You are on page 1of 6

7/12/13

Revealed: how Microsoft handed the NSA access to encrypted messages | World news | The Guardian

Revealed:howMicrosofthandedthe NSAaccesstoencryptedmessages
SecretfilesshowscaleofSiliconValleycooperationonPrism Outlook.comencryptionunlockedevenbeforeofficiallaunch SkypeworkedtoenablePrismcollectionofvideocalls Companysaysitislegallycompelledtocomply
GlennGreenwald,EwenMacAskill,LauraPoitras,SpencerAckermanandDominicRushe TheGuardian,Thursday11July201318.53BST

SkypeworkedwithintelligenceagencieslastyeartoallowPrismtocollectvideoandaudioconversations.Photograph: PatrickSinkel/AP

MicrosofthascollaboratedcloselywithUSintelligenceservicestoallowusers' communicationstobeintercepted,includinghelpingtheNationalSecurityAgencyto circumventthecompany'sownencryption,accordingtotopsecretdocumentsobtained bytheGuardian. ThefilesprovidedbyEdwardSnowdenillustratethescaleofcooperationbetween SiliconValleyandtheintelligenceagenciesoverthelastthreeyears.Theyalsoshed newlightontheworkingsofthetopsecretPrismprogram,whichwasdisclosedbythe GuardianandtheWashingtonPostlastmonth. Thedocumentsshowthat:


www.guardian.co.uk/world/2013/jul/11/microsoft-nsa-collaboration-user-data 1/6

7/12/13

Revealed: how Microsoft handed the NSA access to encrypted messages | World news | The Guardian

MicrosofthelpedtheNSAtocircumventitsencryptiontoaddressconcernsthatthe agencywouldbeunabletointerceptwebchatsonthenewOutlook.comportal TheagencyalreadyhadpreencryptionstageaccesstoemailonOutlook.com, includingHotmail ThecompanyworkedwiththeFBIthisyeartoallowtheNSAeasieraccessviaPrism toitscloudstorageserviceSkyDrive,whichnowhasmorethan250millionusers worldwide MicrosoftalsoworkedwiththeFBI'sDataInterceptUnitto"understand"potential issueswithafeatureinOutlook.comthatallowsuserstocreateemailaliases InJulylastyear,ninemonthsafterMicrosoftboughtSkype,theNSAboastedthata newcapabilityhadtripledtheamountofSkypevideocallsbeingcollectedthrough Prism MaterialcollectedthroughPrismisroutinelysharedwiththeFBIandCIA,withone NSAdocumentdescribingtheprogramasa"teamsport". ThelatestNSArevelationsfurtherexposethetensionsbetweenSiliconValleyandthe Obamaadministration.Allthemajortechfirmsarelobbyingthegovernmenttoallow themtodisclosemorefullytheextentandnatureoftheircooperationwiththeNSAto meettheircustomers'privacyconcerns.Privately,techexecutivesareatpainsto distancethemselvesfromclaimsofcollaborationandteamworkgivenbytheNSA documents,andinsisttheprocessisdrivenbylegalcompulsion. Inastatement,Microsoftsaid:"Whenweupgradeorupdateproductswearen't absolvedfromtheneedtocomplywithexistingorfuturelawfuldemands."The companyreiterateditsargumentthatitprovidescustomerdata"onlyinresponseto governmentdemandsandweonlyevercomplywithordersforrequestsaboutspecific accountsoridentifiers". InJune,theGuardianrevealedthattheNSAclaimedtohave"directaccess"through thePrismprogramtothesystemsofmanymajorinternetcompanies,including Microsoft,Skype,Apple,Google,FacebookandYahoo. Blanketordersfromthesecretsurveillancecourtallowthesecommunicationstobe collectedwithoutanindividualwarrantiftheNSAoperativehasa51%beliefthatthe targetisnotaUScitizenandisnotonUSsoilatthetime.TargetingUScitizensdoes requireanindividualwarrant,buttheNSAisabletocollectAmericans' communicationswithoutawarrantifthetargetisaforeignnationallocatedoverseas. SincePrism'sexistencebecamepublic,Microsoftandtheothercompanieslistedonthe NSAdocumentsasprovidershavedeniedallknowledgeoftheprogramandinsisted
www.guardian.co.uk/world/2013/jul/11/microsoft-nsa-collaboration-user-data 2/6

7/12/13

Revealed: how Microsoft handed the NSA access to encrypted messages | World news | The Guardian

thattheintelligenceagenciesdonothavebackdoorsintotheirsystems. Microsoft'slatestmarketingcampaign,launchedinApril,emphasizesitscommitment toprivacywiththeslogan:"Yourprivacyisourpriority." Similarly,Skype'sprivacypolicystates:"Skypeiscommittedtorespectingyourprivacy andtheconfidentialityofyourpersonaldata,trafficdataandcommunications content." ButinternalNSAnewsletters,markedtopsecret,suggestthecooperationbetweenthe intelligencecommunityandthecompaniesisdeepandongoing. ThelatestdocumentscomefromtheNSA'sSpecialSourceOperations(SSO)division, describedbySnowdenasthe"crownjewel"oftheagency.Itisresponsibleforall programsaimedatUScommunicationssystemsthroughcorporatepartnershipssuch asPrism. ThefilesshowthattheNSAbecameconcernedabouttheinterceptionofencrypted chatsonMicrosoft'sOutlook.comportalfromthemomentthecompanybegantesting theserviceinJulylastyear. Withinfivemonths,thedocumentsexplain,MicrosoftandtheFBIhadcomeupwitha solutionthatallowedtheNSAtocircumventencryptiononOutlook.comchats Anewsletterentrydated26December2012states:"MS[Microsoft],workingwiththe FBI,developedasurveillancecapabilitytodeal"withtheissue."Thesesolutionswere successfullytestedandwentlive12Dec2012." Twomonthslater,inFebruarythisyear,MicrosoftofficiallylaunchedtheOutlook.com portal. AnothernewsletterentrystatedthatNSAalreadyhadpreencryptionaccessto Outlookemail."ForPrismcollectionagainstHotmail,Live,andOutlook.comemails willbeunaffectedbecausePrismcollectsthisdatapriortoencryption." Microsoft'scooperationwasnotlimitedtoOutlook.com.Anentrydated8April2013 describeshowthecompanyworked"formanymonths"withtheFBIwhichactsas theliaisonbetweentheintelligenceagenciesandSiliconValleyonPrismtoallow PrismaccesswithoutseparateauthorizationtoitscloudstorageserviceSkyDrive. Thedocumentdescribeshowthisaccess"meansthatanalystswillnolongerhaveto makeaspecialrequesttoSSOforthisaprocessstepthatmanyanalystsmaynot haveknownabout". TheNSAexplainedthat"thisnewcapabilitywillresultinamuchmorecompleteand timelycollectionresponse".Itcontinued:"ThissuccessistheresultoftheFBIworking
www.guardian.co.uk/world/2013/jul/11/microsoft-nsa-collaboration-user-data 3/6

7/12/13

Revealed: how Microsoft handed the NSA access to encrypted messages | World news | The Guardian

formanymonthswithMicrosofttogetthistaskingandcollectionsolution established." Aseparateentryidentifiedanotherareaforcollaboration."TheFBIDataIntercept TechnologyUnit(DITU)teamisworkingwithMicrosofttounderstandanadditional featureinOutlook.comwhichallowsuserstocreateemailaliases,whichmayaffectour taskingprocesses." TheNSAhasdevotedsubstantialeffortsinthelasttwoyearstoworkwithMicrosoftto ensureincreasedaccesstoSkype,whichhasanestimated663millionglobalusers. OnedocumentboaststhatPrismmonitoringofSkypevideoproductionhasroughly tripledsinceanewcapabilitywasaddedon14July2012."Theaudioportionsofthese sessionshavebeenprocessedcorrectlyallalong,butwithouttheaccompanyingvideo. Now,analystswillhavethecomplete'picture',"itsays. EightmonthsbeforebeingboughtbyMicrosoft,SkypejoinedthePrismprogramin February2011. AccordingtotheNSAdocuments,workhadbegunonsmoothlyintegratingSkypeinto PrisminNovember2010,butitwasnotuntil4February2011thatthecompanywas servedwithadirectivetocomplysignedbytheattorneygeneral. TheNSAwasabletostarttaskingSkypecommunicationsthefollowingday,and collectionbeganon6February."FeedbackindicatedthatacollectedSkypecallwas veryclearandthemetadatalookedcomplete,"thedocumentstated,praisingtheco operationbetweenNSAteamsandtheFBI."Collaborativeteamworkwasthekeyto thesuccessfuladditionofanotherprovidertothePrismsystem." ACLUtechnologyexpertChrisSoghoiansaidtherevelationswouldsurprisemany Skypeusers."Inthepast,Skypemadeaffirmativepromisestousersabouttheir inabilitytoperformwiretaps,"hesaid."It'shardtosquareMicrosoft'ssecret collaborationwiththeNSAwithitshighprofileeffortstocompeteonprivacywith Google." TheinformationtheNSAcollectsfromPrismisroutinelysharedwithboththeFBIand CIA.A3August2012newsletterdescribeshowtheNSAhasrecentlyexpandedsharing withtheothertwoagencies. TheNSA,theentryreveals,hasevenautomatedthesharingofaspectsofPrism,using softwarethat"enablesourpartnerstoseewhichselectors[searchterms]theNational SecurityAgencyhastaskedtoPrism". Thedocumentcontinues:"TheFBIandCIAthencanrequestacopyofPrismcollection ofanyselector"Asaresult,theauthornotes:"thesetwoactivitiesunderscorethe
www.guardian.co.uk/world/2013/jul/11/microsoft-nsa-collaboration-user-data 4/6

7/12/13

Revealed: how Microsoft handed the NSA access to encrypted messages | World news | The Guardian

pointthatPrismisateamsport!" InitsstatementtotheGuardian,Microsoftsaid: Wehaveclearprincipleswhichguidetheresponseacrossourentire companytogovernmentdemandsforcustomerinformationforbothlaw enforcementandnationalsecurityissues.First,wetakeourcommitments toourcustomersandtocompliancewithapplicablelawveryseriously,so weprovidecustomerdataonlyinresponsetolegalprocesses. Second,ourcomplianceteamexaminesalldemandsveryclosely,andwe rejectthemifwebelievetheyaren'tvalid.Third,weonlyevercomplywith ordersaboutspecificaccountsoridentifiers,andwewouldnotrespondto thekindofblanketordersdiscussedinthepressoverthepastfewweeks, asthevolumesdocumentedinourmostrecentdisclosureclearlyillustrate. Finallywhenweupgradeorupdateproductslegalobligationsmayinsome circumstancesrequirethatwemaintaintheabilitytoprovideinformation inresponsetoalawenforcementornationalsecurityrequest.Thereare aspectsofthisdebatethatwewishwewereabletodiscussmorefreely. That'swhywe'vearguedforadditionaltransparencythatwouldhelp everyoneunderstandanddebatetheseimportantissues. Inajointstatement,ShawnTurner,spokesmanforthedirectorofNational Intelligence,andJudithEmmel,spokeswomanfortheNSA,said: ThearticlesdescribecourtorderedsurveillanceandaUScompany's effortstocomplywiththeselegallymandatedrequirements.TheUS operatesitsprogramsunderastrictoversightregime,withcareful monitoringbythecourts,CongressandtheDirectorofNational Intelligence.Notallcountrieshaveequivalentoversightrequirementsto protectcivillibertiesandprivacy. Theyadded:"Inpractice,UScompaniesputenergy,focusandcommitmentinto consistentlyprotectingtheprivacyoftheircustomersaroundtheworld,whilemeeting theirobligationsunderthelawsoftheUSandothercountriesinwhichtheyoperate." Thisarticlewasamendedon11July2013toreflectinformationfromMicrosoftthat itdidnotmakeanychangestoSkypetoallowPrismcollectiononoraroundJuly2012.

www.guardian.co.uk/world/2013/jul/11/microsoft-nsa-collaboration-user-data

5/6

7/12/13

Revealed: how Microsoft handed the NSA access to encrypted messages | World news | The Guardian

SignupfortheGuardianToday
Oureditors'picksfortheday'stopnewsand commentarydeliveredtoyourinboxeachmorning. Signupforthedailyemail

MorefromtheGuardian
complaints10Jul2013

What'sthis?

IrnBru'pushupbra'adcleareddespitemorethan170

NSAscandaldeliversrecordnumbersofinternetusers toDuckDuckGo10Jul2013 SecondBoeing777suffersmidairincident09Jul2013 RussianguardservicerevertstotypewritersafterNSA leaks11Jul2013 Tridentsubmarinebase:No10disownsMoD'sFaslane sovereigntyproposal11Jul2013

2013GuardianNewsandMediaLimitedoritsaffiliatedcompanies.Allrightsreserved.

www.guardian.co.uk/world/2013/jul/11/microsoft-nsa-collaboration-user-data

6/6

You might also like