Friday, July 11, 2008

FISA: By way of counterpoint

Marty Lederman has an interesting post, riffing off some FISA analysis over at the Volokoh Conspiracy:

I'm no legal scholar, so I can't vouch for Orin's analysis - but if his assertions are true, there are some good things happening in title I of the new FISA bill:
  • For the first time ever, surveillance of Americans abroad will require a court finding of probable cause to believe that the person is an agent of a foreign power
  • There is to be more congressional oversight. 
  • And, the new law requires the executive to adopt "minimization" procedures that comply with the traditional FISA minimization rules.
  • The law clarifies that "targeting" of foreign persons cannot be a pretext for obtaining information about U.S. persons. 
  • The FISA court can only approve the NSA's surveillance plan if it finds that the plan is consistent with the Fourth Amendment. 
  • it appears the FISA Court is suppose to conduct a de novo, rather than deferential, review of whether the NSA is complying with the statutory standards.
I'd take issue with the minimization measures, unless there there is verification of these procedures by someone outside of the executive, and some kind of enforcement clause.

If the FISA Court is truly going to adopt a new standard of review when it reviews warrant requests (something I am inferring from the last item) that would be encouraging - but something that I'll believe when I see the number of rejections spike.

Title II is still a total loss, as far as I'm concerned. I don't see any reason why Congress should rush to immunize conduct that has not been disclosed.


They've abandoned the (hopelessly dated) geographical requirement of FISA - and I don't think anyone would have a problem with this. The example of a foreign-to-foreign phone call that gets routed through a phone switch in NYC is something that doesn't need to fall under FISA. Under the old FISA, it would - and that was a big mistake. They've now fixed that, but  the other areas now under FISA are more troubling:


Like email.


Change that foreign-to-foreign communication to email and things get ugly in a hurry.

A phone call exists in real time - you hang up, it's gone. When the NSA eavesdrops on it, there are three locations: Person A, Person B, and the location of the wiretap.

Under old FISA, you need a warrant if the target, or the wiretap is in the US. If there is no target (or all the targets are outside the US) and the intercept takes place outside of the US - you don't need a FISA warrant.

Lots of flaws there - but they are all related to tracking both ends of a conversation, and the intercept.

Email makes the geographical requirement of FISA much worse.

Email persists, and is stored on many different computers. In other words, the conversation has its own geography.

Now you're tracking Person A, Person B, the intercept, and the physical location of the message.

So, two guys are in Pakistan emailing each other - the email gets routed and stored on a server in Oregon. Old FISA requires that they get a warrant for a targeted intercept, since the intercept is happening in the US.

During a phone call, the goverment can have a reasonable idea of where the parties are when they make the call. Email frees the participants from having a stable "end" of the conversation. They could access their email from a café, from their buddy's computer, while they're on a trip to Japan - whatever. At the point when you are reading their email on that server in Oregon, there's no way to know where the author or recipient are located.

It's a mess - and the single best reason for FISA getting an overhaul.

The beef I have is how this will apply to drift net intelligence. For thirty years, the NSA has been able to monitor all domestic-to-foreign communications in aggregate. Their computers scan for hot button words like "I'm going to hijack a plane" and flag conversations that the NSA finds interesting.

Again, this has its own problems - but email makes it worse. If the NSA wants to run drift net monitoring of foreign-to-foreign email on our hypothetical server in Oregon - they have virtually no way to distinguish between what's foreign, and what's not.

Under new FISA (as near as I can tell) they can drift net everything on the server, without a warrant. They cannot target a US citizen without a FISA warrant - but they can listen to everything in aggregate and retain copies. Assuming there is no outside body holding their feet to the fire on minimization, what's to say that some of those keywords can't be things like "Feingold" "Kennedy" and "Dodd"?

Not a hell of a lot.

No comments: