|
If you rely on encrypted messaging services, take note: German authorities have found a way to read messages on WhatsApp, Signal, and Telegram without breaking the services’ encryption. According to the Netzpolitik news site (you can select an English language version on most browsers), German law-enforcement and intelligence agencies exploit the services’ legitimate “linked device” features, which allow users to access their accounts from computers and other devices. Authorities can quietly connect a government-controlled computer to a targeted account after gaining physical access to a phone, obtaining a verification code through phishing, or intercepting an SMS code. Once connected, authorities can receive future messages and – depending on the service – access earlier messages, contacts, and other account information. In some cases, the linked device can even send messages in the user’s name. Users may remain unaware because encryption remains intact. The government does all this by simply placing itself at one of the authorized endpoints. German customs authorities reportedly tested this technique beginning in 2023 and made it a permanent investigative tool in 2025 after claiming significant successes against serious and organized crime. Its legal basis, even in surveillance-friendly Germany, remains disputed. There is little reason to believe the German government is the only one doing this. Cybernews warns that the technique uses readily available functions built into popular apps. Does the FBI have this capability? That might be a good question for someone in Congress to ask. Given this exposure, what can you do to protect your privacy? When you sign on to an encrypted account, take a few seconds to review the devices linked to your account. Immediately remove any you do not recognize. Strong encryption protects communications in transit. It cannot protect users when a government – or hacker – is secretly inside a seemingly authorized endpoint. How’s this for a prompt for ChatGPT or Claude: “Give me a list of people who’ve criticized the regime in the last several months.” Artificial intelligence helps small teams accomplish work that once required large organizations. Unfortunately, that now includes secret police units in repressive regimes around the world. According to the London-based, dissident-run Iran International news site, the AI company Anthropic discovered that Iranian paramilitary and security units had used its Claude AI model to monitor Iranians’ social media posts to identify opposition and diaspora accounts. One Iranian unit analyzed hundreds of thousands of social-media posts and identified 39 opposition accounts to track. Other actors used Claude to develop tools for identifying and profiling users, including a malicious Firefox extension disguised as a prayer-times utility. Iranian units also used Claude to develop or improve a centralized surveillance case-management system. AI was not merely collecting information. It was helping the state organize its surveillance bureaucracy and decide whom to watch. The stakes of Iran’s domestic surveillance are deadly. Medical networks, whistleblowers, and unofficial leaks estimate that thousands of Iranian dissidents and protesters, most of them young men and women, have been killed in the streets or executed just before the beginning of the U.S.-Iranian war earlier this year. To its credit, Anthropic has aggressively countered this misuse of its product. In the Iranian operations, it identified and unplugged 16 Claude accounts operated by two units associated with Iranian paramilitary and domestic security agencies. Iran is far from alone in its authoritarian abuse of AI. Axios reports that government-linked actors in China and Mali have also used Claude to automate surveillance. A consultant working for Malian security authorities reportedly created a system that gathers information from mobile operators and builds dossiers on individuals. In China, an intelligence office dedicated to spying on religious organizations once required large teams of analysts in many offices. AI consolidated it to a single office capable of producing thousands of investigations each month. Chinese authorities also used Claude to evaluate politically sensitive social-media posts and identify people for “control” – potentially including coercive questioning and closer monitoring of their movements and communications. Anthropic says it banned every account associated with the surveillance operations that it uncovered and strengthened its safeguards. But the company acknowledges the limits of any response. In the case of Mali, authorities simply transferred their surveillance platform to locally operated AI models. The danger is therefore larger than one company or chatbot. As Anthropic threat-intelligence chief Jacob Klein told Axios, AI is making state surveillance cheaper and more efficient. A lone official or contractor can increasingly perform work that once required whole teams of programmers and intelligence analysts. Authoritarian governments have always wanted to monitor dissidents, journalists, religious minorities, and political opponents. AI is abolishing the practical constraints that once limited human surveillance. George Orwell’s nightmare vision of totalitarian surveillance in 1984 always faced the practical constraint of recruiting enough watchers to monitor people around the clock. For every subversive comment or passed note, the watchers of 1984 would have had to sit through thousands of hours of people eating breakfast, brushing their teeth, and walking to work. But AI repression doesn’t get bored. It needs no lunch breaks or naps. And it is here. Flock Safety cameras and other automated license-plate reader (ALPR) systems have become a national flashpoint in debates over surveillance, policing, and privacy. Even data centers poll better than Flock cameras. Now a former police chief is proposing a detailed framework intended to preserve the investigative uses of Flock and other ALPR systems while imposing new rules governing how police departments operate them. Tom Weitzel, who served as police chief in Riverside, Illinois, has released a position paper on automated license plate reader systems, including the cameras made by Flock Safety. Weitzel, a 37-year law-enforcement veteran, writes that he has seen technology improve policing – and seen its misuse damage public trust. In a letter published by Patch, Weitzel explains what prompted his proposal: “I keep watching the debate and feel stuck between two bad options: leave these systems running with no real oversight or rip them out altogether. I don’t accept either option. I’ve seen ALPR data recover stolen vehicles, locate missing people, and crack violent crime cases that otherwise would have gone cold. Walking away from that capability doesn’t make anyone safer. “At the same time, I won’t defend a system that can’t demonstrate it’s being used honestly.” Weitzel proposes that communities adopt:
We note that Weitzel’s suggested 30-day retention period for “non-hit” data – images of vehicles not related to any law-enforcement hot list – exceeds the 7-day retention period now recommended by Flock CEO Garrett Langley. We would also recommend including an explicit prohibition against tracking individuals solely on the basis of their religious, political, or journalistic activity protected by the First Amendment. His paper also proposes transparency measures, including a dashboard that reports aggregate searches, criminal-activity hits, usage audits, and disciplinary actions against officers. He proposes a public portal called “Explain My Stop,” and the selection of community members by lottery to participate in audits. Weitzel would also institute an annual “State of Surveillance” town hall and independent academic reviews. Other elements include a plain-language explanation of ALPR policies, public accounts of cases solved with ALPR assistance, optional alerts for residents whose plates are searched repeatedly, and independent compliance certification for programs. Weitzel’s framework provides a detailed set of ideas for lawmakers in Congress and state legislatures, police departments, and communities to consider as they debate whether – and under what conditions – to continue using ALPR systems Imagine you get pulled over, a police officer walks up to your window and asks: “Did you know your taillight is broken?” -or- “I pulled you over because you were weaving between lanes.” -or- “You didn’t come to a complete stop at the stop sign.” -But never- “I pulled you over because the federal government, which monitors your financial transactions, wonders if you might be engaged in illicit activity and wanted me to come up with a BS excuse to pull you over and find a reason to search your car.” We’ve long reported that federal agents are mining our private financial information to identify Americans for investigation – even when they are not suspected of any particular crime. In a disturbing investigation for 404 Media, Joseph Cox reveals that secretive predictive-policing units within the U.S. Border Patrol are analyzing Americans’ financial activity and other data. Federal agents pass their suspicions to local police, who then spot the targeted Americans in their cars and look for traffic violations and other opportunities to obtain consent to search their vehicles. This arrangement turns financial surveillance into a backdoor predicate for police encounters. Federal agents need not begin with evidence that someone committed a crime. An algorithm or analyst merely decides that a person’s spending or other activities look interesting. Police officers can then look for a broken taillight, an improper lane change, or some equally flimsy excuse to pull that person over. This practice reverses the constitutional order. Under the Fourth Amendment, law enforcement is supposed to begin with individualized suspicion and obtain a warrant when a search requires one. Predictive policing begins with mass data, generates an opaque hunch, and then goes looking for a violation to justify an investigation that is secretly already underway. These reported abuses demonstrate why financial privacy cannot be dismissed on the theory that bank records are merely business records. Financial data can provide the government with a detailed map of a person’s life. When combined with location information – perhaps from automated license plate readers like those provided by Flock Safety – purchased commercial databases, and other digital records, financial information provides the raw material for suspicionless surveillance. The partnership between federal analysts and local police adds another layer of abuse by obscuring the true origin of an investigation. Courts, defense attorneys, and defendants may see only a routine traffic stop, never knowing about the federal data dragnet operating behind it. Congress should demand full disclosure of these units’ sources, methods, targeting criteria, and coordination with local police. It should also require warrants for Americans’ sensitive financial information and prohibit federal agencies from laundering suspicionless surveillance through pretextual stops. Credit to Joseph Cox and 404 Media for exposing this machinery. The U.S. House of Representatives today passed the NDO Fairness Act by voice vote, delivering a major victory for privacy, due process, and government accountability. Credit goes to Rep. Scott Fitzgerald (R-WI), who sponsored this bipartisan reform with Rep. Jerry Nadler (D-NY), as well as with support from Judiciary Chairman Jim Jordan (R-OH) and Ranking Member Jamie Raskin (D-MD). Rep. Fitzgerald has persistently championed the bill through several Congresses, recognizing that Americans should not be kept forever in the dark when the government obtains their private digital records. Under current law, prosecutors can secretly demand a person’s emails, messages, photographs, location history, and other sensitive information from a communications or cloud provider. They can then seek a nondisclosure order – really, a gag order – preventing the provider from notifying its customer. Such orders can continue indefinitely, leaving people with no opportunity to challenge improper surveillance. The NDO Fairness Act brings this secretive process under meaningful judicial control. Under the act, an initial gag order for most investigations could last no longer than 90 days. Any extension would be limited to another 90 days and would require a court to make renewed written findings based on “specific and articulable facts.” The court would also have to find that the gag is narrowly tailored and that no less restrictive alternative would protect the investigation, witnesses, evidence, or public safety. Most importantly, once the gag expires, the government – not the communications provider – would generally have five business days to notify the person whose information was sought. That notice must describe the inquiry, identify the court that authorized the secrecy, and disclose that the government requested or received the person’s records. The individual could also request a copy of the information disclosed. “As PPSA has long maintained, notice is essential to accountability,” said Bob Goodlatte, former Chairman of the House Judiciary Committee and PPSA Senior Policy Advisor. “A right that can be violated forever in secret is almost impossible to defend. “The House has acted and the Senate should now take up the NDO Fairness Act and send it to the president’s desk,” he said. “Americans deserve and can have both security and transparency. This bill advances both.” Sen. Josh Hawley (R-MO), chairman of the Senate Judiciary Subcommittee on Crime and Counterterrorism, has launched a welcome investigation into Flock Safety’s vast network of automated license plate readers. In a letter to Flock CEO Garrett Langley, Sen. Hawley writes: “In a few short years, Flock has assembled an unprecedented national surveillance network. Your company boasts more than 120,000 cameras across 49 states and more than 20 billion vehicle scans every month. The overwhelming majority of the Americans captured in those records did nothing wrong.” Sen. Hawley adds that, instead of supporting discrete investigations, Flock’s camera data can be harnessed by artificial intelligence “to pool what they capture into a national database that customers can search.” PPSA commends Sen. Hawley for recognizing what a departure from American privacy norms Flock’s technology represents. Flock cameras record the movements of millions of innocent drivers. How that information is collected, stored, searched, shared, and ultimately used should not be governed solely by corporate policies and thousands of customized contracts with police departments scattered across the country. As Sen. Hawley writes: “Americans do not surrender their privacy rights when they drive to work, drop their kids off at school, or go to church. The Supreme Court has recognized that a comprehensive, retrospective record of a person’s movements is different in kind from ordinary observation in public. Congress never authorized the network your industry has built.” The investigation should closely examine how government access to Americans’ movements works – and the potential for that access to evolve into practices we associate with China’s surveillance state. Under Flock’s contracts, state and local police departments generally own the data their cameras generate. How do they use that data? Here are questions for Sen. Hawley and his colleagues to ask:
As Sen. Hawley concludes, “the American people want to know who has access to their personal data and how.” Americans deserve to know whether such arrangements allow federal agencies to evade constitutional and statutory safeguards. This investigation should provide those answers – and set the foundation for national standards governing Flock data. At least two safeguards should emerge from this investigation. An explicit prohibition is needed to prevent Flock data from being used to track Americans’ First Amendment activities. Standards should also include strict limits on collection, retention, sharing, and secondary uses, as well as a clear requirement that police obtain a probable-cause warrant before using Flock’s network to track an American’s movements. The threats to personal privacy posed by Flock Safety’s national network of 120,000 automated license plate readers (ALPRs) are generating national pushback. As dozens of communities cancel their contracts with Flock – and Sen. Bernie Sanders (D-VT) calls on Congress to ban Flock – the company’s CEO, Garrett Langley, is undertaking a charm offensive to defend his product by pointing to the technology’s benefits. In a Saturday interview on Fox News with Kayleigh McEnany, Langley said Flock’s network has helped locate 10,000 missing persons. He claimed that if Flock cameras had been in the right part of Arizona, the disappearance of Nancy Guthrie would not be a mystery. The Need for Guardrails Langley said that two priorities must be followed in future regulation. The first priority is to put limits on police departments’ retention of Flock data. Langley said we should all ask, “So how long is this data stored?” Flock now recommends a default retention period of seven days. Langley noted that this is a tighter standard than the 21-day limit imposed by the strictest state legislation. The second priority, Langley said, is “accountability” for abuses of this technology by a few bad apples in law enforcement. “Today, it is too often that in Flock and other technologies, there is no regulation. There is no accountability. And we think that’s wrong.” In response to recent stories about police officers misusing Flock for stalking, Langley pointed to Flock’s change to an “audit assistance tool,” which monitors the ways in which Flock is used. Flock and AI McEnany asked Langley about a Wired report on the integration of a powerful new AI tool that allows Flock’s system to use ALPR data and other records to identify drivers (and, by implication, their movements and associations). Langley acknowledged that AI is “incredibly powerful, but also a very dangerous tool.” He promised not to move “recklessly” into AI. “It requires more third-party attestation; more support from the community.” Langley added that a consumer might be irritated by an AI agent that flubs a flight reservation. But when one calls 911, he said, “it has to work. There’s no space for hallucinations.” Langley pledged to seek community support to confirm that AI has appropriate “guardrails.” Promises Made, But How Will They Be Implemented? It is a welcome sign that Flock’s CEO acknowledges that his technology needs guardrails and regulation – an implicit admission that its unregulated use poses risks to Americans’ privacy. It is also a welcome sign that Langley acknowledges that AI is a “dangerous tool” and that it must operate with near-perfect accuracy. The devil – if not a host of devils – is in the myriad details. For example, the ACLU questions whether Flock’s new audit tool could boomerang and expand surveillance. And the guardrails for AI are, as of today, speculative. It is not enough to eliminate false positives that could misidentify innocent people as suspects to be targeted by law enforcement. The combination of AI and Flock technology is precisely the kind of tool that enables the surveillance state of the People’s Republic of China. Congress should consider a law that prohibits federal and state agencies from using AI to search ALPR databases in order to track Americans’ daily movements without a probable-cause warrant. Otherwise, our daily lives and associations – personal, romantic, political, commercial, and religious – will be an open book. But we should all welcome Langley’s openness to further discussion. The lapse in the reauthorization of Section 702 of the Foreign Intelligence Surveillance Act was a crisis until it wasn’t. This surveillance law authorizes federal intelligence agencies to spy on foreign threats on foreign soil. But it has also been used by the FBI to snoop on the communications of Americans who are suspected of no crime and whose communications were incidentally swept up in the National Security Agency’s global maw. Millions of such searches have been conducted in recent years. Reform-minded Members of Congress, troubled by these mass, unrestrained searches of Americans, sought to add a warrant requirement to Section 702 before the government could read Americans’ communications at will. They were stopped by an unprecedented shutdown of regular order that prevented any debate on even modest reform amendments. As a result, Congress deadlocked and Section 702’s reauthorization expired in late spring. Dire predictions were made about the consequences of Section 702 “going dark.”
Well, the World Cup and Fourth of July celebrations came and went with no terrorist attacks. The eight men who were apprehended around that time for allegedly planning to disrupt the White House UFC event on the White House grounds were caught after warrants were issued following a tip to law enforcement from one suspect’s mother. To be clear, we do not by any means dismiss the ever-present threat of terrorism, especially with Iran now making lurid threats against the president, his family, and the American people. Our point is that it was well known on Capitol Hill that Section 702 had only expired as a governing statute. But the secret FISA Court had already approved “certifications,” or surveillance orders targeting terrorists and foreign threats under Section 702, that will “keep the lights on” through March 2027. So Section 702 never went dark. The intelligence community is still using it as it always has. If a terrorist attack occurs between now and March, it won’t be because the NSA, CIA, and FBI are unable to conduct surveillance. We raise this bit of recent history because it typifies the disingenuous way in which this debate has been conducted. While making unfounded claims in public, defenders of the status quo have twisted the rules in private to stiff-arm any meaningful debate on common-sense reforms. When Congress returns after the August recess, we hope that leadership in the House and Senate will respect regular order and allow for a meaningful debate of the kind that they were unafraid to permit in past Section 702 debates. Members of Congress should be allowed to vote on:
All proposals put forward by reformers contain reasonable exceptions for emergency circumstances. When Congress returns, won’t it be time, after all the turmoil and gamesmanship of the spring, to finally have a candid debate on these reforms, followed by an up-and-down vote? “The Government Doesn’t Own Our Data” PPSA has been following the case of Samuel Tunick, who was pulled aside during a customs search at Hartsfield-Jackson Atlanta International Airport in January. As we’ve often reported, Customs and Border Protection agents have been detaining travelers arriving from abroad until they agree to hand over their phones and other digital devices to search for potentially illegal content. It is a well-established principle that customs agents can search international travelers’ suitcases for illegal narcotics, weapons, and other contraband. The relatively new practice of scanning digital devices is different, since these devices contain, as a landmark U.S. Supreme Court opinion put it, “the privacies of life.” Such privacies include our stored photos, text messages, and emails, along with any political, religious, or cultural items we download, from books to movies. It is unknown why Tunick was pulled aside for close inspection. He is a 30-year-old left-wing activist who protested against a large police and fire training center being built in Atlanta. When detained while returning from a vacation in the Dominican Republic, Tunick was asked to give agents the passcode to his phone. He gave them a number that activated his operating system, GrapheneOS, prompting it to delete all the data on his phone. Tunick was arrested and charged with obstructing federal law enforcement. The question now is whether he will also be charged with “terrorism.” Under National Security Presidential Memorandum 7 (NSPM-7), federal authorities are directed to investigate obstruction of law enforcement at the border as possible terrorism. On Friday, a New York Times interview with Tunick crystallized much of what we have been saying about these digital border searches. What Tunick said could have come from the mouth of any constitutional conservative or libertarian. Sam Tunick said: “If someone you don’t know, who’s actively hostile to you, is trying to access your private data, your pictures, your messages, or notes to self, that may not be something that you’d like … “. . . it’s interesting to me that my charges and the other federal charges come on the heels of NSPM-7, which is the Trump Administration’s mandate to attack left-wing movements under the bogus pretense of domestic terrorism. I think we should just call that what it is, which is a direct attack on our First Amendment rights to free speech and free assembly.” To be fair, there have been high-profile instances of people interfering with border enforcement by throwing objects at agents and assaulting them. Whatever you think of the possible expansion of charges to define such people as “terrorists,” does it follow that the erasure of one’s private information should put an American in the same category as Osama bin Laden? Tunick said that under the charge of obstructing a federal law enforcement agent alone, he could face five years in prison. A traveling musician, Tunick must get the approval of a judge every time he leaves the Northern District of Georgia. Yet he remains defiant: “Just the knowledge that the government is peering into your private life in this way, trying to dig up dirt on you, even though it’s unsuccessful, it’s creepy … “I just hope to send the message that the government doesn’t own our data. The government doesn’t own our communications, our relationships, as hard as they might try to.” Cities and counties across America are “deflocking” – curbing or removing Flock Safety’s automated license-plate readers (ALPRs), with many citizens seeing this technology as a pervasive threat to their privacy. By our unofficial count, almost 50 cities and counties have either terminated their Flock contracts or failed to renew them since 2024. We counted six each in Arizona and California, four each in Washington State and Wisconsin, three in Texas, and many more in 13 other states. Community leaders from coast to coast who are taking these actions are all more or less saying the same thing. “We’ve made clear that we believe Flock systems pose an unacceptable risk to the liberty and privacy of our constituents,” Mike Siegel, a city councilman in Austin, Texas, told KUT News. Flock Safety, backed by $1 billion in venture capital, is clearly reeling from a trend that grew from a squeak of protest into a roar. This is especially true as stories emerge around the country about the misuse of Flock technology by individual police officers for stalking and by Flock personnel for creepy surveillance. Flock is responding. CEO Garrett Langley recently acknowledged and apologized for these shortcomings and announced several operational changes in response. The most salient example is Flock’s reduction of its standard data retention period from a month to seven days. The ACLU, in a sharp but fair analysis of Flock’s changes, conceded that this “may be a step in the right direction.” “Whether this is a real change or just another Flock PR move, however, will depend on how its ‘Evidence Mode’ operates,” the ACLU says. Evidence Mode is a feature that allows law enforcement to preserve specific vehicle and license plate data for ongoing criminal investigations. The ACLU writes: “If ‘Evidence Mode’ only retains hit result data that police determine may be evidence in an active investigation of a specific case, then the change may be a positive one. But if ‘Evidence Mode’ triggers the retention of any ALPR data that is searched, then the new mode could indefinitely retain all of the ALPR data Flock collects and shares nationally.” The ACLU also raised critical questions about Flock’s plans to give communities more control over how their data can be accessed by police in other communities, as well as about the effectiveness of new tools designed to reduce misuse of Flock technology by individual officers. At the same time, it would be a disservice to overlook Flock’s usefulness. In a recent interview with Detroit’s Local 4 reporter Lauren Kostiuk, Langley quoted a Florida sheriff who speculated that the recent national decline in crime might well be attributable to Flock’s never-blinking eye. Langley credited Flock with helping find than 1,000 missing people and identify 22,000 stolen cars across the United States in one month. Charles Fain Lehman of the Manhattan Institute made similar points in a piece in The Atlantic, “In Defense of Flock.” He wrote that the certainty of apprehension is a powerful disincentive to commit a crime – and that the more surveillance there is, the less crime there will be. Mike Fox, a legal fellow at the Cato Institute, has a trenchant response. “To test Lehman’s thesis, one need only apply his logic to his own doorstep. Imagine if the local police department installed a high-resolution pole camera directed squarely at his front door. By his own logic, Lehman should be elated: The camera would deter prospective burglars and, should an intruder ignore it, capture their every movement in crisp detail to ensure swift apprehension. “Naturally, this arrangement requires government officials to observe every detail of Lehman’s private life. With sufficient resolution, operators could log the packages delivered to his porch, track his every departure and return, note when he walks his dog, and monitor when his children leave for school. Under Lehman’s framework, none of this should disturb him; it is simply the price of crime suppression. His home might never be burglarized, but the cost is continuous state surveillance of his castle.” Even a search of Lehman’s doorstep limited to seven days would be deeply intrusive. Some critics see Flock as an exemplar of surveillance capitalism, although Flock does not own or sell the data its technology generates. (Law enforcement customers own the data.) PPSA has a broader concern, one illustrated by Mike Fox’s thought experiment scaled up to a national system of 120,000 Flock cameras across 49 states. Whatever Flock’s policies and safeguards, our nation is building out a network that could be used by the government to track anyone throughout their daily life. While there is no federal portal into Flock, tracking data in the hands of local law enforcement and perhaps regional “fusion centers” could wend its way upward to politically influenced agencies in Washington, D.C. The greatest danger is that such data could fall into the hands of officials and agencies eager to create dossiers on Americans by tracking our political, business, romantic, and religious associations. In short, Flock could take us down the road to a Russian or Chinese-style surveillance state. That danger is all the more reason for Congress to step in and prevent such an evolution by subjecting the use of data generated by ALPRs to safeguards grounded in the First and Fourth Amendments. Congress should consider requiring warrants before ALPR data may be used to track individual Americans. Congress should also explicitly ban the use of Flock data to monitor how Americans exercise their speech and associational rights in politics, religion, and other sensitive areas. Six weeks after the U.S. Supreme Court’s 6-3 opinion in Chatrie v. United States, it is just now becoming clear what a breakthrough opinion it actually was. This ruling leaves an altered legal landscape, one in which courts have fresh opportunities to apply stringent constitutional scrutiny to many intrusive technologies, ranging from automated license plate readers to internet search histories. At first, this ruling struck many legal observers as a welcome but modest expansion of Fourth Amendment law. Basing its conclusions on recent precedents, the Court held that whenever the government uses a geofence warrant to pinpoint an individual’s location history through cellphone data, it is performing a Fourth Amendment search. Stanford Law School professor Orin Kerr has now written a sharp analysis contending that Chatrie’s apparently narrow ruling is, in fact, a “blockbuster” that offers the most “rhetorically broad vision of the Fourth Amendment” in 140 years. We think he is right. Kerr writes that Chatrie “is an expansive pro-privacy opinion that advances new principles and throws into question a wide range of existing surveillance practices.” The Principle of Consumer Perception Much of Chatrie’s majority opinion was grounded in precedent, such as Carpenter v. United States. This 2018 ruling held that a warrant is required to track a person’s location history, while limiting that standard to location data collected from cell towers. “But a close look shows that Chatrie recasts precedents at every turn,” Kerr writes. “Chatrie alters the applicable approaches, adopts new standards, and drops old distinctions.” For example, a generation ago, the Fourth Amendment was widely understood to prohibit authorities from searching property and “effects” inside a home, a car trunk, or a suspect’s pockets without a warrant based on probable cause. Outside those protected spaces, authorities were – and are – generally free to tail people or rifle through their garbage. Chatrie demolished this inside/outside distinction. Data held in the cloud can now enjoy a level of protection similar to that of a document in a desk in one’s home. Another way Chatrie goes beyond Carpenter is by bringing users’ perceptions into the equation. Kerr writes: “It appears that a typical user’s perception of connection with data – generally a matter of app design and interface – can govern whether there are Fourth Amendment rights in the data after the data is disclosed.” The Intimacy of Data as a Factor Kerr notes that the ruling introduces new concepts into Fourth Amendment law, holding that data generated by ordinary activities on cellphones cannot be presumed to be voluntarily disclosed to third-party tech companies. And Chatrie reorients Fourth Amendment law around the intimacy of private information, rather than the manner in which it was obtained. Kerr quotes Justice Sonia Sotomayor’s concurrence in a prior case, in which she noted that GPS records contain a “comprehensive record of a person’s public movements that reflects a wealth of detail about her familial, political, professional, religious, and sexual associations.” This reasoning from one justice in a 2012 case about GPS seems to have filtered into the majority’s thinking about technology in general. What’s Next? Where does the law go from here? Some courts will undoubtedly interpret Chatrie narrowly, restricting it to location data. Doing so, however, would ignore the broader implications of Justice Kagan’s majority opinion and its new standards. We can expect conflicting rulings as lower courts try to apply Chatrie to automated license plate readers, tower dumps, IP addresses, subscriber information, internet search terms, blockchain transactions, and online undercover operations. If lower courts are true to Chatrie, they will recognize a constitutional imperative to apply the Fourth Amendment to curb the unprecedented power of new technology to expose the entirety of a human life. The Securities and Exchange Commission is charged with policing securities markets. It is not an intelligence agency. So why was it secretly monitoring the air travel of people under investigation? Collin Mercer of Tech Times reports that newly released documents show the SEC purchased access to the Travel Intelligence Program, a massive airline-ticket database maintained by the Airlines Reporting Corporation (ARC). ARC is a clearinghouse that processes transactions between airlines and travel agencies. This gives it access to passenger names, credit card numbers, flight numbers, travel dates, and departure and arrival cities. Its database contained more than one billion records, including information about flights between foreign countries. The SEC did not merely search historical records. It subscribed to a surveillance service that automatically compared new bookings against the agency’s watchlists. Whenever a listed individual purchased a ticket, the SEC could receive an alert within 24 hours. The agency requested the ability to receive between one and 25 such alerts a day. No warrant was required, nor did a judge review whether the surveillance was justified. The SEC may have used this information to investigate insider trading or determine whether two people suspected of exchanging confidential information had traveled to the same place. This form of tracking could have provided complementary evidence in cases flagged by ARTEMIS, the SEC’s data analytics platform that sifts through six billion trading records to identify transactions that have the hallmarks of insider trading. But a plausible investigative purpose does not erase the Fourth Amendment. If the government wants to track someone’s movements, it should demonstrate probable cause to a judge. As PPSA has reported, ARC’s government customers have also included Customs and Border Protection, the Bureau of Alcohol, Tobacco, Firearms and Explosives, the Transportation Security Administration, the State Department, the U.S. Marshals Service, and the IRS. The SEC’s participation demonstrates the limitless nature of the data-broker loophole: If one federal agency can purchase sensitive information without judicial review, virtually any agency can. ARC ended the Travel Intelligence Program in 2025 after its surveillance activities attracted public and congressional scrutiny. But the legal loophole that enabled the program remains open, and other vendors can offer similar services. Nor does the end of TIP mean that suspects will be informed that they were targeted. Since the SEC brings civil enforcement actions, rather than criminal prosecutions, it is not obligated to turn over exculpatory evidence to the people it charges the way prosecutors must. So people whose travel was tracked by the SEC while TIP was in play may never learn that their personal data was used to bring a case against them. The SEC should fill in the blanks by disclosing how it used ARC’s information, whether that data remains in government systems, and whether it has purchased comparable information from other brokers. It should then formally renounce this practice. While this SEC practice appears to have been curbed, at least a dozen other federal agencies – including the FBI, the IRS, the Department of Homeland Security, and the Pentagon – are still purchasing Americans’ digital data, including search histories and communications metadata, from shady third-party data brokers for unknown uses. Congress should investigate and inform the American people about how our government uses and abuses our purchased data. An unsecured police database has provided a rare glimpse inside China’s surveillance state. The database examined by The New York Times tracked hundreds of foreigners. But its significance extends far beyond the surveillance of foreign residents. As The Times reports, its existence illustrates how Chinese authorities aggregate vast amounts of information from surveillance cameras, medical records, utility bills, facial-recognition systems, and other sources to monitor and analyze individuals’ behavior. The database included hospital visits, gas payments, frequently visited locations, and air and rail travel – down to seat numbers. It tracked one woman’s movements from her home to shopping malls, restaurants, and supermarkets, sometimes using facial recognition. The power of China’s surveillance system does not rest on any single camera or database. It comes from joining countless streams of personal information into one comprehensive picture. Now for the turnabout: Is the United States a surveillance state like China – or are we about to become one? Consider recent reports on the domestic surveillance capabilities our government already possesses: • Foreign communications: Section 702 of the Foreign Intelligence Surveillance Act, now awaiting congressional reauthorization, allows federal agencies to collect global communications. That collection inevitably sweeps in Americans’ messages, which the FBI has searched millions of times in recent years. Congress must debate a warrant requirement before federal agencies are allowed to search Section 702 data for Americans’ communications. • Forcing businesses to spy on their customers: The “Make Everyone a Spy” provision of the most recent FISA reauthorization in 2024 dramatically expanded the definition of an electronic communications service provider. It can require owners and operators of commercial facilities and even churches housing communications equipment (including common services like free WiFi) to assist government surveillance – and remain silent forever under a gag order. • Political and social-media activity: The Wall Street Journal reports that ICE has established a round-the-clock dragnet across Facebook, Instagram, X, and other platforms. Contractors prepare dossiers that can include a person’s name, address, workplace, Social Security number, vehicle registration, and criminal history. DHS has reportedly issued hundreds of subpoenas to identify anonymous critics, while agents have confronted Americans over online speech. • DNA: According to Wired, ICE may have contributed almost 920,000 DNA profiles to the FBI’s CODIS database in 2025 alone. The broader DHS collection program includes people accused of no crime. Newly released CBP records show that it has even collected DNA from children as young as four. • Air travel: The Securities and Exchange Commission purchased access to more than one billion airline-ticketing records, according to 404 Media. These records covered not only domestic U.S. flights and international flights involving the United States, but also travel between foreign countries. The airline-owned data broker reportedly made this information available without passengers’ knowledge and likely without warrants. • Movements on the ground: Flock Safety cameras record millions of drivers in thousands of American communities. Flock has announced plans to combine license-plate-reader records with public records, open-source intelligence, and commercial “people lookup” data. This can transform a vehicle sighting into a dossier – and allow algorithms to generate suspicion from ordinary patterns of movement. So, is the United States a surveillance state? In terms of capabilities, yes. In terms of intent, not quite – at least not yet at the comprehensive, integrated scale practiced by China. It would take a concerted effort to bring all these elements together into a single system – integrated by artificial intelligence – to comprehensively surveil Americans through their faces, foreign communications, DNA, geolocation, movements, searches, and interests. In short, what separates the United States from Chinese levels of comprehensive surveillance is not capability. It is the intent of government officials – and our trust that they will respect the institutional and constitutional restraints that stand in their way. And in case you have been living off the grid in the Australian Outback for the last decade, trust is in short supply these days. Part I: Flock’s Cameras Were Supposed to Watch for Criminals – Why Were Employees Watching Children?8/5/2026
Automated license plate readers are sold to communities as straightforward public-safety tools: cameras photograph passing vehicles, record their license plates, and alert police when they detect a car linked to a crime. But Flock Safety is becoming much more than a network of license plate readers. As the company integrates traffic cameras, police databases, drones, and privately owned video feeds into a surveillance platform, the opportunities for abuse are multiplying. Mary Rooke of The Daily Caller highlights a disturbing example from Dunwoody, Georgia. Local resident Jason Hunyar used public-records requests to obtain audit logs showing how Flock employees accessed cameras connected to the Dunwoody Police Department’s surveillance system. Some of those cameras were inside the Marcus Jewish Community Center of Atlanta. They showed swimming pools, fitness studios, preschool hallways, and gymnastics rooms where children practiced in their leotards. Hunyar found that one Flock executive had accessed Dunwoody’s live and recorded footage 185 times since the beginning of 2025. On one occasion, the only camera he viewed was inside the gymnastics room. Another Flock employee clicked through several cameras at the community center before settling on a view of its main pool. Why were employees of a surveillance vendor looking at these feeds? Why did sales and business-development personnel have such access in the first place? We should not rule out an innocent explanation. But even if there is one, this story demonstrates the many ways these camera systems can be misused in ways to threaten Americans’ privacy. A camera installed for one purpose can quietly become part of a much larger system. A feed intended to protect a private facility can become available to police officials, corporate employees, outside agencies, or any hacker who defeats the system’s security. License plate records can be combined with video, location histories, and other databases to produce an increasingly intimate picture of people’s lives. Communities with Flock technology should require enforceable limits on who may access cameras and data, individualized credentials, prompt disclosure of misuse, independent security testing, and meaningful penalties for improper access. Cameras inside private facilities – especially spaces used by children – should never be swept into police surveillance networks without fully informed consent and exceptionally strong protections. The question is no longer simply whether these systems can help police solve crimes. It is whether any claimed benefit justifies building a surveillance network that may enable strangers to watch us and our children. Amid mounting concern about the misuse of personal data from Flock Safety cameras, the college community of Harrisonburg, Virginia, has joined the growing ranks of American communities rejecting that company’s pervasive surveillance of motorists. The Harrisonburg City Council voted unanimously to end the city’s contract with Flock Safety, shut down its automated license plate readers, and cover the cameras with trash bags until they can be removed. The council also adopted a policy encouraging future councils to consider privacy, data security, equity, and public trust before deploying similar technology. Residents are continuing to press for a binding ordinance that would require public scrutiny of any future mass-surveillance proposal. Harrisonburg Mayor Deanna Reed acknowledged that Flock cameras can help solve crimes. But she concluded that its risks outweighed its benefits. “We might not share the data, that doesn’t mean that somebody can’t get a hold of what we have,” Reed told a reporter at WHSV, a local television station. “The safest thing to do is just not use it at all.” That is a sensible response to a technology that does far more than snap an occasional picture. Flock’s artificial-intelligence system records license plates and vehicle characteristics, allowing police to reconstruct a person’s movements and search for vehicles by color, model, dents, and bumper stickers. Networks linked across jurisdictions can transform scattered observations into a detailed account of where someone worships, works, seeks medical treatment, associates with others, or attends a political protest. Then there is the problem of accuracy. A Business Insider investigation found that Flock’s software misread plates in 71 percent of the stolen-vehicle and felony alerts it sent to police in Roseville, California, during 2023 and 2024. Records showed that the cameras also produced blurry images, missed vehicles, and sent delayed alerts. Roseville’s unusual camera positioning may have contributed to the errors, and its police said none of the false alerts resulted in a stop or arrest because officers independently verified the information. Other communities have not been so fortunate. Flock errors, sometimes compounded by failures of police verification, have led innocent drivers elsewhere to be stopped at gunpoint, jailed, and even mauled by a police dog. Harrisonburg is part of a genuinely bipartisan revolt. Charlottesville ended its Flock pilot program over concerns about data protection, misuse, and local control. In Bandera, Texas, opposition came from residents steeped in a conservative tradition of personal liberty and distrust of government overreach. Across the ideological spectrum, Americans understand that tools to combat serious crimes can easily expand into routine, warrantless monitoring. Police should use targeted investigative methods to pursue people reasonably suspected of crimes. They should not assemble a searchable record of everyone’s movements just in case someone might later come to the attention of authorities. Harrisonburg has made the right call. Other communities should follow its lead and tell mass surveillance to get the Flock out. We’re shocked – shocked! – to find that spying is going on in Morocco. That country’s intelligence service is using what may be the world’s most powerful spyware to target “journalists, human rights defenders, French politicians and Spanish cabinet ministers and police officers,” according to reporting led by Sam Jones for The Guardian. The new evidence comes from a whistleblower who previously worked for Morocco’s internal security services and was uncovered in a collaborative journalistic investigation that includes Amnesty International’s Security Lab. The spyware Morocco is believed to have used includes the infamous Pegasus, which allows its operator to access everything on a target’s mobile phone, including emails, text messages, and photographs. This software does not require the victim to fall for a phishing scam, but can simply install itself remotely. Pegasus can also activate the phone’s recorder and camera, turning it into a 24/7 listening and video-recording device. In July, Security Lab published a technical analysis of Pegasus, labeling it “the world’s most notorious spyware system.” Pegasus manufacturer NSO Group says it sells its software to governments that need help tracking criminals and terrorists. For its part, Morocco denies having any relationship with NSO. The investigation’s leader Forbidden Stories and its partners found evidence to the contrary. For entities with an interest in such technology, Pegasus is particularly appealing because, again, it can infect phones remotely – physical access no longer required. This spyware also has the added advantage of erasing any evidence of its existence. What used to be exceedingly difficult – traditional field intelligence – has suddenly become easy. Perhaps too easy. As described in the accompanying documentary, “Pegasus Project: Inside the Moroccan Spying Machine,” after Morocco’s intelligence service realized what it possessed in Pegasus, its agents quickly added the cell numbers of Moroccan journalists and human rights defenders. Not exactly “criminals and terrorists.” And before long, The Guardian reports, “the targeting had begun to extend beyond Morocco’s borders,” eventually including 200 Spanish mobile numbers, among them those of the prime minister, the minister of defense, the interior minister, and the minister of agriculture. Spain dropped its initial investigation, only to briefly reopen it after French authorities shared details of their own Pegasus experience. “We spy on everyone,” a former Moroccan intelligence officer said in conversation with the journalists, “just in case.” It’s all just one more chapter in the unfolding real-life thriller that is the NSO/Pegasus drama. Imagine taking your child to a playground and later learning that strangers could watch her play live online – or replay it at any time. Technology researcher and YouTuber Benn Jordan discovered an alarming example of privacy vulnerability – a Flock Safety camera permanently aimed at a playground near the San Francisco Bay Area was openly broadcasting over the internet. No username or password was required. Jordan and security researcher Jon “GainSec” Gaines found nearly 70 unsecured Flock cameras through a commercial search engine that catalogs internet-connected devices. The cameras were so easy to access that Jordan compared the system to “Netflix for stalkers.” These were not merely license plate readers. They included Flock’s Condor cameras, which can pan, tilt, and zoom – and use artificial intelligence to detect and follow people automatically. Condor is not a license-plate reader. It is a people watcher. Jordan says he watched a man leave his home in New York and a woman jog alone on a wooded trail in Georgia. He watched a man rollerblade, stop, and view videos on his phone. The camera’s AI zoomed in closely enough to see what he was watching. Jordan also saw a couple arguing at an Atlanta street market – and used common internet resources to identify their health and financial problems. In another disturbing sequence, he observed emergency responders attending to an apparently injured person. All of this was available to anyone who found the feeds. The exposure went far beyond live viewing. According to 404 Media, visitors could access administrative controls, download about a month of archived footage, change settings, inspect logs, run diagnostics, and even delete video. Jordan demonstrated the vulnerability by standing beneath one of the cameras and watching himself on his phone in real time. Flock called the episode a “limited misconfiguration” affecting a small number of devices and said it had corrected the problem. But that response misses the larger lesson. As Jordan stresses later in his account, responsibility also rests with the local governments that purchase and deploy these systems. City councils and police departments are building interconnected networks of AI-enabled cameras without first demanding rigorous independent security audits, enforceable access controls, clear data-retention limits, and public accountability. Local officials cannot outsource their responsibility to protect citizens’ privacy. Before approving surveillance technology, they should understand precisely what it records, who can access it, how it can be abused, and what happens when its security fails. A camera installed in the name of public safety should not become an unlocked window into a child’s playground, a couple’s argument, or anyone’s daily life. The story of the mobile spy SUVs purchased by the state of Texas for $4.5 million continues to unfold. According to Alex Barrientos of Gadget Review, the Texas Department of Public Safety’s purchase of four Chevy Tahoes includes an extra $3.9 million for a proprietary surveillance system from a company named Cognyte, Israel’s version of Palantir. Cognyte is the maker of the FalcoNet surveillance technology embedded in the SUVs. FalcoNet, writes Andrew Collins of The Drive, has already been deployed in Florida (as has similar stingray technology elsewhere). Its purpose is simple, if ominous: get between cellphone towers and any phones that happen to be near them, and then secretly intercept and capture everything that being transmitted. FalcoNet and its competitors do this by pretending to be ordinary cell towers, tricking every phone nearby into connecting (smartphones can't help themselves because they are programmed to respond to the strongest signal). Cognyte claims FalcoNet can be activated in under three minutes and can connect with thousands of devices at once as the surveillance vehicles roll through traffic and past pedestrians. Those intercepts are meant to catch the communications of bad actors being sought by authorities. But the software cannot filter out the private information of bystanders from that of suspects, which means that Texas and Florida are sweeping up the data of everyone who happens to be in the mobile system’s vicinity. The data of thousands of innocent persons can then be sifted through afterward. This presumes that only law enforcement will do the sifting – and not hackers, data brokers, or hostile state actors. Even so, that is cold comfort given what we know from the actual abuse and potential misuses of similar surveillance systems. The growing use of stingrays, whether installed on poles in busy parts of town, in mobile police units, or even mounted on drones, underscores the importance of commercial encryption services in protecting our everyday communications. We should be able to enjoy the same level of privacy in our texts and emails that we expect when having a private conversation with a friend. Equally important, the entire premise of such spy regimes – no matter what the official rationalization – flies in the face of the Fourth Amendment. Designed to protect against the invasive and indiscriminate mass searches of general warrants, the Fourth Amendment offers a simple calculus: probable cause + a court warrant + narrowly defined search criteria. In their current forms, programs like the aptly named FalcoNet – and it is a net – are functional dragnets, modern-day general warrants that thwart every aspect of the Constitution’s privacy safeguards. Not even outmoded interpretations of the third-party doctrine can (or should) be invoked to save them. The good news is that we now live in the Chatrie era. In that recent decision, the U.S. Supreme Court clearly articulated a fundamental right to certain forms of digital privacy, specifically regarding location tracking (including geofencing, the whole raison d'être for those shiny new Texas spy SUVs). In short, this practice of roving mass surveillance is ripe for a challenge in court. When PPSA last examined Canada’s proposed Lawful Access Act, we described how it could undermine encryption and endanger privacy worldwide. Now Sen. Ron Wyden (D-OR) is warning that the bill could also enable the Canadian government to conscript American technology companies into spying on Americans. Bill C-22, which has passed Canada’s House of Commons and is now before the Canadian Senate, would grant authorities in Ottawa sweeping new surveillance powers. It would require service providers to retain sensitive user metadata, such as location information, for up to a year. It could also force companies to alter their systems to facilitate government access or install tracking capabilities and security backdoors. In a letter to Secretary of State and acting National Security Adviser Marco Rubio and acting Attorney General Todd Blanche, Sen. Wyden writes that the bill “threatens to weaponize American technology infrastructure by enabling the Canadian government to force U.S. companies to secretly facilitate surveillance of Americans, while systematically undermining the security of their products.” A foreign government could conceivably pressure an American company to retain special backups of an American target’s data, relocate encryption keys to a jurisdiction where they could be seized, or deliver government spyware through a compromised software update. The target could be anyone. As Sen. Wyden warns, “U.S. law does not explicitly prohibit American companies from secretly facilitating foreign surveillance of U.S. citizens – even if the target is the President or another senior U.S. government official.” “This is not a dilemma of U.S. companies being caught between conflicting international legal obligations,” he writes. “It is a glaring statutory vacuum.” Canada is negotiating an agreement with the United States under the CLOUD Act, which would enable Canadian authorities to seek some data directly from American companies. Sen. Wyden urges the Trump Administration to use those negotiations to obtain “ironclad, explicit prohibitions” against Canadian demands that U.S. companies reengineer their products or facilitate surveillance of Americans. As PPSA has warned, there should be no encryption backdoor reserved for trustworthy governments. Any vulnerability can be exploited by hostile governments, criminals, and increasingly capable artificial intelligence systems. Sen. Wyden puts the principle succinctly: “Bilateral trust with our closest intelligence partners cannot be built on the secret subversion of American cybersecurity infrastructure.” The Trump administration should heed his warning. Canada must not be permitted to turn American technology companies into instruments of secret spying on Americans. "Custom-house officers may enter our houses, when they please ... may break locks, bars, and everything in their way; whether they break through malice or revenge, no man, no court can inquire." |
Categories
All
|
RSS Feed