NSA Snoops Extend Ops to Online Games

The U.S. National Security Agency and British counterpart GCHQ have monitored the activities of online gamers, according to documents published Monday that were leaked by whistleblower Edward Snowden.

The two agencies gained access to the online Xbox Live console network, the documents suggest, as well as deploying real-life agents into the virtual realms of Blizzard’s World of Warcraft and Linden Labs’ Second Life. Once inside, agents monitored the activity of some gamers as well as recruiting potential informants.

Obtained by The Guardian, the files date back to 2008 and were published in partnership with The New York Times and ProPublica.

The NSA did not respond to our request for further information.

Digital ‘Dead Drop’

The agencies were motivated by a fear that terrorists and criminal networks could use online games to communicate secretly, move money or even plot attacks while hiding in plain sight.

“Today it is more difficult than ever not to be seen on the internet, so the game becomes one of finding ways not to stand out,” Jim Purtilo, associate professor with the computer science department, at the University of Maryland, told TechNewsWorld.

“For a while, people interested in anonymity would communicate with one another via a digital ‘dead drop’ — some innocuous electronic place where one party can leave information for another,” Purtilo explained. “You might recall that is how General Petraeus famously exchanged messages with a paramour, for example, but as also shown by that case, the technique only works for so long.

“So many records are preserved for traffic analysis these days that investigators can work back to reconstruct social networks just as soon as one party becomes of interest,” he added.

Indeed, BitTorrent and hacking websites “are simply already monitored too much to make much sense for terrorists and serious criminals,” noted Alan Webber, principal analyst with Asymmetric Insights. “Games provide a different way for the exchange of information.”

Virtual Goods Transmit Real Information

Online gaming worlds are also filled with objects that can often be shared among players, and this creates possibilities that go way beyond a dead drop.

“Think of that virtual map,” Webber told TechNewsWorld. “What else can it contain? Information can be stored inside those objects.”

Given the Internet’s scope, “the cat-and-mouse game thus continues, with one group looking for increasingly obscure ways to message one another, and the other group working to preserve increasingly invasive mounds of data,” said Purtilo.

Recruitment Tool

Of course, observed in a gaming context, it could be difficult for a government agency to tell whether an online discussion is about a real-world plot or in-game strategy. That, however, may ultimately be secondary.

“Honestly, this isn’t really what the NSA and the Brits are doing,” said Webber. “They’re not really monitoring those conversations as much as looking to see whether disenfranchised youth might be recruited by these criminal or terrorist organizations.

“Gamers have technical skills, and many disenfranchised people find solace in these games,” he added. “The games can become a recruiting ground.”

Aggressive Tactics

So far, there have been no reports indicating that the two agencies’ game-monitoring efforts have produced any beneficial results, noted Webber.

“We all hope investigators are effective in ferreting out real dangers, but the more aggressive the tactics, such as trolling game rooms on the Web, the more the danger that innocent, even if incautious, speech might needlessly bring people under police suspicion,” Purtilo said.

“If officials look hard for violent-sounding speech, they’re going to find it, but its discovery does not automatically translate into a public safety benefit,” he concluded. “We should also all hope that casting such a broad net for data simply doesn’t become a job security policy for agencies.”

1 Comment

  • "virtual realms of Blizzard’s World of Warcraft and Linden Labs’ Second Life"

    Err.. Why WoW? I mean, that is just… wtf?

    Second Life.. Is a bit.. more unusual, it actually is a "virtual world" not a "game", so its possible for people to set up sims, which are closed locations, which only people in certain groups could get into, and then build just about anything they might want in there, as long as Linden didn’t find out that it was something that broke their policies. It is, thus, at least feasible that some people might try to use it for meeting places, or other activities, where are.. not in the best interest in the real world. What that means, in a practical sense, with respect to how you treat the content, is.. interesting. Do you treat it as an open system, where the "agent" just happens to wander in, like a park (since large parts of it are), or do you have to treat each location as private property, requiring search warrants, to get in there? What about the old spy agency thing, of undercover agents? Where does that come it, and how, under the circumstances?

    It, imho, makes a certain AM ount of sense that, in an open world, with no restrictions, beyond the usual real world ones, like not being allowed to have a certain content "period", etc., that Second Life, being so user configurable, "does" end up being like a building owned in a real city, or a city itself, **depending** on how the sim is set up. If open, it should be possible for people to overhear what someone else might be talking about, just as an agent might overhear someone talking at a public restaurant. If its closed.. then I would expect there need to be a search warrant, just like a real residence, and that any methods of surveillance have to be like in the real world as well (with the same, or very similar, rules).

    But, again.. how the frack does WoW, where all the content is pre-created, and, at most, a few odd people have an occasional business meeting in it, for kicks, involve that sort of activity? How would that ever work, for that matter? Its not like, if you wanted to spy on a criminal organization, they would hold the meeting in public, in some known location, instead of, say, a house, where only the people "in" a guild would be let in, in the first place. Some NSA guy is supposed to do what, wait outside and see who came in/out of the meeting (instead of just logging on "in" the guild hall)? lol

    I just don’t get what the hell the point would be, in an actual MMO.

Leave a Comment

Please sign in to post or reply to a comment. New users create a free account.

More by Peter Suciu
More in Privacy

Technewsworld Channels