] threat to life situations and targets can be placed on [...] within hours (surveillance and stored comms).
Get to know your Product line FAA adjudicators and FAA leads.

According to an NSA report (pdf) published in April 2014, analysts "may seek to query a U.S. person identifier when there is an imminent threat to life, such as a hostage situation".

Just like a number of other slides and fragments thereof shown on television, there seems to be no good reason why a slide like this is still not published in a clear and proper way. They contain nothing that endangers the national security of the US, but instead would help to much better understand how the PRISM program is actually used.



9. This slide was one of four disclosed by The Washington Post on June 29, 2013.

It shows the flow of data which are collected under the PRISM program. Again we see that it's the FBI's DITU that picks up the data at the various providers and sends them to the PRINTAURA system at NSA.

From PRINTAURA some of the data are directed to TRAFFICTHIEF, which is a database for metadata about specifically selected e-mail addresses and is part of the TURBULANCE umbrella program to detect threats in cyberspace.

The main stream of data is sent through SCISSORS, which seems to be used for separating different types of data and protocols. Metadata and voice content then pass the ingest processing systems FALLOUT and CONVEYANCE respectively. Finally, the data are stored in the following NSA databases:
- MARINA: for internet metadata
- MAINWAY: for telephone and internet metadata contact chaining
- NUCLEON: for voice content
- PINWALE: for internet content, video content, and "FAA partitions"




10. This slide was one of four disclosed by The Washington Post on June 29, 2013.

It shows the composition of the Case Notation (CASN) which is assigned to all communications which are intercepted under the PRISM program.

We see that there are positions for identifying the providers, the type of content, the year and a serial number. Also there's a fixed trigraph which denotes the source. For NSA's PRISM collection this trigraph is SQC. From another document (pdf) we learn that the trigraph for FISA data used by the FBI is SQF.

The abbreviations stand for: IM = Instant Messaging; RTN-EDC = Real Time Notification-Electronic Data Communication(?); RTN-IM = Real Time Notification-Instant Messaging; OSN = Online Social Networking.

> See for more about this slide: PRISM case notations



11. This slide was one of four disclosed by The Washington Post on June 29, 2013.

The content of the slide shows a screenshot of a web based application called REPRISMFISA, which is probably accessible through the web address which is blacked out by the Post. Unfortunately there's no further explanation of what application we see here, but it seems to be for querying data collected under FISA and FAA authority.

In the center of the page there are three icons, which can be clicked: PRISM, FBI FISA and DOJ FISA. This shows that both NSA, FBI and the Department of Justice (DOJ) are using data collected under the authority of the Foreign Intelligence Surveillance Act (FISA), and that the NSA's part is codenamed PRISM.

Below these icons there is a search field, to query one or more databases resulting in a partial list of records. At the left there's a column presenting a number of options for showing totals of PRISM entries. The screenshot shows that on April 5, 2013, there were 117.675 "current entries" for PRISM.

> See for more about this slide: Searching the collected data

The tool shown in this slide is not use for analysing the data. For that, analysts can use other software programs like DNI Presenter or Analyst's Notebook.
Update: According to Barton Gellman's book Dark Mirror from May 2020, this is actually slide 40 of the original presentation, which also includes speaker's notes that haven't been published.*



Section 702 FAA Operations

The following slides are about how PRISM can be used to collect various types of data. This collection is governed by section 702 of the FISA Amendments Act (FAA), which in NSA-speak is called FAA702 or just merely 702.

Section 702 FAA was enacted in 2008 in order to legalize the interception that was going on since 2001 and that became known as the "warrentless wiretapping" because it was only authorized by a secret order of president George W. Bush. The FAA was re-authorized by Congress in December 2012 and extended for five years.

Under section 702 FAA, NSA is authorized to acquire foreign intelligence information by intercepting the content of communications of non-US persons who are reasonably believed to be located outside the US. This interception takes place inside the United States with the cooperation of American telecommunication and internet companies.

Operations under the original Foreign Intelligence Surveillance Act (FISA) from 1978 require an individual determination (the target might well be a whole organization though) by the FISA Court, but under FAA the Attorney General and the Director of National Intelligence (DNI) annually certify the procedures and safeguards for collecting data about certain groups of foreign intelligence targets.

These certifications are then reviewed by the FISA Court to determine whether they meet the statutory requirements, like the minimization rules for hiding names and addresses of US citizens that may unintentionally come in with the communications of the foreign targets.



12. This slide was additionally published by The Guardian on June 8, 2013, to clarify that PRISM, which involves data collection from servers, is distinct from the programs FAIRVIEW, STORMBREW, BLARNEY and OAKSTAR. These involve data collection from "fiber cables and infrastructure as data flows past", which is called Upstream collection.

NSA can collect data that flow through the internet backbone cables, as well as data that are stored on the servers of companies like Google, Facebook, Apple, etc. The latter are collected "directly from the servers" as opposed to the communications that are still on their way to those servers when passing through the main internet cables and switches.

Directly from servers?

The words "directly from the servers" were misinterpreted by The Guardian and The Washington Post, leading to the claim that NSA had "direct access" to the servers of the internet service providers. As the next slide will show, there's no such direct access.

(The claim of NSA having "direct access" was not only based on this slide, but also on misreading a section from the draft of a 2009 NSA Inspector General report about the STELLARWIND program, which on page 17 says: "collection managers sent content tasking instructions directly to equipment installed at company-controlled locations". The Washington Post thought this referred to the companies involved in the PRISM program, but it actually was about Upstream Collection, which has filters installed at major internet switches. This follows from two facts: first, that the STELLARWIND program was terminated in January 2007 while PRISM only started later that year; second, that STELLARWIND only involved companies that operate the internet and telephony backbone cables, like AT&T and Verizon, not internet service providers like Facebook and Google)

Despite this clear evidence that speaks against a "direct access" to company servers, Glenn Greenwald still sticks to that claim in his book No Place To Hide, which was published on May 13, 2014. Asked about this by a Dutch news website, Greenwald said that the "direct access" doesn't mean that NSA "has full, unlimited access. But they can tell the companies what they want to have and then they can get it".

The Section 702 Program Report (pdf) by the Privacy and Civil Liberties Oversight Board (PCLOB) from July 2, 2014 describes that for PRISM collection, the FBI on behalf of the NSA sends selectors (such as an e-mail addresses or a chat handle) to a US-based internet service provider that has been served a Section 702 Directive. Under such a directive, the provider is compelled to hand over the communications sent to or from such selectors. Such acquisition continues until the government detasks a particular selector.

According to a document (pdf) declassified in September 2014, the government provided Yahoo with multiple lists of user accounts for which surveillance was wanted, and as of May 12, 2008, Yahoo started the surveillance of these accounts.


Upstream collection

An important thing that wasn't well explained by the media, is that not only PRISM, but also the domestic part of Upstream collection is legally based upon section 702 FAA. Note that NSA also conducts Upstream collection under three other legal authorities: FISA and Transit inside the US and Executive Order 12333 when the collection takes place abroad.


From a 2011 FISA Court ruling (pdf) that was declassified upon request of the Electronic Frontier Foundation we learn that under section 702 FAA, NSA acquires more than 250 million "internet communications" each year. This number breaks down as follows:
- Upstream: ca. 9% or more than 22 million communications *
- PRISM: ca. 91% or more than 227 million communications
The ruling doesn't explain what exactly a "internet communication" is. A problem that troubled both NSA and the FISA court was that under Upstream it's technically very difficult to distinguish between single communications to, from or about targeted persons and those containing multiple communications, not all of which may be to, from or about approved targeted addresses. The latter may contain to up to 10,000 domestic communications each year.*
 

Statistical transparency

On June 27, 2014, the Director of National Intelligence (DNI) for the first time published an Annual Statistical Transparancy Report (ASTR), which says that in 2013, the collection under Section 702 FAA affected some 89.138 targets. Such a target "could be an individual person, a group, an organization or a foreign power".

Specifically for 702 FAA collection, the number of 89.138 targets includes an "estimated number of known users of particular facilities (sometimes referred to as selectors)" - which means users of e-mail and IP addresses and such.

The report gives the following example: "foreign intelligence targets often communicate using several different email accounts. Unless the Intelligence Community has information that multiple email accounts are used by the same target, each of those accounts would be counted separately in these figures. On the other hand, if the Intelligence Community is aware that the accounts are all used by the same target, as defined above, they would be counted as one target".


Number of targets under Section 702 FAA - click to enlarge


In the various Statistical Transparency Reports published by the Director of National Intelligence we find the numbers of foreign targets under Section 702 FAA:
2013: 89.138 targets
2014: 92.707 targets
2015: 94.368 targets
2016: 106.468 targets
2017: 129.080 targets
2018: 164.770 targets
2019: 204.968 targets
2020: 202.723 targets
2021: 232.432 targets
2022: 246.073 targets
2023: 268.590 targets
2024: 291.824 targets
2025: 349.823 targets

 
13. This slide was one of three published on the website of the French paper Le Monde on October 22, 2013. It compares the main features of the PRISM program and the Upstream collection.

Direct Access?

The last line says that for PRISM there is no "Direct Relationship with Comms Providers". Data are collected through the FBI. This clearly contradicts the initial story by The Guardian and The Washington Post, which claimed that NSA had "direct access" to the servers of the internet companies. This led to spectacular headlines, but also a lot of confusion, as it allowed the companies involved to strongly deny any direct relationship with the NSA - because it's actually the FBI that is picking up their data.

Had this slide been published right in the beginning, then more adequate questions could have been asked and probably we could have got answers that made more sense.

A direct relationship does exist however with the companies which are involved in the Upstream collection, like AT&T and Verizon, who most likely have high volume filtering devices like the Narus STA 6400 installed at their switching stations. Unlike intercept facilities outside the US, where the XKeyscore system can store and search 3 days of content, the sites inside the US only seem to filter data as they flow past, and hence there's no access to Stored Communications.

About Collection

The slide also shows that the so-called "Abouts" collection is only conducted under the Upstream method. As we learned from a hearing of the Presidential Civil Liberties Oversight Board (PCLOB ), this About Collection is not for gathering communications to or from a certain target, but about a specific selector, like for example an e-mail message in which an e-mail address or a phone number of a known suspect is mentioned. This About Collection is not looking for names or keywords, is only used for internet communications and was authorized by the FISA Court.

Because under Upstream NSA is allowed to do About Collection which pulls in a broader range of communications, the retention period (the time the data are stored) is only two years. Data collected under PRISM, which are restricted to communications to and from specific addresses, are stored for the standard period of five years. Both under PRISM and Upstream there's no collection based upon keywords.



14. The slide was seen in a television report and shows a world map with the undersee fiber optic cables according to the volumes of data they transmit. This map is used as background of a number of other slides about FAA 702 Operations. In seems that additional information, like in the next slide, appears by mouse clicking the original powerpoint presentation.



15. The slide shows the same world map with fiber-optic cables and is hardly readable, but according to Wikipedia, the subheader reads "Collection only possible under FAA702 Authority" and in the central cyan colored box the codenames FAIRVIEW and STORMBREW are shown subsequently. Maybe other codenames are in the yellow box at the right side. It's not clear what the irregular blue shapes in the Indian Ocean are. The figure which is right of New Zealand is a stereotype depiction of a terrorist with a turban.



16. This partial slide was seen on the laptop of Glenn Greenwald in a report by Brazilian television and shows two scenarios for collection data under FAA 702 authority. It has two boxes with text, the one on the right reads:
UPSTREAM
Scenario #2
OPI tasks badguy@yahoo.com under FAA702 and 12333 authority in UTT
Badguy sends e-mail from [outside?] U.S. and comms flow inside U.S.
FAIRVIEW sees selector but can't tell if destination end is U.S. or foreign
RESULT
Collection allowed
Only the target end needs to be foreign
OPI stands for Office of Primary Interest and UTT for Unified Targeting Tool, the NSA application used for instructing the actual collection facilities.



17. This slide was one of three published on the website of the French paper Le Monde on October 22, 2013.

It shows a list of 35 IP addresses and domain names which are the "Higher Volume Domains Collected from FAA Passive". Data from these domains are collected from fiber optic cables and other internet infrastructures - the Upstream or Passive Collection, complementary to the PRISM collection which involves some major US domains like hotmail.com and yahoo.com.

All IP addresses and domain names are blacked out, except for two French domains: wanadoo.fr (a major French internet service provider) and alcatel-lucent.com (a major French-American telecommunications company). The rest of the list will most likely contain many similar domain names, which shows that redactions of the Snowden-documents are not only made to protect legitimate security interests, but also when the papers, in this case Le Monde, want to keep these revelations strictly focussed to their own audience.
Update:
On May 8, 2014, the French paper Le Monde listed some more targets from NSA's Upstream Collection, although it is not clear whether these are derived from this slide or from a different NSA document.



Reporting based on PRISM

The following slides show some of the results from the PRISM program:


18. This slide was one of three published on the website of the French paper Le Monde on October 22, 2013.

It shows a highlight of reporting under the section 702 FAA authority, which in this case includes both PRISM and the STORMBREW program of the Upstream collection capability. Information derived from both sources made the NSA/CSS Threat Operations Center (NTOC) figure out that someone had gotten access to the network of a cleared defense contractor (CDC) and was either preparing to, or at least had the ability to get 150 gigabytes of important data out. NTOC then alerted the FBI, which alerted the contractor and they plugged the hole the same day, apparently December 14, 2012.

Another cyber attack that was detected by PRISM occured in 2011 and was directed against the Pentagon and major defense contractors. According to the book 'Der NSA Komplex' this attack was codenamed LEGION YANKEE, which indicates that it was most likely conducted by Chinese hackers.*



This slide is not part of the original PRISM presentation, but from another slide deck from NSA's Special Source Operations division. The slide was published at Glenn Greenwald's website The Intercept on April 30, 2014.

It shows that during the 2012 Olympic Games in London, 100 specially trained and/or approved GHCQ employees were granted access to data collected under the PRISM program. 256 selectors (like e-mail addresses) were under surveillance, leading to 11.431 communication fragments ("cuts of traffic") being produced during one week in May. This is an average of 45 communication parts like e-mail and chat messages and such per address.

According to another document published by The Intercept, GCHQ wanted "unsupervised access" to data collected by NSA under the section 702 FAA authority (PRISM and Upstream) in "a manner similar to the Olympic Option" program from 2012. GCHQ seemed to be less enthusiastic about the current procedure to get such kind of access under supervised conditions, called Triage, which involves long steps to get the necessary approvals.



19. From this slide there are two different versions: a small and heavily redacted one appeared on the website of O Globo, and a large one, also with most of the topics censored, was published in Glenn Greenwald's book No Place To Hide on May 13, 2014. The slide is titled "A Week in the Life of PRISM Reporting" and shows some samples of reporting topics from early February 2013.

One of the things that were apparently blacked (or actually whited) out were published in the Indian paper The Hindu, which said that this slide also mentions "politics, space, nuclear" as topics under "India" and also information from Asian and African countries, contributing to a total of "589 End product Reports".



20. This slide was one of three that were made available on the website of the German magazine Der Spiegel on June 18, 2014. It shows a table with numbers about the intelligence reports based upon data collected through the PRISM program.

The table lists NSA units which function as Office of Primary Interest (OPI - click here for an explanation of the internal designations). In this case, the numbers are sorted in the order of reports produced. The top-5 most productive units are:
- F6: NSA/CIA Special Collection Service (3723 reports)
- S2I: Counter-Terrorism Product Line (3493 reports)
- S2E: Middle East and Africa Product Line (2574 reports)
- S2G: Counter Proliferation Product Line (2092 reports)
- NSAT: NSA Texas (1690 reports)

The total number of intelligence reports produced by all these OPI's is 144.779, and 22.500 of them are based upon information from the PRISM program, which is an average of 15%. According to a document published in Greenwald's book, there were 18.973 PRISM-based end-product reports in the fiscal year 2011 and 24.096 in 2012.



21. This slide was one of three that were made available on the website of the German magazine Der Spiegel on June 18, 2014. Just like the previous slide, it shows a table with numbers about the intelligence reports based upon data collected through the PRISM program.

The table again lists NSA units which function as Office of Primary Interest (OPI - click here for an explanation of the internal designations). In this case, the numbers are sorted by how many of the total number of reports issued by the various OPI's are PRISM-based, which can be seen in the fourth column. The top-5 units are:
- ECC: European Cryptologic Center (52%)
- S2I: Counter-Terrorism Product Line (42%)
- S2J: Weapons and Space Product Line (33%)
- S2G: Counter Proliferation Product Line (30%)
- NSAT: NSA Texas (30%)


These lists clearly show that collection under the PRISM program is not restricted to counter-terrorism, but is also not about monitoring ordinary people all over the world, as many people still think. PRISM is used for gathering information about a range of targets derived from the topics in the NSA's Strategic Mission List (pdf). The 2007 edition of this list was also among the Snowden-documents and subsequently published, but got hardly any attention.

Already on June 27, 2013 then NSA director Alexander stated in a Congress hearing that data collected under section 702 FAA and section 215 Patriot Act (the domestic metadata collection), enabled US agencies to disrupt 54 threat events, 42 of which "involved disrupted plots". Of those 54:
- 12 involved cases of material support to terrorists;
- 50 lead to arrests or detentions;
- 25 occurred in Europe;
- 11 were in Asia;
- 5 were in Africa;
- 13 had a homeland nexus.
Alexander said that in 53 of the 54 cases, data collected under section 702 provided the initial tip to "unravel the threat stream" and that almost half of terrorist reporting comes from Section 702.
Update:
Later that year, senator Patrick Leahy from the Senate Judiciary Committee said that "These [54 events] weren't all plots and they weren't all thwarted. The American people are getting left with the inaccurate impression of the effectiveness of NSA program".
In October 2013, general Alexander talked about 54 cases "in which these programs [sections 702 FAA and 215 Patriot Act] contributed to our understanding, and in many cases, helped enable the disruption of terrorist plots in the U.S. and in over 20 countries throughout the world".

According to former NSA deputy director Chris Inglis some 41 terrorist plots were foiled by information collected under section 702 FAA, most of them by PRISM. This is not a very large number, but as we've seen, PRISM is also used for creating intelligence reports about other topics.

In 2012, these were cited as a source in 1477 items of the President's Daily Brief, making PRISM one of the main contributors to this Top Secret intelligence briefing which is provided to the president each morning.

According to its annual report (pdf), the Dutch parliamentary intelligence oversight committee CIVD was informed on July 3, 2013 that information from PRISM prevented 26 terrorist attacks in Europe, including one in the Netherlands.



Conclusions

The following slides are the ones that contain some conclusions of the presentation about the PRISM program:


22. This slide was one of two published by The New York Times on June 4, 2015. Both seem to make up the last ones of the presentation about PRISM. In this slide we see some plans for the near future, like expanding the collection and a practical change to the UTT tasking tool.

More interesting is the aim to extend the PRISM collection to Dropbox, but although it is not clear whether this has been realised, Snowden warned people for using Dropbox (such a service provider doesn't participate voluntarily in the PRISM program, but is served with a Section 702 Directive).

NSA also wanted to obtain a separate certification for cyber threats from the FISA Court, so it could also collect data related to certain strings of malicious code through the PRISM and Upstream programs.



23. This slide was one of two published by The New York Times on June 4, 2015. Both seem to make up the last ones of the presentation about PRISM. It encourages analysts to use the possibilities of the PRISM and Upstream programs as much as possible, as they provide "unique collection on their targets".

Under the last bullet point it is said that PRISM and Upstream collection can also be used for searching "cyber signatures and I.P. addresses", which probably refers to the fact that in July 2012, the Department of Justice allowed NSA to target certain cybersecurity-related IP addresses under these programs, so long as there's a nexus with the Counter-Terrorism (CT), the Foreign Government (FG) or the Counter-Proliferation (CP) certifications.

The fact that IP addresses were explicitely linked to the cybersecurity authorization seems to indicate that (at least under section 702 FAA) IP addresses may not have been used as selectors before - which would contradict the general assumption that NSA commonly used IP addresses as selectors too.

Remarkably, the whole use of section 702 FAA programs for cyber security purposes was not investigated or even mentioned in the extensive report (pdf) on these programs by the Privacy and Civil Liberties Oversight Board (PCLOB) from July 2014.

Update:
On August 15, 2016, the website The Intercept published a few documents from the Snowden trove showing that the NSA used PRISM to get information about a New Zealand citizen who GCSB believed was involved in a plot against the regime on the island of Fiji, which turned out not to be the case.



- See also: Excerpts from NSA documents about PRISM



Links and Sources
- Statement before the House Committee on the Judiciary on the FISA Amendments Act (pdf) (2016)
- WebPolicy.org: The NSA’s Domestic Cybersecurity Surveillance (June 2015)
- EmptyWheel.net: Section 702 Used for Cybersecurity: You Read It Here First (June 2015)
- PCLOB.gov: Section 702 Program Report (pdf) (July 2014)
- MatthewAid.com: New NSA Report on Its Electronic Eavesdropping Programs
- EmptyWheel.net: Back Door Searches: One of Two Replacements for the Internet Dragnet?
- DNI.gov: NSA's Implementation of Foreign Intelligence Surveillance Act Section 702 (pdf)
- TED.com: Edward Snowden: Here's how we take back the Internet
- C-Span.org: Privacy and Civil Liberties Oversight Board Hearing, Government Officials Panel
- TechDirt.com: Why Does The NSA Focus So Much On 'TERROR!' When PRISM's Success Story Is About Cybersecurity?
- SealedAbstract.com: The part of the FISC NSA decision you missed
- GlobalResearch.com: New Documents Shed Light on NSA’s Dragnet Surveillance
- TheGuardian.com: Microsoft handed the NSA access to encrypted messages

Some older articles on this weblog that are of current interest:
In Dutch: Volg de actuele ontwikkelingen rond de Wet op de inlichtingen- en veiligheidsdiensten via het Dossier herziening Wiv 2017