Previous parts:

Thirteen years after the first Snowden documents were published, we did not expect to find unpublished ones sitting in the open. We found three images from an NSA document, uploaded for The Intercept's 2014 drone-strike article and never placed in it, reachable the whole time and, as far as we can tell, never seen. What is in them goes beyond what the article reported. Alongside it we describe a second finding: a full NSA document, uploaded with the 2015 XKEYSCORE files and linked by nothing.

On February 10, 2014, the day The Intercept published its first articles, Jeremy Scahill and Glenn Greenwald ran "The NSA's Secret Role in the U.S. Assassination Program." It described how the geolocation of mobile phones, rather than human intelligence, had become the trigger for drone strikes, and how that reliance killed the wrong people. The reporting drew on several Snowden documents, shown in the article as five screenshots.

One of those documents is a SIDtoday article written by an operator of a program called SHENANIGANS, an airborne system that collected wireless data across whole areas to locate the devices of targets in Yemen. The article quotes this operator directly. His mission, code-named VICTORYDANCE, was "a great experience," it ran six months and forty-three flights, and it mapped the Wi-Fi signature of nearly every major town in Yemen.

Snowden himself too described SHENANIGANS publicly at a 2015 meeting of the Internet Engineering Task Force, an aircraft carrying what he called "a big Stingray on the bottom of it," flown over cities to listen for the wireless identifiers of every device beneath it, used in Yemen to find particular handsets and "aiming missiles at them." He pointed to it as an example of what the former NSA director Michael Hayden meant in saying the agency kills people based on metadata.

The article reproduced five screenshots from the documents it drew on. But some of the source images for the VICTORYDANCE operator's account were uploaded to The Intercept's publishing system and then never placed in the article. Three of them have, to our knowledge, never been published anywhere.

Screenshot of the header of an NSA SIDtoday article. It shows the SIDtoday logo, a 'Published March 2013' line, and a 'By:' byline with the author's name redacted as a SHENANIGANS operator. Below, a mission statement marked TOP SECRET//SI//NOFORN reads that the target is Al Qaeda in the Arabian Peninsula and the mission is to detect and geo-locate wireless devices used by AQAP in Yemen.

The first out of the three is the header of the SIDtoday article itself, showing the SIDtoday logo, a redacted box over what is probably the headline and/or header image, and a redaction over the "By:" line naming the SHENANIGANS operator. It also carries a "Published March 2013" text. The operator's mission statement on it is marked TOP SECRET // SI // NOFORN: Top Secret, in the SI (Special Intelligence) compartment for signals intelligence, and NOFORN, not releasable to any foreign nationals, not even the NSA's Five Eyes allies.

The three images are themselves separate excerpts, so we cannot prove they belong to the same document. But they read as parts of one SIDtoday article, the operator's account of VICTORYDANCE, and we treat them as such here.

Screenshot of text from the SHENANIGANS operator's SIDtoday article, marked SECRET//REL TO USA, FVEY. It describes the tool as easy to use in the air, with only 'start collection' and 'stop collection' buttons, and notes that collection maxed out after about 77 minutes, that fuel was the biggest limiting factor, and that the first flight managed only about 30 minutes of collection before returning to base.

The published article quotes the operator's summary of the mission. The second image contains his account of how the tool actually behaved in the air, that collection "maxed out after about 77 minutes," that the aircraft's fuel was the real constraint, and that the first flight managed only about thirty minutes of collection before having to return to base. None of this is in the article. It is minor, operationally, but it is new.

Screenshot of text from the SHENANIGANS operator's SIDtoday article, marked TOP SECRET//SI//REL. It states that SIGINT analysts at NSA Washington, NSA Georgia, the Special Collection Service, and the Utah Regional Operations Center supported 'the 30 September event' by monitoring communications tied to the AQAP network, and that analysts continue to provide daily insight into AQAP.

The third image carries more weight. It describes SIGINT support for "the 30 September event," the September 30, 2011 strike that killed Anwar al-Awlaki, the U.S. citizen and AQAP figure, and it names the facilities involved. NSA Washington (NSAW), NSA Georgia, the Special Collection Service (SCS), and the Utah Regional Operations Center (UROC), all monitoring communications tied to the AQAP network around the strike. The published article says only that the NSA "played a key supporting role" in the Awlaki killing but this image names the sites that played it.

How we found them

The three images were linked nowhere. They do not appear in any article, and nothing on The Intercept's site points to them. They existed only as orphaned media, files uploaded to the publishing system and attached to no story. A content management system can leave uploaded attachments publicly reachable even when nothing points to them, and that is how these surfaced.

In the course of the same work we found a small number of other Snowden files that were unredacted versions of published documents which carried redactions over people's names. We reported these to The Intercept privately, and they were promptly removed. We are not republishing them, and for now we are not detailing how technically we found any of these images (though we may edit this post about the method later).

The three images are still hosted on The Intercept's own servers, and can be viewed directly:

Why these three were left out, we cannot say. It may have been a mistake of simply forgetting to include them. It may have been editorial, cut for the flow of the piece. Or it may have been deliberate in a stronger sense, a decision not to publish them at the request of the NSA or another authority. We have no way to tell from the outside which it was. We told The Intercept we intended to publish these three images we found and invited any objection; they did not raise one.

A final, minor curiosity. The "Published March 2013" line on the first image would make this the latest-dated SIDtoday document in the published archive. It changes nothing, but it is, so far, the last entry we know of in SIDtoday.

A document linked from nowhere

The three images mentioned above were never published. The next document was published, in the sense that anyone could read it, and yet in another sense it never was: it was uploaded to The Intercept's DocumentCloud account, made public, and then linked from no article at all.

In July 2015, The Intercept published a large investigation into XKEYSCORE, the NSA's tool for searching the private communications it collects. The reporting came in two parts and was accompanied by 48 classified documents, each uploaded to DocumentCloud and linked from the articles. A forty-ninth file was uploaded alongside them but not linked in the article. It is an NSA document titled "Mail and Ports Cheat Sheet."

The document is three pages, prepared by a contractor at Booz Allen Hamilton, marked SECRET//COMINT//REL TO USA, AUS, CAN, GBR, NZL, meaning it was cleared for sharing across all Five Eyes partners. It teaches something a first-year network administrator already knows: how email travels across the internet, and which network ports carry which kind of traffic. What raises it above a tutorial is the surveillance overlay laid on top of the plumbing.

Two NSA diagrams of an email's path across the internet, marked SECRET//COMINT//REL TO FVEY. The first shows an SMTP email from vicepresident@iaea.org to president@jaec.gov.jo over port 25. The second shows webmail from badguy@hotmail.com to badgirl@yahoo.com, with both providers' servers labeled 'U.S. IP Address.'

The first page diagrams two cases. In the first, an email travels server to server over SMTP, and the worksheet does not use placeholder names. The sender is vicepresident@iaea.org and the recipient president@jaec.gov.jo, the International Atomic Energy Agency and Jordan's Atomic Energy Commission. The IAEA was not a hypothetical choice, since it is documented elsewhere in the Snowden archive as an NSA surveillance target. In the second case, a webmail user at badguy@hotmail.com writes to badgirl@yahoo.com, and the diagram marks both the Hotmail and Yahoo servers as sitting at a "U.S. IP Address." That detail is the point of the whole exercise. It flags where a message between two foreign parties passes through American infrastructure, and so becomes collectible.

An NSA diagram of an email from an iaea.org address to a Yahoo account, with notes on what each port reveals. It states that port 80 traffic may expose logins, passwords, and GET requests, and that port 110 traffic carries users' mail-server logins and passwords.

The second page combines the two, an SMTP sender at iaea.org writing to a Yahoo account, and then explains what the ports reveal when read in the other direction. Traffic "TO port 80," the sheet notes, is "people posting things to the Internet," where an analyst "may see logins, passwords and GET requests." Traffic "TO port 110" carries "User logins and passwords for their mail server." The tone is almost casual.

An NSA diagram of a system administrator connecting to a router over TELNET (port 23). It notes that outbound traffic contains the admin's logins, passwords, and typed commands, and return traffic contains configuration files, twice marked 'good for TAO.'

The third page drops the email framing and turns to system administrators directly. Its header asks, in effect, how to obtain "logins, password and/or network configuration files." It diagrams an administrator connecting to a router over an unencrypted protocol at port 23, noting that the outbound traffic carries "logins, passwords, and commands that the S.A. is typing," while the return traffic carries the device's "configuration files." Twice it adds the lesson, once with a smiley, that this is "GOOD for TAO" (TAO being Tailored Access Operations, the NSA's hacking unit).

The worksheet is teaching analysts two things, where to intercept the world's email, and how to harvest the credentials and network maps that let TAO break into the systems carrying it. And the example it picks, to show how an ordinary email travels, is a message between two nuclear agencies.

How we found it

In the process of putting together a complete archive of published Snowden documents, one of the places we pulled from was DocumentCloud, the platform The Intercept uses to host its documents. DocumentCloud lets you filter documents by the organization that uploaded them, and you can then ask the DocumentCloud API for everything that organization has ever uploaded[note1].

We noticed that on DocumentCloud they had the "Mail and Ports Cheat Sheet" document which wasn't in our collection of documents published by The Intercept. The document's DocumentCloud ID and the date of upload strongly indicates that the document belongs to the document set published with the July 2015 XKEYSCORE article, but the document is not linked in the article itself. We wanted to be sure that this document is a truly unlinked document, so we went through each Snowden article by The Intercept and looked for links and references for this document. Going through the articles and looking for the link turned out to be painful because a document can be embedded in an article as an image with a filename that bears no relation to its DocumentCloud title or ID, or it can be referenced in some way no script will catch, so the cross-referencing collapses into purely manual checking, article by article.

We should note that the document was never truly hidden. It was reachable the whole time by anyone from DocumentCloud, and it is not entirely absent from other places of the web: it also sits in a bulk mirror of the Snowden archive uploaded to archive.org by the archivist Michael Best in September 2015. But no Intercept article points to it.

We have not run this same process of hunting unlinked Snowden documents against any other outlets, and we will be honest about why. It is miserable work. At least The New York Times and ProPublica also uploaded Snowden documents to DocumentCloud, so in theory there could be some other unlinked documents out there. We leave that work to whoever has the patience and we wish them luck.

Notes

[1]: How to find the organization ID: open any of an outlet's documents in DocumentCloud and then find its organization ID in the page's HTML source -- 1088, for example, is The Intercept's.[↑back up]