|
Provisions buried in the Senate Intelligence Authorization Act for Fiscal Year 2027 would eliminate one of the few public checks on two of the nation’s most secretive and powerful intelligence agencies. Sections 601(f) and (g) of the bill would end Senate confirmation for the general counsels of the CIA and the Office of the Director of National Intelligence (ODNI). PPSA joined a coalition of leading civil-liberties organizations from the left and the right to urge Congress to strike these provisions. As the coalition’s letter explains: “The general counsels of the CIA and ODNI wield extraordinary influence, and they do so entirely in secret, shaping policies on surveillance, detention, interrogation, and other highly consequential national security matters.” These officials are not merely agency lawyers handling routine questions. They help determine the legal limits of what intelligence agencies may do to Americans, including warrantless domestic spying. Yet very few CIA or ODNI officials require Senate confirmation, and much of the congressional intelligence-oversight process takes place behind closed doors. Confirmation hearings provide a rare opportunity for senators – and the American public – to examine the legal judgments, records, and commitments of officials who will exercise enormous power in secret. Then-Sen. Mark Udall (D-CO), now a PPSA Senior Policy Advisor, used the confirmation hearing of an Obama administration nominee to raise questions about the CIA’s interrogation program. Sen. Ron Wyden (D-OR) secured a commitment concerning a secret legal opinion on cybersecurity. During the Bush administration, the Senate raised concerns about nominee John Rizzo’s involvement in the CIA detention and interrogation program, leading him to withdraw his nomination. Confirmation hearings have also empowered senators to question nominees about surveillance under Section 702 of the Foreign Intelligence Surveillance Act. As the letter notes, eliminating that opportunity “strips away a key safeguard and undermines the credibility of those who argue that Section 702 does not require reform because it is subject to oversight.” Secret power requires more oversight, not less. Congress should strike Sections 601(f) and (g) and preserve Senate confirmation for both general counsels. Part I: Flock’s Cameras Were Supposed to Watch for Criminals – Why Were Employees Watching Children?8/5/2026
Automated license plate readers are sold to communities as straightforward public-safety tools: cameras photograph passing vehicles, record their license plates, and alert police when they detect a car linked to a crime. But Flock Safety is becoming much more than a network of license plate readers. As the company integrates traffic cameras, police databases, drones, and privately owned video feeds into a surveillance platform, the opportunities for abuse are multiplying. Mary Rooke of The Daily Caller highlights a disturbing example from Dunwoody, Georgia. Local resident Jason Hunyar used public-records requests to obtain audit logs showing how Flock employees accessed cameras connected to the Dunwoody Police Department’s surveillance system. Some of those cameras were inside the Marcus Jewish Community Center of Atlanta. They showed swimming pools, fitness studios, preschool hallways, and gymnastics rooms where children practiced in their leotards. Hunyar found that one Flock executive had accessed Dunwoody’s live and recorded footage 185 times since the beginning of 2025. On one occasion, the only camera he viewed was inside the gymnastics room. Another Flock employee clicked through several cameras at the community center before settling on a view of its main pool. Why were employees of a surveillance vendor looking at these feeds? Why did sales and business-development personnel have such access in the first place? We should not rule out an innocent explanation. But even if there is one, this story demonstrates the many ways these camera systems can be misused in ways to threaten Americans’ privacy. A camera installed for one purpose can quietly become part of a much larger system. A feed intended to protect a private facility can become available to police officials, corporate employees, outside agencies, or any hacker who defeats the system’s security. License plate records can be combined with video, location histories, and other databases to produce an increasingly intimate picture of people’s lives. Communities with Flock technology should require enforceable limits on who may access cameras and data, individualized credentials, prompt disclosure of misuse, independent security testing, and meaningful penalties for improper access. Cameras inside private facilities – especially spaces used by children – should never be swept into police surveillance networks without fully informed consent and exceptionally strong protections. The question is no longer simply whether these systems can help police solve crimes. It is whether any claimed benefit justifies building a surveillance network that may enable strangers to watch us and our children. Amid mounting concern about the misuse of personal data from Flock Safety cameras, the college community of Harrisonburg, Virginia, has joined the growing ranks of American communities rejecting that company’s pervasive surveillance of motorists. The Harrisonburg City Council voted unanimously to end the city’s contract with Flock Safety, shut down its automated license plate readers, and cover the cameras with trash bags until they can be removed. The council also adopted a policy encouraging future councils to consider privacy, data security, equity, and public trust before deploying similar technology. Residents are continuing to press for a binding ordinance that would require public scrutiny of any future mass-surveillance proposal. Harrisonburg Mayor Deanna Reed acknowledged that Flock cameras can help solve crimes. But she concluded that its risks outweighed its benefits. “We might not share the data, that doesn’t mean that somebody can’t get a hold of what we have,” Reed told a reporter at WHSV, a local television station. “The safest thing to do is just not use it at all.” That is a sensible response to a technology that does far more than snap an occasional picture. Flock’s artificial-intelligence system records license plates and vehicle characteristics, allowing police to reconstruct a person’s movements and search for vehicles by color, model, dents, and bumper stickers. Networks linked across jurisdictions can transform scattered observations into a detailed account of where someone worships, works, seeks medical treatment, associates with others, or attends a political protest. Then there is the problem of accuracy. A Business Insider investigation found that Flock’s software misread plates in 71 percent of the stolen-vehicle and felony alerts it sent to police in Roseville, California, during 2023 and 2024. Records showed that the cameras also produced blurry images, missed vehicles, and sent delayed alerts. Roseville’s unusual camera positioning may have contributed to the errors, and its police said none of the false alerts resulted in a stop or arrest because officers independently verified the information. Other communities have not been so fortunate. Flock errors, sometimes compounded by failures of police verification, have led innocent drivers elsewhere to be stopped at gunpoint, jailed, and even mauled by a police dog. Harrisonburg is part of a genuinely bipartisan revolt. Charlottesville ended its Flock pilot program over concerns about data protection, misuse, and local control. In Bandera, Texas, opposition came from residents steeped in a conservative tradition of personal liberty and distrust of government overreach. Across the ideological spectrum, Americans understand that tools to combat serious crimes can easily expand into routine, warrantless monitoring. Police should use targeted investigative methods to pursue people reasonably suspected of crimes. They should not assemble a searchable record of everyone’s movements just in case someone might later come to the attention of authorities. Harrisonburg has made the right call. Other communities should follow its lead and tell mass surveillance to get the Flock out. We’re shocked – shocked! – to find that spying is going on in Morocco. That country’s intelligence service is using what may be the world’s most powerful spyware to target “journalists, human rights defenders, French politicians and Spanish cabinet ministers and police officers,” according to reporting led by Sam Jones for The Guardian. The new evidence comes from a whistleblower who previously worked for Morocco’s internal security services and was uncovered in a collaborative journalistic investigation that includes Amnesty International’s Security Lab. The spyware Morocco is believed to have used includes the infamous Pegasus, which allows its operator to access everything on a target’s mobile phone, including emails, text messages, and photographs. This software does not require the victim to fall for a phishing scam, but can simply install itself remotely. Pegasus can also activate the phone’s recorder and camera, turning it into a 24/7 listening and video-recording device. In July, Security Lab published a technical analysis of Pegasus, labeling it “the world’s most notorious spyware system.” Pegasus manufacturer NSO Group says it sells its software to governments that need help tracking criminals and terrorists. For its part, Morocco denies having any relationship with NSO. The investigation’s leader Forbidden Stories and its partners found evidence to the contrary. For entities with an interest in such technology, Pegasus is particularly appealing because, again, it can infect phones remotely – physical access no longer required. This spyware also has the added advantage of erasing any evidence of its existence. What used to be exceedingly difficult – traditional field intelligence – has suddenly become easy. Perhaps too easy. As described in the accompanying documentary, “Pegasus Project: Inside the Moroccan Spying Machine,” after Morocco’s intelligence service realized what it possessed in Pegasus, its agents quickly added the cell numbers of Moroccan journalists and human rights defenders. Not exactly “criminals and terrorists.” And before long, The Guardian reports, “the targeting had begun to extend beyond Morocco’s borders,” eventually including 200 Spanish mobile numbers, among them those of the prime minister, the minister of defense, the interior minister, and the minister of agriculture. Spain dropped its initial investigation, only to briefly reopen it after French authorities shared details of their own Pegasus experience. “We spy on everyone,” a former Moroccan intelligence officer said in conversation with the journalists, “just in case.” It’s all just one more chapter in the unfolding real-life thriller that is the NSO/Pegasus drama. Every decent person deplores child sexual abuse material (CSAM) and supports every reasonable effort to destroy it. Existing laws already make it a crime for anyone – including social media platforms – to “facilitate,” “distribute,” “promote,” or “possess” CSAM. Despite its good intentions, a Senate bill to combat CSAM would have the unintended consequence of degrading the privacy and encryption that shield women and children from stalkers, whistleblowers from wrongdoers, and journalists and dissidents from cartels and tyrants. The STOP CSAM Act has been quietly added to the latest defense authorization bill. This brings us to the same crossroads we arrived at in 2023, when Electronic Frontier Foundation (EFF) contributors Jason Kelley and Sophia Cope detailed why the bill is so problematic. STOP CSAM could allow lawsuits that would threaten encrypted communications – and with it, the privacy of millions of Americans who simply wish for their digital communications to be as private as their conversations with friends in a park. Encryption itself isn’t a crime or a problem. In the digital age, it’s how we ensure true privacy. Any bill that limits encryption – the last true guarantor of the precious anonymity upon which victims, whistleblowers, journalists, dissidents, and peaceful protesters rely – deserves to be transparently and vigorously debated in full view of the American people, not slipped into an enormous, must-pass defense bill. Under the revised STOP CSAM Act, encryption alone would not provide a basis for civil liability, but it could still be used as evidence in litigation. This would pressure companies to scan messages, weaken encryption, or abandon encryption altogether. Such pressure would create the risk that ordinary conversations between teenagers, parents, teachers, doctors, and counselors would be mistaken for evidence of grooming or exploitation. We applaud efforts in Congress to eradicate CSAM and punish its purveyors. But this bill would create a system with so many uncertainties and financial threats that private platforms could be forced to become overzealous censorship agents. As the U.S. Senate prepares to finalize the confirmation of Jay Clayton as Director of National Intelligence, Senate Majority Leader John Thune (R-SD) scored some partisan points about the Democrats’ disdain for Acting Director Bill Pulte. The senator said: “Democrats were so worked up over the president's temporary choice for this position, they allowed our nation’s most important counterterrorism tool to go dark for the first time ever.” This was a reference to the ongoing debate – and delayed vote – on the reauthorization of Section 702, the authority under the Foreign Intelligence Surveillance Act that allows U.S. intelligence agencies to surveil foreign threats on foreign soil, but has often been used to examine the communications of American citizens on American soil who are not suspected of any wrongdoing. It is true that the deadline for Section 702’s reauthorization has come and gone. But the important – and vital – task of surveilling foreign threats and terrorists has not stopped. All that has happened is that the authority’s statute has expired. Its surveillance programs continue to operate under court orders that allow intelligence collection to continue until March 2027. We have that much time – until the spring of next year – to debate reasonable guardrails that can curtail the program’s rampant surveillance of American citizens. There is no reason to stiff-arm all debate about reform amendments. This surveillance authority was never intended to spy on Americans when Congress enacted it to track foreign threats. Section 702 is not “dark for the first time ever.” Nor do we expect it ever to be. We have the luxury of time to hold a fulsome debate over how Section 702 is used and misused – and the best ways to improve it. Sam Biddle of The Intercept is reporting anew on the secretive surveillance startup (three words that should never go together) “Anomaly Six,” or A6. Records obtained through a Freedom of Information Act request reveal the company currently has a multimillion-dollar contract with the U.S. Air Force office responsible for investigating Havana Syndrome, the cluster of unexplained maladies that has affected U.S. intelligence community members since 2016. But, as the new article notes, A6 is a curious choice of contractor. In 2022, The Intercept published an exposé detailing the company’s disturbing approach to pitching its capabilities – spying on American intelligence officers. The A6 modus operandi illustrates why Congress must use the reauthorization of FISA Section 702 to enact meaningful reforms that address glaring threats to Americans’ privacy. What the company and others like it are doing relies on a practice that clearly allows the government to circumvent the Fourth Amendment by purchasing Americans’ personal information from third-party data brokers. Specifically, A6’s intelligence is based on “bulk cellular location data harvested from millions of unwitting smartphone users around the world.” If A6 can refine this purchased data to the point of tracking CIA agents in the field, just imagine what any private company, hacker, or government agency can do with your location history and data. Of course, the capabilities of private companies pale in comparison to what state actors with unlimited resources can perform. “This fusion of publicly available data, privately procured personal records, and computerized analysis isn’t the future of governmental surveillance, but the present,” warns The Intercept. The present moment is a particularly vulnerable one. Increasingly sophisticated technology and a paucity of legal guardrails are creating a Wild West marketplace where the means to track anyone for any reason can be purchased or otherwise obtained. Congress must embrace its responsibility and stand up for Americans’ privacy. The Fourth Amendment is based on an inherent understanding that Americans’ basic rights and our data are one and the same. The ongoing debate over the reauthorization of FISA Section 702 is a rare opportunity to close such surveillance loopholes. Imagine taking your child to a playground and later learning that strangers could watch her play live online – or replay it at any time. Technology researcher and YouTuber Benn Jordan discovered an alarming example of privacy vulnerability – a Flock Safety camera permanently aimed at a playground near the San Francisco Bay Area was openly broadcasting over the internet. No username or password was required. Jordan and security researcher Jon “GainSec” Gaines found nearly 70 unsecured Flock cameras through a commercial search engine that catalogs internet-connected devices. The cameras were so easy to access that Jordan compared the system to “Netflix for stalkers.” These were not merely license plate readers. They included Flock’s Condor cameras, which can pan, tilt, and zoom – and use artificial intelligence to detect and follow people automatically. Condor is not a license-plate reader. It is a people watcher. Jordan says he watched a man leave his home in New York and a woman jog alone on a wooded trail in Georgia. He watched a man rollerblade, stop, and view videos on his phone. The camera’s AI zoomed in closely enough to see what he was watching. Jordan also saw a couple arguing at an Atlanta street market – and used common internet resources to identify their health and financial problems. In another disturbing sequence, he observed emergency responders attending to an apparently injured person. All of this was available to anyone who found the feeds. The exposure went far beyond live viewing. According to 404 Media, visitors could access administrative controls, download about a month of archived footage, change settings, inspect logs, run diagnostics, and even delete video. Jordan demonstrated the vulnerability by standing beneath one of the cameras and watching himself on his phone in real time. Flock called the episode a “limited misconfiguration” affecting a small number of devices and said it had corrected the problem. But that response misses the larger lesson. As Jordan stresses later in his account, responsibility also rests with the local governments that purchase and deploy these systems. City councils and police departments are building interconnected networks of AI-enabled cameras without first demanding rigorous independent security audits, enforceable access controls, clear data-retention limits, and public accountability. Local officials cannot outsource their responsibility to protect citizens’ privacy. Before approving surveillance technology, they should understand precisely what it records, who can access it, how it can be abused, and what happens when its security fails. A camera installed in the name of public safety should not become an unlocked window into a child’s playground, a couple’s argument, or anyone’s daily life. In the face of numerous reports that Meta’s AI-powered smartglasses are a potential privacy nightmare, the company is recruiting celebrities like Kylie Jenner to help make its public-relations case to its Gen Z target market. Jenner is savvy enough to have parlayed her fame into a reported net worth of a billion dollars. Though Jenner sits at the intersection of celebrity and wealth, she seems to be glossing over the creep factor – and that may also help to explain the backlash she’s receiving. It’s also puzzling that Meta tech chief Andrew Bosworth would use a specious argument to dismiss privacy concerns rather than address them directly. When asked about the issue at a press conference, he said: “I’m old enough to remember when there was controversy about phones having cameras, and this predates even the smartphones that we have today. So, there is this social learning thing that has to happen.” Like learning to give up our privacy and open ourselves to stalking and predation – as women in New York are already having to do? Some women were asked: Where’s your boyfriend? What’s your diet? Have we met before? – questions posed by perfect strangers who happened to be wearing Meta smartglasses. Bosworth seems unaware that social learning is not inherently productive and that smartglasses are far more than the technological equivalent of being able to take a selfie with a smartphone. Or consider reports of women in Texas who thought they were having genuine interactions with strangers, only to end up as the subjects of social media posts with millions of views – against their wishes. Or consider the women in Brussels, who were filmed without their consent by creepers wearing Meta glasses looking to post footage on online “seduction coaching” sites. The BBC’s Kali Hays offers even more context in her analysis. A Meta spokesperson told Hays, “We have teams dedicated to limiting and combating misuse, but as with any technology, the onus is ultimately on individual people to not actively exploit it.” Attorney and privacy advocate David Kessler told Hays: “There are some pretty dark places we could go here. I'm not anti-technology in any sense, but as a societal matter ... will I need to think [of being recorded] anytime I go out in public?” Meta is taking the approach of trusting that all users will abide by the terms of service and do the right thing. Some users no doubt will, but not all. When we’re talking about matters as fundamental as personal privacy, enacting commonsense laws is the smarter approach. If an analogy is helpful, think of mandated safety features such as requiring large vehicles to sound a warning when shifting into reverse. After all, as the BBC and many others have pointed out, the minuscule light Meta claims is sufficient to announce that the glasses are in recording mode is laughably inadequate for that purpose. For the record, not all celebrities are buying what Jenner is selling. Lorde at least had the good sense to call out the privacy issues and push back forcefully on the whole idea. “Can I just say, for the record,” she reportedly told a festival crowd in Madrid, “F--- the glasses. Don't get the glasses. Not sexy.” Because aiming wearable spy tech at nonconsenting adults never is. The story of the mobile spy SUVs purchased by the state of Texas for $4.5 million continues to unfold. According to Alex Barrientos of Gadget Review, the Texas Department of Public Safety’s purchase of four Chevy Tahoes includes an extra $3.9 million for a proprietary surveillance system from a company named Cognyte, Israel’s version of Palantir. Cognyte is the maker of the FalcoNet surveillance technology embedded in the SUVs. FalcoNet, writes Andrew Collins of The Drive, has already been deployed in Florida (as has similar stingray technology elsewhere). Its purpose is simple, if ominous: get between cellphone towers and any phones that happen to be near them, and then secretly intercept and capture everything that being transmitted. FalcoNet and its competitors do this by pretending to be ordinary cell towers, tricking every phone nearby into connecting (smartphones can't help themselves because they are programmed to respond to the strongest signal). Cognyte claims FalcoNet can be activated in under three minutes and can connect with thousands of devices at once as the surveillance vehicles roll through traffic and past pedestrians. Those intercepts are meant to catch the communications of bad actors being sought by authorities. But the software cannot filter out the private information of bystanders from that of suspects, which means that Texas and Florida are sweeping up the data of everyone who happens to be in the mobile system’s vicinity. The data of thousands of innocent persons can then be sifted through afterward. This presumes that only law enforcement will do the sifting – and not hackers, data brokers, or hostile state actors. Even so, that is cold comfort given what we know from the actual abuse and potential misuses of similar surveillance systems. The growing use of stingrays, whether installed on poles in busy parts of town, in mobile police units, or even mounted on drones, underscores the importance of commercial encryption services in protecting our everyday communications. We should be able to enjoy the same level of privacy in our texts and emails that we expect when having a private conversation with a friend. Equally important, the entire premise of such spy regimes – no matter what the official rationalization – flies in the face of the Fourth Amendment. Designed to protect against the invasive and indiscriminate mass searches of general warrants, the Fourth Amendment offers a simple calculus: probable cause + a court warrant + narrowly defined search criteria. In their current forms, programs like the aptly named FalcoNet – and it is a net – are functional dragnets, modern-day general warrants that thwart every aspect of the Constitution’s privacy safeguards. Not even outmoded interpretations of the third-party doctrine can (or should) be invoked to save them. The good news is that we now live in the Chatrie era. In that recent decision, the U.S. Supreme Court clearly articulated a fundamental right to certain forms of digital privacy, specifically regarding location tracking (including geofencing, the whole raison d'être for those shiny new Texas spy SUVs). In short, this practice of roving mass surveillance is ripe for a challenge in court. When PPSA last examined Canada’s proposed Lawful Access Act, we described how it could undermine encryption and endanger privacy worldwide. Now Sen. Ron Wyden (D-OR) is warning that the bill could also enable the Canadian government to conscript American technology companies into spying on Americans. Bill C-22, which has passed Canada’s House of Commons and is now before the Canadian Senate, would grant authorities in Ottawa sweeping new surveillance powers. It would require service providers to retain sensitive user metadata, such as location information, for up to a year. It could also force companies to alter their systems to facilitate government access or install tracking capabilities and security backdoors. In a letter to Secretary of State and acting National Security Adviser Marco Rubio and acting Attorney General Todd Blanche, Sen. Wyden writes that the bill “threatens to weaponize American technology infrastructure by enabling the Canadian government to force U.S. companies to secretly facilitate surveillance of Americans, while systematically undermining the security of their products.” A foreign government could conceivably pressure an American company to retain special backups of an American target’s data, relocate encryption keys to a jurisdiction where they could be seized, or deliver government spyware through a compromised software update. The target could be anyone. As Sen. Wyden warns, “U.S. law does not explicitly prohibit American companies from secretly facilitating foreign surveillance of U.S. citizens – even if the target is the President or another senior U.S. government official.” “This is not a dilemma of U.S. companies being caught between conflicting international legal obligations,” he writes. “It is a glaring statutory vacuum.” Canada is negotiating an agreement with the United States under the CLOUD Act, which would enable Canadian authorities to seek some data directly from American companies. Sen. Wyden urges the Trump Administration to use those negotiations to obtain “ironclad, explicit prohibitions” against Canadian demands that U.S. companies reengineer their products or facilitate surveillance of Americans. As PPSA has warned, there should be no encryption backdoor reserved for trustworthy governments. Any vulnerability can be exploited by hostile governments, criminals, and increasingly capable artificial intelligence systems. Sen. Wyden puts the principle succinctly: “Bilateral trust with our closest intelligence partners cannot be built on the secret subversion of American cybersecurity infrastructure.” The Trump administration should heed his warning. Canada must not be permitted to turn American technology companies into instruments of secret spying on Americans. The U.S. House on Tuesday passed the Protecting Privacy in Purchases Act (H.R. 1181) by a vote of 221-201. The bill was sponsored by Rep. Riley M. Moore (R-W.Va.). Rep. Moore’s bill would prohibit payment card networks from using a special merchant category code to identify purchases from firearms retailers. Such codes could easily become something Congress prohibits – a de facto registry of law-abiding gun owners built from financial transaction data. Senators might consider this not just as a Second Amendment bill close to the hearts of most Republicans, but also as a way to raise a broader privacy principle that would cover the privacy concerns of Democrats as well. After all, financial records reveal far more than how much we spend. They can expose our beliefs, medical concerns, political interests, and personal struggles. Once a payment network creates a special category to identify one type of lawful purchase, the way is open to spy on Americans through their spending. In this version of the bill, the protected category is firearms and ammunition. In a wider version, it could cover purchases related to mental health treatment, addiction recovery, religious materials, reproductive healthcare, or books on controversial subjects. Americans across the political spectrum should be wary of creating new mechanisms that catalog lawful, constitutionally protected activity through payment data. Merchant category codes were designed to classify businesses for payment processing, not to create dossiers on consumers. While the codes do not identify individual products, they can reveal that a customer patronized a particular kind of merchant. Combined with transaction amounts, locations, and other available data, they become another pixel in an increasingly detailed image of Americans’ private lives. PPSA has long warned that government agencies can often obtain commercially available data without the warrant requirements that would apply if they collected the same information directly. As financial surveillance capabilities expand, so do the opportunities for government access, private misuse, and mission creep. The Senate should therefore view the Protecting Privacy in Purchases Act as more than a firearms bill. It is an opportunity to establish that payment processors should not create specialized tracking categories for Americans engaged in lawful activities involving sensitive constitutional rights or deeply personal decisions. A new report by Andrew P. Collins of The Drive highlights a striking example of how modern surveillance often hides in plain sight: Texas law enforcement recently spent $4.5 million on just four Chevrolet Tahoes. The SUVs themselves are ordinary enough. What makes them extraordinary is what is concealed inside them – military-grade surveillance technology capable of locating and tracking nearby cell phones. The vehicles carry cell-site simulators, commonly known as Stingrays. These devices impersonate legitimate cell towers, compelling nearby phones to connect to them. In doing so, they can identify phones in the area and help authorities pinpoint the location of a target. But the technology does not interact only with suspects’ devices. Every nearby phone can be swept into the dragnet before investigators isolate the device they seek. The enormous price tag tells its own story. Texas law enforcement was not just buying SUVs. It was buying an advanced mobile surveillance platform worthy of a Mad Max movie. Police understandably need effective tools to locate dangerous fugitives, rescue kidnapping victims, and investigate serious crimes. But powerful surveillance technologies should come with equally powerful safeguards. That is where the Fourth Amendment must draw the line. The government should not be able to exploit technology that silently collects information from countless innocent Americans without rigorous judicial oversight. Warrants based on probable cause should be the rule, not the exception, and agencies should be required to disclose how often these devices are used, under what legal authority, and what happens to data collected from bystanders. PPSA has long warned that surveillance technologies almost always become cheaper, more capable, and more widespread over time. What begins as an extraordinary capability for rare investigations often evolves into a routine policing tool. The four Tahoes purchased in Texas are a reminder that today’s surveillance state doesn't always arrive as a drone overhead or a camera on a pole. Sometimes it looks like an ordinary SUV moving down the street. The real question is not what such a vehicle costs, but what Americans are giving up every time it rolls by. Imagine the government claiming it can open a box of your old letters without a warrant simply because you kept them for more than six months. Absurd? Under a Reagan-era federal law, that is roughly the legal logic applied to your emails. The Electronic Communications Privacy Act (ECPA), passed in 1986, was a landmark bill that established guardrails for the government’s treatment of private communications in the emerging digital world. At that time, emails were usually downloaded to a personal computer and deleted from servers. That law thus contained a loophole that allowed government agencies to obtain stored electronic communications more than 180 days old without a warrant. One tech provider warns that today that “Gmail will NOT automatically delete your old emails after any timeframe. Messages from 5, 10, or even 20 years ago will sit in your account forever unless you manually remove them.” Technology changed. The law didn’t. That is why PPSA applauds Reps. Warren Davidson (R-OH) and Suzan DelBene (D-WA) and Sens. Mike Lee (R-UT) and Ron Wyden (D-OR), for updating the law with the bipartisan Email Privacy Act. The bill would require the government to obtain a warrant before accessing the contents of Americans’ emails and other stored electronic communications, regardless of how long they have been stored. It would also permit service providers to notify customers when the government seeks their information, unless a court orders otherwise. “The Fourth Amendment is clear: the government must get a warrant before searching an individual’s private property, including written communications,” Rep. Davidson said. Sen. Lee similarly noted that “Americans should not lose their Fourth Amendment protections simply because their private communications are stored with a third-party provider.” They are exactly right. Our emails can contain medical information, financial records, family conversations, political discussions, and the intimate details of our daily lives. The idea that constitutional protection should diminish after 180 days is a relic of the dial-up era. This bill also demonstrates that privacy reform remains one of the few issues capable of bringing together serious conservatives and progressives. These legislators deserve our praise for recognizing a simple principle: a private communication does not become government property as it ages. Congress should pass the Email Privacy Act and apply the Fourth Amendment to the reality of 21st century technology. The U.S. Supreme Court’s landmark decision in Chatrie v. United States settled one important question while raising another that Congress can no longer ignore. If the government needs a warrant to compel Google to disclose Americans’ location records, why should it be able to sidestep that requirement by buying the same records from a data broker? Chatrie’s Principles In a 6-3 opinion, the Court held that Americans retain a reasonable expectation of privacy in detailed cellphone location records, even when those records are held by a third party such as Google. Police therefore conduct a Fourth Amendment search when they compel disclosure of that information through a geofence warrant. In writing the majority opinion, Justice Elena Kagan recognized a simple truth about modern life: carrying a smartphone inevitably generates an extraordinarily revealing record of where we go, whom we visit, who our romantic partners are, which churches we attend, what political rallies we join, and countless other intimate details. Americans do not surrender their constitutional privacy merely because technology companies necessarily store that information. But if that is true, an obvious question follows: Why allow the federal government to simply purchase the very same information from a commercial data broker? The Data Broker Loophole Today, at least a dozen federal agencies have acknowledged buying commercially available personal data. These include the FBI, the Drug Enforcement Administration, the IRS, the Department of Homeland Security, the Department of Defense, and elements of the intelligence community. Instead of obtaining a warrant approved by a judge, these agencies often obtain access simply by writing a check. This practice has become known as the “data broker loophole,” a gaping privacy vulnerability that turns the Fourth Amendment inside out. Suppose police could not constitutionally enter your home without a warrant, but could legally pay your neighbor to climb through the window and photograph every room. Few Americans would believe the Constitution permits such an end-run around judicial oversight. Yet that is effectively what has developed in the digital age. Commercial data brokers aggregate astonishing quantities of personal information collected by smartphone apps, advertisers, financial transactions, connected vehicles, and countless online services. These databases can map a person’s movements, habits, religious observance, medical concerns, political associations, and relationships with extraordinary precision. Agencies can often acquire such data without ever demonstrating probable cause to a court. Now, Chatrie pokes holes through the government’s thin rationale by holding that highly revealing location histories remain constitutionally protected even when maintained by private companies. If the Constitution bars the government from compelling disclosure without a warrant, Congress should not permit agencies to obtain the same information merely because a private intermediary has placed it on the market. The bipartisan Fourth Amendment Is Not for Sale Act would close this loophole by requiring government agencies to obtain a warrant before acquiring sensitive commercially available data. The core provisions of that legislation should be incorporated into Section 702 of the Foreign Intelligence Surveillance Act when it comes up for reauthorization. The Supreme Court now recognizes that Americans possess a reasonable expectation of privacy in the digital trails their smartphones inevitably create. Congress should finish the job by closing the data-broker loophole when it reauthorizes Section 702. Jacqueline McNeill of Fayetteville, North Carolina, was driving home from the grocery store – with chicken to prepare for her goddaughter’s funeral, no less – when multiple police cruisers cornered her white Nissan Versa in the parking lot of a convenience store. “I felt like the moment I stepped out of my car,” she later told Tyler Dukes of Raleigh’s The News & Observer, “I was automatically guilty.” The second-grade teacher was arrested on the spot for a drive-by shooting. Jacqueline wasn’t guilty of anything, but that didn’t stop her from becoming a victim of automated license plate readers (ALPRs). Days before, these roadside cameras had spotted a car similar to hers in the vicinity of a shooting. As with so many other surveillance systems, police used this image in place of critical thinking, as visual proof when it was nothing of the sort. And now this far-less-than-foolproof technology – with the privacy protections of a rusted colander – is about to get a massive injection of mission creep. One of the makers of ALPR technology is Leonardo (pro tip before clicking: you might want to decline all cookies). According to Ian Wright of CarBuzz, the company’s SignalTrace technology “is set to move ALPR cameras from just car-tracking to people-tracking devices.” In plain language, that means tracking drivers’ and passengers’ smartphones, vehicle infotainment systems, and any other Bluetooth-capable device – all linked to your license plate or someone else’s. Worse, our devices are uniquely and individually identifiable. In the absence of robust legislation designed to bolster our Fourth Amendment rights, the only thing that can prevent them from being used as straight-up spy tools by authorities is end-to-end encryption. Wright reports the SignalTrace product sheet promises to “create a unique, trackable ‘electronic fingerprint’ for investigative use.” But wait, there’s more! The surveillance dragnet Leonardo is creating includes RFID tags (they’re everywhere, including key cards), pet microchips (so much for taking your dog along on errands), tablets, fitness trackers, tire pressure sensors, and… you get the idea. If there’s a kicker in all of this, it is another passage Wright quotes from the SignalTrace product sheet, which boasts that it “stores device and correlation data securely … for future queries and analysis.” The dystopian quantum leap, Wright notes, is that once implemented, ALPR systems will transition from identifying vehicles to identifying occupants. All of this data will be unbound by time, stored in a permanently searchable database – just in case we need to be retroactively suspected of something that may or may not have been legal once upon a time and that we may or may not have done in a car that we may or may not have been driving (or simply riding in). Calling Steven Spielberg: We just found the sequel to Minority Report. What could go wrong? To name a few risks: false positives; arrests of innocent people; police officers using ALPR systems for stalking and intimidation; and the collection of massive amounts of personal data by for-profit corporations ready, willing, and able to sell that information to any and all comers, including the government. Add to these risks hacking by cybercriminals and bad-faith state actors. It’s all coming to a technocratic authoritarian surveillance state near you. Because of her false arrest that day, Jacqueline McNeill never made it to her goddaughter’s funeral. She also largely avoided driving her Nissan before eventually selling it. And who can blame her? Where you go and who you meet are some of the most revealing facts about you. Does this intimate information deserve to be included within the Fourth Amendment’s protections against “unreasonable searches and seizures”? This question has new force in the wake of the U.S. Supreme Court’s landmark decision in Chatrie v. United States. That ruling strengthened constitutional protection for one form of Americans’ location history – the records of our movements generated by our cellphones and held by third parties like Google. A case before the Fourth Circuit Court of Appeals, Schmidt v. City of Norfolk, extends this concept to the city’s use of automatic license plate readers (ALPRs) in that Virginia city. The plaintiffs demonstrate that Norfolk’s network of cameras continuously photographs them and their vehicles, stores that information, and allows police to reconstruct weeks of their travel history without a warrant. That case, once seen as a bit of a stretch by many legal observers, suddenly looks much more viable after Chatrie. In Chatrie, Justice Elena Kagan wrote the Court’s majority opinion that declared that Americans retain a reasonable expectation of privacy in their location information, even when it is held by a third party. The Court emphasized that the Fourth Amendment must protect citizens against “too permeating police surveillance” and rejected the idea that privacy disappears merely because modern technology records information shared with companies. Those same principles extend naturally to ALPR systems. As PPSA explained in our amicus brief before the Fourth Circuit, the constitutional issue is not whether a single license plate can be seen on a public road. It is the government’s ability to aggregate thousands – or millions – of those observations into a searchable database capable of reconstructing “the whole of a person's physical movements.” The brief warns: “The relevant constitutional question here is whether the government used surveillance technology to collect and aggregate location records that allow retrospective reconstruction of a person's movements. ALPR databases do exactly that.” These retrospective insights go well beyond license plate readers. Modern surveillance increasingly depends on collecting seemingly innocuous bits of location information – from the apps on our cellphones, cellphone records, GPS and vehicle tracking, facial recognition hits, drone footage, and our personal information sold by data brokers to the government. These can all be combined into a detailed dossier on any individual. Each data point may appear harmless. Together, they reveal where we sleep, worship, seek medical care, attend political meetings, and with whom we associate. PPSA's brief argues that this is exactly the type of technological transformation the Supreme Court warned about: “What matters for the Fourth Amendment is the state's use of technology to convert innumerable public-facing moments into a searchable log of a person’s life, not the innocuous nature of any single data point taken alone.” Chatrie may ultimately be remembered not simply as the geofence warrant case, but as the decision that reaffirmed a broader constitutional principle for a host of pervasive forms of surveillance. If that principle is faithfully applied, courts will soon have to ask difficult questions not just about geofence warrants, but about ALPR networks, facial recognition systems, AI-enabled camera platforms, and every other technology that enables the government to reconstruct the movements of ordinary citizens without first obtaining a warrant. The fuse has been lit. Now comes the hard work of ensuring that the Fourth Amendment keeps pace with 21st-century surveillance. The government has yet to respond to a Freedom of Information Act (FOIA) request filed in 2024 by the Cato Institute seeking records on abuses of Section 702 of the Foreign Intelligence Surveillance Act. Court records reveal, however, that the FBI is withholding 39,650 pages responsive to that FOIA request. This should be a matter of vital interest to Congress. Section 702 is a surveillance authority that allows the government to spy on foreign threats on foreign soil, but has been used widely in recent years to warrantlessly spy on millions of Americans whose communications are “incidentally” caught up in the National Security Agency’s global trawl. So you would think that almost 40,000 pages on possible FBI violations of Section 702 would be at the forefront of the debate over whether to add guardrails and reforms as Section 702 faces reauthorization. But Congress has been supine while the FBI promises to release only a meager 128 pages in August. The Privacy and Civil Liberties Oversight Board, which could add clarity to the FBI’s actions, has also been sidelined by the administration. Patrick Eddington, a Cato fellow, wrote: “Congress is being asked to extend, without a warrant requirement, a surveillance program whose compliance record cannot be independently verified, whose oversight bodies have been deliberately disabled, and whose custodians have shown a personal willingness to turn its tools on the press.” The latter is a matter of particular concern. The previous year saw a rise in “sensitive warrantless searches,” or queries that involve political and religious figures or organizations, as well as journalists. When will Congress get curious and demand the information needed to inform the Section 702 debate? Wells v. State of Texas The U.S. Supreme Court’s decision Monday in Chatrie v. United States marked the biggest advance in digital privacy since Carpenter v. United States in 2018. By recognizing that Americans retain a reasonable expectation of privacy in digital location tracking, such as Google’s Location History records, the Court closed a major loophole in Fourth Amendment law. But Chatrie is unlikely to be the final word. Like Carpenter before it, the decision is likely to spark a renewed struggle over how to apply this precedent. One case worth watching is Wells v. State of Texas, which the Supreme Court Tuesday remanded to the Texas Court of Criminal Appeals. The facts are straightforward. In 2018, Dallas police investigating a fatal robbery obtained a geofence warrant directing Google to identify every device that had been present within a defined area around the crime scene during a 25-minute period in the early morning hours. The warrant eventually led investigators to Aaron Wells, who was convicted of capital murder. What makes Wells noteworthy is not the crime but the court's fractured reasoning. Like the Fourth Circuit in Chatrie itself, the Texas Court of Criminal Appeals produced no clear majority rationale. Four judges assumed that obtaining Google's location history constituted a Fourth Amendment search but upheld the warrant because it was supported by probable cause and was – in the language of the Fourth Amendment – sufficiently “particular” about what would be seized. Two of those judges separately explained that the geofence warrant did not involve a constitutional search at all, relying on theories that users surrender their privacy by sharing information with Google. Three other judges concluded that no search occurred for most of the data sought by the warrant. But they further explained that no probable cause existed either because the police obtained a warrant with only the location where a crime occurred, not a suspect. One judge dissented without opinion, and another did not participate. That division matters because Chatrie resolved the question about whether a search occurred, highlighting the importance of the remaining disagreement about the Fourth Amendment’s probable cause and particularity requirements. On that question, the Wells court was divided 4-3, with one justice dissenting but not explaining the basis for his dissent. Now after Chatrie, courts must focus on these difficult questions that divided the Texas Court of Criminal Appeals. In essence, courts will now focus on how broad is too broad. How many innocent people may be swept into an investigation before a warrant becomes the digital equivalent of the general warrants the Fourth Amendment was written to forbid? Those are not academic questions. Geofence warrants have already been used in investigations ranging from bank robberies to protests, and each new case forces courts to balance legitimate law enforcement needs against the privacy rights of countless bystanders whose only “crime” was being nearby. Carpenter reshaped surveillance law for nearly a decade. Chatrie promises to do the same. "Custom-house officers may enter our houses, when they please ... may break locks, bars, and everything in their way; whether they break through malice or revenge, no man, no court can inquire." |
Categories
All
|
RSS Feed