The Register® — Biting the hand that feeds IT

Feeds

NSA headman: 'Don't worry, our watchful analysts TAKE EXAMS'

Puzzle palace prince wishes more countries would hop on the intercept train

Supercharge your infrastructure

Black Hat 2013 NSA head General Keith Alexander believes the NSA's data-slurping programs should "be something we put forward as an example to the rest of the world," due to the oversight afforded by the courts, Congress, and the administration.

The spy chief made his remarks at the Black Hat security conference in Las Vegas on Wednesday, after a tough couple of months for the secretive organization during which mega-leaker Edward Snowden spilled the beans on telephony metadata collection programs in the US, content interception abroad via PRISM, and other schemes abroad.

At Black Hat, Alexander vigorously defended both the metadata interception via the authority provided by the Patriot Act (Section 215), and the Foreign Intelligence Surveillance Act (FISA, Section 702). He argued that the oversight afforded to the government, court, and administration concerning the schemes more than compensates for any potentially uncomfortable feelings people may have about privacy invasion.

Alexander's disclosures came about due to the unprecedented intelligence leaks from Edward Snowden, a former Booz & Allen contractor who had worked in the NSA. Last week Alexander said the Snowden leaks represented a "huge break in trust and confidence" between the NSA and its contractors.

"The tools and things we use are very much the same as the tools you use in securing networks," Alexander said. "The difference in part is the oversight and compliance we have in these programs – that part is missing in much of the discussion."

The general went on to discuss at length the immense oversight that NSA analysts are under, and stressed that very few within the organization have the ability to query the information slurped up by these programs.

He attempted to reassure a skeptical audience by saying "our people have to take courses and pass exams to use this data." Data from the interception programs has "provided value" across some 53 "terror-related activities" detected by the NSA.

"Remember," Alexander said. "Their intent is not to go after our communications, their intent is to find the terrorist that walks among us."

Keith "break in trust and confidence" Alexander also tried to reassure people that the data being shared by Silicon Valley tech companies was not as great as that feared by the press.

"Industry just doesn't dump stuff to us and say 'Hey, here are some interesting facts.' They are compelled by court order to comply where all three branches of our government have come together," he said. Only 35 analysts within the NSA are authorised to run queries on user metadata, Alexander said, and there are 22 people within the NSA that can approve this.

"In 2012 there were less than 300 numbers approved for queries," he said. "These queries resulted in 12 reports to the FBI. Those reports contained less than 500 numbers – not millions, not hundreds of thousands, not tends of thousands: less than 500."

As for the mass interception of foreign national data such as emails and other content via the 702 program, Alexander said that Congress had reviewed this program over a four-year period and "found no willful or knowledgable violations of the law or intent of the law in this program."

He also bridles at the way the FISA court has been portrayed as being a "rubber stamp" organization. "I'm on the other end of that table with federal judges, and anyone here who has been up against a federal judge knows these are people with tremendous legal experience that don't take any – I'm tying to think of a word here – from even a four star general, he said. "They are not a rubber stamp."

The immense oversight under which NSA analysts labor when investigating telephony or email data jars rather heavily with the "XKeyscore" program that was revealed by The Guardian on Wednesday. XKeyscore apparently lets analysts trawl an individual's emails, social media activity, and internet queries, without the need for review by either a court or senior NSA personnel.

The XKeyscore system can be queried by name, telephone number, IP address, and keywords, and email address.

"Allegations of widespread, unchecked analyst access to NSA collection data are simply not true," the NSA said in a statement to The Guardian. "Access to XKeyscore, as well as all of NSA's analytic tools, is limited to only those personnel who require access for their assigned tasks. ... In addition, there are multiple technical, manual and supervisory checks and balances within the system to prevent deliberate misuse from occurring

Near the close of his speech Alexander said "We stand for freedom." A member of the black-clad, security-aware audience, however, took issue with that assertion.

"Bullshit!" he shouted ®

5 ways to prepare your advertising infrastructure for disaster

Whitepapers

5 ways to prepare your advertising infrastructure for disaster
Being prepared allows your brand to greatly improve your advertising infrastructure performance and reliability that, in the end, will boost confidence in your brand.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.
Email delivery: Hate phishing emails? You'll love DMARC
DMARC has been created as a standard to help properly authenticate your sends and monitor and report phishers that are trying to send from your name..
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Email delivery: 4 steps to get more email to the inbox
This whitepaper lists some steps and information that will give you the best opportunity to achieve an amazing sender reputation.

More from The Register

next story
Chaos Computer Club: iPhone 5S finger-sniffer COMPROMISED
Anyone can touch your phone and make it give up its all
NSA in new SHOCK 'can see public data' SCANDAL!
What you say on Twitter doesn't stay on Twitter
Hundreds of hackers sought for new £500m UK cyber-bomber strike force
Britain must rm -rf its enemies or be rm -rf'ed, declares defence secretary
Would you hire a hacker to run your security? 'Yes' say Brit IT bosses
We don't have enough securo bods in the industry either, reckon gloomy BOFHs
UK's Get Safe Online? 'No one cares' - run the blockbuster ads instead
Something like Jack Bauer's 24 ... whatever it'll take to teach kids how to bat away hackers
London schoolboy cuffed for BIGGEST DDOS ATTACK IN HISTORY
Bet his parents wish he'd been playing computer games
RSA: That NSA crypto-algorithm we put in our products? Stop using that
Encryption key tool was dodgy in 2007, and still dodgy now
The NSA's hiring - and they want a CIVIL LIBERTIES officer
In other news, the Spanish Inquisition want an equal opprtunities officer
'Occupy' affiliate claims Intel bakes SECRET 3G radio into vPro CPUs
Tinfoil hat brigade say every PC is on mobile networks, even when powered down
prev story