The program's use prompted changes in how secret information is handled at the State Department, the Pentagon and the intelligence agencies, but recent assessments suggest that those changes may not have gone far enough. For example, arguments have broken out about whether the N.S.A.'s data should all be encrypted "at rest" — when it is stored in servers — to make it harder to search and steal. But that would also make it harder to retrieve for legitimate purposes.Investigators have found no evidence that Mr. Snowden's searches were directed by a foreign power, despite suggestions to that effect by the chairman of the House Intelligence Committee, Representative Mike Rogers, Republican of Michigan, in recent television appearances and at a hearing last week.
But that leaves open the question of how Mr. Snowden chose the search terms to obtain his trove of documents, and why, according to James R. Clapper Jr., the director of national intelligence, they yielded a disproportionately large number of documents detailing American military movements, preparations and abilities around the world.In his statement, Mr. Snowden denied any deliberate effort to gain access to any military information. "They rely on a baseless premise, which is that I was after military information," Mr. Snowden said.The head of the Defense Intelligence Agency, Lt. Gen. Michael T. Flynn, told lawmakers last week that Mr. Snowden's disclosures could tip off adversaries to American military tactics and operations, and force the Pentagon to spend vast sums to safeguard against that. But he admitted a great deal of uncertainty about what Mr. Snowden possessed.
"Everything that he touched, we assume that he took," said General Flynn, including details of how the military tracks terrorists, of enemies' vulnerabilities and of American defenses against improvised explosive devices. He added, "We assume the worst case."Hackers used a weakness in the Internet system that sets the time on'puters' clocks in order to overload a victim's servers with traffic, in what is reportedly the largest-ever such cyberattack.The'mon hacking method is called a distributed denial-of-service attack, in which Web services receive so much traffic that they either slow down or crash.