Feeds

CIA-funded upstart: THE TRUTH about Prism and NSA's web snooping

Mystery of what's inside the spooks' black boxes

Build a business case: developing custom apps

Palantir Technologies has denied its Prism software is related to the NSA's controversial and massive PRISM web surveillance system.

The Big Data startup, backed in its early stages by the the CIA's In-Q-Tel venture capital arm, has insisted that its data-mining Prism software in question is for banks, not governments. Palantir’s legal counsel, Matt Long, supplied Forbes with a more detailed denial along the same lines.

Meanwhile, PRISM is America's computer system for snooping on foreigners' online activities by tapping internet giants for their records, as revealed last week.

"Palantir’s Prism platform is completely unrelated to any US government program of the same name. Prism is Palantir’s name for a data integration technology used in the Palantir Metropolis platform (formerly branded as Palantir Finance). This software has been licensed to banks and hedge funds for quantitative analysis and research," Long said.

An overview of Plantir's Prism software by the company itself provides graphs and examples illustrating its financial analysis applications without, perhaps, excluding other potential applications of the tool.

Y Combinator partner Garry Tan backed up Palantir’s denial of spooky iterations of Prism in a Twitter update:

Palantir's data analysis platform technology grew from software originally developed at PayPal in order to detect fraudulent activity. The security upstart is nonetheless known for its governmental and national security work. This, and the naming coincidence, inevitably led to early speculation by Business Insider and others, since denied.

The NSA's PRISM system allows the Feds to tap "directly into the central servers" of the nine largest internet companies to extract audio, photographs, emails, documents, and connection logs to allow intelligence analysts to track foreign targets, the Washington Post reported on Thursday. Blighty's GCHQ may also have had access to this system, The Guardian added on Friday.

US director of national intelligence James R. Clapper has confirmed the existence of PRISM, while decrying unspecified inaccuracies in media reports.

The tech firms whose data is harvested by PRISM - Google (Gmail, YouTube, etc), Facebook, Microsoft (Hotmail, Skype, etc.), Apple, Yahoo, PalTalk and AOL - have denied providing government with direct access to their servers or a backdoor.

It may be that the original direct access claims, which came from a leaked PowerPoint deck, are technically inaccurate and PRISM actually involves direct access to a Dropbox-like system (potentially hosted by Amazon) which fulfils wiretapping requests made by spooks under the US Foreign Intelligence Surveillance Act (FISA).

We don't know how much data is sucked into these systems, how long it is retained, or how many people are affected but earlier revelations about a secret court order to harvest call data (but not content) of all Verizon customers suggest a possible obtain everything, analyse later approach. On the other hand a leaked budget of $20 million a year points to a much more modest system, or an incredible elegant and efficient Panopticon.

All this leaves how PRISM works and its architecture as open questions.

Alex Stamos, CTO of Artemis Internet, has put together a taxonomy of PRISM possibilities here. Meanwhile, Robert Graham of Errata Security has put together more ideas on what PRISM might mean, based in part on his own experience with the old Carnivore email surveillance system, on the Errata Security blog. ®

Bootnote

Palantir and HBGary Federal worked together to develop a strategy for Bank of America to deal with the threatened exposure of secret documents from the bank. HBGary Federal proposed a smear campaign against journalist Glenn Greenwald as part of these proposals, a move Palantir repudiated and said was solely HBGary's idea. They severed their links with HBGary Federal in February 2011, soon after the infamous LulzSec pwnage of HBGary Federal and its chief exec, Aaron Barr.

Two years later Greenwald worked together with a source, revealed over the weekend as NSA contractor Edward Snowden, to expose secret information about PRISM and secret a court order requiring Verizon to supply call log data on all of its customers on a daily basis.

Boost IT visibility and business value

More from The Register

next story
Microsoft: Azure isn't ready for biz-critical apps … yet
Microsoft will move its own IT to the cloud to avoid $200m server bill
Shoot-em-up: Sony Online Entertainment hit by 'large scale DDoS attack'
Games disrupted as firm struggles to control network
Silicon Valley jolted by magnitude 6.1 quake – its biggest in 25 years
Did the earth move for you at VMworld – oh, OK. It just did. A lot
VMware's high-wire balancing act: EVO might drag us ALL down
Get it right, EMC, or there'll be STORAGE CIVIL WAR. Mark my words
Forrester says it's time to give up on physical storage arrays
The physical/virtual storage tipping point may just have arrived
VMware vaporises vCHS hybrid cloud service
AnD yEt mOre cRazy cAps to dEal wIth
prev story

Whitepapers

Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Endpoint data privacy in the cloud is easier than you think
Innovations in encryption and storage resolve issues of data privacy and key requirements for companies to look for in a solution.
Scale data protection with your virtual environment
To scale at the rate of virtualization growth, data protection solutions need to adopt new capabilities and simplify current features.
Boost IT visibility and business value
How building a great service catalog relieves pressure points and demonstrates the value of IT service management.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?