|
Franklin Delano Roosevelt likened the motley coalition supporting his opponent in the 1940 election to a chameleon. The president joked: “We all know the story of the unfortunate chameleon, which turned brown when placed on a brown rug, and turned red when placed on a red rug, but who died a tragic death when they put him on a Scotch plaid.” Plaid, in actuality, is never fatal, though it has been known to kill the vibes for a few first dates. There is, however, a new use for plaid in the 21st century. With millions of cameras embedded in doorbells and suspended over streets and highways, plaid may just be the fashion accessory for the privacy-conscious. The power of plaid has been discovered by a security researcher, who seems to have found a way to make people and vehicles less visible to the algorithms behind surveillance cameras. As Zack Whittaker of TechCrunch reports, Bill Swearingen’s “noRecognition” project uses computer-generated patterns to confuse automated detection systems. After some 31 million tests, his model produced patterns that defeated 11 open-source algorithms, including software used by Flock license-plate readers, Axon body cameras, and Clearview AI. At the recent DEF CON cybersecurity conference in Las Vegas, a car wrapped in one of Swearingen’s patterns evaded detection from a Flock camera. These patterns, however, do not stop cameras from recording. They merely prevent algorithms from recognizing and flagging people, faces, or vehicles. Swearingen calls these patterns a way to “opt out of being tracked.” It is an ingenious response to a troubling reality: Although we never agreed to it, we are increasingly subjected to automated surveillance that tracks us wherever we go, with the potential to record our associations and activities. Who knows? If people start wearing these patterns, maybe surveillance algorithms will crawl across our images and die. Can authorities rifle through the location histories of thousands of innocent people to catch one guilty person? One federal judge in Mississippi recently gave a decisive answer: No. U.S. District Judge Carlton Reeves of the Southern District of Mississippi had no qualms about drawing the line at the exact edge of the U.S. Constitution. This case concerned “tower dumps,” in which authorities require a cellular provider to produce information concerning every device that connected to specified cell towers during a defined period. On Aug. 5, Judge Reeves held that such “tower dump” warrants are per se unconstitutional. Ryan T. Fenn and Lee M. Cortes, Jr. of Arnold & Porter report in Enforcement Edge that Judge Reeves based his ruling on the conclusion that such searches intrinsically violate the Fourth Amendment because, by their nature, tower dumps cannot be particularized. It is, therefore, impossible to establish probable cause as required by the Fourth Amendment with respect to each device captured. Judge Reeves acknowledged that tower dump warrants can be “uniquely effective” in catching criminals by placing them at the scene of a crime. His concern was that such a search, however, also sweeps in information belonging to thousands of people who have no connection to the investigation. In his opinion, Judge Reeves wrote that the government cannot obtain “an entire haystack because it may contain a needle.” Judge Reeves extended the logic of the Supreme Court’s 2018 Carpenter ruling, which recognized a privacy interest in cell-site location information, but declined to address tower dumps. He also noted that the recent Supreme Court Chatrie decision held that geofence warrants are searches, regardless of the time limits placed on a warrant. The logic of these cases extends to tower dumps, which can identify people inside their homes, offices, and houses of worship – data Judge Reeves found to be “intimate and deeply revealing.” Will this federal judge’s ruling in Mississippi upend the common practice of scraping mass data from cell-phone towers? Will it set a precedent that will quickly bring other forms of mass surveillance – such as federal agencies’ purchases of Americans’ digital lives from data brokers and the increasingly ubiquitous network of public and private cameras to which law enforcement has easy access – under constitutional scrutiny? Short answer: Not likely. But it is still a very positive development. As Fenn and Cortes write, “this is one decision from a district judge – it binds no other court, not even others in the Southern District of Mississippi.” True. We believe, however, that Judge Reeves’s ruling is significant. It is likely to inspire more such cases and rulings – coming down on both sides of the issue – that will force the Supreme Court to provide a more detailed and comprehensive answer on the constitutionality of all forms of geolocation tracking. Stay tuned. Amid mounting concern about the misuse of personal data from Flock Safety cameras, the college community of Harrisonburg, Virginia, has joined the growing ranks of American communities rejecting that company’s pervasive surveillance of motorists. The Harrisonburg City Council voted unanimously to end the city’s contract with Flock Safety, shut down its automated license plate readers, and cover the cameras with trash bags until they can be removed. The council also adopted a policy encouraging future councils to consider privacy, data security, equity, and public trust before deploying similar technology. Residents are continuing to press for a binding ordinance that would require public scrutiny of any future mass-surveillance proposal. Harrisonburg Mayor Deanna Reed acknowledged that Flock cameras can help solve crimes. But she concluded that its risks outweighed its benefits. “We might not share the data, that doesn’t mean that somebody can’t get a hold of what we have,” Reed told a reporter at WHSV, a local television station. “The safest thing to do is just not use it at all.” That is a sensible response to a technology that does far more than snap an occasional picture. Flock’s artificial-intelligence system records license plates and vehicle characteristics, allowing police to reconstruct a person’s movements and search for vehicles by color, model, dents, and bumper stickers. Networks linked across jurisdictions can transform scattered observations into a detailed account of where someone worships, works, seeks medical treatment, associates with others, or attends a political protest. Then there is the problem of accuracy. A Business Insider investigation found that Flock’s software misread plates in 71 percent of the stolen-vehicle and felony alerts it sent to police in Roseville, California, during 2023 and 2024. Records showed that the cameras also produced blurry images, missed vehicles, and sent delayed alerts. Roseville’s unusual camera positioning may have contributed to the errors, and its police said none of the false alerts resulted in a stop or arrest because officers independently verified the information. Other communities have not been so fortunate. Flock errors, sometimes compounded by failures of police verification, have led innocent drivers elsewhere to be stopped at gunpoint, jailed, and even mauled by a police dog. Harrisonburg is part of a genuinely bipartisan revolt. Charlottesville ended its Flock pilot program over concerns about data protection, misuse, and local control. In Bandera, Texas, opposition came from residents steeped in a conservative tradition of personal liberty and distrust of government overreach. Across the ideological spectrum, Americans understand that tools to combat serious crimes can easily expand into routine, warrantless monitoring. Police should use targeted investigative methods to pursue people reasonably suspected of crimes. They should not assemble a searchable record of everyone’s movements just in case someone might later come to the attention of authorities. Harrisonburg has made the right call. Other communities should follow its lead and tell mass surveillance to get the Flock out. The U.S. House on Tuesday passed the Protecting Privacy in Purchases Act (H.R. 1181) by a vote of 221-201. The bill was sponsored by Rep. Riley M. Moore (R-W.Va.). Rep. Moore’s bill would prohibit payment card networks from using a special merchant category code to identify purchases from firearms retailers. Such codes could easily become something Congress prohibits – a de facto registry of law-abiding gun owners built from financial transaction data. Senators might consider this not just as a Second Amendment bill close to the hearts of most Republicans, but also as a way to raise a broader privacy principle that would cover the privacy concerns of Democrats as well. After all, financial records reveal far more than how much we spend. They can expose our beliefs, medical concerns, political interests, and personal struggles. Once a payment network creates a special category to identify one type of lawful purchase, the way is open to spy on Americans through their spending. In this version of the bill, the protected category is firearms and ammunition. In a wider version, it could cover purchases related to mental health treatment, addiction recovery, religious materials, reproductive healthcare, or books on controversial subjects. Americans across the political spectrum should be wary of creating new mechanisms that catalog lawful, constitutionally protected activity through payment data. Merchant category codes were designed to classify businesses for payment processing, not to create dossiers on consumers. While the codes do not identify individual products, they can reveal that a customer patronized a particular kind of merchant. Combined with transaction amounts, locations, and other available data, they become another pixel in an increasingly detailed image of Americans’ private lives. PPSA has long warned that government agencies can often obtain commercially available data without the warrant requirements that would apply if they collected the same information directly. As financial surveillance capabilities expand, so do the opportunities for government access, private misuse, and mission creep. The Senate should therefore view the Protecting Privacy in Purchases Act as more than a firearms bill. It is an opportunity to establish that payment processors should not create specialized tracking categories for Americans engaged in lawful activities involving sensitive constitutional rights or deeply personal decisions. Imagine the government claiming it can open a box of your old letters without a warrant simply because you kept them for more than six months. Absurd? Under a Reagan-era federal law, that is roughly the legal logic applied to your emails. The Electronic Communications Privacy Act (ECPA), passed in 1986, was a landmark bill that established guardrails for the government’s treatment of private communications in the emerging digital world. At that time, emails were usually downloaded to a personal computer and deleted from servers. That law thus contained a loophole that allowed government agencies to obtain stored electronic communications more than 180 days old without a warrant. One tech provider warns that today that “Gmail will NOT automatically delete your old emails after any timeframe. Messages from 5, 10, or even 20 years ago will sit in your account forever unless you manually remove them.” Technology changed. The law didn’t. That is why PPSA applauds Reps. Warren Davidson (R-OH) and Suzan DelBene (D-WA) and Sens. Mike Lee (R-UT) and Ron Wyden (D-OR), for updating the law with the bipartisan Email Privacy Act. The bill would require the government to obtain a warrant before accessing the contents of Americans’ emails and other stored electronic communications, regardless of how long they have been stored. It would also permit service providers to notify customers when the government seeks their information, unless a court orders otherwise. “The Fourth Amendment is clear: the government must get a warrant before searching an individual’s private property, including written communications,” Rep. Davidson said. Sen. Lee similarly noted that “Americans should not lose their Fourth Amendment protections simply because their private communications are stored with a third-party provider.” They are exactly right. Our emails can contain medical information, financial records, family conversations, political discussions, and the intimate details of our daily lives. The idea that constitutional protection should diminish after 180 days is a relic of the dial-up era. This bill also demonstrates that privacy reform remains one of the few issues capable of bringing together serious conservatives and progressives. These legislators deserve our praise for recognizing a simple principle: a private communication does not become government property as it ages. Congress should pass the Email Privacy Act and apply the Fourth Amendment to the reality of 21st century technology. Jacqueline McNeill of Fayetteville, North Carolina, was driving home from the grocery store – with chicken to prepare for her goddaughter’s funeral, no less – when multiple police cruisers cornered her white Nissan Versa in the parking lot of a convenience store. “I felt like the moment I stepped out of my car,” she later told Tyler Dukes of Raleigh’s The News & Observer, “I was automatically guilty.” The second-grade teacher was arrested on the spot for a drive-by shooting. Jacqueline wasn’t guilty of anything, but that didn’t stop her from becoming a victim of automated license plate readers (ALPRs). Days before, these roadside cameras had spotted a car similar to hers in the vicinity of a shooting. As with so many other surveillance systems, police used this image in place of critical thinking, as visual proof when it was nothing of the sort. And now this far-less-than-foolproof technology – with the privacy protections of a rusted colander – is about to get a massive injection of mission creep. One of the makers of ALPR technology is Leonardo (pro tip before clicking: you might want to decline all cookies). According to Ian Wright of CarBuzz, the company’s SignalTrace technology “is set to move ALPR cameras from just car-tracking to people-tracking devices.” In plain language, that means tracking drivers’ and passengers’ smartphones, vehicle infotainment systems, and any other Bluetooth-capable device – all linked to your license plate or someone else’s. Worse, our devices are uniquely and individually identifiable. In the absence of robust legislation designed to bolster our Fourth Amendment rights, the only thing that can prevent them from being used as straight-up spy tools by authorities is end-to-end encryption. Wright reports the SignalTrace product sheet promises to “create a unique, trackable ‘electronic fingerprint’ for investigative use.” But wait, there’s more! The surveillance dragnet Leonardo is creating includes RFID tags (they’re everywhere, including key cards), pet microchips (so much for taking your dog along on errands), tablets, fitness trackers, tire pressure sensors, and… you get the idea. If there’s a kicker in all of this, it is another passage Wright quotes from the SignalTrace product sheet, which boasts that it “stores device and correlation data securely … for future queries and analysis.” The dystopian quantum leap, Wright notes, is that once implemented, ALPR systems will transition from identifying vehicles to identifying occupants. All of this data will be unbound by time, stored in a permanently searchable database – just in case we need to be retroactively suspected of something that may or may not have been legal once upon a time and that we may or may not have done in a car that we may or may not have been driving (or simply riding in). Calling Steven Spielberg: We just found the sequel to Minority Report. What could go wrong? To name a few risks: false positives; arrests of innocent people; police officers using ALPR systems for stalking and intimidation; and the collection of massive amounts of personal data by for-profit corporations ready, willing, and able to sell that information to any and all comers, including the government. Add to these risks hacking by cybercriminals and bad-faith state actors. It’s all coming to a technocratic authoritarian surveillance state near you. Because of her false arrest that day, Jacqueline McNeill never made it to her goddaughter’s funeral. She also largely avoided driving her Nissan before eventually selling it. And who can blame her? Wells v. State of Texas The U.S. Supreme Court’s decision Monday in Chatrie v. United States marked the biggest advance in digital privacy since Carpenter v. United States in 2018. By recognizing that Americans retain a reasonable expectation of privacy in digital location tracking, such as Google’s Location History records, the Court closed a major loophole in Fourth Amendment law. But Chatrie is unlikely to be the final word. Like Carpenter before it, the decision is likely to spark a renewed struggle over how to apply this precedent. One case worth watching is Wells v. State of Texas, which the Supreme Court Tuesday remanded to the Texas Court of Criminal Appeals. The facts are straightforward. In 2018, Dallas police investigating a fatal robbery obtained a geofence warrant directing Google to identify every device that had been present within a defined area around the crime scene during a 25-minute period in the early morning hours. The warrant eventually led investigators to Aaron Wells, who was convicted of capital murder. What makes Wells noteworthy is not the crime but the court's fractured reasoning. Like the Fourth Circuit in Chatrie itself, the Texas Court of Criminal Appeals produced no clear majority rationale. Four judges assumed that obtaining Google's location history constituted a Fourth Amendment search but upheld the warrant because it was supported by probable cause and was – in the language of the Fourth Amendment – sufficiently “particular” about what would be seized. Two of those judges separately explained that the geofence warrant did not involve a constitutional search at all, relying on theories that users surrender their privacy by sharing information with Google. Three other judges concluded that no search occurred for most of the data sought by the warrant. But they further explained that no probable cause existed either because the police obtained a warrant with only the location where a crime occurred, not a suspect. One judge dissented without opinion, and another did not participate. That division matters because Chatrie resolved the question about whether a search occurred, highlighting the importance of the remaining disagreement about the Fourth Amendment’s probable cause and particularity requirements. On that question, the Wells court was divided 4-3, with one justice dissenting but not explaining the basis for his dissent. Now after Chatrie, courts must focus on these difficult questions that divided the Texas Court of Criminal Appeals. In essence, courts will now focus on how broad is too broad. How many innocent people may be swept into an investigation before a warrant becomes the digital equivalent of the general warrants the Fourth Amendment was written to forbid? Those are not academic questions. Geofence warrants have already been used in investigations ranging from bank robberies to protests, and each new case forces courts to balance legitimate law enforcement needs against the privacy rights of countless bystanders whose only “crime” was being nearby. Carpenter reshaped surveillance law for nearly a decade. Chatrie promises to do the same. General Douglas MacArthur famously told West Point cadets, “We listen vainly, but with thirsty ear.” In classical rhetoric, that’s known as catachresis – mixing two things that don’t belong together in order to deliberately jar your audience. According to Sophi Charara at Wired, Apple may have plans to create an actual catachresis by putting cameras in its next generation of AirPods. If so, we suggest a marketing campaign along the lines of: “Apple: Our Thirsty Ears Are Watching You.” It’s likely part of an AI device push, and if Charara’s sources are accurate, Apple employees are currently in the late stages of testing technology that will effectively give Apple eyes on the sides of our heads. That’s a very different (and highly concerning) privacy profile than what phones are currently capable of – and much more eerily akin to Meta’s invasive smartglasses, for which the law has yet to catch up. Privacy laws, therefore, won’t be up to speed when Apple starts watching as well as listening. Fortunately, the law may have some time to catch up given the enormous technical constraints of integrating visual intelligence with wireless earbuds. But Apple will get there eventually, that much is certain. The company’s first attempt at camera-based wearable computing – the Vision Pro – struggled commercially, but the ambition hasn’t died. It’s just getting smaller, cheaper, and easier to wear. All of it serves as a reminder that “wearables” as a category are exploding. In the end, it matters less whether it’s Apple or Meta or Google, or whether the device is a watch or glasses, or earbuds. What matters most is that the time is now for the American people and Congress to proactively apply the law against the inevitable data grab that’s coming. Cloud Data Should Not Be an Open Book for the Government Every day, Americans store their most personal information in the cloud. Our photos, messages, financial records, search histories, and private documents now reside on servers owned by tech companies like Google, Apple, Microsoft, and Snapchat. The question before the courts is increasingly simple: Does storing data with a third-party service provider mean surrendering your Fourth Amendment rights? PPSA is telling the U.S. Supreme Court the answer must be no when government pressure is exerted on highly regulated companies to search the content of Americans’ data. The case arises from a Wisconsin prosecution in which a file uploaded to Snapchat was flagged for potentially illegal content, namely suspected child sexual abuse material, by automated scanning software and reported to authorities. A law enforcement officer then conducted the first human review of that file without obtaining a warrant. The Wisconsin Supreme Court held that the user lacked a reasonable expectation of privacy because the data was stored with a third-party – Snapchat, which conducted the initial search – as permitted by its terms of service, which reserves the right to “screen” for illegal content. It is on this basis that the Wisconsin court determined that no warrant was needed. In our brief, PPSA demonstrates that such reasoning turns the Fourth Amendment upside down when such searches are conducted under pressure from the government. If the logic of this case is accepted, digital third parties can become vehicles for extinguishing constitutional rights. The Supreme Court rejected a similarly sweeping approach in Carpenter v. United States. In that landmark 2018 decision, the Court held that the government generally must obtain a warrant before accessing historical cell-site location records, even though those records were held by a third-party company. The Court recognized a basic truth about modern life: participation in the digital world requires us to entrust vast amounts of our lives to service providers. That necessity does not eliminate our expectation of privacy. This case offers the Court the chance to extend the principles of Carpenter with even greater force to cloud storage. Americans do not upload files to the cloud because they wish to expose them to government scrutiny. They do so because cloud services have become the digital equivalent of filing cabinets, photo albums, desk drawers, and personal archives. As PPSA demonstrates, earlier generations routinely entrusted private property and correspondence to third parties for storage, transport, or safekeeping without forfeiting constitutional protections. The same principle that protected privacy then should govern digital information today. This case also raises a troubling question about government outsourcing. Federal and state laws increasingly pressure technology companies to scan user content and report suspicious material. When companies perform searches because the government effectively requires them to do so, those searches begin to resemble state action rather than truly private conduct. As PPSA has shown, government-mandated reporting cannot become a loophole for bypassing the warrant requirement. The Supreme Court recognized in Carpenter that constitutional liberties must survive technological change. If the government can freely inspect because it has coerced third-party services into conducting searches, then one of the most important privacy protections in American law will become little more than a relic of the pre-digital age. While all decent people want to eradicate child sex abuse material, constitutional shortcuts used to detect heinous crimes create a new logic by which the government will be able to inspect content in cloud-stored data for any reason or no reason at all. PPSA is urging the Court to ensure that this does not happen. “The secret of man’s resistance to total power lies in his ability to live in truth. A power which rests on the total manipulation of reality cannot tolerate anyone who points to a reality beyond its control.” - Václav Havel Faith communities answer to a higher authority than the state. They preserve independent institutions, foster private associations, and teach moral truths that governments do not control. For that reason, churches, synagogues, mosques, temples, and religious ministries have often found themselves in the crosshairs of governments eager to monitor dissent. That is why Congress must repeal one of the most dangerous provisions added to FISA Section 702 in 2024 – the expanded definition of an Electronic Communications Service Provider (ECSP), commonly known as the “Make Everyone a Spy” provision. The ECSP expansion dramatically broadens the range of people and organizations that can be compelled to assist government surveillance, including most businesses that provide free Wi-Fi to customers and tenants. While the debate often focuses on privacy, the provision also poses a direct threat to religious liberty.
The chilling effect would be immediate. Individuals seeking spiritual guidance or personal counseling should never have to wonder whether their conversations could become part of a surveillance operation. History teaches us that such fears are not hypothetical.
Nor is religious surveillance a mere relic of the past.
And the danger is not confined to one political party. Just as the Biden administration’s treatment of traditionalist Catholics raised alarms, future conflicts between any administration and religious leaders could create similar temptations. Recent tensions between President Trump and Pope Leo XIV illustrate how quickly political disagreements can spill into disputes involving religious institutions. This is precisely why constitutional protections exist. The First Amendment protects not only the right to worship, but also the right to associate, counsel, organize, and speak freely within religious communities. Those freedoms depend on privacy and trust. Havel warned that governments seeking greater control cannot tolerate institutions that point to truths beyond official power. Religious communities do exactly that. They remind citizens that there are limits to what government may command and limits to what it may know. The ECSP expansion pushes in the opposite direction. It creates new opportunities for surveillance to penetrate institutions that have historically served as centers of conscience, dissent, and moral witness. Congress should enact the ECSP fix and restore the narrow definition of compelled assistance. No church, mosque, synagogue, pregnancy center, religious school, or ministry should be transformed into an unwilling arm of the surveillance state. Your landlord is watching you come and go – and it isn't to say hello Writing in Albany’s Times Union, Fabian Rogers and Jason Taper of privacy watchdog STOP remind us that invasive landlords are nothing new. What is new is the way facial recognition has quietly become a tool for controlling tenants. Landlords, for obvious reasons, don’t like rent-stabilization policies in many cities. Knowing this, technology firms are now marketing facial recognition products as a way to help landlords find new ways to evict people and raise rents (because, to de-regulate an apartment, you first have to empty it). There’s even a wink-wink industry term for this: “de-stabilize.” It’s a technological fishing expedition, and facial recognition tech is the rod. Park a camera at the only door, log every entry and departure, and wait to “catch” a tenant in violation of some technicality – an unauthorized overnight guest or a too-frequent absence that “proves” they don't really live there. Landlords will use all manner of red herring arguments to whitewash what they’re doing, such as claims of enhanced “safety and security.” In co-author Rogers’ own case, his Brooklyn landlord decided to implement a facial recognition system a mere year after the complex was declared rent-stabilized. Coincidence? The Trojan Horse pitch the landlord used was “frictionless entry.” Rogers and his fellow tenants weren’t fooled. After they organized, the landlord backed down. In the end, the tenants’ right to privacy trumped the promise of frictionless entry. This is just one example of how private companies are quietly assembling exactly the kind of always-on surveillance the Constitution forbids the government from building – and that is the loophole. The Fourth Amendment guards your home against the state; it has nothing to say about a property manager with a camera. New York's Senate Bill S8223 would ban landlords from using such tech. This makes sense: No one should have to build a tenant movement simply to preserve the basic freedom to come home without being tracked, watched, and cataloged by the place they live. When you hear of a new surveillance program being marketed as a child-safety initiative, give it particularly close scrutiny. History shows that the narrower and more compelling the stated justification for a surveillance plan, the broader and more outlandish the surveillance will actually be. A newly reported example comes from BusPatrol, a company that has installed AI-powered camera systems on more than 40,000 school buses in 24 states. The cameras have been marketed as a way to identify drivers who ignore the fold-out “STOP” arm signs from buses and illegally pass them while stopped. Joseph Cox of 404 Media reports that BusPatrol is now planning a dramatic expansion of its mission. Leaked company documents reportedly show plans to convert school buses into roaming automatic license plate reader (ALPR) platforms that would capture information on every vehicle a bus passes, regardless of whether any crime or traffic violation occurred. The resulting data would then be sold to law enforcement. A system designed to document a specific violation at a specific moment is fundamentally different from a system that continuously records the movements of everyone nearby. In effect, school buses would become mobile surveillance vehicles. Under the proposal, cameras would photograph vehicles, record their license plate numbers, and attach GPS location data. Law enforcement and possibly other actors could then query those records to reconstruct a vehicle's travel history. As privacy advocates have long warned, tracking a car often means tracking a person. These bait-and-switch tactics are familiar. After the attacks of September 11, Americans were told that extraordinary surveillance programs were necessary to prevent terrorism. Many of those authorities later expanded far beyond their original scope. Section 702 of FISA was enacted to monitor foreign threats overseas, yet the communications of millions of Americans became subject to warrantless searches. From the UK to Congress, we’ve seen how the fight against child sexual abuse material has been used as a shield to threaten the encryption that protects women and children from stalkers, journalists from vengeful politicians, businesses communicating about proprietary information, and millions of law-abiding Americans who want to have a digital conversation without Big Brother listening in. Government agencies have repeatedly justified the acquisition of vast quantities of personal data by pointing to legitimate public concerns, only for those powers to evolve into broader surveillance tools. BusPatrol's reported plans follow the same trajectory. A narrowly tailored safety program aimed at preventing children from being struck by passing vehicles could become a platform for collecting location information on millions of ordinary Americans who have done nothing wrong. The danger is not merely the collection of data. It is the normalization of surveillance infrastructure. Every new camera network creates pressure to find new uses for the information it gathers. Indeed, BusPatrol’s internal documents suggest that this latest move is in response to investor demands for new revenue streams. Protecting children is a worthy goal. Turning school buses into rolling location-tracking platforms is not. Americans should be wary whenever government agencies or private contractors ask them to trade away privacy in exchange for safety. Proposals like this need their own mounted “STOP” arm signs. Canada’s “Lawful Access” Bill Raises Alarm in Congress Over Encryption and Americans’ Privacy5/18/2026
Two powerful House committee chairmen are warning that a sweeping Canadian surveillance proposal could undermine the privacy and cybersecurity of Americans by pressuring U.S. technology companies to weaken encrypted services. At stake is the privacy of Americans who depend on robust encryption to protect sensitive communications, health data, financial records, and personal communications from unwarranted intrusion. In a May 7 letter to the Canadian Minister of Public Safety, House Judiciary Committee Chairman Jim Jordan and House Foreign Affairs Committee Chairman Brian Mast expressed concern that Canada’s proposed “Lawful Access Act of 2026,” known as Bill C-22, would dramatically expand the Canadian government’s ability to compel access to encrypted data. The lawmakers wrote: “Canada’s Bill C-22, currently under consideration in Parliament, would drastically expand Canada’s surveillance and data access powers in ways that create significant cross-border risks to the security and data privacy of Americans … “Bill C-22 would allow Canadian government officials to compel American companies to build backdoors into their encrypted systems, thereby introducing systemic vulnerabilities that could be exploited by hackers, foreign adversaries, and cybercriminals.” At the center of their concern is the requirement for “electronic service providers” to enable government access to data. The bill also authorizes confidential “ministerial orders” compelling providers to comply with demands, while prohibiting disclosure of those orders. “Dangerously Vague” Jordan and Mast argued that these powers are dangerously vague and compel weakening of encryption technologies. They wrote: “If a U.S.-based provider is forced to redesign its system to facilitate Canadian authorized access to content that is currently inaccessible even to the provider itself, the resulting capability cannot be geographically limited.” This could open the way for hostile actors and states to steal Americans’ data at a massive scale. The chairmen referenced the 2024 “Salt Typhoon” intrusion as evidence that government-mandated access points inevitably become attractive targets for hostile actors. Privacy and civil liberties advocates are voicing similar concerns. The Electronic Frontier Foundation warned that Bill C-22 would provide “a mechanism for the Minister of Public Safety to demand companies create a backdoor to their services,” while Meta stated publicly that the bill could “break, weaken, or circumvent encryption.” Endangers the Vulnerable PPSA has long warned that mandates weakening encryption in one democratic nation inevitably create ripple effects far beyond national borders. Breaking secure encryption could endanger journalists, dissidents, religious minorities, businesses, attorneys, and ordinary citizens from criminals and hostile foreign actors alike. Jordan and Mast urged Canada to pursue formal cooperation mechanisms under the CLOUD (Clarifying Lawful Overseas Use of Data) Act framework, which allows cross-border access to digital evidence while preserving legal safeguards and judicial oversight. As Congress debates surveillance reform at home, the dispute over Canada’s Bill C-22 underscores a growing international reality – efforts by governments to weaken encryption abroad can directly threaten the privacy and cybersecurity of Americans at home. The Associated Press last year wrote a landmark series of six stories about the role that U.S. tech firms play in global surveillance, particularly in China. “Made in America, Watched Worldwide,” just won a Pulitzer for international reporting. The award is richly deserved, honoring the efforts of multiple journalists who worked painstakingly on the project for three years. Celebrating their efforts is an opportunity for all of us in the privacy community to reflect not only on the AP’s key findings but also on the ominous realization that the technology described is homegrown. In other words, it can just as easily be sold to U.S. agencies and directed at the American people. That’s over 90,000 distinct entities when you add up the total number of federal, state and local government operations. In other words, U.S. technologists not only helped design the Chinese surveillance state, we’re also not that far from having one ourselves. This danger is growing more acute with the ability of AI to transform information into actionable knowledge and to turn individual data points into personal dossiers. So let’s think about that as we briefly summarize the AP’s topline findings. Everything in this list is all-too-easily capable of being implemented here in the United States:
One of the heroes of AP’s reporting is longtime Chinese activist Zhou Fengsuo. Arrested and imprisoned as a student leader during the Tiananmen protests, the now-U.S. citizen Zhou testified before Congress in 2024, warning that the lack of privacy guardrails and meaningful reform “is a strategic failure by the United States.” Current legal guardrails on American surveillance are not keeping pace with advancing technologies and questionable partnerships unmasked in AP’s series. And that gap underscores the urgent need for robust reform of surveillance laws – before these untethered AI networks are fully (and permanently) turned inward. Congress should take a deeper look into the technologies U.S. companies are selling to China and other adversarial nations – and how they are being deployed here. The rapidly escalating power of AI should especially make it clear why the House leadership proposal to extend FISA Section 702 for three years is unacceptable. Colorado Man’s Flock Nightmare Futurism and other sources report that Kyle Dausman can’t go anywhere in his truck without being swarmed by police. It’s all thanks to a glitch in the Matrix – er, in the Flock Safety camera surveillance system – used by authorities across the state of Colorado. Seriously, this is one of those stories that would be a lot funnier if it were about an average guy named Klaus who lived in the East German police state circa 1986. After stopping him a couple of times, the Cherry Hills Police Department quickly realized that a dubious clerical strategy was responsible for flagging local resident Dausman in the statewide Colorado Crime Information Center database. Because the Centennial State, like others, uses both zeroes and letter Os in license numbers: “Sometimes the data entry will be for both" versions of a plate when an arrest warrant is issued, Cherry Hills police chief Jason Lyons told Denver’s KUSA. A clerk filing a warrant in another county apparently did exactly that in Kyle Dausman’s case, entering both the “0” and “O” versions of the actual offender’s tag, according to the Cherry Hills chief. He also noted, pointedly: "It wasn't a mistake.” Poor Dausman just happened to be the guy with the innocent-yet-incorrect tag sequence. "Everywhere in the state, every time I pass a camera,” laments the victim, “they get alerts in their car that I'm in the area." He justifiably worries for his family’s safety as well as his own. Colorado should order its clerks to stop conflating zeros and Os. Why does the state – like many others – continue to put innocent people in harm’s way? This could be fixed with one executive order from the governor. At least the local police department in Cherry Hills fixed the flag in its local database. But beyond that, Dausman is on his own, and largely without recourse according to the details of various reports: The Colorado Crime Information Center hotlist still shows him as a wanted man, and no one is sure who has the actual authority to address the situation. All of which is to say nothing of actual reform (which lives only on best practice wish lists for now). Dausman’s experience, writes Al Landau for Gadget Review, is emblematic of a fundamental problem with large-scale, big-data-powered surveillance systems like the Flock Safety networks popular across Colorado: “Flawed data produces harmful results, regardless of camera sophistication.” A process, he says, that amplifies bad data practices, potentially turning them into “major personal nightmares.” Like a coal miner’s canary, this story warns not just about the anti-privacy plate-reader industry, but about the dangers of public partnerships with Big Tech that fuels the growth of the modern surveillance state. In the meantime, privacy-loving pro-Fourth-Amendment citizens who want to keep tabs on Flock’s invasive alliances with law enforcement can do so on an advocacy site appropriately called DeFlock. How “Ghost Tapping” Can Pull Cash Out of Your Accounts – and the Best Ways to Guard Against It5/5/2026
Like so many high-tech conveniences, tap-to-pay comes with some privacy and security pitfalls. The same debit and credit cards that have this capability can also be remotely exploited by “ghost tapping,” a hack that can drain funds from your bank accounts in seconds. Click below to get a quick overview of this risk, along with a review of ways to protect your cards – what these solutions cost and how well they work. Chatrie v. United States The U.S. Supreme Court set the first warrant requirement for Americans’ location data in 2018. Chief Justice John Roberts, writing for the majority in Carpenter v. United States, declared that when the government “tracks the location of a cell phone it achieves near-perfect surveillance, as if it had attached an ankle monitor to the phone’s user.” Though the Court’s ruling set a warrant standard for the extraction of historic cell phone data from cell towers, Carpenter failed to become a general precedent for using other means to geolocate Americans – such as tracking people through their phones. On Monday, the U.S. Supreme Court heard oral arguments in a case that has the potential to become the next landmark ruling. If the sharp questions of the Justices are any indication, they may well limit the government’s ability to conduct large geolocation sweeps that can compromise the privacy of large numbers of Americans. The case involves Okello Chatrie, convicted of bank robbery near Richmond, Virginia, after local authorities used a geofence warrant for the area of that crime and picked up Chatrie’s phone at the scene. Hundreds of other people within the area geofenced by police were also pinned, including guests at a Hampton Inn, residents in an apartment house and a retirement home, and diners at a Ruby Tuesday restaurant. What’s the big deal, you ask, if this maneuver helped catch a bank robber? As a lower court judge noted, with such a procedure – this time a warrant issued to Google – everyone within the designated perimeter “has effectively been tailed.” Even when such technology is used for a clear purpose, such as locating a bank robber, the precedent opens the way for the government to track Americans’ associative activities, from protests to political activity to worship. In its questioning, the Supreme Court recognized the Orwellian possibilities of this technology. “What’s to prevent the government from using this to find out the identities of everybody at a particular church, a particular political organization,” Chief Justice Roberts asked the government’s lawyer. “What are the restraints that would prevent that from becoming a problem?” Adam G. Unikowsky, Chatrie’s attorney, characterized geofence warrants as fishing expeditions that “search first and develop suspicions later.” Unikowsky told the Justices: “The technology may be novel, but the constitutional problem it presents is not. The potential for abuse is breathtaking: The government need only draw a geofence around a church, a political rally or a gun shop, and it can compel a search of every user’s records to learn who was there.” The Justice Department lawyer had a tough time arguing that Chatrie did not have a reasonable expectation of privacy for location history data that his phone shared with Google. Justices Neil Gorsuch and Sonia Sotomayor asked questions showing a concern that the government’s position could be expanded to include emails, photos, and documents, as well as location data. The Justices also questioned the extent to which Americans are even aware that their cell phones enable tech companies to track their locations in a way that can be shared with the government. These questions echoed the PPSA amicus brief, in which we told the Justices: “Letting a plumber into your house to fix a sink does not mean you have no expectation of privacy when the police come knocking.” A little levity came to the proceedings when Justice Amy Coney Barrett said she was shocked by how many ads she saw on her phone that were triggered by her visits to specific locations. “I need to check my location settings, plainly,” she said, triggering laughter throughout the courtroom. Judging by the questioning, it appears that this case may, at the very least, lead to some tightening of mass geofencing. PPSA hopes that all the Justices will agree with our brief in which we declared: “The Founders would have been shocked to see privacy brought to this sorry state.” The Wall Street Journal Is Wrong – We Can Reform Section 702 Without Endangering National Security4/14/2026
Did you see The Wall Street Journal editorial Monday morning entitled “Playing National Security Roulette”? The editors argue that anything less than a clean reauthorization of the FISA Section 702 surveillance authority will “put the lives of Americans at risk.” The Journal editors acknowledge that this authority, enacted by Congress to surveil foreign threats abroad, was misused by FBI agents who ran searches on political protesters, political donors, and Members of Congress. “But the intelligence community has since instituted safeguards on how searches must be authorized,” the editors tell us. Thus, according to The Journal, adding any amendments to Section 702 would be a reckless gamble with national security – and reforms are not needed anyway, because the Reforming Intelligence and Securing America Act (RISAA) fixed all the problematic parts of Section 702. Wrong on both counts. Reforms Would Not Compromise National Security Reformers want to amend the law to make the program consistent with the Fourth Amendment by requiring probable cause warrants before inspecting Americans’ communications. But the warrant requirement being proposed for surveillance of Americans contains very clear exceptions for “exigent circumstances,” such as terrorist threats, as well as exceptions for every single other type of search the administration has claimed is helpful in protecting national security, including defenses against cyberattacks. Not only would these reform proposals allow the FBI to proceed without obtaining a warrant in an emergency, but the Bureau would also have great latitude as to what constitutes an emergency. In short, warrants would be required in cases where the government is conducting a fishing expedition with no nexus to national security – such as an agent searching for the communications of his Tinder date, or searching for the communications of thousands of donors to a congressional campaign – but would not be required in exigent cases with national security implications. The FBI Continues to Violate the Law A FISA Court opinion in March 2025 revealed that the FBI had been systematically violating statutory requirements. In August 2024, DOJ overseers learned that the FBI was operating a “filtering” tool that allowed it to query Section 702 data under the radar. These U.S. person “searches” or queries were not counted, tracked, or audited, nor were they approved by an attorney or supervisor, as required by law. Thus, the actual number of U.S. person queries for 2024 remains unknown and outside of any audits. A new FISA Court opinion found that the systemic violations continue. According to The New York Times and The Washington Post, the FISA Court issued a classified opinion that reportedly reveals that even though DOJ shut down the filtering tool the FBI used in 2024, the FBI has been using another, similar filtering tool to conduct queries without following the requirements of RISAA. Thus, the systemic violations of RISAA are not fixed. They are ongoing. In Summary: The warrant requirement proposals contain sufficient exceptions to counter potential terrorists, cybersecurity attacks, and other threats to the American people. And contrary to The Journal’s assertion that the RISAA “reforms appear to be working,” they are clearly not. One final note – while the reauthorization of the Section 702 statute has an April 20 deadline, FISA Court surveillance orders are in effect through next spring. The House has plenty of time to debate these reform measures. There is no need for the kind of panic The Journal – obviously influenced by intelligence community spin – is fomenting. The Fibbing Four Are at It Again “Does the NSA collect any type of data at all on millions or hundreds of millions of Americans?” That was the question Sen. Ron Wyden (D-OR) put to then-Director of National Intelligence James Clapper in an open hearing in 2013. “No sir,” Director Clapper responded, then qualified his statement by saying, “not wittingly.” It has since been proven – and is a matter of government record – that the NSA’s global trawl of data has pulled in the communications of Americans by the millions over the last five years. Quite a record for a surveillance authority enacted by Congress to surveil foreign targets on foreign soil. See for yourself the misuse of this authority revealed in a rare public scolding of the FBI by the secret FISA Court over “widespread violations” of Americans’ privacy with Section 702 data. Or look at the revelations issued by that court of specific instances of how the FBI misused warrantless Section 702 material against U.S. political figures. It is widely reported that the FBI has freely helped itself to Section 702 data, searching the data of more than 19,000 congressional donors, a state judge, and Members of Congress. The Hunter Biden Laptop Deceit In 2016, former Director Clapper was joined by former CIA Director John Brennan, former NSA General Counsel Glenn Gerstell, and former NSA Deputy Director Richard Ledgett, along with almost 50 other former senior intelligence officials in signing a letter released just before the 2020 election. They chimed in on a New York Post story about the contents of a laptop owned by Joe Biden’s son, Hunter. This time, the Fibbing Four solemnly told the American people that the contents of the Hunter Biden laptop had “all the classic earmarks of a Russian intelligence operation.” The FBI later determined that the emails and contents of the laptop were “not tampered with or manipulated.” Even The New York Times was forced to report that the laptop and its contents were genuine. The irony is that former intelligence officials, abusing their continued access to classified information to skew a national election, is about the most Russian thing they could do. Misinformation About Reform Legislation Now Director Clapper, and his Hunter Biden colleagues Brennan, Gerstell, and Ledgett, have fired off another letter. This one is directed at Congress telling Members not to allow any reform amendments to the Foreign Intelligence Surveillance Act authority, Section 702, because that would degrade the government’s ability to protect Americans. “If Congress fails to authorize Section 702, history may judge the lapse of Section 702 authorities as one of the worst intelligence failures of our time,” they write, joined by enough of their colleagues to get the number of signatories up to around 50. “As Members of Congress know, we face sophisticated threats from China, Russia, Iran, and North Korea, including the real possibility of devastating cyber-attacks and state-sponsored terrorism directed at Americans.” These are, of course, real and active threats. But the Fibbing Four gloss over the fact that all of the reform proposals being proposed in Congress contain exceptions for “exigent circumstances.” These exceptions would allow intelligence agencies to react to time-sensitive emergencies, such as the so-called “ticking time bomb” scenario. These reform proposals also contain exceptions for cybersecurity and warrantless searches of metadata, requiring court approval only to examine the content of Americans’ communications. Fool Me Once… The good news is that Congress is getting wise to such shenanigans just before every vote. Before the last Section 702 reauthorization two years ago, the champions of the intelligence community put out a cryptic story about “a serious national security threat” that turned out to be theoretical, not imminent, reports about “Russian space nukes.” Our advice to Congress is to look at the plain language of the reform legislation that allows the intelligence community to continue to defend America – while upholding our constitutional rights as well. We can defend America and obey the Constitution at the same time. Don’t let anyone tell you otherwise. As Congress prepares to debate the reauthorization of FISA Section 702, lawmakers should understand one simple fact: Americans do not trust the government with their data. A new poll shows that 74 percent of Americans are concerned about the privacy and security of their personal data in government hands. The poll, released last week by the Center for Democracy & Technology (CDT), shows that 79 percent of respondents agreed that: “Congress should use its authority to hold the government accountable when it ignores privacy laws.” “People want their privacy protected,” said CDT’s Elizabeth Laird, “and bipartisan majorities want their elected leaders to do something about it. Lawmakers who ignore privacy are significantly out of step with their constituents.” The high level of public concern about the warrantless access by government agencies to Americans’ data – at the heart of the Section 702 debate – was consistent regardless of respondents’ political affiliation or age group. The survey also revealed specific concerns about how that data is used – and misused: 68 percent are concerned about personal data being shared with law enforcement across the federal, state, and local levels 67 percent are concerned about personal data being shared with the Department of Homeland Security 83 percent are concerned about a breach of a government database exposing their personal data 73 percent agree that, without privacy laws, government agencies would track and monitor anyone they choose 44 percent say they would forgo government benefits rather than risk misuse of their personal data These numbers are a warning. Poll after poll has shown that Americans across the political spectrum are deeply uneasy about how the government collects, searches, and uses their data. That concern is especially acute when it comes to warrantless searches of Americans’ communications under Section 702 – so-called “backdoor searches” that bypass the Fourth Amendment. Nor are these fears hypothetical. From millions of warrantless queries in recent years to the government’s routine purchase of Americans’ data from brokers, the gap between surveillance authorities and constitutional protections has become impossible to ignore. If “trust is the lifeblood of democracy,” then these findings suggest that America is running dangerously low. Congress now faces a choice. It can once again rush through a “clean” reauthorization of Section 702, ignoring both public opinion and constitutional concerns. Or it can act – by requiring warrants for searches of Americans’ communications, closing the data broker loophole, and imposing real oversight. Fortunately, the path forward is clear: —Reform Section 702. —Restore the warrant requirement. —Rebuild public trust. House Members Should Not Be Stampeded – Congress Has All Year to Debate and Fix Section 7023/31/2026
As the April 20 expiration of FISA Section 702 approaches, a familiar script is playing out on Capitol Hill. Members are warned that any delay in reauthorizing Section 702 – which enables U.S. intelligence agencies to surveil foreign threats – risks allowing a terrorist attack to unfold on American soil. This “you will have blood on your hands” argument is not just wrong. It is a cynical ploy to short-circuit a debate that Congress owes the American people, one that would in no way endanger national security. Here is the reality: Letting the statutory authority of Section 702 lapse does NOT mean America’s surveillance goes dark. Surveillance continues under Section 702 certifications issued by the Foreign Intelligence Surveillance Court, which remain valid until their expiration – currently extending to March 2027. This is not speculation. It is how this law works. As The New York Times has reported, legal directives to communications providers “shall continue in effect” under existing court authorizations. Yet lawmakers are again being told by the intelligence community to act immediately or risk catastrophe. This fear-based messaging has become routine, repeatedly stampeding Congress into reauthorizing Section 702 without strong reforms to protect Americans’ privacy. Enacted by Congress to target foreign threats abroad, Section 702 has been used to conduct millions of warrantless searches of Americans’ communications – peaking at 3.4 million in 2021. These are the predictable results of allowing the government to conduct “backdoor searches” without a warrant. In 2024, a bipartisan amendment to require warrants for searches of Americans’ communications failed in a 212–212 tie in the House. That vote showed how close meaningful reform is – if lawmakers are given the time to pursue it. Supporters of a “clean” extension – one without any reform amendments – are once again promising a debate on reforms later. Such promised reform debates never arrive. Recent history gives no reason to believe that this time will be different. Congress has time to debate well beyond April 20. It has time to patiently consider reforms, such as adding a warrant requirement before 702-derived communications of Americans can be inspected. The choice for Congress is not between national security and civil liberties. It is between rubber-stamping a flawed surveillance authority and doing the hard work of fixing it for their constituents. “Think Minority Report, But for Your Morning Commute” “Zero crash fatalities” was the way some advocates touted the vehicle safety mandates authorized by the infrastructure package that Joe Biden signed in 2021. As admirable as such goals sound, the mandates are an ill-conceived, undefined approach that, from a privacy standpoint, has more holes in them than a cocktail strainer. Now, three years past its original deadline, the NHTSA is barreling ahead with a model-year 2027 implementation while still not having posted a draft rule. The possible design architecture is a nightmare – including AI-powered infrared cameras that actively monitor biometrics (e.g., pupil dilation) to determine whether a driver is “impaired.” “Your car simply watches and decides whether you’re fit to drive,” Gadget Review contributor C. Da Costa writes – “Think Minority Report, but for your morning commute.” Unlike drunk driving laws that already exist and work, warns Lauren Fix, the vagueness of these mandates takes them beyond traditional constitutional safeguards: “No breath test is required. No police officer is involved. The judgment is made by software. Once flagged, the vehicle can refuse to start or restrict operation – and here is the critical issue: there are no federal rules defining how a driver gets out of that lockout. No required appeal process. No mandated reset timeline. No human review. Drivers are placed into what critics now call ‘kill switch jail,’ with no clear exit. This is not targeted enforcement. It applies to every driver, every time, regardless of driving history.” “Advanced impaired driving prevention technology” (in the words of the original mandate) seems unlikely to work as advertised. Instead of saving perhaps 10,000 lives annually, it will merely make already too-expensive vehicles even more expensive as reluctant manufacturers pass these costs on to consumers. From a privacy standpoint, it will create a massive public-private database of biometric data that will be the envy of government agents and hackers alike. In doing so, it will permanently end one of the few remaining bastions of American personal freedom, and one that is already under serious threat – the privacy we enjoy behind the wheel. 404 Media just uncovered something that should unsettle anyone who uses Zoom: An AI-powered site called WebinarTV is using third-party apps to access online meetings and record them, with meeting presenters repackaged and marketed as “experts” in public-facing webinars.
If they're lucky, these unwitting experts – who gain nothing from their newfound notoriety and, indeed, rightly thought they were mere participants in an invited Zoom call – might receive an AI-generated email from an AI-generated agent at AI-based WebinarTV announcing the surprise “rebranding” of their Zoom meeting participation, and perhaps providing the means to opt out. All of this, of course, is after the fact, so it's a privacy-last approach (not to mention that such notifications are probably being routed to spam). For privacy-first users, it's yet another lesson in the ever-growing lecture titled “Pay Attention to Those Settings!” To wit, when informed by 404, Zoom did a review and found that WebinarTV is accessing meeting links that have been publicly shared. That’s the key weakness: Various browser extensions and other digital tools make it possible to record and edit such publicly accessible meetings – even if the meetings themselves aren't being recorded. Using third-party tools (and perhaps their own) WebinarTV is capturing a meeting's audio and video in real time. “Third-party screen recording” is how a Zoom spokesperson described it to 404, while also suggesting that the company was technically powerless to stop it. So it’s up to us for the time being. Consider taking the following steps to avoid getting “webinarred” (or “Zoomjacked”?):
The CEO of WebinarTV told 404 that because the meeting links were publicly accessible, attendees shouldn't have any expectation of privacy. Hence, his company is justified in its actions and isn't guilty of any violations. Our recommendation? See items 1 through 4 above and don't give WebinarTV the satisfaction. In the meantime, and at this rate, caveat emptor. If you want a deeper dive into WebinarTV’s shenanigans, CyberAlberta details the steps. After the end of the pandemic, retail theft became rampant in New York City, as it did in San Francisco, Los Angeles, and elsewhere. Retail theft has evolved into a multibillion-dollar industry for highly organized criminal gangs. Last year, Queens District Attorney Melinda Katz charged a theft ring with hitting Home Depot outlets up to four times a day, only taking breaks from larceny for team lunches. New York Gov. Kathy Hochul said that the state, after toughening laws and putting money behind enforcement, had driven down retail theft crimes in New York City and the state with double-digit reductions. Yet retail theft continues to eat away at the profits of stores, from big chains to mom-and-pop shops. It is understandable that businesses would turn to biometric identifiers to spot serial offenders and block them before they can enter a store. But there is a cost to such surveillance – one that we all pay. “Many of us know the feeling of discovering our credit card information has been stolen,” said New York Councilmember Shahana Hanif. “It’s invasive and frightening, but you can cancel a credit card and get a new one. You cannot cancel your face. You cannot cancel your iris.” Hanif is sponsoring legislation that would prohibit biometric identifying technology in “public accommodation” spaces such as concerts and grocery stores. (Hat tip to Liam Quigley of Gothamist.) The city already requires stores to post notice to customers that they collect biometric data. Is this a simple case of caveat emptor? Or is the better question: should we give up our privacy just to buy groceries? There is more at stake than just what store managers see. It is what happens to this biometric data after it is collected. Hanif’s legislation would stop businesses from selling, leasing, or trading biometric data for profit. It would also require written consent from customers who wish to share their data, including in stores where biometrics are accepted for payment. At the very least, protecting our biometric data – and blocking its sale to other businesses, as well as preventing it from being sold or given to government agencies – would be a reasonable guardrail for New York City and other municipalities to adopt. Majority Oppose Forced AI Surveillance Talk of a “clean reauthorization” of Section 702 of the Foreign Intelligence Surveillance Act (FISA) is growing on Capitol Hill. But as Washington starts to dream of an easy vote that includes no surveillance reforms, the American people are not having it. FISA Section 702 is an authority enacted by Congress to enable the surveillance of foreign threats on foreign soil, but it has often been used by the FBI in recent years to spy on the communications of millions of Americans. Included in that debate is concern over the way in which a dozen federal agencies – ranging from the FBI to the IRS – are purchasing Americans’ personal information from shady third-party data brokers. A new poll commissioned by Demand Progress shows that Americans are paying attention to this threat to privacy – and they don’t like what they see.
The poll also shows that the recent dust-up between the Pentagon and AI company Anthropic is focusing the public’s attention on the potential for the government to use artificial intelligence to drive the surveillance of the American people to unprecedented levels. This is especially true as the administration works to dismantle long-standing information silos and remove safeguards that once limited the sharing of Americans’ private data between agencies – from the Department of Homeland Security to the FBI and the IRS. AI surveillance, with data collected under Section 702, could allow government employees across the federal bureaucracy to run warrantless searches of Americans’ private communications. Combined with the vast amounts of Americans’ personal data that federal agencies purchase from third-party data brokers, AI-run surveillance programs will have truly frightening reach. The poll also shows that Americans are watching the AI debate and that a majority see it as a threat to privacy.
Before Congress embraces a comfortable conformity on a “clean” reauthorization of Section 702 or any other surveillance authority, Members would do well to pay attention to the rising alarm over surveillance among their constituents. |
Categories
All
|
RSS Feed