Just after congress voted to curb government surveillance programs with passage of the USA Freedom Act, a new report by the New York Times revealed a covert National Security Agency program monitoring Internet traffic between American citizens and international persons involved in cyber crime.
The program purportedly focused on discovering IP addresses and “cybersignatures” associated with state-sponsored cyberattacks, though NSA wanted to extend the program to include any hackers — including American citizens — whether or not there was a direct link to foreign governments.
More: NSA leak raises concerns about IT hiring practices
The intelligence agency argued that difficulties in attribution in cyberspace make it hard to ensure that malicious actors are in fact communicating with foreign governments, leaving a critical gap if the agency can’t collect information on potential threats.
Even without that broader implementation, the program still raises privacy concerns about the kind of monitoring being conducted and amount of data being collected, all without warrants.
The report cites two 2012 memos authorizing the program from the Department of Justice, leaked to theTimes and ProPublica by former NSA contactor Edward Snowden, who first outted the spy agency’s bulk data collection programs back in 2013.
More: Declassified docs show officials clashed over spy program
“It should come as no surprise that the U.S. government gathers intelligence on foreign powers that attempt to penetrate U.S. networks and steal the private information of U.S. citizens and companies,” Brian Hale, spokesman for the Office of the Director of National Intelligence, is quoted in the Times piece. “Targeting overseas individuals engaging in hostile cyber activities on behalf of a foreign power is a lawful foreign intelligence purpose.”
Read the full story on NYTimes.com.




