lately, the national security agency has been in the news for all the wrong reasons. constituted in 1954 from the ashes of the armed forces security agency, the institution is charged with carrying out clandestine electronic surveillance to protect the united states and its allies. ideally, this should be carried out within the limits of the law. documents leaked by ed snowden, a former employee of the organization have raised concerns that this may not the case. failing to stick to its legally-constituted limits would put the nsa on the same level as rogue white blood cells, a danger to the very people it is meant to protect. going by information from the leaks, intelligence agencies from other countries may also be a part of the problem. the agency uses several approaches to gain access to private information.


1. legal compulsion

the patriot act's section 215 gives the nsa power to compel american businesses to give up private information in a restricted set of circumstances. to prevent abuse, such actions are governed by law. unfortunately, affected companies are legally forbidden to publicly reveal the number and nature of such requests. snowden's revelations seem to indicate that google, facebook, twitter, microsoft, apple, and other technology giants have been forced to give up private subscriber data on several occasions.



2. cooperation

some companies voluntarily give the nsa access to private information. reports backed up by snowden's leaked documents show that in the period after september 11, 2001, a major american telecommunications company - rumored to be either at&t or verizon - voluntarily gave the agency access to its call records among other customer data. the nsa has invested a significant amount of time and money on personnel, software and equipment to sweep such data for important clues. companies that choose this route are immune to prosecution courtesy of the protection conferred by the fisa amendments act.



3. digital splitters and undersea cables

where legal instruments and cooperation are not available, the agency turns to other tricks up its clandestine sleeve. snowden's documents indicate that from the second quarter of 2012, the government communications headquarters, the british equivalent of the nsa, has been tapping undersea cables that move massive amounts of information across the globe. the gchq calls this 'operation tempora'. data is collected and stored for up to 30 days. the nsa provides the tools needed to glean important clues from the stored data. results are shared between the two agencies. another approach involves installing digital splitters in a company's servers to shunt communications traffic to the nsa.



4. spies

when all else fails, the nsa and its partner agencies turn to a tried and tested method; old fashioned spying. according to a respected british publication, the guardian, the gchq has a unit dubbed the humint operations team. 'humint' stands for 'human intelligence.' this team is responsible for recruiting and planting agents in telecommunications companies around the world. with spies in the right places, the nsa can get practically any information it needs.



5. malicious software

where necessary, the agency uses malicious applications to exploit unreported software weaknesses and extract, implant or manipulate information. stuxnet and flame are some examples of such malware. using infected email and other methods, the agency installs remote administration software in target computers, making surreptitious long term surveillance possible. in addition, germany's respected der spiegel magazine reports that the nsa can even worm its way into devices using ios, android and blackberry operating systems, and take advantage of their unique capabilities to, for example, track the whereabouts of those using them.



6. back doors

in order to find its way around encrypted data, the nsa will at times work with technology companies and other organizations to build backdoors into commercial encryption hardware and software. these holes are designed to be invisible to the end user while offering surreptitious access to those who know about them. for instance, the global technology community suspects that the nsa may have somehow compelled the us national institute of standards and technology to approve the deliberately flawed dual elliptic curve deterministic random bit generator cryptographic standard.



7. brute force attacks on encrypted databases

the nsa cannot snoop at data that is properly encrypted. in such cases, the agency finds other ways to get what it wants. usually, it will look for weaknesses at the points where data originates or ends. in a strategy reminiscent of hacking attacks that have affected a number of organizations around the world, the agency covertly acquires target databases, then applies brute force attacks to uncover their contents. in case that approach fails, the nsa stores the information for up to five years, waiting for the day when advances in technology will give them the means to crack recalcitrant databases.



how to keep your data safe

1. avoid texting and instant messaging

when you send texts or an instant messages, copies are retained in your service provider's servers, where they are vulnerable to hackers and, well, government spooks. currently, it is not possible to make texting more secure. however, instant messages can be protected, but this is not possible if you are using public im services like google hangouts, skype and aim. for enhanced security, turn to cisco united presence or any other service that offers an extensible messaging and presence protocol. however, the recipient should use the same approach, because if they are on a public im service, copies of your messages will end up in a corporate server somewhere.



2. always encrypt your email

solutions for encrypting email have been around for a long time, but an overwhelming majority of users are not even aware of them. the biggest hurdles to mass adoption of these technologies is lack of awareness and the relatively high level of technical proficiency needed. please note that email encryption only works when both the sender and receiver use it.



3. avoid social networks

close your facebook, twitter and other social media accounts, and never use them again. social networks are a treasure trove of personal information, so avoid them like the plague. some people may find this advice a bit hard to swallow, but the benefits in enhanced privacy are worth it in the end.



4. turn off services that you do not use

modern devices are constantly syncing data with servers in the cloud. while this makes it possible to receive emails and instant messages almost as soon as they are sent, it may provide a way for government agents to snoop into your private data. so, if you do not need location information, turn off your gps; if you are not within the range of a hotspot, turn off wifi, and if you are not transferring files or listening to music, turn off bluetooth.



5. do not store sensitive files in public cloud services

going by snowden's leaks, cloud service providers have been a particularly juicy target for the nsa. add that to the unresolved crisis that is megaupload, and you can see why you should not store sensitive data in public clouds. nsa personnel do not necessarily need access to your cloud account; they can grab data as you upload your files. the same methods can be used to collect information from software-as-a-service applications like office 365 and google drive. to protect yourself, store data in your own servers or in a private cloud, encrypt your traffic and limit communications to your corporate intranet.



6. keep web browsing private

avoid relying on the 'do not track' feature that is built into most modern websites. it cannot prevent snooping. firefox and chrome users should switch to the electronic frontier foundation's https everywhere browser extension. it uses the popular secure socket layer encryption scheme to keep web browsing private. an even better option is tor; use it to secure yourself. unfortunately, the technology makes browsing rather slow, but that may be the price you need to pay to keep your data secure.



7. use open source encryption

wherever possible, use open source encryption software. unlike proprietary programs from companies like microsoft, they are less likely to incorporate back doors. the truly paranoid can always turn to carrier pigeons; it is a little hard to build backdoors into feathers.



parting words

ultimately, however, no system, no matter how secure can be said to be truly nsa proof. a lasting solution may lie in strengthening privacy laws and improving oversight. this would ensure that intelligence agencies exercise their mandate without violating the law. if you haven't already done so, start petitioning the relevant authorities.