Bioterrorism Defense in the U.S.
This article argues that most of the $44 billion spent in the U.S. on bioterrorism defense has been wasted.
Page 57 of 61
This article argues that most of the $44 billion spent in the U.S. on bioterrorism defense has been wasted.
A paper from the CATO Institute.
This is absolutely essential reading for anyone interested in how the U.S. is prosecuting terrorism. Put aside the rhetoric and the posturing; this is what is actually happening.
Among the key findings about the year-by-year enforcement trends in the period were the following:
- In the twelve months immediately after 9/11, the prosecution of individuals the government classified as international terrorists surged sharply higher than in the previous year. But timely data show that five years later, in the latest available period, the total number of these prosecutions has returned to roughly what they were just before the attacks. Given the widely accepted belief that the threat of terrorism in all parts of the world is much larger today than it was six or seven years ago, the extent of the recent decline in prosecutions is unexpected. See Figure 1 and supporting table.
- Federal prosecutors by law and custom are authorized to decline cases that are brought to them for prosecution by the investigative agencies. And over the years the prosecutors have used this power to weed out matters that for one reason or another they felt should be dropped. For international terrorism the declination rate has been high, especially in recent years. In fact, timely data show that in the first eight months of FY 2006 the assistant U.S. Attorneys rejected slightly more than nine out of ten of the referrals. Given the assumption that the investigation of international terrorism must be the single most important target area for the FBI and other agencies, the turn-down rate is hard to understand. See Figure 2 and supporting table.
- The typical sentences recently imposed on individuals considered to be international terrorists are not impressive. For all those convicted as a result of cases initiated in the two years after 9//11, for example, the median sentence—half got more and half got less—was 28 days. For those referrals that came in more recently—through May 31, 2006—the median sentence was 20 days. For cases started in the two year period before the 9/11 attack, the typical sentence was much longer, 41 months. See Figure 3.
Transactional Records Access Clearinghouse (TRAC) puts this data together by looking at Justice Department records. The data research organization is connected to Syracuse University, and has been doing this sort of thing—tracking what federal agencies actually do rather than what they say they do—for over fifteen years.
I am particularly entertained by the Justice Department’s rebuttal, which basically just calls the study names without offering any substantive criticism:
The Justice Department took issue with the study’s methodology and its conclusions.
The study “ignores the reality of how the war on terrorism is prosecuted in federal courts across the country and the value of early disruption of potential terrorist acts by proactive prosecution,” said Bryan Sierra, a Justice Department spokesman.
“The report presents misleading analysis of Department of Justice statistics to suggest the threat of terrorism may be inaccurate or exaggerated. The Department of Justice disagrees with this suggestion.”
How do I explain it? Most “terrorism” arrests are not for actual terrorism; they’re for other things. The cases are either thrown out for lack of evidence, or the penalties are more in line with the actual crimes. I don’t care what anyone from the Justice Department says: someone who is jailed for four weeks did not commit a terrorist act.
Hours-long waits in the security line. Ridiculous prohibitions on what you can carry onboard. Last week’s foiling of a major terrorist plot and the subsequent airport security graphically illustrates the difference between effective security and security theater.
None of the airplane security measures implemented because of 9/11—no-fly lists, secondary screening, prohibitions against pocket knives and corkscrews—had anything to do with last week’s arrests. And they wouldn’t have prevented the planned attacks, had the terrorists not been arrested. A national ID card wouldn’t have made a difference, either.
Instead, the arrests are a victory for old-fashioned intelligence and investigation. Details are still secret, but police in at least two countries were watching the terrorists for a long time. They followed leads, figured out who was talking to whom, and slowly pieced together both the network and the plot.
The new airplane security measures focus on that plot, because authorities believe they have not captured everyone involved. It’s reasonable to assume that a few lone plotters, knowing their compatriots are in jail and fearing their own arrest, would try to finish the job on their own. The authorities are not being public with the details—much of the “explosive liquid” story doesn’t hang together—but the excessive security measures seem prudent.
But only temporarily. Banning box cutters since 9/11, or taking off our shoes since Richard Reid, has not made us any safer. And a long-term prohibition against liquid carry-ons won’t make us safer, either. It’s not just that there are ways around the rules, it’s that focusing on tactics is a losing proposition.
It’s easy to defend against what the terrorists planned last time, but it’s shortsighted. If we spend billions fielding liquid-analysis machines in airports and the terrorists use solid explosives, we’ve wasted our money. If they target shopping malls, we’ve wasted our money. Focusing on tactics simply forces the terrorists to make a minor modification in their plans. There are too many targets—stadiums, schools, theaters, churches, the long line of densely packed people before airport security—and too many ways to kill people.
Security measures that require us to guess correctly don’t work, because invariably we will guess wrong. It’s not security, it’s security theater: measures designed to make us feel safer but not actually safer.
Airport security is the last line of defense, and not a very good one at that. Sure, it’ll catch the sloppy and the stupid—and that’s a good enough reason not to do away with it entirely—but it won’t catch a well-planned plot. We can’t keep weapons out of prisons; we can’t possibly keep them off airplanes.
The goal of a terrorist is to cause terror. Last week’s arrests demonstrate how real security doesn’t focus on possible terrorist tactics, but on the terrorists themselves. It’s a victory for intelligence and investigation, and a dramatic demonstration of how investments in these areas pay off.
And if you want to know what you can do to help? Don’t be terrorized. They terrorize more of us if they kill some of us, but the dead are beside the point. If we give in to fear, the terrorists achieve their goal even if they were arrested. If we refuse to be terrorized, then they lose—even if their attacks succeed.
This op ed appeared today in the Minneapolis Star-Tribune.
EDITED TO ADD (8/13): The Department of Homeland Security declares an entire state of matter a security risk. And here’s a good commentary on being scared.
In 1994, Congress passed the Communications Assistance for Law Enforcement Act (CALEA). Basically, this is the law that forces the phone companies to make your telephone calls—including cell phone calls—available for government wiretapping.
But now the government wants access to VoIP calls, and SMS messages, and everything else. They’re doing their best to interpret CALEA as broadly as possible, but they’re also pursuing a legal angle. Ars Technica has the story:
The government hopes to shore up the legal basis for the program by passing amended legislation. The EFF took a look at the amendments and didn’t like what it found.
According to the Administration, the proposal would “confirm [CALEA’s] coverage of push-to-talk, short message service, voice mail service and other communications services offered on a commercial basis to the public,” along with “confirm[ing] CALEA’s application to providers of broadband Internet access, and certain types of ‘Voice-Over-Internet-Protocol’ (VOIP).” Many of CALEA’s express exceptions and limitations are also removed. Most importantly, while CALEA’s applicability currently depends on whether broadband and VOIP can be considered “substantial replacements” for existing telephone services, the new proposal would remove this limit.
I can’t believe I forgot to blog this great article about the communications intercept trade show in DC earlier this month:
“You really need to educate yourself,” he insisted. “Do you think this stuff doesn’t happen in the West? Let me tell you something. I sell this equipment all over the world, especially in the Middle East. I deal with buyers from Qatar, and I get more concern about proper legal procedure from them than I get in the USA.”
Read the whole thing.
“Security Implications of Applying the Communications Assistance to Law Enforcement Act to Voice over IP,” paper by Steve Bellovin, Matt Blaze, Ernie Brickell, Clint Brooks, Vint Cerf, Whit Diffie, Susan Landau, Jon Peterson, and John Treichler.
Executive Summary
For many people, Voice over Internet Protocol (VoIP) looks like a nimble way of using a computer to make phone calls. Download the software, pick an identifier and then wherever there is an Internet connection, you can make a phone call. From this perspective, it makes perfect sense that anything that can be done with a telephone, including the graceful accommodation of wiretapping, should be able to be done readily with VoIP as well.
The FCC has issued an order for all “interconnected” and all broadband access VoIP services to comply with Communications Assistance for Law Enforcement Act (CALEA)—without specific regulations on what compliance would mean. The FBI has suggested that CALEA should apply to all forms of VoIP, regardless of the technology involved in the VoIP implementation.
Intercept against a VoIP call made from a fixed location with a fixed IP address directly to a big internet provider’s access router is equivalent to wiretapping a normal phone call, and classical PSTN-style CALEA concepts can be applied directly. In fact, these intercept capabilities can be exactly the same in the VoIP case if the ISP properly secures its infrastructure and wiretap control process as the PSTN’s central offices are assumed to do.
However, the network architectures of the Internet and the Public Switched Telephone Network (PSTN) are substantially different, and these differences lead to security risks in applying the CALEA to VoIP. VoIP, like most Internet communications, are communications for a mobile environment. The feasibility of applying CALEA to more decentralized VoIP services is quite problematic. Neither the manageability of such a wiretapping regime nor whether it can be made secure against subversion seem clear. The real danger is that a CALEA-type regimen is likely to introduce serious vulnerabilities through its “architected security breach.”
Potential problems include the difficulty of determining where the traffic is coming from (the VoIP provider enables the connection but may not provide the services for the actual conversation), the difficulty of ensuring safe transport of the signals to the law-enforcement facility, the risk of introducing new vulnerabilities into Internet communications, and the difficulty of ensuring proper minimization. VOIP implementations vary substantially across the Internet making it impossible to implement CALEA uniformly. Mobility and the ease of creating new identities on the Internet exacerbate the problem.
Building a comprehensive VoIP intercept capability into the Internet appears to require the cooperation of a very large portion of the routing infrastructure, and the fact that packets are carrying voice is largely irrelevant. Indeed, most of the provisions of the wiretap law do not distinguish among different types of electronic communications. Currently the FBI is focused on applying CALEA’s design mandates to VoIP, but there is nothing in wiretapping law that would argue against the extension of intercept design mandates to all types of Internet communications. Indeed, the changes necessary to meet CALEA requirements for VoIP would likely have to be implemented in a way that covered all forms of Internet communication.
In order to extend authorized interception much beyond the easy scenario, it is necessary either to eliminate the flexibility that Internet communications allow, or else introduce serious security risks to domestic VoIP implementations. The former would have significant negative effects on U.S. ability to innovate, while the latter is simply dangerous. The current FBI and FCC direction on CALEA applied to VoIP carries great risks.
In case you thought you had any privacy on the Internet:
Gonzales and Mueller asked Google Inc., Time Warner Inc.’s AOL and other companies to preserve the data at a May 26 meeting, citing their value to investigations into child-pornography distribution and terrorism. Internet companies typically keep customer histories for only a few days or weeks.
The Justice Department said Thursday that it was not seeking to have e-mail content archived, just information about the websites people visit and those with whom they correspond.
Note that the Justice Department invoked two of the Four Horsemen of the Internet Apocalypse: child pornographers and terrorists. If they can figure out how to work kidnappers and drug dealers in, they can probably do anything they want.
Fascinating essay about how EU law would treat the NSA’s collection of everyone’s phone records.
Ira Winkler on why the NSA spying hurts security.
Sidebar photo of Bruce Schneier by Joe MacInnis.