|
Can authorities rifle through the location histories of thousands of innocent people to catch one guilty person? One federal judge in Mississippi recently gave a decisive answer: No. U.S. District Judge Carlton Reeves of the Southern District of Mississippi had no qualms about drawing the line at the exact edge of the U.S. Constitution. This case concerned “tower dumps,” in which authorities require a cellular provider to produce information concerning every device that connected to specified cell towers during a defined period. On Aug. 5, Judge Reeves held that such “tower dump” warrants are per se unconstitutional. Ryan T. Fenn and Lee M. Cortes, Jr. of Arnold & Porter report in Enforcement Edge that Judge Reeves based his ruling on the conclusion that such searches intrinsically violate the Fourth Amendment because, by their nature, tower dumps cannot be particularized. It is, therefore, impossible to establish probable cause as required by the Fourth Amendment with respect to each device captured. Judge Reeves acknowledged that tower dump warrants can be “uniquely effective” in catching criminals by placing them at the scene of a crime. His concern was that such a search, however, also sweeps in information belonging to thousands of people who have no connection to the investigation. In his opinion, Judge Reeves wrote that the government cannot obtain “an entire haystack because it may contain a needle.” Judge Reeves extended the logic of the Supreme Court’s 2018 Carpenter ruling, which recognized a privacy interest in cell-site location information, but declined to address tower dumps. He also noted that the recent Supreme Court Chatrie decision held that geofence warrants are searches, regardless of the time limits placed on a warrant. The logic of these cases extends to tower dumps, which can identify people inside their homes, offices, and houses of worship – data Judge Reeves found to be “intimate and deeply revealing.” Will this federal judge’s ruling in Mississippi upend the common practice of scraping mass data from cell-phone towers? Will it set a precedent that will quickly bring other forms of mass surveillance – such as federal agencies’ purchases of Americans’ digital lives from data brokers and the increasingly ubiquitous network of public and private cameras to which law enforcement has easy access – under constitutional scrutiny? Short answer: Not likely. But it is still a very positive development. As Fenn and Cortes write, “this is one decision from a district judge – it binds no other court, not even others in the Southern District of Mississippi.” True. We believe, however, that Judge Reeves’s ruling is significant. It is likely to inspire more such cases and rulings – coming down on both sides of the issue – that will force the Supreme Court to provide a more detailed and comprehensive answer on the constitutionality of all forms of geolocation tracking. Stay tuned. The Department of Homeland Security (DHS) is assembling a surveillance infrastructure capable of tracking people’s faces, phones, cars, movements, communications, and associations – and then combining that information into detailed personal dossiers. That is the alarming picture presented by a new Brennan Center for Justice report. Since January 2021, DHS has committed more than $2.9 billion to surveillance, data collection, and analytical tools. Because federal contracting records are opaque and often incomplete, the Brennan Center cautions that this figure is probably a minimum. The department’s arsenal falls into six broad categories: video surveillance, biometrics, location tracking, access to phone content, commercial-data purchases, and data analytics. DHS has spent or promised more than $1 billion for biometrics alone. Its tools can identify people through facial and iris recognition, including through mobile devices used by agents in the field. One system, Mobile Fortify, can collect information about anyone – including U.S. citizens – and DHS documentation says images may be retained for 15 years. Meanwhile, Customs and Border Protection has promised more than $675 million for drones. Although its drone program has long been justified as a border-security tool, the Brennan Center reports that drones have also been deployed inside the country to assist immigration raids and monitor protests. DHS also purchases access to commercial data capable of tracking phones and vehicles. Its technology can extract messages, contacts, photographs, and other contents from cellphones. Information from these sources flows into centralized repositories, where artificial intelligence tools can search across databases, connect disparate facts, and generate leads, targets, and detailed profiles. One such system, ICE’s Repository for Analytics in a Virtualized Environment, or RAVEn, allows investigators to combine information from multiple databases. Another tool, Palantir’s Enhanced Leads Identification and Targeting for Enforcement, maps individuals’ locations and connects them with other personal information to guide enforcement operations. DHS policies generally prohibit acting solely because someone engaged in constitutionally protected speech, association, or dissent. But that protection offers little comfort when surveillance tools have reportedly been directed at protesters and observers. A database does not forget that someone attended a rally, visited a religious institution, met with a political organization, or associated with an unpopular group. The real danger lies not in collecting each piece of information, but in combining the pieces. Cameras, biometric databases, cellphone searches, location histories, commercial records, and AI analytics together give the government the power to reconstruct a person’s life. Congress funded this expansion. It must now reassert control over the purse, investigate how these technologies are being used, and impose enforceable privacy safeguards for American citizens. A comprehensive domestic surveillance machine is much easier to restrain before it becomes a permanent feature of American life. An unsecured police database has provided a rare glimpse inside China’s surveillance state. The database examined by The New York Times tracked hundreds of foreigners. But its significance extends far beyond the surveillance of foreign residents. As The Times reports, its existence illustrates how Chinese authorities aggregate vast amounts of information from surveillance cameras, medical records, utility bills, facial-recognition systems, and other sources to monitor and analyze individuals’ behavior. The database included hospital visits, gas payments, frequently visited locations, and air and rail travel – down to seat numbers. It tracked one woman’s movements from her home to shopping malls, restaurants, and supermarkets, sometimes using facial recognition. The power of China’s surveillance system does not rest on any single camera or database. It comes from joining countless streams of personal information into one comprehensive picture. Now for the turnabout: Is the United States a surveillance state like China – or are we about to become one? Consider recent reports on the domestic surveillance capabilities our government already possesses: • Foreign communications: Section 702 of the Foreign Intelligence Surveillance Act, now awaiting congressional reauthorization, allows federal agencies to collect global communications. That collection inevitably sweeps in Americans’ messages, which the FBI has searched millions of times in recent years. Congress must debate a warrant requirement before federal agencies are allowed to search Section 702 data for Americans’ communications. • Forcing businesses to spy on their customers: The “Make Everyone a Spy” provision of the most recent FISA reauthorization in 2024 dramatically expanded the definition of an electronic communications service provider. It can require owners and operators of commercial facilities and even churches housing communications equipment (including common services like free WiFi) to assist government surveillance – and remain silent forever under a gag order. • Political and social-media activity: The Wall Street Journal reports that ICE has established a round-the-clock dragnet across Facebook, Instagram, X, and other platforms. Contractors prepare dossiers that can include a person’s name, address, workplace, Social Security number, vehicle registration, and criminal history. DHS has reportedly issued hundreds of subpoenas to identify anonymous critics, while agents have confronted Americans over online speech. • DNA: According to Wired, ICE may have contributed almost 920,000 DNA profiles to the FBI’s CODIS database in 2025 alone. The broader DHS collection program includes people accused of no crime. Newly released CBP records show that it has even collected DNA from children as young as four. • Air travel: The Securities and Exchange Commission purchased access to more than one billion airline-ticketing records, according to 404 Media. These records covered not only domestic U.S. flights and international flights involving the United States, but also travel between foreign countries. The airline-owned data broker reportedly made this information available without passengers’ knowledge and likely without warrants. • Movements on the ground: Flock Safety cameras record millions of drivers in thousands of American communities. Flock has announced plans to combine license-plate-reader records with public records, open-source intelligence, and commercial “people lookup” data. This can transform a vehicle sighting into a dossier – and allow algorithms to generate suspicion from ordinary patterns of movement. So, is the United States a surveillance state? In terms of capabilities, yes. In terms of intent, not quite – at least not yet at the comprehensive, integrated scale practiced by China. It would take a concerted effort to bring all these elements together into a single system – integrated by artificial intelligence – to comprehensively surveil Americans through their faces, foreign communications, DNA, geolocation, movements, searches, and interests. In short, what separates the United States from Chinese levels of comprehensive surveillance is not capability. It is the intent of government officials – and our trust that they will respect the institutional and constitutional restraints that stand in their way. And in case you have been living off the grid in the Australian Outback for the last decade, trust is in short supply these days. The story of the mobile spy SUVs purchased by the state of Texas for $4.5 million continues to unfold. According to Alex Barrientos of Gadget Review, the Texas Department of Public Safety’s purchase of four Chevy Tahoes includes an extra $3.9 million for a proprietary surveillance system from a company named Cognyte, Israel’s version of Palantir. Cognyte is the maker of the FalcoNet surveillance technology embedded in the SUVs. FalcoNet, writes Andrew Collins of The Drive, has already been deployed in Florida (as has similar stingray technology elsewhere). Its purpose is simple, if ominous: get between cellphone towers and any phones that happen to be near them, and then secretly intercept and capture everything that being transmitted. FalcoNet and its competitors do this by pretending to be ordinary cell towers, tricking every phone nearby into connecting (smartphones can't help themselves because they are programmed to respond to the strongest signal). Cognyte claims FalcoNet can be activated in under three minutes and can connect with thousands of devices at once as the surveillance vehicles roll through traffic and past pedestrians. Those intercepts are meant to catch the communications of bad actors being sought by authorities. But the software cannot filter out the private information of bystanders from that of suspects, which means that Texas and Florida are sweeping up the data of everyone who happens to be in the mobile system’s vicinity. The data of thousands of innocent persons can then be sifted through afterward. This presumes that only law enforcement will do the sifting – and not hackers, data brokers, or hostile state actors. Even so, that is cold comfort given what we know from the actual abuse and potential misuses of similar surveillance systems. The growing use of stingrays, whether installed on poles in busy parts of town, in mobile police units, or even mounted on drones, underscores the importance of commercial encryption services in protecting our everyday communications. We should be able to enjoy the same level of privacy in our texts and emails that we expect when having a private conversation with a friend. Equally important, the entire premise of such spy regimes – no matter what the official rationalization – flies in the face of the Fourth Amendment. Designed to protect against the invasive and indiscriminate mass searches of general warrants, the Fourth Amendment offers a simple calculus: probable cause + a court warrant + narrowly defined search criteria. In their current forms, programs like the aptly named FalcoNet – and it is a net – are functional dragnets, modern-day general warrants that thwart every aspect of the Constitution’s privacy safeguards. Not even outmoded interpretations of the third-party doctrine can (or should) be invoked to save them. The good news is that we now live in the Chatrie era. In that recent decision, the U.S. Supreme Court clearly articulated a fundamental right to certain forms of digital privacy, specifically regarding location tracking (including geofencing, the whole raison d'être for those shiny new Texas spy SUVs). In short, this practice of roving mass surveillance is ripe for a challenge in court. When PPSA last examined Canada’s proposed Lawful Access Act, we described how it could undermine encryption and endanger privacy worldwide. Now Sen. Ron Wyden (D-OR) is warning that the bill could also enable the Canadian government to conscript American technology companies into spying on Americans. Bill C-22, which has passed Canada’s House of Commons and is now before the Canadian Senate, would grant authorities in Ottawa sweeping new surveillance powers. It would require service providers to retain sensitive user metadata, such as location information, for up to a year. It could also force companies to alter their systems to facilitate government access or install tracking capabilities and security backdoors. In a letter to Secretary of State and acting National Security Adviser Marco Rubio and acting Attorney General Todd Blanche, Sen. Wyden writes that the bill “threatens to weaponize American technology infrastructure by enabling the Canadian government to force U.S. companies to secretly facilitate surveillance of Americans, while systematically undermining the security of their products.” A foreign government could conceivably pressure an American company to retain special backups of an American target’s data, relocate encryption keys to a jurisdiction where they could be seized, or deliver government spyware through a compromised software update. The target could be anyone. As Sen. Wyden warns, “U.S. law does not explicitly prohibit American companies from secretly facilitating foreign surveillance of U.S. citizens – even if the target is the President or another senior U.S. government official.” “This is not a dilemma of U.S. companies being caught between conflicting international legal obligations,” he writes. “It is a glaring statutory vacuum.” Canada is negotiating an agreement with the United States under the CLOUD Act, which would enable Canadian authorities to seek some data directly from American companies. Sen. Wyden urges the Trump Administration to use those negotiations to obtain “ironclad, explicit prohibitions” against Canadian demands that U.S. companies reengineer their products or facilitate surveillance of Americans. As PPSA has warned, there should be no encryption backdoor reserved for trustworthy governments. Any vulnerability can be exploited by hostile governments, criminals, and increasingly capable artificial intelligence systems. Sen. Wyden puts the principle succinctly: “Bilateral trust with our closest intelligence partners cannot be built on the secret subversion of American cybersecurity infrastructure.” The Trump administration should heed his warning. Canada must not be permitted to turn American technology companies into instruments of secret spying on Americans. "Custom-house officers may enter our houses, when they please ... may break locks, bars, and everything in their way; whether they break through malice or revenge, no man, no court can inquire." |
Categories
All
|


RSS Feed