Why the German Intelligence Community Infuriates Me

One and a half years ago, I wrote the following about the German (BND) and the U.S. (CIA, NSA…) intelligence services in comparison:

(…) I think there is a marked difference in self-perception between the two nations. I don’t think anyone in Germany even wishes to have an equally powerful and expensive intelligence apparatus. Maybe I’m extremely naive, but I doubt wiretapping foreign heads of state is high on the BND’s agenda. (…)

Of course this was written in the context of the revelations about NSA and CIA operations that infringe on civil rights around the world. I still believe that (i) German agencies probably are less intrusive than their “Five Eyes” counterparts, and (ii) that public opinion in Germany is more critical of surveillance than in the United States.

Sign at the BND construction site (2008), CC-BY-SA by Schmidt/Richter on Wikimedia Commons

Recent news, however, have led me to re-evaluate my standpoint. While I still wish for “my” intelligence agencies to respect civil rights and the rule of law, most importantly I would really appreciate more professionalism on their side. I mean, you really can’t make this stuff up:

  • The construction site for the new BND headquarters in the center of Berlin was vandalized: after thieves removed a couple of faucets (!!!) from the upper floor, water kept leaking for hours
  • …leading to millions of euros in property damage (FYI: the new HQ is expected to cost >1.3 billion)
  • Nobody noticed anything. And this is not the first incident: In 2011, the top-secret construction plans were stolen or “went missing”…

Ironically, there is a German figure of speech that refers to particularly tight security as “wasserdicht” (waterproof). Of course people on Twitter are having a lot of fun with this and other bad puns. Check out the #watergate and #BNDleaks hashtags. Another particularly fitting yet hard to translate one is #läuftbeimBND.

On a more serious note, I am deeply worried about what goes on in the German intelligence community.

  • Domestically, the investigation of the NSU terrorism against immigrants suggests that the “Verfassungsschutz” (homeland security) was paying informants who not only failed to prevent or investigate any of these terrible crimes, but were present at the scenes of murders and then lied about it at court.
  • Internationally, it seems clear now that there is no concerted effort to curtain U.S. activities on European soil, despite all the symbolic outrage. The “no-spy treaty” was hot air, which is not surprising. New revelations about the British GCHQ or the U.S. services violating the rights of European citizens have not led to any serious response as far as I can tell.
  • (My working hypothesis is that several past German governments owe a lot to U.S. support in Afghanistan, which makes it very difficult to criticize these agencies.)
  • The parliamentary investigative committee on NSA/CIA surveillance is under multiple lines of attack:
    • witnesses and experts are extremely tight-lipped, and the BND routinely “forgets” and “loses” documents
    • three members of the committee have stepped down for unclear reasons
    • everything is obscured by lawyers and engineers claiming ignorance of each others’ field, which leads to almost farcical Q&A sessions
    • the security of the committee’s internal lines of communications is questionable: someone intercepted the package carrying the encrypted phone used by the committee chairman on its way to be serviced.
    • (Netzpolitik.org offers very extensive coverage of these events [in German], often supported by leaked documents.)

I am no conspiracy theorist, I am not against intelligence services per se, and I also know that politics are complicated. But this combination of blatant negligence when it comes to civil rights (in the country that spawned both the Third Reich and the Stasi!) with strategic and operational incompetence is infuriating.

Marginal Costs in Intl. Affairs

Zero Marginal Costs SocietyLast week, Jeremy Rifkin presented his current book here in Berlin. In The Zero Marginal Costs Society, he argues that the marginal costs of production in many sectors are moving (close) to zero, leading to economic shifts on the scale of the industrial revolution. Three forces make this possible according to Rifkin:

  • a truly integrated global internet (communication + logistics + sensors)
  • abundant renewable energy
  • 3D printing as extremely cost-efficient mode of producing physical goods

No matter how you think about the details of Rifkin’s predictions, he makes persuasive points on what very low marginal costs can entail. This is obviously true for the areas he addresses (the economics of production, welfare, labor, automation, consumption).

But in addition,  marginal costs are worth  attention when we think about international relations and and transnational political affairs more generally:

  • If we buy Rifkin’s arguments, IPE scholars and others who care about economic power and growth prospects will put less emphasis on traditional metrics of factor endowments. If the Netherlands are just much better at making use of renewables than Russia, size is a bad predictor of success. How do you model something like the political will to embrace the future?
  • The marginal cost of reaching one more pair of eyes applies to political mobilization. No matter how high your PR budget, you can reach millions of potential recruits if you’re willing to be excessively cruel and upload an execution video. And how does having a single “viral” idea (involving buckets of ice) measure up against having a more traditional structure of supporters?
  • I’ve covered intelligence activities here on the blog, in particular the  large-scale surveillance conducted by the NSA and other agencies. Consider the logic of technology-driven surveillance: The marginal cost of targeting one more person is virtually zero. Keeping that person’s data for one more unit of time is free. And there is no physical or technological limit in sight.
  • Similarly, I suspect that “cyber war” skills probably scale at close to zero marginal costs. Once you managed to infiltrate a crucial bit of IT infrastructure (and still have plausible deniability to mitigate political repercussions), deciding about the amount of damage you want to inflict will not be a matter of costs.

I’m sure there are many more examples. And if you’re willing to bear the cost of adding one more book to your reading list, consider Rifkin’s.

Steinmeier on Transatlantic Relations


This morning, I went to see German foreign minister Steinmeier’s speech at the Brookings Institution. Under the heading “Transatlantic Ties for a New Generation”, he argued that to be attractive for young people, the European-American partnership has to be based on shared values and standards of governance. The text is on the ministry’s website. In addition, Brookings published the audio and video recordings of the speech and the Q&A.

To be fair, this speech was more interesting and better prepared than the last foreign policy speech delivered by a Social Democrat that I have attended. Still, if you go beyond the personal anecdotes and jokes he made, Steinmeier said very little, let alone . The Q&A, regrettably, was hurt by the fact that Steinmeier – who had given the speech in English- answered in German. So a lot of time was spent on translation and we only covered four or five (pretty harmless) questions in total.

So, here are the few concrete things I took away from this event. (Plain English translation in italics.)

  • The “no spy” treaty is a non-starter. Instead, Steinmeier wants to have several rounds of talks between U.S. and European officials, which should cover both eavesdropping on government leaders and large-scale surveillance of general population. These talks should include civil society and academia. (We know that’s kind of embarrassing, but what are we gonna do? Nobody wants to kill TTIP because of civil rights.)
  • On the choice to spy: the U.S. government should realize that their surveillance/ spying practices are inappropriate in a setting of close partnership. It must be made clear that democratic bodies have the last words rather than corporate or intelligence interests. (Please be a little bit nicer, for old time’s sake, OK?)
  • Europeans and in particular Germans are committed to show more leadership in foreign policy (“expand the toolbox of diplomacy”). As head of the G8 group in 2015, Germany will push for climate change politics. (But please don’t mention Syria, because we really don’t know what to do.)
  • On Europe: Between Germany and the UK, fundamental disagreements remain about the general trajectory of EU integration. We might see more subsidiarity in select issue areas, but no reversal of integration. (Those ***** Brits! As if we didn’t have enough problems already. Oh, and maybe we should tweak those austerity policies in Southern countries, but please don’t ask about specifics).
  • While the Russian human rights ombudsman Vladimir Lukin played in a constructive role in the talks with German, French, Polish FMs last week, Steinmeier is just as puzzled about Crimea as everybody else. (Nobody knows what’s going on in Ukraine, and even if we knew, we probably couldn’t do much about it. It’s not like we’re a  superpower or anything.)

So, as you can see, no grand commitments or surprise announcements were made today. German foreign policy remains, ahem, underwhelming.

“Tailored Access Operations” are exactly what I want the NSA to do

Happy New Year everyone! We’re back from our winter break. (Actually, some members of the IR Blog editorial board are still enjoying their time off, but I guess they will return to their desks eventually.)

At the 2013 Chaos Communication Congress in Hamburg, Jacob Applebaum gave a talk that summarized what is known about the NSA’s “Tailored Access Operations” unit. You can watch the video above. Basically, “tailored access” means that these are high-tech “hackers” that acquire intelligence on high-profile targets. Their arsenal includes tiny wireless chips inserted into hardware that is intercepted on the way to customers (!) as well as a special kind of bug that can be accessed by radar waves. Given that the information is from 2009, they probably have even more sophisticated tools now.

The related SPIEGEL story is here (in English). Bruce Schneier has collected a couple of links on the topic, and currently presents one of the exploits every day.

In the Guardian, Matt Blaze makes a very important point: “The NSA’s Tailored Access Operations show there’s a way to be safe and get good intelligence without mass surveillance”. The crucial difference is that between (A) civil-rights-abusing mass surveillance (as currently discussed, again, in the German cabinet) and (B) targeted surveillance of people that were chosen based on meaningful criteria. As Blaze puts it:

TAO is retail rather than wholesale.

That is, as well as TAO works (and it appears to work quite well indeed), they can’t deploy it against all of us – or even most of us. They must be installed on each individual target’s own equipment, sometimes remotely but sometimes through “supply chain interdiction” or “black bag jobs”. By their nature, targeted exploits must be used selectively. Of course, “selectively” at the scale of NSA might still be quite large, but it is still a tiny fraction of what they collect through mass collection.

For over a decade now, the NSA has been drowning in a sea of irrelevant data collected almost entirely about innocent people who would never be selected as targets or comprise part of any useful analysis. The implicit assumption has been that spying on everyone is the price we pay to be able to spy on the real bad guys. But the success of TAO demonstrates a viable alternative. And if the NSA has any legitimate role in intelligence gathering, targeted operations like TAO have the significant advantage that they leave the rest of us – and the systems we rely on – alone.

When I wrote earlier that “we are genuinely shocked by the extent to which our friends feel the need to spy on us and don’t think twice about it”, I was mainly referring to mass surveillance. Wiretapping chancellor Merkel is disrespectful, but I expect her to expect this kind of thing as an occupational hazard. What I find unacceptable, on the other hand, is that systematically eroding the integrity of communications networks and the meaning of “privacy” should be the new normal.

In other words: I’m far more comfortable with the idea that U.S. operatives secretly plant a bug in some suspected terrorist’s computer in Berlin than with the fact that all kinds of “metadata” on German (and other) citizens are being collected non-stop.

Putting a stop to individual-level surveillance seems implausible to me, and also impossible seeing that U.S. legislators would have to decide to shut down pretty much all of what intellifence agencies are about. But is it really that far-fetched (or naive) to hope for some consensus in favor of civil rights? Even if you don’t care about somewhat lofty and abstract pro-privacy arguments, U.S. and European business is being hurt by the NSA’s horrible reputation, and then there’s always the risk that backdoors may be used by more than one party…

“Tailored access” is exactly what I want the NSA to do. But please leave my telecoms provider alone and stop tracking my mobile phone “just in case”.

Espionage, Surveillance, and Transatlantic Relations

snowdenletterOK, the NSA was bugging German chancellor Angela Merkel’s cell phone for ten years, and a well-known German member of parliament has just met with whistleblower Edward Snowden in Russia. Snowden has written a letter and offered “to testify to a public prosecutor or an investigating committee of Germany’s lower house of parliament, the Bundestag”, as the SPIEGEL reports.

So I guess it’s time for some quick reflections on two of our favorite topics, Transatlantic relations and surveillance / espionage:

