PHION
Files 16 Uptime 345d Latest 28d

An Introduction to SIGINT

In January 1917, British naval codebreakers working in Room 40 of the Admiralty decoded a telegram from German foreign minister Arthur Zimmermann to his ambassador in Mexico. It proposed a German–Mexican alliance: if the United States entered the war against Germany, Mexico would get back Texas, New Mexico and Arizona. When the contents became public, they helped tip American opinion toward war — the United States declared war on Germany on 6 April 1917, in what historians still call one of Britain’s most significant intelligence victories of the war (Wikipedia: Room 40). A single intercepted message, decrypted and passed on, changed the course of a war. That is the point of signals intelligence — SIGINT — and it is still exactly what it does.

SIGINT is one of several named categories of intelligence collection, alongside HUMINT (human sources), IMINT (imagery) and OSINT (open sources). It covers everything gathered by intercepting a signal rather than talking to a person or looking at a picture: radio traffic, phone calls, internet data, satellite links, radar emissions. Most governments with the money to do it operate a SIGINT agency — the NSA in the United States, GCHQ in the UK, the Australian Signals Directorate, Canada’s Communications Security Establishment, Israel’s Unit 8200 — and most of what they do stays classified. What follows is what is publicly documented: the disciplines, the history, the hardware, and the legal fights over what it is allowed to touch.

SIGINT’s four disciplines

The US Department of Defense splits SIGINT into three disciplines, and a fourth related field is often confused with it:

Discipline What it collects Example
COMINT Communications intelligence — intercepted human communications A phone call, an email, a radio conversation between soldiers
ELINT Electronic intelligence — non-communication electronic emissions A surface-to-air missile radar’s signal, used to identify and locate the system
FISINT Foreign instrumentation signals intelligence — telemetry from weapons and space systems under test Data a missile radios back to ground control during a test flight
MASINT Measurement and signature intelligence — a separate discipline, not SIGINT The unintentional acoustic or radar signature of a piece of hardware, rather than anything it deliberately transmits

The distinction between COMINT and ELINT matters operationally: COMINT is about what is being said, ELINT is about what a piece of equipment is and where it is, inferred from how it transmits even when no human communication is involved (Wikipedia: Signals intelligence).

A short history

The earliest confirmed use of the discipline dates to the Russo-Japanese War: in 1904 the British ship HMS Diana, stationed in the Suez Canal, intercepted Russian naval wireless signals as the Russian fleet sailed to the Pacific (Wikipedia: Signals intelligence). The First World War turned interception into an institution. Britain’s Admiralty set up Room 40 in October 1914; by the war’s end its codebreakers had intercepted and decrypted roughly 80 million words of German wireless traffic, including the Zimmermann telegram. In 1919, Room 40 merged with the army’s codebreaking unit to form the Government Code and Cypher School (GC&CS) — the first peacetime codebreaking agency — which by 1940 could read the diplomatic traffic of 26 countries (Wikipedia: Signals intelligence).

GC&CS moved to Bletchley Park in 1939 and, under the wartime codename Ultra, broke the German Enigma cipher — Alan Turing’s team achieved the key breakthrough in 1941. General Eisenhower called Ultra intelligence decisive to the Allied war effort; the official historian of British intelligence, Harry Hinsley, argued it shortened the war by at least two years and probably by four (Wikipedia: Signals intelligence). Not all of Ultra’s value came from reading content. Ahead of D-Day, traffic analysis — tracking who was transmitting to whom, and how much, without necessarily decrypting the content — let the Allies map the location of all but two of Germany’s 58 Western Front divisions.

The wartime UK–US codebreaking relationship became permanent after the war. The US and UK signed the BRUSA agreement in May 1943 and formalised it as the UKUSA Agreement on 5 March 1946; Canada joined in 1948, and Australia and New Zealand became full partners in 1956, forming what is now known as the Five Eyes (Wikipedia: Five Eyes). Through the Cold War, both sides ran physical taps on the other’s cables: the best documented is Operation Ivy Bells, a 1971 joint US Navy, CIA and NSA operation in which divers from the USS Halibut located a Soviet undersea communications cable in the Sea of Okhotsk and fitted a recording pod around it — without cutting it — built by AT&T’s Bell Labs to store a year of intercepted traffic on tape. The operation ran undetected until 1980, when NSA analyst Ronald Pelton defected and sold the Soviets details of it for US$35,000 (Wikipedia: Operation Ivy Bells).

How modern collection works

From orbit

Cold War SIGINT satellites listened to Soviet missile telemetry and radio traffic from geostationary orbit, far enough out that a wide dish could pick up signals never intended to leave the ground. The lineage runs from the CANYON and RHYOLITE satellites of the 1960s and 70s through AQUACADE to the current ORION (also called MENTOR) constellation, operated by the US National Reconnaissance Office with CIA input. Five have launched since 1995; each is estimated at roughly 5,200kg with a radio-reflecting dish around 100 metres across, parked in geostationary orbit for near-continuous coverage of the Eurasian landmass (Wikipedia: Orion (satellite)).

Ground stations receive and relay what the satellites and terrestrial intercepts pick up. The best known is RAF Menwith Hill in Yorkshire, described as the largest SIGINT facility of its kind; others include Pine Gap near Alice Springs (jointly run by the Australian Signals Directorate and the CIA), GCHQ Bude in Cornwall, Waihopai in New Zealand and Misawa in Japan. Collectively these stations were the physical infrastructure behind ECHELON, the Five Eyes satellite-interception network that grew out of a 1966 US program called FROSTING and became operational in 1971. A European Parliament investigation concluded in July 2001 that ECHELON was capable of intercepting and inspecting the content of phone calls, faxes, emails and other data traffic worldwide, and recommended that European citizens use cryptography to protect their own communications (Wikipedia: ECHELON).

Undersea and backbone cables

Around 99% of intercontinental internet and phone traffic still travels through undersea fibre-optic cables rather than satellites, which makes the cables themselves a collection target. The Cold War version was physical: Ivy Bells-style taps on copper cables. The modern equivalent works differently, because fibre carries data as light rather than electrical current, and a passive optical splitter can copy that light without cutting the fibre or degrading the primary signal.

The best documented case — what the NSA internally calls upstream collection, meaning collection straight off the cable rather than from a company’s own servers — is Room 641A, a secured room inside an AT&T building at 611 Folsom Street in San Francisco. AT&T technician Mark Klein, who worked on the facility’s wiring, came forward in 2006 with internal AT&T documents showing that fibre optic splitters had been installed on the company’s WorldNet internet backbone, feeding a duplicate of the traffic into equipment — including a Narus STA 6400 traffic analysis device — installed for the NSA. The arrangement had been running since 2003. A former GTE chief technology officer who reviewed the schematics concluded it gave the capability to analyse internet content at a massive scale, covering both overseas and purely domestic traffic (Wikipedia: Room 641A). The animation below shows the mechanism: a splitter diverts a copy of the light onto a second fibre while the original signal continues to its destination untouched, which is what makes this kind of interception invisible to both ends of the connection.

A passive beam splitter duplicates the light travelling down a fibre-optic strand. Room 641A, an AT&T facility in San Francisco, used this technique on the company’s internet backbone from 2003 until technician Mark Klein exposed it in 2006. The Electronic Frontier Foundation’s lawsuit against AT&T, Hepting v. AT&T, was dismissed in 2011 after Congress granted telecommunications companies retroactive immunity for cooperating with the program.

The Cold War approach to cable-tapping has not disappeared, either — it has moved to fibre. The US Navy submarine USS Jimmy Carter received a 100-foot hull extension in a 1999 modification, officially called the Multi-Mission Platform, built for divers and remotely operated vehicles to work in open water beneath the submarine. Wikipedia notes that intelligence experts have speculated the platform could serve as an underwater splicing chamber for fibre optic cables, but is explicit that this specific role is unconfirmed rather than documented fact (Wikipedia: USS Jimmy Carter).

Direction finding and IMSI-catchers

Not all SIGINT requires reading content. Direction-finding locates a transmitter by comparing the same signal’s arrival time or phase across multiple receivers — the Cold War-era Wullenweber array used concentric rings of antennas to do this simultaneously across a wide arc. The same principle, miniaturised, sits behind IMSI-catchers (commercially, devices like the Harris Corporation’s Stingray), which impersonate a mobile phone tower to identify nearby handsets. They exploit a specific gap in the GSM standard: a handset must authenticate itself to the network, but the network is never required to authenticate itself to the handset, so a fake tower with a strong enough signal can simply be believed. Once a phone connects, the IMSI-catcher can identify it and, in some configurations, downgrade its encryption. These are used by police and intelligence agencies alike; the UK’s Metropolitan Police is reported to have deployed them since at least 2011, and body-worn versions have been marketed to US law enforcement since 2013 (Wikipedia: IMSI-catcher). In the US they are typically authorised under a pen-register order, a lower legal standard than a search warrant.

What’s publicly known

Almost everything above would still be speculation without Edward Snowden. In June 2013, documents he supplied to the Guardian and the Washington Post revealed PRISM, an NSA program under which participating companies — Microsoft from 2007, Yahoo from 2008, Google, Facebook and PalTalk from 2009, YouTube from 2010, Skype and AOL from 2011, and Apple from 2012 — provided the NSA access to stored communications content under Section 702 court orders (The Guardian, 6 June 2013). Weeks later, further documents revealed XKEYSCORE, which NSA training material describes as its single most far-reaching system for developing intelligence from internet traffic: as of 2012, a single 30-day period saw at least 41 billion records pass through it, and analysts could query it for a person’s browsing, email and chat activity with only a broad, unaudited justification typed into a form (The Guardian, 31 July 2013). Documents later published by The Intercept added detail: over 150 collection sites and 700-plus servers worldwide as of 2008, storing three to five days of full content and 30 to 45 days of metadata (The Intercept, 1 July 2015).

The same leaks put a number on the whole enterprise. A classified US intelligence budget summary given to the Washington Post showed the NSA’s 2013 budget at US$10.8 billion, out of a US$52.6 billion total across 16 agencies. The NSA’s own staff is not officially published but is generally estimated at 30,000 to 40,000 people. Its newest facility, a data centre in Bluffdale, Utah, opened in 2013: roughly a million square feet in total, of which around 100,000 square feet is server floor, reportedly drawing 65 to 75 megawatts of power. Its actual storage capacity is classified, and public estimates disagree sharply — Internet Archive founder Brewster Kahle estimated around 12 exabytes and infrastructure researcher Paul Vixie under 3 exabytes, while NSA whistleblower William Binney’s widely repeated claim of 5 zettabytes was later shown to have misread the underlying storage vendor’s marketing material. Based on the building’s floor space, the lower estimates are the credible ones (Forbes, 24 July 2013).

The most concrete illustration of what a Five Eyes partner will do with this capability against an ally, rather than an adversary, is Germany. Der Spiegel reported in October 2013 that the NSA had monitored German Chancellor Angela Merkel’s mobile phone since 2002 — three years before she became chancellor — with her number listed under an NSA Special Collection Service database entry, apparently still active weeks before a June 2013 visit to Berlin by President Obama. Germany summoned the US ambassador over the revelation, an almost unprecedented step in the post-war relationship, and Merkel later told Obama directly that “spying between friends, that’s just not done” (Al Jazeera, 27 October 2013; PBS NewsHour).

Why it matters

SIGINT law in the United States turns on Section 702 of the Foreign Intelligence Surveillance Act, which authorises the collection of foreign targets’ communications from US companies and cable infrastructure — the legal basis for PRISM and upstream cable collection. It does not require a warrant naming an American, but Americans’ communications get swept up whenever they correspond with a foreign target, a category known as incidental collection. Congress reauthorised Section 702 for two years in April 2024 through the Reforming Intelligence and Securing America Act (RISAA), after years of disclosures that the FBI had run tens of thousands of searches of this data using American identifiers — names, email addresses, phone numbers — without a warrant. RISAA added oversight requirements for the FBI and inspector-general reporting, but it also expanded, rather than narrowed, the range of companies that can be compelled to assist with collection (Congressional Research Service, via EveryCRSReport.com).

The same collection has reshaped how Europeans’ data can legally cross the Atlantic. The Court of Justice of the EU ruled twice — Schrems I in 2015 and Schrems II in 2020 — that US surveillance law failed to give EU citizens legal protection equivalent to what they have at home, striking down first the Safe Harbor and then the Privacy Shield data-transfer agreements each time (Wikipedia: Schrems II). The current arrangement, the EU–US Data Privacy Framework, was adopted in July 2023 after the US created a new redress mechanism, the Data Protection Review Court, under Executive Order 14086. It has already been challenged once — French MP Philippe Latombe argued the review court still lacks real independence and that Section 702’s bulk collection remains incompatible with EU law — and survived that challenge in the EU General Court in 2025, though privacy group noyb has said it intends to pursue a further case (Brennan Center for Justice; Freshfields). In practical terms: whether an ordinary European’s data held by a US cloud provider is legally protected from SIGINT collection has been relitigated three times in a decade, and is not considered settled by the people bringing the cases.

Limitations

SIGINT is not the omniscient system its budget and history might suggest. End-to-end encryption, now default in Signal, WhatsApp and iMessage, denies COMINT access to content even when the traffic itself is fully visible in transit — an agency can see that a call happened, and often exactly who was on it and for how long, but not what was said. That metadata is not a minor consolation: traffic analysis alone mapped most of the German army before D-Day, and it works whether or not the content is encrypted. Collection volume also outstrips analysis capacity by a wide margin — a system like XKEYSCORE only retains full content for three to five days precisely because there is far more of it than any agency can store or read, which is why targeting (a “selector”: a phone number, an email address, a name) matters more in practice than the theoretical reach of the collection. Legal oversight, where it exists, is almost entirely after the fact: FISA court approval and post-hoc inspector-general reviews catch abuse once it is reported, not before it happens, as the pre-RISAA history of unauthorised database queries showed. None of this makes SIGINT collection stop; it means the practical limit on what an agency knows about a given person has less to do with what they can intercept and more with whether anything about that person made an analyst look in the first place.

Sources