Showing posts with label Internet user's privacy. Show all posts
Showing posts with label Internet user's privacy. Show all posts

Monday, May 2, 2011

Bin Laden's Killing Could Alter Af-Pak, Other Policies

By Jim Lobe*
WASHINGTON, May 2, 2011 (IPS) - Sunday's killing of al Qaeda chief Osama bin Laden by a small, helicopter-borne team of U.S. Navy Seals could result in significant impacts on U.S. relations and strategy both in Pakistan, where the raid was carried out, and neighbouring Afghanistan, where it was launched, according to policy experts here.

Analysts agreed that the operation, which targeted a compound in a wealthy suburb of Islamabad without prior consultation with Pakistani officials, will likely worsen already-fraught ties with that country.

They also agreed that the operation's success offers President Barack Obama a chance to more fully embrace a counterterrorist (CT) strategy in Afghanistan, as opposed to the more ambitious counterinsurgency (COIN) and nation-building strategy pursued by the outgoing commander there, Army Gen. David Petraeus. If so, the 100,000 troops currently deployed there could be drawn down more quickly than has been anticipated.

Broadly hailed as a major victory for Washington in its nearly decade-long pursuit of al Qaeda's leadership, most analysts here also agreed that bin Laden's death could hasten the demise of al Qaeda itself, even as threats posed by its affiliates in the Islamic world are likely to persist for some time.

"With his demise, …it will take a long time for anyone to reclaim bin Laden's influence in the salafi terrorist circles, regardless of who and how quickly someone nominally replaces him at the head of al Qaeda," according to Vanda Felbab-Brown, a South Asia specialist at theBrookings Institution, who described his status and prestige among violent Islamists as "almost mythical".

"Bin Laden was the only al-Qaeda figure able to command the attention of a mainstream Arab audience," wrote Marc Lynch, an Arab public opinion expert at George Washington University, on his foreignpolicy.com blog Monday.

"He remained uniquely charismatic and able to frame al-Qaeda's narrative in ways which resonated with a broader Arab and Muslim audience," according to Lynch, who predicted that his death will only briefly distract the Arab media's attention from the popular uprisings that have both dominated the region over the past several months and further marginalised al Qaeda's appeal for violent resistance against the U.S. and the West.

Indeed, bin Laden's killing could actually give renewed momentum to the so-called "Arab Spring", according to Christopher Davidson, a Gulf expert at Britain's Durham University.

While bin Laden himself had become "little more than a figurehead" in recent years, "the impact of his death on authoritarian regimes in Middle Eastern and other Islamic countries will be significant, as he served an important and valuable role as a 'bogeyman' that could be wheeled out to justify …why brutal crackdowns and limits on political expression were often needed," he said.

For now, however, the biggest foreign policy implications of bin Laden's killing – and the completely unilateral manner in which it was carried out – appear to lie with Pakistan.

That bin Laden had been living for some time – possibly as many as five years – in an unusually large and heavily fortified compound in Abbottabad, a community 50 kms from Islamabad whose residents include a disproportionate number of retired senior military officers, confirmed to most analysts that at least some sectors of Pakistan's government provided effective safe haven for Washington's "Public Enemy Number One".

"We are very concerned that he was inside of Pakistan," one senior administration official told reporters in a telephone conference call Sunday night immediately after Obama announced bin Laden's death.

Public charges by senior U.S. government and military officials that Islamabad was not cooperating fully with Washington's counterterrorism efforts had already become increasingly bold in the weeks leading up to Sunday's raid. And despite assurances by both sides Monday that they remain close allies, the action seems certain to worsen relations, according to virtually all analysts here.

"It strains credulity to say that Pakistani officials did not know what was going on in the suburbs of Islamabad," said Richard Haass, president of the Council on Foreign Relations(CFR), in a teleconference with reporters Monday.

"It suggests to me that this long-fraught and difficult relationship will be entering yet another difficult phase moving forward," he said, suggesting that Washington will find it hard to justify continued substantial aid to Islamabad – currently appropriated at 1.5 billion dollars and over one billion dollars a year in non- military and military aid, respectively – unless confidence can be restored.

"Pakistan essentially has a choice. It either partners with the United States much more completely, or it has to be prepared for the United States to act independently," according to Haass, who held senior policy positions in both the George H.W. and George W. Bush administrations.

"This will definitely worsen our relations with Pakistan," said Col. Pat Lang (ret.), who served as the top Mideast and South Asia officer at the Defence Intelligence Agency (DIA). "But I don't see that we can do anything about it; it's the Pakistanis that are moving away from us and toward China, and that process will continue."

Lang also noted that the success of the cross-border strike against bin Laden may also provide an opportunity for Obama to reduce his commitment to a "nation-building" COIN strategy in Afghanistan in favour of a CT strategy that would require many fewer troops on the ground.

That assessment was echoed by Haass, who has been critical of the COIN strategy and its costs in blood and treasure in Afghanistan since Obama agreed with Petraeus in November 2009 to increase U.S. troop strength to 100,000 by late 2010.

"This will very much play into a growing debate as we move towards Jul. 1 about the proper trajectory of U.S. policy in Afghanistan in general and more specifically the rate of drawdown of U.S. forces," he said.

Obama pledged in November 2009 to begin withdrawing U.S. forces from Afghanistan as of Jul. 1, 2011, but Petraeus has reportedly argued for only a nominal reduction.

"I am hopeful that this provides closure to the American public for 9/11, and that closure provides some form of political backbone for members of Congress to become more engaged in the debate on the war," said Matthew Hoh, director of the Afghanistan Study Group, who was deployed to Afghanistan as a marine captain and then as a State Department official.

"I'm also hopeful it will provide political space to President Obama to allow him to pursue a serious de-escalation of the war," he added.

Patrick Cronin, a national security expert at the Center for a New American Security, was even more emphatic in terms of the potential strategic importance of the moment.

"The United States needs to further pivot from counterinsurgency, which feeds the perception of occupation, to counterterrorism, which requires a sharper discrimination between al Qaeda and the Taliban," he said.

But COIN advocates warned against such a move. Max Boot, a neo- conservative who has often given public voice to Petraeus's private views, worried Monday that "many Americans may decide that the threat from al-Qaeda is (now) gone and that we can afford to draw down in Afghanistan."

Noting the continued existence in the region of a number of "Islamist terrorist groups", he argued on the CFR website that a "comprehensive counterinsurgency campaign in Afghanistan is still vital to prevent that country from falling to Osama bin Laden's fellow travellers."

Brookings' Felbab-Brown, meanwhile, argued that bin Laden's death could enhance chances for a negotiated settlement with the Taliban in Afghanistan.

"Despite their separate structures and al Qaeda's limited influence over the Taliban's decision-making, bin Laden likely was a significant force against the Taliban engaging in strategic negotiations – not the least because the Taliban's disavowal of al Qaeda has been a critical precondition and/or the essential desired outcome of such negotiations," she wrote on the Brookings' website.

"Bin Laden's demise may create a more permissive environment for Taliban Central to make such a commitment, saying that whatever new leadership emerges after bin Laden's death is not the same old al Qaeda, with which the Taliban has not been willing to break for over 15 years." 



*Jim Lobe's blog on U.S. foreign policy can be read at http://www.lobelog.com. 

Saturday, April 30, 2011

New FBI Documents Provide Details on Government’s Surveillance Spyware



EFF recently received documents from the FBI that reveal details about the depth of the agency's electronic surveillance capabilities and call into question the FBI's controversial effort to push Congress to expand the Communications Assistance to Law Enforcement Act (CALEA) for greater access to communications data. The documents we received were sent to us in response to a Freedom of Information Act (FOIA) request we filed back in 2007 after Wired reported on evidence that the FBI was able to use “secret spyware” to track the source of e-mailed bomb threats against a Washington state high school. The documents discuss a tool called a "web bug" or a "Computer and Internet Protocol Address Verifier" (CIPAV),1 which seems to have been in use since at least 2001.2

What is CIPAV and How Does It Work?
The documents discuss technology that, when installed on a target's computer, allows the FBI to collect the following information:
  • IP Address
  • Media Access Control (MAC) address
  • "Browser environment variables"
  • Open communication ports
  • List of the programs running
  • Operating system type, version, and serial number
  • Browser type and version
  • Language encoding
  • The URL that the target computer was previously connected to
  • Registered computer name
  • Registered company name
  • Currently logged in user name
  • Other information that would assist with "identifying computer users, computer software installed, [and] computer hardware installed"3
It's not clear from the documents how the FBI deploys the spyware, though Wired has reportedthat, in the Washington state case, the FBI may have sent a URL via MySpace's internal messaging, pointing to code that would install the spyware by exploiting a vulnerability in the user's browser. Although the documents discuss some problems with installing the tool in some cases, other documents note that the agency's Crypto Unit only needs 24-48 hours to prepare deployment.4 And once the tool is deployed, "it stay[s] persistent on the compromised computer and . . . every time the computer connects to the Internet, [FBI] will capture the information associated with the PRTT [Pen Register/Trap & Trace Order].5
Where Has CIPAV Been Used and What Legal Process Does the FBI Rely On to Use It?
It is clear from the documents we received that the FBI—and likely other federal agencies—have used this tool a lot. According the documents, the FBI has used CIPAV in cases across the country—from Denver, El Paso, and Honolulu in 2005; to Philadelphia, California, and Houston in 2006; to Cincinnati and Miami in 2007. In fact, one stack of documents we received consists entirely of requests from FBI offices around the country to the agency's Cryptologic and Electronic Analysis Unit ("CEAU") for help installing the device.6
The FBI has been using the tool in domestic criminal investigations as well as in FISA cases,7 and the FISA Court appears to have questioned the propriety of the tool.8 Other agencies, and even other countries have shown interest in the tool, indicating its effectiveness. Emails from 2006 discuss interest from the Air Force,9 the Naval Criminal Investigative Service10 and the Joint Task Force-Global Network Operations,11 while another email from 2007 discusses interest from the German government.12
The FBI's Crypto Unit appears to have viewed the CIPAV as a proprietary tool. In one email, an agent grumbled, "we are seeing indications that [CIPAV] is being used needlessly by some agencies, unnecessarily raising difficult legal questions (and a risk of suppression without any countervailing benefit)."13 In another email, an agent stated, "[I] am weary [sic] to just hand over our tools to another Gov't agency without any oversight or protection for our tool/technique."14And a third email noted, "[w]e never discuss how we collect the [data CIPAV can collect] in the warrants/affidavits or with case agents. AUSAs, squad supervisors, outside agencies, etc."15
It appears from the documents that the FBI wasn't sure what legal process to seek to authorize use of the spyware device. Some emails discuss trying to use a "trespasser exception" to get around a warrant,16while others discuss telling the AUSA (government attorney) to cite to the "All Writs Act, 28 U.S.C. § 1651(a)."17 And one email suggests some agents thought the tool required no legal process at all. In that email, the FBI employee notes he considers the tool to be "consensual monitoring without need for process; in my mind, no different than sitting in a chat room and tracking participants' on/off times; or for that matter sitting on P2P networks and finding out who is offering KP."18
Eventually, the FBI seems to have sought a legal opinion on the proper use of the tool, both from the Office of General Counsel and from the National Security Law Branch,19 and ultimately, the agency seems to have settled on a "two-step request" process for CIPAV deployments -- a search warrant to authorize intrusion into the computer, and then a subsequent Pen/Trap order to authorize the surveillance done by the spyware.20
What Does This Mean for the FBI's Push for New Back Doors into Our Internet Communications?
Over the past few months, we've heard a lot from the FBI about its need to expand the Communications Assistance to Law Enforcement Act (CALEA), a law that that requires all telecommunications and broadband providers to be technically capable of complying with an intercept order. Federal law enforcement officials have argued that under current regulations they can't get the information they need and want to expand CALEA to apply to communications systems like Gmail, Skype, and Facebook. However, these documents show the FBI already has numerous tools available to surveil suspects directly, rather than through each of their communications service providers. One heavily redacted email notes that the FBI has other tools that "provide the functionality of the CIPAV [text redacted] as well as provide other useful info that could help further the case."21 Another email notes that CIPAVs are used in conjunction with email intercepts, perhaps using similar spyware-type tools.22 If the FBI already has endpoint surveillance-based tools for internet wiretapping, it casts serious doubt on law enforcement's claims of "going dark."
A device that remains "persistent" on a "compromised computer" is certainly concerning. However, if the FBI obtains a probable cause-based court order before installing tools like CIPAV, complies with the minimization requirements in federal wiretapping law by limiting the time and scope of surveillance, and removes the device once surveillance concludes, the use of these types of targeted tools for Internet surveillance would be a much more narrowly tailored solution to the FBI’s purported problems than the proposal to undermine every Internet user's privacy and security by expanding CALEA. We will continue to report on both the FBI's use of endpoint surveillance tools and on the agency's push to expand CALEA as more documents come in.
Click here to access full pdf versions of the documents we received or see below for the pages referenced in this post.
  1. 1.FBI_CIPAV_01 p.26
  2. 2.FBI_CIPAV_09 p.3
  3. 3.FBI_CIPAV_07 pp.10-11
  4. 4.FBI_CIPAV_07 p.50
  5. 5.FBI_CIPAV_08 p.67
  6. 6.FBI_CIPAV_10
  7. 7.FBI_CIPAV_07 p. 45FBI_CIPAV_08 p.132143
  8. 8.FBI_CIPAV_14 p.52
  9. 9.FBI_CIPAV_08 p.20
  10. 10.FBI_CIPAV_09 p.21-22
  11. 11.Id.
  12. 12.FBI_CIPAV_08 p.9
  13. 13.FBI_CIPAV_05 p.1
  14. 14.FBI_CIPAV 09 p.21
  15. 15.FBI_CIPAV_07 pp.11
  16. 16.FBI_CIPAV_08 p.29
  17. 17.FBI_CIPAV_08 p.149
  18. 18.FBI_CIPAV_14 p.36."KP" is likely a reference to "kiddie porn."
  19. 19.FBI_CIPAV_14 p.42, 62
  20. 20.FBI_CIPAV_08 p.169
  21. 21.FBI_CIPAV_08 p.168
  22. 22.FBI_CIPAV_08 p.143