Feeds

CIA-funded upstart: THE TRUTH about Prism and NSA's web snooping

Mystery of what's inside the spooks' black boxes

Top three mobile application threats

Palantir Technologies has denied its Prism software is related to the NSA's controversial and massive PRISM web surveillance system.

The Big Data startup, backed in its early stages by the the CIA's In-Q-Tel venture capital arm, has insisted that its data-mining Prism software in question is for banks, not governments. Palantir’s legal counsel, Matt Long, supplied Forbes with a more detailed denial along the same lines.

Meanwhile, PRISM is America's computer system for snooping on foreigners' online activities by tapping internet giants for their records, as revealed last week.

"Palantir’s Prism platform is completely unrelated to any US government program of the same name. Prism is Palantir’s name for a data integration technology used in the Palantir Metropolis platform (formerly branded as Palantir Finance). This software has been licensed to banks and hedge funds for quantitative analysis and research," Long said.

An overview of Plantir's Prism software by the company itself provides graphs and examples illustrating its financial analysis applications without, perhaps, excluding other potential applications of the tool.

Y Combinator partner Garry Tan backed up Palantir’s denial of spooky iterations of Prism in a Twitter update:

Palantir's data analysis platform technology grew from software originally developed at PayPal in order to detect fraudulent activity. The security upstart is nonetheless known for its governmental and national security work. This, and the naming coincidence, inevitably led to early speculation by Business Insider and others, since denied.

The NSA's PRISM system allows the Feds to tap "directly into the central servers" of the nine largest internet companies to extract audio, photographs, emails, documents, and connection logs to allow intelligence analysts to track foreign targets, the Washington Post reported on Thursday. Blighty's GCHQ may also have had access to this system, The Guardian added on Friday.

US director of national intelligence James R. Clapper has confirmed the existence of PRISM, while decrying unspecified inaccuracies in media reports.

The tech firms whose data is harvested by PRISM - Google (Gmail, YouTube, etc), Facebook, Microsoft (Hotmail, Skype, etc.), Apple, Yahoo, PalTalk and AOL - have denied providing government with direct access to their servers or a backdoor.

It may be that the original direct access claims, which came from a leaked PowerPoint deck, are technically inaccurate and PRISM actually involves direct access to a Dropbox-like system (potentially hosted by Amazon) which fulfils wiretapping requests made by spooks under the US Foreign Intelligence Surveillance Act (FISA).

We don't know how much data is sucked into these systems, how long it is retained, or how many people are affected but earlier revelations about a secret court order to harvest call data (but not content) of all Verizon customers suggest a possible obtain everything, analyse later approach. On the other hand a leaked budget of $20 million a year points to a much more modest system, or an incredible elegant and efficient Panopticon.

All this leaves how PRISM works and its architecture as open questions.

Alex Stamos, CTO of Artemis Internet, has put together a taxonomy of PRISM possibilities here. Meanwhile, Robert Graham of Errata Security has put together more ideas on what PRISM might mean, based in part on his own experience with the old Carnivore email surveillance system, on the Errata Security blog. ®

Bootnote

Palantir and HBGary Federal worked together to develop a strategy for Bank of America to deal with the threatened exposure of secret documents from the bank. HBGary Federal proposed a smear campaign against journalist Glenn Greenwald as part of these proposals, a move Palantir repudiated and said was solely HBGary's idea. They severed their links with HBGary Federal in February 2011, soon after the infamous LulzSec pwnage of HBGary Federal and its chief exec, Aaron Barr.

Two years later Greenwald worked together with a source, revealed over the weekend as NSA contractor Edward Snowden, to expose secret information about PRISM and secret a court order requiring Verizon to supply call log data on all of its customers on a daily basis.

High performance access to file storage

More from The Register

next story
This time it's 'Personal': new Office 365 sub covers just two devices
Redmond also brings Office into Google's back yard
Kingston DataTraveler MicroDuo: Turn your phone into a 72GB beast
USB-usiness in the front, micro-USB party in the back
Dropbox defends fantastically badly timed Condoleezza Rice appointment
'Nothing is going to change with Dr. Rice's appointment,' file sharer promises
Inside the Hekaton: SQL Server 2014's database engine deconstructed
Nadella's database sqares the circle of cheap memory vs speed
BOFH: Oh DO tell us what you think. *CLICK*
$%%&amp Oh dear, we've been cut *CLICK* Well hello *CLICK* You're breaking up...
Just what could be inside Dropbox's new 'Home For Life'?
Biz apps, messaging, photos, email, more storage – sorry, did you think there would be cake?
AMD's 'Seattle' 64-bit ARM server chips now sampling, set to launch in late 2014
But they won't appear in SeaMicro Fabric Compute Systems anytime soon
Amazon reveals its Google-killing 'R3' server instances
A mega-memory instance that never forgets
prev story

Whitepapers

Top three mobile application threats
Learn about three of the top mobile application security threats facing businesses today and recommendations on how to mitigate the risk.
Combat fraud and increase customer satisfaction
Based on their experience using HP ArcSight Enterprise Security Manager for IT security operations, Finansbank moved to HP ArcSight ESM for fraud management.
The benefits of software based PBX
Why you should break free from your proprietary PBX and how to leverage your existing server hardware.
Five 3D headsets to be won!
We were so impressed by the Durovis Dive headset we’ve asked the company to give some away to Reg readers.
SANS - Survey on application security programs
In this whitepaper learn about the state of application security programs and practices of 488 surveyed respondents, and discover how mature and effective these programs are.