|
Franklin Delano Roosevelt likened the motley coalition supporting his opponent in the 1940 election to a chameleon. The president joked: “We all know the story of the unfortunate chameleon, which turned brown when placed on a brown rug, and turned red when placed on a red rug, but who died a tragic death when they put him on a Scotch plaid.” Plaid, in actuality, is never fatal, though it has been known to kill the vibes for a few first dates. There is, however, a new use for plaid in the 21st century. With millions of cameras embedded in doorbells and suspended over streets and highways, plaid may just be the fashion accessory for the privacy-conscious. The power of plaid has been discovered by a security researcher, who seems to have found a way to make people and vehicles less visible to the algorithms behind surveillance cameras. As Zack Whittaker of TechCrunch reports, Bill Swearingen’s “noRecognition” project uses computer-generated patterns to confuse automated detection systems. After some 31 million tests, his model produced patterns that defeated 11 open-source algorithms, including software used by Flock license-plate readers, Axon body cameras, and Clearview AI. At the recent DEF CON cybersecurity conference in Las Vegas, a car wrapped in one of Swearingen’s patterns evaded detection from a Flock camera. These patterns, however, do not stop cameras from recording. They merely prevent algorithms from recognizing and flagging people, faces, or vehicles. Swearingen calls these patterns a way to “opt out of being tracked.” It is an ingenious response to a troubling reality: Although we never agreed to it, we are increasingly subjected to automated surveillance that tracks us wherever we go, with the potential to record our associations and activities. Who knows? If people start wearing these patterns, maybe surveillance algorithms will crawl across our images and die. Can authorities rifle through the location histories of thousands of innocent people to catch one guilty person? One federal judge in Mississippi recently gave a decisive answer: No. U.S. District Judge Carlton Reeves of the Southern District of Mississippi had no qualms about drawing the line at the exact edge of the U.S. Constitution. This case concerned “tower dumps,” in which authorities require a cellular provider to produce information concerning every device that connected to specified cell towers during a defined period. On Aug. 5, Judge Reeves held that such “tower dump” warrants are per se unconstitutional. Ryan T. Fenn and Lee M. Cortes, Jr. of Arnold & Porter report in Enforcement Edge that Judge Reeves based his ruling on the conclusion that such searches intrinsically violate the Fourth Amendment because, by their nature, tower dumps cannot be particularized. It is, therefore, impossible to establish probable cause as required by the Fourth Amendment with respect to each device captured. Judge Reeves acknowledged that tower dump warrants can be “uniquely effective” in catching criminals by placing them at the scene of a crime. His concern was that such a search, however, also sweeps in information belonging to thousands of people who have no connection to the investigation. In his opinion, Judge Reeves wrote that the government cannot obtain “an entire haystack because it may contain a needle.” Judge Reeves extended the logic of the Supreme Court’s 2018 Carpenter ruling, which recognized a privacy interest in cell-site location information, but declined to address tower dumps. He also noted that the recent Supreme Court Chatrie decision held that geofence warrants are searches, regardless of the time limits placed on a warrant. The logic of these cases extends to tower dumps, which can identify people inside their homes, offices, and houses of worship – data Judge Reeves found to be “intimate and deeply revealing.” Will this federal judge’s ruling in Mississippi upend the common practice of scraping mass data from cell-phone towers? Will it set a precedent that will quickly bring other forms of mass surveillance – such as federal agencies’ purchases of Americans’ digital lives from data brokers and the increasingly ubiquitous network of public and private cameras to which law enforcement has easy access – under constitutional scrutiny? Short answer: Not likely. But it is still a very positive development. As Fenn and Cortes write, “this is one decision from a district judge – it binds no other court, not even others in the Southern District of Mississippi.” True. We believe, however, that Judge Reeves’s ruling is significant. It is likely to inspire more such cases and rulings – coming down on both sides of the issue – that will force the Supreme Court to provide a more detailed and comprehensive answer on the constitutionality of all forms of geolocation tracking. Stay tuned. Sam Biddle of The Intercept is reporting anew on the secretive surveillance startup (three words that should never go together) “Anomaly Six,” or A6. Records obtained through a Freedom of Information Act request reveal the company currently has a multimillion-dollar contract with the U.S. Air Force office responsible for investigating Havana Syndrome, the cluster of unexplained maladies that has affected U.S. intelligence community members since 2016. But, as the new article notes, A6 is a curious choice of contractor. In 2022, The Intercept published an exposé detailing the company’s disturbing approach to pitching its capabilities – spying on American intelligence officers. The A6 modus operandi illustrates why Congress must use the reauthorization of FISA Section 702 to enact meaningful reforms that address glaring threats to Americans’ privacy. What the company and others like it are doing relies on a practice that clearly allows the government to circumvent the Fourth Amendment by purchasing Americans’ personal information from third-party data brokers. Specifically, A6’s intelligence is based on “bulk cellular location data harvested from millions of unwitting smartphone users around the world.” If A6 can refine this purchased data to the point of tracking CIA agents in the field, just imagine what any private company, hacker, or government agency can do with your location history and data. Of course, the capabilities of private companies pale in comparison to what state actors with unlimited resources can perform. “This fusion of publicly available data, privately procured personal records, and computerized analysis isn’t the future of governmental surveillance, but the present,” warns The Intercept. The present moment is a particularly vulnerable one. Increasingly sophisticated technology and a paucity of legal guardrails are creating a Wild West marketplace where the means to track anyone for any reason can be purchased or otherwise obtained. Congress must embrace its responsibility and stand up for Americans’ privacy. The Fourth Amendment is based on an inherent understanding that Americans’ basic rights and our data are one and the same. The ongoing debate over the reauthorization of FISA Section 702 is a rare opportunity to close such surveillance loopholes. The U.S. House on Tuesday passed the Protecting Privacy in Purchases Act (H.R. 1181) by a vote of 221-201. The bill was sponsored by Rep. Riley M. Moore (R-W.Va.). Rep. Moore’s bill would prohibit payment card networks from using a special merchant category code to identify purchases from firearms retailers. Such codes could easily become something Congress prohibits – a de facto registry of law-abiding gun owners built from financial transaction data. Senators might consider this not just as a Second Amendment bill close to the hearts of most Republicans, but also as a way to raise a broader privacy principle that would cover the privacy concerns of Democrats as well. After all, financial records reveal far more than how much we spend. They can expose our beliefs, medical concerns, political interests, and personal struggles. Once a payment network creates a special category to identify one type of lawful purchase, the way is open to spy on Americans through their spending. In this version of the bill, the protected category is firearms and ammunition. In a wider version, it could cover purchases related to mental health treatment, addiction recovery, religious materials, reproductive healthcare, or books on controversial subjects. Americans across the political spectrum should be wary of creating new mechanisms that catalog lawful, constitutionally protected activity through payment data. Merchant category codes were designed to classify businesses for payment processing, not to create dossiers on consumers. While the codes do not identify individual products, they can reveal that a customer patronized a particular kind of merchant. Combined with transaction amounts, locations, and other available data, they become another pixel in an increasingly detailed image of Americans’ private lives. PPSA has long warned that government agencies can often obtain commercially available data without the warrant requirements that would apply if they collected the same information directly. As financial surveillance capabilities expand, so do the opportunities for government access, private misuse, and mission creep. The Senate should therefore view the Protecting Privacy in Purchases Act as more than a firearms bill. It is an opportunity to establish that payment processors should not create specialized tracking categories for Americans engaged in lawful activities involving sensitive constitutional rights or deeply personal decisions. Imagine the government claiming it can open a box of your old letters without a warrant simply because you kept them for more than six months. Absurd? Under a Reagan-era federal law, that is roughly the legal logic applied to your emails. The Electronic Communications Privacy Act (ECPA), passed in 1986, was a landmark bill that established guardrails for the government’s treatment of private communications in the emerging digital world. At that time, emails were usually downloaded to a personal computer and deleted from servers. That law thus contained a loophole that allowed government agencies to obtain stored electronic communications more than 180 days old without a warrant. One tech provider warns that today that “Gmail will NOT automatically delete your old emails after any timeframe. Messages from 5, 10, or even 20 years ago will sit in your account forever unless you manually remove them.” Technology changed. The law didn’t. That is why PPSA applauds Reps. Warren Davidson (R-OH) and Suzan DelBene (D-WA) and Sens. Mike Lee (R-UT) and Ron Wyden (D-OR), for updating the law with the bipartisan Email Privacy Act. The bill would require the government to obtain a warrant before accessing the contents of Americans’ emails and other stored electronic communications, regardless of how long they have been stored. It would also permit service providers to notify customers when the government seeks their information, unless a court orders otherwise. “The Fourth Amendment is clear: the government must get a warrant before searching an individual’s private property, including written communications,” Rep. Davidson said. Sen. Lee similarly noted that “Americans should not lose their Fourth Amendment protections simply because their private communications are stored with a third-party provider.” They are exactly right. Our emails can contain medical information, financial records, family conversations, political discussions, and the intimate details of our daily lives. The idea that constitutional protection should diminish after 180 days is a relic of the dial-up era. This bill also demonstrates that privacy reform remains one of the few issues capable of bringing together serious conservatives and progressives. These legislators deserve our praise for recognizing a simple principle: a private communication does not become government property as it ages. Congress should pass the Email Privacy Act and apply the Fourth Amendment to the reality of 21st century technology. Jacqueline McNeill of Fayetteville, North Carolina, was driving home from the grocery store – with chicken to prepare for her goddaughter’s funeral, no less – when multiple police cruisers cornered her white Nissan Versa in the parking lot of a convenience store. “I felt like the moment I stepped out of my car,” she later told Tyler Dukes of Raleigh’s The News & Observer, “I was automatically guilty.” The second-grade teacher was arrested on the spot for a drive-by shooting. Jacqueline wasn’t guilty of anything, but that didn’t stop her from becoming a victim of automated license plate readers (ALPRs). Days before, these roadside cameras had spotted a car similar to hers in the vicinity of a shooting. As with so many other surveillance systems, police used this image in place of critical thinking, as visual proof when it was nothing of the sort. And now this far-less-than-foolproof technology – with the privacy protections of a rusted colander – is about to get a massive injection of mission creep. One of the makers of ALPR technology is Leonardo (pro tip before clicking: you might want to decline all cookies). According to Ian Wright of CarBuzz, the company’s SignalTrace technology “is set to move ALPR cameras from just car-tracking to people-tracking devices.” In plain language, that means tracking drivers’ and passengers’ smartphones, vehicle infotainment systems, and any other Bluetooth-capable device – all linked to your license plate or someone else’s. Worse, our devices are uniquely and individually identifiable. In the absence of robust legislation designed to bolster our Fourth Amendment rights, the only thing that can prevent them from being used as straight-up spy tools by authorities is end-to-end encryption. Wright reports the SignalTrace product sheet promises to “create a unique, trackable ‘electronic fingerprint’ for investigative use.” But wait, there’s more! The surveillance dragnet Leonardo is creating includes RFID tags (they’re everywhere, including key cards), pet microchips (so much for taking your dog along on errands), tablets, fitness trackers, tire pressure sensors, and… you get the idea. If there’s a kicker in all of this, it is another passage Wright quotes from the SignalTrace product sheet, which boasts that it “stores device and correlation data securely … for future queries and analysis.” The dystopian quantum leap, Wright notes, is that once implemented, ALPR systems will transition from identifying vehicles to identifying occupants. All of this data will be unbound by time, stored in a permanently searchable database – just in case we need to be retroactively suspected of something that may or may not have been legal once upon a time and that we may or may not have done in a car that we may or may not have been driving (or simply riding in). Calling Steven Spielberg: We just found the sequel to Minority Report. What could go wrong? To name a few risks: false positives; arrests of innocent people; police officers using ALPR systems for stalking and intimidation; and the collection of massive amounts of personal data by for-profit corporations ready, willing, and able to sell that information to any and all comers, including the government. Add to these risks hacking by cybercriminals and bad-faith state actors. It’s all coming to a technocratic authoritarian surveillance state near you. Because of her false arrest that day, Jacqueline McNeill never made it to her goddaughter’s funeral. She also largely avoided driving her Nissan before eventually selling it. And who can blame her? Wells v. State of Texas The U.S. Supreme Court’s decision Monday in Chatrie v. United States marked the biggest advance in digital privacy since Carpenter v. United States in 2018. By recognizing that Americans retain a reasonable expectation of privacy in digital location tracking, such as Google’s Location History records, the Court closed a major loophole in Fourth Amendment law. But Chatrie is unlikely to be the final word. Like Carpenter before it, the decision is likely to spark a renewed struggle over how to apply this precedent. One case worth watching is Wells v. State of Texas, which the Supreme Court Tuesday remanded to the Texas Court of Criminal Appeals. The facts are straightforward. In 2018, Dallas police investigating a fatal robbery obtained a geofence warrant directing Google to identify every device that had been present within a defined area around the crime scene during a 25-minute period in the early morning hours. The warrant eventually led investigators to Aaron Wells, who was convicted of capital murder. What makes Wells noteworthy is not the crime but the court's fractured reasoning. Like the Fourth Circuit in Chatrie itself, the Texas Court of Criminal Appeals produced no clear majority rationale. Four judges assumed that obtaining Google's location history constituted a Fourth Amendment search but upheld the warrant because it was supported by probable cause and was – in the language of the Fourth Amendment – sufficiently “particular” about what would be seized. Two of those judges separately explained that the geofence warrant did not involve a constitutional search at all, relying on theories that users surrender their privacy by sharing information with Google. Three other judges concluded that no search occurred for most of the data sought by the warrant. But they further explained that no probable cause existed either because the police obtained a warrant with only the location where a crime occurred, not a suspect. One judge dissented without opinion, and another did not participate. That division matters because Chatrie resolved the question about whether a search occurred, highlighting the importance of the remaining disagreement about the Fourth Amendment’s probable cause and particularity requirements. On that question, the Wells court was divided 4-3, with one justice dissenting but not explaining the basis for his dissent. Now after Chatrie, courts must focus on these difficult questions that divided the Texas Court of Criminal Appeals. In essence, courts will now focus on how broad is too broad. How many innocent people may be swept into an investigation before a warrant becomes the digital equivalent of the general warrants the Fourth Amendment was written to forbid? Those are not academic questions. Geofence warrants have already been used in investigations ranging from bank robberies to protests, and each new case forces courts to balance legitimate law enforcement needs against the privacy rights of countless bystanders whose only “crime” was being nearby. Carpenter reshaped surveillance law for nearly a decade. Chatrie promises to do the same. Cloud Data Should Not Be an Open Book for the Government Every day, Americans store their most personal information in the cloud. Our photos, messages, financial records, search histories, and private documents now reside on servers owned by tech companies like Google, Apple, Microsoft, and Snapchat. The question before the courts is increasingly simple: Does storing data with a third-party service provider mean surrendering your Fourth Amendment rights? PPSA is telling the U.S. Supreme Court the answer must be no when government pressure is exerted on highly regulated companies to search the content of Americans’ data. The case arises from a Wisconsin prosecution in which a file uploaded to Snapchat was flagged for potentially illegal content, namely suspected child sexual abuse material, by automated scanning software and reported to authorities. A law enforcement officer then conducted the first human review of that file without obtaining a warrant. The Wisconsin Supreme Court held that the user lacked a reasonable expectation of privacy because the data was stored with a third-party – Snapchat, which conducted the initial search – as permitted by its terms of service, which reserves the right to “screen” for illegal content. It is on this basis that the Wisconsin court determined that no warrant was needed. In our brief, PPSA demonstrates that such reasoning turns the Fourth Amendment upside down when such searches are conducted under pressure from the government. If the logic of this case is accepted, digital third parties can become vehicles for extinguishing constitutional rights. The Supreme Court rejected a similarly sweeping approach in Carpenter v. United States. In that landmark 2018 decision, the Court held that the government generally must obtain a warrant before accessing historical cell-site location records, even though those records were held by a third-party company. The Court recognized a basic truth about modern life: participation in the digital world requires us to entrust vast amounts of our lives to service providers. That necessity does not eliminate our expectation of privacy. This case offers the Court the chance to extend the principles of Carpenter with even greater force to cloud storage. Americans do not upload files to the cloud because they wish to expose them to government scrutiny. They do so because cloud services have become the digital equivalent of filing cabinets, photo albums, desk drawers, and personal archives. As PPSA demonstrates, earlier generations routinely entrusted private property and correspondence to third parties for storage, transport, or safekeeping without forfeiting constitutional protections. The same principle that protected privacy then should govern digital information today. This case also raises a troubling question about government outsourcing. Federal and state laws increasingly pressure technology companies to scan user content and report suspicious material. When companies perform searches because the government effectively requires them to do so, those searches begin to resemble state action rather than truly private conduct. As PPSA has shown, government-mandated reporting cannot become a loophole for bypassing the warrant requirement. The Supreme Court recognized in Carpenter that constitutional liberties must survive technological change. If the government can freely inspect because it has coerced third-party services into conducting searches, then one of the most important privacy protections in American law will become little more than a relic of the pre-digital age. While all decent people want to eradicate child sex abuse material, constitutional shortcuts used to detect heinous crimes create a new logic by which the government will be able to inspect content in cloud-stored data for any reason or no reason at all. PPSA is urging the Court to ensure that this does not happen. “The secret of man’s resistance to total power lies in his ability to live in truth. A power which rests on the total manipulation of reality cannot tolerate anyone who points to a reality beyond its control.” - Václav Havel Faith communities answer to a higher authority than the state. They preserve independent institutions, foster private associations, and teach moral truths that governments do not control. For that reason, churches, synagogues, mosques, temples, and religious ministries have often found themselves in the crosshairs of governments eager to monitor dissent. That is why Congress must repeal one of the most dangerous provisions added to FISA Section 702 in 2024 – the expanded definition of an Electronic Communications Service Provider (ECSP), commonly known as the “Make Everyone a Spy” provision. The ECSP expansion dramatically broadens the range of people and organizations that can be compelled to assist government surveillance, including most businesses that provide free Wi-Fi to customers and tenants. While the debate often focuses on privacy, the provision also poses a direct threat to religious liberty.
The chilling effect would be immediate. Individuals seeking spiritual guidance or personal counseling should never have to wonder whether their conversations could become part of a surveillance operation. History teaches us that such fears are not hypothetical.
Nor is religious surveillance a mere relic of the past.
And the danger is not confined to one political party. Just as the Biden administration’s treatment of traditionalist Catholics raised alarms, future conflicts between any administration and religious leaders could create similar temptations. Recent tensions between President Trump and Pope Leo XIV illustrate how quickly political disagreements can spill into disputes involving religious institutions. This is precisely why constitutional protections exist. The First Amendment protects not only the right to worship, but also the right to associate, counsel, organize, and speak freely within religious communities. Those freedoms depend on privacy and trust. Havel warned that governments seeking greater control cannot tolerate institutions that point to truths beyond official power. Religious communities do exactly that. They remind citizens that there are limits to what government may command and limits to what it may know. The ECSP expansion pushes in the opposite direction. It creates new opportunities for surveillance to penetrate institutions that have historically served as centers of conscience, dissent, and moral witness. Congress should enact the ECSP fix and restore the narrow definition of compelled assistance. No church, mosque, synagogue, pregnancy center, religious school, or ministry should be transformed into an unwilling arm of the surveillance state. Your landlord is watching you come and go – and it isn't to say hello Writing in Albany’s Times Union, Fabian Rogers and Jason Taper of privacy watchdog STOP remind us that invasive landlords are nothing new. What is new is the way facial recognition has quietly become a tool for controlling tenants. Landlords, for obvious reasons, don’t like rent-stabilization policies in many cities. Knowing this, technology firms are now marketing facial recognition products as a way to help landlords find new ways to evict people and raise rents (because, to de-regulate an apartment, you first have to empty it). There’s even a wink-wink industry term for this: “de-stabilize.” It’s a technological fishing expedition, and facial recognition tech is the rod. Park a camera at the only door, log every entry and departure, and wait to “catch” a tenant in violation of some technicality – an unauthorized overnight guest or a too-frequent absence that “proves” they don't really live there. Landlords will use all manner of red herring arguments to whitewash what they’re doing, such as claims of enhanced “safety and security.” In co-author Rogers’ own case, his Brooklyn landlord decided to implement a facial recognition system a mere year after the complex was declared rent-stabilized. Coincidence? The Trojan Horse pitch the landlord used was “frictionless entry.” Rogers and his fellow tenants weren’t fooled. After they organized, the landlord backed down. In the end, the tenants’ right to privacy trumped the promise of frictionless entry. This is just one example of how private companies are quietly assembling exactly the kind of always-on surveillance the Constitution forbids the government from building – and that is the loophole. The Fourth Amendment guards your home against the state; it has nothing to say about a property manager with a camera. New York's Senate Bill S8223 would ban landlords from using such tech. This makes sense: No one should have to build a tenant movement simply to preserve the basic freedom to come home without being tracked, watched, and cataloged by the place they live. We’ve long chronicled how China is building the world’s most sophisticated surveillance state. Cameras equipped with facial recognition software, biometric databases, digital tracking systems, and artificial intelligence have become commonplace across the country. Now, newly reported details reveal a Chinese surveillance apparatus that is even more expansive and well-integrated than previously understood. In a report by De Zheng for DW, a cybersecurity researcher discovered an exposed Chinese police database connected to a platform known as “Bright Eyes.” The system reportedly maintained extensive records on foreign journalists, visitors, and residents, including passport photographs, visa information, travel histories, and other personal details. But what makes Bright Eyes remarkable is not merely the quantity of data it collects. It is the way the system combines disparate information into what Chinese authorities call a “holistic personnel archive,” creating “holographic profiles” of individuals. According to the report, Bright Eyes integrates data from facial-recognition cameras, immigration records, hotel registrations, transportation systems, mobile-phone identifiers, and other databases. The system reportedly can identify not only that a person traveled but also precisely where that person sat on a train, when he entered a venue, and who was nearby. De Zheng notes: “It even synchronizes photos from different camera systems and checkpoints, creating a continuous visual record of a person's movements.” Because the system has access to multiple streams of information, authorities can reconstruct a person's activities with extraordinary precision. Officials can analyze not only an individual's movements but also relationships, routines, and patterns of behavior over time. Perhaps most striking is the system's apparent emphasis on social connections. The report describes analytical tools designed to determine “how frequently targets are captured interacting on camera, revealing exactly who knows who, and how much time they spend together.” The system maps human networks for social and political analysis. China’s surveillance architecture offers a warning about the direction technology can take when constitutional constraints are absent. The technologies involved – artificial intelligence, facial recognition, data aggregation, and predictive analytics – are becoming more powerful. The Solomon Islands in the South Pacific provide a stark example of how this surveillance state can be exported. David Pierson and Berry Wang of The New York Times detailed the pushback by local residents after China installed its “model police state” through a secret agreement with that country’s government. The Australian Strategic Policy Institute warned that the Solomon Islands is becoming China’s “proving ground for authoritarian practices under the guise of community service.” An official mouthpiece of the Chinese government described such Western reactions as “the discomfort of former colonial powers whose exclusive influence in the Pacific is no longer assured.” But who is the real imperialist in this scenario? The lesson for Americans is straightforward. Privacy is more than a setting. It is the condition that makes free speech, free association, religious liberty, and a free press possible. Once governments acquire the ability to know everything about everyone, the freedoms guaranteed by the First and Fourth Amendments become increasingly difficult to exercise in practice. China’s “holographic profiles” show why constitutional limits on surveillance matter now more than ever. That’s something for Congress to keep in mind when it considers whether to revisit surveillance policy in the ongoing Section 702 debate in two years or much longer. The speed at which artificial intelligence is evolving should lead Americans to insist that Congress keep a tight leash on any would-be American version of Bright Eyes. When you hear of a new surveillance program being marketed as a child-safety initiative, give it particularly close scrutiny. History shows that the narrower and more compelling the stated justification for a surveillance plan, the broader and more outlandish the surveillance will actually be. A newly reported example comes from BusPatrol, a company that has installed AI-powered camera systems on more than 40,000 school buses in 24 states. The cameras have been marketed as a way to identify drivers who ignore the fold-out “STOP” arm signs from buses and illegally pass them while stopped. Joseph Cox of 404 Media reports that BusPatrol is now planning a dramatic expansion of its mission. Leaked company documents reportedly show plans to convert school buses into roaming automatic license plate reader (ALPR) platforms that would capture information on every vehicle a bus passes, regardless of whether any crime or traffic violation occurred. The resulting data would then be sold to law enforcement. A system designed to document a specific violation at a specific moment is fundamentally different from a system that continuously records the movements of everyone nearby. In effect, school buses would become mobile surveillance vehicles. Under the proposal, cameras would photograph vehicles, record their license plate numbers, and attach GPS location data. Law enforcement and possibly other actors could then query those records to reconstruct a vehicle's travel history. As privacy advocates have long warned, tracking a car often means tracking a person. These bait-and-switch tactics are familiar. After the attacks of September 11, Americans were told that extraordinary surveillance programs were necessary to prevent terrorism. Many of those authorities later expanded far beyond their original scope. Section 702 of FISA was enacted to monitor foreign threats overseas, yet the communications of millions of Americans became subject to warrantless searches. From the UK to Congress, we’ve seen how the fight against child sexual abuse material has been used as a shield to threaten the encryption that protects women and children from stalkers, journalists from vengeful politicians, businesses communicating about proprietary information, and millions of law-abiding Americans who want to have a digital conversation without Big Brother listening in. Government agencies have repeatedly justified the acquisition of vast quantities of personal data by pointing to legitimate public concerns, only for those powers to evolve into broader surveillance tools. BusPatrol's reported plans follow the same trajectory. A narrowly tailored safety program aimed at preventing children from being struck by passing vehicles could become a platform for collecting location information on millions of ordinary Americans who have done nothing wrong. The danger is not merely the collection of data. It is the normalization of surveillance infrastructure. Every new camera network creates pressure to find new uses for the information it gathers. Indeed, BusPatrol’s internal documents suggest that this latest move is in response to investor demands for new revenue streams. Protecting children is a worthy goal. Turning school buses into rolling location-tracking platforms is not. Americans should be wary whenever government agencies or private contractors ask them to trade away privacy in exchange for safety. Proposals like this need their own mounted “STOP” arm signs. “The Founding Fathers would roll over in their graves if they knew the government was able to demand a list of everyone a person called and texted, everyone who watched a YouTube video or visits a website, or uncover anonymous social media accounts, all without a warrant or court order of any kind.” - Sen. Ron Wyden During the Biden administration, Special Counsel Jack Smith obtained the phone records of 20 current or former Republican Members of Congress during the federal probe of Donald Trump. Before that, the Department of Justice under the Trump administration obtained the phone records of two Democratic Members of Congress and 43 congressional staffers from both parties. Administrations of both parties have held such actions to be perfectly legal, despite their being obvious violations of the Fourth Amendment’s requirement for a probable cause warrant before inspecting our personal information. “Americans’ constitutional rights should not disappear just because they made a phone call or sent a text,” said Sen. Cynthia Lummis (R-WY). “Yet today, federal agencies can secretly demand your phone records and personal data from tech companies as often as they want without ever stepping inside a courtroom. This kind of unchecked power is something you’d expect under the Chinese Communist Party, not in the U.S.” “The very term ‘administrative subpoena’ is an oxymoron that is offensive to the Fourth Amendment,” said Bob Goodlatte, PPSA Senior Policy Advisor and former Chairman of the House Judiciary Committee. “It avoids judicial oversight and gives the executive branch the ability to make legitimate-sounding demands to inspect our houses, papers, effects, and data, when it is in fact just illicit government overreach.” To rein in this clearly unconstitutional surveillance practice, Sens. Ron Wyden (D-OR), and Cynthia Lummis, along with Reps. Adriano Espaillat (D-NY), Thomas Massie (R-KY), Robin Kelly (D-IL), and Eric Burlison (R-MO) released the Subpoena Abuse Prevention Act – a bill that would require the government to go before a judge in order to obtain phone records. It would also prevent the use of subpoenas against phone and tech companies to spy on Americans for engaging in speech or other constitutionally protected activities. The Subpoena Abuse Prevention Act would:
“The laws protecting Americans’ rights aren’t keeping up with advances in government surveillance,” Sen. Wyden said. “This bipartisan, bicameral bill rebalances the scales to protect our constitutional rights against unnecessary intrusion by the federal authorities.” Goodlatte commended the sponsors of this bill for pushing back against a growing practice that endangers our constitutional rights. “PPSA is proud to support this corrective legislation,” he said. Throwing Out the Baby (Privacy) With the (Robocall) Bath Water Robocalls are incredibly annoying, and the public’s frustration with them is entirely justified. Consumers should not have to endure endless scam calls, spoofed numbers, and invasive solicitations. Reasonable regulation of commercial robocalling is both necessary and constitutional. Businesses do not have a First Amendment right to anonymously bombard Americans with sales pitches, demands for personal information, or manipulative solicitations. At the same time, the effort to curb robocalls should not come at the expense of the privacy rights of ordinary Americans. Mike Pearl at Gizmodo reports that some critics fear the FCC’s proposed cure “might be worse than the disease,” at least from a privacy standpoint. It’s already the case that tracking technology has made traveling in our vehicles far from the anonymous refuge it once was. According to watchdog groups, the FCC’s plan could have a similar effect on phone communications by creating what Ken Macon of Reclaim the Net describes as “an identity-verification regime covering one of the last semi-anonymous communication tools available to ordinary Americans.” Among the FCC’s proposed changes are restrictions that could effectively eliminate burner phones while imposing extensive identity-verification requirements on customers. Telecom law firm Wiley reports that both new and returning customers could be required to present government IDs and provide physical addresses, legal names, and alternate phone numbers. “High-volume” customers could face even more scrutiny, including disclosure of IP addresses and intended phone usage. There is a meaningful distinction, however, between anonymous commercial solicitation and the legitimate use of privacy-protective communications tools by ordinary people. Businesses making robocalls to sell products or collect data should be regulated. But burner phones and other forms of semi-anonymous communication also serve lawful and socially valuable purposes. These include:
According to Phil Clark at Mashable, the FCC’s proposed “red flags” are broad enough to encompass many ordinary and lawful activities, including using virtual offices, paying with cryptocurrency, maintaining unusual email addresses, or having phone numbers not tied to residential addresses. Critics worry that such criteria could sweep too broadly and normalize extensive identity tracking for routine communications. The challenge for policymakers is to strike the right balance. Americans deserve meaningful protection from robocalls and phone scams. But regulations aimed at bad actors should be carefully tailored so they do not create a universal government registration system for everyone who purchases or uses a phone. Canada’s “Lawful Access” Bill Raises Alarm in Congress Over Encryption and Americans’ Privacy5/18/2026
Two powerful House committee chairmen are warning that a sweeping Canadian surveillance proposal could undermine the privacy and cybersecurity of Americans by pressuring U.S. technology companies to weaken encrypted services. At stake is the privacy of Americans who depend on robust encryption to protect sensitive communications, health data, financial records, and personal communications from unwarranted intrusion. In a May 7 letter to the Canadian Minister of Public Safety, House Judiciary Committee Chairman Jim Jordan and House Foreign Affairs Committee Chairman Brian Mast expressed concern that Canada’s proposed “Lawful Access Act of 2026,” known as Bill C-22, would dramatically expand the Canadian government’s ability to compel access to encrypted data. The lawmakers wrote: “Canada’s Bill C-22, currently under consideration in Parliament, would drastically expand Canada’s surveillance and data access powers in ways that create significant cross-border risks to the security and data privacy of Americans … “Bill C-22 would allow Canadian government officials to compel American companies to build backdoors into their encrypted systems, thereby introducing systemic vulnerabilities that could be exploited by hackers, foreign adversaries, and cybercriminals.” At the center of their concern is the requirement for “electronic service providers” to enable government access to data. The bill also authorizes confidential “ministerial orders” compelling providers to comply with demands, while prohibiting disclosure of those orders. “Dangerously Vague” Jordan and Mast argued that these powers are dangerously vague and compel weakening of encryption technologies. They wrote: “If a U.S.-based provider is forced to redesign its system to facilitate Canadian authorized access to content that is currently inaccessible even to the provider itself, the resulting capability cannot be geographically limited.” This could open the way for hostile actors and states to steal Americans’ data at a massive scale. The chairmen referenced the 2024 “Salt Typhoon” intrusion as evidence that government-mandated access points inevitably become attractive targets for hostile actors. Privacy and civil liberties advocates are voicing similar concerns. The Electronic Frontier Foundation warned that Bill C-22 would provide “a mechanism for the Minister of Public Safety to demand companies create a backdoor to their services,” while Meta stated publicly that the bill could “break, weaken, or circumvent encryption.” Endangers the Vulnerable PPSA has long warned that mandates weakening encryption in one democratic nation inevitably create ripple effects far beyond national borders. Breaking secure encryption could endanger journalists, dissidents, religious minorities, businesses, attorneys, and ordinary citizens from criminals and hostile foreign actors alike. Jordan and Mast urged Canada to pursue formal cooperation mechanisms under the CLOUD (Clarifying Lawful Overseas Use of Data) Act framework, which allows cross-border access to digital evidence while preserving legal safeguards and judicial oversight. As Congress debates surveillance reform at home, the dispute over Canada’s Bill C-22 underscores a growing international reality – efforts by governments to weaken encryption abroad can directly threaten the privacy and cybersecurity of Americans at home. House Appropriations Committee Advances Privacy Protections Against Data Brokers and AI Surveillance5/14/2026
The House Appropriations Committee took a big step toward closing one of the most dangerous loopholes in modern surveillance practices. On Wednesday, lawmakers adopted an amendment by Rep. Adriano Espaillat (D-NY) that would prohibit the government from buying Americans’ sensitive personal data from data brokers without judicial oversight. The amendment mirrors the bipartisan Fourth Amendment Is Not For Sale Act, legislation previously passed by the House in 2024 with strong support from members of both parties. The issue is straightforward: Federal agencies increasingly obtain Americans’ location histories, browser records, app usage, and other sensitive digital information by purchasing them from private data brokers rather than seeking a warrant from a judge. This practice is an end-run around the Fourth Amendment. And yet, this is a common practice in the federal government. Agencies from the FBI to the IRS, the Department of Homeland Security, and the Department of Defense routinely use commercially available data to obtain information that otherwise would require a judge-issued warrant. PPSA has long opposed these practices and supported reforms aimed at curbing warrantless surveillance. Our efforts have focused not only on traditional government data collection but also on the rapidly growing ability of artificial intelligence systems to aggregate and analyze commercially purchased data into detailed personal dossiers. “AI tools can now synthesize purchased location records, browsing behavior, buying history, social media activity, and other streams of data into comprehensive profiles of Americans’ lives, associations, religious practices, political activity, and daily routines,” said Bob Goodlatte, former Chairman of the House Judiciary Committee and Senior Policy Advisor to PPSA. “A government agency that cannot legally compel a person to turn over information directly should not be able to purchase it indirectly from a data broker.” The “data broker loophole” has become one of the defining privacy controversies of the digital age. As multiple civil liberties groups and lawmakers have noted, the government increasingly treats commercially available data as exempt from constitutional scrutiny, even when that same data reveals the whole of a person’s movements and activities. The bipartisan concern surrounding this issue has been building for years. The original Fourth Amendment Is Not For Sale Act drew support from lawmakers as ideologically diverse as Reps. Warren Davidson, Jerry Nadler, Thomas Massie, and Zoe Lofgren, as well as Sens. Mike Lee, Ron Wyden, and Rand Paul. In 2024, the House passed this legislation by a bipartisan vote of 219-199. Now the Espaillat amendment revives that effort, marking continued momentum for privacy protections, especially in the current debates over Section 702 surveillance authority in Congress. “Most heartening of all, the House Appropriations Committee’s actions show that support for surveillance reform is broad, deep, and bipartisan,” Goodlatte said. “At stake is a basic constitutional principle – the federal government should not be allowed to pull out its wallet and buy its way around the Bill of Rights.” The Associated Press last year wrote a landmark series of six stories about the role that U.S. tech firms play in global surveillance, particularly in China. “Made in America, Watched Worldwide,” just won a Pulitzer for international reporting. The award is richly deserved, honoring the efforts of multiple journalists who worked painstakingly on the project for three years. Celebrating their efforts is an opportunity for all of us in the privacy community to reflect not only on the AP’s key findings but also on the ominous realization that the technology described is homegrown. In other words, it can just as easily be sold to U.S. agencies and directed at the American people. That’s over 90,000 distinct entities when you add up the total number of federal, state and local government operations. In other words, U.S. technologists not only helped design the Chinese surveillance state, we’re also not that far from having one ourselves. This danger is growing more acute with the ability of AI to transform information into actionable knowledge and to turn individual data points into personal dossiers. So let’s think about that as we briefly summarize the AP’s topline findings. Everything in this list is all-too-easily capable of being implemented here in the United States:
One of the heroes of AP’s reporting is longtime Chinese activist Zhou Fengsuo. Arrested and imprisoned as a student leader during the Tiananmen protests, the now-U.S. citizen Zhou testified before Congress in 2024, warning that the lack of privacy guardrails and meaningful reform “is a strategic failure by the United States.” Current legal guardrails on American surveillance are not keeping pace with advancing technologies and questionable partnerships unmasked in AP’s series. And that gap underscores the urgent need for robust reform of surveillance laws – before these untethered AI networks are fully (and permanently) turned inward. Congress should take a deeper look into the technologies U.S. companies are selling to China and other adversarial nations – and how they are being deployed here. The rapidly escalating power of AI should especially make it clear why the House leadership proposal to extend FISA Section 702 for three years is unacceptable. Does That Make It Okay for American-Made Cars to Spy on Us as Well? If Chinese-made cars are “surveillance packages on wheels,” as one U.S. senator warns, then Americans should ask a harder question: Why are we comfortable driving surveillance packages built at home? Why You Currently Can’t Buy Chinese Cars China’s BYD electric cars are a marvel. Well-crafted with roomy interiors, stuffed with lots of high-tech bells and whistles, and efficient charging, they would, if sold in the United States, provide tough competition to American-made electric cars. But you cannot buy a BYD in the U.S. market. They are still banned under a Biden-era rule forbidding Chinese automotive software and hardware, along with a prohibitive 100-percent tariff on Chinese cars. Now President Trump is reported to be considering a deal with PRC leader Xi Jinping to allow China to enter into U.S. joint ventures with American automakers to make them here. A Bill to Outright Ban Chinese Cars Enter Sens. Bernie Moreno (R-OH) and Elissa Slotkin (D-MI), who have introduced the Connected Vehicle Security Act, which would ban Chinese-made connected vehicles and their hardware and software components from the American market. What do they mean by “connected”? These senators note that Chinese-made cars can collect, process, and transmit the geolocation, operational, and personal information of drivers and passengers. That is why Sen. Slotkin, who served in the Central Intelligence Agency before entering politics, called Chinese cars “surveillance packages on wheels, with the ability to collect on American citizens and sensitive sites.” The bill’s language not only targets these cars for their espionage potential, but also – more alarmingly – for the possibility of their “remote takeover” on American roads. It is likely no coincidence that these two senators are from two states known for their U.S. car plants and large electoral blocs of American autoworkers. Sen. Moreno, who owned car dealerships before his election, said that “the fate of the American auto industry and countless autoworkers depends on” a ban on Chinese cars. Clearly, protectionist sentiment is at play here. But it is also undeniable that Sen. Slotkin is right – Chinese-made goods incorporate surveillance as a feature, not a bug. As we’ve reported, even Chinese-made toasters and baby monitors are a concern. With cars, as with toasters, “Made in China” should come with the warning “Watching from China.” American Cars Are “Surveillance Packages on Wheels,” Too The senators’ proposal overlooks the built-in surveillance features of cars made in America, as well as those from friendly allies like Japan, Korea, and Germany. Cars to be sold next year must adhere to the Biden-era drunk driver detection systems. In a new car in 2027, if you appear to be impaired – perhaps rattled because you urgently need to drive someone to the ER – you might find your car disabled by a kill switch. Privacy advocates are alarmed by proposals to use cameras and microphones to scan drivers for signs of impairment. Would conversations be recorded and kept in a database? Would every passenger be logged as well? Even now, the seats in our cars record our weight, and our GPS systems and tire-pressure monitoring systems track, record, and report where we go. Given China’s recent behavior, skepticism about Chinese software and hardware on the roads is well deserved. And certainly Xi’s regime is nothing if not malevolent toward America. But let’s not kid ourselves – automotive surveillance is a Made-in-America threat to privacy, too. Congress should hit the brakes – or at least establish guardrails – on the surveillance systems in the cars we already drive every day. Colorado Man’s Flock Nightmare Futurism and other sources report that Kyle Dausman can’t go anywhere in his truck without being swarmed by police. It’s all thanks to a glitch in the Matrix – er, in the Flock Safety camera surveillance system – used by authorities across the state of Colorado. Seriously, this is one of those stories that would be a lot funnier if it were about an average guy named Klaus who lived in the East German police state circa 1986. After stopping him a couple of times, the Cherry Hills Police Department quickly realized that a dubious clerical strategy was responsible for flagging local resident Dausman in the statewide Colorado Crime Information Center database. Because the Centennial State, like others, uses both zeroes and letter Os in license numbers: “Sometimes the data entry will be for both" versions of a plate when an arrest warrant is issued, Cherry Hills police chief Jason Lyons told Denver’s KUSA. A clerk filing a warrant in another county apparently did exactly that in Kyle Dausman’s case, entering both the “0” and “O” versions of the actual offender’s tag, according to the Cherry Hills chief. He also noted, pointedly: "It wasn't a mistake.” Poor Dausman just happened to be the guy with the innocent-yet-incorrect tag sequence. "Everywhere in the state, every time I pass a camera,” laments the victim, “they get alerts in their car that I'm in the area." He justifiably worries for his family’s safety as well as his own. Colorado should order its clerks to stop conflating zeros and Os. Why does the state – like many others – continue to put innocent people in harm’s way? This could be fixed with one executive order from the governor. At least the local police department in Cherry Hills fixed the flag in its local database. But beyond that, Dausman is on his own, and largely without recourse according to the details of various reports: The Colorado Crime Information Center hotlist still shows him as a wanted man, and no one is sure who has the actual authority to address the situation. All of which is to say nothing of actual reform (which lives only on best practice wish lists for now). Dausman’s experience, writes Al Landau for Gadget Review, is emblematic of a fundamental problem with large-scale, big-data-powered surveillance systems like the Flock Safety networks popular across Colorado: “Flawed data produces harmful results, regardless of camera sophistication.” A process, he says, that amplifies bad data practices, potentially turning them into “major personal nightmares.” Like a coal miner’s canary, this story warns not just about the anti-privacy plate-reader industry, but about the dangers of public partnerships with Big Tech that fuels the growth of the modern surveillance state. In the meantime, privacy-loving pro-Fourth-Amendment citizens who want to keep tabs on Flock’s invasive alliances with law enforcement can do so on an advocacy site appropriately called DeFlock. How “Ghost Tapping” Can Pull Cash Out of Your Accounts – and the Best Ways to Guard Against It5/5/2026
Like so many high-tech conveniences, tap-to-pay comes with some privacy and security pitfalls. The same debit and credit cards that have this capability can also be remotely exploited by “ghost tapping,” a hack that can drain funds from your bank accounts in seconds. Click below to get a quick overview of this risk, along with a review of ways to protect your cards – what these solutions cost and how well they work. Short answer: Yes. Longer answer: Hell, yes. Carter Page, a former foreign policy advisor to the 2016 Trump presidential campaign, will be paid $1.25 million to settle claims for surveillance that resulted from an FBI that knowingly made untruthful claims against him before the secret Foreign Intelligence Surveillance Court (FISA) Court. At a time when history is measured in news cycles, this may seem like ancient history to many in Washington. And yes, the Page debacle concerned Title I of FISA, a different surveillance authority from the FISA Section 702 authority, whose reauthorization is now the subject of intense debate in Congress. But the Carter Page ordeal is well worth revisiting. It does, in fact, have a lot to say about the current Section 702 controversy. The Essentials of the Carter Page Debacle The FBI obtained four improperly obtained surveillance orders from the secret FISA Court to surveil Page. Under the law’s “two hop” rule, these orders not only allowed the FBI to spy on Page; they also allowed the FBI to spy on anyone Page communicated with (such as the Trump campaign manager) and anyone that person communicated with (the candidate himself). One doesn’t have to be an admirer of Donald Trump to find it beyond dangerous for the FBI to investigate a presidential campaign, and ultimately the candidate himself, in the middle of a national election. This is especially true when we consider that the whole investigation was predicated on lies the FBI told the court, accompanied by a forgery in the form of a document altered by an FBI attorney. Does that sound overwrought? Consider: The four secret surveillance orders were the direct result of the Department of Justice and the FBI committing acts of omission and commission in their representations to the FISA judge in 2016 and 2017. Department of Justice Inspector General Michael Horowitz – a Democrat, by the way – conducted an exhaustive investigation that identified 17 “significant inaccuracies and omissions in each of the four applications.” The FBI, in its surveillance application for Page, did not inform the court that the basis of its suspicions – an intelligence report produced by a dodgy ex-MI6 officer, Christopher Steele – was something that the Bureau itself had concluded was completely unreliable. Indeed, the “Steele dossier’s” most salacious report, that Russian intelligence had a “pee tape” of Trump cavorting with micturating prostitutes in a Moscow hotel room, was later determined by Horowitz’s investigation to have started as a bar joke. Not only did the FBI know that the basis for probable cause presented to the court was sketchy, but it also falsified evidence. Former FBI lawyer Kevin Clinesmith would later plead guilty to altering an email from the CIA that he had submitted as evidence to the court. What had been altered? The court asked if Carter Page had a connection to the CIA. He had, in fact, been a secret operational contact for the CIA, which had given Page its highest rating for dependability. The FBI attorney altered that CIA document, changing it from affirming Page’s relationship with that agency to denying it. Some Obvious Conclusions We admit to feeling a little personal about this. PPSA attorneys have represented Page in his quest for justice. We can attest that Page – who was subjected to repeated FBI interrogations and a day-long examination before a grand jury – spent months in a lonely, personal hell. Had Page made the slightest mistake in his recollections, he could have been sentenced to years in federal prison. He deserves every penny of this settlement. But the takeaway for the public and every Member of Congress – Democrats as well as Republicans – should be what this story tells us about Section 702. It has been revealed that under Section 702, the FBI secretly surveilled U.S. Senators and U.S. Representatives, a state judge, political and religious organizations, and journalists. If the FBI is willing to be this disingenuous before a federal judge, just imagine what it might be willing to do with the communications of everyday Americans obtained by Section 702 programs that are usually warrantless and lack direct judicial oversight of individual queries. Far from being ancient history, the Carter Page ordeal is a constitutional cautionary tale – one Congress ignores at the peril of every American’s Fourth Amendment rights. Chatrie v. United States The U.S. Supreme Court set the first warrant requirement for Americans’ location data in 2018. Chief Justice John Roberts, writing for the majority in Carpenter v. United States, declared that when the government “tracks the location of a cell phone it achieves near-perfect surveillance, as if it had attached an ankle monitor to the phone’s user.” Though the Court’s ruling set a warrant standard for the extraction of historic cell phone data from cell towers, Carpenter failed to become a general precedent for using other means to geolocate Americans – such as tracking people through their phones. On Monday, the U.S. Supreme Court heard oral arguments in a case that has the potential to become the next landmark ruling. If the sharp questions of the Justices are any indication, they may well limit the government’s ability to conduct large geolocation sweeps that can compromise the privacy of large numbers of Americans. The case involves Okello Chatrie, convicted of bank robbery near Richmond, Virginia, after local authorities used a geofence warrant for the area of that crime and picked up Chatrie’s phone at the scene. Hundreds of other people within the area geofenced by police were also pinned, including guests at a Hampton Inn, residents in an apartment house and a retirement home, and diners at a Ruby Tuesday restaurant. What’s the big deal, you ask, if this maneuver helped catch a bank robber? As a lower court judge noted, with such a procedure – this time a warrant issued to Google – everyone within the designated perimeter “has effectively been tailed.” Even when such technology is used for a clear purpose, such as locating a bank robber, the precedent opens the way for the government to track Americans’ associative activities, from protests to political activity to worship. In its questioning, the Supreme Court recognized the Orwellian possibilities of this technology. “What’s to prevent the government from using this to find out the identities of everybody at a particular church, a particular political organization,” Chief Justice Roberts asked the government’s lawyer. “What are the restraints that would prevent that from becoming a problem?” Adam G. Unikowsky, Chatrie’s attorney, characterized geofence warrants as fishing expeditions that “search first and develop suspicions later.” Unikowsky told the Justices: “The technology may be novel, but the constitutional problem it presents is not. The potential for abuse is breathtaking: The government need only draw a geofence around a church, a political rally or a gun shop, and it can compel a search of every user’s records to learn who was there.” The Justice Department lawyer had a tough time arguing that Chatrie did not have a reasonable expectation of privacy for location history data that his phone shared with Google. Justices Neil Gorsuch and Sonia Sotomayor asked questions showing a concern that the government’s position could be expanded to include emails, photos, and documents, as well as location data. The Justices also questioned the extent to which Americans are even aware that their cell phones enable tech companies to track their locations in a way that can be shared with the government. These questions echoed the PPSA amicus brief, in which we told the Justices: “Letting a plumber into your house to fix a sink does not mean you have no expectation of privacy when the police come knocking.” A little levity came to the proceedings when Justice Amy Coney Barrett said she was shocked by how many ads she saw on her phone that were triggered by her visits to specific locations. “I need to check my location settings, plainly,” she said, triggering laughter throughout the courtroom. Judging by the questioning, it appears that this case may, at the very least, lead to some tightening of mass geofencing. PPSA hopes that all the Justices will agree with our brief in which we declared: “The Founders would have been shocked to see privacy brought to this sorry state.” Congress made a solemn promise on surveillance reform to the American people in public, only to break it in private. As a result, the “Make Everyone a Spy” provision allows the government to conscript office-space providers – including those who rent space to media organizations, law firms, and political campaigns – into enabling warrantless surveillance through their buildings’ internet networks. Even churches and other houses of worship can be targeted. As the House debates the reauthorization of Section 702, PPSA and our followers call on House leadership to deliver on this very public promise to narrow the provisions of a loophole in the definition of government electronic communications service providers (ECSP) in Section 702 of the Foreign Intelligence Surveillance Act. How We Got Here When FISA Section 702 was reauthorized in 2024, it included a provision that was intended to allow the government to compel the cooperation of one particular type of company, believed to be providers of cloud computing, to respond to requests for data for national security purposes. The broad language of this provision, however, allows the National Security Agency to secretly demand access to communications equipment from almost every U.S. business or non-profit organization. During the Senate debate on this intelligence legislation in 2024, key lawmakers admitted that their draft language was overly broad. They insisted there was no time to fix it, but assured their colleagues that after passage they would work to narrow the ECSP language, making a “technical fix” to ensure that only appropriate entities could be compelled to assist in surveillance. House Intelligence Committee leaders indicated openness to that correction, calling it “totally fine.” As the U.S. House of Representatives once again moves forward on the next reauthorization of Section 702, that promised fix has been ignored by both houses of Congress for two years. Basic Liberties at Stake The ability to surveil foreign threats is vital to protecting the homeland and the American people. But PPSA is firm in the conviction that we can have robust surveillance of terrorist and cybersecurity threats without allowing our government to regularly spy on the American people – especially with massive databases supercharged by AI. For that reason, we ask House leadership to embrace several key reforms. · First, warrants must be required before Americans’ communications, swept up in NSA’s global trawl, can be accessed by the government. · Second, the secret FISA courts should be required to rely on qualified amici – civil liberties experts with high-level security clearances – to represent the larger constitutional concerns of the American people in sensitive cases. · Third, the House should close the “data broker loophole” that allows government agencies to sidestep the Fourth Amendment by buying Americans’ search histories, geolocation histories, and communications from shady, third-party data brokers. · One more obvious reform is the one already promised: The House must address the “Make Everyone a Spy” provision before reauthorizing Section 702. It is unconscionable that the NSA can conscript vast swaths of American businesses and non-profit organizations that provide ordinary services, such as Wi-Fi, into a domestic spying operation on customers, tenants, and congregants. This ability of the government to spy on media, law firms, political organizations, and religious groups trashes both the First and Fourth Amendments. This is more than a failure in legislative oversight. It is a breach of trust. Just as bad, when combined with other unresolved problems, such as Section 702’s warrantless “backdoor searches,” and the government’s purchase of sensitive personal data by a dozen government agencies, Congress has set the stage for a genuine American surveillance state. Fortunately, the House has no lack of solutions. Bipartisan proposals – from Rep. Andy Biggs’s Protect Liberty and End Warrantless Surveillance Act to the Government Surveillance Reform Act, sponsored by Rep. Warren Davidson and Rep. Zoe Lofgren – contain language that would narrow the ECSP definition. Since Senate leaders did not deliver the ECSP fix earlier in their own chamber, the responsibility now falls squarely on the House. Leadership should not move forward with any intelligence package that ignores this commitment or relies on vague assurances that reforms will come “later,” behind closed doors. Anything less would confirm the worst suspicions of the American people – that when it comes to surveillance, a promised reform is always just one vote away, one that never quite arrives. Click here to tell House Speaker Mike Johnson to drop any attempt at a clean reauthorization of FISA Section 702 that rejects reasonable domestic surveillance reforms. The Wall Street Journal Is Wrong – We Can Reform Section 702 Without Endangering National Security4/14/2026
Did you see The Wall Street Journal editorial Monday morning entitled “Playing National Security Roulette”? The editors argue that anything less than a clean reauthorization of the FISA Section 702 surveillance authority will “put the lives of Americans at risk.” The Journal editors acknowledge that this authority, enacted by Congress to surveil foreign threats abroad, was misused by FBI agents who ran searches on political protesters, political donors, and Members of Congress. “But the intelligence community has since instituted safeguards on how searches must be authorized,” the editors tell us. Thus, according to The Journal, adding any amendments to Section 702 would be a reckless gamble with national security – and reforms are not needed anyway, because the Reforming Intelligence and Securing America Act (RISAA) fixed all the problematic parts of Section 702. Wrong on both counts. Reforms Would Not Compromise National Security Reformers want to amend the law to make the program consistent with the Fourth Amendment by requiring probable cause warrants before inspecting Americans’ communications. But the warrant requirement being proposed for surveillance of Americans contains very clear exceptions for “exigent circumstances,” such as terrorist threats, as well as exceptions for every single other type of search the administration has claimed is helpful in protecting national security, including defenses against cyberattacks. Not only would these reform proposals allow the FBI to proceed without obtaining a warrant in an emergency, but the Bureau would also have great latitude as to what constitutes an emergency. In short, warrants would be required in cases where the government is conducting a fishing expedition with no nexus to national security – such as an agent searching for the communications of his Tinder date, or searching for the communications of thousands of donors to a congressional campaign – but would not be required in exigent cases with national security implications. The FBI Continues to Violate the Law A FISA Court opinion in March 2025 revealed that the FBI had been systematically violating statutory requirements. In August 2024, DOJ overseers learned that the FBI was operating a “filtering” tool that allowed it to query Section 702 data under the radar. These U.S. person “searches” or queries were not counted, tracked, or audited, nor were they approved by an attorney or supervisor, as required by law. Thus, the actual number of U.S. person queries for 2024 remains unknown and outside of any audits. A new FISA Court opinion found that the systemic violations continue. According to The New York Times and The Washington Post, the FISA Court issued a classified opinion that reportedly reveals that even though DOJ shut down the filtering tool the FBI used in 2024, the FBI has been using another, similar filtering tool to conduct queries without following the requirements of RISAA. Thus, the systemic violations of RISAA are not fixed. They are ongoing. In Summary: The warrant requirement proposals contain sufficient exceptions to counter potential terrorists, cybersecurity attacks, and other threats to the American people. And contrary to The Journal’s assertion that the RISAA “reforms appear to be working,” they are clearly not. One final note – while the reauthorization of the Section 702 statute has an April 20 deadline, FISA Court surveillance orders are in effect through next spring. The House has plenty of time to debate these reform measures. There is no need for the kind of panic The Journal – obviously influenced by intelligence community spin – is fomenting. Immigration and Customs Enforcement (ICE) is now using powerful “zero-click” commercial spyware that can break encrypted communications – a step that should alarm anyone concerned about privacy, civil liberties, and constitutional limits on government surveillance. At the center of the NPR story is “Graphite,” a tool developed by Paragon Solutions. Unlike traditional hacking methods, Graphite relies on “zero-click” exploits – meaning it can infiltrate a phone without the user doing anything at all. No suspicious links. No malicious attachments. Just silent compromise. If that sounds familiar, it should. As PPSA has previously warned in our analysis of Pegasus spyware, zero-click tools represent the cutting edge of surveillance: invisible, unaccountable, and extraordinarily intrusive. Like a pathogen spreading without contact, they turn personal devices into government multimedia surveillance devices. From Counterterrorism to Domestic Use ICE says the technology is aimed at dismantling fentanyl trafficking networks and other serious threats. But NPR’s reporting raises serious concerns about how broadly such tools might be used – and against whom. ICE has expanded its surveillance footprint domestically, including monitoring protests and other constitutionally protected activities. The risk is clear: tools justified for national security can quickly veer into routine domestic enforcement – or even the surveillance of constitutionally protected protests. Once established, Graphite will almost certainly migrate to other agencies, from the FBI to the IRS, supercharged by AI technology. If spyware of this power can be deployed with minimal judicial oversight, it becomes the digital equivalent of a general warrant – precisely what the Fourth Amendment was designed to forbid. A Tool with a Troubling Track Record The risks are not hypothetical. NPR reports that Graphite has already been used by foreign governments to target journalists and members of civil society. Researchers identified cases in which phones belonging to journalists and humanitarian workers were compromised through messaging platforms like WhatsApp. This mirrors the global experience with Pegasus and similar tools, which have repeatedly been used not just against criminals, but against dissidents, reporters, and political opponents. The Constitutional Stakes The deployment of zero-click spyware inside the United States raises profound constitutional questions. Unlike traditional surveillance, which might be constrained by warrants or physical limitations, these tools allow the government to access the most intimate details of a person’s life – messages, photos, location, even real-time communications – without detection. Layer that capability onto the federal government’s growing practice of purchasing Americans’ data from brokers, and the result begins to resemble a comprehensive, warrantless surveillance architecture. Even ICE’s assurances that its use will “comply with constitutional requirements” ring hollow without transparency or meaningful oversight. The Section 702 Debate Congress now faces a choice. It can allow this technology to take root in domestic law enforcement with minimal guardrails, or it can insist on strict warrant requirements, transparency, and accountability before such tools become entrenched. The House vote on the reauthorization of the FISA Section 702 surveillance authority, set to take place within days, is the best chance Congress will have to set the precedent for guardrails on out-of-control federal surveillance. If zero-click surveillance becomes routine, the line between targeting criminals and monitoring citizens may disappear altogether. |
Categories
All
|
RSS Feed