Snowden Disclosures Finally Hit 12 on a Scale of 1 to 10


A few days ago, NBC News quoted a former intelligence official about the fallout from Edward Snowden’s NSA leaks. “The damage, on a scale of 1 to 10, is a 12,” he said.

At the time, I thought it was an odd thing to say. Obviously Snowden’s leaks have been damaging to the NSA, and just as obviously they’ve caused the NSA enormous PR problems. Still, we’ve known for years that they were collecting telephone metadata. We’ve known they were subpoenaing email and online documents from tech providers like Google and Microsoft. We’ve known they were monitoring switching equipment and fiber optic cables. We certainly know a lot more details about this stuff than we used to, but the basic outline of NSA’s capabilities hasn’t really come as much of a surprise.

So what was this former intelligence official talking about? I suspect it was this:

The agency has circumvented or cracked much of the encryption, or digital scrambling, that guards global commerce and banking systems, protects sensitive data like trade secrets and medical records, and automatically secures the e-mails, Web searches, Internet chats and phone calls of Americans and others around the world, the documents show.

….Some of the agency’s most intensive efforts have focused on the encryption in universal use in the United States, including Secure Sockets Layer, or SSL; virtual private networks, or VPNs; and the protection used on fourth-generation, or 4G, smartphones.

….By this year, the Sigint Enabling Project had found ways inside some of the encryption chips that scramble information for businesses and governments, either by working with chipmakers to insert back doors or by exploiting security flaws, according to the documents. The agency also expected to gain full unencrypted access to an unnamed major Internet phone call and text service; to a Middle Eastern Internet service; and to the communications of three foreign governments.

….[In 2010, a] briefing document claims that the agency had developed “groundbreaking capabilities” against encrypted Web chats and phone calls. Its successes against Secure Sockets Layer and virtual private networks were gaining momentum.

But the agency was concerned that it could lose the advantage it had worked so long to gain, if the mere “fact of” decryption became widely known. “These capabilities are among the Sigint community’s most fragile, and the inadvertent disclosure of the simple ‘fact of’ could alert the adversary and result in immediate loss of the capability,” a GCHQ document warned.

That’s a 12 on a scale of 1 to 10. The Snowden documents don’t make clear precisely what NSA’s capabilities are, or exactly what kind of encryption it can break. Nor is it clear how many of its new capabilities are truly due to mathematical breakthroughs of some kind, and how many are more prosaic hacking exploits that have given them more encryption keys than in the past.

Nonetheless, this is truly information that plenty of bad guys probably didn’t know, and probably didn’t have much of an inkling about. It’s likely that many or most of them figured that ordinary commercial crypto provided sufficient protection, which in turn meant that it wasn’t worth the trouble to implement strong crypto, which is a bit of a pain in the ass. (Recall, for example, Glenn Greenwald’s admission that he “almost lost one of the biggest leaks in national-security history” because Snowden initially insisted on communicating with strong crypto and Greenwald didn’t want to be bothered to install it.)

But now that’s all changed. Now every bad guy in the world knows for a fact that commercial crypto won’t help them, and the ones with even modest smarts will switch to strong crypto techniques that remain unbreakable. It’s still a pain in the ass, but it’s not that big a pain in the ass.

For what it’s worth, this is about the point where I get off the Snowden train. It’s true that some of these disclosures are of clear public interest. In particular, I’m thinking about the details of NSA efforts to infiltrate and corrupt the standards setting groups that produce commercial crypto schemes.

But the rest of it is a lot more dubious. It’s not clear to me how disclosing NSA’s decryption breakthroughs benefits the public debate much, unlike previous disclosures that have raised serious questions about the scope and legality of NSA’s surveillance of U.S. persons. Conversely, it’s really easy to see how disclosing them harms U.S. efforts to keep up our surveillance on genuine bad guys. Unlike previous rounds of disclosures, I’m a lot less certain that this one should have seen the light of day.

WE'LL BE BLUNT

It is astonishingly hard keeping a newsroom afloat these days, and we need to raise $253,000 in online donations quickly, by October 7.

The short of it: Last year, we had to cut $1 million from our budget so we could have any chance of breaking even by the time our fiscal year ended in June. And despite a huge rally from so many of you leading up to the deadline, we still came up a bit short on the whole. We can’t let that happen again. We have no wiggle room to begin with, and now we have a hole to dig out of.

Readers also told us to just give it to you straight when we need to ask for your support, and seeing how matter-of-factly explaining our inner workings, our challenges and finances, can bring more of you in has been a real silver lining. So our online membership lead, Brian, lays it all out for you in his personal, insider account (that literally puts his skin in the game!) of how urgent things are right now.

The upshot: Being able to rally $253,000 in donations over these next few weeks is vitally important simply because it is the number that keeps us right on track, helping make sure we don't end up with a bigger gap than can be filled again, helping us avoid any significant (and knowable) cash-flow crunches for now. We used to be more nonchalant about coming up short this time of year, thinking we can make it by the time June rolls around. Not anymore.

Because the in-depth journalism on underreported beats and unique perspectives on the daily news you turn to Mother Jones for is only possible because readers fund us. Corporations and powerful people with deep pockets will never sustain the type of journalism we exist to do. The only investors who won’t let independent, investigative journalism down are the people who actually care about its future—you.

And we need readers to show up for us big time—again.

Getting just 10 percent of the people who care enough about our work to be reading this blurb to part with a few bucks would be utterly transformative for us, and that's very much what we need to keep charging hard in this financially uncertain, high-stakes year.

If you can right now, please support the journalism you get from Mother Jones with a donation at whatever amount works for you. And please do it now, before you move on to whatever you're about to do next and think maybe you'll get to it later, because every gift matters and we really need to see a strong response if we're going to raise the $253,000 we need in less than three weeks.

payment methods

WE'LL BE BLUNT

It is astonishingly hard keeping a newsroom afloat these days, and we need to raise $253,000 in online donations quickly, by October 7.

The short of it: Last year, we had to cut $1 million from our budget so we could have any chance of breaking even by the time our fiscal year ended in June. And despite a huge rally from so many of you leading up to the deadline, we still came up a bit short on the whole. We can’t let that happen again. We have no wiggle room to begin with, and now we have a hole to dig out of.

Readers also told us to just give it to you straight when we need to ask for your support, and seeing how matter-of-factly explaining our inner workings, our challenges and finances, can bring more of you in has been a real silver lining. So our online membership lead, Brian, lays it all out for you in his personal, insider account (that literally puts his skin in the game!) of how urgent things are right now.

The upshot: Being able to rally $253,000 in donations over these next few weeks is vitally important simply because it is the number that keeps us right on track, helping make sure we don't end up with a bigger gap than can be filled again, helping us avoid any significant (and knowable) cash-flow crunches for now. We used to be more nonchalant about coming up short this time of year, thinking we can make it by the time June rolls around. Not anymore.

Because the in-depth journalism on underreported beats and unique perspectives on the daily news you turn to Mother Jones for is only possible because readers fund us. Corporations and powerful people with deep pockets will never sustain the type of journalism we exist to do. The only investors who won’t let independent, investigative journalism down are the people who actually care about its future—you.

And we need readers to show up for us big time—again.

Getting just 10 percent of the people who care enough about our work to be reading this blurb to part with a few bucks would be utterly transformative for us, and that's very much what we need to keep charging hard in this financially uncertain, high-stakes year.

If you can right now, please support the journalism you get from Mother Jones with a donation at whatever amount works for you. And please do it now, before you move on to whatever you're about to do next and think maybe you'll get to it later, because every gift matters and we really need to see a strong response if we're going to raise the $253,000 we need in less than three weeks.

payment methods

We Recommend

Latest

Sign up for our free newsletter

Subscribe to the Mother Jones Daily to have our top stories delivered directly to your inbox.

Get our award-winning magazine

Save big on a full year of investigations, ideas, and insights.

Subscribe

Support our journalism

Help Mother Jones' reporters dig deep with a tax-deductible donation.

Donate