General Michael HaydenOn October 17, 2002 General Michael Hayden, then director of the National Security Agency, spoke in prepared remarks in front of a joint hearing of the Senate Select Committee on Intelligence and the House Permanent Select Committee on Intelligence. General Hayden was speaking about NSA’s knowledge of the events leading up to the attacks of September 11, 2001. General Hayden concluded his remarks by telling the Committees what he hoped would result from the public debate on the NSA’s future role:

Let me close by telling you what I hope to get out of the national dialogue that these committees are fostering. I am not really helped by being reminded that I need more Arabic linguists or by someone second-guessing an obscure intercept sitting in our files that may make more sense today than it did two years ago. What I really need you to do is to talk to your constituents and find out where the American people want that line between security and liberty to be.

In the context of NSA’s mission, where do we draw the line between the government’s need for CT information about people in the United States and the privacy interests of people located in the United States? Practically speaking, this line-drawing affects the focus of NSA’s activities (foreign versus domestic), the standard under which surveillances are conducted (probable cause versus reasonable suspicion, for example), the type of data NSA is permitted to collect and how, and the rules under which NSA retains and disseminates information about U.S. persons.

These are serious issues that the country addressed, and resolved to its satisfaction, once before in the mid-1970’s. In light of the events of September 11th, it is appropriate that we, as a country, readdress them. We need to get it right. We have to find the right balance between protecting our security and protecting our liberty. If we fail in this effort by drawing the line in the wrong place, that is, overly favoring liberty or security, then the terrorists win and liberty loses in either case. [Emphasis added by me.]

General Hayden’s concluding remarks to the Committees give us a window into the thought process of the man who has been nominated to be the next Director of Central Intelligence. General Hayden was challenging Congress and the American people to move the line between liberty and security toward more security. He suggested that favoring liberty over security, as was the case before September 11, 2001, will mean that "the terrorists win". He suggested that the line needs to be moved so that the standards for doing surveillance ("probable cause versus reasonable suspicion" ) can be lowered toward "reasonable suspicion". He arrogantly told Congress that he is not "helped by being reminded" of NSA’s shortcomings or by being second-guessed on NSA’s failures. The most important thing for him was that Americans give up some liberty for security in order that he, Michael Hayden, can guarantee the American people liberty by intruding on their privacy.

As General Hayden spoke to Congress on that day, we now know, the NSA was already engaged in tapping Americans’ phone conversations and collecting the phone records of millions of American citizens without required court orders. The line between liberty and security had already been moved by General Hayden and a like-minded White House without the consent or the knowledge of the American people. General Hayden had moved the privacy threshold from "probable cause" to "reasonable suspicion" without an amendment to the Constitution. In his mind, it would appear, General Hayden had convinced himself that the Constitution had been amended. In his now infamous exchange with a reporter at the National Press Club recently he made the outrageous claim that the 4th Amendment of the Constitution did not specify a "probable cause" threshold:

QUESTION: Jonathan Landay with Knight Ridder. I’d like to stay on the same issue, and that had to do with the standard by which you use to target your wiretaps. I’m no lawyer, but my understanding is that the Fourth Amendment of the Constitution specifies that you must have probable cause to be able to do a search that does not violate an American’s right against unlawful searches and seizures. Do you use —

GEN. HAYDEN: No, actually — the Fourth Amendment actually protects all of us against unreasonable search and seizure.

QUESTION: But the —

GEN. HAYDEN: That’s what it says.

QUESTION: But the measure is probable cause, I believe.

GEN. HAYDEN: The amendment says unreasonable search and seizure.

QUESTION: But does it not say probable —

GEN. HAYDEN: No. The amendment says —

QUESTION: The court standard, the legal standard —

GEN. HAYDEN: — unreasonable search and seizure.

QUESTION: The legal standard is probable cause, General. You used the terms just a few minutes ago, "We reasonably believe." And a FISA court, my understanding is, would not give you a warrant if you went before them and say "we reasonably believe"; you have to go to the FISA court, or the attorney general has to go to the FISA court and say, "we have probable cause." And so what many people believe — and I’d like you to respond to this — is that what you’ve actually done is crafted a detour around the FISA court by creating a new standard of "reasonably believe" in place in probable cause because the FISA court will not give you a warrant based on reasonable belief, you have to show probable cause. Could you respond to that, please?

GEN. HAYDEN: Sure. I didn’t craft the authorization. I am responding to a lawful order. All right? The attorney general has averred to the lawfulness of the order.

Just to be very clear — and believe me, if there’s any amendment to the Constitution that employees of the National Security Agency are familiar with, it’s the Fourth. And it is a reasonableness standard in the Fourth Amendment. And so what you’ve raised to me — and I’m not a lawyer, and don’t want to become one — what you’ve raised to me is, in terms of quoting the Fourth Amendment, is an issue of the Constitution. The constitutional standard is "reasonable." And we believe — I am convinced that we are lawful because what it is we’re doing is reasonable.

In light of the General’s previous remarks to Congress, the exchange at the National Press Club does not appear to be a slip of the tongue by the General. It appears that the General in pushing the bounds of civil liberties has convinced himself that the Constitution does not offer citizens the protections it quite clearly does.

General Hayden not only believed the line between liberty and security needed to move toward security he acted upon it with gusto. Under General Hayden the NSA embarked upon a massive investment in technology to enhance NSA’s eavesdropping prowess. In his remarks to Congress he stated:

Another part of our strategy for nearly three years has been a shift to a greater reliance on American industry. We have been moving along this path steadily and we have the metrics to show it. As you know, in project GROUNDBREAKER we have already outsourced a significant portion of our information technology so that we can concentrate on mission. We have partnered with academia for our systems engineering. I have met personally with prominent corporate executive officers. (One senior executive confided that the data management needs we outlined to him were larger than any he had previously seen). Three weeks ago we awarded a contract for nearly $300 million to a private firm to develop TRAILBLAZER, our effort to revolutionize how we produce SIGINT in a digital age. And last week we cemented a deal with another corporate giant to jointly develop a system to mine data that helps us learn about our targets. In terms of "buy vs. make" (the term Congress has used), we spent about a third of our SIGINT development money this year making things ourselves. Next year the number will be 17%. [Emphasis added by me.]

The $300 million for TRAILBLAZER was awarded to SAIC to develop a platform for doing massive data collection and analysis in real-time or near real time. NSA also awarded contracts to mine the massive amounts of data collected by TRAILBLAZER. In launching and managing TRAILBLAZER General Hayden presided over the largest waste of taxpayer dollars in the history of the National Security Agency. Since its inception in 1999, the program’s budget has ballooned to $1.2 billion. For the huge investment in taxpayer dollars, instead of the sophisticated surveillance platform promised by the contractors,  "only a few isolated analytical and technical tools have been produced" in the program’s six and a half years of existence.

In April of 2005, General Hayden testified before Congress about the delays and cost overruns of the TRAILBLAZER program:

In April, Hayden testified to the Senate Intelligence Committee that Trailblazer was racking up extra costs and dropping behind schedule.

"The costs were greater than anticipated to the tune of, I would say, hundreds of millions," Hayden said. "The slippages were actually more dramatic than the costs. As we slipped, the costs were pushed to the right."

General Hayden also learned what happens when you give big corporations blank checks written on the backs of the American taxpayer:

Hayden, in his testimony in April, acknowledged that NSA initially had mishandled the Trailblazer contract.

"We learned within Trailblazer that when we asked industry for something they had or something close to what they already had, they were remarkable in providing us a response, an outcome," Hayden told the committee. "When we asked them for something that no one had yet invented, they weren’t any better at inventing it than we were in doing it ourselves." [Emphasis added by me.]

General Hayden had bet the farm on TRAILBLAZER and he mismanaged the project at great expense to the American taxpayer.  But in spite of his utter failure in managing the most important project during his tenure as the head of the NSA, General Hayden has many backers and apologists in Washington:

But General Hayden’s fans remain loyal. Mr. [Bob] Graham, who was chairman of the Senate Intelligence Committee when the problems with Trailblazer became evident, said he preferred to attribute the difficulties to worthy ambitions.

"There were failures, but in my judgment they were not failures of competence or management," he said. "When you’re Christopher Columbus, you’re not going to get to your destination on the first try."

Apparently in Washington, you only need to think big not deliver big. I would think after the Iraq debacle the American people have had just enough of grand ideas backed up by incompetent execution.

The TRAILBLAZER program is likely the platform on which the domestic wiretaps and the phone records program are based. It now appears quite clear that the phone records database and the domestic wiretaps are in fact two aspects of the same program. The TRAILBLAZER program, flawed as it is, is likely being used to create and analyze a database of phone records. Based on hits from the analysis of the phone records, the NSA is likely tapping the phone calls of those that it has a "reasonable suspicion" might be connected to terrorism. I think it is now clear why the NSA did not seek to get warrants for the domestic wiretaps and why they unilaterally lowered the standard for wiretaps to "reasonable suspicion" from "probable cause". The phone numbers that the NSA wants to tap are likely gathered using link analysis techniques applied on their database of phone records. Without having listened in on the actual calls all the NSA is able to establish is that person A may have communicated with person B through a series of intermediaries. The NSA would find it very difficult to get warrants using "probable cause" for taps on the phone numbers of the intermediaries. For all the NSA or the court knows the call to the "intermediary" may have been an innocent call to a pizza place. The explanation provided by General Hayden that the current FISA warrants are slow is probably not correct. The more likely explanation is that the NSA is on a fishing expedition based on  "reasonable suspicion" and no court would grant a warrant under these circumstances. Having run into the law of the land, the NSA and the Administration simply chose to ignore the law.

In their zeal to root out terrorists in our midst, General Hayden and this Administration have chosen to ignore laws that protect our civil liberties. They have chosen expediency at the expense of prudence. They have chosen ambitious programs that have wasted tax payer dollars on ideas that have barely left the drawing board. When faced with a choice between programs that were designed with the civil liberties of Americans in mind on the one hand and programs that promised maximum intrusion upon privacy on the other, General Hayden chose the latter. After September 11, 2001 General Hayden and the NSA killed a program called ThinThread, designed with privacy protections, in favor of the more expensive and more ambitious TRAILBLAZER program.

General Hayden has consistently demonstrated, in testimony before Congress and in his actions as head of the NSA, that he is quite willing to disregard or ignore Amerians’ privacy rights in his pursuit of "security".  As Congress considers the nomination of General Hayden today, they should be mindful of the General’s distaste for civil liberties and his demonstrated failure as a manager. General Hayden may be a very competent intelligence officer, but he has shown himself to be a poor manager and protector of civil liberties. General Hayden’s intelligence expertise can be harnessed by the intelligence community but he should not be in charge of one of the premier intelligence services of the United States Government. He promises to continue to disregard civil liberties if he is placed in a decision-making role at such a high level. He needs to be guided and checked by strong leaders who understand where the line should be properly drawn between civil liberties and security. As such, he is not fit to lead an agency but is qualified to be a senior member of such an agency. General Hayden has it backwards when he says, that if we draw the line  "overly favoring liberty or security, then the terrorists win and liberty loses in either case." On the contrary, the terrorists win every time our civil liberties are eroded. General Hayden would do well to remember the oft-quoted Benjamin Franklin’s admonition that "those who would give up essential liberty to purchase a little temporary safety, deserve neither liberty nor safety. "

Signal-to-Noise RatioThe prospect of a $200 billion class action lawsuit has the effect of clearing the mind and clouding the facts. After the initial shock of the USA Today report on collection of domestic phone records by the NSA wore off the accused phone companies have now circled the wagons. Verizon and BellSouth have both issued statements denying involvement in the phone records gathering program.

After a week of bobbing and weaving by the Administration and its surrogates, the phone company denials need to be scrutinized carefully. First the President made a hastily organized public statement the morning after the USA Today report was released claiming NSA activities were lawful without confirming the program. Then Administration surrogate Richard Falkenrath delivered a fantastical and deeply flawed defense of the NSA program in a Washington Post opinion piece. Over the weekend Senator Frist went on national television and confirmed the existence of the NSA program before realizing his mistake and trying to back away from it.  Yesterday the President appeared with Australian Prime Minister John Howard in a joint news conference and appeared to confirm the existence of the program. Later White House spokesman Tony Snow denied the President had confirmed the existence of the program. In doing so, Snow bizarrely noted that a Washington Post poll showed that the majority of Americans approved of the program (the existence of which of course he could not confirm or deny). Finally, the often-confused Senator Orrin Hatch stated yesterday that two FISA judges had been briefed on the program but had not necessarily approved the program. Again, a spokesman for Hatch had to later clarify that the Senator had not meant to confirm the existence of the program.

With the waters muddied by the Administration, BellSouth announced in its statement:

As a result of media reports that BellSouth provided massive amounts of customer calling information under a contract with the NSA, the Company conducted an internal review to determine the facts. Based on our review to date, we have confirmed no such contract exists and we have not provided bulk customer calling records to the NSA. [Emphasis added by me.]

Verizon announced firmly in its statement:

Contrary to the media reports, Verizon was not asked by NSA to provide, nor did Verizon provide, customer phone records from any of these businesses, or any call data from those records. None of these companies - wireless or wireline - provided customer records or call data. [Emphasis added by me.]

The key to interpreting these denials are the words "provide" and "phone records". Verizon and BellSouth both are denying that they did not provide phone records to the NSA. BellSouth cuts this even finer by saying they did not provide bulk phone records. They do not however deny that they may have allowed the NSA to tap into their phone traffic and gather the phone data real time. This is a very crucial distinction from the phone companies’ point of view. By not providing the NSA stored call data, the phone companies are not in violation of the Stored Communications Act. However, if the NSA is collecting the data real-time from taps on the phone traffic the Government would be in violation of the "pen register" and "trap and trace device" statutes. It is not clear if by simply allowing the NSA to tap into their traffic whether the phone companies are in violation of the Telecommunications Act and the resulting $1000 per violation penalty.

Verizon and BellSouth’s narrow denials may be designed to muddy the waters and protect the companies from the massive class action suits against them. The phone companies may also be depending on the Government to intervene on their behalf in the lawsuits on national security grounds. In the meantime, the denials from the phone companies and the lack of confirmation from the Administration may sufficiently cloud the issue so that the facts of the NSA program will be obscured from the general public. The phone companies need to be challenged on their denials. Specific questions need to be asked about the nature of their transactions with the NSA and whether they are allowing the NSA to tap into their phone traffic. This is the time for reporters to aggressively follow up on the USA Today story. Nothing less then the civil liberties of the American people is at stake.

 

Bill FristBehold the intelligence of the man who wants to be your next President. Today on Late Edition with Wolf Blitzer, Senator Bill Frist confirmed the existence of the NSA phone records collection program first revealed by USA Today. The following is the transcript of Frist’s exchange with Wolf Blitzer on CNN:

BLITZER: Let’s talk about the surveillance programs here in the United States since 9/11. USA Today reported a bombshell this week. Let me read to you from the article on Thursday.

"The National Security Agency has been secretly collecting the phone call records of tens of millions of Americans using data provided by AT&T, Verizon and BellSouth. The NSA program reaches into homes and businesses across the nation by amassing information about the calls of ordinary Americans, most of whom aren’t suspected of any crime. With access to records of billions of domestic calls, the NSA has gained a secret window into the communications habits of millions of Americans."

Are you comfortable with this program?

FRIST: Absolutely. Absolutely. I am one of the people who are briefed…

BLITZER: You’ve known about this for years.

FRIST: I’ve known about the program. I am absolutely convinced that you, your family, our families are safer because of this particular program.

I absolutely know that it is legal. The program itself is anonymous, in the sense that identifiers, in terms of protecting your privacy, are stripped off. And, as you know, the program is voluntary, the participants in that program.

And it comes to the reality — it faces the reality that we’re in the 21st century. And the only way to connect the dots, whether around the world or in this country, to prevent another 9/11, whether it’s in the Pentagon or in New York or back in Nashville, Tennessee, is to connect those dots. And the only way to connect those dots is to use 21st-century technology that protects your privacy, and that’s exactly what this does.

BLITZER: Can you tell the American people right now that over these past almost five years since the phone records have been collected — I’m not talking about the warrantless surveillance, the warrantless wiretaps — the phone records, that has resulted in thwarting one terrorist attack in the United States?

FRIST: You know, I am not going to comment on the program until the appropriate time. There has not been even a confirmation of the USA Today program itself. I…

BLITZER: But have you been briefed on one success story?

FRIST: I can tell you I’ve been briefed in a classified way, and I can tell you that I am absolutely, 100 percent sure, confident that this has protected and saved lives in the United States of America.

BLITZER: But has there been one success story that you can point to?

FRIST: I just don’t want to be pulled in…

BLITZER: Without specifics, just tell us that there has been a terrorist attack that was plotted and, as a result of collecting these phone calls, was thwarted.

FRIST: You know, in appropriate hearings and settings, this will come out. But this is classified information about a classified program. You know, the more we talk about these programs, the more we’re giving our playbook to the terrorists who are sitting out around this country right now, who did plan 9/11 and what happened at the Pentagon today. And they are in this country now. They are waiting. And the more we talk about these programs, we’re giving them the playbook, and that empowers them to be able to have an attack on this country. And it’s just not the right thing to do. [Emphasis added by me.]

I think the Department of Justice should crack down on leakers of classified information before they further help the terrorists. DOJ should start by asking Senator Frist about why he divulged the existence of a classified NSA program on national television. Apparently it is ok to divulge the existence of the classified program but it is not ok to mention if even one terrorist has been caught as a result of the program.

Senator Frist is the first Government official to publicly confirm the existence of the NSA spying program. Unless he has been authorized to declassify this information, he is likely in violation of a number of laws aimed at protecting classified information. Clearly Senator Frist cannot be trusted to keep our nation’s secrets protected. Perhaps his security clearance should be revoked.

As the Administration continues its witch hunt to silence leakers of classified information, it needs to look hard at the Senate Majority Leader’s loose lips. Senator Frist, don’t you know the terrorists are watching?

The Kool Aid ManThere is a remarkable opinion piece today in The Washington Post entitled "The Right Call on Phone Records". It is remarkable because the author, former Deputy Homeland Security Advisor and Deputy Assistant to the President Richard Falkenrath, has apparently taken leave of his senses.

The op-ed begins with this bizarre paragraph:

On Thursday, USA Today reported that three U.S. telecommunications companies have been voluntarily providing the National Security Agency with anonymized domestic telephone records — that is, records stripped of individually identifiable data, such as names and place of residence. If true, the architect of this program deserves our thanks and probably a medal. That architect was presumably Gen. Michael Hayden, former director of the NSA and President Bush’s nominee to become director of the Central Intelligence Agency. [Emphasis added by me]

Richard FalkenrathWhen I read this, my initial thought was that the author was joking. But as I read through the rest of the fantasy piece I realized that Mr. Falkenrath was quite serious. I hope the remaining people at the top level of Homeland Security do not believe that a phone number is "anonymized" as Mr. Falkenrath appears to believe. If our senior leaders are this ignorant then we are in very serious trouble.  Here’s a little exercise for you, Mr. Falkenrath. Given the phone number 202-456-1414, how long will it take the NSA to find out whom this number belongs to? Ok, don’t hurt yourself. I will tell you. It will take them less then 23 seconds. Try it for yourself. Go to AnyWho and do a reverse lookup on 202-456-1414. Within seconds you will find that this phone number belongs to:

White House Switchboard Main Number

WASHINGTON, DC 20001
The notion that Mr. Falkenrath believes that phone numbers are "anonymized" would be laughable if not for the fact that the belief is held by the former Deputy Homeland Security Advisor to the President. If this is the kind of advice President Bush is getting we as a country are being ill served. The level of ignorance and incompetence this demonstrates is shocking.
 
Mr. Falkenrath goes on to praise General Hayden for devising this clever phone records analysis tool:
Very few career government officials possess the expertise, initiative and creativity needed to devise a system to penetrate such networks, using only existing statutory and presidential authorities, employing only existing technical and personnel resources, and violating the privacy of no American. Yet, if the USA Today story is correct, this appears to be exactly what Hayden did.
This again shows a frightening level of ignorance. The system that Mr. Falkenrath praises General Hayden for creating has been in existence since the year 1736 when Graph Theory was first discussed by Leonhard Euler. The modern derivations of graph theory, specifically network analysis, that is used to analyze networks is commonly used by many mathematicians and computer scientists. The specific algorithm apparently used by the NSA, link analysis, was famously adapted in 1995 by Sergey Brin and Lawrence Page in creating the search engine Google. Every Internet blogger is also familiar with this "system" and they regularly use its power when they use Technorati to find which web pages link to their blogs. Mr. Falkenrath, feel free to click here to find out how many web sites link to my blog. For the less technically inclined, General Hayden’s "system" is on display in the "Six Degrees of Kevin Bacon" Game. General Hayden’s "creativity" is neither original nor dramatic. He is just using technology already in existence to mine data from our phone records. The only newsworthy part of General Hayden’s "system" is that it likely violates the law.
 
Speaking of the law, Mr. Falkenrath leaps to General Hayden’s defense:

Some legislators and observers have questioned the legality of the alleged NSA domestic telephone records collection program. If the facts of the program are as reported in USA Today, there is every reason to believe that the program is perfectly legal.

There are, of course, strict legal limits on the ability of federal agencies such as the NSA to compel the provision of domestic information or to collect it secretly. The USA Today story, however, alleges that three telecommunications companies — AT&T, Verizon and BellSouth — provided it voluntarily. How else could one company (Qwest) decline to provide the information? Since there is no prohibition against federal agencies receiving voluntarily provided business records relating to their responsibilities, it appears that the NSA’s alleged receipt and retention of such information is perfectly legal.

Mr. Falkenrath must be patting himself on the back for his clever logical inversion here. It is a very nice argument to put the Government’s actions in the passive voice. To imply that the phone companies somehow left the phone records on the NSA’s doorstep and one fine morning General Hayden discovered these records as he went out for the morning paper is too clever an argument to sustain itself. Mr. Falkenrath ignores the fact the Government demanded these records from the phone companies without the required court orders. It went as far as to try to bully and blackmail Qwest into turning over the phone records. That kind of behavior hardly suggests that the NSA was a passive actor in this fiasco. Perhaps Mr. Falkenrath needs a reminder of the laws that were broken when the NSA demanded these records without a court order. You can read my layman’s analysis here or Professor Kerr’s analysis here and here.

Mr. Falkenrath concludes by putting in a plug for General Hayden for the CIA Director post. He also praises the can-do gung-ho attitude of General Hayden in contrast to the timidity of the rest of the bureaucracy:

Bureaucrats excel at finding reasons not to do something. They are most often guilty of sins of omission, not commission. A timid, ordinary executive might have concluded that it was too risky to ask U.S. telecommunications companies to provide anonymized call records voluntarily to an agency such as the NSA, dealing with foreign intelligence. If the USA Today story is correct, it appears that Mike Hayden is no timid, ordinary executive. Indeed, it appears that he is exactly the sort of man that we should have at the helm of the CIA while we are at war.

Mr. Falkenrath apparently does not understand that there is a difference between initiative and law breaking. The Constitution and the laws are there for a purpose. Choosing to ignore the laws does not make a good executive or a good nominee for the position of Director of Central Intelligence.

Mr. Falkenrath’s deeply flawed opinion piece should cause all citizens alarm. This opinion piece is a window into the thinking of some our top officials in Government entrusted with protecting us. The level of ignorance and incompetence demonstrated by Mr. Falkenrath may unfortunately be commonplace amongst the political appointees within this Administration. For exposing this level of incompetence, we all owe Mr. Falkenrath an enormous debt of gratitude.

 

Phone Link Analysis

 
The latest revelation that the National Security Agency has gathered phone records of millions of ordinary Americans has generated outrage and controversy across the political spectrum. The NSA has gathered phone records apparently without court orders in violation of existing statutes. It appears that the NSA is attempting to use this vast database of phone records to connect the dots between known terrorists by using software to look for links and patterns in the records. Unfortunately, the fact that the phone records contain the phone numbers of millions of ordinary and innocent Americans opens the door to abuse of the database and guilt by association.
 
The NSA is likely using link analysis techniques in an attempt to connect known targets separated by multiple degrees of separation. Link analysis is a simple yet powerful tool that can be used very effectively on structured relational data. Link analysis is nothing but the high tech equivalent of the "Kevin Bacon Game".
 
The image above [click image for a larger image] shows an example of how NSA would connect Bad Guy #1 with Bad Guy #2. To do so, NSA would need the phone records of Bad Guy #1, Person A, Person D, Person G and Bad Guy #2. By traversing the phone record tree from both directions the NSA could connect Bad Guy #1 and Bad Guy #2 by finding that they both are connected to intermediate Persons A, D or G.
 
In order for the NSA to do link analysis with a court order, the NSA would have to first get a warrant for the phone records of Bad Guy #1. It would then have to get a warrant for phone records for each person on Bad Guy #1’s phone record (i.e., persons A and B) and then get warrants for the persons on the phone records of the next set of people and so on. At some point, the NSA would have a difficult case to make that one of these intervening people was legitimately connected to an ongoing investigation. Even if it succeeded in making the case for the warrant, the logistics of getting a warrant at every step of the process would make this kind of link analysis cumbersome and nearly impossible to perform in real time. I suspect that is why the NSA and the President decided to go around the law. When faced with a question of law, instead of asking Congress to update the law, the Government chose to ignore the law.
 
The problem in this approach for the NSA was that getting the phone records of intervening persons between two known bad guys requires court orders. There is perhaps a simple way to achieve the goals of the NSA without the court orders and the violations of privacy that results if the court orders are not sought. I propose that instead of seeking the actual phone numbers from the phone companies, the NSA should seek secure hashed equivalents of the phone numbers. That is, all phone records handed over to the NSA should contain secure hashed ids instead of the actual phone numbers of American citizens. The phone company would keep the actual phone records and the mappings between the phone numbers and their hashed equivalents. This will ensure that the NSA does not have a database of phone numbers of ordinary Americans. I also believe there is no law that would be violated by the phone companies turning over this data to the NSA.
 
Briefly, secure hashing is a technique that is commonly used to store passwords and to digitally sign electronic messages. The power of secure hashing lies in that when a number or string is hashed to produce a message digest, there is no way to get back to the original number or string. However, the same number, if secure hashed repeatedly will result in the same message digest. This feature allows one to store data, a password or phone record for example, in a database without the original password or phone record being compromised. Given the original phone number or password, one can secure hash it and then compare it to data in the database to find its matching hash. SHA-1, the most commonly used secure hashing algorithm was designed by none other than the National Security Agency.
 
This new database maintained at the NSA, using secure hashed ids in lieu of phone numbers, would be just as effective for data mining and link analysis. If the NSA knows the phone number(s) of a known target or targets, they can simply convert the phone number to its secure hashed equivalent (or "message digest" ). These message digests then can be used to perform link analysis on the database. Using the example in the image, the NSA would secure hash the phone number of Bad Guy #1 and look up the phone record equivalents in the database. They would find the hashed message digests representing Persons A and B. When they look up the records for the message digest of person A, they would similarly find the message digest of Person D. Similarly, coming from the other side, the NSA would secure hash the actual number for Bad Guy #2 and find the message digest of Person G. In looking at the records of Person G, the NSA would find the message digest of Person D. Then, Voila!, the NSA will have connected Bad Guy #1 to Bad Guy #2 without knowing the phone numbers of Persons A, D and G. Armed with the message digests of Persons A, D and G, the NSA can now approach the court for a warrant based on probable cause. The phone companies can then provide the NSA with the actual numbers and identities of Persons A, D and G by mapping the message digests to their original phone numbers that the companies would keep in their own databases. The phone records of all other persons not involved between Bad Guy #1 and Bad Guy #2 will remain unknown to the NSA.
 
This simple use of existing cryptography techniques may eliminate the need for the massive intrusion into the privacy of ordinary Americans that is currently occurring. This solution allows the NSA to troll and mine to their hearts content in an attempt to keep us safe without violating our hard earned civil liberties. Who knows, with any luck it will come to light that the NSA is already doing this and all this fuss will have been about nothing. However, the fact that Qwest balked at handing over phone records to the NSA suggests to me that the NSA is not using this simple but effective technique.

Inspector ClouseauUSA Today reported this morning that the National Security Agency has been collecting phone records of tens of millions of ordinary Americans with the willing cooperation of the phone companies (except Quest which refused to hand over records without a court order). This disclosure caused an irritated President Bush to make a brief statement this morning. I quote the statement in its entirety:

After September the 11th, I vowed to the American people that our government would do everything within the law to protect them against another terrorist attack. As part of this effort, I authorized the National Security Agency to intercept the international communications of people with known links to al Qaeda and related terrorist organizations. In other words, if al Qaeda or their associates are making calls into the United States or out of the United States, we want to know what they’re saying.

Today there are new claims about other ways we are tracking down al Qaeda to prevent attacks on America. I want to make some important points about what the government is doing and what the government is not doing.

First, our international activities strictly target al Qaeda and their known affiliates. Al Qaeda is our enemy, and we want to know their plans. Second, the government does not listen to domestic phone calls without court approval. Third, the intelligence activities I authorized are lawful and have been briefed to appropriate members of Congress, both Republican and Democrat. Fourth, the privacy of ordinary Americans is fiercely protected in all our activities.

We’re not mining or trolling through the personal lives of millions of innocent Americans. Our efforts are focused on links to al Qaeda and their known affiliates. So far we’ve been very successful in preventing another attack on our soil.

As a general matter, every time sensitive intelligence is leaked, it hurts our ability to defeat this enemy. Our most important job is to protect the American people foreign another attack, and we will do so within the laws of our country.

Thank you.

You will notice that the President does not deny the facts of the USA Today story. He also specifically notes that the Administration’s "international activities" strictly target al Qaeda. He leaves open the possibility that domestic activities cast a much wider net. He also notes that the Administration is "not mining or trolling" through the "personal lives" of Americans. Mr. Bush is parsing very hard here to make a distinction between personal lives and personal records. The distinction is between contents of a phone conversation and records of a phone conversation. That distinction allows Mr. Bush to escape the clutches of the 4th Amendment.

However, this new NSA spying disclosure does violate at least one and perhaps two laws enacted by Congress. Where FISA does not apply, access to phone records are covered by the "pen register" or "trap and trace device" laws. The two relevant laws are 18 U.S.C. §§3121-3127 and 50 U.S.C. §§1841-1846. In order to get the phone records of a "U.S. person" the Government must get a court order. If the Government is arguing that they need the order for foreign intelligence or terrorism related activities and the information does not concern a "U.S. person", the Government must also get a court order. In both cases the application for the court order must show that the information requested is "relevant to an ongoing criminal investigation" or is "relevant to an ongoing investigation to protect against international terrorism or clandestine intelligence activities". In the case of a foreign intelligence investigation, there is a provision for an emergency authorization where the Attorney General can approve the gathering of information without a court order provided that an application is made for an order within 48 hours. There is also a provision in the law that states that in a time of war the President can authorize the collection of phone records without a court order for up to 15 calendar days following a declaration of war by Congress. There is also a requirement for the Attorney General to make detailed annual reports to Congress regarding collection of U.S. persons’ phone records and a requirement for the Attorney General to make detailed semi-annual reports to the "Permanent Select Committee on Intelligence of the House of Representatives and the Select Committee on Intelligence of the Senate" regarding collection of phone records related to foreign intelligence or terrorism.

The Bush Administration is almost certainly violating the law by not getting the required court orders. If the program is as widespread as has been reported the Administration would have had to apply for and receive tens of millions of court orders. The Bush Administration may also have violated the Congressional oversight requirements of the statutes. Judging by the reaction in Congress today it appears that Congress was not fully briefed by the Administration.

The argument from the Administration will probably again be reduced to a defense on the President’s alleged inherent Article II powers as Commander-in-Chief during wartime. The President will argue that the Constitution gives him inherent authority to violate duly enacted laws in his capacity as Commander-in-Chief. This is a flimsy argument at best and is quite easily debunked. In the end the Administration is left with no Constitutional leg to stand on.

When the law and the Constitution are not on his side, the President can, in the final analysis, rely upon the Republican controlled Congress to turn a blind eye once more.