Technology Review - Published By MIT
Advertisement

The Total Information Awareness Project Lives On

Continued from page 2

By Mark Williams

Wednesday, April 26, 2006

smaller text tool iconmedium text tool iconlarger text tool icon

Beyond these programs, additionally, there exist all the data-mining applications currently employed in the private sector for purposes like detecting credit card fraud or predicting health risks for insurance. All the information thus generated goes into databases that, given sufficient government motivation or merely the normal momentum of future history, may sooner or later be accessible to the authorities.

How should data-mining technologies like TIA be regulated in a democracy? It makes little sense to insist on rigid interpretations of FISA. This isn't only because when the law was passed by Congress 30 years ago, terrorist threats on al Qaeda's scale did not yet exist and technological developments hadn't gone so far in potentially giving unprecedented destructive power to small groups and even individuals. Today's changed technological context, additionally, invalidates FISA's basic assumptions.

In an essay published next month in the New York University Review of Law and Security, titled "Whispering Wires and Warrantless Wiretaps: Data Mining and Foreign Intelligence Surveillance," K. Taipale, executive director of the Center for Advanced Studies in Science and Technology Policy, points out that in 1978, when FISA was drafted, it made sense to speak exclusively about intercepting a targeted communication, where there were usually two known ends and a dedicated communication channel that could be wiretapped.

With today's networks, however, data and increasingly voice communications are broken into discrete packets. Intercepting such communications requires that filters be deployed at various communication nodes to scan all passing traffic with the hope of finding and extracting the packets of interest and reassembling them. Thus, even targeting a specific message from a known sender today generally requires scanning and filtering the entire communication flow in which it's embedded. Given that situation, FISA is clearly inadequate because, Taipale argues, were it to be "applied strictly according to its terms prior to any 'electronic surveillance' of foreign communication flows passing through the U.S. or where there is a substantial likelihood of intercepting U.S. persons, then no automated monitoring of any kind could occur."

Taipale proposes not that FISA should be discarded, but that it should be modified to allow for the electronic surveillance equivalent of a Terry stop -- under U.S. law, the brief "stop and frisk" of a person by a law enforcement officer based on the legal standard of reasonable suspicion. In the context of automated data mining, it would mean that if suspicion turned out to be unjustified, after further monitoring, it would be discontinued. If, on the other hand, continued suspicion was reasonable, then it would continue, and at a certain point be escalated so that human agents would be called in to decide whether a suspicious individual's identity should be determined and a FISA warrant issued.

To attempt to maintain FISA and the rest of our current laws about privacy without modifications to address today's changed technological context, Taipale insists, amounts to a kind of absolutism that is ultimately self-defeating. For example, one of the technologies in the original TIA project, the Genisys Privacy Protection program, was intended to enable greater access to data for security reasons while simultaneously protecting individuals' privacy by providing critical data to analysts via anonymized transaction data and by exposing identity only if evidence and appropriate authorization was obtained for further investigation. Ironically, Genisys was the one technology that definitely had its funding terminated and was not continued by another government agency after the public outcry over TIA.

Home page image is available under GNU Free Documentation License 1.2. Caption: Original logo of the now-defunct Total Information Awareness Office, which drew much criticism for its "spooky" images.

Comments

  • TIA
    Time to fire up the old PGP.
    Rate this comment: 12345
    Guest (bill)
    04/26/2006
    Posts:1
    • PGP
      What is PGP?
      Rate this comment: 12345
      Guest (Sam)
      04/26/2006
      Posts:1
      • tia
        encryption; google "pgp"
        Rate this comment: 12345
        Guest (sid)
        04/26/2006
        Posts:1
  • PGP
    It may hide the content but the NSA will still know who's talking to who.
    Rate this comment: 12345
    Guest (Tom)
    04/26/2006
    Posts:1
    • PGP / TOR
      TOR.  From the same Navy that John Poindexter was an admiral in.  TOR is to traffic analysis as PGP is to message content.  Google 6,266,704 and feel lucky.
      Rate this comment: 12345
      Guest (quercetin)
      04/29/2006
      Posts:1
  • PGP
    The more who encrypt, the more unweildy TIA will become
    Rate this comment: 12345
    Guest (P1)
    04/26/2006
    Posts:1
  • Orwellian TIA
    Stop Big Brother NOW!
    Rate this comment: 12345
    Guest (Vic Anderson)
    04/30/2006
    Posts:1
  • TIA
    Is not more new and mere weared informatic idea?
    Rate this comment: 12345
    Guest (Vladimir)
    05/01/2006
    Posts:1
    • TIA
      Yes and no. Increasing the ability to exchange greater amounts of information over a wider area should definately be considered improvement; but if an individual is stripped of the ability to choose who he wants to share that information with, a freer exchange of information can be invasive, and threatening.
      Rate this comment: 12345
      Guest (pud)
      05/03/2006
      Posts:1
  • Confidential but threatening information
    How can we identify and extract only threatening information, and leave the rest secret?  How can we professionalize the persons handling that information?  Threatening information about any person or entity should be available only to profesionalized persons following lawful regulations, employed by lawful entities responsible for protecting the community.
    Rate this comment: 12345
    Guest (owennmtz)
    07/14/2006
    Posts:1
    • Threatening Informatoin?
      Seems like we are protecting the repulic ( entrenched power holders) NOT the public. Of what value are individual rights when the power base is threatened? Where is the ACLU?
      Rate this comment: 12345
      Guest (Dale)
      07/14/2006
      Posts:1
      • Where's the ACLU?
        Thank goodness they weren't officed in the WTC or they wouldn't have known it was coming either!!!  They'd be dead.  Yea, who needs intelligence?  Clinton was right...burp!
        Rate this comment: 12345
        Guest (clan_enoch)
        07/14/2006
        Posts:1
        • Re: Where's the ACLU?
          Thank Goodness they didn't have offices in WTC? One of the WTC buildings had an outpost for the CIA New York City office where the US corporate execs after foreign travel would be debriefed, etc. Administrative functions primarily. Do you think anyone would have just intentionally disregarded the information in order to observe what to the buildings can happen to see had the specific threat of that attack been caught in advance? If so then you are a scoundrel who projects his own ignorance upon others.
          Rate this comment: 12345

          forexmant
          01/18/2010
          Posts:1

Log In

Forgot your password?     Register »
Advertisement

Videos

Malleable Maps, Artistic Robots and Bubble Interfaces
Technology Review January/February 2010

Current Issue

Security in the Ether
Information technology's next grand challenge will be to secure the cloud--and prove we can trust it.
Advertisement
Advertisement
Advertisement
Subscribe to Technology Review's daily e-mail update. Enter your e-mail address

TECHNOLOGY RESOURCES
Advertisement
MIT Massachusetts Institute of Technology © 2010 Technology Review. All Rights Reserved.