Ottawacitizen’ da Kanada Isyani

OTTAWA — American spies can snoop
through Canadians’ computer
data — including
 that of political organizations and
without warrants — if the data resides within popular
U.S. cloud computing services, says
a former Microsoft executive.

In a report commissioned
by the European Parliament, former Microsoft chief privacy adviser Caspar Bowden reveals,
“it is lawful in the U.S. to conduct purely political surveillance on foreigners’ data accessible in U.S. clouds,” operated by U.S. firms such as Google, Microsoft, Apple, IBM and others.

One sweeping provision of the Foreign Intelligence Surveillance Act (FISA) authorizes the targeting of, “foreign-based political organization(s)... or foreign territory that relates to... conduct of the foreign affairs of the United States.”

While other contentious U.S. post-9/11 laws,
such as the Patriot Act, significantly lifted restrictions on government surveillance,
Bowden says the foreign surveillance law, “for the first time (has) created a power of mass-surveillance specifically targeted at the data of non-U.S. persons located outside the U.S., which applies to cloud computing.”

In an interview with the Citizen, he characterized the U.S. law as a “grave risk” to European data sovereignty and said, “everything I’ve said about the situation of Europeans applies also to Canadians.”

British lawmakers reacted with anger this week after broke the story.
The newspaper The Independent quoted members of parliament calling on the government to consider a halt to shared intelligence services with the U.S. and to end the use of U.S.-based cloud computing for sensitive government data.

The Canadian government makes limited use of cloud computing for some human resources and financial data services, but the systems are internal and controlled by Shared Services Canada.

The biggest threat from FISA snooping appears to be Canadian business and non-governmental organizations that use the cloud.

“There’s no question we would be targeted,”
says Garry Neil, executive-director
of Council of Canadians,
one of the largest advocacy groups
for Canada-first policies on issues
such as energy, natural resources and economic policy. “We’re involved in
campaigns that affect U.S. interests, in campaigns to try and slow down the development of the tarsands that would be seen as American foreign policy.”

The organization stores its primary computer data internally and contracts with only Canadian companies for Internet and web services.

Still, Neil says, “it does indicate for many who take advocacy positions that they really need to be very cautious about what they’re doing for the want of saving a few dollars,” by outsourcing their computer services to the Cloud.

Authorization for the U.S. cloud surveillance comes from a subtle and largely unnoticed 2008 amendment to FISA commonly known as “warrantless wiretapping.”

The controversial act allows U.S. federal agencies to electronically gather foreign intelligence on
U.S. soil through electronic eavesdropping and other measures and without probable-cause search warrants. One of the parties to the targeted information must be believed to be outside the U.S. to protect the privacy of American citizens.

But the 2008 change incorporated
“remote computing services”
 — cloud computing —
 into the existing definition of
an “electronic communication service provider.” Experts say that allows
U.S. agencies to access customer files and other information at various U.S-owned cloud data centres in the U.S., Europe, India and other countries.

Approval for electronic surveillance is given
by the U.S. attorney general for a period of up to one year. U.S. companies that fail
to comply
with a FISA order can be brought
before a secret FISA court for punishment
and are prohibited from disclosing the existence of FISA orders served on them.

A five-year extension of the FISA Amendment Act of 2008 was granted by Congress and the White House in December 2012.