XKeyscore: Global NSA Query Interface (Revealed July 2013)
Introduction
In July 2013, the Guardian published NSA training documents provided by Edward Snowden describing a system called XKeyscore. The documents described XKeyscore as the NSA's ''widest-reaching'' signals intelligence analytic tool — a query interface that allowed NSA analysts to search across enormous repositories of collected internet content and metadata by specifying a selector such as an email address, phone number, IP address, or keyword.
XKeyscore was not itself a collection programme; it was a query and analysis layer sitting atop data collected by the NSA's various upstream and downstream collection capabilities, including taps on international fibre-optic cables and collection from internet exchange points.
What XKeyscore Does
XKeyscore operates as a distributed database and query system. Analysts enter a selector — an identifier associated with a target — and XKeyscore searches across indexed repositories of intercepted data to return matching content and metadata. The repositories hold data for rolling time windows: full content of internet sessions for up to a few days, and metadata for longer periods.
The scope of what XKeyscore indexes is extensive. NSA training slides published by the Guardian included descriptions of the system covering email content and headers, web browsing history, search queries, social media activity, online chat logs, metadata showing communication patterns, and file transfers. Analysts could use XKeyscore to track a target across multiple communications channels, reconstruct browsing activity, and identify previously unknown associates through pattern analysis.
The ''No Warrant Required'' Problem
A significant aspect of the XKeyscore disclosure was the training documents' description of the query process. Analysts could run searches on their own authority for the purpose of intelligence collection on foreign targets. While NSA policy required analysts to document their basis for queries and oversight systems were described as monitoring for abuse, the system allowed real-time access to collected content without requiring the analyst to obtain a court order for each individual search.
This was the feature Glenn Greenwald emphasised in the original Guardian reporting and that Snowden referenced in interviews: an analyst could, in his description, ''sit at a terminal and listen to anyone.'' The NSA disputed characterisations of XKeyscore as permitting unconstrained domestic surveillance, arguing that legal authorities and technical controls limited collection to foreign targets. Subsequent reporting and legal analysis suggested the technical controls were imperfect and that US person communications were captured incidentally.
Global Reach
Training documents indicated that XKeyscore drew on collection from over 150 field sites worldwide. The system was described as covering ''nearly everything a typical user does on the internet.'' Partner intelligence agencies in the Five Eyes alliance — Australia, Canada, New Zealand, and the UK — had access to XKeyscore under bilateral intelligence-sharing arrangements.
Confirmation and Official Response
The NSA confirmed XKeyscore's existence in a statement responding to the Guardian's story, describing it as a tool used for ''valid foreign intelligence purposes'' subject to ''extensive oversight.'' The Office of the Director of National Intelligence subsequently declassified additional information about the programme in 2013 and 2014 in response to public and congressional pressure following the Snowden disclosures.
Multiple independent security researchers and legal analysts have analysed the published XKeyscore slides and assessed them as credible and consistent with known NSA technical architecture.
Verdict
Confirmed. XKeyscore's existence is confirmed by NSA training documents published by the Guardian in July 2013, the NSA's own public acknowledgement, and subsequent government declassifications. The system gives NSA analysts query access to billions of intercepted records across global collection sites, covering email, web browsing, search queries, and chat, with analyst-initiated searches not requiring individual court orders.
Beyond the NSA: Who Else Had a Login
The 2013 disclosures described XKeyscore as an NSA system, but later reporting on the same Snowden document set showed the tool's reach extended well past the NSA itself. Under Five Eyes intelligence-sharing arrangements, New Zealand's Government Communications Security Bureau (GCSB) operated its own XKeyscore access, and 2016 reporting drawing on documents reviewed by Der Spiegel found that Germany's foreign intelligence service (the BND) and its domestic counterpart (the BfV) had used XKeyscore since 2007 — years before the Guardian's story made the tool's name public. NSA material described the German services as "key partners" in the relationship. None of this changes what XKeyscore is; it does mean that assessing the programme purely as a question of US domestic law misses that several allied governments had their own terminals into comparable data.
Scope Creep: Not Every Query Was About Terrorism
XKeyscore's official justification, in both the original NSA training slides and the agency's public statements, is counterterrorism and foreign-intelligence collection. Reporting in 2015 by The Intercept and New Zealand's Herald newspapers, based on separate leaked GCSB documents, showed the tool used for purposes that sit uneasily with that framing. One document showed the GCSB building XKeyscore "fingerprints" — targeted keyword combinations — to intercept communications about rival candidates during the 2013 race to become director-general of the World Trade Organization, a contest in which New Zealand's own trade minister, Tim Groser, was a candidate. One fingerprint specifically flagged Indonesia's candidate, Mari Elka Pangestu, as a "particular concern." A second document, dated January 2013, showed XKeyscore configured to intercept messages naming several Solomon Islands government officials and Benjamin Afuga, an anti-corruption campaigner who ran a group publishing government leaks — none of them associated with terrorism in the reporting. The GCSB's acting director, asked about the Solomon Islands surveillance, said "everything we do is explicitly authorised and subject to independent oversight," which may be true as a matter of New Zealand law while still illustrating how a tool sold publicly as a counterterrorism system in practice supported ordinary diplomatic and political intelligence work by a partner agency.
What the NSA Says in Its Own Defense
The NSA's formal response to the Guardian's 2013 story is itself part of the public record and deserves to be represented directly rather than paraphrased. The agency said: "XKeyscore is used as a part of NSA's lawful foreign signals intelligence collection system," and that "allegations of widespread, unchecked analyst access to NSA collection data are simply not true." It added that access is "limited to only those personnel who require access for their assigned tasks," that there are "multiple technical, manual and supervisory checks and balances within the system to prevent deliberate misuse," and that "every search by an NSA analyst is fully auditable, to ensure that they are proper and within the law." This is the NSA's own characterization, not an independent finding, but it is the agency's considered position and the correct baseline against which to weigh the leaked material: the dispute is not over whether XKeyscore exists or what it can technically do — both sides agree on that — but over how tightly the described legal and technical controls actually constrain its use in practice.
That dispute has some genuine texture to it. The 2015 Intercept document release included NSA training material describing system administrators as sharing a single "oper" login and, according to the reporting, having a path to query the underlying databases directly in a way that would not necessarily appear in the query-level logs that record an individual analyst's searches. That detail complicates the "fully auditable" claim, though it addresses a different population (system administrators) than the one the NSA's statement was defending (analysts running searches), so the two claims are not flatly contradictory — they describe two different layers of the same system, one of which appears to have had a documented gap.
The Oversight Board Finally Weighs In
For years after 2013, no US oversight body had publicly examined XKeyscore in detail. That changed when the Privacy and Civil Liberties Oversight Board (PCLOB), an independent federal watchdog agency, disclosed that it had conducted a classified "deep dive" review of NSA's use of XKeyscore for counterterrorism purposes under Executive Order 12333, completing a classified report in December 2020. The PCLOB requested declassification in 2021, and after a lengthy intelligence-community redaction process, released a heavily redacted unclassified version in February 2024 as the Report on Certain NSA Uses of XKEYSCORE for Counterterrorism Purposes.
The report's seven Board-level recommendations are themselves informative about the state of internal oversight as of 2020. They included that NSA "conduct and periodically review and update a legal analysis of XKEYSCORE" — implying no such regularly updated analysis existed at the time — and that NSA "notify the Board of changes to XKEYSCORE that could materially affect the privacy or civil liberties of U.S. persons," a notification requirement that, again, had apparently not been in place. The Board also recommended that NSA periodically report the number and nature of XKeyscore queries resulting in significant compliance findings involving US persons, which implies such findings occur with enough regularity to be worth systematically tracking. Two Board members, Edward Felten and Travis LeBlanc, filed additional recommendations going further, including that XKeyscore analysts be required to tag or otherwise flag known or believed US-person data and that NSA "affirmatively deprioritize" such data within the system. LeBlanc separately and publicly argued, after the redacted report's release, that the redactions obscured the seriousness of what the review had actually found — a dispute among the Board's own members about how alarming the underlying (still-classified) material is.
What the report does not do, at least in its public form, is find that XKeyscore had been used unlawfully against domestic targets outside its authorized foreign-intelligence mission; its scope was a review of process and compliance around an authorized counterterrorism tool, not an investigation into whether the tool's basic legal authority was being exceeded. That is a real limit on how far the report can be read as vindicating the most expansive readings of the 2013 leak, even as its recommendations show that, years after NSA's public assurances, the Board found the internal legal-review and change-notification processes underlying those assurances to be incomplete.
The "Collect It All" Debate: What "Full-Take" Actually Means
A recurring point of dispute since 2013 is what "full-take" collection implies. Some coverage of the leak treated it as evidence that the NSA stores a permanent, searchable copy of everyone's internet activity. An open-source-intelligence analysis of the 2015 New Zealand documents pushed back on that reading, describing "full-take" as a rolling buffer: unfiltered content held for roughly three to five days and metadata for around thirty days before being overwritten, with a targeted "selector" or "fingerprint" required to extract anything meaningful from the buffer rather than the system functioning as an indiscriminate, permanently retained archive. One NSA training slide quoted in that analysis describes the tool's purpose as helping analysts narrow "gigantic shrimping nets" down to "tiny goldfish-sized nets" — the agency's own metaphor for query-based filtering rather than bulk retention. That nuance matters for evaluating the collection architecture, but it does not resolve the underlying concern raised elsewhere in the documents: the same training material describes a low-friction process for defining a selector, and flagged results can be moved into longer-retention NSA databases such as Pinwale for years — so the rolling-buffer point limits, rather than eliminates, the "collect it all" characterization.
Evidence Filters21
NSA training slides published by Guardian confirm system
SupportingStrongThe Guardian published NSA training slides for XKeyscore in July 2013. The slides describe the system's architecture, query capabilities, data types, and geographic coverage across more than 150 field sites. The publication is primary-source documentary evidence.
NSA publicly acknowledged XKeyscore in response to reporting
SupportingStrongThe NSA issued a statement acknowledging XKeyscore's existence while defending its use as subject to 'extensive oversight' and limited to 'valid foreign intelligence purposes.' The public acknowledgement is itself confirmation.
Described as the 'widest-reaching' NSA SIGINT analytic tool
SupportingStrongNSA training documents characterised XKeyscore as the agency's 'widest-reaching' signals intelligence analytic system. The claim is consistent with the described global scope (150+ sites) and data types (email, web, chat, search).
Analysts could query content without per-search court orders
SupportingStrongTraining materials described analysts initiating searches on their own authority without obtaining individual court orders for each query, relying instead on the pre-existing collection authorities and internal policy controls for query justification.
ODNI subsequently declassified additional XKeyscore details
SupportingStrongThe Office of the Director of National Intelligence, responding to post-Snowden political pressure, declassified additional information about XKeyscore and related programmes in 2013 and 2014, confirming aspects of the Guardian's reporting.
NSA disputed 'listen to anyone' characterisation
DebunkingThe NSA and administration officials disputed Snowden's description that an analyst could 'sit at a terminal and listen to anyone,' arguing that legal authorities, minimisation procedures, and technical controls limited collection to foreign targets and prevented domestic abuse.
Rebuttal
The NSA's dispute concerns the scope and limits of XKeyscore use, not its existence. The system's existence and broad query capabilities are confirmed. The legal and policy constraints on its use are separately disputed and under ongoing litigation.
Five Eyes partners had access under intelligence-sharing arrangements
SupportingTraining documents indicated that partner intelligence agencies in the Five Eyes alliance — Australia, Canada, New Zealand, and the UK — had access to XKeyscore under bilateral intelligence-sharing agreements, extending the system's effective reach beyond US collection alone.
Independent security researchers assessed slides as technically credible
SupportingCryptographers and network security researchers who reviewed the published XKeyscore slides assessed them as technically credible and consistent with the described architecture for indexing and querying large-scale intercepted internet data.
Leaked 2015 Training Materials Describe a Shared Admin Login That Could Bypass Query-Level Audit Logs
SupportingStrongThe Intercept's 2015 XKeyscore document release included NSA training material indicating that system administrators used a shared "oper" account and could reportedly query the underlying MySQL databases directly, a path that would not necessarily appear in the query-level audit logs generated by an individual analyst's searches.
New Zealand's GCSB Used XKeyscore in a WTO Leadership Race, Not a Terrorism Investigation
SupportingStrongA leaked GCSB document reported by The Intercept and the New Zealand Herald in March 2015 showed New Zealand's spy agency building XKeyscore "fingerprints" to intercept communications about rival candidates - including Indonesia's Mari Elka Pangestu, flagged as a "particular concern" - during the 2013 race to lead the World Trade Organization, a contest in which New Zealand's own trade minister was a candidate.
Show 11 more evidence points
New Zealand Used XKeyscore Against an Anti-Corruption Campaigner With No Reported Terrorism Link
SupportingStrongA January 2013 GCSB document reported by The Intercept and the New Zealand Herald showed XKeyscore configured to intercept messages naming Solomon Islands anti-corruption campaigner Benjamin Afuga and several Solomon Islands government officials, none of whom the reporting connected to terrorism.
Germany's BND and BfV Also Operated XKeyscore, Starting in 2007
SupportingReporting drawing on Der Spiegel's review of Snowden documents found that Germany's foreign intelligence service (BND) and domestic intelligence service (BfV) began using XKeyscore in 2007, and that NSA material described the German services as "key partners" in intelligence sharing.
XKeyscore Is a Query Interface, Not an Independent Collection Programme
NeutralXKeyscore functions as a federated search tool across data already collected by upstream programmes (PRISM, MUSCULAR, RAMPART-A, cable taps). It does not itself collect data; it indexes and retrieves content within NSA's distributed infrastructure. Snowden's slide deck describing XKeyscore's capabilities therefore reflects the aggregate collection of multiple authorised programmes, not a standalone system with independent collection authority. This distinction matters because legal constraints, oversight mechanisms, and accountability frameworks apply to the upstream collection programmes, not to XKeyscore as a retrieval interface.
XKeyscore Is a Search Interface Dependent on Prior Collection Authority
NeutralXKeyscore is a database query and analysis tool, not itself a collection program. Its capabilities are bounded by what data underlying collection programs — PRISM, MUSCULAR, upstream collection — have already gathered under their respective legal authorities. An analyst querying XKeyscore cannot access data that hasn't been collected and indexed by these prior programs. This matters because the most alarming descriptions of XKeyscore — implying an analyst can query "everything on the internet" — conflate the search interface with the underlying collection infrastructure. The scope of accessible data depends on collection authorities, FISA-court-approved selectors, and data-retention policies, not solely on XKeyscore's query capabilities.
Training Slides Describe Using XKeyscore to Harvest Login Credentials and Cite Monitoring of a Sitting UN Secretary-General
SupportingTraining material published by The Intercept in 2015 describes XKeyscore being used to harvest usernames and passwords in support of follow-on hacking operations, and cites intelligence collected in April 2013 on UN Secretary-General Ban Ki-moon as an example of the system's use.
FISA Court-Approved Selectors Formally Constrain Analyst Queries
DebunkingNSA's minimisation procedures, reviewed annually by the FISA Court, require that queries of raw collection databases use court-approved "selectors" (identifiers like email addresses or phone numbers) tied to foreign intelligence purposes. NSA Inspector General reports (partially declassified 2013–2014) document instances of non-compliance and the resulting disciplinary processes. While these constraints are imperfect and self-reported, they demonstrate that XKeyscore access is not the unrestricted "wiretap anyone" capability that Snowden's presentation slides, read without operational context, might suggest.
Documented Minimization Procedures Constrain Casual Analyst Access
DebunkingNSA minimization procedures, partially declassified following Snowden and subsequent FOIA litigation, require analysts to document justification for queries involving US-person identifiers and prohibit "about" queries on US persons without specific legal authorization. NSA Inspector General reports document compliance violations — suggesting oversight existed and caught some violations — rather than a system with no controls. FISA Court opinions (some declassified) imposed additional restrictions on how query results involving US persons could be used. These constraints are imperfect and have been violated, but their existence limits the "any analyst can spy on anyone" characterization that XKeyscore presentations, taken out of context, can imply.
2024 Declassified PCLOB Report Found NSA Lacked a Current Legal Analysis and a Formal Change-Notification Process for XKeyscore
SupportingStrongThe Privacy and Civil Liberties Oversight Board's declassified 2020 report, released February 2024, made seven recommendations - including that NSA "conduct and periodically review and update a legal analysis of XKEYSCORE" and notify the Board of changes affecting US-person privacy - steps that had apparently not been standard practice at the time of the review.
NSA's Formal Rebuttal: Access Is Restricted to Foreign Targets and "Fully Auditable"
DebunkingResponding to the Guardian's 2013 story, the NSA said XKeyscore "is used as a part of NSA's lawful foreign signals intelligence collection system," that "allegations of widespread, unchecked analyst access to NSA collection data are simply not true," and that "every search by an NSA analyst is fully auditable, to ensure that they are proper and within the law."
Rebuttal
The Intercept's 2015 document release complicates the "fully auditable" framing: it describes a shared administrator account with a route to bypass query-level audit logs. The NSA's statement concerns analyst searches specifically, not system-administrator access, so the two claims describe different layers of the same system rather than flatly contradicting each other.
Technical Analysts Dispute the "Collect It All" Reading of "Full-Take" Collection
DebunkingAn open-source-intelligence analysis of the 2015 New Zealand XKeyscore documents argued that "full-take" collection is a rolling buffer - content held roughly three to five days and metadata roughly thirty days before being overwritten - that requires a targeted selector to extract anything, rather than a permanent bulk store of everyone's traffic; a training slide quoted in the analysis describes the goal as narrowing "gigantic shrimping nets" into "tiny goldfish-sized nets."
Rebuttal
This point concerns retention mechanics, not the ease of initiating a search: the same documents describe a low-friction process for defining a selector, and flagged data can be moved into longer-term NSA storage systems such as Pinwale for years. The rolling-buffer detail limits, but does not remove, the underlying "collect it all" concern.
PCLOB's Review Was Scoped to Counterterrorism Process Under E.O. 12333, Not a Finding of Unlawful Domestic Use
DebunkingThe PCLOB's XKEYSCORE report stemmed from a July 2014 Board decision to review counterterrorism-related intelligence activity under Executive Order 12333; its public recommendations concern strengthening legal review, training, and notification processes rather than reporting that XKeyscore had been used against domestic targets outside its authorized foreign-intelligence mission.
Rebuttal
The released report is heavily redacted, and Board Member Travis LeBlanc has publicly argued the redactions understate the seriousness of the underlying findings. The absence of a public finding of unlawful domestic use in the redacted version is not the same as a clean bill of health on the classified material.
Evidence Cited by Believers13
NSA training slides published by Guardian confirm system
SupportingStrongThe Guardian published NSA training slides for XKeyscore in July 2013. The slides describe the system's architecture, query capabilities, data types, and geographic coverage across more than 150 field sites. The publication is primary-source documentary evidence.
NSA publicly acknowledged XKeyscore in response to reporting
SupportingStrongThe NSA issued a statement acknowledging XKeyscore's existence while defending its use as subject to 'extensive oversight' and limited to 'valid foreign intelligence purposes.' The public acknowledgement is itself confirmation.
Described as the 'widest-reaching' NSA SIGINT analytic tool
SupportingStrongNSA training documents characterised XKeyscore as the agency's 'widest-reaching' signals intelligence analytic system. The claim is consistent with the described global scope (150+ sites) and data types (email, web, chat, search).
Analysts could query content without per-search court orders
SupportingStrongTraining materials described analysts initiating searches on their own authority without obtaining individual court orders for each query, relying instead on the pre-existing collection authorities and internal policy controls for query justification.
ODNI subsequently declassified additional XKeyscore details
SupportingStrongThe Office of the Director of National Intelligence, responding to post-Snowden political pressure, declassified additional information about XKeyscore and related programmes in 2013 and 2014, confirming aspects of the Guardian's reporting.
Five Eyes partners had access under intelligence-sharing arrangements
SupportingTraining documents indicated that partner intelligence agencies in the Five Eyes alliance — Australia, Canada, New Zealand, and the UK — had access to XKeyscore under bilateral intelligence-sharing agreements, extending the system's effective reach beyond US collection alone.
Independent security researchers assessed slides as technically credible
SupportingCryptographers and network security researchers who reviewed the published XKeyscore slides assessed them as technically credible and consistent with the described architecture for indexing and querying large-scale intercepted internet data.
Leaked 2015 Training Materials Describe a Shared Admin Login That Could Bypass Query-Level Audit Logs
SupportingStrongThe Intercept's 2015 XKeyscore document release included NSA training material indicating that system administrators used a shared "oper" account and could reportedly query the underlying MySQL databases directly, a path that would not necessarily appear in the query-level audit logs generated by an individual analyst's searches.
New Zealand's GCSB Used XKeyscore in a WTO Leadership Race, Not a Terrorism Investigation
SupportingStrongA leaked GCSB document reported by The Intercept and the New Zealand Herald in March 2015 showed New Zealand's spy agency building XKeyscore "fingerprints" to intercept communications about rival candidates - including Indonesia's Mari Elka Pangestu, flagged as a "particular concern" - during the 2013 race to lead the World Trade Organization, a contest in which New Zealand's own trade minister was a candidate.
New Zealand Used XKeyscore Against an Anti-Corruption Campaigner With No Reported Terrorism Link
SupportingStrongA January 2013 GCSB document reported by The Intercept and the New Zealand Herald showed XKeyscore configured to intercept messages naming Solomon Islands anti-corruption campaigner Benjamin Afuga and several Solomon Islands government officials, none of whom the reporting connected to terrorism.
Show 3 more evidence points
Germany's BND and BfV Also Operated XKeyscore, Starting in 2007
SupportingReporting drawing on Der Spiegel's review of Snowden documents found that Germany's foreign intelligence service (BND) and domestic intelligence service (BfV) began using XKeyscore in 2007, and that NSA material described the German services as "key partners" in intelligence sharing.
Training Slides Describe Using XKeyscore to Harvest Login Credentials and Cite Monitoring of a Sitting UN Secretary-General
SupportingTraining material published by The Intercept in 2015 describes XKeyscore being used to harvest usernames and passwords in support of follow-on hacking operations, and cites intelligence collected in April 2013 on UN Secretary-General Ban Ki-moon as an example of the system's use.
2024 Declassified PCLOB Report Found NSA Lacked a Current Legal Analysis and a Formal Change-Notification Process for XKeyscore
SupportingStrongThe Privacy and Civil Liberties Oversight Board's declassified 2020 report, released February 2024, made seven recommendations - including that NSA "conduct and periodically review and update a legal analysis of XKEYSCORE" and notify the Board of changes affecting US-person privacy - steps that had apparently not been standard practice at the time of the review.
Counter-Evidence6
NSA disputed 'listen to anyone' characterisation
DebunkingThe NSA and administration officials disputed Snowden's description that an analyst could 'sit at a terminal and listen to anyone,' arguing that legal authorities, minimisation procedures, and technical controls limited collection to foreign targets and prevented domestic abuse.
Rebuttal
The NSA's dispute concerns the scope and limits of XKeyscore use, not its existence. The system's existence and broad query capabilities are confirmed. The legal and policy constraints on its use are separately disputed and under ongoing litigation.
FISA Court-Approved Selectors Formally Constrain Analyst Queries
DebunkingNSA's minimisation procedures, reviewed annually by the FISA Court, require that queries of raw collection databases use court-approved "selectors" (identifiers like email addresses or phone numbers) tied to foreign intelligence purposes. NSA Inspector General reports (partially declassified 2013–2014) document instances of non-compliance and the resulting disciplinary processes. While these constraints are imperfect and self-reported, they demonstrate that XKeyscore access is not the unrestricted "wiretap anyone" capability that Snowden's presentation slides, read without operational context, might suggest.
Documented Minimization Procedures Constrain Casual Analyst Access
DebunkingNSA minimization procedures, partially declassified following Snowden and subsequent FOIA litigation, require analysts to document justification for queries involving US-person identifiers and prohibit "about" queries on US persons without specific legal authorization. NSA Inspector General reports document compliance violations — suggesting oversight existed and caught some violations — rather than a system with no controls. FISA Court opinions (some declassified) imposed additional restrictions on how query results involving US persons could be used. These constraints are imperfect and have been violated, but their existence limits the "any analyst can spy on anyone" characterization that XKeyscore presentations, taken out of context, can imply.
NSA's Formal Rebuttal: Access Is Restricted to Foreign Targets and "Fully Auditable"
DebunkingResponding to the Guardian's 2013 story, the NSA said XKeyscore "is used as a part of NSA's lawful foreign signals intelligence collection system," that "allegations of widespread, unchecked analyst access to NSA collection data are simply not true," and that "every search by an NSA analyst is fully auditable, to ensure that they are proper and within the law."
Rebuttal
The Intercept's 2015 document release complicates the "fully auditable" framing: it describes a shared administrator account with a route to bypass query-level audit logs. The NSA's statement concerns analyst searches specifically, not system-administrator access, so the two claims describe different layers of the same system rather than flatly contradicting each other.
Technical Analysts Dispute the "Collect It All" Reading of "Full-Take" Collection
DebunkingAn open-source-intelligence analysis of the 2015 New Zealand XKeyscore documents argued that "full-take" collection is a rolling buffer - content held roughly three to five days and metadata roughly thirty days before being overwritten - that requires a targeted selector to extract anything, rather than a permanent bulk store of everyone's traffic; a training slide quoted in the analysis describes the goal as narrowing "gigantic shrimping nets" into "tiny goldfish-sized nets."
Rebuttal
This point concerns retention mechanics, not the ease of initiating a search: the same documents describe a low-friction process for defining a selector, and flagged data can be moved into longer-term NSA storage systems such as Pinwale for years. The rolling-buffer detail limits, but does not remove, the underlying "collect it all" concern.
PCLOB's Review Was Scoped to Counterterrorism Process Under E.O. 12333, Not a Finding of Unlawful Domestic Use
DebunkingThe PCLOB's XKEYSCORE report stemmed from a July 2014 Board decision to review counterterrorism-related intelligence activity under Executive Order 12333; its public recommendations concern strengthening legal review, training, and notification processes rather than reporting that XKeyscore had been used against domestic targets outside its authorized foreign-intelligence mission.
Rebuttal
The released report is heavily redacted, and Board Member Travis LeBlanc has publicly argued the redactions understate the seriousness of the underlying findings. The absence of a public finding of unlawful domestic use in the redacted version is not the same as a clean bill of health on the classified material.
Neutral / Ambiguous2
XKeyscore Is a Query Interface, Not an Independent Collection Programme
NeutralXKeyscore functions as a federated search tool across data already collected by upstream programmes (PRISM, MUSCULAR, RAMPART-A, cable taps). It does not itself collect data; it indexes and retrieves content within NSA's distributed infrastructure. Snowden's slide deck describing XKeyscore's capabilities therefore reflects the aggregate collection of multiple authorised programmes, not a standalone system with independent collection authority. This distinction matters because legal constraints, oversight mechanisms, and accountability frameworks apply to the upstream collection programmes, not to XKeyscore as a retrieval interface.
XKeyscore Is a Search Interface Dependent on Prior Collection Authority
NeutralXKeyscore is a database query and analysis tool, not itself a collection program. Its capabilities are bounded by what data underlying collection programs — PRISM, MUSCULAR, upstream collection — have already gathered under their respective legal authorities. An analyst querying XKeyscore cannot access data that hasn't been collected and indexed by these prior programs. This matters because the most alarming descriptions of XKeyscore — implying an analyst can query "everything on the internet" — conflate the search interface with the underlying collection infrastructure. The scope of accessible data depends on collection authorities, FISA-court-approved selectors, and data-retention policies, not solely on XKeyscore's query capabilities.
Timeline
XKeyscore reaches operational maturity
According to NSA training materials, XKeyscore reaches operational maturity as the agency's primary query interface over collected internet data, integrating feeds from collection points at over 150 field sites globally into a searchable indexed system.
Snowden publicly identifies himself as the source
Edward Snowden, a former NSA contractor working through Booz Allen Hamilton, publicly identifies himself as the source of the NSA documents published by the Guardian and Washington Post. He describes his access to systems including XKeyscore in subsequent interviews.
Guardian publishes XKeyscore training slides
The Guardian publishes NSA training slides for XKeyscore, including descriptions of the system's query capabilities, data types, and global site coverage. The NSA issues a statement the same day acknowledging the programme.
Source →ODNI releases additional XKeyscore declassifications
The Office of the Director of National Intelligence releases additional declassified information about XKeyscore and related programmes as part of an administration transparency initiative following sustained congressional and public pressure from the Snowden disclosures.
Reporting Reveals GCSB Used XKeyscore Against Solomon Islands Officials
Verdict
Confirmed by NSA training documents published by the Guardian in July 2013 and by the NSA's own public statement acknowledging the programme. XKeyscore allows analysts to query billions of intercepted internet records — email, browsing, search, chat — across 150+ global collection sites by selector, without obtaining individual court orders for each search. The ODNI subsequently declassified additional details.
Frequently Asked Questions
What can an NSA analyst do with XKeyscore?
According to NSA training slides published by the Guardian, an analyst can query XKeyscore by entering a selector (email address, phone number, IP address, or keyword) to search across billions of indexed records covering email content, web browsing history, search queries, chat logs, and file transfers. The system returns matching content and metadata from rolling repositories maintained at over 150 global field sites.
Did XKeyscore require a court order for each search?
Training documents described analysts initiating searches on their own authority without obtaining individual court orders for each query. Analysts were required to document their basis for queries, and oversight systems were described as monitoring for abuse. The NSA disputed characterisations of XKeyscore as permitting unconstrained domestic surveillance, arguing legal authorities and technical controls limited collection to foreign targets.
Did the NSA confirm XKeyscore exists?
Yes. The NSA issued a public statement on 31 July 2013 — the same day the Guardian published the training slides — acknowledging XKeyscore's existence while defending its use as subject to 'extensive oversight' and limited to 'valid foreign intelligence purposes.' The ODNI subsequently declassified additional details about the programme.
Was XKeyscore only an NSA tool, or did other countries use it too?
Sources
Show 13 more sources
Further Reading
- bookSecret Power: New Zealand's Role in the International Spy Network — Nicky Hager (1996)
- articleXKeyscore: NSA tool collects nearly everything a user does on the internet (Guardian) — Glenn Greenwald (2013)
- documentaryCitizenfour (documentary) — Laura Poitras (2014)
- bookPower Wars: Inside Obama's Post-9/11 Presidency — Charlie Savage (2015)
- bookPermanent Record — Edward Snowden (2019)
- paperReport on Certain NSA Uses of XKEYSCORE for Counterterrorism Purposes — Privacy and Civil Liberties Oversight Board (2020)