Feeds

CIA-funded upstart: THE TRUTH about Prism and NSA's web snooping

Mystery of what's inside the spooks' black boxes

Protecting against web application threats using SSL

Palantir Technologies has denied its Prism software is related to the NSA's controversial and massive PRISM web surveillance system.

The Big Data startup, backed in its early stages by the the CIA's In-Q-Tel venture capital arm, has insisted that its data-mining Prism software in question is for banks, not governments. Palantir’s legal counsel, Matt Long, supplied Forbes with a more detailed denial along the same lines.

Meanwhile, PRISM is America's computer system for snooping on foreigners' online activities by tapping internet giants for their records, as revealed last week.

"Palantir’s Prism platform is completely unrelated to any US government program of the same name. Prism is Palantir’s name for a data integration technology used in the Palantir Metropolis platform (formerly branded as Palantir Finance). This software has been licensed to banks and hedge funds for quantitative analysis and research," Long said.

An overview of Plantir's Prism software by the company itself provides graphs and examples illustrating its financial analysis applications without, perhaps, excluding other potential applications of the tool.

Y Combinator partner Garry Tan backed up Palantir’s denial of spooky iterations of Prism in a Twitter update:

Palantir's data analysis platform technology grew from software originally developed at PayPal in order to detect fraudulent activity. The security upstart is nonetheless known for its governmental and national security work. This, and the naming coincidence, inevitably led to early speculation by Business Insider and others, since denied.

The NSA's PRISM system allows the Feds to tap "directly into the central servers" of the nine largest internet companies to extract audio, photographs, emails, documents, and connection logs to allow intelligence analysts to track foreign targets, the Washington Post reported on Thursday. Blighty's GCHQ may also have had access to this system, The Guardian added on Friday.

US director of national intelligence James R. Clapper has confirmed the existence of PRISM, while decrying unspecified inaccuracies in media reports.

The tech firms whose data is harvested by PRISM - Google (Gmail, YouTube, etc), Facebook, Microsoft (Hotmail, Skype, etc.), Apple, Yahoo, PalTalk and AOL - have denied providing government with direct access to their servers or a backdoor.

It may be that the original direct access claims, which came from a leaked PowerPoint deck, are technically inaccurate and PRISM actually involves direct access to a Dropbox-like system (potentially hosted by Amazon) which fulfils wiretapping requests made by spooks under the US Foreign Intelligence Surveillance Act (FISA).

We don't know how much data is sucked into these systems, how long it is retained, or how many people are affected but earlier revelations about a secret court order to harvest call data (but not content) of all Verizon customers suggest a possible obtain everything, analyse later approach. On the other hand a leaked budget of $20 million a year points to a much more modest system, or an incredible elegant and efficient Panopticon.

All this leaves how PRISM works and its architecture as open questions.

Alex Stamos, CTO of Artemis Internet, has put together a taxonomy of PRISM possibilities here. Meanwhile, Robert Graham of Errata Security has put together more ideas on what PRISM might mean, based in part on his own experience with the old Carnivore email surveillance system, on the Errata Security blog. ®

Bootnote

Palantir and HBGary Federal worked together to develop a strategy for Bank of America to deal with the threatened exposure of secret documents from the bank. HBGary Federal proposed a smear campaign against journalist Glenn Greenwald as part of these proposals, a move Palantir repudiated and said was solely HBGary's idea. They severed their links with HBGary Federal in February 2011, soon after the infamous LulzSec pwnage of HBGary Federal and its chief exec, Aaron Barr.

Two years later Greenwald worked together with a source, revealed over the weekend as NSA contractor Edward Snowden, to expose secret information about PRISM and secret a court order requiring Verizon to supply call log data on all of its customers on a daily basis.

Choosing a cloud hosting partner with confidence

More from The Register

next story
Wanna keep your data for 1,000 YEARS? No? Hard luck, HDS wants you to anyway
Combine Blu-ray and M-DISC and you get this monster
Google+ GOING, GOING ... ? Newbie Gmailers no longer forced into mandatory ID slurp
Mountain View distances itself from lame 'network thingy'
US boffins demo 'twisted radio' mux
OAM takes wireless signals to 32 Gbps
Apple flops out 2FA for iCloud in bid to stop future nude selfie leaks
Millions of 4chan users howl with laughter as Cupertino slams stable door
'Kim Kardashian snaps naked selfies with a BLACKBERRY'. *Twitterati gasps*
More alleged private, nude celeb pics appear online
Students playing with impressive racks? Yes, it's cluster comp time
The most comprehensive coverage the world has ever seen. Ever
Run little spreadsheet, run! IBM's Watson is coming to gobble you up
Big Blue's big super's big appetite for big data in big clouds for big analytics
Seagate's triple-headed Cerberus could SAVE the DISK WORLD
... and possibly bring us even more HAMR time. Yay!
prev story

Whitepapers

Secure remote control for conventional and virtual desktops
Balancing user privacy and privileged access, in accordance with compliance frameworks and legislation. Evaluating any potential remote control choice.
WIN a very cool portable ZX Spectrum
Win a one-off portable Spectrum built by legendary hardware hacker Ben Heck
Storage capacity and performance optimization at Mizuno USA
Mizuno USA turn to Tegile storage technology to solve both their SAN and backup issues.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
The next step in data security
With recent increased privacy concerns and computers becoming more powerful, the chance of hackers being able to crack smaller-sized RSA keys increases.