{"id":649,"date":"2014-02-03T22:37:20","date_gmt":"2014-02-04T03:37:20","guid":{"rendered":"http:\/\/greatapes.ca\/blog\/?p=649"},"modified":"2014-02-04T00:44:30","modified_gmt":"2014-02-04T05:44:30","slug":"lies-and-spies-and-all-five-eyes-whats-going-on-at-csec","status":"publish","type":"post","link":"http:\/\/greatapes.ca\/blog\/2014\/02\/lies-and-spies-and-all-five-eyes-whats-going-on-at-csec\/","title":{"rendered":"Lies and Spies and All Five Eyes: What&#8217;s Going On At CSEC?"},"content":{"rendered":"<p>While the NSA in the United States and GCHQ have come under a lot of scrutiny and criticism for their actions in terms of mass surveillance of their citizens, the role that CSEC (the Canadian equivalent) has played has been subject to significantly less attention.\u00a0 All three countries are part of an intelligence sharing program called Five Eyes that also includes Australia and New Zealand.\u00a0 If you follow me on Twitter or Facebook or wherever else you may have noticed that I&#8217;ve spent a lot of time complaining that Canada&#8217;s role in the coalition had not been reported on nearly enough and that our intelligence services were surely involved in some of the misdeeds that the other spy organisations were taking part in.<\/p>\n<p>A few details began trickling out last fall, but nothing like the broad public surveillance that had been revealed in the U.S. or Britain.\u00a0 Back in October it was reported that <a href=\"http:\/\/www.theglobeandmail.com\/news\/world\/canadas-hacking-power-awes-brazilian-security-expert\/article14850467\/\">CSEC had hacked the Brazilian Ministry of Mines and Energy<\/a> but that was economic espionage, not mass surveillance.\u00a0 In late November the <a href=\"http:\/\/www.cbc.ca\/news\/politics\/new-snowden-docs-show-u-s-spied-during-g20-in-toronto-1.2442448\">CBC reported<\/a> that the NSA had &#8220;conduct[ed] widespread surveillance in Canada during the 2010 G8 and G20 summits&#8221; but the <a href=\"http:\/\/www.cbc.ca\/news2\/pdf\/summit-doc.pdf\">source document<\/a> didn&#8217;t really back that assertion up.\u00a0 The document states that the NSA had assessed that there was no credible information that Islamic extremists were planning to attack the summits (the kind of legitimate work one might want a spy organisation to do) but said nothing that would indicate that there was mass surveillance of private citizens at or around the summits.<\/p>\n<p>But over the past week or so we&#8217;ve finally started to learn about CSEC&#8217;s role in some of the more nefarious kinds of work that the other Five Eyes countries have been involved in.\u00a0 <a href=\"http:\/\/www.theguardian.com\/world\/2014\/jan\/27\/nsa-gchq-smartphone-app-angry-birds-personal-data\">The Guardian reported<\/a> that the NSA and GCHQ had a program to collect private info on the users of smartphone games like Angry Birds by taking advantage of the lax security evident in the ad networks that help fund many smartphone games.\u00a0 One thing that went unreported in every story that I saw about this program failed to notice a detail written in one of the slides that The Guardian published.<\/p>\n<p><img loading=\"lazy\" class=\"aligncenter\" alt=\"\" src=\"https:\/\/image.guim.co.uk\/sys-images\/Guardian\/Pix\/pictures\/2014\/1\/27\/1390841102999\/a52c2207-36f5-4b6f-8a78-609bd44db0fd-460x345.jpeg\" width=\"460\" height=\"345\" \/><\/p>\n<p><!--more-->You&#8217;ll notice that the slide says that it was CSEC &#8211; Canada&#8217;s electronic spying agency &#8211; that ported this program to the Android platform.\u00a0 CSEC seems to have played a pretty important role in the plan to collect the private info of users of smartphone apps.\u00a0 As I say, this went <a href=\"https:\/\/www.google.com\/search?hl=en&amp;gl=ca&amp;tbm=nws&amp;authuser=0&amp;q=csec+android+angry+birds&amp;search_plus_one=form&amp;oq=csec+android+angry+birds&amp;gs_l=news-cc.3..43j43i53.822.5907.0.6002.36.4.6.25.28.0.95.309.4.4.0...0.0...1ac.1.t8_63G6l5ZU\">almost entirely unreported<\/a> but it was the first solid piece of evidence that we had that Canada was playing an important role in some of the Five Eyes&#8217; more troublesome activities.<\/p>\n<p>Later last week it was <a href=\"http:\/\/www.huffingtonpost.com\/2014\/01\/29\/snowden-nsa-surveillance-_n_4681362.html\">reported in The Huffington Post<\/a> that the NSA had spied on a large number of people at the 2009 UN climate negotiations in Denmark.\u00a0 The source document that The Huffington Post used for their story claimed that:<\/p>\n<blockquote><p>analysts here at NSA, <strong>as well as our Second Party partners<\/strong>, will continue to provide policymakers with unique, timely, and valuable insights into key countries&#8217; preparations and goals for the conference, as well as the deliberations within countries on climate change policies and negotiation strategies. (emphasis added)<\/p><\/blockquote>\n<p>The &#8220;Second Party partners&#8221; have widely been interpreted to mean the other Five Eyes countries, meaning Canada was likely involved in wide-scale eavesdropping at the climate conference.<\/p>\n<p>But the most troubling story so far was published by the CBC late last week, when they reported that &#8220;<a href=\"http:\/\/www.cbc.ca\/news\/politics\/csec-used-airport-wi-fi-to-track-canadian-travellers-edward-snowden-documents-1.2517881\">CSEC used airport Wi-Fi to track Canadian travellers<\/a>.&#8221;\u00a0 This story considerably undersold what had actually gone on though.\u00a0 If you read <a href=\"http:\/\/www.cbc.ca\/news2\/pdf\/airports_redacted.pdf\">the full slideshow that the article was based on<\/a> it&#8217;s pretty apparent that CSEC spied on Canadians in a whole host of places, not just airports.\u00a0 The slideshow suggests that the idea of collecting wi-fi info on travellers from an airport was simply an example and a test case for the broader program that they were developing.\u00a0 Look at the following two slides:<\/p>\n<p style=\"text-align: left;\"><a href=\"http:\/\/greatapes.ca\/blog\/wp-content\/uploads\/2014\/02\/slide1.png\"><img loading=\"lazy\" class=\"aligncenter  wp-image-652\" alt=\"slide1\" src=\"http:\/\/greatapes.ca\/blog\/wp-content\/uploads\/2014\/02\/slide1.png\" width=\"517\" height=\"387\" srcset=\"http:\/\/greatapes.ca\/blog\/wp-content\/uploads\/2014\/02\/slide1.png 957w, http:\/\/greatapes.ca\/blog\/wp-content\/uploads\/2014\/02\/slide1-300x224.png 300w\" sizes=\"(max-width: 517px) 100vw, 517px\" \/><\/a><a href=\"http:\/\/greatapes.ca\/blog\/wp-content\/uploads\/2014\/02\/slide2.png\"><img loading=\"lazy\" class=\"aligncenter  wp-image-654\" alt=\"slide2\" src=\"http:\/\/greatapes.ca\/blog\/wp-content\/uploads\/2014\/02\/slide2.png\" width=\"516\" height=\"386\" srcset=\"http:\/\/greatapes.ca\/blog\/wp-content\/uploads\/2014\/02\/slide2.png 955w, http:\/\/greatapes.ca\/blog\/wp-content\/uploads\/2014\/02\/slide2-300x224.png 300w\" sizes=\"(max-width: 516px) 100vw, 516px\" \/><\/a><\/p>\n<p style=\"text-align: left;\">The first slide makes it clear that airport wi-fi was one of a number of kinds of public wi-fi networks they spied on (other slides give more detail on this point).\u00a0 The second slide states, quite clearly, that CSEC carried out a &#8220;proof of concept&#8221; in which they collected info on hundreds of thousands of wireless Internet connections inside a Canadian city.\u00a0 They did <em>not<\/em> just spy on Canadians in an airport, they spied on Canadians inside a Canadian city using other wireless access points, and the slideshow on the whole suggests that the plan was to enable this technology to be used in Canada (and elsewhere) in the aid of law enforcement activities; <em>not<\/em> to track terrorists.<\/p>\n<p style=\"text-align: left;\">It&#8217;s possible that the example given in the slideshow, tracking a kidnapper across Canada, is just an example to demonstrate the idea and that the technology was only ever intended to be used in practice overseas to track terrorists.\u00a0 But nothing in the slideshow suggests this; indeed, the details in the document seem to indicate that this could be deployed domestically.\u00a0 And even if one grants that the general plan may be to track terrorism-related suspects, that does nothing to diminish the fact that the slideshow indicates that on at least two occasions this technique has <em>already<\/em> been deployed in Canada.<\/p>\n<p style=\"text-align: left;\">This brings us to a number of comments made recently by the Minister of Defence (Rob Nicholson) and the Deputy Head &amp; Chief of CSEC (John Forster).\u00a0 All subsequent quotes from either man are taken from <a href=\"http:\/\/www2.macleans.ca\/2014\/02\/03\/the-sketch-meta-answers-about-metadata\/\">Aaron Wherry&#8217;s piece on this subject at Macleans<\/a>.\u00a0 One thing that quickly becomes apparent is that Nicholson and Forster are quite happy to use the kinds of obfuscating, avoiding answers that representatives of the NSA have given to the U.S. Congress.\u00a0 They frequently try to re-frame issues or redefine words so that they can give the answers they want.<\/p>\n<p style=\"text-align: left;\">Nicholson claimed that:<\/p>\n<blockquote>\n<p style=\"text-align: left;\">CSEC made it clear to the CBC that nothing in the documents they had obtained showed that Canadian communications were targeted, collected or used, nor that travellers\u2019 movements were tracked.<\/p>\n<\/blockquote>\n<p style=\"text-align: left;\">This is a favourite tactic of the NSA: claim that &#8220;communications&#8221; and &#8220;content&#8221; were not collected, rather than answer substantive questions about what <em>was<\/em> collected.\u00a0 No one claims that CSEC collected individual &#8220;communications&#8221;.\u00a0 It&#8217;s widely acknowledged that what they collected is metadata.\u00a0 Among many others, <a href=\"http:\/\/www.privacybydesign.ca\/content\/uploads\/2013\/07\/Metadata.pdf\">Ontario&#8217;s Information and Privacy Commissioner has explained how metadata can be incredibly revealing<\/a>, often every bit as revealing as the &#8220;content&#8221; of &#8220;communications&#8221;.\u00a0 As for the claim that no travellers&#8217; movements were tracked, that&#8217;s flatly contradicted by the slideshow.\u00a0 Slides 8-18 describe the technique they used.\u00a0 This particular slide is the one that most plainly contradicts the Defence Minister&#8217;s remark:<\/p>\n<p style=\"text-align: center;\"><a href=\"http:\/\/greatapes.ca\/blog\/wp-content\/uploads\/2014\/02\/slide3.png\"><img loading=\"lazy\" class=\"aligncenter  wp-image-656\" alt=\"slide3\" src=\"http:\/\/greatapes.ca\/blog\/wp-content\/uploads\/2014\/02\/slide3.png\" width=\"515\" height=\"452\" srcset=\"http:\/\/greatapes.ca\/blog\/wp-content\/uploads\/2014\/02\/slide3.png 953w, http:\/\/greatapes.ca\/blog\/wp-content\/uploads\/2014\/02\/slide3-300x263.png 300w\" sizes=\"(max-width: 515px) 100vw, 515px\" \/><\/a><\/p>\n<p style=\"text-align: left;\">Oversight for CSEC&#8217;s activities is primarily the responsibility of just one man, the CSEC Commissioner.\u00a0 Nicholson said that:<\/p>\n<blockquote>\n<p style=\"text-align: left;\">past commissioners have reviewed CSEC metadata activities and found them to be in compliance with the law and be subject to comprehensive and satisfactory measures to protect the privacy of Canadians.<\/p>\n<\/blockquote>\n<p style=\"text-align: left;\">This is misleading.\u00a0 <a href=\"http:\/\/www.michaelgeist.ca\/content\/view\/6938\/125\/\">Here&#8217;s what the Commissioner himself said just last summer<\/a>:<\/p>\n<blockquote>\n<p style=\"text-align: left;\">I had no concern with respect to the majority of the CSEC activities reviewed. However, a small number of records suggested the possibility that some activities may have been directed at Canadians, contrary to law. A number of CSEC records relating to these activities were unclear or incomplete. After in-depth and lengthy review, I was unable to reach a definitive conclusion about compliance or non-compliance with the law.<\/p>\n<\/blockquote>\n<p style=\"text-align: left;\">That&#8217;s not a ringing endorsement.\u00a0 In fact, that&#8217;s the Comissioner saying quite clearly that CSEC did not provide him with the information necessary to reach a proper conclusion, but he expresses concern that Canadians <em>were<\/em> spied upon illegally.<\/p>\n<p style=\"text-align: left;\">CSEC is not the only Canadian spy agency to have problems obeying the law.\u00a0 Last December <a href=\"http:\/\/www.ottawacitizen.com\/news\/CSIS+asked+foreign+agencies+Canadians+kept+court+dark+judge+says\/9312615\/story.html\">a federal judge found that CSIS<\/a> (Canada&#8217;s equivalent to the CIA)<\/p>\n<blockquote>\n<p style=\"text-align: left;\">purposely misled him when he granted it numerous warrants beginning in 2009 to intercept the electronic communications of unidentified Canadians abroad suspected as domestic security threats.<\/p>\n<p>\u201cThis was a breach of the duty of candour owed by the service and their legal advisers to the court,\u201d Mosley said in his Further Reasons for Order.<\/p><\/blockquote>\n<p>Indeed, <a href=\"http:\/\/o.canada.com\/news\/csec-csis-withheld-info-from-court\/\">Judge Mosley also said<\/a> that &#8220;The failure to disclose that information was the result of a deliberate decision to keep the court in the dark about the scope and extent&#8221; of CSIS and CSEC&#8217;s activities and that CSIS\/CSEC&#8217;s actions have &#8220;led to misstatements in the public record about the scope of the authority granted the service.&#8221;\u00a0 Misstatements like the one Nicholson made when he claimed that CSEC had been found to be in compliance with the law, it would seem.<\/p>\n<p>The head of CSEC provided the same kind of evasive answers as the Defence Minister: &#8220;The work relied on metadata &#8230; metadata is data about a communication. It\u2019s not the content of a communication.&#8221; But no one has claimed that CSEC collected the &#8220;content of a communication&#8221; so this is entirely irrelevant.<\/p>\n<p>According to CSEC Chief Forster, &#8220;This was not an operational surveillance program.&#8221;\u00a0 This is contradicted by the CBC article on the program which states that &#8220;Sources tell CBC News the technologies tested on Canadians in 2012 have since become fully operational.&#8221;\u00a0 Indeed, it&#8217;s even contradicted by Forster&#8217;s own remarks as he &#8220;claimed to be aware of two cases in the past 12 months in which these models had been used to find &#8216;legitimate foreign targets&#8217;.&#8221;<\/p>\n<p>So we are left with this: through CSEC (and possibly to a lesser extent CSIS) Canada is an active partner in NSA and GCHQ efforts to spy on a wide variety of people.\u00a0 Experts including academics, a federal court judge, and the CSEC Commissioner have all stated either that Canada&#8217;s spy organisations have broken the law or that they seem likely to have done so.\u00a0 The answers provided by the Defence Minister and the Chief of CSEC are evasive and obfuscatory and they are at odds with publically available evidence.\u00a0 This is not democratic and it is not sufficient.\u00a0 Canadians deserve answers and they should demand them.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>While the NSA in the United States and GCHQ have come under a lot of scrutiny and criticism for their actions in terms of mass surveillance of their citizens, the role that CSEC (the Canadian equivalent) has played has been subject to significantly less attention.\u00a0 All three countries are part of an intelligence sharing program [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[3,4,21],"tags":[],"_links":{"self":[{"href":"http:\/\/greatapes.ca\/blog\/wp-json\/wp\/v2\/posts\/649"}],"collection":[{"href":"http:\/\/greatapes.ca\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/greatapes.ca\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/greatapes.ca\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/greatapes.ca\/blog\/wp-json\/wp\/v2\/comments?post=649"}],"version-history":[{"count":10,"href":"http:\/\/greatapes.ca\/blog\/wp-json\/wp\/v2\/posts\/649\/revisions"}],"predecessor-version":[{"id":662,"href":"http:\/\/greatapes.ca\/blog\/wp-json\/wp\/v2\/posts\/649\/revisions\/662"}],"wp:attachment":[{"href":"http:\/\/greatapes.ca\/blog\/wp-json\/wp\/v2\/media?parent=649"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/greatapes.ca\/blog\/wp-json\/wp\/v2\/categories?post=649"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/greatapes.ca\/blog\/wp-json\/wp\/v2\/tags?post=649"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}