NSA's Alexander to Black Hats: Trust us, we need you

 

Connecting state and local government leaders

Gen. Keith Alexander traveled to the "technical center of gravity" instead of appearing before Congress to plead his case that surveillance programs are targeted, limited and under control.

National Security Agency director Gen. Keith Alexander’s appeal last week to a gathering of hackers, security professionals and researchers at the Black Hat Briefings in Las Vegas reflected not only the significance of intell-gathering programs but the weight the cybersecurity community carries with the NSA.

The importance he placed on the Black Hat venue was illustrated by the fact that Alexander chose to appear at the conference, while sending a deputy to testify before a Senate Judiciary Committee hearing that same morning at which declassified information about the programs was presented. He said the cybersecurity community’s understanding was essential to supporting the NSA’s credibility.

Alexander travelled to what he called “the world’s technical center of gravity” to plead his case that controversial surveillance programs established after Sept. 11, 2001, are targeted, limited and governed by strong technical controls, agency policy and judicial oversight that limit the ability of analysts to access data being gathered on domestic phone calls.

“The controls that go onto this database” are greater than on any other maintained by NSA, Alexander said in his keynote address. The agency gathers only metadata about domestic phone calls, he said. “They do not include the contents of the call,” or names and addresses or participants.

The programs, first leaked by expatriate and former NSA contractor Edward Snowden, have been described in news articles and congressional hearings, but Alexander said, “all the facts are not on the table,” and “I promise you the truth,” although not necessarily the whole truth. He added some details about how the programs are administered and controlled and their role in thwarting a dozen terrorist attacks in the United States.

He said the Snowden leaks have done “significant and irreversible” damage to national security.

“If you are not satisfied with the current situation, help us find a better solution,” he said.

Despite some skepticism, the talk was well received by the packed ballroom. There was a shouted expletive indicating disbelief when Alexander said “we stand for freedom,” which received scattered applause, but the greatest applause was for his measured response to the few hecklers.

Alexander described the limitations of the two programs. The Foreign Intelligence Surveillance Act Amendments Act of 2008 allows the NSA to sweep up metadata of phone calls from U.S. service providers, including the time of the call, the number called and the number called from, its duration and its origin. This is used to help connect the dots in information gathered from the second program, known as PRISM, under Section 702 of the act, a lawful intercept program that can be used to listen in on communications of foreign nationals.

Queries of the domestic call database must be authorized. Alexander said only 22 people at NSA can place a U.S. telephone number on the list of numbers that can be queried, and only 35 analysts are authorized to query those numbers. Alexander said that fewer than 300 numbers were placed on the query list in 2012, and these resulted in 12 reports to the FBI for follow-up within the United States.

“We stopped 13 terrorist related activities in the United States,” since the programs began in 2007, Alexander said. Twelve of those investigations used phone data gathered under the Section 215 program, which provided “good information” in eight of those cases.

One of the cases involved the 2009 arrest of Najibullah Zazi in a plot to bomb the New York subway system. Alexander said Zazi was identified when the NSA notified the FBI that a suspected terrorist in Pakistan had called Zazi’s Colorado phone number.

Alexander said repeatedly, “These are facts,” and emphasized that the surveillance programs are under strict oversight by the NSA’s own directory of compliance as well as the secret FISA Court and Congress. He said a Senate Select Intelligence Committee study of four years of operations found no NSA violations. “No one at NSA has ever gone outside the boundaries we’ve been given,” he said.

He offered little documented information about the classified programs to support his assertions, but the presentation generally received high marks, even if it did not convince everyone.

“There is nothing that he could do to persuade” hardcore skeptics in the audience, said John Dickson, former Air Force security officer and CTO of the Denim Group, an application security consultancy. But he did a good job of steering a middle path between preaching to the choir and confronting hostile listeners. “I thought he made a forceful argument,” Dickson said.

X
This website uses cookies to enhance user experience and to analyze performance and traffic on our website. We also share information about your use of our site with our social media, advertising and analytics partners. Learn More / Do Not Sell My Personal Information
Accept Cookies
X
Cookie Preferences Cookie List

Do Not Sell My Personal Information

When you visit our website, we store cookies on your browser to collect information. The information collected might relate to you, your preferences or your device, and is mostly used to make the site work as you expect it to and to provide a more personalized web experience. However, you can choose not to allow certain types of cookies, which may impact your experience of the site and the services we are able to offer. Click on the different category headings to find out more and change our default settings according to your preference. You cannot opt-out of our First Party Strictly Necessary Cookies as they are deployed in order to ensure the proper functioning of our website (such as prompting the cookie banner and remembering your settings, to log into your account, to redirect you when you log out, etc.). For more information about the First and Third Party Cookies used please follow this link.

Allow All Cookies

Manage Consent Preferences

Strictly Necessary Cookies - Always Active

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Sale of Personal Data, Targeting & Social Media Cookies

Under the California Consumer Privacy Act, you have the right to opt-out of the sale of your personal information to third parties. These cookies collect information for analytics and to personalize your experience with targeted ads. You may exercise your right to opt out of the sale of personal information by using this toggle switch. If you opt out we will not be able to offer you personalised ads and will not hand over your personal information to any third parties. Additionally, you may contact our legal department for further clarification about your rights as a California consumer by using this Exercise My Rights link

If you have enabled privacy controls on your browser (such as a plugin), we have to take that as a valid request to opt-out. Therefore we would not be able to track your activity through the web. This may affect our ability to personalize ads according to your preferences.

Targeting cookies may be set through our site by our advertising partners. They may be used by those companies to build a profile of your interests and show you relevant adverts on other sites. They do not store directly personal information, but are based on uniquely identifying your browser and internet device. If you do not allow these cookies, you will experience less targeted advertising.

Social media cookies are set by a range of social media services that we have added to the site to enable you to share our content with your friends and networks. They are capable of tracking your browser across other sites and building up a profile of your interests. This may impact the content and messages you see on other websites you visit. If you do not allow these cookies you may not be able to use or see these sharing tools.

If you want to opt out of all of our lead reports and lists, please submit a privacy request at our Do Not Sell page.

Save Settings
Cookie Preferences Cookie List

Cookie List

A cookie is a small piece of data (text file) that a website – when visited by a user – asks your browser to store on your device in order to remember information about you, such as your language preference or login information. Those cookies are set by us and called first-party cookies. We also use third-party cookies – which are cookies from a domain different than the domain of the website you are visiting – for our advertising and marketing efforts. More specifically, we use cookies and other tracking technologies for the following purposes:

Strictly Necessary Cookies

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Functional Cookies

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Performance Cookies

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Sale of Personal Data

We also use cookies to personalize your experience on our websites, including by determining the most relevant content and advertisements to show you, and to monitor site traffic and performance, so that we may improve our websites and your experience. You may opt out of our use of such cookies (and the associated “sale” of your Personal Information) by using this toggle switch. You will still see some advertising, regardless of your selection. Because we do not track you across different devices, browsers and GEMG properties, your selection will take effect only on this browser, this device and this website.

Social Media Cookies

We also use cookies to personalize your experience on our websites, including by determining the most relevant content and advertisements to show you, and to monitor site traffic and performance, so that we may improve our websites and your experience. You may opt out of our use of such cookies (and the associated “sale” of your Personal Information) by using this toggle switch. You will still see some advertising, regardless of your selection. Because we do not track you across different devices, browsers and GEMG properties, your selection will take effect only on this browser, this device and this website.

Targeting Cookies

We also use cookies to personalize your experience on our websites, including by determining the most relevant content and advertisements to show you, and to monitor site traffic and performance, so that we may improve our websites and your experience. You may opt out of our use of such cookies (and the associated “sale” of your Personal Information) by using this toggle switch. You will still see some advertising, regardless of your selection. Because we do not track you across different devices, browsers and GEMG properties, your selection will take effect only on this browser, this device and this website.