/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

How the NSA's XKEYSCORE system for collecting and searching Internet data works

A Look at the Inner Workings of NSA's XKEYSCORE  —  Second in a series.  Part 1 here.  —  The sheer quantity of communications that XKEYSCORE processes, filters and queries is stunning.

The Intercept

Context & Ripple Effects

This explainer is the second half of a two-part disclosure: the day before, new documents showed XKEYSCORE collecting more than previously reported, including web searches and router configuration data alongside raw communications traffic. Together they move the Snowden-era record from 'the NSA has a tool' to 'here is how the tool actually works' — filters, queries, and the sheer volume it processes.

The piece slots into an established arc of leaked capability documents. Earlier Snowden material showed the NSA routinely intercepting SSL/TLS traffic and decrypted VPN connections while struggling against PGP, Tor, and other resistant tools, and later reporting traced the same trove toward Big Awesome Graph, an effort to map people's social networks out of intercepted communications.

First-order effects

  • The NSA's own documentation is now public in operational detail: adversaries can read exactly what metadata and content types XKEYSCORE captures, including web searches and router configurations, and harden their traffic accordingly.
  • Users whose traffic transits tapped backbone points are affected immediately, since the system's disclosed scope covers far more than targeted selectors.

Second-order effects

  • Allied agencies become both customers and suppliers in this architecture: Germany's BfV received XKeyscore software from the NSA in exchange for German surveillance data, so each disclosure pressures foreign governments to defend or disavow the arrangement.
  • Demand shifts toward the tools the leaks show resisting interception — the earlier Spiegel documents flagged PGP, Truecrypt, Tor, OTR, and ZRTP as pain points, making adoption of such encryption the rational response for at-risk users.

Third-order effects

  • The pattern across these disclosures points to intelligence built as searchable indexes of entire populations rather than files on named targets — a structure that turns any new data type (social graphs via Big Awesome Graph, web searches, device configs) into another queryable layer.
  • If partner-sharing like the BfV exchange generalizes, XKEYSCORE-class systems spread beyond the US intelligence community while the disclosures themselves become the main driver of global encryption defaults.

The trend: Signals intelligence is shifting from targeted interception to search-engine-scale indexing of global communications, with leaked source documents and allied-software transfers defining its pace.