Balkinization  

Wednesday, June 25, 2008

FISA Fix Follow-Ups

Marty Lederman

A couple of lingering questions raised by David Kris's wonderfully elucidating series of posts:

1. Will the new law, as David suggests, permit the NSA to engage in undifferentiated "vacuum-cleaner"-like collection of calls between persons in the U.S. and those outside it, or does the requirement that there be "targeting of persons reasonably believed to be located outside the United States" mean that the NSA has to focus its surveillance on particular, known persons outside the U.S.? As James Dempsey puts the question in an extremely helpful post that complements David's, "are we talking about recording millions and billions of calls and emails or merely hundreds of thousands?" It is something of a scandal that neither we the public, nor many (if any) of the legislators voting for this bill, know the answer to this and related questions.

2. In his latest post, David emphasizes a point that not many people appreciate -- namely, that under the 1978 FISA, the NSA was free under federal law to indiscriminately intercept, and then use, virtually all communications between U.S. persons in the U.S. and persons overseas, as long as the interception took place overseas (and the surveillance was not "directed" at someone in the States). (Conceivably, the Fourth Amendment might limit such surveillance, but I'm not aware of any case law on the question.)

Several defenders of the new law have argued that if there was nothing wrong with such interceptions from 1978 to 2001 -- and they were not subject to FISA -- what is the big deal about the new law, which simply authorizes interceptions outside the FISA framework of the exact same U.S.-to-foreign communications, but this time where the interception occurs here in the States? Indeed, as David points out, in one respect the new law will be even more restrictive than FISA, in that section 704 of the new statute will require a judicial finding of probable cause for such surveillance if it targets U.S. persons located abroad (something that was not required under FISA).

So what's the fuss about?

Well, to begin with, I take slight issue with David's characterization that "Congress in 1978 deliberately allowed NSA to conduct warrantless surveillance of international calls [intercepted abroad] as long as it was not targeting individual Americans located in the United States." Congress recognized that this practice, too, could raise serious problems with respect to the privacy of Americans who make such calls. But the issue raised very difficult questions that could not be resolved by the time Congress was ready to act, and so the legislature decided to put the issue off, with the conferees promising that they would address the issue in the near term.

And such reconsideration never happened. Why? Who knows? Perhaps Congress didn't enact such post-FISA gap-filling legislation because there was no political impetus for it; or because the Reagan Administration was strongly opposed and a presidential signature seemed unlikely; or because it was too hard to come up with the proper statutory fix; or perhaps because Congress reconsidered and concluded that the NSA should be free to indiscriminately collect such communications overseas. Or some combination thereof.

For quite a while, this congressional failure to address NSA's overseas surveillance of U.S.-to-foreign communications was simply not that big a deal, because U.S. persons did not make many international phone calls. And virtually no one had e-mail. Moreover, surveillance overseas was quite onerous -- presumably the NSA could not simply collect virtually all international communications. Thus, for many years after FISA was enacted, although there was no statute limiting the NSA's interceptions of U.S. person phone calls to foreigners (where the U.S. person was not the target), this regulatory lacuna likely did not result in very many NSA interceptions of such calls.

Now, as a practical matter, everything has changed. Obviously, the volume of U.S. person communications with foreigners has increased exponentially -- it is a ubiquitous feature of many of our lives. In addition, the new law will greatly increase the NSA's power to intercept such calls, by allowing the agency to do so here in the U.S., with the assistance of U.S. telecoms. These two changes -- one in the nature of our worldwide communications, the other in the capabilities of the NSA -- conspire to mean that, under the new law, the NSA will be able to collect many, many more of our communications. The law may have remained "neutral" as a formal matter, but because technologies, and thus practices, have changed, such "neutrality" has profound implications for the sheer magnitude of the intrusion into the privacy of our international communications.

This does not mean that the NSA should, or should not, be given this new authority. But it does mean that it would be a profound sea change, not business as usual or a technical tweak to the 1978 regime.

A Guide to the New FISA Bill, Part III

Guest Blogger

David Kris

[Here is Part I and Part II]

In my last post, I compared the pending legislation to my speculation about the January 2007 FISA Court orders. Of course, it’s also interesting to compare the pending legislation to current (traditional) FISA. That can be done in two ways, both of which I will attempt here. First, cribbing from Chapter 7 of my book, I’ll describe the four main limits on current FISA’s regulatory scope, and explain how the new legislation will affect each of those limits. Next, approaching the issue in a different way, I will divide the world of electronic communications into three main groups, and say a few words about each group under traditional FISA and modernized FISA.

1. FISA’s Four Limits. Under current law, there are four significant limits on FISA’s regulatory scope with respect to surveillance. First, the statute does not apply where all parties to a wire or radio communication are located abroad, even if they are Americans (U.S. persons), and even if the surveillance is conducted inside the United States. Such foreign-to-foreign wire and radio communications are (and always have been) simply outside the statute’s scope. Under the new law, this will change, because surveillance targeting an American located abroad will generally be subject to Sections 703 (if the surveillance occurs in the United States) or 704 (if the surveillance occurs abroad), both of which require judicial findings of probable cause that the targeted American is an agent of a foreign power. This will be the case even if the American abroad is communicating with another person located abroad. In this respect, it would be fair to say that the new law will expand FISA. (Section 703 may be best seen as a limit on the contraction of FISA as discussed in the next paragraph, but Section 704 appears to be a genuine expansion.)

The opposite is true, however, with respect to stored e-mail. Although traditional FISA has never regulated surveillance of foreign-to-foreign wire or radio communications, as mentioned earlier it currently does regulate surveillance of foreign-to-foreign e-mail if the e-mail is acquired from storage inside the United States; and this is the case even if all parties to the e-mail are foreigners (non-U.S. persons). Under the new law, this anomaly will be corrected, and foreign-to-foreign e-mail exchanged between foreigners will no longer require a FISA warrant, even if acquired from storage in the United States. (As noted in the previous paragraph, however, if an American abroad is the target of such e-mail surveillance, Section 703 of the new statute will apply, even if the American is communicating with a foreigner who is also located abroad.) In this respect – concerning foreign-to-foreign e-mail exchanged between foreigners – the new law will contract FISA.

The second major limit in current FISA is that the statute does not apply where the surveillance target is located abroad and the surveillance occurs abroad. Again, the new statute will both expand and contract FISA in this area. It will expand FISA because Section 704 of the new statute will require a judicial finding of probable cause for such surveillance targeting Americans located abroad. But it will contract FISA because Section 702 of the new statute will eliminate the need for a traditional FISA order even if the surveillance (or other acquisition activity) targeting a foreign person located abroad occurs inside the United States.

The third major limit is that current FISA does not apply to wire surveillance where the target is a foreigner, and the surveillance occurs abroad. As discussed above, the main effect of the new statute will be to enlarge this exception to cover situations in which the surveillance occurs inside the United States, as long as the foreign target is (reasonably believed to be) located abroad. In this respect, it can be said that the new law will contract FISA’s regulatory reach.

Fourth and finally, current FISA does not apply to radio surveillance not targeting a U.S. person located in the United States where any party to the radio communication is outside the United States. This exception will be essentially unchanged under the new law.

2. On the assumption that the foregoing discussion left some readers unsatisfied (or perhaps even a little queasy), let me try to approach the issue from a different perspective, dividing the world of electronic communications into three groups, and analyzing each group under current law and the pending legislation. The three groups are:

(a) U.S.-to-U.S. communications, also known as domestic communications;

(b) foreign-to-U.S. communications, also known as one-end-U.S. communications; and

(c) foreign-to-foreign communications.

a. Domestic Communications. The first group to be discussed is purely domestic communications, where both parties are located in the United States. This includes, for example, a telephone call from Washington to New York. By and large, FISA has always regulated surveillance of these domestic communications. Certainly that was the case in 1978. Although the Protect America Act cast some doubt on this during its operative period (August 2007 to February 2008), the current legislation provides expressly that it does not apply to intentional acquisition of known domestic communications (Section 702(b)(4)). Accidental acquisition is possible, and no doubt in operation there will be interesting fact-intensive questions about whether and when the government “knows” that a communication is domestic. (This alone could be the topic of a separate discussion; for now, it’s enough to note that the statute requires the government to establish guidelines to address these concerns (702(g)(2)(A)(iii).) In theory, at least, the government cannot use the new statute to target domestic communications, even if exchanged between and among visiting foreigners in this country.

b. One-End-U.S. Communications. The second group is for “one-end-U.S.” communications, where one party, but not both, is located in the United States. This includes, for example, a telephone call from New York to London. Here, FISA has always been a mixed bag. But as I mentioned in prior posts, Congress in 1978 deliberately allowed NSA to conduct warrantless surveillance of international calls as long as it was not targeting individual Americans located in the United States. Vacuum-cleaner surveillance of communications to or from the United States, which didn’t target anyone in particular, was permitted if NSA took certain operational steps – namely, applying the vacuum cleaner either to a radio communication or to a wire or cable located outside the United States. And this was the rule even if that surveillance acquired calls to, from, or about Americans located in the United States.

The key with respect to surveillance of these one-end-U.S. communications was that no “particular, known” American in the United States could be targeted. For example, to paraphrase one witness who testified in Congressional hearings leading to FISA, the NSA could not run its vacuum cleaners over a transatlantic telephone cable with filters set to record all calls mentioning “David Kris” (or my home address, or my social security number). That kind of surveillance clearly would be designed to obtain information from or about a particular, known American located in the United States (me), and would therefore be subject to FISA. On the other hand, however, NSA could set its filters to record all calls mentioning the word “terrorism” – because that does not target anyone in particular – and could keep those calls even if some of them were made by me. (Of course, when I say that NSA “could” do something, I mean that it could do so legally, not operationally or technically.)

Under the modernized version of FISA, the government will have both more and less authority in this area. It will still need a warrant to target any particular, known American in the United States – that is unchanged. It will no longer need a traditional FISA warrant to target a foreign person located abroad, even if the surveillance occurs on wires or cables inside this country – that is a contraction of FISA. But it will need a judicial finding of probable cause to target an American person located abroad, whether the surveillance occurs inside the United States (Section 703) or abroad (Section 704) – that is an expansion of FISA, at least as to surveillance conducted abroad.

The third and final group in my taxonomy is for foreign-to-foreign communications, where all parties are located abroad. This includes, for example, a telephone call from London to Paris. As noted earlier, FISA has never – at any time – regulated surveillance of a wire or radio communication between two foreign locations, even if made by two Americans, and even if acquired inside the United States (as can happen because of the way the world’s telephone lines are laid out). But, as also noted earlier, it does currently regulate surveillance of an e-mail exchanged between persons in two foreign locations, if the e-mail is acquired from storage inside the United States, even if both the sender and recipient of the e-mail are foreigners. Under the new statute, if the target is a foreigner located abroad, FISA does not require a warrant (Section 702); if the target is an American, it requires a judicial finding of probable cause (Sections 703 and 704).

This is just a preliminary cut at the new material, subject to revision as I continue thinking, but for now I hope it helps.

Partisan Entrenchment in the Civil Service: The Case of the Justice Department

JB

Back in 2006 I wrote about the Bush Administration's plans to stock the Justice Department with movement conservatives, based on earlier reporting by Charlie Savage. The Inspector General's office has now issued a critical report arguing that the Administration systematically and illegally used ideological and political allegiances to decide which law school graduates it would hire in the Department of Justice's honors program and summer internships, which are often stepping stones to permanent jobs.

Much of what I had to say in 2006 is still relevant today to understanding what is going on here.

There are many different techniques of partisan entrenchment. The most familiar is entrenchment of ideological allies in the judiciary, which nobody thinks illegal. The Bush Administration sought to entrench young movement conservatives in the civil service, particularly the Justice Department, reasoning that these lawyers, like judges, would serve for many years, and move the application and enforcement of federal law toward the right. As recent stories about the Office of Legal Counsel suggest, lawyers in the Executive Branch decide what much of federal law will be in practice, through their decisions about which cases to bring, which cases not to bring, which cases to settle (and on what terms), and through their interpretation of laws and regulations affecting the executive branch, which are often not reviewed by the courts.

Although partisan entrenchment in the judiciary is a familiar practice, the civil service rules are designed to keep the President from stocking the civil service (as opposed to political appointees) with his ideological allies. Political appointees come and go with each administration, while the members of the civil service may stay in place for long periods of time. As a result, the federal bureaucracy, including the Justice Department, acts as a counterweight against attempts to radically change the practical enforcement (or non-enforcement) of federal law. This sort of check-- and an emphasis on non-partisan expertise in hiring and promotion-- is part of the point of these civil service rules.

Even with these rules in place, no one doubts that political appointees, who staff the upper levels of the Administration, have significant effects on the general shape and direction of the bureaucracy, and on the enforcement and interpretation of federal law. But the Bush Administration sought to infiltrate every level of decisionmaking, reasoning that in this way it could promote movement values for the foreseeable future, even when Democrats controlled the White House. Equally important, it could block entry to too many lawyers that did not share the conservative movement's goals or were hostile to them.

As so often with the Bush Administration, its leaders pushed too hard, too quickly, and too clumsily to have their way, and they ended up breaking the law in the process. As before, the Administration might have been far more successful in entrenching its values and vision in the federal bureaucracy had it acted within the boundaries of the law. For example, it might have made sure that more movement conservatives applied for these jobs and made sure they were given a fair chance to compete, which would have predictably resulted in increased numbers of hires. Democrats might have grumbled but there would be little they could have done about it.

No matter who wins the election, there will probably be a strong push in the next Administration to return hiring in the Justice Department (and the civil service generally) to strongly non-partisan merit based policies. And if Obama wins, we may also see a mass exodus of movement conservatives from the Justice Department and other civil service positions when many of them discover that they will not be able to shape law in the way they want. As a result, the Bush Administration's efforts at partisan entrenchment in the Justice Department may not succeed. Moreover, by overplaying its hand, the Bush Administration has sensitized Congress and the public to the issue. People will be watching if the next administration tries something similar.

Tuesday, June 24, 2008

When a Good Prosecutor Throws a Case

David Luban

Should a prosecutor throw a case to avoid sending men he thinks are innocent to jail?

This story appeared in yesterday’s New York Times: a career prosecutor in New York City’s DA’s office, Daniel Bibb, was ordered to reexamine two men’s murder convictions because of new evidence. After an exhaustive 21-month investigation, Bibb became convinced that they were not guilty. But he couldn’t persuade his superiors to drop the cases, so he went in to the hearing and, in his words, threw the case. "‘I did the best I could,’ he said. ‘To lose.’"

He made sure that the exculpatory witnesses showed up at the hearing, told witnesses what questions he was going to ask them on cross-examination, and helped defense lawyers draw connections between different pieces of evidence when they weren’t getting it. All the while, he continued to ask his superiors to drop the cases. They agreed to do so for one of the men, and a new trial was ordered for the other. At that point, Bibb said, "I’m done....I wanted nothing to do with it." Bibb eventually resigned – although all he had ever wanted to be is a career prosecutor. Today he’s trying to start over as a defense lawyer.

There’s no doubt that what Bibb did was unusual. And there’s no doubt that he violated the usual role expectations of the adversary system, where lawyers never try to help the other side make their case even when they think the other side is right. But did Bibb do anything wrong?
Stephen Gillers, a nationally-renowned legal ethics expert, thinks he did, and might face professional discipline. "He’s entitled to his conscience, but his conscience does not entitle him to subvert his client’s case. It entitles him to withdraw from the case, or quit if he can’t." Bibb, on the other hand, said that he didn’t withdraw because "he worried that if he did not take the case, another prosecutor would — and possibly win."

I have great admiration for Steve Gillers, but in this case I think he's wrong. Daniel Bibb deserves a medal, not a reprimand.

Before I explain why, let’s see what the ethics case against Bibb might be. Imagine that a private lawyer representing a private client did the same thing: located truthful but adverse witnesses, revealed his cross-examination, coached the opposing lawyers. And suppose his client lost. The lawyer did it because he thought the other side was right. First, there is no question that the lawyer could be sued for malpractice. As for ethics violations, the lawyer could be charged with violating the requirement of competency (Model Rule 1.1); the requirement that the client, not the lawyer, sets the goals of the representation (Rule 1.2(a)); the requirement of diligence ("zeal," although the Model Rules don’t use that word in Rule 1.3); and the conflict of interest provision (Rule 1.7). Conceivably the lawyer could also be charged with using client confidences against the client’s interests, if any of his conduct was based on confidential information from the client. In short, a mountain of ethics violations.


Presumably, the same could be said of a prosecutor (except for the confidentiality violation); and New York’s rules contain counterparts to all these ABA rules.

But there is a difference. Prosecutors aren’t supposed to win at all costs. In a time-honored formula, their job is to seek justice, not victory. It’s a mantra that appears in all the crucial ethics documents: in the current ABA Model Rules of Professional Conduct ("A prosecutor has the responsibility of a minister of justice and not simply that of an advocate." Comment to Rule 3.8); in the previous ABA Code of Professional Responsibility ("The responsibility of a public prosecutor differs from that of the usual advocate: his duty is to seek justice, not merely to convict" (EC 7-13)); in the ABA’s Standards for the Prosecution Function ("The duty of the prosecutor is to seek justice, not merely to convict....", standard 3-1.2(c)). The ancestor of all these pronouncements is the Supreme Court’s dictum in a 1935 case, Berger v. U.S.:

The United States Attorney is the representative not of an ordinary party to a controversy, but of a sovereignty whose obligation to govern impartially is as compelling as its obligation to govern at all; and whose interest, therefore, in a criminal prosecution is not that it shall win a case, but that justice shall be done. As such, he is in a peculiar and very definite sense the servant of the law, the twofold aim of which is that guilt shall not escape or innocence suffer. Berger, 295 U.S. 78, 88 (1935).

Admittedly, there’s a Delphic quality to "seek justice, not victory." ‘Justice’ is a grandiose and vague word. (Holmes famously said "This is a court of law, young man, not a court of justice," and wrote that whenever someone starts talking about justice he knows that legal thinking has come to an end.) The actual ethics rules – as opposed to aspirational standards – take a pretty minimalist view of the prosecutor’s responsibilities. They shouldn’t proceed without probable cause, they should make a reasonable effort to ensure that the accused has been informed of his rights, they shouldn’t try to get an unrepresented person to waive rights, and they should do timely Brady disclosures. That's about it. It’s a widely recognized fact that a lot of prosecutors measure their success by their conviction rate. Fred Zacharias, a noted ethics authority, thinks that the "justice" prosecutors seek "has two fairly limited prongs: (1) prosecutors should not prosecute unless they have a good faith belief that the defendant is guilty; and, (2) prosecutors must ensure that the basic elements of the adversary system exist at trial." (That’s from his 1991 article "Structuring the Ethics of Prosecutorial Trial Practice: Can Prosecutors Do Justice?,"44 Vand. L. Rev. 45, 49.)

And yet I’ve talked with a lot of prosecutors who take "seek justice, not victory" seriously, even if they aren’t 100% confident they know exactly what it requires. At the very least, they know it means that you shouldn’t try to keep people behind bars if you think they didn't do it.

And just this year, the ABA House of Delegates agreed. The ABA added two new Model Rules to deal with prosecutors' obligations when new evidence suggests that they obtained wrongful convictions. Rule 3.8(g) requires a prosecutor who learns of "new, credible, and material evidence creating a reasonable likelihood that a convicted defendant did not commit an offense of which the defendant was convicted," to disclose the evidence to the proper authorities as well as the defendant, and initiate an investigation. And Rule 3.8(h) requires a prosecutor who receives clear and convincing evidence that a defendant was convicted of a crime he did not commit to "seek to remedy the conviction."

This rule is brand-new. It isn’t in New York's Code of Professional Responsibility yet, and it’s perfectly clear that the ABA wasn’t thinking of Bibb’s unorthodox tactics as the way a lawyer should "seek to remedy the conviction." But what, after all, did Bibb do wrong? He persuaded witnesses to show up in court and testify (against the state). Think for a moment about the alternative. Bibb was charged with investigating the case, and he did a yeoman’s job to locate the witnesses. Bibb "and two detectives conducted more than 50 interviews in more than a dozen states, ferreting out witnesses the police had somehow missed or ignored." Once he had these witnesses’ evidence, he was under an obligation to turn it over to the defense.

The alternatives: don’t investigate the case for fear you’ll find out that the guys doing 25-years-to-life are innocent; or, having investigated it, don’t turn over the exculpatory evidence to the defense, violating your constitutional and ethical obligations; or, having turned it over, put the defense to the difficulty of locating the witnesses and getting them to court – so, if they don’t succeed, the truth stays buried. THAT’s the ethical obligation of a public prosecutor?

Admittedly, it’s weirder to have the prosecutor remind the defense about how the evidence fits together, and weirder still to tell witnesses what you’re planning to ask them on cross examination. But how does that subvert criminal justice? How does that harm anybody or violate anyone's interests?

This is the real question. Steve Gillers says that Bibb subverted his client’s case. But who is his client? Bibb himself seems to think his client was Morgenthau, the DA, but that’s a misunderstanding. Prosecutors work for their boss, they don’t represent them. The court record says that a prosecutor’s client is the "people" or "state" of New York. That doesn’t help much, but it helps some. It helps us to focus on the question of why the people or state of New York have an interest in two innocent men serving long prison terms. For that matter, wouldn’t the people or state be better served if the police couldn’t close the books on the Palladium killings, given that the real killers are very likely still at large? The fact is that Bibb didn’t harm any discernible interest of his client.

And don’t think that Bibb’s conduct is totally unusual. A former federal prosecutor tells me that prosecutors often throw cases at the grand jury stage, because they think the case stinks but they’re under political pressure to take it to the grand jury. That’s less conspicuous than Bibb throwing the case at the hearing, but morally it’s hard to see the difference; and if my former prosecutor friend is right, it’s how conscientious prosecutors operate.

In the interest of full disclosure: I’ve never thought that the adversary system is the mightiest engine of truth and justice ever devised. And I’ve always thought that lawyers who shrug their shoulders at injustices they cause and say, "Don’t blame me, blame the adversary system" are ducking their moral responsibilities. Blaming the system is the weasel’s way out.

But even if I’m wrong about the adversary system in general, the prosecutor’s role is different. To "seek justice, not merely to convict" means that prosecutors aren’t supposed to be the ruthless partisan warriors the adversary system presupposes. Bibb was in a tough spot – ordered, for whatever reason, to defend convictions that he thought were wrong. He became a conscientious objector on the battlefield. His way out was unusual enough to land him on the front page of the New York Times. But he did the right thing, and hopefully THAT isn’t unusual.

Jonathan Zittrain, The Future of the Internet -- And How to Stop It

Neil Netanel

In his new book, The Future of the Internet – and How to Stop It, Oxford University Professor of Internet Governance and Regulation Jonathan Zittrain presents a decidedly dystopic view of the Internet. He also offers a “can do” silver lining (that’s the How to Stop It part). But to my mind, Zittrain’s proposals fall short, leaving his portrait of the Internet’s future darker still.

Zittrain’s book wrestles with the problem of how to maintain the Internet’s “generativity” in the face of growing pressure to make it more tame, regulated, and secure. As Zittrain defines it, “[g]enerativity denotes a technology's overall capacity to produce unprompted change driven by large, varied, and uncoordinated audiences.” A generative technology or social system is an ongoing work-in-progress, one that is sufficiently malleable and open that users and participants can readily employ, build upon, and adapt it to a wide array of different tasks. Generative systems thus enable a large number of people to innovate, collaborate, and express themselves with little or no central coordination and control.

Numerous commentators have exalted in the generativity of the Internet, with its loose, consensus-driven technological underpinning, open end-to-end architecture (treating all digital communication as the same and thus allowing maximum capacity for innovation in application platforms), and welter of web sites, blogs, and other spaces for online communication. Zittrain adds a number of important insights.

First, the Internet’s generativity lies not only in the end-to-end openness of the network but also in the network’s endpoints, the personal computers and other hardware that we use to communicate over the Internet. Virtually all the debate over the Internet’s generativity has centered on the openness of the network (often termed “network neutrality”) and content available on the network (principally, the debate over copyright industries’ use of digital encryption and digital rights management). But as Zittrain cogently argues, the proliferation of personal computers, mobile phones, and other network communication devices that are themselves non-generative -- that sharply constrain users’ ability to adapt and use them outside the device’s predetermined functionality or the supplier’s ongoing control– may greatly diminish the generativity of the system as a whole.


Second, there is nothing inherently generative about network communication or the devices used to communicate. As Zittrain describes in rich detail, the Internet as we know it is a result of happenstance and initial engineering design. Digital communications technology can just as well support closed, proprietary networks, like the old AT&T monopoly phone network and today’s cable television and mobile phone systems. Similarly, computer manufacturers’ decision to sell dumb, general purpose computers and Microsoft’s decision to make Windows an essentially open platform, giving application software developers a wide range to innovate, were not foregone conclusions and are no less important to the Internet’s generativity than is the openness of the network itself.

Third, Internet generativity has become a victim of its own success. The openness of the Internet and personal computers have created a vast communications network that millions of people can use not just to communicate but also to distribute new tools of communication and information manipulation throughout the network. The result has been a continuing outpour of useful innovation, ranging from Internet telephony like Skype to search engines like Google. But by virtue of its open design, the Internet is also increasingly populated with the bad computer code used to propagate spam, computer viruses, spyware, identity theft, and the unwanted collection and dissemination of personal information. These deleterious uses are rapidly undermining the usefulness of Internet accessibility and communication. Zittrain delivers a wake-up call to those wedded to the Internet’s current open architecture and libertarian ethos. Given the Internet’s vulnerability to bad code and evil actors’ willingness to exploit that vulnerability, the status quo is increasingly untenable.

Finally, Zittrain argues, our response to bad code should not be to embrace the security of government regulation or non-generative, limited purpose, closed communication devices, such as mobile phones and PCs that run only manufacturer-controlled software and have no capacity to store new applications (Zittrain calls such devices “appliances”). Both would sharply curtail the Internet’s generativity, with the incumbent costs to widespread innovation and self expression. Rather we need to find ways to use the very decentralized initiative and voluntary social cooperation that underlie generativity to cabin the bad innovations. The solutions that Zittrain proffers are, true to the continually evolving, one-size-does-NOT-fit-all character of generative systems, varied and incomplete. They range from social organization, including relying on a dedicated elite, like Wikipedia’s volunteer administrators, who can block certain self-serving and maliciously erroneous edits to the online encyclopedia, to technical fixes, such as designing PCs to store a complete history of all documents and applications for easy restoring in the event of a virus or crash.

It is often easier to diagnose problems than to come up with workable, effective solutions – and certainly the problems surrounding the Internet are no exception. So it is perhaps not surprising that Zittrain’s proffered remedies are less convincing than his diagnosis. The Wikipedia administrators impose an element of central control over Wikipedia in order to preserve much of its generativity (the ability of any registered user to add or edit entries). That might work for similar projects that feature a dedicated elite of administrators and knowledgeable participants, but it seems ill-suited to address the broader problems that threaten the viability of the Internet – spam, identity theft, and the like. Zittrain seems to agree. He proclaims in the book’s concluding paragraph that Internet generativity actually depends upon millions of users experiencing the Internet as something with which they identify and belong and that they will accordingly actively protect and nurture.

If so, I am pessimistic: I just don’t see an emerging global sea of active, participatory, and technologically savvy Internet citizens coalescing to save the Internet from bad actors. Similarly, the technical fixes that Zittrain proposes all seem to require a level of time and technological sophistication that most Internet users lack: computers divided into safe and experimental virtual PCs, software that shares data about what programs causes problems on other computers (but, I suppose, that somehow keeps that information from those who would use it to cause more problems), tools that enable Internet users to tag the personal data that they put on the Internet to express their privacy preferences about how that data ought to be indexed and used (and hope that others will honor those preferences), and other tools that inform us when others are using data about our online behavior (I’m not sure what would be worse: facing an inbox filled with spam or receiving a constant stream of alerts telling me that I should read about how data of my online behavior is being used).

Zittrain’s book is a must read for those who care – or who should care – about the Internet’s future. But don’t expect to find a happy end of how to stop it.


Monday, June 23, 2008

The Strangest (and Perhaps Most Revealing) Sentence in Justice Scalia's Boumediene Dissent

Marty Lederman

It's the penultimate sentence: "[M]ost tragically, [the Court] sets our military commanders the impossible task of proving to a civilian court, under whatever standards this Court devises in the future, that evidence supports the confinement of each and every enemy prisoner."

Impossible?! I rather doubt it. Indeed, it will be surprising if the habeas courts do not rule in the government's favor in a majority of the 100 or so petitions that might be resolved on the merits. (After all, the government itself has already released the vast majority (hundreds?) of detainees who the Pentagon determined to be not detainable even under the Administration's own broad standards. Presumably, then, it continues to detain only those against whom the evidence is relatively stronger.) [Or perhaps not. Note that in an MCA/DTA review of a CSRT decision in the Parhat case, a very diverse panel of the court of the D.C. Circuit reversed the CSRT's detention decision last Friday. Because the opinion contains classified information, it hasn't yet been released. But this could be a very significant development. It might even establish a working definition of "enemy combatant" for use by the habeas courts.]

So what explains Justice Scalia's assumption that it will be "impossible" for the government to justify detentions of the habeas petitioners? Well, take a look back at another curious passage earlier in his dissent, the one in which he notoriously complains that "at least 30" of the detainees the Pentagon itself has released have allegedly "returned to the battlefield." That assertion is dubious, at best. But my focus here is slightly different: Scalia's point in this part of his opinion is that the Pentagon itself really has no good idea which of its detainees are dangerous and which are not; just as he believes that there have been many "false negatives" (the mythical returnees to the "battlefield"), he also appears to concede that there have been false positives -- that the military might, indeed, have detained many prisoners based on precious little reliable evidence that they present a threat to the United States. Scalia pointedly refers to "the incredible difficulty of assessing who is and who is not an enemy combatant in a foreign theater of operations where the environment does not lend itself to rigorous evidence collection."

This earlier statement is very interesting for a couple of reasons. First, it demonstrates why Scalia is dreadfully wrong when he asserts that "the category of prisoner comparable to these detainees are . . . the more than 400,000 prisoners of war detained in the United States alone during World War II[, none of whom] was accorded the right to have his detention validated by a habeas corpus action in federal court." Traditional POWs in traditional wars were not denied a right to contest their detentions — they simply had no basis for contesting them. The vast majority of such detainees were uniformed, and captured in a traditional combat setting. There was no real dispute about their detainability, and the alternative to detention was being shot on sight -- really, what had they to complain about? Moreover, they were accorded the sort of humane treatment required for POWs, and were not tortured or coerced. And because the conflict was between nation states, it was likely they would be exchanged or repatriated after not too long a period. There was a dearth of habeas actions filed by such prisoners not because courts refused to recognize the writ, but because there was no real basis for challenging detention in the mine run of cases.

In this conflict, by contrast, the U.S. has detained thousands of persons without very reliable assurances that they are, in fact, dangerous. Its detention practices, in other words, have been much more indiscriminate and uncertain -- and motivated principally by a design to interrogate as many persons as possible who might conceivably be able to offer some actionable intelligence, rather than (primarily) for the traditional purposes of incapacitating and weakening the enemy. When you're looking for a needle in a haystack, you tend to collect a lot of hay. That is exactly why the military itself has released such a high percent of the GTMO detainees: because its criteria for detention in the first instance were so permissive.

Second, I think this explains why Justice Scalia concludes at the end of his opinion that it will be "impossible" for the military to justify the remaining detentions. In his view, there is simply no way of telling who is an al Qaeda combatant and who is not. Now, if he were correct about this -- if indeed it will be virtually impossible for the military to come forth with evidence supporting the confinement of most of these remaining detainees -- one would think that would say a whole lot about the legitimacy of the GTMO detention program: If the detentions are predicated on either flimsy and unreliable evidence, or evidence that the military might be reluctant to show a court because of what it reveals about the nature of our interrogation practices, the legal legitimacy of the program would be seriously undermined.

But not according to Justice Scalia. This is the most remarkable thing of all about his opinion: As I read it, in his view if reliable evidence does not tell us who is, and who is not, an al Qaeda operative, the proper solution is not to release the detainees but to detain indefinitely anyone who is (in the military's view) at all suspicious. This explains, I think, the insuperable gulf between the majority and the dissent in Boumediene.

The thrust of Justice Scalia's apparent reasoning is captured rather nicely by Stephen Colbert, in this exchange last week with my colleague Neal Katyal:
Colbert: What is the practical outcome of [Boumediene]? So these guys -- boom!, they’re sprung from prison right now? They’ll all be out now, right?

Katyal: Absolutely not. What they were saying was we just want to have a fair hearing before a federal judge.

Colbert: So some of them will get out – a bunch of them will get out, like a third of them or something like that?

Katyal: The innocent ones, yeah.

Colbert: But we don’t know if any of them are innocent.

Katyal: And we don’t know if any of them are guilty.

Colbert: Right! – So we’d better just keep them all in there, for safety’s sake, ya know? The devil you know and the devil you don’t know – just lock them all up!

Sunday, June 22, 2008

The Key Questions About the New FISA Bill

Marty Lederman

We've invited David Kris to publish some posts explaining the new FISA bill. Check out his first two posts, just below David Luban's important Commander in Chief post. David K. was Associate Deputy Attorney General in charge of national security issues from 2000 to 2003, and before that he was in the Criminal Appellate section of the Criminal Division. He was widely regarded as one of the very best lawyers in the Department -- and became one of the most trusted, most well-respected authorities in the Department on criminal law and electronic surveillance issues once he moved on to the DAG's Office. As I've written here before, he's extremely thorough, careful, and impartial. We're thrilled to have his input here.

David's posts have prompted me to think about what might be the most important questions the new law will raise. There is a general sense out there that this new law gives the government substantially more powers to surveille communications of U.S. persons -- perhaps in ways that implicate the Fourth Amendment -- but there is, thus far, very little understanding of how that might be so, and how the new surveillance regime will differ from the one in place from 1978 to 2001.

David has begun to answer some of the more important questions. The answers to others remain hidden in the shadows and the vagaries of the law -- and some might never become public. But I think that the answers must be at the heart of any serious assessment of what Jack calls the "New Surveillance State" under which we will be governed very soon. I would be very grateful to David and other readers and bloggers -- and perhaps even the Congress! -- if they can provide further insight into what those answers might be. [This reminds me: The most troubling thing of all about the new statute is probably that virtually no one outside the executive branch has the slightest idea what it authorizes, or how, exactly it will work in practice. Folks such as David and I can provide our best guesses, but this opaque legislative process shares nothing in common with the extensive, transparent debate that occurred during the three years that FISA was under consideration. For more -- much more -- on these process issues and the possible technological practices that might be underlying this issue, I recommend a "Breakfast Table" discussion that David and I conducted at Slate with Orin Kerr and Patrick Keefe last year. Upon rereading it, it occurs to me that the more things change, the more they . . . remain inscrutable.]

But in any event, let's start with the key questions, below the fold . . .
QUESTION ONE: Why has the Administration been so desperate to "modernize" or to circumvent FISA, when its surveillance capabilities were already so extensive: (i) FISA doesn't regulate international-to-international phone calls at all, as long as a U.S. person in the U.S. is not a target; (ii) FISA doesn't regulate any communications intercepted overseas, even if they are international-to-domestic; (iii) to the extent FISA covers international-to-international e-mails intercepted from facilities in the U.S., everyone agrees it should not, and thus that would be an uncontroversial fix (at least assuming there's some way to identify such e-mails in the first instance); and, most importantly, (iv) the FISA Court must, and does, regularly authorize NSA surveillance whenever the agency can demonstrate probable cause that the target of its surveillance is a foreign power (including al Qaeda) or an agent thereof.

In light of all these significant authorities, why the desperate rush to legislate?

David provides the answer to this question, I think: The NSA wishes to be able to engage in what he calls "vacuum-cleaner" surveillance of U.S. facilities in circumstances where (i) there is no way of knowing in advance which calls are wholly international and (ii) there is no way of knowing in advance which of the targets of such vacuum-cleaner surveillance are foreign powers or their agents. The new law apparently will allow this sort of vacuum-cleaner surveillance by authorizing any and all surveillance "targeting . . . persons reasonably believed to be located outside the United States to acquire foreign intelligence information." Under this new standard, there's no need that the surveillance have any connection to al Qaeda, or terrorism, or even to national security. The only substantial requirements are that someone overseas be a "target" and that one "significant purpose" of the surveillance be to acquire "foreign intelligence information," which is very broadly defined to include most anything that occurs overseas and in which the federal government might have an interest (including information necessary to protect against the full range of foreign threats to national security, including both international terrorism and espionage, and information with respect to a foreign power that is necessary to the national defense or foreign affairs).

This sort of "vacuum" surveillance could not be approved under the old FISA scheme, which requires either that the calls be wholly international, or that the interception be made overseas, or that the NSA demonstrate evidence in advance that the target is an agent of a foreign power. Under the new law, the NSA can engage in surveillance where none of those three criteria are met. [NOTE: Many critics of the bill are focusing on the fact that there is no meaningful judicial review to ensure that each case of surveillance meets the new substantive standards. But because those substantive standards are now defined so broadly -- much, much broader than the "agent of a foreign power" standard under FISA -- I doubt that individualized court review to ensure compliance with the statutory standard would make much difference in terms of limiting the scope of surveillance. The real issue is what is permitted.]

QUESTION TWO: As a practical matter, what will the change in FISA coverage mean for the scope and breadth of NSA's interception of domestic-to-international communications involving U.S. persons?

When FISA was enacted, most Americans made very few international phone calls, and the birth of e-mail was many years away. Thus, the NSA's interceptions overseas did not have much of a practical impact on many communications of U.S. persons. Today, by contrast, many of us make innumerable, regular international communications, by phone, e-mail, and other electronic media. Although the NSA theoretically has the ability to intercept those communications overseas, it remains the case under FISA that not too many of our communications are intercepted -- at least not without proof that we are agents of a foreign power.

Under the new regime, presumably NSA (or its computers, anyway) will be permitted to intercept considerably more communications between U.S. persons here in the States and persons abroad -- perhaps even most of those international phone calls, e-mails and other communications, because the new law allows any interceptions of persons overseas if collecting "foreign intelligence information" is a significant objective.

Am I right about this? What is the real, practical difference between the volume and types of domestic-to-international communications that NSA could intercept under FISA until 2001, and those it can and will intercept under the new law? Is it as vast a difference as I am suggesting? I'm really not sure.

David's posts thus far have not quite addressed that question head-on; I hope he'll be able to speak to it further in future posts. Unless and until we learn the answer to this question in some meaningful detail, it will be very difficult for those of us not "in the know" to accurately evaluate the effect of the new law on our privacy -- and will make Fourth Amendment analysis exceedingly speculative and difficult.

QUESTION THREE: When, in the course of its surveillance of overseas targets, the NSA inevitably obtains vast amounts of information about U.S. persons who communicate with those foreign targets, what can the NSA do with that U.S.-person information? Can it permanently store the information? Allow human analysts to study it? Share the information with other agencies (including law enforcement agencies)? Perhaps most importantly -- Can the NSA plug the communications into its computer programs that search for key words, or for "metadata" patterns," so that those computers can identify U.S. persons for further surveillance?

The answer to this all-important question depends on the nature of the required "minimization." The new law will require the Attorney General to adopt minimization procedures consistent with FISA section 101(h). Section 101(h), in turn, requires that such procedures generally "minimize the acquisition and retention, and prohibit the dissemination, of nonpublicly available information concerning unconsenting United States persons." So far, so good. The trick, however, is that such minimization need only be made "consistent with the need of the United States to obtain, produce, and disseminate foreign intelligence information." (And recall how broadly "foreign intelligence information" is defined.) Moreover, even where the information is not foreign intelligence information, section 101(h) permits "the retention and dissemination of information that is evidence of a crime which has been, is being, or is about to be committed and that is to be retained or disseminated for law enforcement purposes." That is to say, even if you were not the original target of the surveillance, the government can make use of and disseminate information about you if your international phone calls or e-mails reveal evidence of any crime. And, of course, if those same communications provide evidence that you are an agent of a foreign power, that evidence can then be used to obtain an order for surveillance of your own phone and/or computer more broadly, under FISA itself.

The minimization requirements, in other words, are small solace: The government may not use or disseminate the information it incidentally obtains concerning U.S. persons . . . unless it has a (national security, foreign affairs or law enforcement) need to do so.

Now, the government quite understandably responds that these minimization requirements are nothing new: They are exactly the same as the requirements that apply when the government incidentally obtains information about U.S. persons from FISA surveillance, or from surveillance occurring overseas, which is not subject to FISA.

Which is true (I think). However, that fairly minor current problem expands exponentially where, as under the new law, the government has a vastly expanded reservoir of foreign-to-domestic communications from which it can cull information about nontargeted U.S. persons.

It seems to me, then, that "modernizing" and strengthening the old minimization standards, to deal with the vast expansion of NSA authority to "incidentally" obtain U.S. person information, and to deal with the explosion of international communications by U.S. persons, is a critical area for further study and possible amendment.


QUESTION FOUR:
How important is the "exclusivity" provision as a check on even broader executive surveillance practices?

Not very important, I think -- not for several years, anyway. It'll probably be surplusage come January, because Senator Obama has virtually pledged that he would not assert a constitutional authority to disregard the law, and Senator McCain has suggested likewise. Even for President Bush in the next few months, it'll be a non-issue, but for a different reason -- namely, that the new law itself will allow him to do everything he wants, and therefore there will be no need for him to assert any constitutional authority to disregard. This passage from George Terwilliger on the News Hour the other night made the point quite well:
[The exclusivity provision is] very important. And it's important to understand the balance that was struck as to that provision itself. The reason the president had to resort to the [alleged constitutional] authorities that he used before this legislation was because what needed to be done couldn't be done under the old law. Now the procedures have been changed, and the authorization that's been given has been broadened sufficiently to make it possible to do what the intelligence professionals say we need to do, but to do it under these FISA proceedings.
In other words: The President will only violate the law when he thinks it's too restrictive, and this law is not restrictive at all, so there's nothing to worry about. The "balance that was struck," to which Terwilliger refers, is that the White House acceded to the exclusivity provision, in exchange for substantive standards so permissive as to ensure that the exclusivity provision will never be pertinent.

QUESTION FIVE: How can there ever be a meaningful adequate public accounting of the Bush Administration's lawbreaking from 2001 to 2007? After the telecom immunity goes into effect, the odds of a judicial assessment of the legality of the TSP will become increasingly slim. Thus, whether and when the public can ever find out about the extent of the lawbreaking -- and the evolution of the legal manipulation on which it was based -- will almost certainly depend upon whether the next President decides to allow a public accounting, something that will be very difficult for him to accomplish because of the NSA's and telecoms' insistence that everything about the TSP remain classified.

* * * *

Of course these aren't the only important questions. Others will include: whether the new law adequately protects against wholly domestic warrantless wiretapping; whether there is a sufficiently specific and limiting definition of "targeting"; whether the IG and congressional oversight is sufficiently rigorous; whether, as I suggested earlier, the directive that courts dismiss lawsuits against telecoms, regardless of the merits of such suits, raises an arcane constitutional problem; etc. And I'm sure I've missed several others.

But that's plenty for starters.

On the Commander in Chief Power

David Luban

My article on the President’s commander in chief power has now been published in the Southern California Law Review, available here; it’s different (hopefully better) than the pre-print on SSRN. The aim of the paper is to understand the nature of the commander in chief power by looking at military history, U.S. founding era history, and the contemporary literature on civilian-military relations. The conclusion is that the commander in chief power should be understood to encompass a rather narrow set of powers to command and supervise the military, not the broad and uncircumscribed power that the Bush Administration has claimed.

The basic idea of the paper is similar to Jack’s post here. Historically, there are two very different reasons for fusing the top civilian leader and the military commander in chief. One reason is military efficiency: it’s to create an empowered warrior-executive who consolidates political authority with military expertise. The other is a separation of powers idea: it’s to head off possible military coups by placing a civilian at the top of the military chain of command. Of course, that creates problems of its own, notably that a civilian commander in chief might abuse his power domestically (think Caesar or Cromwell) or launch military adventures. But, assuming that those problems can be solved by a well-designed constitution, the point of the Commander in Chief Clause is to ensure civilian control of the military, not to create a warrior-king.

I call the first theory “consolidationist,” because it aims to consolidate civilian and military supremacy in a single fighting leader. It’s hardly unfamiliar: it was the prevailing theory in ancient heroic societies – the world depicted in epic poems like Gilgamesh and The Iliad, and (in real life) the world of Alexander the Great. As the military historian John Keegan puts it, military risk-taking legitimized rule. Consolidationism was also the prevailing theory in feudal Europe, where kings and nobles were supposed to display military prowess and honor, and where vassals exchanged loyalty for military protection.

The second theory is “separationist,” because it aims to set up institutional checks and balances against Caesarism; and – no surprise – it was the theory of the constitutional framers. Part of my paper shows how, beginning in the sixteenth and seventeenth centuries, the consolidationist theory began to erode. (Briefly: guns made it too easy to inflict a meaningless, unheroic death on fighting kings, so kings stopped leading the troops; and bigger states meant that kings needed to spend less time fighting and more time governing.) The last British king to lead troops in battle was George II in 1743.

A second part of the paper reviews the constitutional debates to show how the framers and ratifiers had all three of the classic separationist concerns (fear of military coups, fear that the civilian commander would abuse his military command, and fear of reckless military adventurism). Those separationist concerns are reflected in the Constitutional grant of Article I war powers, but also in the militia clauses and the second and third amendments.

Finally, with a tour through contemporary debates about civilian control of the military, the paper argues that the basic separationist concerns are still valid today (so, even if you’re not an originalist, you should still think of the civilian commander in chief the way the framers did). This part of the discussion focuses on contemporary theorists (Samuel Huntington, Peter Feaver, Eliot Cohen, Andrew Bacevic) and draws examples from the Vietnam and Iraq wars showing how dangerous it is for civilian leaders to think of themselves as warrior-executives.

One big difference between the consolidationist and separationist theories of the commander in chief power is that consolidationism offers institutional competence reasons for other branches of the government to defer to the president on military matters. It views the civilian commander in chief as a warrior-executive. Separationism offers just the opposite of an institutional competence argument: it emphasizes that the commander in chief is a civilian – a military amateur. Especially when the President claims commander in chief powers over matters that otherwise don’t look particularly military, other branches of government have no reason to defer to him. Think, for example, of the President’s initial assertion (later rebuffed by the courts) that he had unreviewable C-in-C authority to declare Jose Padilla an unlawful enemy combatant after having Padilla arrested in Chicago. As none other than Michael Mukasey argued at the time (Padilla v. Bush, 233 F.Supp.2d 564, 607-08 , page 95 here), deciding on the basis of evidence which legal pigeonhole a person belongs in is the classic institutional competence of a judge. Where Mukasey (the judge in Padilla’s case) erred was in going on to say that despite institutional competence, the President has the constitutional commission of making such calls.

This paper reaches many of the same conclusions as David Barron’s and Marty Lederman’s magnum opus on “the commander in chief at the lowest ebb,” available here and here. But the argument is different enough that I don’t think they’re redundant.


A Guide to the New FISA Bill, Part II

Guest Blogger

David Kris


Yesterday, in discussing H.R. 6304, the FISA modernization bill passed by the House on Thursday, I identified the key elements of current FISA, and described what I see as the main legal and operational arguments for and against modernizing the statute. Today, I’d like to describe the Bush Administration’s actual efforts to “modernize” electronic surveillance. There have been, essentially, three Administration approaches to modernizing electronic surveillance – one directed at each branch of the federal government. As it turns out, the first two approaches seem to have failed, but the third (embodied in H.R. 6304) appears to be on the verge of success.

a. Executive Branch. The Bush Administration’s first approach to modernization, illustrated by the TSP, was simply to ignore FISA. That method, relying on unilateral action by the executive branch, prevailed without public knowledge or challenge for approximately four years, until the famous December 2005 story by the New York Times. Much has been written about this period, on Balkinzation and elsewhere.

b. Judicial Branch. A little more than a year later, the government appeared to find a judicial solution to the problem of FISA modernization, advancing a new interpretation of the statute that at least one judge accepted. In January 2007, the FISA Court “issued orders authorizing the Government to target for collection international communications into or out of the United States where there is probable cause to believe that one of the communicants is a member or agent of al Qaeda or an associated terrorist organization.” As a result of these orders, the Department of Justice (DOJ) announced, “any electronic surveillance that was occurring” under the TSP “will now be conducted subject to the approval” of the FISA Court. Although DOJ so far has refused to disclose the legal theory underlying these court orders, it is worth considering whether and how they could have both complied with FISA and, as DOJ asserted, allowed the necessary “speed and agility” of warrantless surveillance. The following paragraphs set forth an educated guess about the January 2007 FISA Court orders, drawn from a much longer discussion in Chapter 15 of my book .

As noted in yesterday’s post, FISA has three essential substantive requirements: first, a target that is a foreign power or an agent of a foreign power; second, a facility being used by that target; and third, minimization. To satisfy these requirements without sacrificing speed and agility, it is necessary to identify the broadest possible target and facility, which will yield the broadest possible authorization order, which will require the fewest possible court orders for the most surveillance.

Identifying the broadest possible target is relatively straightforward under FISA – foreign powers (such as al Qaeda) are far broader than individual agents of a foreign power (such as Osama Bin Laden). This is entirely legitimate, and conventional, as long as the government is genuinely interested in getting information about al Qaeda, rather than any particular member of al Qaeda. If the government focuses its attention too much on any single terrorist, then that terrorist becomes the target. But if the government uses a wide-angle lens, focused on the group as a whole, it is comfortably within the requirements of FISA.

The broadest possible facility is harder to identify. A “facility” in FISA is the electronic analogue for location or place in an ordinary search – a concept with roots in the Fourth Amendment’s Particularity Clause. In a conventional criminal case, for example, the police obtain a warrant to search for the murder weapon in the suspect’s apartment. The warrant is not issued for the suspect’s entire apartment building, let alone his entire street or neighborhood, because that would be insufficiently particular. But nor is the warrant limited, for example, to the top drawer of the suspect’s desk – that is more particular than the Fourth Amendment requires. The location specified in a search warrant must be “reasonably” particular, and so too a FISA facility must be reasonably particular. For example, as noted in yesterday’s post, the traditional FISA facilities are 10-digit telephone numbers or name@domain e-mail addresses.

As far as I can determine, the government seems to have persuaded the FISA Court in January 2007 that the international gateway switches, which essentially are the junctions between the U.S. and the rest of the world’s telecommunications grids, are reasonably particular FISA “facilities,” and that al Qaeda is using them. If that is right, it means that a handful of orders gave the government access to all, or almost all, of the international telecommunications traffic entering or leaving the United States. That is very speedy and agile.

The problem, of course, is that while al Qaeda is using those switches, so is everyone else. Even under the most extreme estimates, al Qaeda cannot account for more than a tiny percentage of calls transiting the switches.

It is possible that the government and the FISA Court saw this problem, and dealt with it through minimization. What they may have decided is that while the government has authority to conduct surveillance of al Qaeda on the switches, it cannot actually have someone monitor – listen to or record – any individual call without probable cause (or something like probable cause) that at least one party to the call is a terrorist (or something like a terrorist). This minimization standard may resemble the normal probable-cause determination required by FISA for agents of a foreign power, except that it is made by the executive branch rather than by the FISA Court.

To understand the function of such a FISA order, consider an (admittedly flawed) analogy to the world of ordinary searches. Imagine that the FBI obtains a warrant to search for drugs anywhere in New York City. Standing alone, this seems too broad – a clear Particularity Clause problem. But now imagine that the warrant provides expressly that while the FBI has nominal authority to search all buildings in New York, it may not enter any particular building unless a Supervisory Special Agent or higher-ranking official finds probable cause that drugs are indeed located within that building. Rightly or wrongly, this is the basic idea behind the January 2007 orders as described above. Again, the clever aspect is that those orders moved the bedrock probable-cause requirement of FISA from the front end of the statute, where a judge decides it, to the back end, where the executive branch applies it as part of minimization, subject only to after-the-fact review by the court. If this is indeed what the FISA Court decided in January 2007, it is easy to understand why the government announced the result publicly, as it seems to solve many of the problems posed by the TSP being conducted in violation of FISA.

It appears, however, that in April 2007, another FISA Court judge rejected the government’s interpretation at least in part, imposing limits and conditions that the executive branch apparently could not tolerate. As the DNI explained to Congress in September 2007, “we were devoting substantial expert resources towards preparing applications that needed FISA Court approval. This was an intolerable situation, as substantive experts, particularly IC subject matter and language experts, were diverted from the job of analyzing collection results and finding new leads, to writing justifications that would demonstrate their targeting selections would satisfy the statute.”

c. Legislative Branch. The government’s setback in the FISA Court led to a third approach, involving the legislative branch, that appears to have culminated in the bill passed by the House of Representatives on Thursday. I’m still working my way through the bill, but here is my initial take on its essential provisions, with new FISA Title VII section numbers noted in parentheses so any interested readers can check my work and correct it if I’ve messed up.

The new bill allows the government, “[n]otwithstanding any other provision of law,” to engage in the “targeting of persons reasonably believed to be located outside the United States to acquire foreign intelligence information” (702(a)). There is no probable-cause requirement; the only thing that matters is (the government’s reasonable belief about) the target’s location. The acquisition must be to obtain foreign intelligence information, which includes information necessary to protect against the full range of foreign threats to national security, including both international terrorism and espionage, and information with respect to a foreign power that is necessary to the national defense or foreign affairs. The acquisition is not limited to any particular facility or place (702(g)(4)), which means that the government can use it to direct surveillance (or other acquisition methods) at various facilities without obtaining a separate authorization for each one.

The acquisition authority granted by the statute is subject to several essential requirements and limitations:

  • First, the acquisition “may be conducted only in accordance with” what are referred to in the bill as “targeting procedures” (702(c)(1)(A)) which must be “reasonably designed” to “ensure that any acquisition … is limited to targeting persons reasonably believed to be located outside the United States,” and to “prevent the intentional acquisition” of communications “known, at the time of the acquisition,” to be purely domestic (702(d)(1)) – these communications remain subject to surveillance under traditional FISA (702(b)(4)).

  • Second, the acquisition “may be conducted only in accordance with” some version of traditional “minimization procedures” (702(c)(1)(A)), which must be “consistent with” FISA’s definition of that term for electronic surveillance or physical searches (702(e)).

  • Third, a senior Justice Department official and the Director of National Intelligence must certify in advance (or if necessary, a week after acquisition begins (702(g)(1)), that the targeting and minimization procedures satisfy the statutory requirements, that a “significant purpose” of the acquisition is to obtain foreign intelligence information, and that the acquisition involves the assistance of an electronic communication service provider (702(g)(2)).

  • Fourth, where the targeted person is a United States person – e.g., a U.S. citizen or green card holder – more restrictive measures apply depending primarily on whether the acquisition occurs inside or outside the United States (703 and 704).

Under the bill, the FISA Court reviews the targeting and minimization procedures to ensure that they meet the statutory requirements and the Fourth Amendment (702(i)), and orders modifications if necessary; the court reviews the certification only as a matter of form, to ensure that it “contains all the required elements” (702(i)(3)(A)-(B)). The court’s order is issued to the government only – there is no provision in the bills for a secondary order. Instead, the government itself issues a “directive” to electronic communication service providers requiring their assistance (702(h)). Providers may challenge such directives in the FISA Court (702(h)(4)), and the government may seek FISA Court orders compelling compliance from a recalcitrant provider (702(h)(5)). Thereafter, providers may be punished via contempt of court for noncompliance (702(h)(4)(G) and (h)(5)(D)). There are reporting and oversight procedures, including review by Inspectors General of the government’s compliance with the targeting and minimization procedures, and the number of targets originally believed to be abroad but later determined to have been located in the United States (702(l)), and there is a reiteration of FISA’s 1978 “exclusivity provision” in Section 102 of the bill.

It is interesting to compare the pending legislation to the TSP as it may have been implemented just prior to, and just after, the January 2007 FISA Court orders. There appear to be two main differences. First, the pending legislation applies only to targets located abroad, while the January 2007 orders may have allowed surveillance of targets in the U.S. (as long as they were making international calls). Second, more importantly, the pending legislation focuses only on the target’s location (or the government’s reasonable belief about his location) not his status or conduct as a terrorist or agent of a foreign power. In other words, there is no requirement that anyone – the FISA Court or the NSA – find probable cause that the target is a terrorist or a spy before (or after) commencing surveillance. This may well be a reaction, or perhaps an over-reaction, to the FISA Court’s April 2007 order, which appears to have frustrated the government by requiring more, or more frequent, reporting about the status of certain surveillance targets. But, as discussed above, the Administration’s request for this aspect of the bill seems to have provoked a countervailing limitation from Congress, in that the pending legislation extends some version of FISA to surveillance conducted abroad of a U.S. person who is located abroad; today, such surveillance is conducted unilaterally by the executive branch, without statutory regulation or judicial review and approval, albeit with a requirement that the Attorney General find probable cause that the U.S. person is an agent of a foreign power. (It is also interesting to compare the pending legislation to the current, traditional version of FISA, but in an abundance of caution I plan to seek prepublication review for that comparison, and therefore cannot provide it here.)

Looking ahead, I believe the pending legislation probably represents only an interim solution to the problem of FISA modernization. First, it is extremely complicated. As I read the bill, it establishes at least five different categories of full-content acquisition: (1) traditional electronic surveillance, (2) traditional physical searches, (3) surveillance or searches targeting non-U.S. persons reasonably believed to be abroad, (4) surveillance or searches targeting U.S. persons reasonably believed to be abroad when the acquisition occurs in the United States, and (5) surveillance or searches targeting U.S. persons reasonably believed to be abroad when the acquisition occurs outside the United States. FISA has always been an arcane and difficult statute, but the intricacy of the pending legislation risks confusing the government officials who must apply it, often under substantial time pressure. This can lead to errors of both major types – improper acquisition of private communications (or other information) that undermines liberty and privacy, and improper abstention from acquisition that undermines security.

In addition, the pending legislation continues to rely, at least to some degree, on the location of the surveillance target. For now, that may be the best we can do. For the long run, however, we may need more radical change. If the government genuinely cannot determine a person’s location, it makes no sense to use geography as a trigger for FISA’s warrant requirements. In those circumstances, a geographical approach will always be too broad or too narrow – treating all communicating parties, or none, as if they were in the United States.

There is more to say here, and some of it I (and others) have said elsewhere, but for here and now I have probably already said too much. Thanks.

Saturday, June 21, 2008

A Guide to the New FISA Bill, Part I

Guest Blogger

David Kris


Marty Lederman and Jack Balkin invited me to submit a post on the FISA modernization bill (H.R. 6304) that was passed on Thursday by the House of Representatives, and that appears to be on the verge of becoming law. To understand this new legislation, I think you need to appreciate three matters:

(1) some elements of the current version of FISA, which are what is at stake in the (soon to be concluded) debate over modernizing the statute;

(2) the main legal and operational arguments for and against modernizing FISA; and

(3) the Bush Administration’s actual efforts to modernize electronic surveillance, beginning with the NSA’s Terrorist Surveillance Program (TSP) in 2001, and ending with the new legislation.

Even in abbreviated, non-technical form, these three matters require some heavy lifting, so I’ll cover the first two today, and then address the third in a separate post that will appear tomorrow. Most of what I say in both posts comes wholesale from a previously published whitepaper and my book , both of which discuss these issues in much greater detail. (This allows me to avoid separate prepublication review of these posts; the government’s reviewers are usually very responsive, but it’s tough for them to keep up with the pace of the blogosphere, especially on a Friday night.)

1. Background on FISA

FISA is a very complex statute, but for present purposes it has three essential substantive elements. First, there is the bedrock probable-cause requirement that the “target” of the surveillance – the entity from or about whom the government seeks information – be either a “foreign power,” or an “agent of a foreign power.” These terms are defined in detail in the statute, but for present purposes it is enough to say that they mean more or less what you think they would mean. For example, a “foreign power” includes not only a foreign government, but also an international terrorist group, like al Qaeda; and an agent of a foreign power includes someone who works on behalf of a foreign power in certain specified ways, like Osama Bin Laden.

Second, there must be probable cause that the target of the surveillance – the foreign power or agent of a foreign power – is using or about to use the “facility” at which the surveillance will be directed. The term “facility” is not defined in FISA, but legislative history makes clear that it is the electronic analogue to “location” in an ordinary physical search; for example, the traditional examples of “facility” are either a 10-digit telephone number or a standard name@domain e-mail address.

Third, FISA dictates the use of specific “minimization procedures” that require the government, in the implementation of surveillance, to balance its foreign intelligence needs against Americans’ privacy interests. In particular, minimization procedures must be “reasonably designed in light of the purpose and technique of the particular surveillance, to minimize the acquisition and retention, and prohibit the dissemination, of nonpublicly available information concerning unconsenting United States persons consistent with the need of the United States to obtain, produce, and disseminate foreign intelligence information.” These minimization procedures can differ from case to case depending on the facts and circumstances, and they are in part classified to avoid suggesting countermeasures to our adversaries.

Procedurally, in general, FISA requires approval (and signatures) from two very senior government officials – for example, the Attorney General and the FBI Director – and a judge of the FISA Court, that the statutory requirements have been met for each target and facility being surveilled. By and large, the government has to get these written approvals before surveillance of any target or facility may begin (there are some exceptions).

Details aside, the key point is that FISA electronic surveillance is very different from ordinary foreign intelligence surveillance that is outside the statute’s scope. With respect to foreign intelligence surveillance not covered by FISA, the Director of National Intelligence sets general collection requirements – for example, “determine the order of battle of the army of the government of Zendar” – and the intelligence community collects against those requirements without case-by-case approval from the Attorney General or a judge. The collectors follow their own internal minimization and related procedures (set out in documents with names like DOD 5240-1R and USSID-18), but they undeniably enjoy more “speed” and “agility” in this realm than they do under FISA. This kind of surveillance, outside FISA’s scope, has in the past been referred to by at least one Attorney General as “vacuum-cleaner” surveillance; I use the term here in a non-pejorative sense, only as a convenient shorthand.

Fundamentally, this is what I think is at stake in the debate about FISA modernization: whether and to what extent the government will be subject to FISA’s individualized warrant requirement, rather than a vacuum-cleaner regime, for its foreign intelligence surveillance. The debate concerns not only the substantive standards for surveillance, but also the question of who applies those standards, in what manner, at what time, and subject to what minimization requirements.

2. Arguments for FISA Modernization

There are three main arguments for modernizing FISA, only the first of which has been advanced publicly with any force by the Bush Administration. This first argument is that FISA must be modernized because, in the years since 1978, the statute’s regulatory reach has been artificially expanded by the transition from satellite to fiber optic cable for carriage of transoceanic communications. Satellites use radio waves to carry international calls, and FISA does not regulate surveillance of international radio communications to or from the United States (unless the target of the surveillance is a particular, known, U.S. person who is located in the United States). But FISA does regulate surveillance of international wire or cable communications, to or from the United States, when conducted in this country (even if the target is a non-U.S. person). Thus, the government claims, surveillance of international communications that used to be conducted outside of FISA is now subject to the statute because of changing technology. A review of telecommunications history, detailed in my whitepaper, shows this claim to be exaggerated: the transition from satellite to cable was neither as dramatic, nor as unanticipated, as the government argues.

On the other hand, there is a second, related point that has not been as well understood. FISA was written to permit warrantless surveillance not only of international radio communications, but also of international wire or cable communications, if the wire surveillance was conducted outside the United States – e.g., in the Atlantic ocean. That is, FISA does regulate surveillance of international wire or cable communications, to or from the United States, when conducted inside this country. As long as no particular American in the U.S. is being targeted, however, FISA does not regulate surveillance of those same communications, on those same wires or cables, when conducted on a portion of the wire or cable located outside this country. Today, it appears, the government wants or needs to conduct such surveillance inside the United States, probably because it needs the assistance of the telecommunications providers and their equipment. Bringing the surveillance into this country, however, also brings it under FISA. One of the key issues in the debate about FISA modernization is whether that change in the location of the surveillance should continue to trigger the statute’s application.

Third and finally, there is the problem of e-mail. Nearly two years after launching its campaign for FISA modernization, the government publicly stated that FISA poses a problem for surveillance of e-mail. Here the evidence is clear: FISA regulates surveillance of e-mail more than it regulates surveillance of telephone calls. In particular, while FISA does not regulate (and has never regulated) surveillance of a foreign-to-foreign telephone call – e.g., a call from Paris to London – even if monitored inside the United States, it does regulate surveillance of a foreign-to-foreign e-mail message if acquired from electronic storage inside the United States. Most knowledgeable observers agree that this is an anomaly in need of correction – there is no substantial debate about this.

As it turns out, however, changing technology and increasing globalization make it very difficult to devise a narrowly tailored legislative solution to this recognized anomaly. With the advent of web-based communication and other developments, the government cannot always determine – consistently, reliably, and in real time – the location of parties to an e-mail message. Thus, a FISA exemption for foreign-to-foreign e-mail does not always help the government, because it cannot always verify the “to-foreign” part of the exemption. Without requiring such verification, however, the exemption may be too broad, potentially embracing domestic e-mail, which even the Director of National Intelligence has said should remain subject to traditional FISA. This is one of the main problems that has bedeviled efforts at FISA modernization.

Okay, that’s it for today. In tomorrow’s post, I will try to provide a chronology of FISA modernization, beginning with the Terrorist Surveillance Program (TSP), which circumvented the FISA statute, and ending with a discussion of the new bill as passed by the House on Thursday. Thanks for sticking with me this far.

Friday, June 20, 2008

Why Obama Kinda Likes the FISA Bill (But He Won't Come Out and Say It)

JB

Emily Bazelon wonders, entirely correctly, why Barack Obama has been missing in action on the FISA compromise bill passed by the House today. Finally, the Obama campaign sent a lukewarm endorsement of the measure: As to the key reforms of FISA, the bill is an acceptable compromise, not perfect but the best one can do under the situation. As to the retroactive immunity for telecom companies, Obama says he will work to change that in the Senate.

What gives? Why did Obama stay silent for so long, and why did he finally offer such a muted response to the bill?

The answer is simple:

Barrack Obama plans to be the next President of the United States. Once he becomes President, he will be in the same position as George W. Bush: he wants all the power he needs to protect the country. Moreover, he will be the beneficiary of a Democratic-controlled Congress, and he wants to get some important legislation passed in his first two years in office.

Given these facts, why in the world would Obama oppose the current FISA compromise bill? If it's done on Bush's watch, he doesn't have to worry about wasting political capital on it in the next year. Perhaps it gives a bit too much power to the executive. But he plans to be the executive, and he can institute internal checks within the Executive Branch that can keep it from violating civil liberties as he understands them. And not to put too fine a point on it, once he becomes president, he will likely see civil liberties issues from a different perspective anyway.

So, in short, from Obama's perspective, what's not to like?

Most Americans don't realize that the FISA compromise comes in two parts. The first part greatly alters FISA by expanding the executive's ability to wiretap and engage in much broader searches of communications than were permissible under the law before. It essentially gives congressional blessing to some but not all of what the executive was doing under President Bush. President Obama will like having Congress authorize these new powers. He'll like it just fine. People aren't paying as much attention to this part of the bill. But they should, because it will define the law of surveillance going forward. It is where your civil liberties will be defined for the next decade.

Part II, by contrast, is the part that everyone has gotten up in arms about. It creates effective immunity for telecom companies. It makes perfect sense for Obama to criticize this part of the bill. That's because he doesn't need it as much as he needs the first part, and his base really really dislikes it. True, it might be nice to have retroactive immunity for the players who he will be working with in the future. But remember, he expects to be President, and he figures that his OLC and Justice Department can offer sufficient assurances of legality going forward based on the changes in the first part of the bill.

So, let's sum up: Congress gives the President new powers that Obama can use. Great. (This is change we can believe in). Obama doesn't have to expend any political capital to get these new powers. Also great. Finally, Obama can score points with his base by criticizing the retroactive immunity provisions, which is less important to him going forward than the new powers. Just dandy.

It should now be clear why the Obama campaign has taken the position it has taken. And given what I have just said, Obama's supporters should be pressing him less on the immunity provisions and more on the first part of the bill which completely rewrites FISA. Because, if he becomes president, he'll be the one applying and enforcing its provisions.

If you really care about civil liberties in the National Surveillance State, you have to recognize that both parties will be constructing its institutions. The next President will be a major player in its construction, as important if not more important than George W. Bush ever was. That President will want more authority to engage in surveillance, and he'll be delighted for Congress to give it to him officially.

Older Posts
Newer Posts
Home