Does anyone know how they do this, technically, and to what extent? Does Google just feed them billions of emails, or what? Do they type my name into a form on Amazon.com to get SSH access my EC2 server? And how the hell do they see my finances? Do all of those terms of service agreements say, "By the way, we give your private information to the government without question" ??? At first I thought it didn't matter tha…
They use network taps[robust ones] to sift thru the unencrypted traffic[most email traffic and regular net traffic]...and most likely a close relationship with the SSL cert-auth roots to scrutinize the 'secure' stuff.
Anything else encrypted in place is most likely sent to Oak Ridge or there own HPC clusters and bf'd.
Defense?
AES 256 with loooooooong and strong passphrases and keyfiles. and generate your own SSL certs[4096 min]....and use VPN's which terminate out of country and don't keep logs.