Your smartphone can become a 24/7 surveillance device without you making a single wrong click In our last post, we reported on leaks that reveal that the Bulgarian government has approved the export of advanced spy technologies to governments around the world, many of them with poor ratings for their treatment of human rights, press freedoms, and political dissent. Thanks to this technology, tyrants, tormentors, and regimes around the world have gained unprecedented capabilities to intercept communications, track individuals, and harvest sensitive personal data – texts, emails, and calls – through defects in global telecommunications systems. Who is behind this privacy apocalypse? The Same Players Keep Appearing Human Rights Watch notes that the company selling these exploits, Circles, was founded by Tal Dilian, who also founded Intellexa, maker of the Predator zero-click tool. Dilian was sanctioned by the United States in 2024 for activities connected to the development and distribution of commercial spyware used against journalists, dissidents, policy experts, and government officials. Circles itself also has historical ties to NSO Group, the maker of Pegasus. The result is an ecosystem in which a relatively small group of firms and executives have repeatedly surfaced in controversies involving surveillance abuses around the world. Their activities demonstrate how interconnected the commercial spyware industry has become. A Growing Threat to Privacy and Democracy Such technologies often operate in secrecy, with little transparency, limited judicial oversight, and no remedies for victims. Human Rights Watch recently documented how surveillance technologies exported from European countries have been used by governments to target journalists, activists, academics, humanitarian workers, and political critics. The organization concluded that existing controls are failing to prevent sales to countries where there is a substantial risk of abuse. Figures ranging from journalists in Mexico and India to opposition politicians in Spain, and even a British prime minister, have been targeted by Pegasus software. With the expansive growth of Circles’ new surveillance software, Americans should wake up and realize that we are not immune to this global trend. As PPSA noted in our original reporting on mercenary spyware, American officials have already been targeted by foreign spyware campaigns. The proliferation of these capabilities means that sophisticated digital surveillance is becoming cheaper, more accessible, and harder to contain. The Lesson The leaked Bulgarian licenses provide another reminder that surveillance technology does not stay confined to the governments that first develop it. In short, the spread of mercenary spyware was once viewed as an emerging problem. Today, it is a mature global industry. The dangers posed by these sophisticated attacks have long been foreshadowed in Congressional testimony and hearings. Yet solutions are not obvious or easy. Like narcotics, surveillance tech often spreads through international markets, private vendors, shell companies, and workarounds of export controls until powerful interception capabilities become available to governments around the world, as well as criminals and cartels. Congress and policymakers must now recognize that this global marketplace for commercial spying tools is thriving and potentially threatens any American. The question is whether democratic governments will establish meaningful safeguards before these technologies become even more pervasive – and even more difficult to control. Ottawa would provide China, criminals the perfect hack for AI “C-22” just sounds like the name of something dangerous, and thanks to Canada, it is. The country’s government continues to push a privacy-busting measure of epic proportions. As we wrote in May, Bill C-22, “An Act respecting lawful access” to digital data, has the potential to – among a host of other transgressions – end encryption not only in Canada, but worldwide. The proposal has had three readings in the House of Commons and last week received its first reading in the Canadian Senate. All of this, notes Thorin Klosowski of the Electronic Frontier Foundation, has occurred in a complete absence of serious debate. In fact, the Conservative minority has accused the Liberal government of attempting to ram through the legislation through highly unusual and “undemocratic” methods. This Lawful Access Act, as it’s also known, was recently scrutinized by The Citizen Lab at the University of Toronto. Their findings read like that moment in a blockbuster when the horror-stricken protagonists flip through the pages of a diabolical secret plan, then look despairingly into the distance while the minor chords swell to a crescendo. And with good reason. The bill’s second part in particular is a pro-surveillance, anti-privacy juggernaut, which The Citizen Lab sums up as a “mix of open-ended powers, flexible safeguards, and a government-driven oversight framework that excludes strict judicial controls.” The net effect of this new regime will be to create “significant human rights, privacy, and cybersecurity hazards.” What could possibly go wrong? In an open letter urging C-22’s withdrawal, the Global Encryption Coalition zeroed in on the privacy Achilles heel that the legislation’s second part represents: “There is no way to provide backdoor access to encrypted data and communications without compromising the privacy and security of millions of law-abiding citizens. This is particularly true in the wake of new AI systems that can autonomously scan software, find the vulnerabilities created by encryption backdoors, and write attacks to break in.” If ever there was a bill that deserves vigorous debate, says the Canadian Civil Liberties Association, this is it. Even worse, the damage to security and privacy caused by the Salt Typhoon should remind us that killing encryption would be a gift to China, as well as to common criminals. Your smartphone can become a 24/7 surveillance device without you making a single wrong click Four years ago, PPSA warned about the rise of “mercenary spyware” – powerful surveillance tools once reserved for elite intelligence agencies that were rapidly becoming available around the world. The poster child for this trend was Pegasus, the Israeli-developed “zero-click” spyware capable of silently taking over a smartphone, activating its camera and microphone, turning it into a full-time surveillance device that extracts nearly every detail of a person’s life. Human Rights Watch reports that the market for such dystopian surveillance technology is now truly global. A new investigation based on leaked Bulgarian export licenses reveals that a surveillance company called Circles received approval to export similarly sophisticated communications interception and phone-tracking technologies to a wide range of foreign governments between 2018 and 2023. According to the documents, Bulgarian authorities licensed exports to Azerbaijan, Bahrain, Brazil, the Dominican Republic, El Salvador, Ghana, Guatemala, Israel, Jordan, Malaysia, Mexico, Morocco, Panama, Serbia, and the United Arab Emirates. The governments of many of these countries have been criticized by human rights organizations for surveillance abuses, restrictions on press freedom, and crackdowns on political dissent. Human Rights Watch concluded that the licenses raise serious questions about whether European export controls designed to prevent abusive surveillance exports are being enforced. What Can These Systems Do? The leaked documents describe a suite of surveillance products that far surpass traditional wiretaps. Unlike Pegasus, a “zero-click” capability that could remotely infect your smartphone without you making a single wrong click, Circles’ technology exploits chinks in the global telecommunications infrastructure, capturing your data as it is transmitted. Among the exported technologies were:
As one expert warned Congress in testimony highlighted by PPSA in 2022, capabilities once available only to a few nation-states are now available to dozens. CrowdStrike reports an 89 percent increase this year in AI-enabled attacks. The most advanced surveillance technologies are no longer confined to a handful of superpowers. They could be in the hands of almost any government – and, before long, in the hands of your competitors or personal enemies. In our next post on this topic, we will look at the corporate entities fomenting this global privacy disaster, the implications for privacy and democracy, and the need for Congress and the administration to develop responses. We’ve long chronicled how China is building the world’s most sophisticated surveillance state. Cameras equipped with facial recognition software, biometric databases, digital tracking systems, and artificial intelligence have become commonplace across the country. Now, newly reported details reveal a Chinese surveillance apparatus that is even more expansive and well-integrated than previously understood. In a report by De Zheng for DW, a cybersecurity researcher discovered an exposed Chinese police database connected to a platform known as “Bright Eyes.” The system reportedly maintained extensive records on foreign journalists, visitors, and residents, including passport photographs, visa information, travel histories, and other personal details. But what makes Bright Eyes remarkable is not merely the quantity of data it collects. It is the way the system combines disparate information into what Chinese authorities call a “holistic personnel archive,” creating “holographic profiles” of individuals. According to the report, Bright Eyes integrates data from facial-recognition cameras, immigration records, hotel registrations, transportation systems, mobile-phone identifiers, and other databases. The system reportedly can identify not only that a person traveled but also precisely where that person sat on a train, when he entered a venue, and who was nearby. De Zheng notes: “It even synchronizes photos from different camera systems and checkpoints, creating a continuous visual record of a person's movements.” Because the system has access to multiple streams of information, authorities can reconstruct a person's activities with extraordinary precision. Officials can analyze not only an individual's movements but also relationships, routines, and patterns of behavior over time. Perhaps most striking is the system's apparent emphasis on social connections. The report describes analytical tools designed to determine “how frequently targets are captured interacting on camera, revealing exactly who knows who, and how much time they spend together.” The system maps human networks for social and political analysis. China’s surveillance architecture offers a warning about the direction technology can take when constitutional constraints are absent. The technologies involved – artificial intelligence, facial recognition, data aggregation, and predictive analytics – are becoming more powerful. The Solomon Islands in the South Pacific provide a stark example of how this surveillance state can be exported. David Pierson and Berry Wang of The New York Times detailed the pushback by local residents after China installed its “model police state” through a secret agreement with that country’s government. The Australian Strategic Policy Institute warned that the Solomon Islands is becoming China’s “proving ground for authoritarian practices under the guise of community service.” An official mouthpiece of the Chinese government described such Western reactions as “the discomfort of former colonial powers whose exclusive influence in the Pacific is no longer assured.” But who is the real imperialist in this scenario? The lesson for Americans is straightforward. Privacy is more than a setting. It is the condition that makes free speech, free association, religious liberty, and a free press possible. Once governments acquire the ability to know everything about everyone, the freedoms guaranteed by the First and Fourth Amendments become increasingly difficult to exercise in practice. China’s “holographic profiles” show why constitutional limits on surveillance matter now more than ever. That’s something for Congress to keep in mind when it considers whether to revisit surveillance policy in the ongoing Section 702 debate in two years or much longer. The speed at which artificial intelligence is evolving should lead Americans to insist that Congress keep a tight leash on any would-be American version of Bright Eyes. Canada’s “Lawful Access” Bill Raises Alarm in Congress Over Encryption and Americans’ Privacy5/18/2026
Two powerful House committee chairmen are warning that a sweeping Canadian surveillance proposal could undermine the privacy and cybersecurity of Americans by pressuring U.S. technology companies to weaken encrypted services. At stake is the privacy of Americans who depend on robust encryption to protect sensitive communications, health data, financial records, and personal communications from unwarranted intrusion. In a May 7 letter to the Canadian Minister of Public Safety, House Judiciary Committee Chairman Jim Jordan and House Foreign Affairs Committee Chairman Brian Mast expressed concern that Canada’s proposed “Lawful Access Act of 2026,” known as Bill C-22, would dramatically expand the Canadian government’s ability to compel access to encrypted data. The lawmakers wrote: “Canada’s Bill C-22, currently under consideration in Parliament, would drastically expand Canada’s surveillance and data access powers in ways that create significant cross-border risks to the security and data privacy of Americans … “Bill C-22 would allow Canadian government officials to compel American companies to build backdoors into their encrypted systems, thereby introducing systemic vulnerabilities that could be exploited by hackers, foreign adversaries, and cybercriminals.” At the center of their concern is the requirement for “electronic service providers” to enable government access to data. The bill also authorizes confidential “ministerial orders” compelling providers to comply with demands, while prohibiting disclosure of those orders. “Dangerously Vague” Jordan and Mast argued that these powers are dangerously vague and compel weakening of encryption technologies. They wrote: “If a U.S.-based provider is forced to redesign its system to facilitate Canadian authorized access to content that is currently inaccessible even to the provider itself, the resulting capability cannot be geographically limited.” This could open the way for hostile actors and states to steal Americans’ data at a massive scale. The chairmen referenced the 2024 “Salt Typhoon” intrusion as evidence that government-mandated access points inevitably become attractive targets for hostile actors. Privacy and civil liberties advocates are voicing similar concerns. The Electronic Frontier Foundation warned that Bill C-22 would provide “a mechanism for the Minister of Public Safety to demand companies create a backdoor to their services,” while Meta stated publicly that the bill could “break, weaken, or circumvent encryption.” Endangers the Vulnerable PPSA has long warned that mandates weakening encryption in one democratic nation inevitably create ripple effects far beyond national borders. Breaking secure encryption could endanger journalists, dissidents, religious minorities, businesses, attorneys, and ordinary citizens from criminals and hostile foreign actors alike. Jordan and Mast urged Canada to pursue formal cooperation mechanisms under the CLOUD (Clarifying Lawful Overseas Use of Data) Act framework, which allows cross-border access to digital evidence while preserving legal safeguards and judicial oversight. As Congress debates surveillance reform at home, the dispute over Canada’s Bill C-22 underscores a growing international reality – efforts by governments to weaken encryption abroad can directly threaten the privacy and cybersecurity of Americans at home. The Associated Press last year wrote a landmark series of six stories about the role that U.S. tech firms play in global surveillance, particularly in China. “Made in America, Watched Worldwide,” just won a Pulitzer for international reporting. The award is richly deserved, honoring the efforts of multiple journalists who worked painstakingly on the project for three years. Celebrating their efforts is an opportunity for all of us in the privacy community to reflect not only on the AP’s key findings but also on the ominous realization that the technology described is homegrown. In other words, it can just as easily be sold to U.S. agencies and directed at the American people. That’s over 90,000 distinct entities when you add up the total number of federal, state and local government operations. In other words, U.S. technologists not only helped design the Chinese surveillance state, we’re also not that far from having one ourselves. This danger is growing more acute with the ability of AI to transform information into actionable knowledge and to turn individual data points into personal dossiers. So let’s think about that as we briefly summarize the AP’s topline findings. Everything in this list is all-too-easily capable of being implemented here in the United States:
One of the heroes of AP’s reporting is longtime Chinese activist Zhou Fengsuo. Arrested and imprisoned as a student leader during the Tiananmen protests, the now-U.S. citizen Zhou testified before Congress in 2024, warning that the lack of privacy guardrails and meaningful reform “is a strategic failure by the United States.” Current legal guardrails on American surveillance are not keeping pace with advancing technologies and questionable partnerships unmasked in AP’s series. And that gap underscores the urgent need for robust reform of surveillance laws – before these untethered AI networks are fully (and permanently) turned inward. Congress should take a deeper look into the technologies U.S. companies are selling to China and other adversarial nations – and how they are being deployed here. The rapidly escalating power of AI should especially make it clear why the House leadership proposal to extend FISA Section 702 for three years is unacceptable. Does That Make It Okay for American-Made Cars to Spy on Us as Well? If Chinese-made cars are “surveillance packages on wheels,” as one U.S. senator warns, then Americans should ask a harder question: Why are we comfortable driving surveillance packages built at home? Why You Currently Can’t Buy Chinese Cars China’s BYD electric cars are a marvel. Well-crafted with roomy interiors, stuffed with lots of high-tech bells and whistles, and efficient charging, they would, if sold in the United States, provide tough competition to American-made electric cars. But you cannot buy a BYD in the U.S. market. They are still banned under a Biden-era rule forbidding Chinese automotive software and hardware, along with a prohibitive 100-percent tariff on Chinese cars. Now President Trump is reported to be considering a deal with PRC leader Xi Jinping to allow China to enter into U.S. joint ventures with American automakers to make them here. A Bill to Outright Ban Chinese Cars Enter Sens. Bernie Moreno (R-OH) and Elissa Slotkin (D-MI), who have introduced the Connected Vehicle Security Act, which would ban Chinese-made connected vehicles and their hardware and software components from the American market. What do they mean by “connected”? These senators note that Chinese-made cars can collect, process, and transmit the geolocation, operational, and personal information of drivers and passengers. That is why Sen. Slotkin, who served in the Central Intelligence Agency before entering politics, called Chinese cars “surveillance packages on wheels, with the ability to collect on American citizens and sensitive sites.” The bill’s language not only targets these cars for their espionage potential, but also – more alarmingly – for the possibility of their “remote takeover” on American roads. It is likely no coincidence that these two senators are from two states known for their U.S. car plants and large electoral blocs of American autoworkers. Sen. Moreno, who owned car dealerships before his election, said that “the fate of the American auto industry and countless autoworkers depends on” a ban on Chinese cars. Clearly, protectionist sentiment is at play here. But it is also undeniable that Sen. Slotkin is right – Chinese-made goods incorporate surveillance as a feature, not a bug. As we’ve reported, even Chinese-made toasters and baby monitors are a concern. With cars, as with toasters, “Made in China” should come with the warning “Watching from China.” American Cars Are “Surveillance Packages on Wheels,” Too The senators’ proposal overlooks the built-in surveillance features of cars made in America, as well as those from friendly allies like Japan, Korea, and Germany. Cars to be sold next year must adhere to the Biden-era drunk driver detection systems. In a new car in 2027, if you appear to be impaired – perhaps rattled because you urgently need to drive someone to the ER – you might find your car disabled by a kill switch. Privacy advocates are alarmed by proposals to use cameras and microphones to scan drivers for signs of impairment. Would conversations be recorded and kept in a database? Would every passenger be logged as well? Even now, the seats in our cars record our weight, and our GPS systems and tire-pressure monitoring systems track, record, and report where we go. Given China’s recent behavior, skepticism about Chinese software and hardware on the roads is well deserved. And certainly Xi’s regime is nothing if not malevolent toward America. But let’s not kid ourselves – automotive surveillance is a Made-in-America threat to privacy, too. Congress should hit the brakes – or at least establish guardrails – on the surveillance systems in the cars we already drive every day. Short answer: Yes. Longer answer: Hell, yes. Carter Page, a former foreign policy advisor to the 2016 Trump presidential campaign, will be paid $1.25 million to settle claims for surveillance that resulted from an FBI that knowingly made untruthful claims against him before the secret Foreign Intelligence Surveillance Court (FISA) Court. At a time when history is measured in news cycles, this may seem like ancient history to many in Washington. And yes, the Page debacle concerned Title I of FISA, a different surveillance authority from the FISA Section 702 authority, whose reauthorization is now the subject of intense debate in Congress. But the Carter Page ordeal is well worth revisiting. It does, in fact, have a lot to say about the current Section 702 controversy. The Essentials of the Carter Page Debacle The FBI obtained four improperly obtained surveillance orders from the secret FISA Court to surveil Page. Under the law’s “two hop” rule, these orders not only allowed the FBI to spy on Page; they also allowed the FBI to spy on anyone Page communicated with (such as the Trump campaign manager) and anyone that person communicated with (the candidate himself). One doesn’t have to be an admirer of Donald Trump to find it beyond dangerous for the FBI to investigate a presidential campaign, and ultimately the candidate himself, in the middle of a national election. This is especially true when we consider that the whole investigation was predicated on lies the FBI told the court, accompanied by a forgery in the form of a document altered by an FBI attorney. Does that sound overwrought? Consider: The four secret surveillance orders were the direct result of the Department of Justice and the FBI committing acts of omission and commission in their representations to the FISA judge in 2016 and 2017. Department of Justice Inspector General Michael Horowitz – a Democrat, by the way – conducted an exhaustive investigation that identified 17 “significant inaccuracies and omissions in each of the four applications.” The FBI, in its surveillance application for Page, did not inform the court that the basis of its suspicions – an intelligence report produced by a dodgy ex-MI6 officer, Christopher Steele – was something that the Bureau itself had concluded was completely unreliable. Indeed, the “Steele dossier’s” most salacious report, that Russian intelligence had a “pee tape” of Trump cavorting with micturating prostitutes in a Moscow hotel room, was later determined by Horowitz’s investigation to have started as a bar joke. Not only did the FBI know that the basis for probable cause presented to the court was sketchy, but it also falsified evidence. Former FBI lawyer Kevin Clinesmith would later plead guilty to altering an email from the CIA that he had submitted as evidence to the court. What had been altered? The court asked if Carter Page had a connection to the CIA. He had, in fact, been a secret operational contact for the CIA, which had given Page its highest rating for dependability. The FBI attorney altered that CIA document, changing it from affirming Page’s relationship with that agency to denying it. Some Obvious Conclusions We admit to feeling a little personal about this. PPSA attorneys have represented Page in his quest for justice. We can attest that Page – who was subjected to repeated FBI interrogations and a day-long examination before a grand jury – spent months in a lonely, personal hell. Had Page made the slightest mistake in his recollections, he could have been sentenced to years in federal prison. He deserves every penny of this settlement. But the takeaway for the public and every Member of Congress – Democrats as well as Republicans – should be what this story tells us about Section 702. It has been revealed that under Section 702, the FBI secretly surveilled U.S. Senators and U.S. Representatives, a state judge, political and religious organizations, and journalists. If the FBI is willing to be this disingenuous before a federal judge, just imagine what it might be willing to do with the communications of everyday Americans obtained by Section 702 programs that are usually warrantless and lack direct judicial oversight of individual queries. Far from being ancient history, the Carter Page ordeal is a constitutional cautionary tale – one Congress ignores at the peril of every American’s Fourth Amendment rights. Rep. Jim Jordan, Chairman of the House Judiciary Committee, and Rep. Brian Mast, Chairman of the House Foreign Affairs Committee, are urging the United Kingdom Home Secretary to reveal details of a secret order to Apple that may kill encryption for Americans and Apple customers around the world. The secret order involves Apple’s Advanced Data Protection, which offers customers end-to-end encryption so strong that even Apple itself does not have the ability to break it. As a result, journalists and their sources, women and their children hiding from stalkers, dissidents around the world, businesses communicating about proprietary products, and people who simply value their privacy, all rely on Apple’s ADP to protect their communications. In February 2025, the UK Home Office – roughly equivalent to the U.S. Department of Homeland Security – issued a Technical Capability Notice (TCN) to Apple demanding access to end-to-end encrypted data stored in Apple’s iCloud. In order to be able to continue to serve Britons with other products and services, and to protect customers’ privacy, Apple was forced to comply with the law by disabling ADP for 35 million iPhone users in the UK. This had the additional unfortunate effect of depriving Americans and people from around the world of the ability to privately communicate with UK Apple customers – including with other Americans inside the UK. The UK’s Gag Order – an American Company Cannot Talk to Its Government “However, it remains unclear whether this action satisfies the UK’s demands, particularly as the order reportedly extends to data of users outside the UK, including American citizens,” Jordan and Mast wrote in a letter to Home Secretary Shabana Mahmood. Such an order is not only in violation of the Clarifying Lawful Overseas Use of Data (CLOUD) Act, which authorizes the U.S. to enter into data-sharing agreements with the UK and a few other countries, but prohibits orders that require providers to decrypt data. Incredibly, the UK government’s TCN imposes a gag order on Apple that makes it a criminal violation for this American company to petition or even discuss the order with the U.S. Department of Justice. The “Bare Details” of the TCN Are Not Enough Since then, a tribunal in the UK rejected the idea that “the revelation of the bare details of the case would be damaging to the public interest or prejudicial to national security.” Late last year, the Investigatory Powers Commissioner, which advises Prime Minister Keir Starmer, agreed with the tribunal’s ruling, saying that disclosure of some details about the TCN is necessary for “a mature and informed public debate.” Yet no such briefing is in the works, which is why the chairmen are now making a direct request to UK Home Secretary Mahmood to provide a briefing that would spell out the terms of the TCN to the committees by March 11. What’s more, the committees need more than the “bare details” of the TCN to ensure that the actions of the UK government are within the terms of the CLOUD Act. Otherwise, how could Chairmen Jordan and Mast ascertain if the order weakens “the security, privacy, and constitutional rights of American citizens”? PPSA applauds the chairmen for taking this stand for the right of Americans. The U.S. Can Suspend the CLOUD Act Agreement with the UK Bob Goodlatte, former Chairman of the House Judiciary Committee and PPSA Senior Policy Advisor, who helped lead the passage of the CLOUD Act in 2018, is pointing to a way out if the UK does not respond to Jordan and Mast. In a letter to Attorney General Pam Bondi on Dec. 12, Goodlatte noted that the CLOUD Act was intended to streamline cross-border cooperation, but “was never intended by Congress to be leveraged by a foreign partner to compel any form of ‘backdoor’ access or other types of decryption assistance.”
The letter from Chairmen Jordan and Mast did not invoke the possibility of taking this strong action. But Home Secretary Mahmood would be wise to realize that this is likely a step the Trump administration and Congress will take if the British government continues to remain resistant to American concerns. Why do so many Americans object to the expansion of surveillance networks like Flock technology that can track where we drive, pervasive Ring networks that show where we walk, and government purchases of our personal data that reveal information about us that is more sensitive than a diary? After all, this is for our own good – to protect us. We can trust the government, right? One reason for alarm among the civil liberties community is that we have seen how these separate surveillance systems can be woven together by AI to create a comprehensive surveillance state. This used to be the stuff of dystopian science fiction. Today, it is a functioning model we can see in real time across the Pacific. Consider the Fujian Police Academy in China, which at the end of last year released an internal document that shows how AI can detect unrest by weaving together actionable intelligence from sound sensors, cameras, reports from paid community spies called “grid workers,” and other sources. The China Media Project unearthed and analyzed this document (linked here for Mandarin readers) showing how comprehensive surveillance can further the cause of “social governance.” China Media Project reports that:
China Media Project summarizes: “Throughout the past year, institutions across China, both private and state-owned, have proposed variations of the same system: taking big data from China’s extensive surveillance system – including input from street cameras and satellites, noise sensors, social media posts, as well as reports from social services – and feeding it into AI models to aid predictive policing.” Of course, Washington is not Beijing. We are not going to find ourselves having to memorize the platitudes of our Dear Leader and spout them online in order to enjoy internet and travel privileges. But the technological ambition – to fuse disparate surveillance streams into systems for “predictive policing” – is not uniquely Chinese. This ambition was reflected in the post-9/11 attempt by the Pentagon to create “total informational awareness” – an ambition finding new life in the many surveillance elements that PPSA reports on daily. Unlike the “netizens” of China, we can urge our elected leaders to take us off the path that leads to a surveillance state. Congress has an immediate opportunity to do exactly that. One step off this path would be the passage, this April, of measures to end the purchasing of Americans’ most sensitive and personal data by the FBI, the IRS, the Department of Defense, the Department of Homeland Security, and other federal agencies. The lesson from China is not that America is doomed to follow the same path – but that once surveillance systems integrate, pulling them apart becomes exponentially harder. We will keep you posted as the surveillance debate heats up in Congress. If you got a Roomba for Christmas, we have good news and bad news. The good news is that your product will likely continue to be supported despite the company’s recent bankruptcy filing. The bad news: this Massachusetts-based brand may soon be just another piece of Chinese-owned spy tech. Amazon tried to buy iRobot, the maker of Roomba, in 2021, but that deal was ultimately nixed by the Federal Trade Commission on antitrust grounds. Now, if a judge approves the pending sale of iRobot to Shenzhen Picea Robotics, Roomba will join numerous brands under the ever-expanding surveillance umbrella that many Chinese products represent. Not that China is the sole problem when it comes to protecting the privacy of American consumer data. The United States has no robust privacy laws apart from a few state initiatives, and the data practices of companies like Amazon are a mixed bag. But the Chinese Communist Party doesn't even pretend to care about privacy, instead marketing highly functional (and affordable) electronics capable of gathering all manner of personal information. This ill-fated combination has created a veritable Wild West when it comes to the consumer electronics market. iRobot says Roomba will remain an American brand, a claim that means little when no one is minding the privacy store in the first place. So you can either trust that your data will be treated with care (good luck) or you can try to protect yourself just a bit. According to experts, disconnecting from Wi-Fi and Bluetooth will likely disable any advanced features but will not prevent Roomba models from actually cleaning. “Advanced features” in this context mostly mean updates to the app, which Roombas can operate without. And it certainly refers to a data pipeline that goes straight to who-knows-where, replete with maps of your home’s layout and eye-level images of your pets and you playing on the floor. Remember, any connected devices, including vacuum cleaners, can be (and have been) hacked. Apps are black holes for data and privacy anyway. So just press “Clean” and forget it. Former House Judiciary Committee Chairman Bob Goodlatte Urges DOJ to Suspend U.S.–UK Data Deal12/19/2025
General Warrants Are Back – This Time in Digital Form If you’ve read Rick Atkinson’s prize-winning books on the American Revolution or watched Ken Burns’ documentaries on that founding event, you know how deeply Americans have always valued privacy. The Revolution itself was sparked, in part, by outrage over the British Crown’s use of “general warrants” – sweeping authorities that allowed the King’s agents to ransack homes, warehouses, offices, and ships at dock in search of anything they deemed suspicious. Now, nearly 250 years after the Declaration of Independence, London is at it again. This time, the British government is executing a plan to override the security and encryption protections built into U.S. technology products – exposing the private data of Americans, and potentially users around the world, beginning with Apple devices. The CLOUD Act — and a Deal Gone Wrong PPSA Senior Policy Advisor Bob Goodlatte knows this territory well. A former congressman from Virginia and Chairman of the House Judiciary Committee, Goodlatte helped lead passage in 2018 of the Clarifying Lawful Overseas Use of Data Act, better known as the CLOUD Act. The CLOUD Act allows the United States and trusted foreign partners to enter into data-sharing agreements, enabling law enforcement to seek data through warrants or subpoenas regardless of where that data is stored. But Congress paired this authority with firm guardrails to protect privacy, civil liberties, and the rule of law. One of those agreements – the U.S.–UK Data Access Agreement (DAA) – has now veered sharply off course. “I am deeply troubled by how the United Kingdom has taken advantage of our goodwill,” Goodlatte wrote in a letter sent late last week to Attorney General Pam Bondi. Britain’s Abuse of Surveillance Powers At issue is the UK’s use of so-called Technical Capabilities Notices, or TCNs, issued under the UK Investigatory Powers Act. These secret orders can compel U.S. technology companies to weaken, delay, or suspend the deployment of essential security features, including end-to-end encryption. “The threat to Americans’ privacy from these measures is real,” Goodlatte warned, whether the UK’s actions affect U.S. companies’ global products or are limited to services offered in Britain. Even in the latter case, he explained, the consequences are profound: increased risk of global surveillance, compromised digital infrastructure, and a direct assault on the protections Congress demanded when it approved the agreement. Approval Rights and Gag Orders on U.S. Companies Goodlatte also pointed to a particularly alarming requirement: U.S. companies must notify the British government before rolling out security upgrades – precisely the kind of foreign leverage Congress explicitly sought to prevent. The CLOUD Act’s promise of streamlined cross-border cooperation, he wrote, “was never intended by Congress to be leveraged by a foreign partner to compel any form of ‘backdoor’ access or other types of decryption assistance.” Even worse, UK policy reportedly imposes gag orders that prevent U.S. companies, starting with Apple, from disclosing this interference even to the U.S. government itself. The Only Remedy: Suspend the Agreement The CLOUD Act anticipated this scenario. Under the DAA, the United States may suspend or terminate the agreement when a partner government’s laws or practices materially undermine its privacy and civil liberties commitments. “Accordingly,” Goodlatte wrote, “I urge the Department of Justice to invoke Article 12.3 and suspend the Agreement unless and until the UK withdraws its use of TCNs.” During passage of the CLOUD Act, Goodlatte insisted on strong congressional oversight of the law’s implementation. Now, he is calling on the Justice Department to enforce the deal’s terms – and protect Americans from a digital revival of the general warrants our founders fought to abolish. Expect sitting Members of Congress to take up that call as well. Almost every day, we learn of new capabilities in China’s ever-expanding surveillance and intimidation operations. Xi Jinping’s regime is perfecting its ability to track enemies, even as far from Beijing as West Texas. Consider the story of Li Chuanliang, a retired Communist Party official who fled China and was granted asylum in the United States. Now in Midland, Texas, Li told the Associated Press: “They track you 24 hours a day. All your electronics, your phone – they’ll use every method to find you, your relatives, your friends, where you live: No matter where you are, you’re under their control.” What’s even more disturbing may be the source of China’s capabilities. Technology first deployed to track and persecute China’s Muslim Uyghur minority now helps power the country’s worldwide surveillance network, supported by technology developed in the United States. When the AP asked U.S. companies about their role in such potentially deadly technology transfer, most deflected: “IBM said in a statement that it sold its division making the i2 program in 2022, and has ‘robust processes’ to ensure its technology is used responsibly. Oracle declined comment, and Microsoft did not respond.” But for China, it’s all been a golden opportunity – literally. The regime named the U.S.-derived lynchpins of its surveillance network “Golden Tax,” “Golden Finance,” and “Golden Audit.” (See also China’s notorious Golden Shield program, which American cyber-giant Cisco helped to build.) The Chinese Communist Party hunts for its perceived enemies in-person as well as online. It involves attempts to recruit American citizens to the cause, according to court filings against two Chinese organizations. The schemes included the use of fake social media accounts to intimidate Chinese dissidents residing abroad. And, it seems, they occasionally have help from U.S. citizens such as an ex-New York cop convicted of hunting dissidents for the PRC. It’s a sordid tale and, sadly, far from an isolated incident. Nor is the tale of such transnational aggression limited to state actors like China alone. In addition to matters of statecraft, the human toll exacted by such global Big Brother programs is immeasurable, as seen in the mental health effects of state surveillance on Chinese students who are merely studying in the United States. Some have cut all ties to family and friends back home to protect their loved ones from the suspicion that comes from simply being in America. We should remember these souls during this season of light. If you know a Chinese student or resident who doesn’t seem to have many friends here, it might not be by choice. Consider reaching out to them in person and offering your support. Just be careful about using your cellphone (or theirs) to make plans. Consider getting your church involved too, like congregants in Midland did for Li and others. Speaking of which, check out the AP’s poignant photo essay chronicling Li’s attempts to build a new life in Midland, together with other Chinese expatriates. Now more than ever, be careful about choosing collaboration partners. That’s the lesson Strategy Risks and the Human Rights Foundation are drawing in a new report. Their findings are a jaw-dropping wake-up call about China manipulating Western institutions into giving up cutting-edge AI knowledge to serve its dictatorship. Here’s the play-by-play:
It gets worse. U.S. Department of Defense agencies were also involved in the funding process, and their specialized involvement helped drive research into national security questions: Optical-phase-shifting tech and biometric monitoring, to cite two examples. The Chinese military is keen on tracking people using drones and facial recognition algorithms. Or more to the point: it is keen on surveilling, detaining, and persecuting more than one million Uyghur Muslims. The report found that ethics watchdogs on the Western side lost their bark. Only two bothered to call out the troubling connection between Western institutions and their Chinese collaborators in the five years since 2020. “A staggering lack of interest,” is how the Human Rights Foundation characterized it to Fox News Digital. Still, in defense of what may have simply been an appalling level of naiveté on the part of Western researchers, the report concludes: “Chinese laboratories are rarely listed as direct grant recipients, allowing them to bypass due-diligence checks while benefiting directly through co-authorship and knowledge transfer. Taxpayer resources generate knowledge that flows into institutions embedded in China’s apparatus of repression.” The report then calls for the following guardrails: Mandatory due diligence on human rights, full disclosure of international partnerships, and expanded ethics mandates for AI institutes. It’s a lesson the FBI itself still needs to learn. We would add that this revelation cries out for congressional oversight and hearings – and if the facts warrant it – threats to cut off federal funding. Of course, those guardrails will have no effect on China’s institutions, where security and technology firms are required to share their findings with the Chinese Communist Party. But at least such reforms will give us a fighting chance to stymie these covert spycraft efforts, as well as to disabuse ourselves of the Faustian illusion that such collaborations were ever, or will ever be, business as usual. Keep Lummis-Wyden in the NDAA to Secure the Pentagon – and Our Democracy – from Foreign Hackers10/31/2025
National security wake-up calls do not get louder than the revelation that a Chinese government-linked hacking group, known as Salt Typhoon, successfully penetrated major U.S. telecommunications carriers in 2024. AT&T and Verizon were among the companies compromised, exposing the communications of Members of Congress, senior officials, and even both major-party presidential candidates. This was not an isolated breach. It followed a 2023 cyberattack in which Chinese state hackers infiltrated Microsoft’s cloud-hosted email systems, compromising accounts at multiple federal agencies, including the Departments of State and Commerce. According to the Cyber Safety Review Board, the attackers downloaded roughly 60,000 emails from the State Department alone. Pilfered correspondence included those of Cabinet-level officials. These events underscore an uncomfortable truth – the Department of Defense and the intelligence community cannot defend the nation with unencrypted communications routed through a handful of vulnerable providers. The good news is that we do not have to accept this status quo. As the House and Senate negotiate the National Defense Authorization Act (NDAA) for Fiscal Year 2026, conferees must retain the Lummis-Wyden amendment, which mandates secure, interoperable, end-to-end-encrypted collaboration tools for the Pentagon. A Pattern of Foreign Infiltration From defense contractors to cloud service providers, adversarial regimes have repeatedly exploited weak communication infrastructure to spy on U.S. institutions. The Salt Typhoon and Microsoft incidents illustrate how a single breach in a major service can compromise thousands of sensitive conversations. When communication systems lack end-to-end encryption, even one point of failure can expose entire networks to foreign intelligence agencies. What Lummis-Wyden Would Do This measure requires the Department of War to use only collaboration systems that meet rigorous cybersecurity standards – including true end-to-end encryption that ensures only the sender and intended recipient can read a message, even if servers in between are hacked. Just as importantly, Lummis-Wyden mandates interoperability. Today, the Pentagon is confined to using a small set of proprietary, “walled garden” platforms that block seamless communication across systems. Interoperable standards would allow the Defense Department to adopt superior tools as they emerge, preventing vendor lock-in that traps communications in the domains of single companies, while enhancing long-term resilience of the Pentagon’s digital networks. By promoting interoperability and strong encryption, Lummis-Wyden would open the door to competition, inviting companies to develop more secure, agile, and affordable solutions. America’s defense and intelligence agencies should never be dependent on single-point-of-failure vendors whose systems are ripe targets for global espionage. A Strategic Imperative From the theft of federal employee records to the infiltration of telecom carriers, the pattern is unmistakable: insecure communications infrastructure is a strategic liability. Passing Lummis-Wyden would do more than patch vulnerabilities: it would redefine what secure collaboration means in the 21st century. It would signal that America prizes both privacy and resilience, and rewards technologies that deliver genuine end-to-end security rather than superficial compliance checkboxes. “Made in China” products should carry the warning “Watching from China,” according to threat assessor Michael Lucci in an interview with Fox News. Nebraska Attorney General Mike Hilgers agrees and is suing the Chinese firm, Lorex, accusing it of using technology the FCC banned in 2022. Lorex cameras are commonly sold by U.S. retailers ranging from Costco to Best Buy, Kohls, and Home Depot. Nebraska’s complaint accuses Lorex of using tech from Dahua, one of the companies the FCC banned after accusing it of sharing American consumers’ data with the Chinese government. So far, Lorex and other companies have managed to get around the ban by employing a popular strategy known as “white labeling,” in which products are made generically by Company A but sold under Company B’s name. India recently made a similar determination about such products, imposing stringent new security requirements on mostly Chinese-made CCTV cameras. As we wrote at the time, China’s rap sheet when it comes to using products to spy on other countries is a long one. Nowhere is this truer than in the United States, China’s largest trading partner and most persistent observer. Lorex’s cameras are frequently sold for in-home surveillance of infants and small children. But what threat could a baby monitor pose? Who cares if every gurgle and burp is captured? Consider: With video and audio monitoring, Beijing could listen in to the conversations of parents who work in the military or in intelligence agencies. Knowing when thousands of parents with such duties are being called in for a weekend or late night could, in an emergency, be priceless strategic intelligence. The device could also be within earshot of parents talking about work in a way that yields intelligence about commercial business plans or useful Washington gossip. As always, China is playing a numbers game. The PRC hoovers in vast intelligence, and then turns to AI and a vast army at the Ministry of State Security and its many consultants to winnow out useful intelligence. That is why Attorney General Hilgers calls these baby monitors a “national security issue.” Even if all Beijing has access to is Mom asking Dad to go to the kitchen for a bottle of milk, the erosion of privacy is galling. No American couple signs up to let a foreign government in their baby’s bedroom. If these concerns are accurate, then parents and families aren’t the only ones being watched. All of which also makes us queasy about the growing popularity of AI-powered children’s toys – or, perhaps, justifiably paranoid. We’ve recently reported on how Mexico is managing to surpass even the expansive surveillance state ambitions of Washington, D.C. Mexico has passed laws that require every person to enroll in biometric ID systems that must now be presented for any significant transactions in banking, schooling, social services, and health care. This data, in turn, is fed into a “Central Intelligence Program” that can be accessed by civil and military forces. An update by Karen Gullo at EFF shows just how Orwellian the new system actually is: “The Mexican government passed a package of outrageously privacy-invasive laws in July that gives both civil and military law enforcement forces access to troves of personal data and forces every individual to turn over biometric information regardless of any suspicion of crime. “The laws create a new interconnected intelligence system dubbed the Central Intelligence Platform, under which intelligence and security agencies at all levels of government – federal, state and municipal – have the power to access, from any entity public or private, personal information for ‘intelligence purposes,’ including license plate numbers, biometric information, telephone details that allow the identification of individuals, financial, banking, and health records, public and private property records, tax data, and more. “You read that right. Banks’ customer information databases? Straight into the platform. Hospital patient records? Same thing …” Of course, a Mexican citizen can opt out, provided they are willing to live off the grid without a bank account, healthcare, children in school, or much of anything else. Mexico’s turn from a multi-party democracy to a state dominated by one party – the Morena Party – makes this collectivization of biometric data even more problematic. As Washington toys with the idea of a national ID, which would have to be based on biometrics to be effective, the uses and abuses of such a database south of the border should be top of mind. In a prior age, some politicians were accused of being so paranoid about communism that they saw “a Red under every bed.” We will leave the judgments of history to others, but it is a plain fact that today the People’s Republic of China is, if not exactly under our beds, surrounding us with potential surveillance devices embedded in everything from shipping cranes at U.S. ports to coffee pots in American hotels. Now the Federal Highway Administration warns that “certain foreign-manufactured power inverters” and battery management systems of solar-powered highway infrastructure contain radios hidden within them. These devices power highway infrastructure including signs, traffic cameras, weather stations, solar-powered visitor areas, warehouses, and electric vehicle chargers. This raises the possibility of not just surveillance, but of components that could be used for extensive spying or even remotely switched off, which would create an immediate freeze-up of highway traffic and possibly mass casualties. Reuters, which first reported this FHA memo, also reports that “industry group Green Power Denmark said that unexplained electronic components had been found in imported equipment for Denmark’s energy supply network.” Here is our advice for U.S. policymakers and industry: QUIT BUYING ANYTHING FROM CHINA THAT CAN BE WEAPONIZED. We have never before reverted to all bold caps, but it should be clear by now that seeding weaponized devices from a hostile government is a suicidal proposition. We should either take this tariff moment to make such critical infrastructure here at home, or at least buy from manufacturers from democracies (such as Mexico) that we can trust. While writing this, we had a sudden jolt of fear – are there, in fact, reds under our bed? Some of us own smart mattresses that report how long and how well we slept during the night, including how much of our night was spent in deep sleep, light sleep, and REM sleep, as well as a stream of health data. To our relief, the brand we own is American-made. But some brands of smart mattresses are made in China. The good news: The communists are not under your bed. The bad news: For some consumers, they may actually be your bed. If you don’t like the feeling of being followed, we recommend avoiding Stockholm, Dubai, Almaty, and – this just in – Mexico City. All are major destinations under constant and growing surveillance by public cameras. Izabelė Pukėnaitė at Cybernews reports that Mexico’s capital is now launching a mass surveillance CCTV plan with the suitably creepy name of “Eyes That Look After You.” Let’s break that down: 30,000 new cameras, 15,200 new poles, a $19 million budget, and a whole lot of connectivity. Each pole will have two cameras, one fixed and one capable of tilting/zooming. All of this comes as Mexico’s ruling Morena party moves to eliminate numerous independent regulatory and oversight agencies. One of those was a body that functioned as an ombudsman for the population, with the power to force government departments to hand over information citizens had filed requests for – a sort of Mexican version of the Freedom of Information Act. As is always the case when such moves are enacted, the powers that be resort to doublespeak. “There will be more transparency,” declared Mexican President Claudia Sheinbaum, adding, “the public will be able to easily review the functioning, the spending, and everything the Mexican government does.” An equally disturbing maneuver is the Morena party’s radical overhaul of the country’s judicial system that critics say could easily lead to unabashed one-party rule. Color us skeptical, but we’re having a hard time seeing how a party that is voraciously concentrating its own power is going to use a new mass surveillance system to somehow make people freer – especially a camera system that the cartels have already used to target and kill informants. These “eyes” aren’t designed to “look after” anyone. “Look for” is more like it, which, thanks to new legislation mandating a single biometric ID for all Mexican citizens, will soon be easier to do than ever. It is not hard to imagine these systems being used by Morena-controlled officials for political surveillance. You might be tempted to think at least that could never happen here. It already is. Washington, D.C., beats out Mexico City as the global city with the most government-controlled cameras per capita. Oh well, Ojos que no ven, corazón que no siente – What the eye doesn’t see, the heart doesn’t grieve. It’s hard to believe we have to write this. In 2025, after years of warnings about Chinese surveillance threats, the FBI is still certifying biometric surveillance devices made by Chinese Communist Party–linked companies – including Hikvision, a firm already sanctioned for human rights abuses and banned from receiving U.S. federal contracts. Yes, that Hikvision. According to a bipartisan letter released this week by the House Select Committee on the Strategic Competition Between the United States and the Chinese Communist Party, the FBI maintains a Certified Products List that includes devices from 32 Chinese companies, several with ties to the Chinese military-industrial complex. These certifications effectively offer a “stamp of approval” to products that not only could pose a risk to American privacy but are manufactured by companies blacklisted by other parts of the U.S. government. Let that sink in: A company banned under federal law from receiving government contracts due to national security risks is, at the same time, having its surveillance gear certified as safe and trustworthy – by the FBI. This jaw-dropping contradiction was called out in a forceful letter from Committee Chairman John Moolenaar (R-MI) and Ranking Member Raja Krishnamoorthi (D-IL). The lawmakers warned FBI Director Kash Patel that including these products on the agency’s certification list “sends a dangerous signal” to government buyers and private entities alike, potentially encouraging wider adoption of Chinese-made surveillance tech. They’re absolutely right. Hikvision, to name just one example, was placed on the Commerce Department’s Entity List in 2019 for its role in enabling the Chinese government’s mass surveillance and oppression of Uyghur Muslims in Xinjiang. It has since been sanctioned under multiple federal authorities, including Executive Order 13959 for its ties to the Chinese military. And yet today, its biometric gear can still carry an FBI certification label? The American people deserve to know: How did we get here? Who in government is asleep at the switch? Civil liberties groups have long warned about the quiet spread of foreign surveillance technologies, particularly those from authoritarian regimes, into American infrastructure – both public and private. The fact that U.S. law enforcement agencies are facilitating that spread through outdated or unvetted certification programs is nothing short of alarming. And it raises troubling questions: Does the FBI have a robust vetting process for foreign vendors? Are they coordinating with other federal agencies to ensure consistency in national security policy? Or are we witnessing another example of institutional inertia allowing critical lapses in judgment? We applaud Reps. Moolenaar and Krishnamoorthi for sounding the alarm. It should not take congressional intervention for the FBI to apply common sense to its own certification processes. It’s time for the FBI to get serious about technological due diligence. When it comes to Americans’ privacy and national security, there is no room for double standards. Hearing Evokes Unprompted, Strong Endorsement of a Warrant Requirement for Section 702 The CLOUD Act of 2018 is a framework for working with U.S. tech companies to share digital data with other governments. This law and basis for international agreements was a reasonable concession to allow these companies to do business around the world. But the agreement has gone off the rails because of the United Kingdom’s astonishing attempt to force Apple to break end-to-end encryption so they can access the data of all Apple users stored in the cloud. Rather than violate the privacy of its users, Apple has stood by its customers and withdrawn encrypted iCloud storage from the UK altogether. The House Judiciary’s Subcommittee on Crime and Federal Government Surveillance was already skeptical about that agreement, but appalled when the British government used it to secretly order Apple to provide that unfettered, backdoor access to all the cloud content uploaded by every Apple user on the planet. It was an unprecedented request, and an unexpected one from a fellow democracy.
In April, members of the House Judiciary Committee asked Attorney General Pam Bondi to terminate the U.K. agreement. As extreme as that sounds, PPSA supports that proposal as the best way to persuade Britain to back off an unreasonable position. In the worst-case scenario, no agreement would be better than comprehensive violation of Americans’ privacy. Undeterred, the subcommittee convened a recent hearing entitled “Foreign Influence On Americans’ Data Through The CLOUD Act.” Greg Nojeim from the Center for Democracy & Technology was an invited witness. If one had to name a single theme to his powerful testimony, it would come down to one word: “dangerous.” Subcommittee Chairman Andy Biggs used the same word, declaring the secretive British demand of Apple “sets a dangerous precedent and if not stopped now could lead to future orders by other countries.” Ranking Judiciary Committee Member Jamie Raskin struck a similar chord: “Forcing companies to circumvent their own encrypted services in the name of security is the beginning of a dangerous, slippery slope.” In short, the hearing demonstrated that the CLOUD Act has been abused by a foreign government that does not respect privacy and civil liberties or anything remotely like the Fourth Amendment to our Constitution. It needs serious new guardrails, beginning with new rules to address its failure to protect encryption. Expert witness Susan Landau of Tufts University warned the subcommittee that the U.K. appeared to be undermining encryption as a concept. A U.S.-led coalition of international intelligence agencies, she observed, recently called for maximizing the use of encryption to the point of making it a foundational feature of cybersecurity. Yet Britain conspicuously demurred.
That debate will likely become intense between now and next spring when Congress takes up the reauthorization of Section 702 of FISA, the Foreign Intelligence Surveillance Act. Judiciary Chairman Jim Jordan indicated as much when he used his opening remarks to tout the “good work” the Committee has ahead of it in preparing to evaluate and reform Section 702. Later in the hearing, Chairman Jordan returned to the looming importance of the Section 702 debate, asking each of the witnesses in turn a version of the question, “Should the United States government have to get a warrant before they search the 702 database on an American?” All agreed without hesitation. “Wow!” declared Rep. Jordan in response. “This is amazing! We all think we should follow the Constitution and require a warrant if you're going to go search Americans’ data.” Rep. Raskin nodded along. And that’s as bipartisan as it gets. Israel’s spycraft is first-rate. From the “pager” attacks that decapitated Hezbollah, to the surgical strikes over the last few days that have eliminated Iran’s top generals and scientists, it is clear that Israel’s strategic success owes much to world-leading intelligence capabilities in the digital realm. “In Israel, a land lacking in natural resources, we learned to appreciate our greatest national advantage – our minds,” said the late Israeli Prime Minister Shimon Peres. Under constant threat, Israel has applied its great minds to information technology in the service of national defense. What works well in the national security space for Israel, however, is a problem for the rest of the world when cutting-edge surveillance technologies are exported. PPSA has extensively covered the Israeli-based NSO Group, which released malware called Pegasus into the international market. Pegasus is a “zero-click” attack that can infiltrate a smartphone, extract all its texts, emails, images and web searches, break the encryption of messaging apps like WhatsApp and Signal, and transform that phone’s camera and microphone into a 24/7 surveillance device. It is ingenious, really. Zero-click means the victim doesn’t have to accidentally fall for a phishing scam. The malware is just installed into a phone remotely. Victims can then be counted on to do what we all do – compulsively carry their smartphones with them wherever they go, allowing total surveillance of all they and their friends say and do.
Another Israeli technology company, Paragon, differentiates itself from the NSO Group by promising a more careful approach. Its U.S. subsidiary promises that it is about “Empowering Ethical Cyber Defense.”
Much of the world media reports that an indignant Italian government severed ties with Paragon. But Israeli media reports that after the Italian government rejected an offer by the company to investigate one of these cases, it was Paragon that unilaterally terminated its contract with the Italian government. The takeaway from all this is that even with a responsible vendor who sets guardrails and ethical policies, a zero-click hack is too tempting a capability for intelligence services, even those in democracies. Whether Pegasus or Graphite, a zero-click, total surveillance capability is like a dandelion in the wind. It will want to go everywhere – and eventually, it will. The Ninth Circuit ruled that American tech companies share a degree of liability if their tools facilitate human rights abuses in other countries. The court’s 2023 decision meant that thirteen members of the Falun Gong spiritual practice group could continue to press their years-long case against Cisco Systems for its role in supporting China’s “Golden Shield.” Golden Shield is the Chinese Communist Party’s domestic internet surveillance system. Members of the Falun Gong creed claim that the Chinese government used the Cisco-powered system to aggressively persecute them in a long-running and coordinated campaign. Because a significant portion of Cisco’s work on Golden Shield was done in the United States, ruled the Ninth Circuit, the plaintiffs had sufficient standing to sue here. Importantly, the court noted that, “Cisco in California acted with knowledge of the likelihood of the alleged violations of international law and with the purpose of facilitating them.” The company’s role was essential, direct, and substantial to the point of being liable for “aiding and abetting.” As the Electronic Frontier Foundation points out, this ruling wouldn’t apply to American companies that merely market a tool that anyone could buy and then potentially misuse. What happened in this case was different. Cisco is alleged to have designed, built, maintained – and even upgraded – a “customized surveillance product that the company knew would have a substantial effect on the ability of the Chinese government to engage in violations of human rights.” In so many words, said the Court in assessing Cisco’s role, the Chinese couldn’t have done it without them. To wit, Cisco empowered the following aspects of the Golden Shield surveillance system:
Cisco is accused of doing this while simultaneously helping the Chinese build a nationwide video surveillance system. The result was a state-of-the-art integrated system capable of creating “lifetime” information profiles on Falun Gong members, so full-featured that it could even be updated with data from members’ latest “interrogation” and “treatment” sessions at the hands of Chinese security personnel. Cisco is alleged to have done it all in an environment in which it is common knowledge that torture, and other violations of international law, are likely to take place. This is not conjecture, but clear information in news coverage, shareholder resolutions, State Department communiques, etc. Cisco rejects the Ninth Circuit’s decision, and recently asked the U.S. Supreme Court to grant cert and rule in its favor. As of now, the High Court has yet to decide whether or not it will do so, but on May 27 it asked the Solicitor General to weigh in with the government’s opinion. This case has always been about testing whether foreign victims can sue U.S. companies for deliberately helping foreign governments commit human rights abuses – an inevitable outcome of advanced surveillance systems in particular. Let’s hope the Supreme Court will deny Cisco’s request. If it does, that will only mean that the case will move forward in California and Cisco and its accusers will still get a full and proper hearing. This is too important a question with too many far-reaching implications to skip a step. India has a pro tip for would-be users of surveillance cameras, especially ones installed in your own government’s buildings: Don’t buy from China. Recognizing since at least 2021 that they might have a teensy-weensy security problem with the one million Chinese-made cameras installed in government institutions, India has finally decided that maybe they should, well, do something. In April, according to Reuters, Indian officials met with 17 surveillance gear makers and asked them if they were ready to play by the country’s new rules, which require closed-circuit television (CCTV) vendors to “submit hardware, software and source code for assessment in government labs.” And to absolutely no one’s surprise, they answered (more or less), “Um, no. We don’t like your rules, so, we’re not ready.” All of which is to say, the surveillance gear makers pitched a wall-eyed fit, predictably portending industry losses, marketplace tremors, timeline impacts, and disruption of various unspecified projects. Of all the CCTV players, China has the most to lose, given their million installed cameras and that 80 percent of all camera components in India are Chinese-made. For its part, China sees India’s new rules as a smear campaign. But it’s hard to be sympathetic when U.S. officials discovered:
The U.S. government has wisely banned certain brands of Chinese telecom equipment because they posed an unacceptable risk to U.S. national security. But India reminds us that we need to do more. We don’t think India’s stance is old-fashioned protectionism, as some of the new policy’s detractors would like to suggest. Given China’s track record, we consider it a prudent form of self-preservation and risk mitigation. In February, a Department of Homeland Security (DHS) bulletin connected the dots in no uncertain terms: Chinese cameras double as spy tools for the Chinese Communist Party and could even be used to disrupt critical U.S. infrastructure. The DHS bulletin’s advice is as clear as its warning: “Broader dissemination of tools designed to help recognize PRC cameras, particularly white-labeled cameras, could tighten enforcement of the 2022 Federal Communication Commission (FCC) ban on the import of these cameras and help mitigate the threat of PRC cyber actors exploiting them for malicious purposes.” Tens of thousands of such cameras are currently used across U.S. sectors that include critical ones like the energy and chemical industries. Yet the DHS bulletin notes that because of loopholes like the aforementioned “white-labeling” (where imported cameras ship under other companies’ brands), the ongoing proliferation of this Chinese spy tech continues. It’s time to end practices like white-labeling banned Chinese cameras. And while we’re at it, let’s open up the cases on samples of CCTV cameras sold here and have a look inside. And if doing so “voids the warranty,” we should just take our chances. Ireland’s Data Protection Commission, acting in its official capacity as an EU privacy guardian, recently fined TikTok $600 million (€530 million) for breaching its data privacy rules. This punishment was meted out after the conclusion of a four-year investigation, so it’s a decision that was not made lightly. None of this surprises us. We have previously reported on the surveillance issues related to TikTok as well as other Chinese-owned concerns. It’s naïve to think that any software of Chinese provenance isn’t being used as a data collection scheme, and equally naïve to believe that said data isn’t being shared with the Chinese government. A year ago, Congress passed a law mandating that ByteDance, the Chinese parent of TikTok, divest its ownership else be banned in the United States. ByteDance could be rich beyond all the dreams of avarice if it chose to sell. That it hasn’t done so simply reinforces everyone’s suspicions that the service’s real owner is primarily interested in something other than profits. The bill that President Biden signed had passed the House 360-58 and the Senate 79-18. TikTok sued but the Supreme Court upheld the law in a unanimous ruling in January. It’s an astonishingly bipartisan issue in a deeply divided time. Yet in a mystifying turn of events, the current administration has twice extended the original divestment deadline (now set for June 19). “Perhaps I shouldn’t say this,” President Trump told NBC’s Kristen Welker, “but I have a little warm spot in my heart for TikTok.” Quite the switch for someone who rightly attempted to ban the service during his first term. After the latest show of bad faith by Tik Tok revealed by Irish regulators, President Trump should now enforce this sale – after all, it is a law, not a suggestion – and protect our citizens. It is the president’s constitutional duty to carry out the laws the American people pass through the voice of their representatives. A show of seriousness about enforcing this law would probably allow TikTok to survive in some form. Moreover, it would protect tens of millions of Americans from Chinese government surveillance. |
Categories
All
|
RSS Feed