Samantha Murphy Kelly of CNN Business news has a snappy take on Amazon’s recent product press event. The company, she wrote, “knows when you’re in and out of the room. A gadget that monitors your breathing pattern while you sleep. An enhanced voice assistant that highlights just how much it knows about your everyday life.”
She notes another event where Amazon introduced drones and Astro, a dog-like robot that can patrol the home when you’re gone.
Will consumers be deterred by the creep factor of giving so much of our personal information taken from the intimacy of our homes? Kelly quotes a consumer analyst who said that “negative consumer attitudes” about data collection is lessened by the service, price, and convenience of these products.
It is easy to see why consumers are sanguine about sharing data with a company that sells products and services they like. All Amazon wants to do is to sell us even more products. Dangers emerge, however, when consumer data migrates beyond the company you’re doing business with. Amazon, for its part, says that “information about our customers is an important part of our business, and we are not in the business of selling our customers’ personal information to others.”
The company does share information with third parties, such as vendors whose goods are sold through Amazon. A recent FTC filing against the data broker Kochava shows that Amazon Web Services Marketplace allows companies to buy consumers’ IP addresses and precise geolocation histories. Amazon also encourages its Ring customers to share their data with police agencies across the country – creating a national surveillance network stitched together from more than three million cameras.
Whatever the limits of Amazon’s privacy policies, most of the other major social media platforms freely sell consumer data to brokers. Among the major customers of this data, as PPSA has endlessly reported, are the intelligence and law enforcement agencies of the U.S. government – reason why PPSA has joined with almost fifty other civil liberties organizations to call for the passage of the Fourth Amendment Is Not for Sale Act.
Your dog may follow you around the house, but she will never judge you. Not so with the many devices that are infiltrating into our lives.
If you thought being subjected to “random” TSA screenings at airports was dehumanizing, just imagine your most sensitive, personal digital information being secretly reviewed by any one of thousands of government agents operating without a warrant or public oversight.
The Customs and Border Protection Commissioner Christopher Magnus revealed to Sen. Ron Wyden (D-OR) that the agency is scooping data from thousands of seized electronic devices every year. (Hat tip to Drew Harwell of The Washington Post for detailing this abuse of privacy.) That data is then added to a CBP database accessible by more than 2,700 CBP agents. That data – which can include call logs, messages, contact lists, and photos – can be kept for up to 15 years.
This story is just the latest development in a long-running series of data privacy breaches by federal law enforcement officials. Sen. Wyden criticized the agency for “allowing indiscriminate rifling through Americans’ private records.”
CBP conducted more than 37,000 searches of travelers’ devices in the 12 months ending in October 2021. According to The Washington Post, the default configuration for some data searches has been to download and retain all contact lists, call logs and messages. This means potentially millions of calls, contacts, and text messages from thousands of phones could be compromised.
It has long been known that CBP makes generous use of the “border search” exception in Fourth Amendment law. Sen. Wyden’s revelation about the scale and the scope of this loophole reveals an egregious new threat to the security of Americans’ data privacy. Congress must act now to bolster protections for data privacy.
It is high time for the Supreme Court to review and modify the judicially created border search exception in light of the massive amounts of information being seized from law-abiding citizens and then stored for long periods of time. If the Court does not protect the Fourth Amendment, then Congress should step up.
Last year, Sens. Wyden and Rand Paul (R-KY) introduced legislation that would require border officials to get a warrant before searching a traveler’s device. Congress should also pass the Fourth Amendment Is Not for Sale Act to ensure this database doesn’t fall into the hands of data brokers.
Last week, PPSA reported on Fog Reveal, a product from Fog Data Science that sells billions of data points extracted from apps on 250 million mobile devices to local police departments. An unlimited-use, one-year subscription costs a department only $7,500.
For this price, Fog Reveal offers a powerful capability, the ability to track hundreds of millions of Americans in their daily movements. It allows police to locate every device in a given geo-fenced area. It also allows police to trace the location history of a single device (and therefore, its user) over months or years.
Fog Data Science claims that it is respectful of privacy because it does not reveal the names or addresses of individual users. But a slide show from Fog Data Science prepared for police highlights how this technology can easily be used to track a suspect to his or her “bed-down” over a 180-day period. (Hat tip to the Electronic Frontier Foundation, which helpfully added yellow highlights to significant passages of Fog documents.)
It is more than a stretch then to call this data “anonymized” when it follows people to their homes, as well as to their houses of worship, meetings with friends or lovers, trips to health or mental health clinics, journalists meeting with whistleblowers, or other locales that reveal sensitive and personal information.
For those in law enforcement who go through the motions of filing a warrant, Fog Data Science offers a template warrant. Such warrants are misbegotten. They can be employed to follow a number of people in the vicinity of a crime or track everyone who attended a political protest. The Fourth Amendment requires “probable cause” in which a warrant describes “the place to be searched, and the persons or things to be seized.” It makes a mockery of the Constitution’s requirement for particularity when the police have at their fingertips a whole ocean of data involving many people. How can such a requirement be fulfilled when Fog technology allows police to go on a fishing expedition in that ocean, with any American potentially being a catch?
It is through technologies such as Fog Reveal that our country, device by device, is moving steadily toward becoming a full-fledged surveillance state.
Such details should spur Congress to investigate the uses of this technology. It should also inspire Congress to pass the Fourth Amendment Is Not for Sale Act, which would block the auctioning of our private, personal information to all government agencies.
PPSA recently reported that prosecutors charged two Twitter employees with being spies for Saudi Arabia. One of the men fled the country. The other was convicted.
Now, more bad news for Americans concerned about privacy. While Twitter’s shareholders were approving the $44 billion sale of their company to Elon Musk on Tuesday, Peiter Zatko, Twitter’s former head of security, testified before the Senate Judiciary Committee about the state of security inside the social media platform. Zatko said that the FBI had informed him that at least one agent of China’s Ministry of State Security was “on the payroll inside Twitter.”
Zatko told the senators: “I discovered that the company had ten years of overdue critical security issues, and it was not making meaningful progress on them. This was a ticking time bomb of security vulnerabilities.” He added that he made the decision to inform the FBI, which led to his dismissal. “In those disclosures, I detail how the company leadership misled its Board of Directors, regulators, and the public. Twitter’s security failures threaten national security, compromise the privacy and security of users, and at times threaten the very continued existence of the company.”
In his more than two hours of testimony, Zatko described Twitter’s senior management as deliberately ignoring security issues to protect the bottom line. “It doesn’t matter who has keys if you don’t have any locks on the doors,” he said. “It’s not far-fetched to say an employee inside the company could take over the accounts of all the senators in this room.”
At least two agents for the Indian government were on the company payroll, Zatko said, as well as the one from China. Some ads sponsored by the Chinese government appeared to have been designed to specifically capture user information.
“Twitter is acting dangerously and negligently to turn its back on user safety,” Nora Benavidez, Free Press senior counsel, told The New York Times. These alleged Twitter breaches, as bad as they are, come on top of a host of similarly disturbing stories about privacy.
From foreign infiltration of Twitter, to potential exposure of the data of American TikTok users to Chinese intelligence, to the practice of private data brokers selling Americans’ personal information scrapped from apps to U.S. law enforcement and intelligence agencies – it is clear that we are in a privacy crisis with implications for Americans’ well-being and national security. One way that Congress can respond to that crisis is by passing the Fourth Amendment is Not for Sale Act, which would ban the sale of private data to the government. Once that bill passes, it will be a helpful achievement in creating momentum to deal with all the remaining privacy issues.
To quote a line from a great play, “attention must be paid.”
A growing number of House and Senate members are supporting the Fourth Amendment Is Not for Sale Act, which would require law enforcement and intelligence agencies to obtain a probable cause warrant before accessing Americans’ personal information purchased from a private-sector data broker.
But what about non-state actors buying our information?
A recent lawsuit brought against private-data broker Kochava by the Federal Trade Commission reveals the horrific exposure of Americans’ most personal data to unseen – and possibly unknown – private actors.
Kochava claims to have “rich geo data spanning billions of devices globally,” with location data feed that “delivers raw latitude/longitude data with volumes around 94B-plus billion geo transactions per month, 125 million monthly active users, and 35 million daily active users, on average observing more than 90 daily transactions per device.”
In its filing on Aug. 29, the FTC writes that a purchaser would only need to provide Kochava a personal email address and describe the intended use as “business” to gain access to your data from Kochava.
“The location data provided by Kochava is not anonymized,” the FTC filing asserts. “It is possible to use the geolocation data, combined with the mobile devices MAID (Mobile Advertising ID), to identify the mobile device’s user or owner.”
The FTC claims:
“Precise geolocation data associated with MAIDs, such as the data sold by Kochava, may be used to track consumers to sensitive locations, including places of religious worship, places that may be used to infer an LGBTQ+ identification, domestic abuse shelters, medical facilities, and welfare and homeless shelters.” It can identify women who visit reproductive clinics and people who attend services at Jewish, Christian, Islamic and other religious denominations’ places of worship.
Kochava, the FTC claims, does not employ a blacklist that removes or obfuscates data-set location signals from these sensitive locations.
The facts presented by the FTC, as alarming as they are, should not get mixed up in the separate debate on the Hill over restricting the government’s ability to purchase our private data. The many federal agencies that buy our data are not just violating our privacy. They are eviscerating the plain meaning of the Constitution’s Fourth Amendment, which requires government to get a warrant from a court to access our personal information.
The solution to private-sector access to personal information is a deep and complex debate taking place within multiple Congressional committees and stakeholders from business and consumer groups. Passing the Fourth Amendment Is Not for Sale Act in this Congress, which would close off the government’s warrantless access to Americans’ personal information, would be a strong predicate for that next step in the privacy debate.
In a hearing over the summer, the House Judiciary Committee took a hard look at the way in which private data brokers freely sell Americans most personal information to a host of government law enforcement and intelligence agencies.
Chairman Jerry Nadler said that digital tracking is “so precise that officers can track individuals within specific homes and businesses … tracking your location over time, within inches, without any due process whatsoever.
“The end result is that, just by going about your daily life, your data may be swept up in and make you the subject of a criminal investigation … If law enforcement and intelligence agencies remain unrestrained in their ability to purchase this data, our right to privacy will be at best illusory.”
Ranking Member Jim Jordan said that the government continues to transform guardrails meant to protect privacy into loopholes to allow the government to do whatever it wants. Jordan said, “this is wrong and it’s un-American.”
Representatives of both parties expressed dismay about how freely federal agencies utilize and abuse surveillance powers in defiance of the Fourth Amendment. Rep. Zoe Lofgren detailed the many ways the U.S. Immigration and Customs Enforcement agency tracks Americans’ daily movements and extracts personal information from utility records. Rep. Andy Biggs spoke of the uses to which the government can employ geolocation tracking against Americans.
In short, the House Judiciary Committee did an excellent job of teeing up the issue. Now it is time to swing the club for a legislative solution.
On Wednesday, PPSA joined with Americans for Prosperity, Demand Progress, the Due Process Institute and Free Press Action to call on the committee to take bipartisan action and mark up the Fourth Amendment Is Not for Sale Act.
Local law enforcement agencies have been caught using a cheap new cell phone tracking tool called Fog Reveal. (A hat tip to The Associated Press for compiling this story). The tool gives police agencies “the power to follow people’s movements months back in time,” according to The Associated Press.
Fog Reveal has been used since at least 2018 in criminal investigations, can search billions of records from 250 million mobile devices, and is possibly a potent workaround of the 4th Amendment. It is no wonder why police rarely mention Fog Reveal “in court records, something that defense attorneys say makes it harder for them to properly defend their clients in cases in which the technology was used.”
Fog Reveal “relies on advertising identification numbers, which Fog officials say are culled from popular cell phone apps such as Waze, Starbucks, and hundreds of others” according to police emails obtained by The Associated Press. That information is then sold to companies including Fog, further demonstrating the role of data brokers in undermining the digital privacy of Americans.
“The capability that it had for bringing up just anybody in an area whether they were in public or at home seemed to me to be a very clear violation of the Fourth Amendment,” said Davin Hall, a former crime data analysis supervisor for the Greensboro, North Carolina, Police Department.
Congress must investigate the use of Fog Reveal by law enforcement agencies and bolster legal protections against such 4th Amendment violations. Congress could begin by passing The Fourth Amendment Is Not for Sale Act, which would block data brokers from selling our personal information to law enforcement and intelligence agencies without authorization by a court. Congress must work to ensure the privacy of all Americans is safe and secure.
“To exist in 2022 is to be surveilled, tracked, tagged and monitored — most often for profit.” It might sound like an exaggeration, but it’s far from it. When nearly every American is carrying a tracking device, audio and video recorder, and all their personal data in their pocket, nobody is truly private.
The cracks in our digital privacy are getting wider, allowing an almost unfiltered ocean of our most sensitive data to flow into anyone’s hands. As Alex Kingsbury writes in The New York Times:
“Consider just last week: Apple released a surprise software update for its iPhones, iPads and Macs meant to remove vulnerabilities the company says may have been exploited by sophisticated hackers. The week before that, a former Google engineer discovered that Meta, the parent company of Facebook and Instagram, was using a piece of code to track users of the Facebook and Instagram apps across the internet without their knowledge. In Greece the prime minister and his government have been consumed by a widening scandal in which they are accused of spying on the smartphones of an opposition leader and a journalist.
And this month Amazon announced that it was creating a show called “Ring Nation” — a sort of ‘America’s Funniest Home Videos’ made up of footage recorded by the company’s Ring doorbells.”
Just one of these examples should be cause for concern to any American, but the problem is simply too big for individuals to handle. As Kingsbury states, “there are simply too many tech companies, government entities, data brokers, internet service providers and others tracking everything we do.” Congress must take bold action to protect Americans from predatory data collectors and misusers.
Legislation like the Fourth Amendment is Not for Sale Act is a step in the right direction. It would prohibit law enforcement and other government agencies from purchasing bulk data from data brokers. In the wake of renewed state battles over the future of abortion rights, the My Body, My Data Act would tighten rules around personal health information. Absent these reforms, “we’re about to find out what happens when that privacy has all but vanished.” PPSA will continue to monitor these issues and fight for privacy in Congress and the courts.
Earlier this month, former Vice-President Mike Pence called out criticism of the FBI lodged by members of his own party. In his speech, Pence stated “I … want to remind my fellow Republicans we can hold the attorney general accountable for the decision that he made without attacking the rank-and-file law enforcement personnel at the FBI..” While the intent of Pence’s statement is certainly laudable, it comes at a time when the public is increasingly distrustful of the agency’s activities.
Pence’s comments have been received so poorly because they dismiss the credible concerns emanating from all sectors of the American public. The distrust towards the agency turned into full-blown outrage when the FBI raided former President Trump’s Mar-a-Lago estate earlier this month on August 8th. It has been weeks since the raid, and there has been little official explanation provided. What information we do have has been pieced together from an unsealed warrant and source leaks. From the warrant, the search was related to potential violations of three laws including the Espionage Act. Attorney General Merrick Garland said during remarks on August 11 that he would not explain why he personally signed off on seeking a search warrant. Even though documents were recovered, distrust of the agency has become so severe, that swaths of the American public may choose to believe that the evidence seized was forged and planted.
Also worried is Michael Horowitz, Inspector General of the U.S. Department of Justice. Across multiple reports, Horowitz details the abuses, noncompliance, and mishandling that is currently ongoing within the FBI. For a few examples, in September of 2021, the office of the Inspector General released a report stating that there “was widespread non-compliance with the Woods Procedures,” a set of procedures to ensure factual accuracy in FISA applications. In August of 2019, the office of the Inspector General released a report detailing the multiple rules violations by former FBI Director James Comey, indicating a culture of secrecy and noncompliance at the highest level in the chain of command. There are multiple reports detailing commercial sex, accepting illegal gifts from the media, the violation of ethics rules, and a “lack of candor.”
When American citizens display “a lack of candor,” they can be fired from their jobs. When senior officials at the FBI do it, prosecution is declined and the offending party is “reassigned to a nonsupervisory role.”
In 2019, the Foreign Intelligence Surveillance Court criticized the FBI for misleading it in applications to wiretap former Trump campaign aide, Carter Page. Inspector General Horowitz found that the FBI had omitted facts and provided false statements to the FISA court when the FBI filed for a warrant to conduct surveillance on Page. FISA court presiding Judge Rosemary Collier stated in her opinion that “The FBI’s handling of the Carter Page applications, as portrayed in the OIG report, was antithetical to the heightened duty of candor described above…”
So, not only is the public concerned, but so is the office of the Inspector General and the FISA courts, two organizations which either oversee or directly liaise with the FBI.
Just this week, the escapades of the FBI were on full display during a trial to convict two men involved in the 2020 plan to kidnap Michigan Governor Gretchen Whitmer. The already high-profile nature of the case was catapulted into the stratosphere when the FBI revealed there were at least five informants or undercover agents embedded among the suspected planners. Defense attorneys have argued there were at least twelve. The involvement of FBI agents and informants was so significant, that a trial for a separate set of suspected planners failed to get a single conviction. One informant became second-in-command of a militia. Another undercover agent offered to provide explosives to the group. It calls into question whether the FBI was engaged in entrapment.
FBI agents assigned to the case became subjects of scrutiny themselves. As the New York Times reports, “one F.B.I. agent on the case was fired last year after being charged with domestic violence, and another agent, who supervised a key informant, tried to build a private security consulting firm based in part on some of his work for the F.B.I.…” That FBI agents so close to an ongoing plan to kidnap a governor were themselves so compromised is very chilling.
It seems obvious from the last several years that the FBI is in need of both oversight and reform. An agency with significant investigatory and enforcement powers, Congress can and should do more to monitor the activities of the agency.
On Tuesday, House Judiciary Committee Chairman Jerrold Nadler and House Homeland Security Committee Chairman Bennie Thompson sent a letter to the heads of key agencies demanding answers to questions about their use of data brokers.
It is no secret that agencies ranging from the FBI to the DEA have been circumventing the Fourth Amendment by purchasing the data of millions of Americans from private data brokers. This letter is the latest sign Congress is waking up to the privacy and surveillance threat posed by data brokers contracting with the federal government.
Reps. Nadler and Thompson wrote Attorney General Merrick Garland, FBI Director Christopher Wray, Homeland Security Secretary Alejandro Mayorkas, as well as the heads of Customs and Border Protection, the Bureau of Alcohol, Tobacco, Firearms and Explosives, Immigration and Customs Enforcement and the Drug Enforcement Administration.
The two chairmen noted:
“In a recent hearing before the House Judiciary Committee, a witness stated that materials provided by data brokers ‘turn policing from a suspect-focused search into a constant, intrusive surveillance system that surveils all of us. Rather than focusing on particular suspects, data policing tools are dragnets, sifting through all of our data.’”
The letter demanded each agency provide four sets of documents:
This is a step in the right direction, and PPSA looks forward to further work by Congress on the subject. What we learn from these requests should prompt Congress to pass the Fourth Amendment Is Not For Sale Act.