> They don't sniff all the packets to find anything useful. Snowden showed that they intercept certain packets flowing between particular sources and destinations that might contain useful information
Their legal argument was that it was actually ok for them to grab and store all packets, and that it wasn't a search until they ran an actual search that matched against that stored traffic.
> In Snowden's leaks, one such application was email inbox backup transfers for big Internet companies that did not (at that time) encrypt their WAN traffic, from which they mined the sender and recipient to build a social graph, a program that the leaks said had already been shut down.
That was private fiber they had spliced into, not anything routed across public Internet. That's why the DCs weren't encrypting it to begin with.
> Their legal argument was that it was actually ok for them to grab and store all packets, and that it wasn't a search until they ran an actual search that matched against that stored traffic.
No, they never made that argument because they don't grab and store all packets. Instead, they stored the metadata extracted from these packets (the sender and receiver). This program has ended prior to Snowden's leaks according to his documents, but the telephone pen register collection was still ongoing.
> That was private fiber they had spliced into,
No, this was public Internet, at places like Room 641A. There was nothing in the leaks suggesting they had spliced private fiber.