Microsoft Seeks To Disclose Number of Court Spy Requests

Microsoft, Facebook, Google and Yahoo on Monday all filed amended motions seeking broader disclosure of customer data access requests by the U.S. Foreign Intelligence Surveillance Court (FISC).

The cookie-cutter-like legal documents issued by the four service providers all request that they be able to describe which of their disclosures come from the court. The amended motions follow from failed talks with the government back in July and August.

The FISC is a secret legal chamber that oversees surveillance warrants regarding foreign individuals. However, a document leaked by National Security Agency (NSA) whistleblower Edward Snowden illustrated that the court also approves bulk domestic spying requests, as in the case of an order addressed to telecom services provider Verizon.

The four service providers currently provide aggregate reports that show the number of legal requests they have complied with, including FISC requests, with Yahoo being the latest company to issue a "Transparency Report." Microsoft first began publishing its own "Law Enforcement Requests Report" in March, following the lead set by Google and Twitter. The Sept. 9 filings by Microsoft (PDF), Facebook (link), Google (PDF) and Yahoo (PDF) now seek FISC approvals to break down those totals and show the actual number of FISC requests, without specifically naming the parties under surveillance.

Microsoft's filing cites two FISC disclosure permissions:

  1. "The number of orders and/or directives (if any) received that require the production of only non-content data, and the number of accounts affected by any such orders and/or directives; and
  2. "The total number of orders and/or directives (if any) received that require the production of content and non-content data, and the number of accounts affected by any such orders and/or directives (together, the "Aggregate Data")."

The disclosure of so-called "non-content data" isn't negligible because it discloses details such as the names of the parties communicating, e-mail addresses and locations. Most of the information released by Microsoft and other service providers is this noncontent data.

The companies say that they are petitioning the court because of potential harm caused to their businesses from "false" media reports. Specifically, the service providers all deny that the NSA's PRISM program can "tap directly" into their servers, as alleged by Snowden.

"The media has erroneously reported that the alleged PRISM program enables the U.S. Government to 'tap directly into the central servers' of electronic communication service providers, including Microsoft, to collect information about their users," Microsoft's amended motion states (p. 2).

If the court were to grant the service providers' requests, it's unclear how the listing of those FISC requests would disprove Snowden's assertion that their networks were directly tappable by the NSA. The amended motion documents don't make that case at all. Instead, they all point to an August announcement by the Director of National Intelligence that the U.S. intelligence community itself plans to disclose the number of FISC requests during the previous year. Given that decision, the service providers argue that they should be able to do the same thing.

Many of the documents argue that First Amendment speech rights allow the companies to disclose the numbers anyway. However, all of the companies remained silent about their participation in the NSA's PRISM program for years. Microsoft was the first company to join the PRISM program in 2007, reportedly after Yahoo failed in contesting its participation.

The stakes potentially are high for U.S. service providers. They could lose an estimated $21.5 billion to $35.0 billion over the next three years if companies and individuals elect to use cloud-based services located outside the United States, according to a report.

About the Author

Kurt Mackie is senior news producer for the 1105 Enterprise Computing Group.


  • Industrial Control System Honeypot Illustrates Bad Security Practices

    Security solutions provider Trend Micro has published results (PDF) from running an industrial control system (ICS) "honeypot."

  • Ransomware: What It Means for Your Database Servers

    Ransomware affects databases in very specific ways. Joey describes the mechanics of a SQL Server ransomware attack, what DBAs can do to protect their systems, and what security measures they should be advocating for.

  • Windows Admin Center vs. Hyper-V Manager: What's Better for Managing VMs?

    Microsoft's preferred interface for Windows Server is Windows Admin Center, but can it really replace Hyper-V Manager for managing virtual machines? Brien compares the two management tools.

  • Microsoft Offers More Help on Windows Server 2008 Upgrades

    Microsoft this week published additional help resources for organizations stuck on Windows Server 2008, which fell out of support on Jan. 14.

comments powered by Disqus

Office 365 Watch

Sign up for our newsletter.

Terms and Privacy Policy consent

I agree to this site's Privacy Policy.