Authors: Edward Snowden
STELLARWIND was the classified report’s deepest secret. It was, in fact, the NSA’s deepest secret, and the one that the report’s sensitive status had been designed to protect. The program’s very existence was an indication that the agency’s mission had been transformed, from using technology to defend America to using technology to control it by redefining citizens’ private Internet communications as potential signals intelligence.
Such fraudulent redefinitions ran throughout the report, but perhaps the most fundamental and transparently desperate involved the government’s vocabulary. STELLARWIND had been collecting communications since the PSP’s inception in 2001, but in 2004—when Justice Department officials balked at the continuation of the initiative—the Bush administration attempted to legitimize it ex post facto by changing the meanings of basic English words, such as “acquire” and “obtain.” According to the report, it was the government’s position that the NSA could collect whatever communications records it wanted to, without having to get a warrant, because it could only be said to have
acquired
or
obtained
them, in the legal sense, if and when the agency “searched for and retrieved” them from its database.
This lexical sophistry was particularly galling to me, as I was well aware that the agency’s goal was to be able to retain as much
data as it could for as long as it could—for perpetuity. If communications records would only be considered definitively “obtained” once they were used, they could remain “unobtained” but collected in storage forever, raw data awaiting its future manipulation. By redefining the terms “acquire” and “obtain”—from describing the act of data being entered into a database, to describing the act of a person (or, more likely, an algorithm) querying that database and getting a “hit” or “return” at any conceivable point in the future—the US government was developing the capacity of an eternal law-enforcement agency. At any time, the government could dig through the past communications of anyone it wanted to victimize in search of a crime (and everybody’s communications contain evidence of something). At any point, for all perpetuity, any new administration—any future rogue head of the NSA—could just show up to work and, as easily as flicking a switch, instantly track everybody with a phone or a computer, know who they were, where they were, what they were doing with whom, and what they had ever done in the past.
T
HE TERM
“
MASS
surveillance” is more clear to me, and I think to most people, than the government’s preferred “bulk collection,” which to my mind threatens to give a falsely fuzzy impression of the agency’s work. “Bulk collection” makes it sound like a particularly busy post office or sanitation department, as opposed to a historic effort to achieve total access to—and clandestinely take possession of—the records of all digital communications in existence.
But even once a common ground of terminology is established, misperceptions can still abound. Most people, even today, tend to think of mass surveillance in terms of content—the actual words they use when they make a phone call or write an email. When they find out that the government actually cares comparatively little about that content, they tend to care comparatively little about government surveillance. This relief is understandable, to a degree,
due to what each of us must regard as the uniquely revealing and intimate nature of our communications: the sound of our voice, almost as personal as a thumbprint; the inimitable facial expression we put on in a selfie sent by text. The unfortunate truth, however, is that the content of our communications is rarely as revealing as its other elements—the unwritten, unspoken information that can expose the broader context and patterns of behavior.
The NSA calls this “metadata.” The term’s prefix, “meta,” which traditionally is translated as “above” or “beyond,” is here used in the sense of “about”: metadata is data about data. It is, more accurately, data that is made by data—a cluster of tags and markers that allow data to be useful. The most direct way of thinking about metadata, however, is as “activity data,” all the records of all the things you do on your devices and all the things your devices do on their own. Take a phone call, for example: its metadata might include the date and time of the call, the call’s duration, the number from which the call was made, the number being called, and their locations. An email’s metadata might include information about what type of computer it was generated on, where, and when, who the computer belonged to, who sent the email, who received it, where and when it was sent and received, and who if anyone besides the sender and recipient accessed it, and where and when. Metadata can tell your surveillant the address you slept at last night and what time you got up this morning. It reveals every place you visited during your day and how long you spent there. It shows who you were in touch with and who was in touch with you.
It’s this fact that obliterates any government claim that metadata is somehow not a direct window into the substance of a communication. With the dizzying volume of digital communications in the world, there is simply no way that every phone call could be listened to or email could be read. Even if it were feasible, however, it still wouldn’t be useful, and anyway, metadata makes this unnecessary by winnowing the field. This is why it’s best to regard metadata not as some benign abstraction, but as the very essence
of content: it is precisely the first line of information that the party surveilling you requires.
There’s another thing, too: content is usually defined as something that you knowingly produce. You know what you’re saying during a phone call, or what you’re writing in an email. But you have hardly any control over the metadata you produce, because it is generated automatically. Just as it’s collected, stored, and analyzed by machine, it’s made by machine, too, without your participation or even consent. Your devices are constantly communicating for you whether you want them to or not. And, unlike the humans you communicate with of your own volition, your devices don’t withhold private information or use code words in an attempt to be discreet. They merely ping the nearest cell phone towers with signals that never lie.
One major irony here is that law, which always lags behind technological innovation by at least a generation, gives substantially more protections to a communication’s content than to its metadata—and yet intelligence agencies are far more interested in the metadata—the activity records that allow them both the “big picture” ability to analyze data at scale, and the “little picture” ability to make perfect maps, chronologies, and associative synopses of an individual person’s life, from which they presume to extrapolate predictions of behavior. In sum, metadata can tell your surveillant virtually everything they’d ever want or need to know about you, except what’s actually going on inside your head.
After reading this classified report, I spent the next weeks, even months, in a daze. I was sad and low, trying to deny everything I was thinking and feeling—that’s what was going on in my head, toward the end of my stint in Japan.
I felt far from home, but monitored. I felt more adult than ever, but also cursed with the knowledge that all of us had been reduced to something like children, who’d be forced to live the rest of our lives under omniscient parental supervision. I felt like a fraud, making excuses to Lindsay to explain my sullenness. I felt like a fool, as someone of supposedly serious technical skills who’d
somehow helped to build an essential component of this system without realizing its purpose. I felt used, as an employee of the IC who only now was realizing that all along I’d been protecting not my country but the state. I felt, above all, violated. Being in Japan only accentuated the sense of betrayal.
I’ll explain.
The Japanese that I’d managed to pick up through community college and my interests in anime and manga was enough for me to speak and get through basic conversations, but reading was a different matter. In Japanese, each word can be represented by its own unique character, or a combination of characters, called kanji, so there were tens of thousands of them—far too many for me to memorize. Often, I was only able to decode particular kanji if they were written with their phonetic gloss, the
furigana
, which are most commonly meant for foreigners and young readers and so are typically absent from public texts like street signs. The result of all this was that I walked around functionally illiterate. I’d get confused and end up going right when I should have gone left, or left when I should have gone right. I’d wander down the wrong streets and misorder from menus. I was a stranger, is what I’m saying, and often lost, in more ways than one. There were times when I’d accompany Lindsay out on one of her photography trips into the countryside and I’d suddenly stop and realize, in the midst of a village or in the middle of a forest, that I knew nothing whatsoever about my surroundings.
And yet: everything was known about me. I now understood that I was totally transparent to my government. The phone that gave me directions, and corrected me when I went the wrong way, and helped me translate the traffic signs, and told me the times of the buses and trains, was also making sure that all of my doings were legible to my employers. It was telling my bosses where I was and when, even if I never touched the thing and just left it in my pocket.
I remember forcing myself to laugh about this once when Lindsay and I got lost on a hike and Lindsay—to whom I’d told
nothing—just spontaneously said, “Why don’t you text Fort Meade and have them find us?” She kept the joke going, and I tried to find it funny but couldn’t. “Hello,” she mimicked me, “can you help us with directions?”
Later I would live in Hawaii, near Pearl Harbor, where America was attacked and dragged into what might have been its last just war. Here, in Japan, I was closer to Hiroshima and Nagasaki, where that war ignominiously ended. Lindsay and I had always hoped to visit those cities, but every time we planned to go we wound up having to cancel. On one of my first days off, we were all set to head down Honshu to Hiroshima, but I was called in to work and told to go in the opposite direction—to Misawa Air Base in the frozen north. On the day of our next scheduled attempt, Lindsay got sick, and then I got sick, too. Finally, the night before we intended to go to Nagasaki, Lindsay and I were woken by our first major earthquake, jumped up from our futon, ran down seven flights of stairs, and spent the rest of the night out on the street with our neighbors, shivering in our pajamas.
To my true regret, we never went. Those places are holy places, whose memorials honor the two hundred thousand incinerated and the countless poisoned by fallout while reminding us of technology’s amorality.
I think often of what’s called the “atomic moment”—a phrase that in physics describes the moment when a nucleus coheres the protons and neutrons spinning around it into an atom, but that’s popularly understood to mean the advent of the nuclear age, whose isotopes enabled advances in energy production, agriculture, water potability, and the diagnosis and treatment of deadly disease. It also created the atomic bomb.
Technology doesn’t have a Hippocratic oath. So many decisions that have been made by technologists in academia, industry, the military, and government since at least the Industrial Revolution have been made on the basis of “can we,” not “should we.” And the intention driving a technology’s invention rarely, if ever, limits its application and use.
I do not mean, of course, to compare nuclear weapons with cybersurveillance in terms of human cost. But there is a commonality when it comes to the concepts of proliferation and disarmament.
The only two countries I knew of that had previously practiced mass surveillance were those two other major combatants of World War II—one America’s enemy, the other America’s ally. In both Nazi Germany and Soviet Russia, the earliest public indications of that surveillance took the superficially innocuous form of a census, the official enumeration and statistical recording of a population. The First All-Union Census of the Soviet Union, in 1926, had a secondary agenda beyond a simple count: it overtly queried Soviet citizens about their nationality. Its findings convinced the ethnic Russians who comprised the Soviet elite that they were in the minority when compared to the aggregated masses of citizens who claimed a Central Asian heritage, such as Uzbeks, Kazakhs, Tajiks, Turkmen, Georgians, and Armenians. These findings significantly strengthened Stalin’s resolve to eradicate these cultures, by “reeducating” their populations in the deracinating ideology of Marxism-Leninism.
The Nazi German census of 1939 took on a similar statistical project, but with the assistance of computer technology. It set out to count the Reich’s population in order to control it and to purge it—mainly of Jews and Roma—before exerting its murderous efforts on populations beyond its borders. To effect this, the Reich partnered with Dehomag, a German subsidiary of the American IBM, which owned the patent to the punch card tabulator, a sort of analog computer that counted holes punched into cards. Each citizen was represented by a card, and certain holes on the cards represented certain markers of identity. Column 22 addressed the religion rubric: hole 1 was Protestant, hole 2 Catholic, and hole 3 Jewish. Shortly thereafter, this census information was used to identify and deport Europe’s Jewish population to the death camps.
A single current-model smartphone commands more comput
ing power than all of the wartime machinery of the Reich and the Soviet Union combined. Recalling this is the surest way to contextualize not just the modern American IC’s technological dominance, but also the threat it poses to democratic governance. In the century or so since those census efforts, technology has made astounding progress, but the same could not be said for the law or human scruples that could restrain it.
The United States has a census, too, of course. The Constitution established the American census and enshrined it as the official federal count of each state’s population in order to determine its proportional delegation to the House of Representatives. That was something of a revisionist principle, in that authoritarian governments, including the British monarchy that ruled the colonies, had traditionally used the census as a method of assessing taxes and ascertaining the number of young men eligible for military conscription. It was the Constitution’s genius to repurpose what had been a mechanism of oppression into one of democracy. The census, which is officially under the jurisdiction of the Senate, was ordered to be performed every ten years, which was roughly the amount of time it took to process the data of most American censuses following the first census of 1790. This decade-long lag was shortened by the census of 1890, which was the world’s first census to make use of computers (the prototypes of the models that IBM later sold to Nazi Germany). With computing technology, the processing time was cut in half.