Feeds

FBI faked terror alerts to get phone records

Subpoena scamola spilled

Next gen security for virtualised datacentres

The FBI fabricated terrorism emergencies to obtain thousands of phone records between 2002 and 2006, it's been revealed.

The Bureau created "exigent letters" to get around rules that had already been significantly loosened by the Patriot Act. The letters were used to obtain some 2,000 phone records, The Washington Post reports.

Washington Post and New York Times journalists were among the targets.

The internal concerns were confirmed in emails that are part of an investigation by the Justice Department's inspector general, which is due to report this month.

As well as fabricating emergencies, FBI counter-terror investigators obtained phone records by simply leaning on operators, getting approval after the fact with blanket authorisations.

The Patriot Act allowed investigators to effectively self-certify their requests for communications data, using a "National Security Letter" (NSL), a type of subpoena without judicial oversight. The Justice Department has found that by fabricating emergencies and sending NSLs after it had obtained phone records, the FBI violated what civil liberties protections remained.

In response, the FBI claimed that although it did not follow statutory process to obtain the records, they were all legitimate targets for investigation.

"The [Justice Department] report is not expected to find — nor were there — any intentional attempts to obtain records that counterterrorism personnel knew they were not legally entitled to obtain," said assistant director of public affairs Michael Kortan.

He added all the numbers obtained have been deleted and that "steps were taken as early as 2006 to ensure similar situations do not occur in the future". However, The Washington Post said it had seen emails showing FBI lawyers sounded the alarm in 2005.

The US NSL system is similar to the UK's Regulation of Investigatory Powers Act (RIPA) regime for authorities to obtain communications data from phone companies and ISPs. Each has no judicial oversight and investigators effectively self-certify their requests.

The UK system is much broader, however, with no requirement that national security is threatened and many more agencies, such as local councils, empowered to access records.

Oversight is provided by a former High Court judge appointed by the Prime Minister, who produces an annual report. In 2008, the most recent available, he says that 595 errors were made but added: "I am not convinced that any useful purpose would be served by providing a more detailed report of these errors."

The government is developing a major extension to communications surveillance that would require internet firms to retain huge amounts of extra data, under the Interception Modernisation Programme. Ministers have argued that that RIPA will be sufficient to govern access to the newly available terabytes of private information. ®

The essential guide to IT transformation

More from The Register

next story
GCHQ protesters stick it to British spooks ... by drinking urine
Activists told NOT to snap pics of staff at the concrete doughnut
Britain's housing crisis: What are we going to do about it?
Rent control: Better than bombs at destroying housing
What do you mean, I have to POST a PHYSICAL CHEQUE to get my gun licence?
Stop bitching about firearms fees - we need computerisation
Top beak: UK privacy law may be reconsidered because of social media
Rise of Twitter etc creates 'enormous challenges'
Redmond resists order to hand over overseas email
Court wanted peek as related to US investigation
Ex US cybersecurity czar guilty in child sex abuse website case
Health and Human Services IT security chief headed online to share vile images
NZ Justice Minister scalped as hacker leaks emails
Grab your popcorn: Subterfuge and slur disrupts election run up
We need less U.S. in our WWW – Euro digital chief Steelie Neelie
EC moves to shift status quo at Internet Governance Forum
prev story

Whitepapers

Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Endpoint data privacy in the cloud is easier than you think
Innovations in encryption and storage resolve issues of data privacy and key requirements for companies to look for in a solution.
Why cloud backup?
Combining the latest advancements in disk-based backup with secure, integrated, cloud technologies offer organizations fast and assured recovery of their critical enterprise data.
Consolidation: The Foundation for IT Business Transformation
In this whitepaper learn how effective consolidation of IT and business resources can enable multiple, meaningful business benefits.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?