So, if I could basically accept gathering all meta-data in one place provided it was not under the control of the NSA or anyone else who could look at it, provided that looking at it required a court order and some degree of particularized suspicion, provided that adequate minimization procedures were employed to ensure that innocent data was not retained, and finally, provided that warrants were narrow enough to keep agents on a reasonably tight leash, why am I still leery about passing a law to allow it?
Basically, because the NSA's past behavior does not exactly inspire confidence. It has regularly either broken the law or stretched it so far as to make it meaningless and, when caught, declared that its actions were necessary for our security and gotten Congress to expand its powers. Once legislation expanding its powers was passed, it then either broke the new law or stretched it so far as to make it meaningless. Before I take another turn in this cycle, I want some sort of assurance that it will be the last one. And I don't want the new law simply to expand the NSA's powers to allow it to do all the questionable things it has been doing anyhow. I want the basic structure out in the open, even if, of course, the operational details must be kept secret. If having a collection of all meta-data is necessary, I want it authorized by law, not done by an absurd interpretation of an existing statute. I want it stored somewhere that neither the NSA nor any other law enforcement agency can access without a proper court order. I want a date after which the information must be destroyed. I want the court order held to standards that are not so vague as to be meaningless.
More than that, if we are going to grant the NSA this expansion in this power, I want it counterbalanced with some real restraints. Two have been suggested. The Supreme Court has never ruled on it, but several federal circuits, and the FISA court, have held that the Fourth Amendment does not apply to foreign intelligence. This means that there is no constitutional restrain on the executive branch's power to engage in foreign intelligence surveillance; the only constraints are the ones in the FISA statute. It is a normal and routine feature of our legal system that the courts make legally binding interpretations of statutes. Often a short and sparse statute may be little more than a skeleton, with the courts fleshing out these bare bones. (One of the reasons so many statutes run to hundreds of pages these days is to limit the courts' latitude). Court interpretation of statutes are on the public record, and if Congress does not like how a court has interpreted a statute, it may amend it. FISA is a notable exception. The FISA court works in secrecy. Only two cases under FISA have ever been appealed. The first one held that the FISA court may not build a "wall" between intelligence gathering and prosecution, and may not forbid law enforcement from participating in FISA surveillance. The other case rules that (1) communications companies have standing to appeal orders they consider unjust; (2) the Fourth Amendment does not apply to foreign intelligence; and (3) targeting a US person outside the United States did not require particularity to be reasonable. (What this last part means is somewhat vague in the absence of facts). Many people have suggested that, although operational details and routine matters should be kept secret, any legally significant interpretations of FISA by the lower FISA court should be published. It has also been suggested that, since obviously the target of surveillance cannot be warned and allowed to appeal, communications companies should be given that right, expressly. I favor both of these, along with more narrowing and particularity in what a FISA wiretap can do.
In short, before I listen to people saying we just have to expand the NSA's powers to do what they have already been doing, I want some assurance that it will finally stop here, and some institutional teeth build in.
Sunday, July 14, 2013
One Final Comment on Surveillance
Surveillance and Minimization Procedures
One thing that gets talked about a lot during the debate on surveillance are minimization procedures. What are minimization procedures. This is not something I know anything about, except what comes from court cases. Roughly speaking, though, even a completely legitimate wiretap will collect innocent information. Minimization procedures come in two kinds: Stopping the collection of data once it becomes clear that it is innocent, and getting rid of the innocent material that is invariable swept in.
In re Sealed Case No. 02-001, the only FISA opinion currently on public record, explains both types:
This should also provide some guidance on sifting through metadata. Since sifting through metadata more or less by definition involves sweeping in a great deal of innocent information, everything but specific patterns of metadata involving actual terrorists (or spies) should be discarded and destroyed.
____________________________________________
*A distinction not always as clear as one might wish.
**Just to make clear, at the time Zionists wishing to move to Israel were a distinct minority among Soviet Jews. Most were highly assimilated and had no desire to leave the only home they had. Nonetheless, Soviet mistreatment of Jews who did wish to move to Israel was inexcusable.
In re Sealed Case No. 02-001, the only FISA opinion currently on public record, explains both types:
[M]inimization procedures are designed to protect, as far as reasonable, against the acquisition, retention, and dissemination of nonpublic information which is not foreign intelligence information. If the data is not foreign intelligence information as defined by the statute, the procedures are to ensure that the government does not use the information to identify the target or third party, unless such identification is necessary to properly understand or assess the foreign intelligence information that is collected. Id. § 1801(h)(2). By minimizing acquisition, Congress envisioned that, for example, “where a switchboard line is tapped but only one person in the organization is the target, the interception should probably be discontinued where the target is not a party” to the communication. H. REP. at 55-56. By minimizing retention, Congress intended that “information acquired, which is not necessary for obtaining[,] producing, or disseminating foreign intelligence information, be destroyed where feasible.” H. REP. at 56.Zweibon v. Mitchell is a fine example of why minimization procedures are needed. Mitchell in this case refers to Richard Nixon's Attorney General. The case involved the Jewish Defense League, an organization widely known as a right wing terrorist group. It appears to have begun as something between a neighborhood watch and a vigilante organization* in the late 1960's, when black crime rates were surging and white flight was in full force. Upper middle class Jews moved to the suburbs, working class and Orthodox Jews, who could not afford to move, were frequent victims of black crime. It moved beyond mere defense to outright racism. In the 1970's, it became a champion of Soviet Jews denied visas to move to Israel.** Much of its activity was lawful -- anti-Soviet protests, demonstrations, and carrying signs. But it also engaged in numerous acts of terrorism against Soviet diplomatic facilities, airlines, and even the Bolshoi Ballet. Their activities jeopardized Nixon's policies of detente with the Soviet Union. The Soviets did not always make the distinction between lawful picketing and unlawful acts of violence; they just wanted the whole thing to stop. Clearly, then, since the Jewish Defense League was practicing terrorism that affected our foreign relations, wiretapping some of its activities was appropriate. But at the time it has approximately 15,000 members, most of whom were not involved with terrorism and conducted a great deal of lawful business. What was called for, then were strict minimization procedures. While it might be acceptable at first to listen in to its conversations in general, the government should be required to determine which connections were likely to lead to actual terrorism and which were not, and to stop listening in to the innocent ones and discard all such information. The temptation, since even the League's lawful activities were a foreign policy headache, was to listen in to everything.
This should also provide some guidance on sifting through metadata. Since sifting through metadata more or less by definition involves sweeping in a great deal of innocent information, everything but specific patterns of metadata involving actual terrorists (or spies) should be discarded and destroyed.
____________________________________________
*A distinction not always as clear as one might wish.
**Just to make clear, at the time Zionists wishing to move to Israel were a distinct minority among Soviet Jews. Most were highly assimilated and had no desire to leave the only home they had. Nonetheless, Soviet mistreatment of Jews who did wish to move to Israel was inexcusable.
Sunday, July 7, 2013
A Short Detour on Republicans and Obamacare
As Obamacare comes closer and closer to coming on line, Republicans are getting desperate how to stop it. I suppose I should give them credit for at least one thing. They are no longer claiming that it will be the end of all liberty or turn us into a Communist dictatorship or lead to T-4 or the mass murder of senior. Claiming such thing about something remote and far-off is one thing. Claiming it about something due to come online in about six months is another. It is too easily falsifiable to be even remotely plausible as a claim. Instead, Republicans are starting to make legitimate complaints about problems that might actually occur. They worry that employers will refuse to give people full time work to avoid paying for their insurance, or that premiums will rise, especially for the young and the healthy (with no mention of the subsidies that will help people afford those premiums).
Still, I do note that their objections look mighty shifty. Until the individual mandate was upheld by the Supreme Court, it was the absolute worst feature of the law. Individual mandate was the end of all liberty; it allowed government to dictate anything and everything people could do; government could even force people to eat broccoli. Law supporters responded that the individual mandate was necessary to prevent people from postponing buying health insurance until they were sick and sending the system into a death spiral. Well, now that the individual mandate has been upheld, it appears that the greatest flaw in the system is that it is not sufficiently enforced, that with such mild penalties, some people might decide not to buy insurance until they are sick and send the system into a death spiral. And, of course, they are doing their best to keep people from buying insurance and thereby accelerate the process. And they plan to run on repealing Obamacare in 2014.
Still and all, I see an obvious problem there. So far, it is hard to generate much enthusiasm about the program because very few people have benefited from it. But what happens when people do? Certainly, it appears that not as many people will sign up for insurance as we had hoped, but some will -- probably not a trivial number. And suddenly in 2014 running on a promise to repeal Obamacare will mean running on a promise to take people's health insurance away. That really looks like a losing proposition to me.
Or consider another matter. The statute provided for subsidies for people buying healthcare on state exchanges, but not on federal exchanges. The assumption was that all states would set up exchanges. In fact, some 28 states refused, so federal exchanges were substituted. The IRS implemented regulations allowing subsidies for people buying insurance on exchanges. Now various groups have sued to block the regulation. Granted, the regulation is legally and constitutionally suspect, but the problem is (theoretically) easy to solve simply by slightly modifying the originals statute to allow subsidies on either federal or state exchanges. So the question is not simply whether the regulation is statutorily or constitutionally sound, but also whether it wiser on either a political or a policy basis to block the regulation, rather than to correct the error. Defenders of the suit argue that it will protect employers from having to pay fines for not insuring employees if their employees are not eligible for the subsidy. Ignored is the more important effect -- that it will "protect" people who would otherwise want to buy insurance on the exchanges from getting subsidies to do so. So, there will be people wanting insurance, but unable to afford it and facing fines for not having it who will resent the law. And by narrowing the pool of people buying insurance, it will encourage a death spiral. So if your goal is to kill Obamacare, it makes perfect sense from a policy standpoint.
But consider the politics of it. Yes, if people buying insurance on federal exchanges are blocked from subsidies before January 1, 2014, they will be presented with promises of insurance they cannot afford and fines for not having it and be justifiably resentful. Arguments that Republicans are blocking their subsidies, or that people in a neighboring state with its own exchange are getting them will probably not go very far. Politically, it will work to Republicans' advantage. But the chances of that happening in the next since months at any higher a level than federal district court are not high. And the chances of the Supreme Court making it the national law of the land within that time are essentially nil. Which means that if the lawsuit succeeds, it will occur after people have already started getting subsidies to buy insurance and will suddenly have them cut off. The political pressure to fix the problem will be rapid and intense. And if it becomes clear that Republicans consider it a proud achievement to have cut off those subsidies and will move heaven and earth to keep anyone from getting them back -- well, I have to imagine they will pay a price at the polls.
Still, I do note that their objections look mighty shifty. Until the individual mandate was upheld by the Supreme Court, it was the absolute worst feature of the law. Individual mandate was the end of all liberty; it allowed government to dictate anything and everything people could do; government could even force people to eat broccoli. Law supporters responded that the individual mandate was necessary to prevent people from postponing buying health insurance until they were sick and sending the system into a death spiral. Well, now that the individual mandate has been upheld, it appears that the greatest flaw in the system is that it is not sufficiently enforced, that with such mild penalties, some people might decide not to buy insurance until they are sick and send the system into a death spiral. And, of course, they are doing their best to keep people from buying insurance and thereby accelerate the process. And they plan to run on repealing Obamacare in 2014.
Still and all, I see an obvious problem there. So far, it is hard to generate much enthusiasm about the program because very few people have benefited from it. But what happens when people do? Certainly, it appears that not as many people will sign up for insurance as we had hoped, but some will -- probably not a trivial number. And suddenly in 2014 running on a promise to repeal Obamacare will mean running on a promise to take people's health insurance away. That really looks like a losing proposition to me.
Or consider another matter. The statute provided for subsidies for people buying healthcare on state exchanges, but not on federal exchanges. The assumption was that all states would set up exchanges. In fact, some 28 states refused, so federal exchanges were substituted. The IRS implemented regulations allowing subsidies for people buying insurance on exchanges. Now various groups have sued to block the regulation. Granted, the regulation is legally and constitutionally suspect, but the problem is (theoretically) easy to solve simply by slightly modifying the originals statute to allow subsidies on either federal or state exchanges. So the question is not simply whether the regulation is statutorily or constitutionally sound, but also whether it wiser on either a political or a policy basis to block the regulation, rather than to correct the error. Defenders of the suit argue that it will protect employers from having to pay fines for not insuring employees if their employees are not eligible for the subsidy. Ignored is the more important effect -- that it will "protect" people who would otherwise want to buy insurance on the exchanges from getting subsidies to do so. So, there will be people wanting insurance, but unable to afford it and facing fines for not having it who will resent the law. And by narrowing the pool of people buying insurance, it will encourage a death spiral. So if your goal is to kill Obamacare, it makes perfect sense from a policy standpoint.
But consider the politics of it. Yes, if people buying insurance on federal exchanges are blocked from subsidies before January 1, 2014, they will be presented with promises of insurance they cannot afford and fines for not having it and be justifiably resentful. Arguments that Republicans are blocking their subsidies, or that people in a neighboring state with its own exchange are getting them will probably not go very far. Politically, it will work to Republicans' advantage. But the chances of that happening in the next since months at any higher a level than federal district court are not high. And the chances of the Supreme Court making it the national law of the land within that time are essentially nil. Which means that if the lawsuit succeeds, it will occur after people have already started getting subsidies to buy insurance and will suddenly have them cut off. The political pressure to fix the problem will be rapid and intense. And if it becomes clear that Republicans consider it a proud achievement to have cut off those subsidies and will move heaven and earth to keep anyone from getting them back -- well, I have to imagine they will pay a price at the polls.
NSA Meta-Data: What I Consider Reasonable
We know much less about what the NSA is doing than what the Postal Service is doing. Nonetheless, I believe that reasoning by analogy from what is acceptable for the postal service is a good way to decide what would be acceptable for the NSA.
We know that the NSA is collecting meta-data on all phone calls made in the country. What we do not know is what it is doing with all that information. The general guess is that it is doing one of two things. One possibility is that it is tracing calls of known and suspected terrorists to find their contacts and patterns of calls. For instance, if a terrorist attempts to thwart surveillance by changing phones, the new phone can be found by looking for a new number that has the same contacts and patterns of calls as the old one. It may trace terrorist phone numbers to find their contacts and calling patterns, and to see who needs further investigation. The other possibility is that the NSA is doing general data mining on this immense database, looking for possible patterns of terrorist activity. My position is that I consider the former use acceptable if appropriate safeguards are in place, and the latter use unacceptable. And I definitely do not want it to be within the NSA's unbridled discretion to decide what what it does with this immense database.
Why is overall data mining without particularized suspicion unacceptable to me? Maybe the simplest answer is that the invasion of privacy just feels creepy to me. Defenders would argue that I am being unreasonable, that my identity is not known to the people tracking my meta-data, that my meta-data is too small and insignificant to attract attention, and that nothing so abstract and impersonal could in any way be an invasion of privacy. I suppose my answer comes from Bruce Schneier. For data mining to be an effective tool, three conditions must be met. There must be a well-defined profile, reasonable frequency of attacks, and a low cost of false positives. Hence data mining works well for credit card fraud. Credit card fraud has a definable profile -- purchase of an expensive or easily fenced item, or a sudden change in the owner's spending habits. It is common -- out of 900 million credit cards in circulation in the US, about 1% are typically stolen or used fraudulently in a year. And the cost of a false alarm is no more than a phone call to verify that a purchase is genuine. Terrorism is a different matter altogether. It is by no means clear that there is a well-defined profile of a terrorist. But, even assuming that there is such a profile, terrorists are rare. Even a very low false alarm rate, false alarms will vastly outnumber real leads, to the point that frustrated law enforcement refers to them as "calls to Pizza Hut." Schneier focuses on this mostly as a waste of law enforcement resources, but it is more than that. It is an invasion of privacy for every innocent target investigated as a result of a false alarm. Then there is also the frustration factor in looking for a needle in a haystack and not finding one. The temptation will become great to sharpen a strand of hay and call it a needle. Certainly there is some evidence that at least some agencies, lacking terrorists to surveill, have gone looking for someone -- anyone -- else to keep an eye on. (Now if only someone could be caught conducting surveillance on the Tea Party!)
So, why is use of the entire national electronic communications database to track known and suspected terrorists acceptable to me? If there is a known target, why not use more conventional means to follow that target. Here I will have to plead lack of expertise and deference to the experts. The basic point appears to be that electronic communications are much more mobile, extensive, and easy to change than when most of the rules for wiretapping were made. People have more phones than in the past, and can switch numbers more quickly and easily. The pre-paid or disposable phone has replaced the pay phone as the best source of anonymity. And, of course, there are many forms of non-telephonic instant communication. So I am prepared to believe that given the mobility and interchangeability of communications these days, finding a terrorist every trying to evade surveillance might require access to a very large database. Maybe finding a terrorist's new phone by looking for a similar pattern really does call for extensive data mining. Maybe there are other uses in tracking terrorists that I never thought of.
What safeguards would I consider necessary for me to be comfortable with the NSA collecting all our electronic meta data? Probably something similar to what I would consider appropriate for the Postal Service. I consider it reassuring that in the case of the mail, the agency collecting meta-data and the agencies using it are separate. Even the minimal procedural barrier of having to make an application for information limits requests to cases of some sort of particularized suspicion. If the NSA is going to collect all our meta data, then the agency storing the data and the one using it should be separate. If the NSA is looking for something in the meta-data, it should require a court order and some sort of particularized suspicion. The current pen register rule for tracing contacts with a particular number is "relevance to an ongoing investigation." This is not a high standard. My understanding that it is theoretically what the NSA is still held to in its use of meta data, but it has evaded even that narrow standard by simply arguing that all meta data is relevant to its search for terrorist (can't find link). Clearly, then, something more specific is called for. I am open to persuasion as to whether it should require "specific and articulable facts" or even "probably cause," but simply that it might yield something some time is not enough. Regardless, once you authorize searching through such an immense database even with particularized suspicion, a lot of innocent data is going to be swept in. We therefore need stringent minimization procedures, that is rules forbidding follow-up on leads that turn out to be innocent, and destruction of information gathered that turns out to be innocent. And finally, on the subject of data destruction, we need some sort of expiration date on the information gathered. It may be that to properly trace a number requires information that dates back for a period of time, perhaps even years. But there must be a point beyond which the trail goes cold and the usefulness of meta-data is limited. No doubt there is always a faint possibility of some sort of use, but at some point it starts sounding like an excuse. We need an expiration date on meta data collected.
I intend to follow up with a few posts on other surveillance topics besides meta data.
We know that the NSA is collecting meta-data on all phone calls made in the country. What we do not know is what it is doing with all that information. The general guess is that it is doing one of two things. One possibility is that it is tracing calls of known and suspected terrorists to find their contacts and patterns of calls. For instance, if a terrorist attempts to thwart surveillance by changing phones, the new phone can be found by looking for a new number that has the same contacts and patterns of calls as the old one. It may trace terrorist phone numbers to find their contacts and calling patterns, and to see who needs further investigation. The other possibility is that the NSA is doing general data mining on this immense database, looking for possible patterns of terrorist activity. My position is that I consider the former use acceptable if appropriate safeguards are in place, and the latter use unacceptable. And I definitely do not want it to be within the NSA's unbridled discretion to decide what what it does with this immense database.
Why is overall data mining without particularized suspicion unacceptable to me? Maybe the simplest answer is that the invasion of privacy just feels creepy to me. Defenders would argue that I am being unreasonable, that my identity is not known to the people tracking my meta-data, that my meta-data is too small and insignificant to attract attention, and that nothing so abstract and impersonal could in any way be an invasion of privacy. I suppose my answer comes from Bruce Schneier. For data mining to be an effective tool, three conditions must be met. There must be a well-defined profile, reasonable frequency of attacks, and a low cost of false positives. Hence data mining works well for credit card fraud. Credit card fraud has a definable profile -- purchase of an expensive or easily fenced item, or a sudden change in the owner's spending habits. It is common -- out of 900 million credit cards in circulation in the US, about 1% are typically stolen or used fraudulently in a year. And the cost of a false alarm is no more than a phone call to verify that a purchase is genuine. Terrorism is a different matter altogether. It is by no means clear that there is a well-defined profile of a terrorist. But, even assuming that there is such a profile, terrorists are rare. Even a very low false alarm rate, false alarms will vastly outnumber real leads, to the point that frustrated law enforcement refers to them as "calls to Pizza Hut." Schneier focuses on this mostly as a waste of law enforcement resources, but it is more than that. It is an invasion of privacy for every innocent target investigated as a result of a false alarm. Then there is also the frustration factor in looking for a needle in a haystack and not finding one. The temptation will become great to sharpen a strand of hay and call it a needle. Certainly there is some evidence that at least some agencies, lacking terrorists to surveill, have gone looking for someone -- anyone -- else to keep an eye on. (Now if only someone could be caught conducting surveillance on the Tea Party!)
So, why is use of the entire national electronic communications database to track known and suspected terrorists acceptable to me? If there is a known target, why not use more conventional means to follow that target. Here I will have to plead lack of expertise and deference to the experts. The basic point appears to be that electronic communications are much more mobile, extensive, and easy to change than when most of the rules for wiretapping were made. People have more phones than in the past, and can switch numbers more quickly and easily. The pre-paid or disposable phone has replaced the pay phone as the best source of anonymity. And, of course, there are many forms of non-telephonic instant communication. So I am prepared to believe that given the mobility and interchangeability of communications these days, finding a terrorist every trying to evade surveillance might require access to a very large database. Maybe finding a terrorist's new phone by looking for a similar pattern really does call for extensive data mining. Maybe there are other uses in tracking terrorists that I never thought of.
What safeguards would I consider necessary for me to be comfortable with the NSA collecting all our electronic meta data? Probably something similar to what I would consider appropriate for the Postal Service. I consider it reassuring that in the case of the mail, the agency collecting meta-data and the agencies using it are separate. Even the minimal procedural barrier of having to make an application for information limits requests to cases of some sort of particularized suspicion. If the NSA is going to collect all our meta data, then the agency storing the data and the one using it should be separate. If the NSA is looking for something in the meta-data, it should require a court order and some sort of particularized suspicion. The current pen register rule for tracing contacts with a particular number is "relevance to an ongoing investigation." This is not a high standard. My understanding that it is theoretically what the NSA is still held to in its use of meta data, but it has evaded even that narrow standard by simply arguing that all meta data is relevant to its search for terrorist (can't find link). Clearly, then, something more specific is called for. I am open to persuasion as to whether it should require "specific and articulable facts" or even "probably cause," but simply that it might yield something some time is not enough. Regardless, once you authorize searching through such an immense database even with particularized suspicion, a lot of innocent data is going to be swept in. We therefore need stringent minimization procedures, that is rules forbidding follow-up on leads that turn out to be innocent, and destruction of information gathered that turns out to be innocent. And finally, on the subject of data destruction, we need some sort of expiration date on the information gathered. It may be that to properly trace a number requires information that dates back for a period of time, perhaps even years. But there must be a point beyond which the trail goes cold and the usefulness of meta-data is limited. No doubt there is always a faint possibility of some sort of use, but at some point it starts sounding like an excuse. We need an expiration date on meta data collected.
I intend to follow up with a few posts on other surveillance topics besides meta data.
Saturday, July 6, 2013
NSA Spying and the Postal Service
I will not attempt to figure out what is going on with the NSA, and what they are or are not spying on. What is known so far is that they are collecting all metadata on all phone calls in the US (and presumably the world). They have a warrant to do so, so the collection does not technically break the law, although it stretches it well past its reasonable elasticity. What is not known is how extensive use the NSA makes of the metadata it has collected. A warrant is required to listen in on domestic calls. It is not clear, however, whether that means an individual warrant, or a "basket warrant" of a broader group, allowing the NSA discretion to decide which individual numbers fit within the "basket." If the NSA inadvertently listens in on a domestic phone call, it must destroy the information, unless it reveals either a "threat of harm" or "criminal activity," which can be kept and passed on to the FBI. Not known is whether the NSA is using this loophole to circumvent the usual warrant requirement by "accidentally" listening in on as many domestic phone calls as possible. And the latest report is that the NSA is not just tracking all telephone meta-date, but even recording (though not listening to) all telephone calls. We don't know whether the NSA is collecting metadata on domestic e-mails. We believe it is not tapping in on everything that goes through the internet, but has developed a system that makes it easier to turn over information when required by court order. And not it appears that the Postal Service is keeping meta-data on all mail being sent, ready to be turned over to law enforcement.
Our information is too sketchy to do more than speculate about what is going on. I do not know enough about electronic surveillance to speculate intelligently. I will therefore consider what would be acceptable surveillance and what would not. A good place to start, and move onward by analogy, is the recent revelation that the Postal Service is keeping cover information on all mail sent in the US.
In some ways, the Postal Service story is less alarming than the rest. In that case, the Postal Service collected the meta-data on all letters, but only turns them over to law enforcement upon request. In other words, the agency collecting meta-data on letters is not the same as the one using it. Neither the NSA or any other law enforcement agency is given all the information to play with;* to obtain information law enforcement must have some sort of particularized suspicion. The Times story distinguishes between two uses of mail tracking by law enforcement. In the older version, dating back for a hundred years, law enforcement can ask the postal service to record the covers of all mail sent or received by a particular target. The newer program, adopted with the anthrax letters following 9-11, the Postal Service has routinely kept meta-data on all mail sent, and can provide meta-data on past letters sent upon request of law enforcement. One form of surveillance is prospective; the other retrospective. One could be used to follow and break up a plot as it progresses; the other is for solving crimes already committed.
But in another way, the Postal Service story is alarming. The threshold for turning over information is not high. No court order is required; law enforcement need only submit an application, which is almost never refused. (Opening mail requires a warrant, of course). And, unlike the NSA program which remains shadowy, the Postal Service program has had definite cases of abuse, and disturbing episodes. Sheriff Joe Arpaio (who else?) has been accused of using the program to trace mail on a political opponent. And the Times story begins with the account of Leslie James Pickering, a former spokesman for the Earth Liberation Front (ELF). ELF, it should be noted, is an eco-terrorist organization that engages in acts of sabotage, although it has not killed anyone so far, so surveillance of active members suspected of engaging in sabotage is legitimate. And although Pickering limited himself to propaganda on behalf of ELF and did not engage in actual violent acts, perhaps one could argue for surveillance on him on the grounds that he might lead law enforcement to violent members. But Pickering does not appear to have been actively involved with ELF for nearly a decade.
My ultimate conclusion is that I would be open to reforming, rather than abolishing, storage of meta-data on mail. Reform would follow three points:
First, the postal service must be limited to collecting meta-data and may not use the data itself. (So far as we know, this has been done).
Second, meta-data should be destroyed after a reasonable period of time. I do not know what a reasonable period of time is, but there must be some time after which the trail is too cold to be worth following. Data after this period of time should be destroyed.
Third and finally, a court order should be required. The act of submitting an application, even in the absence of scrutiny, is enough to limit use of mail meta-data to some sort of particularized suspicion, but the story makes clear that this is not safeguard enough, and that more is required.
Alas, I fear that evidence that the FBI may have improperly surveilled a former member of the ELF will not be enough to spur any serious reconsideration of the program. Improper surveillance of Operation Rescue, now, or the militia movement would lead to some action! Let's hope some such surveillance turns up.
_______________________________________
*So far as we know. It is entirely possible that the NSA is also vacuuming up the Postal Services' cover information as well.
Our information is too sketchy to do more than speculate about what is going on. I do not know enough about electronic surveillance to speculate intelligently. I will therefore consider what would be acceptable surveillance and what would not. A good place to start, and move onward by analogy, is the recent revelation that the Postal Service is keeping cover information on all mail sent in the US.
In some ways, the Postal Service story is less alarming than the rest. In that case, the Postal Service collected the meta-data on all letters, but only turns them over to law enforcement upon request. In other words, the agency collecting meta-data on letters is not the same as the one using it. Neither the NSA or any other law enforcement agency is given all the information to play with;* to obtain information law enforcement must have some sort of particularized suspicion. The Times story distinguishes between two uses of mail tracking by law enforcement. In the older version, dating back for a hundred years, law enforcement can ask the postal service to record the covers of all mail sent or received by a particular target. The newer program, adopted with the anthrax letters following 9-11, the Postal Service has routinely kept meta-data on all mail sent, and can provide meta-data on past letters sent upon request of law enforcement. One form of surveillance is prospective; the other retrospective. One could be used to follow and break up a plot as it progresses; the other is for solving crimes already committed.
But in another way, the Postal Service story is alarming. The threshold for turning over information is not high. No court order is required; law enforcement need only submit an application, which is almost never refused. (Opening mail requires a warrant, of course). And, unlike the NSA program which remains shadowy, the Postal Service program has had definite cases of abuse, and disturbing episodes. Sheriff Joe Arpaio (who else?) has been accused of using the program to trace mail on a political opponent. And the Times story begins with the account of Leslie James Pickering, a former spokesman for the Earth Liberation Front (ELF). ELF, it should be noted, is an eco-terrorist organization that engages in acts of sabotage, although it has not killed anyone so far, so surveillance of active members suspected of engaging in sabotage is legitimate. And although Pickering limited himself to propaganda on behalf of ELF and did not engage in actual violent acts, perhaps one could argue for surveillance on him on the grounds that he might lead law enforcement to violent members. But Pickering does not appear to have been actively involved with ELF for nearly a decade.
My ultimate conclusion is that I would be open to reforming, rather than abolishing, storage of meta-data on mail. Reform would follow three points:
First, the postal service must be limited to collecting meta-data and may not use the data itself. (So far as we know, this has been done).
Second, meta-data should be destroyed after a reasonable period of time. I do not know what a reasonable period of time is, but there must be some time after which the trail is too cold to be worth following. Data after this period of time should be destroyed.
Third and finally, a court order should be required. The act of submitting an application, even in the absence of scrutiny, is enough to limit use of mail meta-data to some sort of particularized suspicion, but the story makes clear that this is not safeguard enough, and that more is required.
Alas, I fear that evidence that the FBI may have improperly surveilled a former member of the ELF will not be enough to spur any serious reconsideration of the program. Improper surveillance of Operation Rescue, now, or the militia movement would lead to some action! Let's hope some such surveillance turns up.
_______________________________________
*So far as we know. It is entirely possible that the NSA is also vacuuming up the Postal Services' cover information as well.
Sunday, June 30, 2013
Another (Scandal) Bites the Dust
So, it appears that the IRS scandal is a big dud. Besides applying extra scrutiny to applications for tax exempt status containing the words "Tea Party," "Patriot," and "9-12," it also targeted groups with the words "progressive," "progress," "blue" and "occupy," and names containing reference to open source software. The reason it targeted groups saying they were dedicated to open source software was that some of these groups are really commercial and improperly seeking tax exempt status. It is quite probable that more conservative than liberal organizations received extra scrutiny, but this was not because of ideological bias, but simply because more conservative than liberal organizations were applying.
Still, it would be false to say that there is no problem at all. A commenter to Kevin Drum explains:
I would also add, the problem is also with the laws the IRS is enforcing. A 501(c)(4) organization is a "social welfare" organization. Although not allowed to endorse candidates or engage in openly partisan activities, it may engage in "civic," "educational," or "issue" activities that look very much like lobbying or grass roots lobbying. Some of them are simply PAC's (political action committees) under a very thin veneer of civic action. Nor is this limited to the right -- moveon.org is a 501(c)(4) organization, as are many others. Drawing the line between "educational" or "issues" advocacy, which is allowed by the tax code, and partisan or candidate activity which is not, is going to mean making hopelessly fine distinctions that make no sense to anyone. Any attempt to enforce it will necessarily mean relentless and heavy-handed scrutiny. The other alternative, of course, is to give up and not attempt to enforce the rule.
It would be nice if the initial impression that the IRS was violating the rights of right wingers led to some sort of impetus for reform. Maybe there should be more resources devoted to enforcement to allow a less heavy-handed approach. Or some sort of guidance should be offered. Or maybe (God forbid!) the law should be changed to eliminate the distinction between partisan and issue-oriented.
Oh, well. I can dream, can't I?
Still, it would be false to say that there is no problem at all. A commenter to Kevin Drum explains:
I worked in the field for several years, and while it'd be pretty easy to convince me that some of these organizations deserve closer scrutiny, the IRS' "screening" has been wildly disproportionate. Groups that are unquestionably above board have been in limbo for years, unable to start fundraising in earnest, because the IRS refuses to finally approve or reject their application for 501(c)3 status.He goes on to say that the Tea Party is probably experiencing the same problem -- some of its applications for tax exempt status are legitimate; some are not. The problem is that office in charge of deciding which organizations are legitimate lacks the resources to address the issue properly, so they cast a very broad net and unduly delay many organizations whose applications are legitimate. In other words, just because the IRS was not being partisan does not mean that all is well. It means that the problem is structural -- the IRS is poorly equipped to give proper and timely scrutiny to questionable applications.
I would also add, the problem is also with the laws the IRS is enforcing. A 501(c)(4) organization is a "social welfare" organization. Although not allowed to endorse candidates or engage in openly partisan activities, it may engage in "civic," "educational," or "issue" activities that look very much like lobbying or grass roots lobbying. Some of them are simply PAC's (political action committees) under a very thin veneer of civic action. Nor is this limited to the right -- moveon.org is a 501(c)(4) organization, as are many others. Drawing the line between "educational" or "issues" advocacy, which is allowed by the tax code, and partisan or candidate activity which is not, is going to mean making hopelessly fine distinctions that make no sense to anyone. Any attempt to enforce it will necessarily mean relentless and heavy-handed scrutiny. The other alternative, of course, is to give up and not attempt to enforce the rule.
It would be nice if the initial impression that the IRS was violating the rights of right wingers led to some sort of impetus for reform. Maybe there should be more resources devoted to enforcement to allow a less heavy-handed approach. Or some sort of guidance should be offered. Or maybe (God forbid!) the law should be changed to eliminate the distinction between partisan and issue-oriented.
Oh, well. I can dream, can't I?
Sunday, June 16, 2013
Why I Favor Violating the Rights of Right Wingers
Well, what I had hoped for has come to pass. The Obama Administration has infringed on the liberties of right wingers. I have reluctantly concluded that there is no other way to get civil liberties onto the radar screen. All presidents have a tendency to want to expand their own power. This tendency is trans-partisan and should not be too surprising. Indeed, it was one of the original assumptions when the Constitution was first drafted, that the executive (as well as the other branches) would seek to aggrandize its power. It was also assumed that the other branches would be equally protective of their own prerogatives and therefore hold each other in check. There were two things the Founding Fathers failed to take into account. One was political parties. If the same party controlled both the Presidency and Congress, members might be more interested in pursuing partisan advantage than in maintaining institutional prerogatives. One may say that this is short-sighted, that political power alternates between parties quite regularly, and that Congress should not want the President to have unchecked power once the other party comes to power. But, alas, people tend to be short-sighted on these things. The other, more baleful thing they failed to foresee was the national security state, with interests of its own apart from elective government, and with its ability to play on people's fears of foreign threats.
Ever since 9-11 (and possibly even before) the dynamic worked as follows: Every President, regardless of party, wants to expand the government's eavesdropping powers. If a Republican holds the White House and Republicans control Congress, they will happily give the President unlimited power, confident that he will never abuse it. If the Democrats control Congress, regardless of the party in the White House, they will not dare check the President's eavesdropping powers for fear of being labeled soft on terrorism. Ah, but if a Democrat holds the White House and Republicans control Congress, right wingers will fear they might be targets of surveillance and act to block it. That was what happened after Timothy McVeigh blew up the Oklahoma City Federal Building. Bill Clinton wanted expanded surveillance powers to watch right wing private armies. Right wingers freaked out, fearing that more mainstream organizations would be next, and blocked the expansion.
Unfortunately, this dynamic has failed until now. Two things (I suspect) have kept conservatives from freaking out over the massive powers of surveillance that the government has. One was that they were started by a Republican and therefore must be all right. The other is that the assumption thus far has always been that these powers will only be directed at someone else, and so conservatives have nothing to fear. Now several things have happened to make them less confident.
One is that the IRS has apparently been singling out "Tea Party," Patriot" and other conservative names for extra scrutiny when groups apply for tax exempt status under Regulation 501(c)(4). As I understand it 501(c)(4) is a loophole in the tax code that allows "civic leagues and other corporations operated exclusively for the promotion of "social welfare", such as civics and civics issues" to receive tax exempt status and does not have to report donors. While some such organizations are genuinely devoted to "charitable, educational, or recreational purposes," others are simply lobbying organizations by another name. While organizations that support a particular candidate or party are not tax exempt, "issues" advocacy groups can be. Some of the largest and most powerful lobbying and think tank organizations in the country are tax exempt under 501(c)(4). Apparently with the founding of the Tea Party, the IRS experienced a huge flood of applications for such status and started singling ones with Tea Party sorts of names out for special scrutiny to see if they were really political organizations in disguise. This was despite having approved tax exempt status for many larger and more powerful advocacy organizations, left and right, in the past. So, was this proper or improper, persecution of conservatives, or an attempt to prevent abuse of the tax code. I don't think we have the information yet to know. There is no evidence yet that the IRS has done anything illegal, but ample evidence that the law does not give the IRS enough guidance how to handle such requests.
Next, it turned out the Obama Administration obtained the phone records, first of an AP reporter and then of a Fox reporter, and their contacts. Both reporters appear to have published leaks that the Administration had legitimate national security reasons to want plugged. In both cases, the Administration obtained a warrant to search for the reporter's phone records, so no laws were broken. But to prosecute a reporter for publishing a leak, as well as the leaker who made it, is simply not done. And, in fact, the Obama Administration did not prosecute the reporter, but did obtain a warrant by indicating (almost certainly falsely) that it might. In other words, although the Administration did not technically break the law, it stretched it to the extreme fraying point. Also, given that it treated the AP reporter and the Fox reporter the same way, it seems reasonable to assume that a general war on leaks, not partisan animus, was the motive.
My impression is that right wingers were inclined to applaud when the Obama Administration stretched the law to get telephone records on the AP reporter, but a Fox reporter was a different matter altogether. Similarly, Democrats are eager to investigate the IRS targeting of the Tea Party, probably at least in hopes of expanding the investigation to earlier possible improper targeting of liberal groups. My impression, frankly, is that right wingers would be entirely happy to pass a law broadly expanding the government's power to subpoena reporters' telephone records, so long as Fox News, the Washington Times, the National Review, the Weekly Standard, talk radio, and other conservative outlets are exempted. They might also be quite happy to make a rule that conservative advocacy group could have tax exempt status, but liberal ones could not. But that isn't going to happen. Obvious ideological targeting will neither pass constitutional muster nor be acceptable to the broader public. So if right wingers want to protect themselves from intrusive government, they will have no choice but to protect others as an accidental side effect.
It was against this backdrop that revelations about NSA information collecting on telephone and online information were made. In other words, the right was primed to be suspicious and fear that after all, they and not just terrorists might be targets. Kevin Drum, in a column that (alas) I can no longer find, comments that any unchecked surveillance program is dangerous, and that just because there is no evidence yet that the NSA has been data mining Occupy Wall Street does not prevent some future administration from doing so. But I say, if you want this thing brought under control, forget about Occupy Wall Street. Point out that it could be used to data mine records of the Tea Party. Then we will get some action!
Ever since 9-11 (and possibly even before) the dynamic worked as follows: Every President, regardless of party, wants to expand the government's eavesdropping powers. If a Republican holds the White House and Republicans control Congress, they will happily give the President unlimited power, confident that he will never abuse it. If the Democrats control Congress, regardless of the party in the White House, they will not dare check the President's eavesdropping powers for fear of being labeled soft on terrorism. Ah, but if a Democrat holds the White House and Republicans control Congress, right wingers will fear they might be targets of surveillance and act to block it. That was what happened after Timothy McVeigh blew up the Oklahoma City Federal Building. Bill Clinton wanted expanded surveillance powers to watch right wing private armies. Right wingers freaked out, fearing that more mainstream organizations would be next, and blocked the expansion.
Unfortunately, this dynamic has failed until now. Two things (I suspect) have kept conservatives from freaking out over the massive powers of surveillance that the government has. One was that they were started by a Republican and therefore must be all right. The other is that the assumption thus far has always been that these powers will only be directed at someone else, and so conservatives have nothing to fear. Now several things have happened to make them less confident.
One is that the IRS has apparently been singling out "Tea Party," Patriot" and other conservative names for extra scrutiny when groups apply for tax exempt status under Regulation 501(c)(4). As I understand it 501(c)(4) is a loophole in the tax code that allows "civic leagues and other corporations operated exclusively for the promotion of "social welfare", such as civics and civics issues" to receive tax exempt status and does not have to report donors. While some such organizations are genuinely devoted to "charitable, educational, or recreational purposes," others are simply lobbying organizations by another name. While organizations that support a particular candidate or party are not tax exempt, "issues" advocacy groups can be. Some of the largest and most powerful lobbying and think tank organizations in the country are tax exempt under 501(c)(4). Apparently with the founding of the Tea Party, the IRS experienced a huge flood of applications for such status and started singling ones with Tea Party sorts of names out for special scrutiny to see if they were really political organizations in disguise. This was despite having approved tax exempt status for many larger and more powerful advocacy organizations, left and right, in the past. So, was this proper or improper, persecution of conservatives, or an attempt to prevent abuse of the tax code. I don't think we have the information yet to know. There is no evidence yet that the IRS has done anything illegal, but ample evidence that the law does not give the IRS enough guidance how to handle such requests.
Next, it turned out the Obama Administration obtained the phone records, first of an AP reporter and then of a Fox reporter, and their contacts. Both reporters appear to have published leaks that the Administration had legitimate national security reasons to want plugged. In both cases, the Administration obtained a warrant to search for the reporter's phone records, so no laws were broken. But to prosecute a reporter for publishing a leak, as well as the leaker who made it, is simply not done. And, in fact, the Obama Administration did not prosecute the reporter, but did obtain a warrant by indicating (almost certainly falsely) that it might. In other words, although the Administration did not technically break the law, it stretched it to the extreme fraying point. Also, given that it treated the AP reporter and the Fox reporter the same way, it seems reasonable to assume that a general war on leaks, not partisan animus, was the motive.
My impression is that right wingers were inclined to applaud when the Obama Administration stretched the law to get telephone records on the AP reporter, but a Fox reporter was a different matter altogether. Similarly, Democrats are eager to investigate the IRS targeting of the Tea Party, probably at least in hopes of expanding the investigation to earlier possible improper targeting of liberal groups. My impression, frankly, is that right wingers would be entirely happy to pass a law broadly expanding the government's power to subpoena reporters' telephone records, so long as Fox News, the Washington Times, the National Review, the Weekly Standard, talk radio, and other conservative outlets are exempted. They might also be quite happy to make a rule that conservative advocacy group could have tax exempt status, but liberal ones could not. But that isn't going to happen. Obvious ideological targeting will neither pass constitutional muster nor be acceptable to the broader public. So if right wingers want to protect themselves from intrusive government, they will have no choice but to protect others as an accidental side effect.
It was against this backdrop that revelations about NSA information collecting on telephone and online information were made. In other words, the right was primed to be suspicious and fear that after all, they and not just terrorists might be targets. Kevin Drum, in a column that (alas) I can no longer find, comments that any unchecked surveillance program is dangerous, and that just because there is no evidence yet that the NSA has been data mining Occupy Wall Street does not prevent some future administration from doing so. But I say, if you want this thing brought under control, forget about Occupy Wall Street. Point out that it could be used to data mine records of the Tea Party. Then we will get some action!
Labels:
Partisan politics,
Surveillance,
War on Terror
Subscribe to:
Posts (Atom)