Privacy

Report: Yahoo scanned users’ email for U.S. intelligence agencies

Comment

Image Credits: Ken Wolter (opens in a new window) / Shutterstock (opens in a new window)

Yahoo’s trust with users is damaged today by a Reuters report that claims the company developed a custom program to search all users’ incoming email for specific queries given by U.S. intelligence officials.

“We’ve worked hard over the years to earn our users’ trust and we fight hard to preserve it,” Yahoo CEO Marissa Mayer says in the opening to the company’s transparency report, in which it documents government requests for user data. But it appears that Yahoo subverted user trust by creating the custom program, and excluded information about it from its transparency report.

The dragnet surveillance of Yahoo’s email customers was initiated last spring and was confirmed to Reuters by former employees. The former employees claimed that the software was developed in response to a classified government order and led to the June 2015 resignation of Yahoo’s then-Chief Information Security Officer, Alex Stamos. Mayer and Yahoo General Counsel Ron Bell directed email engineers to create the program, which was discovered by Yahoo’s security team in May 2015, Reuters reports. Stamos and other security team members initially thought hackers had compromised the company’s email security, and Stamos resigned when he learned that Mayer had approved the program.

“Yahoo is a law abiding company, and complies with the laws of the United States,” a Yahoo spokesperson told TechCrunch. A spokesperson at Facebook, where Stamos is currently Chief Security Officer, declined an interview request for Stamos.

The surveillance program has already been condemned by lawyers for the American Civil Liberties Union and members of Congress, who have called the government order received by Yahoo unconstitutional.

“This is big brother on steroids and it must be stopped,” Congressman Ted Lieu said in a statement. “If true, the government’s directive to Yahoo to write a software program and search all of its customers’ incoming emails for certain content is a gross abuse of federal power.”

Between January and July 2015, the period in which Yahoo allegedly implemented the program, the company says content from 21,000 – 21,499 user accounts was requested under the Foreign Intelligence Surveillance Act, and content from 0 – 499 accounts was requested via National Security Letters. (Until the passage of the USA Freedom Act last year, companies were only allowed to disclose FISA and NSL requests in ranges of 500. Now, companies may disclose more detail on FISA requests, with a tradeoff of an additional six months’ reporting delay.) Yahoo says that it requires “valid legal process” in order to turn over user data, except “in the rare instance where we conclude that disclosure without delay is necessary to prevent imminent danger of death or serious physical injury to any person.” It’s not clear whether the scope of the email-scanning program is much smaller than reported by Reuters, or if Yahoo purposefully withheld information about the program from its transparency report.

The most accounts Yahoo said it ever turned over since it began publishing biannual transparency reports in 2013 was 51,000 – 51,499 accounts between July and December 2013. But even those numbers pale in comparison to the hundreds of millions accounts that may have been accessed by the customized program.

It’s not the first time that Yahoo has been accused of providing customer data to U.S. intelligence agencies. Documents leaked to the Guardian by former NSA contractor Edward Snowden in 2013 revealed that Yahoo provided access to the content of users’ emails and other data through the NSA’s PRISM program, beginning in 2008. Yahoo’s general counsel, Bell, later revealed that the company had resisted joining PRISM because it thought the government’s demands for user data were “unconstitutional and overbroad.” However, Yahoo was threatened with $250,000-per-day fines if it did not comply, with that fine set to double each week until compliance began.

“Forcing a private sector company to search emails is even worse than the NSA’s bulk collection program because now the federal government is seizing and searching content, not just meta data, without a warrant,” Congressman Lieu said.

Mayer reportedly did not believe that Yahoo would win a legal challenge against the demand to develop the custom program, and chose not to fight it. But Yahoo has previously had some success in fighting to make NSLs public, and became the first tech company to publish NSLs when it released three such letters in June. Apple also had notable success in this area earlier this year, when it fought the FBI’s demand that it create a custom program to help investigators unlock in iPhone.

Yahoo has also recently struggled with cybersecurity, disclosing last month that data from at least 500 million users was stolen by a hacker. The announcement stirred speculation that the breach could cause trouble in Yahoo’s sale to Verizon (Verizon is the parent company of TechCrunch) and Senator Mark Warner has called on the Securities and Exchange Commission to investigate whether Yahoo properly disclosed the breach to its users and its buyer. The delay in disclosing the breach to users and initiating a password reset was reportedly motivated by Mayer’s fear that any mention of a breach would drive users away from Yahoo’s already-faltering email service.

As independent journalist Marcy Wheeler notes, the demand for a search on Yahoo users’ email coincides with an executive order issued by President Obama that categorized cyber attacks by individuals outside the U.S. a national emergency, and the executive order may have been used as justification for the program.

It’s worth noting that Yahoo and other free email providers scan users’ email for their own business purposes — Gmail, for instance, serves ads to users based on keywords found in their email. Still, allowing all email data to be accessed in real-time by an intelligence agency is a shocking move.

More TechCrunch

The Series C funding, which brings its total raise to around $95 million, will go toward mass production of the startup’s inaugural products

AI chip startup DEEPX secures $80M Series C at a $529M valuation 

A dust-up between Evolve Bank & Trust, Mercury and Synapse has led TabaPay to abandon its acquisition plans of troubled banking-as-a-service startup Synapse.

Infighting among fintech players has caused TabaPay to ‘pull out’ from buying bankrupt Synapse

The problem is not the media, but the message.

Apple’s ‘Crush’ ad is disgusting

The Twitter for Android client was “a demo app that Google had created and gave to us,” says Particle co-founder and ex-Twitter employee Sara Beykpour.

Google built some of the first social apps for Android, including Twitter and others

WhatsApp is updating its mobile apps for a fresh and more streamlined look, while also introducing a new “darker dark mode,” the company announced on Thursday. The messaging app says…

WhatsApp’s latest update streamlines navigation and adds a ‘darker dark mode’

Plinky lets you solve the problem of saving and organizing links from anywhere with a focus on simplicity and customization.

Plinky is an app for you to collect and organize links easily

The keynote kicks off at 10 a.m. PT on Tuesday and will offer glimpses into the latest versions of Android, Wear OS and Android TV.

Google I/O 2024: How to watch

For cancer patients, medicines administered in clinical trials can help save or extend lives. But despite thousands of trials in the United States each year, only 3% to 5% of…

Triomics raises $15M Series A to automate cancer clinical trials matching

Welcome back to TechCrunch Mobility — your central hub for news and insights on the future of transportation. Sign up here for free — just click TechCrunch Mobility! Tap, tap.…

Tesla drives Luminar lidar sales and Motional pauses robotaxi plans

The newly announced “Public Content Policy” will now join Reddit’s existing privacy policy and content policy to guide how Reddit’s data is being accessed and used by commercial entities and…

Reddit locks down its public data in new content policy, says use now requires a contract

Eva Ho plans to step away from her position as general partner at Fika Ventures, the Los Angeles-based seed firm she co-founded in 2016. Fika told LPs of Ho’s intention…

Fika Ventures co-founder Eva Ho will step back from the firm after its current fund is deployed

In a post on Werner Vogels’ personal blog, he details Distill, an open-source app he built to transcribe and summarize conference calls.

Amazon’s CTO built a meeting-summarizing app for some reason

Paris-based Mistral AI, a startup working on open source large language models — the building block for generative AI services — has been raising money at a $6 billion valuation,…

Sources: Mistral AI raising at a $6B valuation, SoftBank ‘not in’ but DST is

You can expect plenty of AI, but probably not a lot of hardware.

Google I/O 2024: What to expect

Dating apps and other social friend-finders are being put on notice: Dating app giant Bumble is looking to make more acquisitions.

Bumble says it’s looking to M&A to drive growth

When Class founder Michael Chasen was in college, he and a buddy came up with the idea for Blackboard, an online classroom organizational tool. His original company was acquired for…

Blackboard founder transforms Zoom add-on designed for teachers into business tool

Groww, an Indian investment app, has become one of the first startups from the country to shift its domicile back home.

Groww joins the first wave of Indian startups moving domiciles back home from US

Technology giant Dell notified customers on Thursday that it experienced a data breach involving customers’ names and physical addresses. In an email seen by TechCrunch and shared by several people…

Dell discloses data breach of customers’ physical addresses

Featured Article

Fairgen ‘boosts’ survey results using synthetic data and AI-generated responses

The Israeli startup has raised $5.5M for its platform that uses “statistical AI” to generate synthetic data that it says is as good as the real thing.

18 hours ago
Fairgen ‘boosts’ survey results using synthetic data and AI-generated responses

Hydrow, the at-home rowing machine maker, announced Thursday that it has acquired a majority stake in Speede Fitness, the company behind the AI-enabled strength training machine. The rowing startup also…

Rowing startup Hydrow acquires a majority stake in Speede Fitness as their CEO steps down

Call centers are embracing automation. There’s debate as to whether that’s a good thing, but it’s happening — and quite possibly accelerating. According to research firm TechSci Research, the global…

Retell AI lets companies build ‘voice agents’ to answer phone calls

TikTok is starting to automatically label AI-generated content that was made on other platforms, the company announced on Thursday. With this change, if a creator posts content on TikTok that…

TikTok will automatically label AI-generated content created on platforms like DALL·E 3

India’s mobile payments regulator is likely to extend the deadline for imposing market share caps on the popular UPI (unified payments interface) payments rail by one to two years, sources…

India likely to delay UPI market caps in win for PhonePe-Google Pay duopoly

Line Man Wongnai, an on-demand food delivery service in Thailand, is considering an initial public offering on a Thai exchange or the U.S. in 2025.

Thai food delivery app Line Man Wongnai weighs IPO in Thailand, US in 2025

Ever wonder why conversational AI like ChatGPT says “Sorry, I can’t do that” or some other polite refusal? OpenAI is offering a limited look at the reasoning behind its own…

OpenAI offers a peek behind the curtain of its AI’s secret instructions

The federal government agency responsible for granting patents and trademarks is alerting thousands of filers whose private addresses were exposed following a second data spill in as many years. The…

US Patent and Trademark Office confirms another leak of filers’ address data

As part of an investigation into people involved in the pro-independence movement in Catalonia, the Spanish police obtained information from the encrypted services Wire and Proton, which helped the authorities…

Encrypted services Apple, Proton and Wire helped Spanish police identify activist

Match Group, the company that owns several dating apps, including Tinder and Hinge, released its first-quarter earnings report on Tuesday, which shows that Tinder’s paying user base has decreased for…

Match looks to Hinge as Tinder fails

Private social networking is making a comeback. Gratitude Plus, a startup that aims to shift social media in a more positive direction, is expanding its wellness-focused, personal reflections journal to…

Gratitude Plus makes social networking positive, private and personal

With venture totals slipping year-over-year in key markets like the United States, and concern that venture firms themselves are struggling to raise more capital, founders might be worried. After all,…

Can AI help founders fundraise more quickly and easily?