Germany’s BND Intelligence Agency Is Cutting Cooperation With The NSA

Entrance to the future BND Headquarters office in Pullach, Bavaria.

German intelligence has drastically reduced its cooperation with the US National Security Agency in response to a growing fall-out over their alleged joint surveillance of European officials and companies, according to media reports.

The BND, Germany’s foreign intelligence agency, ceased the online surveillance it is believed to have been carrying out on behalf of the NSA at its satellite listening station in Bad Aibling, Bavaria, at the start of the week, pending an investigation into the scandal. The end of the operation was reported by the national daily newspaper Süddeutsche Zeitung and other German media, citing sources close to a German parliamentary inquiry into the allegations.

Fax and phone intercepts were still being passed on, according to the reports.

The move was welcomed by Konstantin von Notz of the Green party ombudsman, who is in the parliamentary committee investigating the Edward Snowden revelations, of NSA spying. He said it was an acknowledgement that the operation was out of control.

“This is certainly a drastic step. It’s like pulling the emergency rip cord, because even in the year 2015 they’re still not able to control these search terms for Internet traffic,” he said, adding that Angela Merkel’s government had proven she was unable to protect German and European interests.

The decision was made after the NSA failed to provide a clear reason for each request for the surveillance of individuals or organisations. This had been demanded by the BND and Merkel’s office last month after BND’s chief, Gerhard Schindler, informed the chancellery that there was “massive doubt” about the veracity of the joint surveillance activities, which have been going on for a decade.

The government has yet to respond to the allegations. Members of her own party have joined calls for the government to release the list of 40,000 “selectors” – the IP addresses, search terms and names – used by the BND on behalf of the NSA.

Angela Merkel is under increasing pressure to reveal more about the nature of Germany’s cooperation with the NSA.

Wolfgang Bosbach, a prominent member of Merkel’s CDU and chair of the Bundestag’s home affairs select committee, said the lists were necessary in order to be able to establish whether or not the BND had acted illegally in assisting the NSA.

“It still remains to be seen whether this list can be released, as that depends on what arrangements were made with the US by the then government [of Gerhard Schröder] after the dramatic events of September 11 … I would like to know what was agreed with the Americans. It’s important in order to be able to answer the question as to whether the BND has acted within the law,” he told German broadcaster DLF.

Merkel has so far ruled out releasing the list until consultations with the US are completed. She has said she is prepared to go before the parliamentary committee and answer questions.

According to media reports citing those present at a secret session of the parliamentary committee, it is believed that on the request of Berlin for the NSA to justify each search request, the agency did provide necessary explanations for telephone numbers – believed to be in the millions – that it was wanting information on. But regarding other “selectors” such as those used to search emails, the response was sluggish, Peter Altmaier, Merkel’s chief of staff is reported to have told the committee.

It has also emerged that in his appearance before the committee, the BND boss Schindler, said that his agents had failed to record the data they had passed onto the NSA, making it nearly impossible to reconstruct what information they were provided with. He reportedly said they had no technical means of being able to retrieve the searches.

Whether the admission is just a convenient ploy to cover up any mistakes the BND might have made, as some MPs have inferred, has yet to be seen. The admission has added a further sting to the revelations, and does nothing to improve the position of the BND in the affair. The BND would appear to have at the best very careless if it indeed failed to record any details of the information transfers.

According to Schindler, no companies were on the surveillance list, rather European politicians, EU institutions and other officials.

Schindler, however, was at pains to play down the potential political damage caused. According to Spiegel Online, he told the committee the BND had only seized on communications originating in crisis areas of the world such as Africa and the Far East. He said with that in mind it was unlikely that the search of EU politicians’ emails would have been fruitful.

Schindler also said that most European authorities and almost all diplomats communicated via Virtual Private Networks (VPNs) rather than by email, which would have hindered BND attempts to intercept them.
Schindler repeated that he had first been made aware that the NSA was undertaking a massive sweep of European data by a colleague on March 13, and he had immediately informed the chancellery in Berlin.
Altmaier said the government was putting “considerable pressure” on the US to release the selectors list. A close advisor to Merkel told the committee that it expected an answer without delay.

Christine Lambrecht, parliamentary head of the opposition SPD faction, said despite calls for people to resign over the affair it was too early for conclusions to be drawn. She said it was important that the row did not overshadow the cooperation between intelligence agencies, “as it’s ever clearer that this work cannot be managed by one service alone … the question is only in what legal framework such cooperation takes place.”

Guardian: http://bit.ly/ZCp1oG

« What Do UK Consumers Think About SMEs’ Cyber Security?
Ex-CIA Chief: ‘If we don’t handle China well, it will be catastrophic’ »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

CYRIN

CYRIN

CYRIN® Cyber Range. Real Tools, Real Attacks, Real Scenarios. See why leading educational institutions and companies in the U.S. have begun to adopt the CYRIN® system.

XYPRO Technology

XYPRO Technology

XYPRO is the market leader in HPE Non-Stop Security, Risk Management and Compliance.

NordLayer

NordLayer

NordLayer is an adaptive network access security solution for modern businesses — from the world’s most trusted cybersecurity brand, Nord Security. 

DigitalStakeout

DigitalStakeout

DigitalStakeout enables cyber security professionals to reduce cyber risk to their organization with proactive security solutions, providing immediate improvement in security posture and ROI.

North Infosec Testing (North IT)

North Infosec Testing (North IT)

North IT (North Infosec Testing) are an award-winning provider of web, software, and application penetration testing.

Venable

Venable

Venable is an American Lawyer 100 law firm with nine offices across the USA, Practice areas include Cybersecurity.

Centre for Development of Advanced Computing (C-DAC)

Centre for Development of Advanced Computing (C-DAC)

C-DAC is the premier R&D organization of the indian Ministry of Electronics & Information Technology. Areas of research include cyber security.

Sigma Payment Solutions

Sigma Payment Solutions

Sigma Payment Solutions offers a comprehensive suite of automated payment processing services, solutions, and technology to businesses in the USA.

Me Learning

Me Learning

Me Learning provides engaging, informative and clearly explained learning materials for complex and challenging professional environments in areas including GDPR and Information Governance.

New Zealand Internet Task Force (NZITF)

New Zealand Internet Task Force (NZITF)

The New Zealand Internet Task Force (NZITF) is a non-profit with the mission of improving the cyber security posture of New Zealand.

Canadian Institute for Cybersecurity (CIC)

Canadian Institute for Cybersecurity (CIC)

The Canadian Institute for Cybersecurity (CIC) is a comprehensive multidisciplinary training, research and development, and entrepreneurial unit.

Sectigo

Sectigo

Sectigo is a leading cybersecurity provider of digital identity solutions, including TLS / SSL certificates, DevOps, IoT, and enterprise-grade PKI management, as well as multi-layered web security.

AU10TIX

AU10TIX

AU10TIX’s smart forensic-level ID authentication technology links physical and digital identities, meets compliance mandates, and ensures your customers know their trust and safety come first.

Gordian Networks

Gordian Networks

Gordian Networks offers complete managed IT services and IT support for small to large businesses.

Silicon Labs

Silicon Labs

Silicon Labs are a leader in secure, intelligent wireless technology for a more connected world. We provide award-winning hardware and software security to help safeguard connected devices.

Gem Security

Gem Security

Gem is on a mission to help security operations evolve into the cloud era, and stop cloud threats before they become incidents.

Rezonate

Rezonate

Rezonate discovers, profiles, and protects Identities and their entire access journey to cloud infrastructure and critical SaaS applications. Preventing and stopping cyberattacks.

Eden Data

Eden Data

Eden Data is on a mission to break the outdated mold of traditional cybersecurity consulting. We handle all of your security, compliance & data privacy needs.

Technology Mindz

Technology Mindz

Technology Mindz is a leading provider of cybersecurity services. We offer a wide range of services to help businesses. Our services are Identity and access management, Governance risk and compliance.

Prescott

Prescott

Prescott acts as your guiding light in the preparation for your CMMC assessment and long after by governing your cybersecurity practice.

Aegis9

Aegis9

Aegis9 is an Australian owned and sovereign consultancy that specialises in providing tailored security solutions for both public and private sector clients based on their specific needs.