Showing posts with label NSA. Show all posts
Showing posts with label NSA. Show all posts

Friday, November 7, 2014

Klayman v Obama at DC Court of Appeals

Tuesday was midterm election day, but the important event that got much less attention was the DC court of Appeals hearing regarding NSA's metadata collection in the case of Klayman v Obama.

The Oral Arguments are available here from the court's website and here from C-SPAN, with pictures showing who is talking which is nice.

Here is a recap/summary of the arguments.

After Snowden's revelations last year, many lawsuits were filed against the government fighting dragnet collection as unconstitutional under the 4th Amendment.  Larry Klayman is a DC lawyer and conservative activist famous for many controversial lawsuits against Presidents Clinton and Obama, (here he was during the government shutdown last year, he sued claiming Obama is not an American citizen, and is now in the news for his Ebola lawsuit more than the NSA case, let alone the Seal Team 6 helicopter crash case, which I find very interesting because as I wrote here it adds attorney-client privilege to the dangers of dragnet surveillance.
One recent morning, he and half a dozen clients attend a hearing in the Rayburn Building. His clients are parents of servicemen who were killed when a helicopter with the call sign Extortion 17 was shot down in Afghanistan on Aug. 6, 2011. Thirty Americans were killed, including some members of the Navy SEALs unit that had killed Osama bin Laden. The crash was the deadliest incident for U.S. forces in the war.
The Pentagon maintains that the tragedy was caused by a lucky shot with a rocket-propelled grenade. But these parents, and Klayman, think their sons may have been sold out by Afghan turncoats for a Taliban ambush. They base their suspicions on anomalies in the official explanation and partial evidence they have unearthed.
Michael was a Navy cryptologist who was working with SEAL Team 6 when he was killed shortly after the killing of Osama bin Laden.  
the military sent Michael to train for five months as a cryptologist in Pensacola, Florida, so he could learn how to decode encrypted messages between terrorist cells. “We didn’t know he was that smart,” Charlie says. “That’s some bad shit, you know?” After Florida, in 2005, the Navy sent Michael to its Naval Information Operations Command in Hawaii, which works closely with the 2,700 Hawaii employees of the National Security Agency. He deployed to Afghanistan for the first time later that year, and then to Iraq in 2006, where he spent nine months embedded with SEAL Team Two, providing crypto support. He’d go into battle with a kind of laptop that could pick up enemy signals and locate snipers and “squirters” — military lingo for people who flee a target area.
Michael eventually left Hawaii for a coveted spot in Virginia Beach, Virginia, home to the Naval Special Warfare Development Group, better known as SEAL Team Six.
continued 
Last June, after former NSA contractor Edward Snowden disclosed to the world that the U.S. government was gathering “metadata” on the phone calls of millions of Verizon customers, Klayman called Charlie and talked to him about it. Was Charlie a Verizon customer? Charlie said he was. Would he like to sue the government to stop this kind of data collection in the future? He said he would. “So we don’t become an Orwellian society,” Charlie says.
The suit was a long shot. Klayman made himself a plaintiff, along with Charlie and Mary. In his complaint, he listed the following as defendants: “Barack Hussein Obama II,” Attorney General Eric Holder, director of the NSA Keith Alexander, the CEO of Verizon, a judge on the Foreign Intelligence Surveillance Court, Verizon, the NSA and the Department of Justice. The complaint seemed more than a bit grandiose, especially given that no judge had ever rebuked the NSA the way Klayman and the Stranges were demanding. And Klayman’s style attracted some ridicule. In oral argument, he told the court about some unusual text messages the Stranges had gotten, texts from Michael’s old number that contained only ones and zeroes, and said he’d gotten some bizarre messages himself; he also talked about the disk that Charlie thought contained spyware. The government, Klayman said, was “messing with me.”
Dan Froomkin writes that Klayman nearly derailed the case
when the three-judge panel began peppering him to substantiate his claims of standing and harm, Klayman was unable to make a cogent argument. He accused the government of consistently lying and of getting “into people’s underwear.”
Luckily Cindy Cohn was there as a friend of the court from EFF and was able to respond to the judge's questions and explain to the court how
the crucial issue of how the information being collected by the NSA differs from the information being collected in the 1979 case of  Smith v. Maryland, Cohn provided the key answer that Klayman was incapable of summoning: Its size.
Smith was about one robbery suspect, whose calls were monitored for three days.  “This is the untargeted mass collection of the phone calls of millions of people over many years,” Cohn said.
Judge David Sentelle interrupted: “Does it become an invasion because there’s lots of it? Or is a million times nothing still nothing?”
Cohn said American citizens have a reasonable expectation that the government isn’t logging all their phone calls all the time for no specific reason. “There are regular people making everyday phone calls, that are swept up in this.”
Judge Stephen Williams raised the example of drunk-driving checkpoints, where many innocent people are nevertheless subject to a traffic stop.
Cohn said there is some element of targeting in those checkpoints. “Here there’s no suspicion whatsoever,” she said. Drunk-driving checkpoints would “not be OK if they were everywhere and everybody.”
“The aggregation of all this information is like nothing we’ve seen before,” noted Judge Janice Rogers Brown. But, she said, “it seems like the implications” of an adverse ruling could “go in many directions.”
The three judges on the panel are all Republican-appointed conservatives. But each has occasional libertarian streaks that civil-libertarians were hoping might come into play.
Whatever the panel’s ruling, it will not be final. Arguments before the full Appellate Court are considered likely; a Supreme Court argument is considered inevitable.
Matthew Aid writes that
The three appeals judges in the Washington case have generally come down on the government’s side on national security issues.
Appeals judge David Sentelle permitted the George W. Bush administration to withhold names and other details about hundreds of foreigners detained in the months after the Sept. 11, 2001, terrorist attacks. Appeals judge Stephen Williams upheld the military tribunals set up by the Bush administration to try terrorism suspects for war crimes. Janice Rogers Brown ruled that four British citizens had no right to sue Pentagon officials over accusations that the detainees were tortured and their religious rights violated while held at the U.S. detention center at Guantanamo Bay, Cuba.
Marcy Wheeler explains that
because of the incomplete reporting of a bunch of NSA beat reporters — Klayman may be improperly thrown out on standing because he is only a Verizon cell customer, not a Verizon landline customer.
Marcy explains (I think this is what she is saying) that the distinction has to do with collection of cell tower location data, and a new order from FISC that later made location collection a violation, and whether Verizon responded by destroying records or just no longer handing them over.

It is certainly possible that Verizon stopped providing cell data once it ended its TCAU contact in 2009. If that’s the case, the government’s hasty destruction of call records in March would probably have eliminated the last of the data it had on Klayman (though not on ACLU, since ACLU is a landline customer as well as a wireless customer).
But if Verizon just stopped handing over cell records in 2013 after Claire Eagan made it impossible for the government to force Verizon to comply with such orders, then Klayman — and everyone else whose records transited Verizon’s backbone — should still have standing.
Marcy also writes here about the judges hearing Klayman and the Mosaic theory of the Fourth Amendment, where
an aggregation of non-searches and subsequent analysis of the collected data at some point becomes a Fourth Amendment search.

There's also another lawyer contesting the NSA dragnet, challenging not just the PATRIOT Act Section 215 and the FISA Amendment Act section 702, but also Executive Order 12333. Elliot Schuchardt's case was also dismissed due to lack of standing like Klayman's PRISM lawsuit (Klayman II), but he is already preparing 
his response to the government’s motion to dismiss. "I'm making an allegation that no one else is making: I'm contending that the government is collecting full content of e-mail," he said. "I'm contending that they're not doing it by PRISM but via 12333. I'm not saying that this is being done on a case by case basis but that they're grabbing it all.
I don't think Schuchardt would be as bad in court as Klayman was arguing his case.
In a declaration submitted to the court on Monday, Major General Gregg C. Potter, the military deputy director for signals intelligence at the NSA, he noted that "although there has been speculation that the NSA, under the bulk telephony metadata program, acquires metadata relating to all telephone calls to, from, or within the United States, that is not the case."

This caught Schuchardt’s attention: "They're not collecting all metadata, but they didn't deny that they're collecting all content, and they can't because they would lying."
Even if the case is heard, much of the surveillance is done outside of the court's jurisdiction
John Tye, a former State Department official, who has spoken publicly in recent months many times (including with Ars) about the dangers of Executive Order 12333, lauded Schuchardt's case.

"There should be more lawsuits like this. However, such lawsuits face an uphill battle, not on the facts but in getting a court to rule on the merits of the claim," he said by e-mail.
"Most Americans don't realize this, but there is ongoing illegal government activity that it is in effect impossible to stop through a lawsuit. The judicial branch has created a variety of procedural legal doctrines—like standing and state secrets—that make it very difficult for a plaintiff with even a legitimate complaint to have his or her case heard. Most likely this case will be thrown out on the basis of a procedural objection, before the court makes any ruling on whether NSA collection on US persons under 12333 is legal or not. And by deciding not to rule on the merits, the court will thereby permit illegal collection on US persons to continue."
This case was about Verizon metadata, but Klayman filed two lawsuits, one contesting Verizon metadata collection under Section 215 of the PATRIOT Act (Klayman I or Klayman v Obama et al) and one contesting PRISM collection under FISA Amendement Act Section 702 (Klayman II or Klayman et al v Obama et al).  Klayman's PRISM lawsuit was dismissed because of standing, since it was argued that he couldn't prove his online communications were being monitored.

The NSA lawsuits were last in the news in December 2013 when metadata collection was ruled unconstitutional by one judge and constitutional by another, the ACLU's lawsuit was dismissed (the dismissal was appealed) and the Supreme Court declined to hear a case (for various reasons), and in yet another case (before Snowden's revelations) the Supreme Court argued that the plaintiffs couldn't prove they were spied on.

Despite these legal setbacks, hope still appears to come from the courts as Congress is slowly debating several bills and
despite a promise from President Obama and efforts in Congress to rein in the NSA, few reforms have been enacted, even despite findings by a presidential review board and the government's independent privacy watchdog that concluded that bulk phone surveillance was illegal and yields little to no national security benefit.
In response to inaction elsewhere, anti-surveillance activists believe the courts may ultimately provide the best way forward to reforming the government's surveillance state.
continued
In September, the Court of Appeals for the 2nd Circuit heard another suit, ACLU v. Clapper,challenging the NSA's phone spying on similar constitutional grounds. Unlike Klayman's suit, the lower court in that case defended NSA spying as a necessary and effective response to terrorist threats such as al-Qaida.
A third case challenging the program, Smith v. Obama, is set to undergo review in December by the Court of Appeals for the 9th Circuit. The San Francisco-based court is commonly regarded as one of the most left-leaning and sympathetic to the concerns of the tech industry. That court also recently reviewed whether the FBI can compel companies to hand over communications data or financial records of users for national-security investigations in conjunction with a gag order.
The flurry of judicial action suddenly lurching forward contrasts with slow-burning efforts in Congress to curtail NSA spying, where negotiations have repeatedly been slowed despite efforts by members in both chambers to pass a bill this year. President Obama in January pledged to reform the government's surveillance programs, but said he had to wait until lawmakers put a suitable bill on his desk to do so.
continued
any action in Congress could dictate how courts ultimately go forward with their reviews of NSA spying. A sudden dismantling of the Patriot Act, or a significant change, could render judicial reviews essentially moot, according to legal observers.
"It's a very likely scenario that the Supreme Court will review this," said Patrick Toomey, a lawyer with the American Civil Liberties Union. "But it depends on what Congress does."
The Electronic Frontier Foundation, representing itself and the ACLU, will also argue before the court Tuesday on behalf of Klayman. Additionally, the Center for National Securities Studies will present an argument challenging the government's statutory interpretation of the Patriot Act.
A decision by the D.C. Appeals Court is not expected until at least early next year.
Whether the Supreme Court will take the case depends on who you ask
Depending on the judges, [Harvard Law professor Mark] Tushnet says his gut prediction is the court will say maintaining the database is constitutionally permissible. He expects the case would be reviewed by the Supreme Court of the United States if the government loses, but not if they win on appeal and the program remains. As for digital privacy rights, Tushnet says the Supreme Court hasn’t said very much about their existence, but it’s assumed there is an argument for digital privacy in the Constitution. “Exactly where would be controversial,” he says.

Journalists and commentators have come down on both sides with their crystal balls. Benjamin Wittes, editor in chief of the blog Lawfare and senior fellow in governance studies at the Brookings Institution, predicts that should the case get to the top court, he “can’t count five votes” that could bear “responsibility for the next bad thing that might happen” and shut down a major intelligence program.

Writing in Slate, Emily Bazelon sees things differently. “If Judge Leon didn’t buy the government’s argument about why it needs to collect and keep all this metadata, other judges—and many of the rest of us—may see it the same way.”

Dan Froomkin writes
The three judges on the panel are all Republican-appointed conservatives. But each has occasional libertarian streaks that civil-libertarians were hoping might come into play.
Whatever the panel’s ruling, it will not be final. Arguments before the full Appellate Court are considered likely; a Supreme Court argument is considered inevitable.

Government spying on lawyers

On Tuesday the DC Circuit Court of Appeals heard arguments in Klayman v Obama, filed the day after the first Snowden revelation last year of NSA spying on phone call metadata.  Because I had not been following the case too closely, I thought that the case was filed only because as customers of Verizon, Klayman had standing because as a Verizon customer he was the target of dragnet surveillance without reasonable suspicion, which is against the Fourth Amendment.  But on Tuesday while listening to the oral arguments I learned something new about the case.  The case was not just about Klayman's personal calls as a Verizon customer, but spying related to a specific case he represented as a lawyer.  That case is about the death of Michael Strange (h/t emptywheel), a solider with SEAL Team VI killed in the helicopter shoot-down right after the killing of Osama bin Laden.

I have another post about the Klayman case, but I bring it up because I learned about the attorney-client privilege aspects of it on Tuesday.

Today I learned about this.

Secretive court to consider Government spying on lawyers’ communications
A court which usually sits in secret will tomorrow (Thursday) consider whether the Government should be forced to release more information regarding its surveillance of legally privileged communications between lawyers and their clients.
In a rare public hearing, the Investigatory Powers Tribunal (IPT) – which is responsible for oversight of the intelligence services – will hear further argument in a complaint brought by two families who were subjected to ‘rendition’ and torture in a joint MI6-CIA-Libyan operation.
The al Saadi and Belhadj families are concerned that the Government may have given itself an unfair advantage in a separate, High Court case concerning their mistreatment, by listening in to communications with their legal teams at charity Reprieve and solicitors Leigh Day.  Legal privilege – which protects confidential communications between lawyer and client – is a central principle in British law which helps ensure the right to a fair trial.


Then there was this on Twitter today about other recent cases of government spying on attorneys and their clients.



Not only do we need to stop NSA dragnet spying on Americans, but we need to protect attorney-client privilege.

**Update December 17, 2014

Looking up an unrelated matter I found these articles on NSA surveillance and attorney-client privilege.

ABA Journal, September 1, 2014 link

NSA response, mentioned in above ABA article link

Jurist article, August 15, 2014 link

ACLU June, 21, 2013 bullet point #6 link

EFF February 22, 2014 link

July 2, 2014 CCR and lawyers for Guantanamo Bay detainees respond to PCLOB report link



Tuesday, November 4, 2014

Facebook's Hidden Onion Service helps protect users' privacy a little more

Facebook has long been criticized for its privacy concerns, but recently made a good move, creating a "Hidden Service" web address for the Tor browser.  You can download the Tor Browser Bundle here, and see video here (you can but don't have to put Tor on a USB).

Once you open Tor and check Tor at https://check.torproject.org/ go to https://facebookcorewwwi.onion/ to access Facebook's Hidden Service

Read Facebook's statement here on recent security implementations, including 

HTTPS across our service, and Perfect Forward Secrecy, HSTS, and other technologies

Here's what this does and doesn't do.

Tor wrote their own response after Tor users and journalists asked Tor for their thoughts.
Part one: yes, visiting Facebook over Tor is not a contradiction
I didn't even realize I should include this section, until I heard from a journalist today who hoped to get a quote from me about why Tor users wouldn't ever use Facebook. Putting aside the (still very important) questions of Facebook's privacy habits, their harmful real-name policies, and whether you should or shouldn't tell them anything about you, the key point here is that anonymity isn't just about hiding from your destination.
There's no reason to let your ISP know when or whether you're visiting Facebook. There's no reason for Facebook's upstream ISP, or some agency that surveils the Internet, to learn when and whether you use Facebook. And if you do choose to tell Facebook something about you, there's still no reason to let them automatically discover what city you're in today while you do it.
Also, we should remember that there are some places in the world that can't reach Facebook.

The Committee to Protect Journalists applauded the move too, citing how social media has become an important tool for journalism, and can now be accessed over Tor in countries that censor the internet and block access to social media sites
The Committee to Protect Journalists welcomes Facebook's move to enable access via a Tor hidden service, which came into effect on Friday. The step protects journalists and other users who are at risk of surveillance, censorship, or online attack.
continued
The dedicated hidden service makes it much easier for a journalist using Tor to access Facebook, while making it extremely difficult for attackers to monitor their activities or location or to intercept or block their connections to Facebook. This is a substantial improvement in both safety and usability for journalists who use Facebook to disseminate news, connect with sources, and communicate with colleagues. It also means that journalists using Tor to protect their privacy and that of their sources when connecting to Facebook no longer have to worry about triggering Facebook security alerts which can temporarily lock out users from their accounts. 
but then continued to acknowledge that
The move does not prevent Facebook from monitoring the activities of its users as they navigate the site, but unlike normal browsing, access via Tor does not automatically convey to Facebook a user's physical location.
Facebook's move now hopefully puts pressure on other social media networks to do more to protect users






Many have also called for encryption for so called "private" communications that really aren't private.
From 2011

From 2013


And from 2014


WIRED writes
Over the past few years, sites like Google, Facebook, and Twitter have all implemented default SSL encryption to protect users’ traffic. Sandvik sees Facebook’s Tor hidden service as a sign that Tor may be the next basic privacy protection Silicon Valley companies will be expected to offer their users.

Let's hope so.

**Update 11/5 As with any new product, especially in cyber-security, there are always new developments to keep track of as more people try things out and find problems






Thursday, October 2, 2014

About the iPhone Encryption

There have been lots of news stories about the iPhone 6 encryption, and lots of headlines claiming that it "locks out the NSA." It doesn't.

First, the bad journalism.

Signaling Post-Snowden Era, New iPhone Locks Out N.S.A.
Devoted customers of Apple products these days worry about whether the new iPhone 6 will bend in their jean pockets. The National Security Agency and the nation’s law enforcement agencies have a different concern: that the smartphone is the first of a post-Snowden generation of equipment that will disrupt their investigative abilities.
The phone encrypts emails, photos and contacts based on a complex mathematical algorithm that uses a code created by, and unique to, the phone’s user — and that Apple says it will not possess.
The result, the company is essentially saying, is that if Apple is sent a court order demanding that the contents of an iPhone 6 be provided to intelligence agencies or law enforcement, it will turn over gibberish, along with a note saying that to decode the phone’s emails, contacts and photos, investigators will have to break the code or get the code from the phone’s owner.
of course this is how the article ends instead of begins
Mr. Zdziarski said that concerns about Apple’s new encryption to hinder law enforcement seemed overblown. He said there were still plenty of ways for the police to get customer data for investigations. In the example of a kidnapping victim, the police can still request information on call records and geolocation information from phone carriers like AT&T and Verizon Wireless.
“Eliminating the iPhone as one source I don’t think is going to wreck a lot of cases,” he said. “There is such a mountain of other evidence from call logs, email logs, iCloud, Gmail logs. They’re tapping the whole Internet.”

Now some explanation.

The iPhone will automatically encrypt data stored on the device.
On devices running iOS 8, your personal data such as photos, messages (including attachments), email, contacts, call history, iTunes content, notes, and reminders is placed under the protection of your passcode.
Now Apple has said that they cannot decrypt data, even when asked by law enforcement or a court, but is not the end of the story.  Depending on the case the courts can force you to unlock it yourself. (See for example this court order)
In many cases, the American judicial system doesn’t view an encrypted phone as an insurmountable privacy protection for those accused of a crime. Instead, it’s seen as an obstruction of the evidence-gathering process, and a stubborn defendant or witness can be held in contempt of court and jailed for failing to unlock a phone to provide that evidence.
continued
In some cases, the Fifth Amendment’s protection against self-incrimination may block such demands
continued
but the few cases where suspects have pleaded the Fifth to avoid decrypting a PC—the legal equivalent of a smartphone—have had messy, sometimes contradictory outcomes.
 In some cases you can plead the Fifth 
The court ruled that forcing him to surrender his password and decryption keys would be the same as making him provide self-incriminating testimony, and let him off the hook.
But in other cases 
He refused, pleading the Fifth. A judge ruled against him, calling the contents of the computer a “foregone conclusion.” The police didn’t need Boucher’s “testimony” to get the files, in other words—they only needed him to stop obstructing access to them. 
In some situations other evidence can be considered
enough to nullify her Fifth amendment argument. As with Boucher, the judge ruled that she give police access to the files or be held in contempt.
NIST Encryption Standards

A really important, overlooked part seems to be NIST's weakened encryption standards. (Many thanks to Rayne)

**Update (November 21, 2014 EFF Joins calls for NIST reform) 


A reality check on encryption standards based on NIST
Let’s reset all the hype:
There is no smartphone security available on the market we can trust absolutely to keep out the National Security Agency. No password or biometric security can assure the encryption contained in today’s smartphones as long as they are built on current National Institute of Standards and Technology (NIST) standards and/or the Trusted Computing Platform. The NSA has compromised these standards and TCP in several ways, weakening their effectiveness and ultimately allowing a backdoor through them for NSA use, bypassing any superficial security system.
There is nothing keeping the NSA from sharing whatever information they are gleaning from smartphones with other government agencies. Citizens may believe that information gleaned by the NSA ostensibly for counterterrorism may not be legally shared with other government agencies, but legality/illegality of such sharing does not mean it hasn’t and isn’t done. (Remember fusion centers, where government agencies were supposed to be able to share antiterrorism information? Perhaps these are merely window dressing on much broader sharing.)
There is no exception across the best known mobile operating systems to the vulnerability of smartphones to NSA’s domestic spying.
More on NIST from Rayne

On NSA’s Subversion of NIST’s Algorithm

Our security is only as good as the tools we use to protect it, and compromising a widely used cryptography algorithm makes many Internet communications insecure.
continued
Improving the security of cryptographic standards is an issue where the equities overwhelmingly lie on one side of the equation. By increasing the funding for—and thus capabilities in—NIST’s Computer Security Division, Congress can help restore confidence in NIST’s cryptographic standards efforts. This is a win for all.

The NSA, NIST and the AMS

Among the many disturbing aspects of the behavior of the NSA revealed by the Snowden documents, the most controversial one directly relevant to mathematicians was the story of the NSA’s involvement in a flawed NIST cryptography standard.
continued
this is a clearly identifiable case where mathematicians seem to have been involved in using their expertise to subvert the group tasked with producing high quality cryptography.
Matt Green on NIST
In this post I'm going to try to explain the curious story of Dual-EC. While I'll do my best to keep this discussion at a high and non-mathematical level, be forewarned that I'm probably going to fail at least at a couple of points. I you're not the mood for all that, here's a short summary:
  • In 2005-2006 NIST and NSA released a pseudorandom number generator based on elliptic curve cryptography. They released this standard -- with very little explanation -- both in the US and abroad. 
  • This RNG has some serious issues with just being a good RNG. The presence of such obvious bugs was mysterious to cryptographers.
  • In 2007 a pair of Microsoft researchers pointed out that these vulnerabilities combined to produce a perfect storm, which -- together with some knowledge that only NIST/NSA might have -- opened a perfect backdoor into the random number generator itself.
  • This backdoor may allow the NSA to break nearly any cryptographic system that uses it. 

While encrypting data stored on the device is great, this is different from encrypting data like phone calls and internet activity.  Thankfully a new app called Signal from hacker security researcher Moxie Marlinspike is now available for iPhone (it's been on Android for four years already).
If you’re making a phone call with your iPhone, you used to have two options: Accept the notion that any wiretapper, hacker or spook can listen in on your conversations, or pay for pricey voice encryption software.
continued
Like any new and relatively untested crypto app, users shouldn’t entirely trust Signal’s security until other researchers have had a chance to examine it. Marlinspike admits “there are always unknowns,” such as vulnerabilities in the software of the iPhone that could allow snooping. But in terms of preventing an eavesdropper on the phone’s network from intercepting calls, Signal’s security protections are “probably pretty great,” he says.
After all, the technology behind Signal isn’t exactly new. Marlinspike first took on the problem of smartphone voice encryption four years ago with Redphone, an Android app designed to foil all wiretaps.
Another interesting question I have is what if any effect June's Supreme Court decision in Riley v California will have on iPhone, but I assume for now that the answer is the same--5th Amendment depends on the situation.  I will try to get some more answers.  For now see below.

NYT Major Ruling Shields Privacy of Cellphones: Supreme Court Says Phones Can’t Be Searched Without a Warrant
“Cellphones have become important tools in facilitating coordination and communication among members of criminal enterprises, and can provide valuable incriminating information about dangerous criminals,” he wrote. “Privacy comes at a cost.”
But other technologies, he said, can make it easier for the police to obtain warrants. Using email and iPads, the chief justice wrote, officers can sometimes have a warrant in hand in 15 minutes.
continued
What must the police do when they want to search a cellphone in connection with an arrest?
“Get a warrant,” Chief Justice Roberts wrote. 
Marcy Wheeler explains that
In real life, it’s likely that cops will integrate cellphone search warrants into their arrest warrant process. And Roberts’ opinion allows police to invoke exigent circumstances to search a phone. But at a minimum, this ruling will prohibit suspicion-less searches of cellphones.
continued
A different part of Sotomayor’s concurrence, arguing that the existing precedent holding that you don’t have a privacy interest in data you’ve given to a third party “is ill suited to the digital age,” has been invoked repeatedly in privacy debates since she wrote it. That’s especially true since the beginning of Edward Snowden’s leaks. Lawsuits against the phone dragnet often cite that passage, arguing that the phone dragnet is precisely the kind of intrusion that far exceeds the intent of old precedent. And the courts have – with the exception of one decision finding the phone dragnet unconstitutional – ruled that until a majority on the Supreme Court endorses this notion, the old precedents hold.
continued
Roberts cited from a different part of Sotomayor’s opinion, discussing how much GPS data on our movements reveals about our personal lives. That appears amid a discussion in which he cites things that make cellphones different: the multiple functions they serve, the different kinds of data we store in the same place, our Web search terms, location and apps that might betray political affiliation, health data or religion. That is, in an opinion joined by all his colleagues, the chief justice repeats Sotomayor’s argument that the sheer volume of this information makes it different.
That by no means says that those challenging the government’s national security surveillance will prevail by pointing to this opinion. Roberts includes an incredibly pregnant footnote, clarifying that “these cases do not implicate the question whether the collection or inspection of aggregated digital information amounts to a search under other circumstances.” Without naming the third-party doctrine explicitly, with his invocation of “search” Roberts makes it clear that’s what he’s discussing.
Here Marcy says Roberts kept it vague on purpose.

So for now, these cases about data on a smartphone or GPS collection are not being used to end NSA collection, which is still being reauthorized every 90 days.

The bill currently getting all the attention to reform the NSA is Senator Leahy's USA Freedom Act, but as Marcy has well documented, the proposed reforms are actually making some problems worse.
The ACLU and EFF normally do great work defending the Fourth Amendment. Both have fought the government’s expansive spying for years. Both have fought hard to require the government obtain a warrant before accessing your computer, cell phone, and location data.
continued
by outsourcing to telecoms, NSA will actually increase the total percentage of Americans’ telephone records that get chained on; sources say it will be more “comprehensive” than the current dragnet and Deputy NSA Director Richard Ledgett agrees the “the actual universe of potential calls that could be queried against is [potentially] dramatically larger.” In addition, the telecoms are unlikely to be able to remove all the noisy numbers like pizza joints — as NSA currently claims to – meaning more people with completely accidental phone ties to suspects will get sucked in. And USA Freedom adopts a standard for data retention — foreign intelligence purpose — that has proven meaningless in the past
But earlier this week, they may have taken action that directly undermines that good work.

So data on the iPhone is now automatically encrypted, but that won't stop police from issuing warrants or courts forcing you to unlock the data yourself.  Phone calls can now be encrypted for free using the Signal app.  All of these are great improvements, but it is still not the end of the story.

Many security experts have focused on iCloud storage.  Micah Lee writes at The Intercept that
despite these nods to privacy-conscious consumers, Apple still strongly encourages all its users to sign up for and use iCloud, the internet syncing and storage service where Apple has the capability to unlock key data like backups, documents, contacts, and calendar information in response to a government demand. iCloud is also used to sync photos, as a slew of celebrities learned in recent weeks when hackers reaped nude photos from the Apple service. (Celebrity iCloud accounts were compromised when hackers answered security questions correctly or tricked victims into giving up their credentials via “phishing” links, Cook has said.)
 continued
The most prominent privacy improvement Apple made to its products last week is a new encryption feature built-in to iOS 8.
Since the iPhone 3GS, all iOS devices have supported encrypting personal data such as text messages, photos, emails, contacts, and call history. If you set a passcode it would be used to encrypt some, but not all, of the data on your device. Apple was still able to decrypt some of the data without knowing your passcode.
If law enforcement confiscated your phone and wanted to snoop at its data, all they would have to do is serve Apple a warrant and to get a copy of the plaintext data.
continued
The improved encryption in iOS 8 is a great move towards protecting consumer privacy and security. But users should be aware that in most cases it doesn’t protect your iOS device from government snoops.
While Apple does not have the crypto keys that can unlock the data on iOS 8 devices, they do have access to your iCloud backup data.
this is not the first time 
This isn’t the first time that Apple has oversold the security of its products. Shortly after the PRISM revelations were published in The Washington Postand The Guardian, Apple denied that it was part of the program and issued a statement claiming that “conversations which take place over iMessage and FaceTime are protected by end-to-end encryption so no one but the sender and receiver can see or read them. Apple cannot decrypt that data.” But security researchers showed that Apple could indeed eavesdrop on iMessage conversations without the user knowing.
ArsTechnica notes that
Apple executives never mentioned the words "iCloud security" during the unveiling of the iPhone 6
continued
In the name of security, we did a little testing using family members as guinea pigs. To demonstrate just how much private information on an iPhone can be currently pulled from iCloud and other sources, we enlisted the help of a pair of software tools from Elcomsoft. These tools are essentially professional-level, forensic software used by law enforcement and other organizations to collect data. But to show that an attacker wouldn’t necessarily need that to gain access to phone data, we also used a pair of simpler “hacks,” attacking a family member’s account (again, with permission) by using only an iPhone and iTunes running on a Windows machine.
As things stand right now, a determined attacker will still find plenty of ways to get to iPhone data. They need to gain physical access to the device, or harvest or crack credentials to do so. But there are ways to do this that won't alert the victim. The weakest links are components of the iCloud service.
passwords are essential but not impossible
We also went after a password-encrypted version of the backup on a local drive using EPPB’s dictionary and brute-force password attacks, cracking the seven-letter password after about two days
continued
since the iCloud backup is only protected by the iCloud password right now, once someone has obtained that password, everything in that backup is wide open.
And there’s a lot in that backup.
There are a number of things some people might be surprised to find in the iCloud backups. Among the data found were:
  • SQLite databases containing phone call history, SMS and iMessage messages, and voicemail message data (with the number they were from and timestamps for when they were trashed) dating back to the phone's original purchase. So much for deleting call history.
  • A file called “recents” that contained e-mail, Messenger, and SMS addresses with message header data and other information.
  • An “accounts” database with all the e-mail, Twitter, and Apple-associated identity accounts we've ever held. Some details synced over from accounts closed before the target phone was purchased.
  • A file with all “known” Wi-Fi hotspots, with the SSIDs and MAC addresses of every hotspot the phone ever connected to.
  • Images, many believed to be long deleted, in three separate photo folders on each backup. All of the images carried the default EXIF data that Apple’s camera app attaches to them: dates taken, GPS latitude, longitude, and altitude. These images, in our oldest iCloud backup, were part of a much older incremental backup that had not been cleared from the cloud, and were found in a duplicate image folder within the DCIM folder of the backup image.
  • A file containing Apple Maps addresses searched for.
  • Mailbox files for the e-mail accounts used with Apple’s Mail app.
  • An address book database with over 1,000 e-mail addresses, phone numbers, Facebook profile links, and other contact data.
That is just what we found sifting around for a few hours aimlessly. It’s clear that anyone targeted by an iCloud account hack hasn’t just had pictures exposed; their entire digital lives have been laid out on display.
and real-time tracking via "Find my iPhone"
Even creepier, the iCloud access also gives the attacker the ability to stalk the victim in real-time by using the Find My iPhone feature. If the phone is turned on and Find My iPhone was configured, the attacker can use the feature just as the owner would (of course, odds are that it’s on the owner’s person). We were able to identify the location of family members in this way as soon as the target phone was turned on. None of this is particularly high-tech. And it’s well within the threshold of pain for a mildly technically literate, very obsessed attacker.
continued
Apple could go a long way toward protecting customer privacy just by adding a second credential to encrypt stored iCloud data. An encryption password could be used to decrypt the backup when downloaded to iTunes or to the device, or it could be used to decrypt the data as it is read by iCloud to stream down to the device. That would at least give backups the same level of protection that they get when stored locally with encryption (already an option in iTunes).
this still won't stop NSA or police
These measures will not mean that the police, the FBI, or the NSA couldn’t get to your iPhone data if they had a need to. The fixes won't stop a determined attacker from finding other ways to compromise a user’s devices to gain access to information. But these tweaks raise the level of effort required enough to deter casual attacks, and they will hopefully raise people’s awareness to attacks in progress early enough to react.
Mashable has a good selection of security researches showing how police can still get your data, then there is a list of reasons not to trust Apple,

For the NSA, Four-hundred-thousand apps means 400,000 possibilities for attacks.  Apps can be used to spy on what users do elsewhere on the phone.  The NSA can replay phone calls, and is as I noted earlier still collecting phone metadata every 90 days.
all call detail records or "telephony metadata" created by Verizon for communications (i) between the United States and abroad; or (ii) wholly within the United States, including local telephone calls. This Order does not require Verizon to produce telephony metadata for communications wholly originating and terminating in foreign countries. Telephony metadata includes comprehensive communications routing information, including but not limited to session identifying information (e.g., originating and
terminating telephone number, International Mobile Subscriber Identity (IMSI) number, International Mobile station Equipment Identity (IMEI) number, etc.), trunk identifier, telephone calling card numbers, and time and duration of call.