MUSCULAR: NSA Tapping Google/Yahoo Inter-DC Links (Revealed 2013)
Introduction
In October 2013, the Washington Post published a story by reporters Barton Gellman and Ashkan Soltani revealing that the National Security Agency, together with Britain's GCHQ, had secretly tapped the private fibre-optic links connecting Google's and Yahoo's data centres to one another. The programme was codenamed MUSCULAR. The disclosure was among the most significant revelations in the Snowden archive because it exposed an intelligence operation targeting the internal infrastructure of two of the world's largest internet companies — infrastructure those companies believed to be private and secure.
What MUSCULAR Was
Google and Yahoo operate global networks of data centres connected by high-capacity fibre-optic cables. Data flowing between these centres — including user emails, search queries, and cloud storage — was, at the time of the MUSCULAR revelations, transmitted unencrypted within the companies' private networks. The companies considered this traffic protected by the private nature of their backbone infrastructure.
MUSCULAR exploited this assumption. The NSA and GCHQ, operating through a covert programme, accessed these inter-data-centre links at points where the cables passed through or near facilities accessible to British intelligence. The data was then forwarded to NSA repositories. Because the interception occurred on the backbone rather than at endpoints, it bypassed the legal framework governing requests to companies — such as the Foreign Intelligence Surveillance Court orders used under PRISM — and occurred entirely without the companies' knowledge or consent.
The Washington Post published NSA slides, including a diagram drawn by an NSA analyst showing data flowing between Google front-end servers with a handwritten annotation, ''SSL added and removed here'' followed by a smiley face. The annotation captured the intelligence significance: Google used SSL (encrypted connections) between users and its servers, but did not at that time encrypt traffic between its own data centres. MUSCULAR collected that unencrypted internal traffic.
Scale of Collection
According to NSA documents published by the Post, MUSCULAR collected millions of records per day. A 30-day period in January 2013 produced approximately 181 million records from the Google and Yahoo networks. The records included metadata and content.
Corporate Response
Google and Yahoo denied knowledge of the programme. Both companies publicly expressed outrage. Within months of the disclosure, both companies accelerated plans to encrypt traffic between their data centres — a direct response to MUSCULAR. Google's engineering blog described the encryption rollout explicitly in the context of NSA surveillance. The episode was a significant driver of industry-wide movement toward end-to-end and in-transit encryption of data centre traffic.
MUSCULAR vs. PRISM
MUSCULAR and PRISM are frequently conflated but are legally and technically distinct. PRISM operated under Section 702 of the FISA Amendments Act, using court-approved orders compelling US communications companies to provide specified data. The companies were legally obligated to comply and legally barred from disclosing it. MUSCULAR involved no legal process directed at the companies and no company knowledge or cooperation — it was a covert infrastructure tap.
The distinction matters because PRISM had a statutory basis (contested but present), while MUSCULAR operated under the NSA's foreign intelligence authority applied to what it characterised as foreign-located infrastructure, exploiting the fact that the cable taps occurred at points outside US jurisdiction.
Confirmation
MUSCULAR is confirmed by NSA and GCHQ slides published by the Washington Post, subsequent reporting by multiple outlets drawing on the Snowden archive, and independent technical analysis corroborating the described interception method. The US government did not deny the programme's existence; it argued that the collection was conducted lawfully under foreign intelligence authorities.
Verdict
Confirmed. NSA and GCHQ slides published by the Washington Post in October 2013 confirm MUSCULAR's existence, scope, and method. The programme tapped unencrypted backbone traffic between Google and Yahoo data centres without the companies' knowledge, collecting millions of records daily. The disclosure directly prompted industry-wide encryption of internal data-centre links.
How the Interception Actually Worked
The NSA's own paperwork named the specific target. Among the slides the Washington Post published was one titled "Google Cloud Exploitation," which IEEE Spectrum's independent technical review described as detailing how MUSCULAR bypassed the security boundary around Google's cloud — the point where traffic left the public, SSL-protected internet and entered Google's private internal network. That boundary was exactly where the programme worked: an NSA analyst had hand-drawn a small diagram of Google's front-end and cloud architecture, and at the point where encrypted user traffic was decrypted before being routed internally, the analyst wrote "SSL added and removed here!" next to a smiley face. When the Post described the drawing to Google engineers, the reaction was immediate. Slate's account of the disclosure reported that two Google engineers "reacted with strong profanity" on seeing it, and one told reporters, "I hope you publish this." The sketch became, in Slate's framing, a symbol less of technical sophistication than of how casually the agency treated a breach of infrastructure a major company believed was private.
What the Documents Showed, and How NSA Responded
The Post's October 30, 2013 story by Barton Gellman and Ashkan Soltani was built on a "top-secret accounting" dated January 9, 2013, showing NSA's Special Source Operations directorate routing millions of records a day from Google's and Yahoo's internal networks to warehouses at Fort Meade. In the 30 days covered by that accounting, field collection had processed exactly 181,280,466 new records, ranging from metadata to content — text, audio and video. What stands out about the NSA's public response is what it didn't do: PBS NewsHour's coverage the same day reported NSA Director Gen. Keith Alexander saying the agency was "not authorized" to conduct such collection domestically and had to "go through a court process," language that addressed the legal framework surrounding US companies in the abstract without specifically denying the interception of Google and Yahoo's overseas links that the documents described. Unlike some earlier Snowden-era disputes, in which officials directly contested reporters' characterizations, the agency's reaction here left the substance of the Post's documents unchallenged.
Inside the Companies: Fury, Statements, and a Race to Encrypt
Google's chief legal officer, David Drummond, put the company's position on the record in terms sharper than most corporate statements of the period: "We have long been concerned about the possibility of this kind of snooping... We do not provide any government, including the U.S. government, with access to our systems. We are outraged at the lengths to which the government seems to have gone to intercept data from our private fiber networks, and it underscores the need for urgent reform," he said, as reported by the Harvard Journal of Law & Technology's Digest. Google's own engineers were angrier still, and said so publicly. Security engineer Brandon Downey wrote on Google+ that the revelations left him wanting to say "fuck these guys," and colleague Mike Hearn added that he was "issuing a giant Fuck You to the people who made these slides," arguing that the warrant system MUSCULAR bypassed was "built from centuries of hard won experience." Yahoo's response combined denial with a concrete commitment. CEO Marissa Mayer stated on November 18, 2013 that "Yahoo has never given access to our data centers to the NSA or to any other government agency. Ever," while announcing the company would encrypt all traffic between its data centers and all traffic to customers by the first quarter of 2014, alongside 2048-bit SSL for Yahoo Mail by January 8, 2014. The Harvard Digest also flagged a caveat from ACLU technologist Christopher Soghoian: encryption "forces surveillance to be more targeted," but "if the NSA wants to get in, they're going to get in" — meaning the companies' response raised the operational cost of collection without claiming to have closed the underlying gap entirely.
MUSCULAR's Legal Grey Zone — the Strongest Counter-Argument, and Why It Doesn't Hold
The clearest statement of MUSCULAR's legal footing comes from the Electronic Frontier Foundation's contemporaneous analysis, which noted the programme was "not part of the PRISM collection under Section 702... or the business records program under Section 215... but a separate program... under what appears to be Executive Order 12333" — a Reagan-era directive covering foreign intelligence collection abroad that, as EFF put it, "relies on Executive oversight" rather than a statute or a court. That is the strongest defense available to the programme's supporters: EO 12333 is a real, decades-old written directive with internal NSA and Justice Department compliance procedures, not a legal vacuum, and it is framed around foreign intelligence targets rather than Americans. On paper, that describes a governance structure, not lawlessness. It does not hold up well under EFF's own reporting from the same period, which quoted then-Senate Intelligence Committee Chair Dianne Feinstein saying EO 12333 collection activity "does not fall within the focus" of her committee's oversight — meaning the body Congress relies on to check this kind of collection had, by its own chair's account, not been exercising that check. Layered onto EFF's broader "upstream vs. downstream" framework — bulk copying of backbone traffic versus itemized legal requests to companies — the practical result was self-certified executive-branch compliance with no independent verification, applied at a scale, 181 million records in 30 days, that inevitably captured Americans' communications riding the same global data links.
Aftermath and Legacy
The encryption commitments both companies made in November 2013 were followed through rather than abandoned, and MUSCULAR is now widely cited as the specific trigger that made encrypting internal, data-centre-to-data-centre traffic a baseline industry practice rather than an unusual precaution. The episode's afterlife extended well past the immediate news cycle. Barton Gellman, the Post reporter who broke the story, revisited it at length in his 2020 book "Dark Mirror: Edward Snowden and the American Surveillance State," recounting the reporting process behind establishing that, in his words, the NSA had found a way inside Google's internal network. PBS's Frontline devoted the second half of its 2014 two-part documentary "United States of Secrets" specifically to what it called "the secret relationship between Silicon Valley and the National Security Agency," using MUSCULAR as a central example of how government collection had reached into infrastructure companies believed was walled off from outside access. Together, the corporate statements, the engineers' public fury, and the sustained retrospective attention from journalists and documentarians make MUSCULAR one of the more thoroughly re-examined episodes to come out of the Snowden archive, distinct from PRISM precisely because no part of the record — then or since — has included a company acknowledging it gave permission.
Evidence Filters16
NSA/GCHQ slides published by Washington Post confirm programme
SupportingStrongThe Washington Post published NSA and GCHQ slides including diagrams of the Google backbone interception architecture and an analyst annotation ('SSL added and removed here :)') confirming that the programme exploited unencrypted inter-data-centre traffic.
181 million records collected in 30 days — January 2013
SupportingStrongNSA documents cited in the Washington Post reporting specified that MUSCULAR collected approximately 181 million records from Google and Yahoo networks during a single 30-day period in January 2013, confirming the scale of the operation.
Google and Yahoo denied knowledge — and encrypted their links in response
SupportingStrongBoth companies publicly denied any knowledge of or cooperation with MUSCULAR. The denial is consistent with the programme's covert character. Both companies accelerated encryption of their inter-data-centre links directly in response to the disclosure.
MUSCULAR bypassed the legal PRISM framework entirely
SupportingStrongPRISM used FISC orders to compel company disclosure under Section 702. MUSCULAR circumvented this framework by intercepting data on private backbone infrastructure at points outside US legal jurisdiction, with no legal process directed at the companies.
NSA characterised interception as lawful foreign intelligence collection
DebunkingThe US government argued that MUSCULAR was lawful because the interception occurred outside the US on infrastructure characterised as foreign, applying foreign intelligence authorities rather than domestic surveillance law. Critics argued this reasoning had no basis in FISA or the Fourth Amendment.
Rebuttal
The government's legal characterisation is disputed and does not affect confirmation of the programme's existence or its technical operation. The legal argument is a justification post-revelation, not a rebuttal of the underlying facts.
Programme operated without company knowledge or consent
SupportingStrongUnlike PRISM, which involved compelled company cooperation under legal orders, MUSCULAR operated covertly against private infrastructure without the target companies' awareness, raising distinct legal and ethical questions about the limits of intelligence collection on nominally private networks.
GCHQ participation confirmed by British intelligence slides
SupportingStrongThe published documents included GCHQ slides confirming British intelligence participation in MUSCULAR, consistent with the Five Eyes signals intelligence-sharing framework under which NSA and GCHQ routinely conduct joint operations.
Technical analysts verified the described interception method is feasible
SupportingIndependent cryptographers and network engineers who reviewed the published slides assessed the described interception method as technically credible and consistent with known capabilities for tapping fibre-optic backbone traffic at cable landing or peering points.
NSA Director Alexander denied the agency 'hacked into' company servers, without addressing the fiber-link interception WaPo described
DebunkingIn coverage published the same day as the Washington Post's story, PBS NewsHour reported NSA Director Gen. Keith Alexander saying the agency was ‘not authorized’ to conduct such collection and had to ‘go through a court process’ — a response about the legal framework governing US companies that did not specifically deny the interception of Google and Yahoo's overseas data-center links described in the leaked documents.
Rebuttal
MUSCULAR's tap point was the fiber-optic link between data centers abroad, not company servers themselves — a technical distinction that let Alexander's statement stand without contradicting the documents. He did not dispute the 181-million-record figure, the existence of MUSCULAR, or GCHQ's role.
MUSCULAR operated under Executive Order 12333, a written presidential directive with internal NSA/DOJ compliance procedures, not a legal void
DebunkingEFF's November 2013 analysis of the Snowden disclosures confirmed MUSCULAR fell under Executive Order 12333 rather than the FISA Section 702 (PRISM) or Section 215 authorities, describing 12333 as a real, decades-old directive governing foreign intelligence collection abroad with formal internal executive-branch oversight procedures.
Rebuttal
The same EFF analysis quoted then-Senate Intelligence Committee Chair Dianne Feinstein saying EO 12333 collection activity 'does not fall within the focus' of her committee's oversight — meaning the body Congress relies on to check this kind of collection had, by its own chair's account, not been exercising that check at the time MUSCULAR was operating.
Show 6 more evidence points
EFF's technical framework situates MUSCULAR-style interception as bulk 'upstream' cable copying, structurally distinct from PRISM's itemized requests to companies
SupportingEFF's 'Upstream vs. PRISM' analysis details how NSA partners physically copy data flowing through fiber-optic backbone cables — the model MUSCULAR used against Google and Yahoo's overseas links — versus PRISM's process of compelling companies to disclose communications tied to specific, court-approved selectors.
IEEE Spectrum's independent technical review corroborated the NSA's 'Google Cloud Exploitation' slide describing a bypass of Google's internal security boundary
SupportingIEEE Spectrum's engineering-press coverage of the leaked slides confirmed the existence and content of a slide titled 'Google Cloud Exploitation,' which detailed how MUSCULAR bypassed Google's security measures at the boundary between public SSL-protected traffic and Google's unencrypted internal cloud network — independently corroborating the mechanism described in the Washington Post's reporting.
Google and Yahoo Deployed Inter-Datacenter Encryption by Early 2014, Ending the Program's Utility
DebunkingWithin months of the November 2013 Washington Post disclosures of MUSCULAR, Google announced it had already begun encrypting traffic between its data centers and accelerated deployment. Yahoo completed similar encryption in 2014. Since MUSCULAR exploited unencrypted fiber links between data centers, this technical response effectively ended the program's collection capability for those companies. The speed of corporate response suggests the companies were genuinely unaware and moved decisively when informed — undermining claims of knowing cooperation. This outcome illustrates that adversarial technical countermeasures, once publicly disclosed, can close specific surveillance vectors relatively quickly.
Google and Yahoo Deployed Inter-Data-Centre Encryption Within Months of Disclosure
NeutralFollowing the Washington Post's October 2013 MUSCULAR story, Google announced it had begun encrypting traffic between its data centres — a measure that would have defeated the programme's collection method. Yahoo implemented similar protections by Q1 2014. This rapid corporate response effectively ended MUSCULAR's operational utility against these targets. The disclosure therefore had a concrete remediation effect, distinguishing this case from surveillance programmes whose continuation was unaffected by exposure.
MUSCULAR Was a UK GCHQ-Led Operation Targeting Non-US Traffic Abroad
DebunkingGCHQ's Blarney programme tapped Google and Yahoo fibre links between overseas data centres — traffic that, because it transited outside US territory, fell outside both FISA Court jurisdiction and Section 702 authorisations. NSA participated as a junior partner. This jurisdictional framing matters: the operation was designed to avoid US legal constraints by operating on non-US soil against non-US-person traffic, making it legally distinct (if ethically contested) from domestic surveillance programmes. Conflating MUSCULAR with domestic collection programmes mischaracterises its legal basis and target scope.
MUSCULAR Operated Under EO 12333, Targeting Non-US Persons Outside the US
NeutralMUSCULAR was operated jointly with UK GCHQ and justified under Executive Order 12333's foreign-intelligence collection authority, which applies outside US borders to non-US persons. The fiber links targeted were located outside the United States, placing collection outside FISA's geographic and person-based constraints. This does not make the program unproblematic — Americans' communications transiting foreign data centers were incidentally collected — but the legal architecture differs from domestic warrantless surveillance. Conflating MUSCULAR's legal basis with Stellar Wind's domestic warrantless collection, or with programs requiring FISA Court orders, obscures meaningfully different legal and operational frameworks governing each program.
Evidence Cited by Believers9
NSA/GCHQ slides published by Washington Post confirm programme
SupportingStrongThe Washington Post published NSA and GCHQ slides including diagrams of the Google backbone interception architecture and an analyst annotation ('SSL added and removed here :)') confirming that the programme exploited unencrypted inter-data-centre traffic.
181 million records collected in 30 days — January 2013
SupportingStrongNSA documents cited in the Washington Post reporting specified that MUSCULAR collected approximately 181 million records from Google and Yahoo networks during a single 30-day period in January 2013, confirming the scale of the operation.
Google and Yahoo denied knowledge — and encrypted their links in response
SupportingStrongBoth companies publicly denied any knowledge of or cooperation with MUSCULAR. The denial is consistent with the programme's covert character. Both companies accelerated encryption of their inter-data-centre links directly in response to the disclosure.
MUSCULAR bypassed the legal PRISM framework entirely
SupportingStrongPRISM used FISC orders to compel company disclosure under Section 702. MUSCULAR circumvented this framework by intercepting data on private backbone infrastructure at points outside US legal jurisdiction, with no legal process directed at the companies.
Programme operated without company knowledge or consent
SupportingStrongUnlike PRISM, which involved compelled company cooperation under legal orders, MUSCULAR operated covertly against private infrastructure without the target companies' awareness, raising distinct legal and ethical questions about the limits of intelligence collection on nominally private networks.
GCHQ participation confirmed by British intelligence slides
SupportingStrongThe published documents included GCHQ slides confirming British intelligence participation in MUSCULAR, consistent with the Five Eyes signals intelligence-sharing framework under which NSA and GCHQ routinely conduct joint operations.
Technical analysts verified the described interception method is feasible
SupportingIndependent cryptographers and network engineers who reviewed the published slides assessed the described interception method as technically credible and consistent with known capabilities for tapping fibre-optic backbone traffic at cable landing or peering points.
EFF's technical framework situates MUSCULAR-style interception as bulk 'upstream' cable copying, structurally distinct from PRISM's itemized requests to companies
SupportingEFF's 'Upstream vs. PRISM' analysis details how NSA partners physically copy data flowing through fiber-optic backbone cables — the model MUSCULAR used against Google and Yahoo's overseas links — versus PRISM's process of compelling companies to disclose communications tied to specific, court-approved selectors.
IEEE Spectrum's independent technical review corroborated the NSA's 'Google Cloud Exploitation' slide describing a bypass of Google's internal security boundary
SupportingIEEE Spectrum's engineering-press coverage of the leaked slides confirmed the existence and content of a slide titled 'Google Cloud Exploitation,' which detailed how MUSCULAR bypassed Google's security measures at the boundary between public SSL-protected traffic and Google's unencrypted internal cloud network — independently corroborating the mechanism described in the Washington Post's reporting.
Counter-Evidence5
NSA characterised interception as lawful foreign intelligence collection
DebunkingThe US government argued that MUSCULAR was lawful because the interception occurred outside the US on infrastructure characterised as foreign, applying foreign intelligence authorities rather than domestic surveillance law. Critics argued this reasoning had no basis in FISA or the Fourth Amendment.
Rebuttal
The government's legal characterisation is disputed and does not affect confirmation of the programme's existence or its technical operation. The legal argument is a justification post-revelation, not a rebuttal of the underlying facts.
NSA Director Alexander denied the agency 'hacked into' company servers, without addressing the fiber-link interception WaPo described
DebunkingIn coverage published the same day as the Washington Post's story, PBS NewsHour reported NSA Director Gen. Keith Alexander saying the agency was ‘not authorized’ to conduct such collection and had to ‘go through a court process’ — a response about the legal framework governing US companies that did not specifically deny the interception of Google and Yahoo's overseas data-center links described in the leaked documents.
Rebuttal
MUSCULAR's tap point was the fiber-optic link between data centers abroad, not company servers themselves — a technical distinction that let Alexander's statement stand without contradicting the documents. He did not dispute the 181-million-record figure, the existence of MUSCULAR, or GCHQ's role.
MUSCULAR operated under Executive Order 12333, a written presidential directive with internal NSA/DOJ compliance procedures, not a legal void
DebunkingEFF's November 2013 analysis of the Snowden disclosures confirmed MUSCULAR fell under Executive Order 12333 rather than the FISA Section 702 (PRISM) or Section 215 authorities, describing 12333 as a real, decades-old directive governing foreign intelligence collection abroad with formal internal executive-branch oversight procedures.
Rebuttal
The same EFF analysis quoted then-Senate Intelligence Committee Chair Dianne Feinstein saying EO 12333 collection activity 'does not fall within the focus' of her committee's oversight — meaning the body Congress relies on to check this kind of collection had, by its own chair's account, not been exercising that check at the time MUSCULAR was operating.
Google and Yahoo Deployed Inter-Datacenter Encryption by Early 2014, Ending the Program's Utility
DebunkingWithin months of the November 2013 Washington Post disclosures of MUSCULAR, Google announced it had already begun encrypting traffic between its data centers and accelerated deployment. Yahoo completed similar encryption in 2014. Since MUSCULAR exploited unencrypted fiber links between data centers, this technical response effectively ended the program's collection capability for those companies. The speed of corporate response suggests the companies were genuinely unaware and moved decisively when informed — undermining claims of knowing cooperation. This outcome illustrates that adversarial technical countermeasures, once publicly disclosed, can close specific surveillance vectors relatively quickly.
MUSCULAR Was a UK GCHQ-Led Operation Targeting Non-US Traffic Abroad
DebunkingGCHQ's Blarney programme tapped Google and Yahoo fibre links between overseas data centres — traffic that, because it transited outside US territory, fell outside both FISA Court jurisdiction and Section 702 authorisations. NSA participated as a junior partner. This jurisdictional framing matters: the operation was designed to avoid US legal constraints by operating on non-US soil against non-US-person traffic, making it legally distinct (if ethically contested) from domestic surveillance programmes. Conflating MUSCULAR with domestic collection programmes mischaracterises its legal basis and target scope.
Neutral / Ambiguous2
Google and Yahoo Deployed Inter-Data-Centre Encryption Within Months of Disclosure
NeutralFollowing the Washington Post's October 2013 MUSCULAR story, Google announced it had begun encrypting traffic between its data centres — a measure that would have defeated the programme's collection method. Yahoo implemented similar protections by Q1 2014. This rapid corporate response effectively ended MUSCULAR's operational utility against these targets. The disclosure therefore had a concrete remediation effect, distinguishing this case from surveillance programmes whose continuation was unaffected by exposure.
MUSCULAR Operated Under EO 12333, Targeting Non-US Persons Outside the US
NeutralMUSCULAR was operated jointly with UK GCHQ and justified under Executive Order 12333's foreign-intelligence collection authority, which applies outside US borders to non-US persons. The fiber links targeted were located outside the United States, placing collection outside FISA's geographic and person-based constraints. This does not make the program unproblematic — Americans' communications transiting foreign data centers were incidentally collected — but the legal architecture differs from domestic warrantless surveillance. Conflating MUSCULAR's legal basis with Stellar Wind's domestic warrantless collection, or with programs requiring FISA Court orders, obscures meaningfully different legal and operational frameworks governing each program.
Timeline
MUSCULAR collects 181 million records in 30 days
NSA documents later published by the Washington Post record that MUSCULAR collected approximately 181 million records from Google and Yahoo networks during a 30-day period in January 2013, illustrating the programme's operational scale at the time of the Snowden disclosures.
Washington Post publishes Gellman/Soltani MUSCULAR investigation
Barton Gellman and Ashkan Soltani publish the MUSCULAR story in the Washington Post, including NSA/GCHQ slides and the analyst annotation confirming that the programme intercepted unencrypted backbone traffic between Google and Yahoo data centres.
Source →NSA responds without denying the specific MUSCULAR allegations
The same day the Washington Post's story runs, PBS NewsHour reports NSA Director Gen. Keith Alexander saying the agency was 'not authorized' to conduct such collection and must 'go through a court process' — a statement about US companies' legal protections that does not specifically deny the interception of Google and Yahoo's overseas data-center links described in the leaked documents.
Source →Google announces encryption of inter-data-centre links
Within days of the MUSCULAR disclosure, Google's security engineering team announces an accelerated rollout of encryption for all traffic between its data centres worldwide, explicitly citing NSA surveillance as the motivation. Yahoo announces similar measures.
Verdict
Confirmed by NSA and GCHQ slides published by the Washington Post in October 2013. MUSCULAR tapped unencrypted fibre-optic links between Google and Yahoo data centres without company knowledge, collecting approximately 181 million records in a single 30-day period. The programme operated outside FISC legal process. Both companies subsequently encrypted their internal backbone traffic in direct response.
Frequently Asked Questions
How is MUSCULAR different from PRISM?
PRISM operated under Section 702 of the FISA Amendments Act, using FISC-approved orders to compel US communications companies to provide specified data. The companies were legally required to comply and knew about the orders. MUSCULAR involved no legal process directed at Google or Yahoo, no company knowledge, and no cooperation — it was a covert tap of private backbone infrastructure at points outside US jurisdiction.
Did Google and Yahoo know about MUSCULAR?
No. Both companies publicly denied any knowledge of or participation in MUSCULAR. The companies expressed outrage at the disclosure. Within weeks, both companies accelerated plans to encrypt their inter-data-centre backbone traffic — a direct response to the discovery that the NSA had exploited the lack of such encryption.
How much data did MUSCULAR collect?
NSA documents cited in the Washington Post reporting specified approximately 181 million records from Google and Yahoo networks in a single 30-day period in January 2013. The records included both content (emails, documents) and metadata (communication patterns, user identifiers).
Was MUSCULAR legal?
The US government argued that MUSCULAR was conducted lawfully under foreign intelligence collection authorities because the interception occurred at points outside US jurisdiction on infrastructure characterised as foreign. Critics and legal scholars argued this reasoning had no basis in FISA or the Fourth Amendment. The programme was not reviewed by any court before the Snowden disclosures.
Sources
Show 11 more sources
Further Reading
- articleNSA infiltrates links to Yahoo, Google data centers worldwide (WaPo) — Barton Gellman, Ashkan Soltani (2013)
- bookNo Place to Hide: Edward Snowden, the NSA, and the U.S. Surveillance State — Glenn Greenwald (2014)
- documentaryUnited States of Secrets (Part Two: 'Privacy Lost') — PBS Frontline (2014)
- bookDark Mirror: Edward Snowden and the American Surveillance State — Barton Gellman (2020)
- bookDark Mirror: Edward Snowden and the American Surveillance State — Barton Gellman (2020)