On June 5, 2013, The Guardian published the first story in what would become the most significant leak of classified intelligence in American history. The article described a secret court order compelling Verizon to hand over the telephone records of millions of Americans on an "ongoing, daily basis." The source was Edward Snowden, a 29-year-old NSA contractor who had spent the previous months copying classified documents onto SD cards and then flew to Hong Kong to hand them to journalists. Over the next two years, the documents he provided would reveal the architecture of global surveillance that the NSA and its Five Eyes partners had built in the decade since September 11, 2001.
The disclosures were not a single revelation but a sustained sequence of them, each one more architecturally significant than the last. Bulk phone metadata collection. PRISM, the program through which the NSA obtained user data directly from the servers of Google, Facebook, Apple, Microsoft, Yahoo, and five other technology companies. XKeyscore, a system described internally as giving analysts the ability to search "nearly everything a user does on the internet." The tapping of the fiber optic cables carrying international internet traffic. The compromise of SSL/TLS encryption. The deliberate weakening of cryptographic standards through NIST. The collection of 200 million text messages per day globally. The surveillance of foreign leaders including German Chancellor Angela Merkel's mobile phone. The programs, taken together, represented an intelligence apparatus of a scale and ambition that most people, including many people in government, had not known existed.
The Architecture Being Revealed
The NSA's surveillance architecture in 2013 operated through several distinct but interconnected programs, each addressing a different part of the communications landscape.
PRISM, which generated the most immediate public reaction, was a program under which the NSA obtained user content from major internet companies through legal orders under Section 702 of the Foreign Intelligence Surveillance Act. The companies - Google, Facebook, Microsoft, Yahoo, Apple, AOL, Skype, YouTube, and PalTalk - were compelled to provide access to the communications of foreign targets. The NSA's internal slides describing PRISM characterized the program as providing access to email, chat, video, photos, stored data, VoIP, file transfers, video conferencing, notifications, and social networking details. The companies denied, in carefully worded statements, that the government had "direct access" to their servers - technically accurate in that the access was provided through a specific legal process rather than a persistent backdoor, but not quite the denial those statements were intended to convey.
Upstream collection, disclosed shortly after PRISM, was in some ways more architecturally significant. Rather than going to companies with legal orders, Upstream collection involved tapping the fiber optic cables carrying internet backbone traffic directly - with the cooperation of telecommunications carriers. The NSA placed collection devices at fiber interconnects, capturing traffic in bulk and then filtering it. This gave the agency access to communications that did not flow through US-based company servers at all - international traffic between two non-Americans could be collected if it happened to traverse a US internet exchange point or undersea cable terminating in the US.
XKeyscore: The Query System
XKeyscore was the analytical front-end that allowed NSA analysts to query the collected data. Snowden's disclosure of XKeyscore was significant because it moved the debate from the question of what was collected to the question of who could access it and how easily.
The XKeyscore training materials showed that analysts could search full-content internet data by email address, phone number, IP address, or various behavioral selectors. An analyst could search for "all Excel spreadsheets containing MAC addresses from country X," or "all users searching for information about a particular subject," or "all users in a given city who accessed Tor." The query interface required filling out a justification field, but the training materials made clear that this was a largely unverified self-certification - analysts were trusted to apply the rules correctly.
Snowden, in his initial interviews with Glenn Greenwald, said that from his position as an NSA contractor he could "wiretap anyone - from you or your accountant, to a federal judge or even the president, if I had a personal email." The NSA and its defenders disputed this characterization. The more accurate statement, based on what the documents showed, was that he could query the collected data extensively - though actually executing a collection against a US person would have required additional legal authorization that the system itself did not enforce automatically.
The Cryptographic Compromise: Bullrun
Among the most technically consequential disclosures was the Bullrun program, which addressed the problem that much internet traffic was encrypted. Rather than accepting encryption as a barrier, the NSA and its British counterpart GCHQ had pursued a decade-long campaign to undermine it.
The Bullrun disclosure - jointly published by The Guardian, New York Times, and ProPublica - described a multi-pronged approach: covert influence over cryptographic standards bodies including NIST, insertion of backdoors into commercial encryption products, agreements with technology companies to obtain plaintext before encryption, and collection of encrypted traffic with the expectation that keys could be obtained later.
The specific standards-body influence related to the Dual EC DRBG controversy had already been brewing in the cryptographic community since 2007, when Dan Shumow and Niels Ferguson gave a presentation at CRYPTO suggesting the NIST-standardized random number generator might contain a backdoor. The Bullrun disclosures confirmed what had been suspected: the NSA had inserted and advocated for Dual EC DRBG through the NIST standardization process specifically because the agency had generated the P and Q constants using a secret relationship that allowed prediction of the generator's output. RSA Security, which had made Dual EC DRBG the default in its BSAFE toolkit after receiving a $10 million payment from the NSA, became the center of a controversy that effectively ended its reputation in the cryptographic community.
The Five Eyes Architecture
The disclosures also detailed the Five Eyes intelligence sharing arrangement - the alliance between the signals intelligence agencies of the United States (NSA), United Kingdom (GCHQ), Canada (CSE), Australia (ASD), and New Zealand (GCSB) - and the extent to which these agencies had divided global collection responsibilities and shared results.
The arrangement allowed the Five Eyes to effectively route around domestic legal restrictions. If the NSA was legally prohibited from conducting certain surveillance against US persons, the GCHQ might collect equivalent data against British persons on behalf of the NSA, and vice versa. The shared databases and collection infrastructure meant that the legal restrictions applicable to any individual agency were substantially less limiting than they appeared when considered in isolation.
The international scope of the disclosures - which revealed surveillance against allies including Germany, France, Brazil, Mexico, and dozens of other countries - created diplomatic crises that went beyond the domestic American debate about civil liberties and government overreach. Angela Merkel's reported response to learning her mobile phone had been under NSA surveillance - "This is unacceptable between friends and allies and has to stop immediately" - captured the reaction of much of the international community.
Edward Snowden: The Source
Snowden worked as an NSA contractor through Booz Allen Hamilton and, before that, Dell, after a brief period as a CIA systems administrator. His access to NSA systems was extensive - contractors often had broad access because they were used to do administrative and infrastructure work that required visibility across many programs. He used this access, over several months in early 2013, to collect documents from NSA internal networks including the Heartbeat archive system and the NSA's internal Wikipedia-style system.
He flew to Hong Kong in late May 2013 and contacted journalists Glenn Greenwald of The Guardian and documentary filmmaker Laura Poitras, who had both previously written about national security surveillance. He was accompanied by Guardian journalist Ewen MacAskill. The interviews he gave from his Hong Kong hotel room, before The Guardian had published anything, established his identity and rationale on camera - a calculated choice to pre-empt what he knew would be a government effort to discredit him by controlling the narrative about who he was.
His stated rationale was consistent across years of interviews: he believed the American public did not know what was being done in their name, that the surveillance architecture being built was fundamentally incompatible with a democratic society, and that the classification system was being used to prevent citizens from making informed decisions about surveillance policy. He did not claim the surveillance was always illegal - he argued that even if technically authorized, the scale and scope of what was being collected represented a policy choice that had never been put to democratic deliberation.
The Government Response
The Obama administration's response operated on several tracks simultaneously. Officials including Director of National Intelligence James Clapper, who had told Congress in March 2013 that the NSA did "not wittingly" collect data on millions of Americans (a statement that the Verizon court order disclosure immediately revealed to be false), defended the programs. NSA Director Keith Alexander argued that the surveillance had disrupted "54 terrorist plots." This figure was later analyzed by the Privacy and Civil Liberties Oversight Board, which concluded that the bulk phone metadata program had not played a significant role in preventing any attacks - the metadata collection was of marginal operational value at best.
Snowden was charged under the Espionage Act in June 2013. While he was in transit from Hong Kong, the US revoked his passport. He ended up stranded in Moscow's Sheremetyevo airport for 40 days before Russia granted him temporary asylum - an outcome that allowed the government to frame him as having defected to Russia, a narrative he strenuously disputed. He has remained in Russia since. In 2022, President Putin granted him Russian citizenship. In 2020, a federal court ruled that the NSA's bulk phone metadata collection program had been illegal.
The Technical Consequences
The Snowden disclosures accelerated changes to internet security infrastructure that were already underway but moved much faster after 2013.
HTTPS adoption was the most visible change. Before 2013, most web traffic was unencrypted HTTP, with HTTPS reserved for login pages and payment forms. The revelation that the NSA was reading unencrypted traffic in bulk provided the motivation for a rapid shift to HTTPS-by-default. Let's Encrypt, which launched in 2016 and provided free automated TLS certificates, was a direct institutional response to the disclosures. The percentage of web traffic using HTTPS went from roughly 30% in 2013 to over 90% by 2020.
End-to-end encryption in messaging applications accelerated dramatically. Signal, which provided end-to-end encrypted messaging with the Signal Protocol, saw adoption surge. WhatsApp integrated the Signal Protocol in 2016, putting end-to-end encryption in front of a billion users. Apple's iMessage had always used end-to-end encryption; the company reinforced and publicized this after 2013. The effect was to move a substantial portion of human communication into channels that could not be read even with legal process against the service provider - exactly the "going dark" problem that law enforcement has been arguing about ever since.
Tor usage increased significantly after 2013. Certificate Transparency, which creates a public log of all issued TLS certificates to prevent unauthorized certificates from being silently issued, was deployed by Google in 2013 and became an industry standard partially in response to concerns about government coercion of certificate authorities. Forward secrecy, which ensures that compromise of a long-term key does not allow decryption of past sessions, became a standard requirement rather than an optional enhancement.
Policy Consequences
The USA FREEDOM Act, passed in June 2015, ended the NSA's bulk collection of domestic telephone metadata. Instead of the NSA holding the records, they would remain with the telephone companies, with the NSA querying them through a more targeted process requiring court approval for each query. This was a genuine legislative reform - the bulk metadata program that had operated since 2001 was specifically ended - though critics noted it left most of the PRISM and Upstream collection programs unchanged.
The European Court of Justice's Schrems decisions (2015 and 2020) struck down the EU-US data transfer frameworks - Safe Harbor and its successor Privacy Shield - on the grounds that US surveillance law did not provide adequate protection for European citizens' data. These decisions created years of legal uncertainty for transatlantic data flows and forced the negotiation of a new framework (the EU-US Data Privacy Framework, adopted in 2023) that remains contested.
Section 702, the legal authority under which PRISM operated, has been periodically reauthorized by Congress with modest modifications. It was reauthorized in April 2024 with an expansion that broadened the categories of businesses that could be compelled to assist with surveillance. The core architecture of the surveillance apparatus that Snowden disclosed remains operational.
The Historical Assessment
Ten years after the initial disclosures, assessments of Snowden's actions and their consequences vary predictably by political orientation and institutional position. Intelligence community officials generally maintain that the disclosures caused lasting damage to US intelligence capabilities and endangered sources. Civil liberties organizations argue that the reforms they produced, however incomplete, were significant and necessary corrections to an apparatus that had grown beyond democratic oversight. Academic assessments tend to be more nuanced about both the value of what the NSA was doing and the harm from disclosure.
What is harder to dispute is the technical record. The cryptographic standards were weakened. The encryption was being compromised at scale. The bulk collection programs were operating with minimal effective oversight. The federal court that eventually reviewed the phone metadata program found it illegal. The surveillance of allied leaders' phones produced diplomatic damage that outlasted the Obama administration. Whatever one thinks about how this information should have been disclosed, the information itself was accurate.
The deeper question the disclosures raised - about the appropriate scope of surveillance by democratic states, about the tension between security and privacy, about whether the classification system serves legitimate interests or primarily protects institutions from accountability - has not been resolved. The architecture continues to operate. The debate continues. The encryption that billions of people use daily has been substantially strengthened in response. The surveillance that operates through legal process against metadata and company data has been reformed at the margins and continues in its substantial form. Snowden remains in Moscow.