High Technology, Consumer Privacy, and U.S. National Security

High Technology, Consumer Privacy, and U.S. National Security
复制标题

高科技、消费者隐私和美国国家安全

DOI:
--
复制
发表时间:
2014
期刊:
影响因子:
--
通讯作者:
L. Donohue
L. Donohue
中科院分区:
--
文献类型:
--
作者:
L. Donohue

文献摘要

被引文献

相似文献

过去一年公布的文件详细说明了美国国家安全局(“NSA”)的电话元数据收集计划和根据《外国情报监视法》(FISA)拦截国际内容的情况,这些文件涉及美国高科技公司的政府监视。2013年6月5日,斯诺登披露的第一批文件显示,美国政府已向威瑞森发出命令,要求威瑞森根据《美国爱国者法案》第215条交出电话元数据。第二天,《卫报》发布了机密幻灯片,详细介绍了美国国家安全局如何根据《外国情报监视法修正案》第702条拦截国际内容。获得的信息类型包括电子邮件、视频和语音聊天、视频、照片和存储数据,以及互联网协议语音、文件传输、视频会议、目标活动通知和在线社交网络。这些公司看起来就像是美国互联网巨头的名人录:微软、雅虎、谷歌、Facebook、PalTalk、YouTube、Skype、AOL和苹果。随后,更多的文章强调了美国国家安全局在美国高科技产业中的地位。2013年9月,ProPublica和《纽约》透露,美国国家安全局在破解常用密码学方面取得了相当大的成功。次月《华盛顿邮报》报道称,美国国家安全局在未经涉案公司同意的情况下,获取了数百万客户的通讯录数据。仅在一天之内,就有大约444,743个电子邮件地址来自雅虎,105,068个来自Hotmail,82,857个来自Facebook,33,697个来自Gmail,22,881个来自其他供应商。上游收集的程度震惊了公众,同样震惊的还有展示NSA如何绕过这些公司加密的幻灯片,在公共互联网和谷歌云之间传输时拦截数据。文件还显示,NSA曾帮助推广一些加密标准,而NSA已经掌握了这些标准的密钥,或者NSA了解这些标准的漏洞,但没有采取措施解决。除此之外,媒体报道还显示,NSA有时会在美国公司不知情的情况下,冒充这些公司,以便接触外国目标。2013年11月,《明镜周刊》报道称,美国国家安全局和英国政府通信总部(GCHQ)创建了虚假版本的Slashdot和LinkedIn,因此当电信公司Belgacom的员工试图从公司电脑访问这些网站时,他们的请求被转移到复制网站,然后将恶意软件注入他们的机器。由于公众对这些问题的认识不断提高,美国公司失去了收入,而非美国公司却从中受益。此外,许多国家担心消费者隐私以及美国监控工作在经济和政治领域的渗透,加快了数据本地化举措,开始限制美国公司进入当地市场,并推出了新的隐私保护措施,这对未来的互联网治理和美国经济增长产生了影响。这些影响引起了人们对美国国家安全的担忧。可以说,其中一些影响,如数据本地化计划,只是机会主义-即,其他国家只是利用国家安全局的披露来促进国家的商业和政治利益。然而,即使是真的,NSA的计划也为其他国家提供了机会。他们削弱了美国在国际竞技场的影响力。国会有能力纠正目前的局面。第一,也是最重要的一点,《外国情报监视法》的改革将对国家安全局的监视活动施加更大的限制。其次,新的国内立法可以更好地保护消费者隐私。这些变化将使美国工业合法地要求改变环境,这将有助于他们获得竞争优势。第三,在国家安全基础设施的方案一级纳入经济关切将有助于确保经济事项在今后的国家安全决定中仍然占据中心地位。
Documents released over the past year detailing the National Security Agency’s (“NSA”) telephony metadata collection program and interception of international content under the Foreign Intelligence Surveillance Act (FISA) implicated U.S. high technology companies in government surveillance. The result was an immediate, and detrimental, impact on U.S. corporations, the economy, and U.S. national security.The first Snowden documents, printed on June 5, 2013, revealed that the government had served orders on Verizon, directing the company to turn over telephony metadata under Section 215 of the USA PATRIOT Act. The following day, The Guardian published classified slides detailing how the NSA had intercepted international content under Section 702 of the FISA Amendments Act. The type of information obtained ranged from E-mail, video and voice chat, videos, photos, and stored data, to Voice over Internet Protocol, file transfers, video conferencing, notifications of target activity, and online social networking. The companies involved read like a who’s who of U.S. Internet giants: Microsoft, Yahoo, Google, Facebook, PalTalk, YouTube, Skype, AOL, and Apple.More articles highlighting the extent to which the NSA had become embedded in the U.S. high tech industry followed. In September 2013 ProPublica and the New York Times revealed that the NSA had enjoyed considerable success in cracking commonly used cryptography. The following month the Washington Post reported that the NSA, without the consent of the companies involved, had obtained millions of customers’ address book data. In one day alone, some 444,743 email addresses from Yahoo, 105,068 from Hotmail, 82,857 from Facebook, 33,697 from Gmail, and 22,881 from other providers.The extent of upstream collection stunned the public, as did slides demonstrating how the NSA had bypassed the companies’ encryption, intercepting data as it transferred between the public Internet and the Google cloud. Documents further suggested that the NSA had helped to promote encryption standards for which it already held the key or whose vulnerabilities the agency understood but had not taken steps to address.Beyond this, press reports indicated that the NSA had at times posed as U.S. companies — without their knowledge — in order to gain access to foreign targets. In November 2013 Der Spiegel reported that the NSA and the United Kingdom’s Government Communications Headquarters (“GCHQ”) had created bogus versions of Slashdot and LinkedIn, so that when employees from the telecommunications firm Belgacom tried to access the sites from corporate computers, their requests were diverted to the replica sites that then injected malware into their machines.As a result of the growing public awareness of these programs, U.S. companies have lost revenues, even as non-U.S. firms have benefited. In addition, numerous countries, concerned about consumer privacy as well as the penetration of U.S. surveillance efforts in the economic and political spheres, have accelerated data localization initiatives, begun restricting U.S. companies’ access to local markets, and introduced new privacy protections, with implications for the future of Internet governance and U.S. economic growth. These effects raise attendant concerns about U.S. national security.It could be argued that some of these effects, such as data localization initiatives, are merely opportunistic — i.e., other countries are merely using the NSA revelations to advance national commercial and political interests. Even if true, however, the NSA programs provide other countries with an opportunity. They have weakened the U.S. hand in the international arena.Congress has the ability to redress the current situation. First, and most importantly, reform of the Foreign Intelligence Surveillance Act would provide for greater restrictions on NSA surveillance. Second, new domestic legislation could extend better protections to consumer privacy. These shifts would allow U.S. industry legitimately to claim a change in circumstance, which would help them to gain competitive ground. Third, the integration of economic concerns at a programmatic level within the national security infrastructure would help to ensure that economic matters remain central to national security determinations in the future.